Cobot Check In API

Members check in to a space for attendance tracking and for using up their time passes.

OpenAPI Specification

cobot-check-in-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cobot Check In API
  termsOfService: https://www.cobot.me/terms
  x-logo:
    url: /api2_logo.webp
    backgroundColor: '#FFFFFF'
    altText: Cobot logo
  description: "This is the 2.0 version of the Cobot API. You can find version 1.0\nas well as various tutorials under [/api-docs](/api-docs).\n\n## JSON API\n\nThis API follows the [JSON API](http://jsonapi.org) standard. This means:\n\n* requests and responses are sent in JSON\n* all requests MUST send a `Accept: application/vnd.api+json` header\n* non-GET requests MUST send a `Content-Type: application/vnd.api+json` header\n* all responses send a `Content-Type: application/vnd.api+json` header\n* all JSON formats are standardized (requests, responses, errors)\n\n## Cross-Origin Resource Sharing (CORS)\n\nAll endpoints send [CORS](https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS)\nheaders so that the API can be used from within browsers.\n\n## Rate Limiting\n\nIn general, the rate limit for an endpoint is 60 requests per minute per user.\nIf applicable, alternative limits are given in the documentation for\nparticular endpoints.\n\nIf you've exceeded the limit, Cobot will return a 429 status code and a JSON\nerror message. The response will also contain a *Retry-After* header, this\ndenotes the number of seconds to wait before your client may retry.\n\n## Times and Dates\n\nTimes and Dates must be in ISO 8601 formats. e.g. date: `2021-01-07`, datetime: `2021-01-07T16:25:51Z`,  time: `16:25:51`.\nMillisecond are ommited, so `16:25:51.811` will become `16:25:51`.\nTime zone offsets must be provided by the client, e.g. `16:25:51+02:00` or '16:25:51Z' for UTC.\n\nTimes are always returned in UTC.\n## Sparse Fieldsets\n\nThis API supports [sparse fieldsets](https://jsonapi.org/format/#fetching-sparse-fieldsets),\nso clients can request which attributes they are interested in.\n\nExample:\n```\nGET https://api.cobot.me/user?fields[users]=email\n```\nThis will only return the user's email.\n\n## Query params\n\nWhen passing query params, arrays of data are expected to be sent as a string of comma separated values.\n\n## Pagination\n\nAll collections are paginated. Pagination follows [JSON-API standards](https://jsonapi.org/format/#fetching-pagination).\n\nExample:\n```json\n{\n  \"meta\": {\n    \"totalPages\": 2,\n    \"currentPage\": 1\n  },\n  \"data\": [{\n    \"id\": \"1\",\n    \"type\": \"users\",\n  }],\n  \"links\": {\n    \"self\": \"/users?page[size]=100&page[number]=1\",\n    \"first\": \"/users?page[size]=100&page[number]=1\",\n    \"prev\": null,\n    \"next\": \"/users?page[size]=100&page[number]=2\",\n    \"last\": \"/users?page[size]=100&page[number]=1\"\n  }\n}\n```\n\nDefault page size is 72 and can be changed by passing a `page[size]` parameter. Maximum page size is 200.\n\n## Errors\n\nWhen a client sends invalid data in a request, Cobot returns a\n422 status code and a JSON-API error response.\n\nExample:\n```json\n{\n  \"errors\": [\n    {\n      \"source\": {\n        \"pointer\": \"/data/attributes/name\"\n      },\n      \"detail\": \"can't be blank\"\n    },\n    {\n      \"source\": {\n        \"pointer\": \"/data/attributes/password\"\n      },\n      \"detail\": \"is too short\"\n    }\n  ]\n}\n```\n"
  version: '2.0'
  contact:
    name: Cobot Support
    url: https://dev.cobot.me/
    email: support@cobot.me
servers:
- url: https://api.cobot.me
security:
- OAuth2: []
tags:
- name: Check-in
  description: Members check in to a space for attendance tracking and for using up their time passes.
paths:
  /check_ins:
    post:
      summary: Check membership in
      description: 'Checks a membership in at a space, after validating that checking in is

        possible (enough time passes, time restrictions). Potentially uses a time pass.


