Shiftly Partner API
Read a business's rostering, time, leave and staff records in Shiftly, and change its rostering, time, leave and projects, with the permissions the business gave your app.
What your app can do
A connected app works with one business at a time, through the eyes of the person who connected it. Everything is scoped to that business, and your app can do no more than that person can.
| Area | Read | Add or change |
|---|---|---|
| Rosters and shifts | Rosters, shifts, availability, open-shift requests, shift swaps and who can cover a shift | Shifts that have not started. A change to a published shift makes it a draft again |
| Timesheets | Worked time, who's on now, totals and labour costs, with pay once the pay permission is held | Pending timesheets, until a manager approves them |
| Leave | Requests, balances, blackout periods and the leave types the business offers | Pending leave requests, until a manager decides them |
| Staff | Employees and their employments | Nothing |
| Business | Business details, locations, positions, public holidays, projects and awards | Projects |
What v1 does not do
Some decisions stay with the people who run the business. Your app can prepare work for them, and it can see what they decided, but it cannot decide for them.
- Publishing a roster. A shift your app creates or changes is a draft until a manager publishes it in Shiftly.
- Approving a timesheet. A timesheet your app creates is pending until a manager approves it.
- Deciding leave. A request your app submits is pending until a manager approves or declines it.
- Changing pay. Rates and awards are read-only.
- Adding, removing or changing staff. People and their details are managed in Shiftly, not through the API.
- Sending notifications. Shiftly does not post events to partner apps yet, so read what you need when you need it.
- Reading tax, bank, super or identity details. These are never available to a partner app.
How access is granted
A business owner, or a manager who can manage team access, connects your app from inside your product. Shiftly shows them a consent screen that names your app, lists what it will be able to view and change, and lets them allow or cancel. If they allow, your app receives a credential for that business, or one for each business they ticked if you asked for several.
The flow is OAuth 2.0 authorization code with PKCE. Permissions are OAuth scopes. There is one connection per business per app. To connect several businesses in one consent, add business_selection=multiple to the authorize request; each ticked business still gets its own connection.
Call the API from your server, never from a web page. The client secret and the access credentials must not reach a browser, so Shiftly refuses any request that carries an Origin header, which browsers add, with 403 origin_not_allowed. The two discovery documents under /.well-known are the exception: any page can read them.
Where to start
- Quickstart: a first request against the sandbox in a few minutes.
- Connect a business: the consent flow in full.
- API reference: every resource, field and operation.
Limited release
The Partner API is in limited release. Each app has a connection limit while it is new, and a business that tries to connect once the limit is reached is told the app can't take new connections yet.
