Endpoints
457 endpoints across 86 controllers. This is the internals view: which permission gates a route and which controller, service and tables sit behind it. For request and response shapes, use the API reference, which is generated from the OpenAPI spec of a running backend.
Access
| Access | Endpoints | Meaning |
|---|---|---|
| Permission | 403 | Carries @PreAuthorize; the token must also hold the named permission |
| Authenticated | 40 | No @PreAuthorize, so .anyRequest().authenticated() applies — a valid token, any permissions |
| Public | 14 | Matched by PUBLIC_ENDPOINTS in SecurityConfiguration; reachable with no token at all |
caution
An endpoint without @PreAuthorize is not an open endpoint. The filter chain ends in .anyRequest().authenticated(), so it still needs a valid token — only the 14 rows marked Public are reachable without one.
Controllers
Every endpoint
| Method | Path | Requires | Controller |
|---|---|---|---|
GET | /api/admin/tenants | Any authenticated user | TenantAdminController |
POST | /api/admin/tenants | Any authenticated user | TenantAdminController |
GET | /api/admin/tenants/{id} | Any authenticated user | TenantAdminController |
PUT | /api/admin/tenants/{id} | Any authenticated user | TenantAdminController |
PATCH | /api/admin/tenants/{id}/reactivate | Any authenticated user | TenantAdminController |
POST | /api/admin/tenants/{id}/repair | Any authenticated user | TenantAdminController |
PATCH | /api/admin/tenants/{id}/suspend | Any authenticated user | TenantAdminController |
GET | /api/announcements | Any authenticated user | AnnouncementController |
POST | /api/announcements | hr.announcements.manage or system.admin.announcements.manage | AnnouncementController |
DELETE | /api/announcements/{id} | hr.announcements.manage or system.admin.announcements.manage | AnnouncementController |
GET | /api/announcements/{id} | Any authenticated user | AnnouncementController |
PUT | /api/announcements/{id} | hr.announcements.manage or system.admin.announcements.manage | AnnouncementController |
PATCH | /api/announcements/{id}/archive | hr.announcements.manage or system.admin.announcements.manage | AnnouncementController |
PATCH | /api/announcements/{id}/restore | hr.announcements.manage or system.admin.announcements.manage | AnnouncementController |
GET | /api/audit-logs | system.admin.logs.view | AuditLogController |
POST | /api/auth/change-password | Any authenticated user | AuthController |
POST | /api/auth/login | Public — no authentication | AuthController |
POST | /api/auth/logout | Public — no authentication | AuthController |
GET | /api/auth/me | Any authenticated user | AuthController |
POST | /api/auth/refresh | Public — no authentication | AuthController |
POST | /api/billing/checkout | system.admin.billing.manage | BillingController |
GET | /api/billing/subscription | system.admin.billing.manage | BillingController |
GET | /api/bonuses | payroll.bonus.manage | BonusController |
POST | /api/bonuses | payroll.bonus.manage | BonusController |
DELETE | /api/bonuses/{id} | payroll.bonus.manage | BonusController |
GET | /api/bonuses/{id} | payroll.bonus.manage | BonusController |
PUT | /api/bonuses/{id} | payroll.bonus.manage | BonusController |
GET | /api/bonuses/tax-preview | payroll.bonus.manage | BonusController |
GET | /api/certificate-templates | payroll.settings.manage | CertificateTemplateController |
POST | /api/certificate-templates | payroll.settings.manage | CertificateTemplateController |
DELETE | /api/certificate-templates/{id} | payroll.settings.manage | CertificateTemplateController |
PUT | /api/certificate-templates/{id} | payroll.settings.manage | CertificateTemplateController |
PUT | /api/certificate-templates/{id}/activate | payroll.settings.manage | CertificateTemplateController |
PUT | /api/certificate-templates/{id}/deactivate | payroll.settings.manage | CertificateTemplateController |
GET | /api/certificate-templates/designs | payroll.settings.manage | CertificateTemplateController |
POST | /api/certificate-templates/preview | payroll.settings.manage | CertificateTemplateController |
