POST
/api/public/v1/shiftsCreate a shift
Puts somebody on the rota. The assignee has to be an ACTIVE employee of this company, and the token has to be able to manage that location’s schedule. The shift shows up read-only on the assignee’s calendar, and a clock-in inside its window links itself to it automatically.
Required scope
The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.
schedule:write
Request Body
| Property | Type | Description |
|---|---|---|
locationId | string | Where the shift is. |
employeeId | string | Who is covering it. |
startAt | string | ISO 8601. |
endAt | string | ISO 8601, strictly after `startAt`. |
role | string | What they are covering — "Front desk", "Cashier". |
note | string |
POSTExample request
curl
curl -X POST "https://www.pxb.app/api/public/v1/shifts" \
-H "Authorization: Bearer your_access_token" \
-H "Content-Type: application/json" \
-d '{
"locationId": "loc_abc123",
"employeeId": "emp_44f1",
"startAt": "2026-08-29T13:00:00.000Z",
"endAt": "2026-08-29T21:00:00.000Z",
"role": "Front desk"
}'200Example response
json
{
"message": "Shift created successfully!",
"content": {
"shift": {
"id": "shf_9911",
"companyId": "com_001",
"locationId": "loc_abc123",
"employeeId": "emp_44f1",
"startAt": "2026-08-29T13:00:00.000Z",
"endAt": "2026-08-29T21:00:00.000Z",
"role": "Front desk",
"note": null,
"createdById": "emp_12ab",
"createdAt": "2026-08-20T10:00:00.000Z",
"updatedAt": "2026-08-20T10:00:00.000Z"
}
}
}403Example response
json
{
"message": "You cannot manage that location’s schedule."
}In the console
The same thing done by hand, for anyone comparing the API against the screen they already use.