> ## Documentation Index
> Fetch the complete documentation index at: https://docs.taptalent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List candidates

> Retrieve a paginated list of candidates in your company with advanced
filtering options.

**Pagination is 0-indexed on this endpoint:** the first page is
`pageNumber=0` (unlike most other endpoints, which start at page 1).
Check `pagination.hasNextPage` to determine whether more data is
available.

Filtering notes:

- For array filters (`jobIds`, `stageIds`, `skills`, `groupIds`),
  use comma-separated values.
- Skill searches are case-insensitive; other text filters may be
  case-sensitive.
- Use `searchTerm` for broad text searches across multiple fields.




## OpenAPI

````yaml /api-reference/openapi.yaml get /candidates/list
openapi: 3.1.0
info:
  title: TapTalent Partner API
  version: 1.0.0
  summary: Partner API for jobs, candidates, pipelines, custom fields, and webhooks.
  description: >
    The TapTalent Partner API lets partner systems manage jobs, candidates,

    job-candidate relationships, hiring pipelines, and custom fields, and

    receive real-time event notifications via webhooks. All communication is

    JSON over HTTPS.


    ## Authentication


    Every request requires an API key sent as an HTTP bearer token:


    ```

    Authorization: Bearer sk_live_AbCdEfGhIjKlMnOpQrStUv

    ```


    Keys are prefixed `sk_live_` (production) or `sk_test_` (sandbox) followed

    by 22 base62 characters, are scoped to a company, and are generated from

    the TapTalent dashboard (Account Settings → Developers → API Key

    Management). Key management is dashboard-only and not available via this

    API.


    ## Response envelopes


    The API uses three envelope styles, by resource family:


    | Family | Success envelope |

    |---|---|

    | Jobs | Bare object (e.g. `{ "jobs": [...], "totalJobs": 45 }` or the job
    object itself) |

    | Candidates, Job Candidates, Pipelines, Custom Fields | `{ "status":
    "success", "data": ... }` |

    | Bulk resume upload and batch retrieval | `{ "success": true, "data": ...
    }` |


    Each operation in this specification models its family's actual envelope;

    no unified envelope is imposed.


    ## Pagination


    Pagination conventions vary by endpoint and are modeled as documented:


    | Endpoint | Page parameter | First page | Default page size | Page size
    rule |

    |---|---|---|---|---|

    | `GET /jobs` | `pageNumber` | 1 | 10 | one of 10, 20, 40, 80, 100 |

    | `GET /candidates/list` | `pageNumber` | **0** | 10 | one of 10, 20, 40,
    80, 100 |

    | `GET /candidates/batch/{batchId}` | `pageNumber` | 1 | 10 | one of 10, 20,
    40, 80, 100 |

    | `GET /job-candidates/job/{jobId}/candidates` | `page` | 1 | 20 | one of
    10, 20, 40, 80, 100 |

    | `GET /job-candidates/stage/{stageId}/candidates` | `page` | 1 | 20 | any
    value from 1 to 100 |


    ## Errors


    Most errors use the canonical envelope:


    ```json

    {
      "error": {
        "code": "ERROR_CODE",
        "type": "error_type",
        "message": "Human-readable error message",
        "details": { "field": "Specific validation error message" }
      }
    }

    ```


    Authentication failures use flat shapes instead (`{"message": ...}`,

    `{"code": ..., "message": ...}` or `{"message": ..., "isApiKeyExists":

    false}`); see the shared 401 response. Rate limits are applied at the

    company level; numeric limits and the 429 response body are not yet

    published.


    ## Webhooks


    Event notifications are delivered as HTTP POST requests to a single

    company-level HTTPS endpoint configured in the dashboard. Deliveries carry

    the headers `X-Webhook-Event`, `X-Webhook-Timestamp`, and `X-Webhook-Key`

    (verify by plain equality against the key generated in the dashboard;

    HMAC signatures are not yet available). Endpoints must respond with a 2xx

    status within 5 seconds; failed deliveries are retried at 200 ms, 400 ms,

    and 800 ms before being marked failed. See the `webhooks` section of this

    document for every event payload.


    ## Conventions used in this specification


    - `x-inferred: true` marks schemas or responses whose shape is inferred
      from related endpoints because the source documentation does not include
      an example; verify against the sandbox before relying on exact field
      names.
    - `x-known-quirk` marks fields whose wire format deviates from the API's
      prevailing conventions (for example an epoch timestamp where other
      endpoints return ISO 8601 strings).
