Skip to content
ShiftlyDevelopers
Documentation menu

Shiftly Partner API

Read a business's rostering, time, leave and staff records in Shiftly, and change its rostering, time, leave and projects, with the permissions the business gave your app.

What your app can do

A connected app works with one business at a time, through the eyes of the person who connected it. Everything is scoped to that business, and your app can do no more than that person can.

AreaReadAdd or change
Rosters and shiftsRosters, shifts, availability, open-shift requests, shift swaps and who can cover a shiftShifts that have not started. A change to a published shift makes it a draft again
TimesheetsWorked time, who's on now, totals and labour costs, with pay once the pay permission is heldPending timesheets, until a manager approves them
LeaveRequests, balances, blackout periods and the leave types the business offersPending leave requests, until a manager decides them
StaffEmployees and their employmentsNothing
BusinessBusiness details, locations, positions, public holidays, projects and awardsProjects

What v1 does not do

Some decisions stay with the people who run the business. Your app can prepare work for them, and it can see what they decided, but it cannot decide for them.

  • Publishing a roster. A shift your app creates or changes is a draft until a manager publishes it in Shiftly.
  • Approving a timesheet. A timesheet your app creates is pending until a manager approves it.
  • Deciding leave. A request your app submits is pending until a manager approves or declines it.
  • Changing pay. Rates and awards are read-only.
  • Adding, removing or changing staff. People and their details are managed in Shiftly, not through the API.
  • Sending notifications. Shiftly does not post events to partner apps yet, so read what you need when you need it.
  • Reading tax, bank, super or identity details. These are never available to a partner app.

How access is granted

A business owner, or a manager who can manage team access, connects your app from inside your product. Shiftly shows them a consent screen that names your app, lists what it will be able to view and change, and lets them allow or cancel. If they allow, your app receives a credential for that business, or one for each business they ticked if you asked for several.

The flow is OAuth 2.0 authorization code with PKCE. Permissions are OAuth scopes. There is one connection per business per app. To connect several businesses in one consent, add business_selection=multiple to the authorize request; each ticked business still gets its own connection.

Call the API from your server, never from a web page. The client secret and the access credentials must not reach a browser, so Shiftly refuses any request that carries an Origin header, which browsers add, with 403 origin_not_allowed. The two discovery documents under /.well-known are the exception: any page can read them.

Where to start

  1. Quickstart: a first request against the sandbox in a few minutes.
  2. Connect a business: the consent flow in full.
  3. API reference: every resource, field and operation.

Limited release

The Partner API is in limited release. Each app has a connection limit while it is new, and a business that tries to connect once the limit is reached is told the app can't take new connections yet.