Docs
API referenceAttendance

Update attendance settings

Preview· P9
PATCH/attendance/settings

Changes methods and evidence settings, publishes notices and sets how long evidence is kept. Send only what changes.

  • Switching evidence on (face or geofence in methods, or a selfie_mode other than off) needs a published notice for it, now or before; otherwise validation_failed at body.notices.<evidence>.
  • Notices: each one you send becomes a new version with its basis, legal_basis (for required) and text. Employees acknowledge (or consent to) the current version.
  • Data protection decisions (notices and retention) need the Data & privacy permission, held by Owners and Admins: keys and OAuth apps get forbidden.
  • At least one method stays on, organisation-wide and at every site; PIN can be off (for example "face only"). The Wi-Fi check is for phone clock-in, so it needs geofence.
  • Methods and evidence your plan doesn't include return plan_required.
  • Switching face off deletes every enrolled face template from your kiosks.

Scope: attendance:manage · Plan: Pro and Enterprise in live mode; every plan in test mode.

Authorization

AuthorizationBearer <token>

Send Authorization: Bearer <token> on every request. The token is one of:

PrefixWhat it isWhere it may be used
agoo_sk_live_Secret key, live modeYour servers only
agoo_sk_test_Secret key, test modeYour servers only
agoo_pk_live_Publishable key, live modeBrowsers and apps: create pre-registrations and bookings, read public booking types (with their intake questions) and their free slots, read the visit types open for pre-registration with their public forms. Never lists people.
agoo_pk_test_Publishable key, test modeAs above, in test mode

Admins create keys in Console → Developers → API keys and choose each key's scopes. A key is shown once. Never put a secret key in a URL, a browser or a mobile app.

In: header

Scope: attendance:manage

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Properties1 <= properties

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X PATCH "https://example.com/attendance/settings" \  -H "Content-Type: application/json" \  -d '{    "methods": [      "qr",      "pin",      "geofence",      "terminal"    ],    "wifi_check": true  }'
{  "methods": [    "qr",    "pin",    "face",    "geofence",    "terminal"  ],  "selfie_mode": "optional",  "location_evidence": "result",  "wifi_check": true,  "wifi_identifiers": false,  "face_fallback_approval": false,  "selfie_retention_days": 90,  "coordinates_retention_days": 90,  "notices": {    "face": {      "version": 2,      "basis": "required",      "legal_basis": "legitimate_interests",      "text": "Ridge Medical uses face matching on its reception kiosk to record your attendance…",      "effective_on": "2026-10-01",      "published_at": "2026-09-28T10:00:00Z"    },    "selfie": {      "version": 1,      "basis": "consent",      "legal_basis": null,      "text": "With your consent, the app takes a photo when you clock in on your phone…",      "effective_on": "2026-10-01",      "published_at": "2026-09-28T10:00:00Z"    },    "location": {      "version": 1,      "basis": "required",      "legal_basis": "employment_contract",      "text": "When you clock in on your phone, the app checks that you are at the clinic…",      "effective_on": "2026-10-01",      "published_at": "2026-09-28T10:00:00Z"    }  },  "updated_at": "2026-09-28T10:00:00Z"}