Gusto for AI agents

Gusto is a payroll, benefits, and HR platform for small and medium businesses, handling employee pay, time off, and compliance. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

HR and recruitingOAuth 2.0MCP + RESTgusto.com
AUDIT LOG · GUSTOPOLICY: acme-support
09:41:07 · claude · u_8f2read
gusto.list_benefits
List Benefits✓ allowed · 212ms
09:41:08 · claude · u_8f2read
gusto.get_job
Get job✓ allowed · 164ms
09:41:09 · claude · u_8f2write
gusto.create_job
Create Job✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
gusto.delete_job
Delete Job✕ blocked · policy: deny
EVERY GUSTO CALL, ON THE RECORD
01 · USE CASES

What agents do in Gusto.

01

Look up an employee's record

Pull an employee's job and compensation details before answering a payroll question.

02

Create a new employee record

Add a newly hired employee's details to start their onboarding in payroll.

03

Approve a pay schedule change

Update a pay schedule assignment only after HR confirms the new schedule with the employee.

02 · ACTIONS

192 Gusto actions, graded by risk.

Every Gusto action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

104

Look things up. Allowed by default.

  • gusto.get_job
    Get job
  • gusto.get_form
    Get Company Form
  • gusto.get_benefit
    Get Benefit
  • gusto.get_company
    Get company
  • gusto.get_payroll
    Get payroll
  • gusto.get_reports
    Get report
  • gusto.get_employee
    Get employee
  • gusto.get_location
    Get location
  • gusto.list_benefits
    List Benefits
  • gusto.get_contractor
    Get Contractor
  • gusto.get_department
    Get Department
  • gusto.get_token_info
    Get token info
  • gusto.list_employees
    List Employees
  • gusto.list_pay_stubs
    List Pay Stubs
  • gusto.get_garnishment
    Get Garnishment
  • gusto.get_home_address
    Get Home Address
+ 88 MORE

write

69

Create and change things. Allow, or ask the user first.

  • gusto.create_job
    Create Job
  • gusto.update_jobs
    Update Jobs
  • gusto.create_admin
    Create Admin
  • gusto.create_flows
    Create flows
  • gusto.create_reports
    Create Custom Report
  • gusto.update_company
    Update Company
  • gusto.create_employee
    Create Employee
  • gusto.update_employee
    Update Employee
  • gusto.update_location
    Update location
  • gusto.create_contractor
    Create Contractor
  • gusto.create_department
    Create Department
  • gusto.update_department
    Update Department
  • gusto.update_garnishment
    Update Garnishment
  • gusto.update_state_taxes
    Update State Taxes
  • gusto.create_garnishments
    Create Garnishment
  • gusto.update_earning_type
    Update Earning Type
+ 53 MORE

destructive

19

Delete, cancel or archive. Ask first, or deny outright.

  • gusto.delete_job
    Delete Job
  • gusto.delete_employee
    Delete Employee
  • gusto.delete_contractor
    Delete Contractor
  • gusto.delete_department
    Delete Department
  • gusto.delete_compensation
    Delete Compensation
  • gusto.delete_work_address
    Delete Work Address
  • gusto.delete_employee_benefit
    Delete Employee Benefit
  • gusto.delete_employee_termination
    Delete Employee Termination
  • gusto.delete_employee_bank_account
    Delete Employee Bank Account
  • gusto.delete_employee_home_address
    Delete Employee Home Address
  • gusto.delete_companie_bank_accounts
    Delete Company Bank Account
  • gusto.remove_people_from_department
    Remove People From Department
  • gusto.delete_time_tracking_time_sheet
    Delete Time Tracking Time Sheet
  • gusto.delete_i9_authorization_document
    Delete I-9 Authorization Document
  • gusto.remove_time_off_policy_employees
    Remove Employees from Time Off Policy
  • gusto.delete_company_holiday_pay_policy
    Delete Company Holiday Pay Policy
+ 3 MORE
03 · HOW IT WORKS

Gusto in three steps.

  1. 01Your users connect GustoThey sign in to Gusto on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create Job” can wait for the user, and “delete Job” can be denied outright.
  3. 03Any agent can actYour agent calls Gusto through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('gusto', {
  read: 'allow',
  write: 'ask',        // create_job
  destructive: 'deny',  // delete_job
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Gusto connects.

Users sign in to Gusto on Arc0 Connect and approve the scopes you request. Build with Arc0’s Gusto OAuth app, or bring your own so the Gusto consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Gusto connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Gusto from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Gusto and Arc0, answered.

Q01

Can I use Gusto with Claude, ChatGPT or Cursor?

Yes. Connect Gusto to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Gusto actions you allow.

Q02

How do users connect Gusto?

Users sign in to Gusto on Arc0 Connect and approve the scopes you request. Build with Arc0’s Gusto OAuth app, or bring your own so the Gusto consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Gusto actions can my agent take?

192 in total: 104 read, 69 write and 19 destructive, such as “create Job”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Gusto?

Yes. Actions like “delete Job” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Gusto too?

Yes. The same Gusto connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Gusto into your agent.

Your users connect Gusto once, under your brand. Your agent gets 192 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan