Docs
API referenceAttendance

Get attendance settings

Preview· P9
GET/attendance/settings

Returns how people may clock in across your organisation, the evidence each punch records, the current notice and basis for each evidence type, and how long selfies and coordinates are kept.

  • Methods: qr (the kiosk scans a staff QR badge), rotating_qr (a phone scans the kiosk's code, which changes every 30 seconds), pin, nfc, face (on a kiosk), geofence (a phone inside the site's area) and terminal (your own terminal, through the API). At least one is on; sites can change them. A method that's off isn't offered, with one exception: after a failed face match the kiosk offers a fallback (PIN, QR, NFC or a supervisor-assisted punch, method assisted), recorded face_check: not_verified for review, so nobody is ever locked out.
  • Evidence (face, selfie, location) is off until you switch it on, and each type needs a published notice. Its basis is required (your organisation requires it under its legal basis; employees acknowledge the notice and capture goes ahead either way) or consent (captured only for people who consented).

Scope: attendance:read · Plan: Pro and Enterprise in live mode; every plan in test mode.

Authorization

AuthorizationBearer <token>

Send Authorization: Bearer <token> on every request. The token is one of:

PrefixWhat it isWhere it may be used
agoo_sk_live_Secret key, live modeYour servers only
agoo_sk_test_Secret key, test modeYour servers only
agoo_pk_live_Publishable key, live modeBrowsers and apps: create pre-registrations and bookings, read public booking types (with their intake questions) and their free slots, read the visit types open for pre-registration with their public forms. Never lists people.
agoo_pk_test_Publishable key, test modeAs above, in test mode

Admins create keys in Console → Developers → API keys and choose each key's scopes. A key is shown once. Never put a secret key in a URL, a browser or a mobile app.

In: header

Scope: attendance:read

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X GET "https://example.com/attendance/settings"
{  "methods": [    "qr",    "pin",    "face",    "geofence",    "terminal"  ],  "selfie_mode": "optional",  "location_evidence": "result",  "wifi_check": true,  "wifi_identifiers": false,  "face_fallback_approval": false,  "selfie_retention_days": 90,  "coordinates_retention_days": 90,  "notices": {    "face": {      "version": 2,      "basis": "required",      "legal_basis": "legitimate_interests",      "text": "Ridge Medical uses face matching on its reception kiosk to record your attendance…",      "effective_on": "2026-10-01",      "published_at": "2026-09-28T10:00:00Z"    },    "selfie": {      "version": 1,      "basis": "consent",      "legal_basis": null,      "text": "With your consent, the app takes a photo when you clock in on your phone…",      "effective_on": "2026-10-01",      "published_at": "2026-09-28T10:00:00Z"    },    "location": {      "version": 1,      "basis": "required",      "legal_basis": "employment_contract",      "text": "When you clock in on your phone, the app checks that you are at the clinic…",      "effective_on": "2026-10-01",      "published_at": "2026-09-28T10:00:00Z"    }  },  "updated_at": "2026-09-28T10:00:00Z"}

Review a punch whose face wasn't verified POST

Accepts or rejects a fallback punch (PIN, QR, NFC or supervisor-assisted) after a failed face match: its `face_check` is `not_verified` and its `review.status` is `pending`. These punches form the review queue (`GET /attendance/events?review_status=pending`) and are counted in the summary until reviewed. - `accepted` keeps the punch. `rejected` voids it: it no longer appears or counts. - A punch that isn't awaiting review returns `invalid_state`. **Scope:** `attendance:manage` · **Plan:** Pro and Enterprise in live mode; every plan in test mode.

Update attendance settings PATCH

Changes methods and evidence settings, publishes notices and sets how long evidence is kept. Send only what changes. - **Switching evidence on** (`face` or `geofence` in `methods`, or a `selfie_mode` other than `off`) needs a published notice for it, now or before; otherwise `validation_failed` at `body.notices.<evidence>`. - **Notices:** each one you send becomes a new version with its `basis`, `legal_basis` (for `required`) and `text`. Employees acknowledge (or consent to) the current version. - **Data protection decisions** (notices and retention) need the Data & privacy permission, held by Owners and Admins: keys and OAuth apps get `forbidden`. - At least one method stays on, organisation-wide and at every site; PIN can be off (for example "face only"). The Wi-Fi check is for phone clock-in, so it needs `geofence`. - Methods and evidence your plan doesn't include return `plan_required`. - Switching face off deletes every enrolled face template from your kiosks. **Scope:** `attendance:manage` · **Plan:** Pro and Enterprise in live mode; every plan in test mode.