Developer portal

Embed payroll UI and APIs into your product in minutes.

Mint a scoped tenant token, mount one of 33 web components, and call the same governed payroll API behind calculations, pay runs, filings, evidence, webhooks, and MCP tools.

Bearer-only auth · no cookies · every write lands in the evidence chain

integrate.htmllive sdk on this page
01
POST /v1/tenants/ten_8fk2/embed/token · backend, partner key
02
<script src="cdn.ledrapay.com/v1/ledrapay-components.js">
03
<ledrapay-payslip-viewer> · el.embedToken = token
<ledrapay-payslip-viewer country="AU">sample mode — no credentials
The trust model

Partner keys stay on your servers. The browser gets a receipt-sized token.

Every credential is scoped to exactly what the page renders — tenant, component allowlist, optionally one employee, optionally one origin — and dies in fifteen minutes.

Token flow your backend
  │ lp_live_* partner key (never leaves your servers)
  ▼
ledra pay api — mints the scoped token
  │ embed token (15-min JWT, tenant-pinned)
  ▼
your browser app — components hold it in memory
  │ component reads + allowlisted writes
  ▼
evidence chain — every write receipted with the token's jti
Token scope · minted server-side
POST /v1/tenants/ten_8fk2/embed/token
{
  "components": ["payslip-viewer", "leave-request"],
  "employee_id": "emp_721",
  "origin": "https://app.yourdomain.com"
}

→ 201 { "token": "…", "expires_in": 900 }
Component allowlist — enforcedA payslip-viewer token cannot approve a pay run. Writes outside the token's components are refused server-side.
Employee pinningSelf-service tokens see one employee: other :employeeId routes 404, tenant-level writes are denied.
Origin bindingA token minted for your origin is rejected from any other — exfiltration doesn't travel. Required for direct CORS embedding.
Component catalogue

33 components across the payroll lifecycle.

ledrapay-* tags · lp-* aliases · ≈1.1 MB raw · ≈400 KB gzipped (fonts embedded), ESM

Onboarding & peoplehire, declare, pay details

ledrapay-employee-onboardingledrapay-employee-detailledrapay-employees-listledrapay-tax-declarationledrapay-bank-detailsledrapay-super-formledrapay-payroll-readiness

Payrollthe run lifecycle, end to end

ledrapay-pay-runs-listledrapay-pay-run-detailledrapay-pay-run-entryledrapay-payroll-calendarledrapay-payslip-viewerledrapay-pay-item-libraryledrapay-payrun-exceptionsledrapay-payments

Leaverequest, approve, manage

ledrapay-leave-requestledrapay-leave-approvalsledrapay-leave-management

Organisationsetup, structure, awards

ledrapay-org-setupledrapay-cost-centresledrapay-requirementsledrapay-award-configledrapay-payroll-checklist

Governance & reportingprove it, file it, watch it

ledrapay-governance-trailledrapay-stp-submissionledrapay-dashboardledrapay-reports-dashboardledrapay-super-overview

Dashboards & insightstiles and charts you compose

ledrapay-kpi-tileledrapay-chartledrapay-portfolio-dashboardledrapay-client-listledrapay-pipeline-board

The dashboard and reports components now render charts; ledrapay-chart (bar · histogram · line · donut) and ledrapay-kpi-tile are standalone primitives you compose from your own data. Every component renders sample data with zero credentials and goes live with an embed token. Attributes, events and theming variables for each: the playground. The payslip in the hero is one of them, running on this page right now.

Ready to go past sample data?

Sandbox keys come with real engine-computed tenants and integration support from the team that built the packs.

Get sandbox keys →