What the API does today
Everything in this list is running in production, verified against the implementation rather than a spec document. If a capability is not on it, it is not live — see the in-development section below for what is coming.
- Scoped keys — people, attendance and payments scopes, read and write separated
- Pull attendance by person or organisation-wide, over IST date ranges, paginated
- Create and update people, assign packages, record payments from your own systems
- Block or unblock a person's device access from an external system
- Push a person to the site's terminals via API — enrolment driven from your software
- Per-minute rate limits, monthly quotas and a full request log on every key
- Keys shown once and stored only as a SHA-256 hash — never recoverable from us