# API and MCP resume automation

> Automate resumes, job tracking, job searches and applications in Hiresweep with the REST API or an MCP-connected AI assistant.

Hiresweep can be driven from code or from an AI assistant. The REST API gives scripts and integrations access to your account with an API key. The MCP server lets an assistant such as Claude, ChatGPT, Cursor or Codex work with your resumes, your job tracker, Job Discovery and applications.

## Automation options

Use the API for scripts, services and integrations you write yourself. Use MCP when you want an AI assistant to do the work in conversation.

Key docs:

- [Using the API](https://docs.hiresweep.com/guides/using-the-api)
- [Using the Patch API](https://docs.hiresweep.com/guides/using-the-patch-api)
- [Using the MCP server](https://docs.hiresweep.com/guides/using-the-mcp-server)
- [Managing connected assistants](https://docs.hiresweep.com/guides/managing-connected-assistants)
- [JSON resume schema](https://docs.hiresweep.com/guides/json-resume-schema)
- The [API reference](https://docs.hiresweep.com/api-reference/introduction)

## What you can automate

**Resumes**

- Create a resume from structured data, or import a full resume JSON document.
- Read resume data for review or transformation.
- Patch targeted fields without replacing the whole resume.
- Duplicate, tag, lock, share or delete resumes.

**Job search**

- Add jobs to your tracker from a link, and change their status and notes.
- Review a posting, score a resume against it, tailor a copy and write a cover letter.
- Draft and start Job Discovery searches, and read the jobs they find.
- Start an application and submit it once the form is filled.

The Patch API is the safest starting point for targeted resume changes because each request states exactly what it changes.

## Authentication and permissions

- **API keys** authenticate the REST API, and also work for MCP in clients that can't sign in. A key isn't scoped: it has the full access of your account, including deleting resumes and sending applications.
- **OAuth** lets an MCP assistant sign in to your account. You choose its permissions on an approval page, for example reading resumes but not deleting them, or tracking jobs but not applying. You can disconnect it at any time.

Prefer OAuth for assistants, and keep API keys for code you control.

<Info>
  Calls that use Hiresweep AI, start job searches or send applications use your plan's allowances, the same as in the
  app. See [Plans and usage](https://docs.hiresweep.com/guides/plans-and-usage).
</Info>

## When not to use automation

For a one-off edit to one resume, the builder is usually faster, and it lets you see the result as you go. Test any automation that changes resumes on a copy first, and be careful with anything that applies to jobs: a sent application can't be recalled.

## Next action

For scripts and integrations, create an API key with [Using the API](https://docs.hiresweep.com/guides/using-the-api), then use [Using the Patch API](https://docs.hiresweep.com/guides/using-the-patch-api) for targeted edits. For assistants, start with [Using the MCP server](https://docs.hiresweep.com/guides/using-the-mcp-server).