GET | /api/company-profile | isAuthenticated() — any authenticated user | CompanyProfileController |
PUT | /api/company-profile | payroll.manage | CompanyProfileController |
GET | /api/conversations/{id} | employee.messages.view | ConversationController |
GET | /api/conversations/{id}/messages | employee.messages.view | ConversationController |
GET | /api/conversations/{id}/messages/cursor | employee.messages.view | ConversationController |
GET | /api/conversations/me | employee.messages.view | ConversationController |
POST | /api/conversations/messages | employee.messages.view | ConversationController |
GET | /api/crm/activities | crm.view | CrmActivityController |
POST | /api/crm/activities | crm.activities.manage | CrmActivityController |
DELETE | /api/crm/activities/{id} | crm.activities.manage | CrmActivityController |
GET | /api/crm/activities/{id} | crm.view | CrmActivityController |
PATCH | /api/crm/activities/{id}/complete | crm.activities.manage | CrmActivityController |
GET | /api/crm/contacts | crm.view | CrmContactController |
POST | /api/crm/contacts | crm.contacts.manage | CrmContactController |
DELETE | /api/crm/contacts/{id} | crm.contacts.manage | CrmContactController |
GET | /api/crm/contacts/{id} | crm.view | CrmContactController |
PUT | /api/crm/contacts/{id} | crm.contacts.manage | CrmContactController |
GET | /api/crm/contacts/by-org/{orgId} | crm.view | CrmContactController |
GET | /api/crm/deals | crm.view | CrmDealController |
POST | /api/crm/deals | crm.deals.manage | CrmDealController |
DELETE | /api/crm/deals/{id} | crm.deals.manage | CrmDealController |
GET | /api/crm/deals/{id} | crm.view | CrmDealController |
PUT | /api/crm/deals/{id} | crm.deals.manage | CrmDealController |
GET | /api/crm/deals/{id}/activities | crm.view | CrmDealController |
GET | /api/crm/deals/{id}/notes | crm.view | CrmDealController |
POST | /api/crm/deals/{id}/notes | crm.activities.manage | CrmDealController |
PATCH | /api/crm/deals/{id}/stage | crm.deals.manage | CrmDealController |
GET | /api/crm/deals/analytics | crm.reports.view | CrmDealController |
GET | /api/crm/deals/pipeline | crm.view | CrmDealController |
GET | /api/crm/leads | crm.view | CrmLeadController |
POST | /api/crm/leads | crm.leads.manage | CrmLeadController |
DELETE | /api/crm/leads/{id} | crm.leads.manage | CrmLeadController |
GET | /api/crm/leads/{id} | crm.view | CrmLeadController |
PUT | /api/crm/leads/{id} | crm.leads.manage | CrmLeadController |
POST | /api/crm/leads/{id}/convert | crm.deals.manage | CrmLeadController |
PATCH | /api/crm/leads/{id}/status | crm.leads.manage | CrmLeadController |
GET | /api/crm/organizations | crm.view | CrmOrganizationController |
POST | /api/crm/organizations | crm.contacts.manage | CrmOrganizationController |
DELETE | /api/crm/organizations/{id} | crm.contacts.manage | CrmOrganizationController |
GET | /api/crm/organizations/{id} | crm.view | CrmOrganizationController |
PUT | /api/crm/organizations/{id} | crm.contacts.manage | CrmOrganizationController |
GET | /api/crm/picklists | crm.settings.manage or crm.view | CrmPicklistController |
POST | /api/crm/picklists | crm.settings.manage | CrmPicklistController |
DELETE | /api/crm/picklists/{id} | crm.settings.manage | CrmPicklistController |
PUT | /api/crm/picklists/{id} | crm.settings.manage | CrmPicklistController |
GET | /api/crm/settings | crm.settings.manage or crm.view | CrmSettingsController |
PUT | /api/crm/settings | crm.settings.manage | CrmSettingsController |
GET | /api/crm/settings/changes | crm.settings.manage | CrmSettingsController |
GET | /api/de-minimis-benefit-types | payroll.settings.manage or payroll.manage | DeMinimisBenefitTypeController |
POST | /api/de-minimis-benefit-types | payroll.settings.manage | DeMinimisBenefitTypeController |
DELETE | /api/de-minimis-benefit-types/{id} | payroll.settings.manage | DeMinimisBenefitTypeController |
PUT | /api/de-minimis-benefit-types/{id} | payroll.settings.manage | DeMinimisBenefitTypeController |
GET | /api/deduction-types | payroll.deduction.manage | DeductionTypeController |
POST | /api/deduction-types | payroll.deduction.manage | DeductionTypeController |
