Resolve the authenticated tenant
Echoes the tenant and role the presented API key resolves to. Useful as an "is my key valid?" check. Returns `401` if the key is missing/invalid.
Echoes the tenant and role the presented API key resolves to. Useful as
an "is my key valid?" check. Returns 401 if the key is missing/invalid.
The per-tenant API key, copied from Settings → API & integrations.
Sent as the x-api-key request header. The key is tenant-scoped and acts
with Admin-equivalent, tenant-wide access.
In: header
Response Body
application/json
application/json
curl -X GET "https://example.com/whoami"{ "tenantId": "f97df110-f4de-492e-8849-4a6af68026b0", "role": "admin", "timezone": "Australia/Sydney"}{ "error": { "code": "unauthorized", "message": "Missing or invalid API key." }}Create an upgrade Checkout session POST
Returns a freshly-created Stripe Checkout URL to upgrade the tenant off the Free plan (e.g. before adding a second project). The human pays in their own browser; the webhook upgrades the tenant. Admin-equivalent.
Create a diary entry POST
Logs a daily site-diary entry. The key acts as a tenant Admin: with `userId` the entry is logged FOR that crew member (issue 6) — they must be an active tenant member assigned to the project, the entry's origin is `logged_for`, `createdBy` names the acting admin, and every surface shows "Logged by [admin] for [crew member]"; without it the key logs its own owner's day (origin `manual`). `entryDate` may not be in the future, and hours ENTERED BY HAND move in 15-minute steps with a 12-hour maximum (ADR 0012, amended): pass `durationMinutes` as a multiple of 15 (0–720, e.g. `465` = 7h 45m), or the legacy `hours` (0–12, rounded to the nearest minute). A value that is not a multiple of 15 is refused the way one over 720 is; entries created by a check-out can hold any whole minute (e.g. 518 = 8h 38m), but those hours are derived and never entered here. To attach photos, first upload each via `POST /projects/{id}/diary-photos/upload-url` and pass the returned `storagePath`(s) in `photoPaths`. Editing/deleting entries stays in the app (the edit verbs `405`, pointing there — "Edit it in the FOREMAN app."; creating is a real API call, so the message does not say "create"). While the subject is checked in, logging by hand would double-count the shift its check-out is about to write, so the create `409`s with "Check out first to log this shift." (brief B2 — one rule across the web form, this REST route and MCP `create_diary_entry`).