Does the PayRun.IO API need an API key?

Does the PayRun.IO API need an API key?

Yes for the 17 operations checked: an anonymous request was refused, on 2026-09-15. Where the document said nothing about it, this replaces a silence with an observation.

ERR-2026-1713, ERR-2026-1722, ERR-2026-1757, ERR-2026-1807, ERR-2026-1817, ERR-2026-1898, ERR-2026-2011, ERR-2026-2030, ERR-2026-2031, ERR-2026-2086, ERR-2026-2089, ERR-2026-2129

Where is the PayRun.IO OpenAPI specification?

Not where the directory says. The URL published as this provider's own document did not answer on 2026-09-15 (1 entry). The directory's cached copy still answers, so the failure is silent: a reader gets a cache of unknown age and cannot tell.

ERR-2026-0614

Every record behind those answers

18 open records, observed 2026-09-10. Every claim below carries the command that disproves it. If one is wrong, it should be withdrawn — 121 have been across the whole registry.

credentials are required (observed) (17)

The document establishes no authentication requirement for this operation; an anonymous request is refused with 401. The requirement is now observed rather than unknown.

ERR-2026-1713Gets the employerHTTP 401checked 2026-09-15, 2 times
ERR-2026-1722Get links to all commentaries for the specified employeeHTTP 401checked 2026-09-15, 2 times
ERR-2026-1757Get employee from employerHTTP 401checked 2026-09-15, 2 times
ERR-2026-1807Gets the DPS messagesHTTP 401checked 2026-09-15, 2 times
ERR-2026-1817Gets the specified pay instruction from the employeeHTTP 401checked 2026-09-15, 2 times
ERR-2026-1898Get commentary from employeeHTTP 401checked 2026-09-15, 2 times
ERR-2026-2011Gets the journal Lines from the specified employeeHTTP 401checked 2026-09-15, 2 times
ERR-2026-2030Get CIS line type tagHTTP 401checked 2026-09-15, 2 times
ERR-2026-2031Get all CIS line type tagsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2086Get the auto enrolment assessmentsHTTP 401checked 2026-09-15, 2 times
ERR-2026-2089Get all tags from the CIS line typeHTTP 401checked 2026-09-15, 2 times
ERR-2026-2129Get CIS line types with tagHTTP 401checked 2026-09-15, 2 times
ERR-2026-2145Gets the DPS messageHTTP 401checked 2026-09-15, 2 times
ERR-2026-2176Get the CIS transactionHTTP 401checked 2026-09-15, 2 times
ERR-2026-2203Get CIS line types from employer.HTTP 401checked 2026-09-15, 2 times
ERR-2026-2226Get all CIS transactions for the employerHTTP 401checked 2026-09-15, 2 times
ERR-2026-2231Get the auto enrolment assessmentHTTP 401checked 2026-09-15, 2 times

Check it yourself:

curl -sS -o /dev/null -w '%{http_code}\n' https://api.test.payrun.io/Employer/errata-probe-not-a-real-identifier

the description document is gone (1)

The document APIs.guru names as this provider's own origin returns HTTP 404.

ERR-2026-0614https://api.test.payrun.io/swagger/jsonHTTP 404checked 2026-09-15, 2 times

Check it yourself:

curl -sS -o /dev/null -w '%{http_code}\n' https://api.test.payrun.io/swagger/json

Withdrawn (1)

Our own check stopped supporting these claims — including claims that were wrong the day they were written.

ERR-2026-17832026-09-15timeout: timeout on https://api.test.payrun.io/Employer/errata-probe-n

Also filed as: payrun.io. One page, because two sweeps named the same subject differently and the record that mattered was on the page nobody would open.

If a record here is wrong

Run its check. If the answer differs from what is written, say so here and it will be withdrawn — 121 already have been. A record nobody can contest is a record asking to be trusted, which is the opposite of the point.

What this page does not tell you

This is not a clean bill of health for anything not listed. The registry was built from a sample of two directories, and an operation absent from it was almost certainly never examined. Silence here means not looked at, not looked at and fine — which is the same mistake this registry exists to record in other people.

What this is

A record of defects in the public description of machine-callable operations: documents a directory claims are live and are not, hosts that no longer resolve, specifications that contradict the API they describe. It is not a ranking, not a review, and not a judgement about the service. No credential is ever sent to anything listed here.

The whole registry, machine-readable: errata.json. Index of subjects: index.html.

Built from registry errata-2026-09-10@b7cb54d3a847. If manifest.json shows a different one, this page is behind the records and should not be trusted over them.