DELETE | /api/deduction-types/{id} | payroll.deduction.manage | DeductionTypeController |
PUT | /api/deduction-types/{id} | payroll.deduction.manage | DeductionTypeController |
GET | /api/departments | hr.employees.view | DepartmentController |
POST | /api/departments | hr.employees.manage | DepartmentController |
DELETE | /api/departments/{id} | hr.employees.manage | DepartmentController |
GET | /api/departments/{id} | hr.employees.view | DepartmentController |
PUT | /api/departments/{id} | hr.employees.manage | DepartmentController |
PATCH | /api/departments/{id}/archive | hr.employees.manage | DepartmentController |
PATCH | /api/departments/{id}/restore | hr.employees.manage | DepartmentController |
GET | /api/departments/search | hr.employees.view | DepartmentController |
GET | /api/employee-deductions | payroll.deduction.manage | EmployeeDeductionController |
POST | /api/employee-deductions | payroll.deduction.manage | EmployeeDeductionController |
DELETE | /api/employee-deductions/{id} | payroll.deduction.manage | EmployeeDeductionController |
GET | /api/employee-deductions/{id} | payroll.deduction.manage | EmployeeDeductionController |
PUT | /api/employee-deductions/{id} | payroll.deduction.manage | EmployeeDeductionController |
GET | /api/employees | hr.employees.view | EmployeeController |
POST | /api/employees | hr.employees.create | EmployeeController |
GET | /api/employees/{id} | hr.employees.view | EmployeeController |
PUT | /api/employees/{id} | hr.employees.edit | EmployeeController |
PATCH | /api/employees/{id}/archive | hr.employees.delete | EmployeeController |
PATCH | /api/employees/{id}/restore | hr.employees.delete | EmployeeController |
PATCH | /api/employees/{id}/status | hr.employees.delete | EmployeeController |
GET | /api/employees/me | employee.profile.view | EmployeeController |
PATCH | /api/employees/me | employee.profile.view | EmployeeController |
GET | /api/ewt-payees | payroll.ewt.manage | EwtController |
POST | /api/ewt-payees | payroll.ewt.manage | EwtController |
DELETE | /api/ewt-payees/{id} | payroll.ewt.manage | EwtController |
PUT | /api/ewt-payees/{id} | payroll.ewt.manage | EwtController |
GET | /api/ewt-transactions | payroll.ewt.manage | EwtController |
POST | /api/ewt-transactions | payroll.ewt.manage | EwtController |
DELETE | /api/ewt-transactions/{id} | payroll.ewt.manage | EwtController |
PUT | /api/ewt-transactions/{id} | payroll.ewt.manage | EwtController |
GET | /api/government-filings | hr.employees.view or payroll.manage | GovernmentFilingController |
POST | /api/government-filings | payroll.manage | GovernmentFilingController |
DELETE | /api/government-filings/{id} | payroll.manage | GovernmentFilingController |
GET | /api/government-filings/{id}/receipt | hr.employees.view or payroll.manage | GovernmentFilingController |
GET | /api/government-forms/alphalist-dat | hr.employees.view or payroll.manage | GovernmentFormsController |
GET | /api/government-forms/bir-1601c | hr.employees.view or payroll.manage | GovernmentFormsController |
GET | /api/government-forms/bir-2316 | hr.employees.view or payroll.manage | GovernmentFormsController |
GET | /api/government-forms/dole-thirteenth-month | hr.employees.view or payroll.manage | GovernmentFormsController |
GET | /api/government-forms/dtr | hr.employees.view or payroll.manage | GovernmentFormsController |
GET | /api/government-forms/ewt/0619e | payroll.ewt.manage | EwtFormsController |
GET | /api/government-forms/ewt/1601eq | payroll.ewt.manage | EwtFormsController |
GET | /api/government-forms/ewt/2307 | payroll.ewt.manage | EwtFormsController |
GET | /api/government-forms/ewt/2307/payees | payroll.ewt.manage | EwtFormsController |
GET | /api/government-forms/payroll-register | hr.employees.view or payroll.manage | GovernmentFormsController |
GET | /api/government-forms/remittance | hr.employees.view or payroll.manage | GovernmentFormsController |
GET | /api/government-forms/thirteenth-month | hr.employees.view or payroll.manage | GovernmentFormsController |
