Workday provides the ability to enable employees to access their external tax documents directly from the Workday UI. Workday invokes the external payroll-vendor REST APIs in real-time to retrieve those documents, allowing employees to view and download them without the files ever being stored in Workday.
When a Workday user navigates to Worker Profile → Pay → Tax Documents, Workday requests a list of documents from the external vendor. Selecting an individual document triggers a second call that streams the file back to Workday for display or download.
Setting up the Integration
IMPORTANT – Role requirements • You must be an Org Admin, Integrations Admin, or Integrations Admin – People in Deel. • You also need the appropriate security role(s) in Workday to create external payroll-vendor objects and key pairs.
✅ Step 1 – Connect the Workday app in Deel
(replaces former, shorter description)
Prerequisites
• Workday must appear under My apps in the Deel App Store. If it does not, contact your Deel administrator.
• You must be permitted to view or manage the relevant Workday integration.
• If more than one Workday entity is listed, know which connected entity you intend to configure.
Detailed steps
-
In the left sidebar, expand “Apps & Automation” and select “App Store”.
- If the Welcome to your Deel Apps & Integrations dialog appears, select I’ll do that later or close it. This does not change integration settings.
-
Under My apps, click the Workday app tile to expand its available entities.
-
Select Manage beside the Workday entity marked Connected. If multiple entities are shown, select the entity you intend to configure. If the intended entity is not yet connected, click Connect and complete the connection before continuing.
- Verify that the selected Workday entity shows Connected and that the Plugins tab is available.
Success criteria
• The selected Workday entity displays a Connected status, the Plugins tab is available, and the EOR – Payslip and tax document sync plugin appears under Configurations and Plugins.
Troubleshooting
• A welcome dialog blocks the App Store – close it or select I’ll do that later, then continue to My apps.
• App not visible – ensure Workday is configured for the current workspace and entity, confirm that you have permission, or ask your Deel admin to enable the Workday app.
• Workday does not open when selected – select the Workday tile to expand its entry, then select Manage beside the intended entity.
• No Manage or Connect button / greyed-out options – confirm your Deel role includes integration management.
✅ Step 2 – Enable the EOR – Payslip and Tax document sync plugin
- On the Workday integration page, remain on the Plugins tab.
- In Configurations and Plugins, locate the EOR section.
- Find EOR – Payslip and tax document sync and click Enable. Do not select Global payroll – Payslip and tax document sync in the Global Payroll section.
- A configuration drawer opens on the right. Confirm that its title is EOR – Payslip and tax document sync. Both Payslips syncing and Tax and documents syncing are initially set to OFF. Leave them OFF for now – you will return after Steps 3-7.
Tip – If you accidentally close the configuration drawer, you can reopen it any time by clicking Enable for the plugin.
IMPORTANT – If the configuration drawer states that Global Payroll employee data sync must be enabled first, complete that prerequisite setup before enabling payslip synchronization for Global Payroll employees.
✅ Step 3 – Create External Payroll Vendor in Workday
If External Payslip is already configured, edit the existing vendor instead of creating a new one and proceed to Step 6.
Otherwise, in Workday Create External Payroll Vendor: 1. Name the vendor (for example, Deel). 2. Select External Tax Documents as the Feature.
✅ Step 4 – Create External Payroll Vendor Mapping
Map the vendor you just created to each required Workday environment.
- Open the vendor.
- Choose Maintain Mapping and assign the correct environment (Sandbox, Implementation, Production, etc.).
✅ Step 5 – Create Public / Private Key Pairs
- In the vendor configuration, click OK and follow the prompt to generate key pairs.
- Name the key pair and select Do Not Allow Regeneration.
- Mark the key pair Active.
- Copy the Public Key – you will paste it into the Deel plugin configuration drawer (Step 8).
✅ Step 6 – Feature Configuration in Workday
- In the vendor record, open Feature Configuration.
- Add External Payslips (if not present).
- For the Attribute choose Retrieval Endpoint.
- Paste the URL that Deel displays in the plugin configuration drawer under Tax & Documents Retrieval URL (from Step 2).
✅ Step 7 – Maintain Pay-Group / Vendor Associations
Associate every relevant Workday Pay Group with the external payroll vendor you created.
✅ Step 8 – Return to Deel and final-enable syncing
- In Deel, expand Apps & Automation in the left sidebar, select App Store, select Workday under My apps, then select Manage beside the appropriate connected entity.
- On the Plugins tab, in the EOR section, click Enable for EOR – Payslip and tax document sync to reopen the configuration drawer.
- Paste the Public Key copied in Step 5.
- Toggle Tax and documents syncing to ON (and Payslips syncing if required).
- Click Enable / Save. The plugin status should change to Enabled.
Tax-Document Security Access
Workday administrators cannot view employees’ tax documents retrieved via this REST-API method. Only the individual employee (Employee Self Service user) can access their own documents while logged in.