Docs

attendance.clocked_in

Preview· P9

An employee clocks in, by any method. Punches made offline fire when the device syncs, with their original occurred_at. Evidence appears only when the punch has it: selfie_file_id, location, wifi, and face_check with review. Agoo never sends face images or templates.

Agoo sends this as a signed POST to every enabled endpoint subscribed to attendance.clocked_in (or *). Verify the signature, return any 2xx within 15 seconds, and de-duplicate on webhook-id.

Header Parameters

webhook-id*string

The event's ID. It is the same on every attempt and redelivery, so use it to de-duplicate.

Match^evt_[0-7][0-9a-hjkmnp-tv-z]{25}$
Example"evt_01m4ww0ezgf2bryg9gxb2gbewx"
webhook-timestamp*string

When this attempt was signed, in Unix seconds. Reject the request if it is more than 5 minutes from your clock.

Match^[0-9]+$
webhook-signature*string

One or more space-separated signatures, each v1,<base64>: the base64 HMAC-SHA256 of {webhook-id}.{webhook-timestamp}.{raw body}, keyed with the base64-decoded part of your whsec_ secret. During a secret rotation there are two. Accept the request if any one matches.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

An event about a clock-in or clock-out.

Response Body

Example Requests

POST/attendance.clocked_in