Who's on now
Staff clocked in right now: one row per open timesheet started in the last 24 hours, earliest clock-in first. It says where a person is, so read it when you need it rather than polling it.
Needs the timesheets:read permission, depending on the operation. The business sees it as "Timesheets".
Fields
| Field | Type | Access | Meaning |
|---|---|---|---|
| employee_id | string | Read-only | Who is clocked in. |
| timesheet_id | string | Read-only | Their open timesheet. Read it at /timesheets/{id}. |
| location_id | string | Read-only | Where they clocked in. |
| position_id | string | Read-only | The position they are working. |
| shift_id | string, may be null | Read-only | The rostered shift. Empty when they clocked in without one. |
| clocked_in_at | timestamp | Read-only | When they clocked in. |
| on_break | boolean | Read-only | True while they are on a break. |
| break_started_at | timestamp, may be null | Read-only | When the current break started. |
| scheduled_end_time | timestamp, may be null | Read-only | When their rostered shift ends. Empty when they clocked in without one. |
Operations
List the staff clocked in now
GET/v1/whos-on
Permission: timesheets:read
| Parameter | Type | Meaning | |
|---|---|---|---|
| location_id | string | Optional | Only this location. |
| employee_id | string | Optional | Only this person. |
{
"data": [
{
"employee_id": "66f1c2a4b3d9e8f7a6b5c4d3",
"timesheet_id": "66f1c2a4b3d9e8f7a6b5c4d3",
"location_id": "66f1c2a4b3d9e8f7a6b5c4d3",
"position_id": "66f1c2a4b3d9e8f7a6b5c4d3",
"shift_id": "66f1c2a4b3d9e8f7a6b5c4d3",
"clocked_in_at": "2026-10-06T09:00:00+11:00",
"on_break": true,
"break_started_at": "2026-10-06T09:00:00+11:00",
"scheduled_end_time": "2026-10-06T09:00:00+11:00"
}
],
"has_more": true,
"next_cursor": "text"
}| Status | When |
|---|---|
| 400 | The error's code is invalid_request or range_too_long. The Errors page describes each code. |
| 401 | The error's code is invalid_token or token_expired. The Errors page describes each code. |
| 403 | The error's code is origin_not_allowed, permission_denied, not_available, connection_disconnected, connection_suspended or app_suspended. The Errors page describes each code. |
| 404 | There is nothing at this address, or no such record in this business. |
| 429 | Too many requests. Retry-After says when to try again. |
| 500 | Something went wrong at Shiftly. Quote the request id. |
| 503 | This environment is not set up for partner apps yet. |
