Pyn connects directly to ADP Workforce Now to sync your employee data, so your directory, groups, and automations always reflect what's in ADP. The connection uses ADP's official API with certificate-based authentication, meaning your data flows securely between the two systems with no third-party tools in between.
Setting up the connection takes a few steps in ADP and a little coordination with the Pyn team. Most customers are up and running within a day or two.
Before you begin
You'll need:
Admin access to ADP Workforce Now, specifically the ability to create projects in ADP API Central.
An active Pyn workspace
Step 1: Create an API project in ADP API Central
Log in to ADP and open API Central.
Create a new API project for Pyn.
Note the Client ID and Client Secret that ADP generates for the project. You'll share these with Pyn in Step 3.
Step 2: Grant Pyn access to worker data
Pyn reads employee records through ADP's Workers API. For the sync to work, your API project needs the worker read permission added to its scope.
In API Central, add this canonical URI to your project's application scope:
/hr/workerInformationManagement/workerManagement/workerProfileManagement/worker.read
Without this permission, the connection will authenticate but Pyn won't be able to retrieve your employee list.
Step 3: Complete the secure certificate exchange
ADP's API requires a security certificate and matching private key to verify Pyn as an authorized application. Rather than asking you to generate and download these files from the ADP portal (which can be error-prone), the Pyn team generates the certificate for you. You then upload it to your ADP project.
Your Pyn contact will walk you through this step and provide the certificate file. Once it's uploaded and you've shared your Client ID and Client Secret, Pyn can complete the connection.
Step 4: Verify your data in Pyn
Once the connection is live, your employees will start appearing in the Directory in Pyn. We recommend you review the data:
Employee names appear as they should (Pyn displays preferred names when they're set in ADP, otherwise legal names).
Hire dates and tenure look correct. Pyn uses ADP's original hire date for hire date, and the seniority date for tenure.
Organizational data like business units and job classes has come across. These map automatically from your ADP organizational units.
Syncing sensitive fields (like birthdays)
Some fields, such as date of birth, are masked by default in ADP and won't sync until you adjust permissions on the ADP side. To sync birthdays (for example, to power birthday messages in Pyn), update the masking settings on your data connector's application profile in ADP so the field is revealed to the API, rather than partially masked.
How the sync works
Ongoing sync: Pyn refreshes your employee data from ADP on a regular schedule, so changes in ADP (new hires, departures, field updates) flow through automatically.
Read-only: Pyn only reads employee data from ADP. It never writes back to your ADP records.
Field changes: If a field you need isn't syncing, it can usually be added. Custom field changes are made in your ADP Workforce Now settings, and the Pyn team can map new fields on our side.