        If the space is part of a network, the membership can be checked in to any space

        of the network.


        **Access**: The current user must be an admin of the space the membership belongs to.

        '
      operationId: create-check-in
      security:
      - OAuth2:
        - write_check_ins
      tags:
      - Check-in
      responses:
        '201':
          description: Checked in successfully.
          content:
            application/vnd.api+json:
              schema:
                $ref: '#/components/schemas/check-in'
              examples:
                default:
                  value:
                    data:
                      id: 12a8fa71ac8df98d29de357180d274d8
                      type: checkIns
                      attributes:
                        validFrom: '2018-01-01T12:45:00Z'
                        validUntil: '2018-01-01T18:00:00Z'
                      relationships:
                        space:
                          data:
                            id: 99da6cb66b5e6b39007690854fd66df9
                            type: spaces
                        membership:
                          data:
                            id: 89da3cb66b5e6b39007690854kd66da4
                            type: memberships
        '422':
          description: Checking in failed because a condition was not met.
          content:
            application/vnd.api+json:
              schema:
                $ref: '#/components/schemas/failure'
              examples:
                default:
                  value:
                    errors:
                    - detail: No time passes left.
                      source:
                        pointer: /data/attributes/base
      requestBody:
        description: Data required to check in.
        required: true
        content:
          application/vnd.api+json:
            schema:
              $ref: '#/components/schemas/create-check-in'
            examples:
              default:
                value:
                  data:
                    type: checkIns
                    attributes:
                      checkInToken: '12345'
                    relationships:
                      space:
                        data:
                          id: 99da6cb66b5e6b39007690854fd66df9
                          type: spaces
  /check_ins/{id}/check_out:
    put:
      summary: Check membership out
      description: 'Checks a membership (that is currently checked in at a space) out.


        If the space is part of a network, the membership can be checked out of any space

        of the network.


        **Access**: The current user must be an admin of the space the membership belongs to.

        '
      operationId: create-check-out
      parameters:
      - name: id
        in: path
        required: true
        description: The id of the check-in to update.
        schema:
          type: string
      security:
      - OAuth2:
        - write_check_ins
      tags:
      - Check-in
      responses:
        '200':
          description: Checked out successfully. `validUntil` is updated.
          content:
            application/vnd.api+json:
              schema:
                $ref: '#/components/schemas/check-in'
              examples:
                default:
                  value:
                    data:
                      id: 12a8fa71ac8df98d29de357180d274d8
                      type: checkIns
                      attributes:
                        validFrom: '2018-01-01T12:45:00Z'
                        validUntil: '2018-01-01T17:00:00Z'
                      relationships:
                        space:
                          data:
                            id: 99da6cb66b5e6b39007690854fd66df9
                            type: spaces
                        membership:
                          data:
                            id: 89da3cb66b5e6b39007690854kd66da4
                            type: memberships
  /memberships/{membershipId}/check_ins:
    get:
      summary: For membership/time
      description: 'List all check-ins of the membership starting in the given time range.

        If the membership''s space belongs to a network, this

        includes check-ins from all spaces in the network.


        **Access**: The current user must be the owner of the membership or an admin

        in the space the membership belongs to.

