Hamshift

Hamshift API

Hamshift manages hospital ward shifts, staff requests, and schedules. Its JSON API is served under https://hmshift.ir/api.

OpenAPI specification · API catalog · Health status

Agent account provisioning and authentication discovery (auth.md) describes manager provisioning, invitation acceptance, session credential use, and revocation.

Authentication and access

Sign in with an existing account using POST /api/auth/login and a JSON body containing username and password. Retain the returned HttpOnly nobat_sid session cookie for subsequent requests. Accounts are created by managers, invitations, or first-run setup; public registration is closed after setup.

State-changing requests must use Content-Type: application/json. Sign-in is rate limited. Role and ward permissions apply to automated clients too. When selecting a ward, send its numeric ID as X-Ward or the ward query parameter; without one, the user's home ward is selected. Unauthorized ward access returns HTTP 403.

HTTP 401 means sign-in is required. HTTP 403 means access is denied or a password change is required. Error responses contain error (usually Persian) and may include a machine-readable code.

Documented endpoints

Method and pathPurposeAccess
GET /api/healthApplication and database health; HTTP 200 when available, 503 when the database is down.Public
GET /api/setupReturns whether first-run setup is needed.Public
POST /api/auth/loginStarts a password-authenticated session.Existing account
POST /api/auth/logoutEnds the session; send a JSON body such as {}.Public; clears the current session if present
GET /api/meCurrent user profile and today's ISO Gregorian date.Signed in

This initial OpenAPI specification covers the endpoints above. Scheduling, staff management, requests, passkeys, and administration operations are not yet described in the specification.