    - Where the published documentation shows placeholder string identifiers
      (for example `"pipelineId_1"` or `"companyId_1"`), this specification
      models the underlying integer identifier types used by the API and notes
      the resolution on the affected field.
  contact:
    name: TapTalent Support
    email: support@taptalent.ai
    url: https://docs.taptalent.io
  license:
    name: Proprietary
    url: https://taptalent.ai
servers:
  - url: https://partner-api.taptalent.io/v1/partner
    description: Production (use `sk_live_` keys)
  - url: https://sandbox.partner-api.taptalent.io/v1/partner
    description: Sandbox / staging (use `sk_test_` keys)
security:
  - bearerAuth: []
tags:
  - name: Jobs
    description: Create, read, update, and list jobs.
  - name: Candidates
    description: >-
      Create and retrieve candidates, upload resumes in bulk, and fetch
      candidates by batch or id list.
  - name: Job Candidates
    description: >-
      Manage the relationship between candidates and jobs, including stage
      placement and per-job resume ingestion.
  - name: Pipelines
    description: Manage hiring pipelines and their stages.
  - name: Custom Fields
    description: Define custom field templates for candidates and jobs.
  - name: Custom Field Values
    description: Read and write custom field values attached to candidates and jobs.
  - name: Webhooks
    description: >-
      Event notifications delivered to your configured webhook endpoint. See the
      top-level `webhooks` section for payloads.
paths:
  /candidates/list:
    get:
      tags:
        - Candidates
      summary: List candidates
      description: |
        Retrieve a paginated list of candidates in your company with advanced
        filtering options.

        **Pagination is 0-indexed on this endpoint:** the first page is
        `pageNumber=0` (unlike most other endpoints, which start at page 1).
        Check `pagination.hasNextPage` to determine whether more data is
        available.

        Filtering notes:

        - For array filters (`jobIds`, `stageIds`, `skills`, `groupIds`),
          use comma-separated values.
        - Skill searches are case-insensitive; other text filters may be
          case-sensitive.
        - Use `searchTerm` for broad text searches across multiple fields.
      operationId: listCandidates
      parameters:
        - name: jobIds
          in: query
          required: false
          description: Comma-separated list of job IDs (integers) to filter candidates by.
          schema:
            type: string
          example: 12345,12346
        - name: stageIds
          in: query
          required: false
          description: Comma-separated list of stage IDs to filter candidates by.
          schema:
            type: string
          example: 790,791
        - name: searchTerm
          in: query
          required: false
          description: Search term to filter candidates by name, email, or other fields.
          schema:
            type: string
          example: engineer
        - name: currentJobTitle
          in: query
          required: false
          description: Filter by candidate's current job title.
          schema:
            type: string
          example: Software Engineer
        - name: currentCompany
          in: query
          required: false
          description: Filter by candidate's current company.
          schema:
            type: string
          example: Acme Corp
        - name: candidatePhone
          in: query
          required: false
          description: Filter by candidate's phone number.
          schema:
            type: string
          example: '+14155550123'
        - name: candidateEmail
          in: query
          required: false
          description: Filter by candidate's email address.
          schema:
            type: string
          example: jane.doe@example.com
        - name: skills
          in: query
          required: false
          description: Comma-separated list of skills to filter by (case-insensitive).
          schema:
            type: string
          example: python,react
        - name: groupIds
          in: query
          required: false
          description: Comma-separated list of group IDs to filter by.
          schema:
            type: string
          example: 10,11
        - name: includeOnlyRejecetedCandidates
          in: query
          required: false
          description: |
            Set to "true" to include only rejected candidates. Note: the
            misspelling of "Rejeceted" in this parameter name is intentional
            and required — it is the actual wire format accepted by the API.
            Passed as a string, not a boolean.
          schema:
            type: string
            enum:
              - 'true'
              - 'false'
            default: 'false'
        - name: source
          in: query
          required: false
          description: Filter by candidate source.
          schema:
            type: string
          example: linkedin
        - name: perPage
          in: query
          required: false
          description: 'Items per page. Must be one of: 10, 20, 40, 80, 100.'
          schema:
            type: integer
            enum:
              - 10
              - 20
              - 40
              - 80
              - 100
            default: 10
        - name: pageNumber
          in: query
          required: false
          description: |
            Page number. **0-indexed** — the first page is `pageNumber=0`
            (unlike most other paginated endpoints, which are 1-indexed).
          schema:
            type: integer
            default: 0
      responses:
        '200':
          description: Paginated list of candidates matching the filters.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListCandidatesResponse'
              examples:
                candidateList:
                  summary: First page of filtered candidates
                  value:
                    status: success
                    data:
                      candidates:
                        - id: 12345
                          firstName: John
                          lastName: Doe
                          email: john.doe@example.com
                          phone: '+1234567890'
                          currentJobTitle: Software Engineer
                          currentCompany: Tech Corp
                          city: San Francisco
                          country: United States
                          skills:
                            - JavaScript
                            - React
                            - Node.js
                          resume: https://storage.example.com/resumes/john-doe.pdf
                          majors:
                            - Computer Science
                          summary: Experienced software engineer...
