Ashby for AI agents

Ashby is an applicant tracking system for recruiting teams, covering job postings, candidate pipelines, interviews, and offers, with reporting to help hiring teams make data-driven decisions. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

HR and recruitingAPI keyMCP + RESTashbyhq.com
AUDIT LOG · ASHBYPOLICY: acme-support
09:41:07 · claude · u_8f2read
ashby.list_jobs
List Jobs✓ allowed · 212ms
09:41:08 · claude · u_8f2read
ashby.list_brand
List Brands✓ allowed · 164ms
09:41:09 · claude · u_8f2write
ashby.create_job
Create Job✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
ashby.archive_location
Archive Location✕ blocked · policy: deny
EVERY ASHBY CALL, ON THE RECORD
01 · USE CASES

What agents do in Ashby.

01

Move a candidate to the next stage

Change an application's stage after an interview round with the candidate has been completed.

02

Add a note to a candidate's profile

Create a candidate note recording feedback from the hiring team after an interview.

03

Confirm before approving an offer

Approving an offer is a significant hiring decision that should require sign-off first.

02 · ACTIONS

125 Ashby actions, graded by risk.

Every Ashby action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

62

Look things up. Allowed by default.

  • ashby.list_jobs
    List Jobs
  • ashby.list_brand
    List Brands
  • ashby.list_users
    List Users
  • ashby.list_offers
    List Offers
  • ashby.search_jobs
    Search Jobs
  • ashby.get_job_info
    Get Job Info
  • ashby.list_sources
    List Sources
  • ashby.search_users
    Search Users
  • ashby.get_file_info
    Get File Info
  • ashby.get_user_info
    Get User Info
  • ashby.list_approval
    List Approvals
  • ashby.list_openings
    List Openings
  • ashby.list_projects
    List Projects
  • ashby.get_offer_info
    Get Offer Info
  • ashby.list_locations
    List Locations
  • ashby.search_opening
    Search Opening
+ 46 MORE

write

54

Create and change things. Allow, or ask the user first.

  • ashby.create_job
    Create Job
  • ashby.update_job
    Update Job
  • ashby.create_offer
    Create Offer
  • ashby.create_opening
    Create Opening
  • ashby.update_opening
    Update Opening
  • ashby.add_opening_job
    Add Opening Job
  • ashby.create_location
    Create Location
  • ashby.create_referral
    Create Referral
  • ashby.create_candidate
    Create Candidate
  • ashby.update_candidate
    Update Candidate
  • ashby.add_candidate_tag
    Add Candidate Tag
  • ashby.create_department
    Create Department
  • ashby.update_department
    Update Department
  • ashby.create_application
    Create Application
  • ashby.update_application
    Update Application
  • ashby.update_job_posting
    Update Job Posting
+ 38 MORE

destructive

9

Delete, cancel or archive. Ask first, or deny outright.

  • ashby.archive_location
    Archive Location
  • ashby.archive_department
    Archive Department
  • ashby.remove_opening_job
    Remove Opening Job
  • ashby.remove_opening_location
    Remove Opening Location
  • ashby.archive_interviewer_pool
    Archive Interviewer Pool
  • ashby.remove_hiring_team_member
    Remove Hiring Team Member
  • ashby.remove_interviewer_pool_user
    Remove User from Interviewer Pool
  • ashby.list_close_reasons
    List Close Reasons
  • ashby.list_archive_reasons
    List Archive Reasons
03 · HOW IT WORKS

Ashby in three steps.

  1. 01Your users connect AshbyThey add their Ashby api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Job” can wait for the user, and “archive Location” can be denied outright.
  3. 03Any agent can actYour agent calls Ashby through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('ashby', {
  read: 'allow',
  write: 'ask',        // create_job
  destructive: 'deny',  // archive_location
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Ashby connects.

Users add their Ashby api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Ashby connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Ashby from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Ashby and Arc0, answered.

Q01

Can I use Ashby with Claude, ChatGPT or Cursor?

Yes. Connect Ashby to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Ashby actions you allow.

Q02

How do users connect Ashby?

Users add their Ashby api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Ashby actions can my agent take?

125 in total: 62 read, 54 write and 9 destructive, such as “create Job”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Ashby?

Yes. Actions like “archive Location” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Ashby too?

Yes. The same Ashby connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Ashby into your agent.

Your users connect Ashby once, under your brand. Your agent gets 125 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan