Diagnostics

Resolve the authenticated tenant

Echoes the tenant and role the presented API key resolves to. Useful as an "is my key valid?" check. Returns `401` if the key is missing/invalid.

GET
/whoami

Echoes the tenant and role the presented API key resolves to. Useful as an "is my key valid?" check. Returns 401 if the key is missing/invalid.

Authorization

x-api-key<token>

The per-tenant API key, copied from Settings → API & integrations. Sent as the x-api-key request header. The key is tenant-scoped and acts with Admin-equivalent, tenant-wide access.

In: header

Response Body

application/json

application/json

curl -X GET "https://example.com/whoami"
{  "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0",  "role": "admin",  "timezone": "Australia/Sydney"}
{  "error": {    "code": "unauthorized",    "message": "Missing or invalid API key."  }}

Create an upgrade Checkout session POST

Returns a freshly-created Stripe Checkout URL to upgrade the tenant off the Free plan (e.g. before adding a second project). The human pays in their own browser; the webhook upgrades the tenant. Admin-equivalent.

Create a diary entry POST

Logs a daily site-diary entry. The key acts as a tenant Admin: with `userId` the entry is logged FOR that crew member (issue 6) — they must be an active tenant member assigned to the project, the entry's origin is `logged_for`, `createdBy` names the acting admin, and every surface shows "Logged by [admin] for [crew member]"; without it the key logs its own owner's day (origin `manual`). `entryDate` may not be in the future, and hours ENTERED BY HAND move in 15-minute steps with a 12-hour maximum (ADR 0012, amended): pass `durationMinutes` as a multiple of 15 (0–720, e.g. `465` = 7h 45m), or the legacy `hours` (0–12, rounded to the nearest minute). A value that is not a multiple of 15 is refused the way one over 720 is; entries created by a check-out can hold any whole minute (e.g. 518 = 8h 38m), but those hours are derived and never entered here. To attach photos, first upload each via `POST /projects/{id}/diary-photos/upload-url` and pass the returned `storagePath`(s) in `photoPaths`. Editing/deleting entries stays in the app (the edit verbs `405`, pointing there — "Edit it in the FOREMAN app."; creating is a real API call, so the message does not say "create"). While the subject is checked in, logging by hand would double-count the shift its check-out is about to write, so the create `409`s with "Check out first to log this shift." (brief B2 — one rule across the web form, this REST route and MCP `create_diary_entry`).