Load Workday strategic sourcing data to DuckDB
Build a Workday strategic sourcing to DuckDB pipeline with your coding agent. One prompt scaffolds it with the dltHub AI harness, plus the Workday strategic sourcing API base URL, auth, endpoints, and incremental loading.
Workday Strategic Sourcing is a procurement platform that provides public REST APIs for managing projects, contracts, reports, and other sourcing data. Everything needed to build a working Workday strategic sourcing → DuckDB pipeline is on this page: the API's base URL, authentication, endpoints, pagination and incremental field — plus a prompt that hands the whole job to your coding agent.
Build your Workday strategic sourcing to DuckDB pipeline
Paste this prompt into Claude, Codex, or Cursor. The agent does the rest.
PromptRunuvx dlthub-init@latestto build a pipeline from Workday strategic sourcing to DuckDB and run it on dltHub
That scaffolds a dltHub workspace and installs the dltHub AI harness — the project rules, the secrets-management skill, and the dlt MCP server your agent needs to work safely. From there it reads the Workday strategic sourcing API, proposes the endpoints to load, then writes, runs and validates the pipeline while you review rather than type. Credentials are inspected through MCP tools, so your agent never reads secrets.toml itself. How the LLM-native workflow works →
Prefer to write it yourself? Every fact the agent uses is below.
Workday strategic sourcing API at a glance
| Base URL | https://api.[region].workdayspend.com/services/ (where region is us, eu, or ca) |
| Example endpoint | GET services/projects/v1/projects |
| Records found at | data |
| Authentication | all requests require three custom headers: X-Api-Key, X-User-Token, and X-User-Email — sent in the request header |
| Also required | X-Api-Key, X-User-Token, X-User-Email |
| Pagination | Page-number page size via page[size] |
| Record id | id |
| API reference | https://apidocs.workdayspend.com/ |
These values come from the Workday strategic sourcing API reference — the authoritative source if anything here looks out of date.
How do I authenticate with the Workday strategic sourcing API?
Authentication requires three custom HTTP headers: 'X-Api-Key' (company-wide key), 'X-User-Token' (user-specific token), and 'X-User-Email' (user email address). All API requests must be made over HTTPS.
1. Get your credentials
To obtain API credentials for Workday Strategic Sourcing, navigate to your Profile page within the Workday Strategic Sourcing application. From the menu that displays when you click your name, locate the 'Integrations' or 'API Tokens' section. Click to access the API tokens page, where you can generate new 'Company' and 'User' tokens. The system will provide these tokens once; ensure you copy and save them securely immediately, as they will not be visible again. You will also need the email address associated with your user profile.
2. Add them to .dlt/secrets.toml
[sources.workday_strategic_sourcing_source] api_key = "your_company_api_key_here" user_token = "your_user_specific_api_token_here" user_email = "your_email@example.com"
dlt reads this file automatically at runtime. With the harness, the setup-secrets skill prompts you for the values and never handles the raw credential in chat. For production, see setting up credentials with dlt.
What Workday strategic sourcing data can I load into DuckDB?
These are the Workday strategic sourcing endpoints dlt can load into DuckDB:
| Resource | Endpoint | Method | Data selector | Description |
|---|---|---|---|---|
| events | services/events/v1/events | GET | data | List events |
| projects | services/projects/v1/projects | GET | data | List projects |
| contracts | services/contracts/v1/contracts | GET | data | List contracts |
| spend_categories | services/spend_categories/v1/spend_categories | GET | data | List spend categories |
| awards | services/awards/v1/awards | GET | data | List awards |
How do I load only new Workday strategic sourcing records?
The Workday strategic sourcing API reference does not document a timestamp or sequence field for these endpoints, so there is nothing to advertise here as verified. Pick a field from the endpoints table above that increases with every write, then set it as the cursor_path.
{"name": "projects", "endpoint": { "path": "services/projects/v1/projects", # Replace with a field that increases on every write. "incremental": {"cursor_path": "REPLACE_ME", "initial_value": "2024-01-01T00:00:00Z"}, }}
On the first run dlt loads everything from initial_value; on every run after that it requests only what changed and appends with write_disposition="merge" if you set a primary key. See incremental loading.
What does the generated Workday strategic sourcing pipeline look like?
A standard dlt REST API pipeline — the same code you would write by hand, loading services/projects/v1/projects and services/events/v1/events from the Workday strategic sourcing API into DuckDB:
import dlt from dlt.sources.rest_api import RESTAPIConfig, rest_api_resources @dlt.source def workday_strategic_sourcing_source(api_key=dlt.secrets.value): config: RESTAPIConfig = { "client": { "base_url": "https://api.[region].workdayspend.com/services/ (where region is us, eu, or ca)", "auth": {"type": "api_key", "api_key": api_key, "name": "X-Api-Key, X-User-Token, X-User-Email", "location": "header"}, }, "resources": [ {"name": "projects", "endpoint": {"path": "services/projects/v1/projects", "data_selector": "data"}}, {"name": "events", "endpoint": {"path": "services/events/v1/events", "data_selector": "data"}} ], } yield from rest_api_resources(config) def load_workday_strategic_sourcing_to_duckdb() -> None: pipeline = dlt.pipeline( pipeline_name="workday_strategic_sourcing_pipeline", destination="duckdb", dataset_name="workday_strategic_sourcing_data", ) load_info = pipeline.run(workday_strategic_sourcing_source()) print(load_info) if __name__ == "__main__": load_workday_strategic_sourcing_to_duckdb()
Run it with python workday_strategic_sourcing_pipeline.py. The agent iterates on this until it loads cleanly — you review and approve, rather than write it from scratch.
How do I query Workday strategic sourcing data in DuckDB?
dlt creates one table per resource. Query the loaded data with Python or SQL — or ask your agent to, through the MCP server's execute_sql_query tool.
Python (pandas DataFrame):
import dlt data = dlt.pipeline("workday_strategic_sourcing_pipeline").dataset() df = data.events.df() print(df.head())
SQL:
SELECT * FROM workday_strategic_sourcing_data.events LIMIT 10;
See querying your data with dataset and exploring it in marimo notebooks.
How do I deploy the Workday strategic sourcing to DuckDB pipeline in production?
The pipeline runs locally, which is ideal for prototyping and one-off analysis. When you need it on a schedule, monitored on every load, and shared with your team, deploy the same dlt code on the dltHub platform — no infrastructure to maintain. The prompt above already ends with "run it on dltHub", so your agent can take it there directly.
- Deploy & schedule — run the pipeline as a managed job with automatic retries.
- Monitor — observable job queues, alerting, and load metrics for every run.
- Transform — promote raw Workday strategic sourcing loads into governed, documented models.
- Visualize & share — explore data in notebooks and publish live dashboards instead of static screenshots.
What other destinations can I load Workday strategic sourcing data to?
dlt loads into any of these — only the destination argument changes:
| Destination | Example value |
|---|---|
| PostgreSQL | "postgres" |
| BigQuery | "bigquery" |
| Snowflake | "snowflake" |
| Redshift | "redshift" |
| Databricks | "databricks" |
| Filesystem (S3, GCS, Azure) | "filesystem" |
Set dlt.pipeline(destination="snowflake") and add credentials in .dlt/secrets.toml. On the dltHub platform the same pipeline runs against a managed Iceberg lakehouse. See the full destinations list.
Next steps
Was this page helpful?
Community Hub
Need more dlt context for Workday strategic sourcing to DuckDB?
Request dlt skills, commands, AGENT.md files, and AI-native context.