API Planned · not live yet

Compliance as an API.

This page documents the API that ships with the production backend; today the rule engine runs in your browser and there is no hosted endpoint. Push events, pull obligations, subscribe to the calendar. Same rule engine, same sourced rules — for your own tools, your CPA's systems or a vertical SaaS.

Endpoints

POST /v1/events
GET  /v1/obligations?status=open&jur=CA
GET  /v1/obligations/{id}
GET  /v1/rules?level=state&jur=TX
GET  /v1/rules/{id}/versions
GET  /v1/calendar.ics
GET  /v1/documents/{id}
GET  /v1/audit?since=2026-09-01

Authorization: Bearer hora_live_…
Rate limit: 600 req/min · JSON · Webhooks for obligation.created, obligation.due_soon, rule.updated

Example: report a hire

POST /v1/events
{
  "type": "NEW_EMPLOYEE",
  "employee": { "name": "Marco Torres", "state": "CA", "start": "2026-09-10", "type": "W2" }
}

→ 201 Created
{
  "event": "ev_7c21", "added": 3,
  "obligations": [
    { "id": "ob_8f21", "rule": "FED-I9", "version": 3, "due": "2026-09-15", "level": "federal" },
    { "id": "ob_8f22", "rule": "ST-NEWHIRE", "version": 2, "due": "2026-09-30", "level": "state", "jur": "CA" },
    { "id": "ob_8f23", "rule": "FED-W4", "version": 1, "due": "2026-09-15", "level": "federal" }
  ]
}

End-to-end: the API brokers encrypted payloads between your integrations and your device vault. Hora cannot read the payloads.