GET | /api/holidays | payroll.holidays.manage or payroll.manage or employee.holidays.view | PhHolidayController |
POST | /api/holidays | payroll.holidays.manage | PhHolidayController |
DELETE | /api/holidays/{id} | payroll.holidays.manage | PhHolidayController |
PUT | /api/holidays/{id} | payroll.holidays.manage | PhHolidayController |
POST | /api/holidays/generate | payroll.holidays.manage | PhHolidayController |
DELETE | /api/interview-feedback/{id} | hr.recruitment.interview.manage | InterviewFeedbackController |
PUT | /api/interview-feedback/{id} | hr.recruitment.interview.manage | InterviewFeedbackController |
GET | /api/interview-schedules | hr.recruitment.view | InterviewScheduleController |
POST | /api/interview-schedules | hr.recruitment.interview.manage | InterviewScheduleController |
DELETE | /api/interview-schedules/{id} | hr.recruitment.interview.manage | InterviewScheduleController |
GET | /api/interview-schedules/{id} | hr.recruitment.view | InterviewScheduleController |
PUT | /api/interview-schedules/{id} | hr.recruitment.interview.manage | InterviewScheduleController |
GET | /api/interview-schedules/{id}/feedback | hr.recruitment.view | InterviewScheduleController |
POST | /api/interview-schedules/{id}/feedback | hr.recruitment.interview.manage | InterviewScheduleController |
PATCH | /api/interview-schedules/{id}/status | hr.recruitment.interview.manage | InterviewScheduleController |
GET | /api/inventory/categories | inventory.items.view | InventoryController |
POST | /api/inventory/categories | inventory.items.manage | InventoryController |
DELETE | /api/inventory/categories/{id} | inventory.items.manage | InventoryController |
PUT | /api/inventory/categories/{id} | inventory.items.manage | InventoryController |
GET | /api/inventory/dashboard | inventory.dashboard.view | InventoryController |
GET | /api/inventory/items | inventory.items.view | InventoryController |
POST | /api/inventory/items | inventory.items.manage | InventoryController |
DELETE | /api/inventory/items/{id} | inventory.items.manage | InventoryController |
GET | /api/inventory/items/{id} | inventory.items.view | InventoryController |
PUT | /api/inventory/items/{id} | inventory.items.manage | InventoryController |
GET | /api/inventory/items/{id}/barcode | inventory.items.view | BarcodeController |
GET | /api/inventory/items/{itemId}/prices | inventory.prices.view | ItemPriceController |
GET | /api/inventory/items/sku/{sku} | inventory.items.view | InventoryController |
GET | /api/inventory/locations | inventory.locations.view | InventoryController |
POST | /api/inventory/locations | inventory.locations.manage | InventoryController |
DELETE | /api/inventory/locations/{id} | inventory.locations.manage | InventoryController |
PUT | /api/inventory/locations/{id} | inventory.locations.manage | InventoryController |
PATCH | /api/inventory/locations/{id}/deactivate | inventory.locations.manage | InventoryController |
GET | /api/inventory/lots | inventory.serials.view | SerialLotController |
POST | /api/inventory/lots | inventory.serials.manage | SerialLotController |
GET | /api/inventory/orders | inventory.orders.view | OrderController |
POST | /api/inventory/orders | inventory.orders.manage | OrderController |
DELETE | /api/inventory/orders/{id} | inventory.orders.manage | OrderController |
GET | /api/inventory/orders/{id} | inventory.orders.view | OrderController |
PUT | /api/inventory/orders/{id} | inventory.orders.manage | OrderController |
POST | /api/inventory/orders/{id}/advance | inventory.orders.manage | OrderController |
GET | /api/inventory/prices | inventory.prices.view | ItemPriceController |
POST | /api/inventory/prices | inventory.prices.manage | ItemPriceController |
DELETE | /api/inventory/prices/{priceId} | inventory.prices.manage | ItemPriceController |
PUT | /api/inventory/prices/{priceId} | inventory.prices.manage | ItemPriceController |
GET | /api/inventory/prices/history | inventory.prices.view | ItemPriceController |
GET | /api/inventory/profit/costing-method | inventory.profit.view | ProfitController |
PUT | /api/inventory/profit/costing-method | inventory.profit.manage | ProfitController |
