Create a key in Admin → Integrations and send it as Authorization: Bearer sl_…. All responses are JSON unless a file format is requested.
List bids (filter by status).
A bid with lines, shifts, results and violations.
Bid package in a file format or a tenant-configured bidding-system format.
Stations + workgroups with their contracts.
Effective resolved rules with sources and conflicts.
Push a demand curve version: { workgroupId, intervalMinutes, mode, label, days: [{ key: 'mon', values: [...] }] }.
Events: bid.submitted, bid.approved, bid.rejected, bid.published, rule.approved. Each POST carries x-shiftline-event and x-shiftline-signature: t=<unix>,v1=<hex>, where v1 = HMAC_SHA256(secret, `${t}.${body}`).
import crypto from "node:crypto"
const [t, v1] = sig.split(",").map((p) => p.split("=")[1])
const ok = crypto.timingSafeEqual(
Buffer.from(v1),
Buffer.from(crypto.createHmac("sha256", secret).update(`${t}.${rawBody}`).digest("hex")),
)