        '
      operationId: get-membership-check-ins
      parameters:
      - name: membershipId
        in: path
        required: true
        description: The id of the membership the bookings belong to.
        schema:
          type: string
      - name: filter[from]
        in: query
        required: true
        description: Start of the time range.
        schema:
          type: string
          format: date-time
        example: '2012-04-12T10:00:00Z'
      - name: filter[to]
        in: query
        required: true
        description: End of the time range.
        schema:
          type: string
          format: date-time
        example: '2012-04-12T18:00:00Z'
      security:
      - OAuth2:
        - read_check_ins
      tags:
      - Check-in
      responses:
        '200':
          description: Membership check-ins for a given time range.
          content:
            application/vnd.api+json:
              schema:
                $ref: '#/components/schemas/check-ins'
              examples:
                default:
                  value:
                    data:
                    - id: 12a8fa71ac8df98d29de357180d274d8
                      type: checkIns
                      attributes:
                        validFrom: '2018-01-01T12:45:00Z'
                        validUntil: '2018-01-01T19:53:00Z'
                      relationships:
                        space:
                          data:
                            id: 99da6cb66b5e6b39007690854fd66df9
                            type: spaces
                        membership:
                          data:
                            id: 89da3cb66b5e6b39007690854kd66da4
                            type: memberships
  /spaces/{spaceId}/check_ins/current:
    get:
      summary: Current by token
      description: 'List check-ins for a membership in a space that are still current, i.e.

        their `validUntil` attribute is in the future.


        The membership is determined by passing a `checkInToken`.

        If the space is part of a network, check-ins can be fetched for any space

        of the network.


        **Access**: The current user must be an admin of the space the membership belongs to.

        '
      operationId: list-space-check-ins-current
      parameters:
      - name: spaceId
        in: path
        required: true
        description: The id of the space the check-ins belong to.
        schema:
          type: string
      - name: filter[checkInToken]
        in: query
        required: true
        description: 'A check-in token of the membership the check-ins belong to. Check-in tokens

          are created via the check-in token API and are typically MAC addresses

          or RFID tokens.

