tofu is an AI-powered applicant screening platform. tofu reviews every inbound application, enriches and ranks candidates against your tailored hiring criteria, and protects your hiring pipeline with applicant fraud detection and deepfake detection — so hiring teams spend their time on real, qualified candidates.
tofu's integration with Greenhouse Recruiting allows users to automatically sync jobs and applications into tofu, review AI-ranked and screened candidates, surface fraud and deepfake detection results as notes on the candidate's application in Greenhouse, and reject or advance applications in Greenhouse with one click from tofu.
Configure the tofu integration
Note: The integration should be authorized by a Greenhouse user who is a Site Admin (or a user who can manage ALL organization's API credentials). We recommend authorizing with a service account (available to Site Admins) so the connection is owned by your organization rather than an individual user. See Connect to Harvest v3 partner integrations in the Greenhouse Support Center for details on authorization methods.
Open your tofu connection link
The connection can be started in either of two ways:
- From the tofu app: navigate to the integrations step of onboarding (or Settings > Integrations), select Greenhouse, and click Connect.
- From a secure link: the tofu team sends you a secure, single-use connection link (hosted at connect.kombo.dev) via email or Slack. Open the link in your browser.
The connection flow looks the same whether you start from the tofu app or from a secure link.
Search for and select Greenhouse (V3), then review the summary of what tofu will access and select Continue.
Review requested permissions and log in to Greenhouse
Select Sign in with Greenhouse (V3). The connection flow launches Greenhouse's OAuth 2.0 authorization page, which lists the specific permissions tofu is requesting for your organization's data. Review the requested permissions, then log in to Greenhouse with your credentials.
Choose an authorization method and authorize
After logging in, Greenhouse asks how to authorize the integration. If you are a Site Admin, we recommend checking Authorize using a service account, which creates an organization-level service account that owns the connection. Actions taken by tofu (such as adding notes or rejecting applications) will appear in Greenhouse as performed by this account. Click Authorize to complete the connection.
Once authorized, you are returned to the confirmation screen and the integration begins syncing automatically. Your jobs and applications will start appearing in tofu shortly after — no source tags, webhooks, or API keys need to be configured.
Data tofu accesses in Greenhouse
tofu requests the following permissions:
| Greenhouse data | Access | How tofu uses it |
| Jobs and job posts | Read (list jobs, job posts) | Import your open roles into tofu |
| Departments and offices | Read (list) | Map roles to your organization's structure |
| Stages and interviews | Read (list application stages, job interview stages, interviews, job interviews, interviewers) | Import your interview pipeline structure and interview activity |
| Candidates and attachments | Read / Write (list and create candidates; list and create attachments) | Import candidates and resumes for screening; create candidates and attach documents when pushed from tofu |
| Applications | Read / Write (list, create, update, move, reject, hire) | Import inbound applications for screening; reflect the actions you take in tofu (advance, reject, hire) in Greenhouse |
| Notes | Write (create) | Add screening summaries and fraud / deepfake detection details to the candidate's application |
| Candidate tags | Read / Write (list and create candidate tags; list, create, and remove applied tags) | Apply and remove tofu screening tags (e.g. fraud flags) on candidates |
| Rejection reasons and rejection details | Read (list) | Let you select the appropriate rejection reason when rejecting from tofu |
| Email templates | Read (list) | Send your configured Greenhouse rejection email when a candidate is rejected from tofu |
| Sources | Read (list) | Attribute candidates to the correct source |
| Offers | Read (list) | Track hiring outcomes for synced applications |
| Pay input ranges | Read (list) | Reference role compensation ranges where configured |
| Users | Read (list) | Match tofu users to Greenhouse users and attribute actions correctly |
| Webhooks | Managed (list, create, update, destroy) | Automatically created and managed for you so data stays in sync in real time — no manual webhook setup required |
Fields tofu writes to: application notes (screening summaries and fraud / deepfake detection details), candidate tags, application status (create / move stage / reject / hire), candidates and attachments (when pushed from tofu), and rejection reason + rejection email when you reject a candidate from tofu. tofu does not modify any other candidate or job data.
Use the tofu integration
Review screened and ranked candidates
After the integration is connected, tofu automatically imports your open jobs and inbound applications. As new candidates apply in Greenhouse, tofu screens each application against your hiring criteria and ranks candidates for every role.
Review fraud and deepfake detection results
tofu analyzes every application for signs of applicant fraud as well as deepfakes. When tofu flags an application, the detection details are added to the candidate's application in Greenhouse (as notes and candidate tags), and the candidate is clearly flagged in tofu for your review.
Reject or advance candidates from tofu
You can act on candidates directly from tofu, and the action is reflected in Greenhouse immediately:
- Reject: reject an application in one click. tofu applies your selected Greenhouse rejection reason and can send your configured Greenhouse rejection email template.
- Advance: move a candidate to the next stage of your Greenhouse interview pipeline.
Actions appear in Greenhouse as performed by the account used to authorize the integration (the service account, if selected during setup).
Additional resources
For additional information or troubleshooting not covered here, reach out to support@hiretofu.com.
FAQ
Who should complete the connection? A Greenhouse Site Admin (or a user who can manage all of your organization's API credentials). Site Admin authorization is required for the integration to list data such as jobs and candidates.
How do I disconnect or review the integration? In Greenhouse, click the Configure icon > Dev Center > Connected integrations. From there you can review tofu's authorized permissions, see which account connected it, or disconnect to revoke access.
What if tofu's permissions change? If tofu requires additional permissions in the future, you'll be asked to re-authorize through a new connection link. The existing connection keeps working until you do.
I'm an existing tofu customer — do I need to do anything? Yes. Greenhouse is deprecating the legacy Harvest API (v1/v2) on August 31, 2026. All customers must re-authorize using the OAuth flow above. The tofu team will send you a secure connection link — completing it takes about one minute, and your existing data and setup in tofu are unaffected.