Total Access Docs
Openapi

Record clock in/out action

Records a clock-in or clock-out action for the authenticated user. Used by SmartClock (desktop app) and mobile apps. Writes to `ta_attendance_logs` with platform metadata.

POST
/api/v1/time-attendance/clock

Records a clock-in or clock-out action for the authenticated user. Used by SmartClock (desktop app) and mobile apps. Writes to ta_attendance_logs with platform metadata.

Authorization

BearerAuth
AuthorizationBearer <token>

JWT access token for REST API endpoints (user-facing apps).

Authorization: Bearer <jwt_access_token>

Tokens expire after 15 minutes. Use the refresh token to obtain a new one.

In: header

Header Parameters

Idempotency-Key?string

UUID v4 or arbitrary string (max 255 chars) to prevent duplicate processing of retried requests. When the same key is sent with the same request body, the original response is returned with an X-Idempotent-Replay: true header. If the same key is sent with a different body, a 409 Conflict is returned.

Lengthlength <= 255

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

curl -X POST "https://example.com/api/v1/time-attendance/clock" \  -H "Content-Type: application/json" \  -d '{    "action": "clock_in"  }'
{  "success": true,  "data": {    "log_id": 0,    "action": "string",    "timestamp": "2019-08-24T14:15:22Z"  }}
{  "success": false,  "error": {    "code": "BAD_REQUEST",    "message": "Request body is empty. Expected JSON with action field.",    "request_id": "req_abc123",    "documentation_url": "https://dev-developer.totalaccess.co.za/docs/api-reference/errors#bad_request"  }}
{  "success": false,  "error": {    "code": "UNAUTHORIZED",    "message": "API key required",    "request_id": "req_abc123",    "documentation_url": "https://dev-developer.totalaccess.co.za/docs/api-reference/errors#unauthorized"  }}