          '
        schema:
          type: string
      security:
      - OAuth2:
        - read_check_ins
      tags:
      - Check-in
      responses:
        '200':
          description: List check-ins.
          content:
            application/vnd.api+json:
              schema:
                $ref: '#/components/schemas/check-ins'
              examples:
                default:
                  value:
                    data:
                    - id: 12a8fa71ac8df98d29de357180d274d8
                      type: checkIns
                      attributes:
                        validFrom: '2018-01-01T12:45:00Z'
                        validUntil: '2018-01-01T23:59:59Z'
                      relationships:
                        space:
                          data:
                            id: 99da6cb66b5e6b39007690854fd66df9
                            type: spaces
                        membership:
                          data:
                            id: 89da3cb66b5e6b39007690854kd66da4
                            type: memberships
components:
  schemas:
    create-check-in:
      id: create-check-in.json#
      type: object
      required:
      - data
      additionalProperties: false
      properties:
        data:
          type: object
          required:
          - type
          - attributes
          - relationships
          additionalProperties: false
          properties:
            type:
              type: string
              enum:
              - checkIns
            attributes:
              type: object
              required:
              - checkInToken
              additionalProperties: false
              properties:
                checkInToken:
                  type: string
                  description: A previously created token via the check-in token API that is associated with the membership (typically a MAC address or RFID token).
            relationships:
              type: object
              additionalProperties: false
              required:
              - space
              properties:
                space:
                  type: object
                  additionalProperties: false
                  required:
                  - data
                  properties:
                    data:
                      type: object
                      required:
                      - id
                      - type
                      additionalProperties: false
                      properties:
                        id:
                          type: string
                        type:
                          type: string
                          enum:
                          - spaces
    check-in:
      id: check-in.json#
      type: object
      required:
      - data
      additionalProperties: false
      properties:
        data:
          $ref: '#/components/schemas/-check-in-data'
    check-ins:
      id: check-ins.json#
      type: object
      required:
      - data
      additionalProperties: false
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/-check-in-data'
        meta:
          $ref: '#/components/schemas/pagination-meta'
        links:
          $ref: '#/components/schemas/pagination-links'
    link:
      description: 'A link **MUST** be represented as either: a string containing the link''s URL or a link object.'
      oneOf:
      - description: A string containing the link's URL.
        type: string
        format: uri-reference
      - type: object
        required:
        - href
        properties:
          href:
            description: A string containing the link's URL.
            type: string
            format: uri-reference
          meta:
            $ref: '#/components/schemas/meta'
    error:
      type: object
      properties:
        id:
          description: A unique identifier for this particular occurrence of the problem.
          type: string
        links:
          $ref: '#/components/schemas/links'
        status:
          description: The HTTP status code applicable to this problem, expressed as a string value.
          type: string
        code:
          description: An application-specific error code, expressed as a string value.
          type: string
        title:
          description: A short, human-readable summary of the problem. It **SHOULD NOT** change from occurrence to occurrence of the problem, except for purposes of localization.
          type: string
        detail:
          description: A human-readable explanation specific to this occurrence of the problem.
          type: string
        source:
          type: object
          properties:
            pointer:
              description: A JSON Pointer [RFC6901] to the associated entity in the request document [e.g. "/data" for a primary data object, or "/data/attributes/title" for a specific attribute].
              type: string
            parameter:
              description: A string indicating which query parameter caused the error.
              type: string
        meta:
          $ref: '#/components/schemas/meta'
      additionalProperties: false
    jsonapi:
      description: An object describing the server's implementation
      type: object
      properties:
        version:
          type: string
        meta:
          $ref: '#/components/schemas/meta'
      additionalProperties: false
    links:
      type: object
      additionalProperties:
        $ref: '#/components/schemas/link'
    meta:
      description: Non-standard meta-information that can not be represented as an attribute or relationship.
      type: object
      additionalProperties: true
    pagination-links:
      type: object
      required:
      - first
      - self
      - next
      additionalProperties: false
      properties:
        first:
          type: string
          description: Link to the first results page.
        prev:
          oneOf:
          - type: string
          - type: 'null'
          description: Link to the previous results page. Null when on the first page.
        self:
          type: string
          description: Link to the current results page.
        next:
          oneOf:
          - type: string
          - type: 'null'
          description: Link to the next results page. Null when on the last page.
        last:
          type: string
          description: Link to the last results page.
    pagination-meta:
      type: object
      additionalProperties: false
      properties:
        totalPages:
          type: number
        currentPage:
          type: number
    -check-in-data:
      type: object
      required:
      - id
      - type
      - attributes
      - relationships
      additionalProperties: false
      properties:
        type:
          type: string
          enum:
          - checkIns
        id:
          type: string
        attributes:
          type: object
          required:
          - validFrom
          - validUntil
          additionalProperties: false
          properties:
            validFrom:
              type: string
              format: date-time
            validUntil:
              type: string
              format: date-time