                          languages:
                            - English
                          educations:
                            - degree: Bachelor's
                              field: Computer Science
                              institution: University
                          workExperiences:
                            - title: Software Engineer
                              company: Tech Corp
                              duration: 2 years
                          projectExperiences: []
                          certifications: []
                          githubUrl: https://github.com/johndoe
                          linkedin: https://linkedin.com/in/johndoe
                      pagination:
                        page: 0
                        perPage: 20
                        totalCandidates: 150
                        totalPages: 8
                        hasNextPage: true
        '400':
          description: |
            Validation error. HTTP status inferred from the error category;
            the source documentation specifies the body but not the status
            code.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
              examples:
                invalidPerPage:
                  summary: Invalid perPage value
                  value:
                    error:
                      code: INVALID_PER_PAGE
                      type: validation_error
                      message: 'perPage must be one of: 10, 20, 40, 80, 100'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '500':
          $ref: '#/components/responses/InternalError'
components:
  schemas:
    ListCandidatesResponse:
      type: object
      description: Success envelope for the list-candidates endpoint.
      required:
        - status
        - data
      properties:
        status:
          type: string
          description: Response status ("success").
          enum:
            - success
        data:
          type: object
          required:
            - candidates
            - pagination
          properties:
            candidates:
              type: array
              description: Array of candidate objects.
              items:
                $ref: '#/components/schemas/CandidateSummary'
            pagination:
              $ref: '#/components/schemas/CandidateListPagination'
    ApiError:
      type: object
      description: Canonical error envelope used by most non-authentication errors.
      required:
        - error
      properties:
        error:
          $ref: '#/components/schemas/ApiErrorBody'
    CandidateSummary:
      type: object
      description: |
        Candidate object as returned by the list and bulk-fetch endpoints.
        Uses compact education and work experience shapes (`duration`-based
        work experience) rather than the detailed shapes returned by the
        create and get-details endpoints.
      properties:
        id:
          type: integer
          description: Unique candidate identifier.
        firstName:
          type: string
          description: Candidate's first name.
        lastName:
          type: string
          description: Candidate's last name.
        email:
          type: string
          description: Candidate's email address.
        phone:
          type: string
          description: Candidate's phone number.
        currentJobTitle:
          type: string
          description: Current job title.
        currentCompany:
          type: string
          description: Current company name.
        city:
          type: string
          description: City location.
        country:
          type: string
          description: Country.
        skills:
          description: |
            Candidate skills. Documented and observed responses return an
            array of skill strings; the plain-string variant is inferred from
            the input-side CSV coercion and is not verified against
            production behavior.
          x-inferred: true
          oneOf:
            - type: array
              items:
                type: string
            - type: string
        resume:
          type: string
          description: URL to the stored resume file.
        majors:
          type: array
          description: |
            Array of majors/fields of study. Note: submitted as a
            comma-separated string on input, returned as an array of strings.
          items:
            type: string
        summary:
          type: string
          description: Professional summary.
        languages:
          type: array
          description: Array of languages.
          items:
            type: string
        educations:
          type: array
          description: Array of compact education objects.
          items:
            $ref: '#/components/schemas/CandidateEducationSummary'
        workExperiences:
          type: array
          description: Array of compact work experience objects.
          items:
            $ref: '#/components/schemas/CandidateWorkExperienceSummary'
        projectExperiences:
          type: array
          description: |
            Array of project experience objects. Item shape is not shown in
            the list examples (arrays appear empty); modeled after the detail
            endpoint shape.
          items:
            $ref: '#/components/schemas/CandidateProjectExperience'
        certifications:
          type: array
          description: |
            Array of certification objects. Item shape is not shown in the
            list examples (arrays appear empty); modeled after the detail
            endpoint shape.
          items:
            $ref: '#/components/schemas/CandidateCertification'
        githubUrl:
          type: string
          description: GitHub profile URL.
        linkedin:
          type: string
          description: LinkedIn profile URL.
    CandidateListPagination:
      type: object
      description: Pagination metadata for the list-candidates endpoint.
      properties:
        page:
          type: integer
          description: Current page number (0-indexed).
        perPage:
          type: integer
          description: Number of items per page.
        totalCandidates:
          type: integer
          description: Total number of candidates matching the filters.
        totalPages:
          type: integer
          description: Total number of pages.
        hasNextPage:
          type: boolean
          description: Indicates if there are more pages.
