Skip to main content
GET
List roles (with preset flag + assigned-employee count)

Authorizations

Authorization
string
header
required

Issue keys in Settings → API. Send them as Authorization: Bearer ont_… (an X-Api-Key: ont_… header is also accepted). Session-cookie routes are used by the OnTime web apps and are shown for completeness.

Response

200 - application/json

Success

id
string<uuid>
required
Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
orgId
string<uuid>
required
Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
name
string
required
permissions
enum<string>[]
required
Available options:
self:read,
self:write,
employee:read,
employee:write,
team:read,
location:read,
location:write,
department:read,
department:write,
settings:read,
settings:write,
role:read,
role:write,
attendance:read,
attendance:punch,
attendance:write,
leave:read,
leave:write,
leave:approve,
leave:config,
pay:read,
payroll:read,
payroll:write,
compliance:read,
compliance:write,
integration:read,
integration:write,
report:read,
report:write,
shift:read,
shift:write,
roster:read,
roster:write,
roster:publish,
holiday:read,
holiday:write,
swap:read,
swap:write,
swap:approve,
regularization:read,
regularization:write,
regularization:approve,
document:read,
document:write,
device:read,
device:write,
audit:read,
notification:read,
message:write,
overtime:request,
overtime:approve,
hr:approve,
api:manage
isPreset
boolean
required
employeeCount
integer
required
Required range: -9007199254740991 <= x <= 9007199254740991