Hamshift manages hospital ward shifts, staff requests, and schedules. Its JSON API is served under https://hmshift.ir/api.
OpenAPI specification · API catalog · Health status
Agent account provisioning and authentication discovery (auth.md) describes manager provisioning, invitation acceptance, session credential use, and revocation.
Sign in with an existing account using POST /api/auth/login and a JSON body containing username and password. Retain the returned HttpOnly nobat_sid session cookie for subsequent requests. Accounts are created by managers, invitations, or first-run setup; public registration is closed after setup.
State-changing requests must use Content-Type: application/json. Sign-in is rate limited. Role and ward permissions apply to automated clients too. When selecting a ward, send its numeric ID as X-Ward or the ward query parameter; without one, the user's home ward is selected. Unauthorized ward access returns HTTP 403.
HTTP 401 means sign-in is required. HTTP 403 means access is denied or a password change is required. Error responses contain error (usually Persian) and may include a machine-readable code.
| Method and path | Purpose | Access |
|---|---|---|
GET /api/health | Application and database health; HTTP 200 when available, 503 when the database is down. | Public |
GET /api/setup | Returns whether first-run setup is needed. | Public |
POST /api/auth/login | Starts a password-authenticated session. | Existing account |
POST /api/auth/logout | Ends the session; send a JSON body such as {}. | Public; clears the current session if present |
GET /api/me | Current user profile and today's ISO Gregorian date. | Signed in |
This initial OpenAPI specification covers the endpoints above. Scheduling, staff management, requests, passkeys, and administration operations are not yet described in the specification.