Postman
Every request your app can make, ready to run against the sandbox. About five minutes to the first answer.
Download
- The collection: every request, in folders by area, with example bodies and the sign-in already set up.
- The Sandbox environment: the demo addresses. Start here.
- The Production environment: the live addresses, for once your app has production credentials.
Import all three into Postman, then choose the Sandbox environment in the top right.
1. Fill in your credentials
In the Sandbox environment, set clientId to your sandbox client id and clientSecret to your sandbox client secret, which starts with shf_sk_. Shiftly sends both when it sets up your sandbox.
2. Let Postman sign in
Postman signs in with the same consent flow your product uses, so Shiftly has to know where to send it back. Ask your Shiftly contact to add this return address to your sandbox app:
https://oauth.pstmn.io/v1/callbackThen open the collection, go to its Authorization tab and choose Get New Access Token. Sign in as the sandbox business owner, allow access, and choose Use Token. Every request in the collection uses it.
The collection asks for every permission. If sign-in stops with "This app may not ask for", delete the permissions it names from the Scope field on the Authorization tab and try again.
Sandbox apps only
Add the Postman return address to your sandbox app, not your production app. To try production, get a credential through your own product and paste it as a bearer token, as described below.
3. Send a request
Open Rostering, then Shifts, and send List shifts. Changes carry an Idempotency-Key that Postman makes fresh for each send; set it to a fixed value to try a safe retry.
Use Postman desktop
Use the Postman desktop app. Shiftly refuses calls made from a web page. Postman on the web can send requests through the Postman desktop agent, but its sign-in may still run in the browser and be refused; if it is, paste a bearer token as described below.
If sign-in won't work
Get an access credential another way, for example from the Quickstart, and paste it on the collection's Authorization tab as a bearer token. It lasts 30 minutes.