    ApiErrorBody:
      type: object
      description: Canonical error object carried under the `error` key.
      required:
        - code
        - type
        - message
      properties:
        code:
          type: string
          description: Machine-readable error code, e.g. `INVALID_REQUEST`.
          examples:
            - INVALID_REQUEST
        type:
          type: string
          description: Error category.
          enum:
            - validation_error
            - internal_error
            - not_found
            - authorization_error
            - resource_error
            - payment_error
            - subscription_error
        message:
          type: string
          description: Human-readable error message.
        details:
          type: object
          description: Optional per-field validation messages or structured error context.
          additionalProperties: true
    AuthMessageError:
      type: object
      description: >-
        Flat authentication error shape (does not use the canonical `error`
        envelope).
      required:
        - message
      properties:
        message:
          type: string
          examples:
            - Invalid API key
    AuthCodeMessageError:
      type: object
      description: >-
        Flat authentication error shape returned when the account subscription
        is inactive.
      required:
        - code
        - message
      properties:
        code:
          type: string
          examples:
            - ACCOUNT_INACTIVE
        message:
          type: string
          examples:
            - >-
              Your subscription is inactive. Please renew your plan to continue
              using this feature.
    AuthApiKeyError:
      type: object
      description: >-
        Flat authentication error shape returned when the API key does not
        exist.
      required:
        - message
        - isApiKeyExists
      properties:
        message:
          type: string
          examples:
            - API key not found
        isApiKeyExists:
          type: boolean
    CandidateEducationSummary:
      type: object
      description: Compact education object as returned in candidate list responses.
      properties:
        degree:
          type: string
          description: Degree name.
        field:
          type: string
          description: Field of study.
        institution:
          type: string
          description: Institution name.
    CandidateWorkExperienceSummary:
      type: object
      description: Compact work experience object as returned in candidate list responses.
      properties:
        title:
          type: string
          description: Job title.
        company:
          type: string
          description: Company name.
        duration:
          type: string
          description: Duration of the role (e.g. "2 years").
    CandidateProjectExperience:
      type: object
      description: |
        Project experience object as returned in candidate responses. Differs
        from the request-side `CandidateProjectExperienceInput` shape.
      properties:
        name:
          type: string
          description: Project name.
        description:
          type: string
          description: Project description.
        technologies:
          type: array
          description: Technologies used.
          items:
            type: string
    CandidateCertification:
      type: object
      description: |
        Certification object as returned in candidate responses. Differs from
        the request-side `CandidateCertificationInput` shape.
      properties:
        name:
          type: string
          description: Certification name.
        issuer:
          type: string
          description: Certification issuer.
        issueDate:
          type: string
          format: date
          description: Issue date.
        expiryDate:
          type: string
          format: date
          description: Expiry date.
  responses:
    Unauthorized:
      description: |
        Authentication failed. Note that authentication errors use flat body
        shapes rather than the canonical `error` envelope.
      content:
        application/json:
          schema:
            anyOf:
              - $ref: '#/components/schemas/AuthMessageError'
              - $ref: '#/components/schemas/AuthCodeMessageError'
              - $ref: '#/components/schemas/AuthApiKeyError'
          examples:
            invalidApiKey:
              summary: Invalid API key
              value:
                message: Invalid API key
            accountInactive:
              summary: Subscription inactive
              value:
                code: ACCOUNT_INACTIVE
                message: >-
                  Your subscription is inactive. Please renew your plan to
                  continue using this feature.
            apiKeyNotFound:
              summary: API key not found
              value:
                message: API key not found
                isApiKeyExists: false
    TooManyRequests:
      x-inferred: true
      description: |
        Rate limit exceeded. Rate limits are applied at the company level; the
        response body below is inferred because the current documentation
        mentions handling 429 responses but does not publish a body. Retry
        with exponential backoff.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          examples:
            rateLimited:
              summary: Rate limit exceeded (inferred example)
              value:
                error:
                  code: RATE_LIMIT_EXCEEDED
                  type: validation_error
                  message: Too many requests. Please retry with exponential backoff.
    InternalError:
      description: Unexpected server error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
          examples:
            internalError:
              summary: Internal error
              value:
                error:
                  code: INTERNAL_ERROR
                  type: internal_error
                  message: Something went wrong.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API key
      description: |
        Company-scoped API key. Production keys are prefixed `sk_live_`,
        sandbox keys `sk_test_`, each followed by 22 base62 characters
        (pattern `^sk_(live|test)_[0-9A-Za-z]{22}$`). Generate keys in the
        TapTalent dashboard under Account Settings → Developers → API Key
        Management; a key is shown once at generation and old keys are
        invalidated immediately on regeneration.

````