Does Regsta have an API and webhooks?
Written for
- Admin
Short answer
Yes. Regsta has a read-only REST API, version 1, for employees, shifts and the published schedule, and webhooks that notify your own systems when something happens. An Admin creates API keys and webhook endpoints under Security. The API cannot create or change data.
The API
- Read-only: the version 1 endpoints answer GET requests for employees, shifts and the published schedule.
- The contract is published as OpenAPI 3.1 at /api/v1/openapi, so you can generate or validate a client from it.
- Send an API key in the Authorization header (Bearer). A key belongs to one company and reads only what its scopes allow.
- Errors carry a stable code and a request ID you can quote to us.
- Long lists are fetched page by page with a cursor.
API keys
In Regsta, open Security and go to API access. Choose Create API key, give it a name and pick what the key can read. The key is shown once. Regsta stores only a SHA-256 hash of it, so a lost key cannot be shown again: revoke it and create a new one.
Webhooks
Under Security, in Webhooks, an Admin adds an endpoint: a public HTTPS address and the events to send. Regsta shows the signing secret once and stores it encrypted.
- Each delivery is signed with HMAC-SHA256 over the timestamp and the body. Check the signature and reject old timestamps to stop replays.
- A failed delivery is retried with growing delays. After repeated failures it moves to a dead-letter queue and is not retried again.
- You can see the delivery status of each endpoint.
Events sent today
- employee.created
- employee.updated
- schedule.published
- payroll_period.closed
- payroll_period.reopened
- export.generated
The API reads; it does not write. There are no endpoints to create employees, publish a schedule or approve time, and webhooks are sent only for the six events above.
Related questions
Did this not answer your question?
Tell us what you were looking for and we will answer it.
Contact us