SD Worx (BE SME Payroll)
Service ID: sdworx-be-sme
SD Worx BE SME OpenPayroll API for Belgian SME payroll master data: employers, contracts and person details.
At a Glance
- Difficulty
- ⚠️INVOLVEDPartnership With SD Worx BeIntegration + Certificate-Based Client Authentication
- Authentication
- OAuth 2.0Client credentials flow signed with a certificate-backed private_key_jwt assertion; each consumer enters its own SD Worx Client ID and private key in Vault.
- Webhooks
- Virtual webhooks↗ - employee created, updated and terminated events, plus company created and updated events.
- Partnership Required
- Yes(Nothing to register on your side: SD Worx BeIntegration issues each connecting employer its own Client ID by email, no portal.)
- Partnership Application
- SD Worx contact page↗
- Apideck Credentials
- Not available(Every connecting employer registers its own certificate with SD Worx BeIntegration; nothing is configured at application level except the environment.)
- Costs
- No separate charge for API access is published; it comes on top of your SD Worx BE SME payroll contract.
- Sandbox Availability
- Available(Acceptance environment with a test employer, provisioned by SD Worx BeIntegration on request as part of the partnership; there is no self-service signup.)
- Account Type Required
- SD Worx BE SME payroll customer in Belgium whose employer file SD Worx BeIntegration has made accessible to your registered client
- Consumer Access Level
- Consumers enter the Client ID and private key issued for their registered certificate, then pick which employer to connect. No SD Worx login.
- Rate Limits
- SD Worx does not publish rate limits for this API.
Responsibility matrix
| Task | You (Customer) | Your Consumer | Apideck |
|---|---|---|---|
| Generate the certificate and register it with SD Worx BeIntegration to obtain a Client ID | — | ✓ | — |
| Select the Server URL (acceptance or production) in Apideck | ✓ | — | — |
| Enter the Client ID and private key when connecting | — | ✓ | — |
| Confirm that the integration may access the employer's payroll file | — | ✓ (if required) | — |
| Select the employer (payroll file) when connecting | — | ✓ | — |
| Mint and refresh access tokens, poll for changes (virtual webhooks) | — | — | ✓ |
| Notify SD Worx before the certificate expires and register the renewed one | — | ✓ | — |
Environments
- Acceptance
- Runs on api.acc.sdworx.com with token host auth.acc.sdworx.com. SD Worx BeIntegration provisions a test employer on request; its Client ID and certificate are separate from production.
- Production
- Runs on api.sdworx.com with token host auth.sdworx.com and requires the production Client ID issued for your registered certificate. ⚠️ Acceptance credentials cannot be used against production.
🚨Important to Know About SD Worx (BE SME Payroll)
- This API carries payroll master data: no time-off requests (SD Worx keeps absences in its separate HR Selfservice product), no departments or managers, and no bank account details.
- SD Worx must be told at least 6 weeks before your certificate expires, and the renewed certificate goes back through the same email round trip.
- One connection covers one employer (payroll file). A customer with several employers at SD Worx needs one connection per employer.
- This is the only SD Worx integration path open to new BE SME customers: SD Worx no longer activates the Business Platform or HR Selfservice web-service access that Apideck's older SD Worx connectors depend on.
⚠️
4 gotchas across 2 resources
Connector-specific behaviors and limitations to be aware of
📦
2 supported resources
View field mappings, supported operations, and schema details