        relationships:
          type: object
          additionalProperties: false
          required:
          - space
          - membership
          properties:
            space:
              type: object
              additionalProperties: false
              required:
              - data
              properties:
                data:
                  additionalProperties: false
                  required:
                  - id
                  - type
                  properties:
                    id:
                      type: string
                    type:
                      type: string
                      enum:
                      - spaces
            membership:
              type: object
              additionalProperties: false
              required:
              - data
              properties:
                data:
                  required:
                  - id
                  - type
                  properties:
                    id:
                      type: string
                    type:
                      type: string
                      enum:
                      - memberships
    failure:
      type: object
      required:
      - errors
      properties:
        errors:
          type: array
          items:
            $ref: '#/components/schemas/error'
          uniqueItems: true
        meta:
          $ref: '#/components/schemas/meta'
        jsonapi:
          $ref: '#/components/schemas/jsonapi'
        links:
          $ref: '#/components/schemas/links'
      additionalProperties: false
  securitySchemes:
    OpenId:
      type: openIdConnect
      openIdConnectUrl: https://www.cobot.me/.well-known/openid-configuration
    OAuth2:
      type: oauth2
      description: "OAuth is \"an open protocol to allow secure API authorization in a simple and\nstandard method from desktop and web applications.\". \"OAuth 2.0 is the\nnext evolution of the OAuth protocol [..]. OAuth 2.0 focuses on client\ndeveloper simplicity [...]. It is supported by many popular sites such as\nFacebook and there are client libraries available for many programming\nlanguages.\n\nFor information about OAuth2 see the [oauth website](http://oauth.net/2/).\n\n**For OAuth2 you need a client id and secret. In order to get those you have\nto [register your application](/oauth2_clients).**\n\nAPI authorization works by passing a bearer token via the HTTP Authorization header:\n\n    Authorization: bearer <token>\n\n## Permissions (Scope)\n\nOAuth2 [defines scopes](https://tools.ietf.org/html/rfc6749#section-3.3) to\nrestrict access to certain resources.\n\nThe required scope for each resource can be found within the documentation\nfor each endpoint.\n\nPlease note that a user's scope can be limited when they access the API as\nan admin of a space and some of their admin permissions have been revoked.\n"
      flows:
        authorizationCode:
          authorizationUrl: https://www.cobot.me/oauth/authorize
          tokenUrl: https://www.cobot.me/oauth/access_token
          scopes:
            read_articles: Read help desk articles.
            read_allocations: Read resource allocation data.
            read_booking_credits: Read information about a membership's booking credits.
            read_bookings: Read booking data.
            read_built_in_email_customizations: Read built in email customizations.
            read_calendar_blockers: Read calendar blockers.
            read_check_ins: Read memberships' check-in data.
            read_contacts: Read contacts.
            read_drop_in_passes: Read drop-in passes.
            read_drop_in_pass_templates: Read drop-in pass templates.
            read_discount_codes: Read discount codes.
            read_event_attendances: Read who is attending an event.
            read_event_messages: Read messages sent about events.
            read_events: Read events of a space.
            read_external_bookings: Read external booking data.
            read_external_resources: Read resources enabled for external booking.
            read_invoices: Read invoices created for a membership in a space.
            read_memberships: Read information about memberships in a space.
            read_teams: Read information about teams in a space.
            read_membership_profiles: Read members' profile data.
            read_navigation_links: Read/list navigation links for a space.
            read_payment_methods: Read payment methods in order to process payments.
            read_published_membership_profiles: Read published members' profile data.
            read_networks: Read information about a network.
            read_products: Read information about products.
            read_resource_categories: Read information about booking calendar categories.
            read_resources: Read information about booking calendar resources.
            read_single_page_apps: Read information about single page apps.
            read_space_profiles: Read space profile information.
            read_spaces: Read basic space information.
            read_space_billing_details: Read information relevant to billing the space.
            read_space_payment_method: Read a space's payment method used to pay for the space's Cobot subscription.
            read_space_subscriptions: Read a space's subscription.
            read_terms_approvals: Shows missing approvals for the current member.
            read_urls: Read the URLs to the Cobot web interface.
            read_user: Read the current user's information.
            write_bookings: Write booking data.
            write_check_ins: Check a member in at a space.
            write_customers: Convert a space to a customer.
            write_drop_in_pass_purchases: Create drop-in pass purchases.
            write_drop_in_passes: Cancel drop-in passes.
            write_event_ticket_purchases: Create event ticket purchases.
            write_event_attendances: Attend/unattend events.
            write_event_messages: Create/update messages sent about events.
            write_events: Write to events of a space.
            write_external_bookings: Create/update bookings as a non-member.
            write_external_resources: Create/update/delete resources enabled for non-memberss
            write_resources: Create/update/delete booking calendar resources.
            write_invoices: Create invoices for members in a space.
            write_invoice_reminders: Send invoice reminder emails.
            write_membership_profiles: Manage the social profiles of members.
            write_navigation_links: Create/update/delete navigation links for a space.
            write_payments: Initiate payments for external bookings.
            write_single_page_apps: Create and update single page apps to be embedded on Cobot.
            write_space_billing_details: Update a space's billing details.
            write_space_payment_method: Update a space's payment method used to pay for the space's Cobot subscription.
            write_space_subscriptions: Change a space's subscription. Only trusted clients can request this scope. Contact support.
            write_terms_approvals: Approve different kinds of terms as a member.