GET | /api/inventory/profit/summary | inventory.profit.view | ProfitController |
GET | /api/inventory/receiving | inventory.receiving.view | InventoryController |
POST | /api/inventory/receiving | inventory.receiving.manage | InventoryController |
GET | /api/inventory/receiving/{id} | inventory.receiving.view | InventoryController |
PATCH | /api/inventory/receiving/{id}/cancel | inventory.receiving.manage | InventoryController |
PATCH | /api/inventory/receiving/{id}/complete | inventory.receiving.manage | InventoryController |
GET | /api/inventory/reports/ledger | inventory.reports.view | InventoryReportController |
GET | /api/inventory/reports/movement-summary | inventory.reports.view | InventoryReportController |
GET | /api/inventory/reports/valuation | inventory.reports.view | InventoryReportController |
GET | /api/inventory/serials | inventory.serials.view | SerialLotController |
POST | /api/inventory/serials | inventory.serials.manage | SerialLotController |
PATCH | /api/inventory/serials/{id}/status | inventory.serials.manage | SerialLotController |
GET | /api/inventory/stock | inventory.stock.view | InventoryController |
GET | /api/inventory/stock/low | inventory.stock.view | InventoryController |
GET | /api/inventory/stock/transactions | inventory.stock.view | InventoryController |
POST | /api/inventory/stock/transactions | inventory.stock.manage | InventoryController |
GET | /api/inventory/stores | inventory.stores.view | StoreController |
POST | /api/inventory/stores | inventory.stores.manage | StoreController |
DELETE | /api/inventory/stores/{id} | inventory.stores.manage | StoreController |
GET | /api/inventory/stores/{id} | inventory.stores.view | StoreController |
PUT | /api/inventory/stores/{id} | inventory.stores.manage | StoreController |
GET | /api/inventory/stores/{id}/inventory | inventory.stores.view | StoreController |
PUT | /api/inventory/stores/{id}/inventory/{itemId} | inventory.stores.manage | StoreController |
GET | /api/inventory/suppliers | inventory.suppliers.view | InventoryController |
POST | /api/inventory/suppliers | inventory.suppliers.manage | InventoryController |
DELETE | /api/inventory/suppliers/{id} | inventory.suppliers.manage | InventoryController |
GET | /api/inventory/suppliers/{id} | inventory.suppliers.view | InventoryController |
PUT | /api/inventory/suppliers/{id} | inventory.suppliers.manage | InventoryController |
GET | /api/inventory/transfers | inventory.transfers.view | WarehouseTransferController |
POST | /api/inventory/transfers | inventory.transfers.manage | WarehouseTransferController |
GET | /api/inventory/warehouses | inventory.locations.view | InventoryController |
POST | /api/inventory/warehouses | inventory.locations.manage | InventoryController |
DELETE | /api/inventory/warehouses/{id} | inventory.locations.manage | InventoryController |
GET | /api/inventory/warehouses/{id} | inventory.locations.view | InventoryController |
PUT | /api/inventory/warehouses/{id} | inventory.locations.manage | InventoryController |
GET | /api/inventory/warehouses/{id}/location-tree | inventory.locations.view | InventoryController |
GET | /api/inventory/warehouses/{id}/stock-by-location | inventory.locations.view | InventoryController |
GET | /api/inventory/warehouses/{warehouseId}/locations | inventory.locations.view | InventoryController |
GET | /api/job-applicants | hr.recruitment.view | JobApplicantController |
POST | /api/job-applicants | hr.recruitment.manage | JobApplicantController |
DELETE | /api/job-applicants/{id} | hr.recruitment.manage | JobApplicantController |
GET | /api/job-applicants/{id} | hr.recruitment.view | JobApplicantController |
PUT | /api/job-applicants/{id} | hr.recruitment.manage | JobApplicantController |
GET | /api/job-applicants/{id}/match-score | hr.recruitment.view | JobApplicantController |
DELETE | /api/job-applicants/{id}/resume | hr.recruitment.manage | JobApplicantController |
GET | /api/job-applicants/{id}/resume | hr.recruitment.view | JobApplicantController |
POST | /api/job-applicants/{id}/resume | hr.recruitment.manage | JobApplicantController |
PATCH | /api/job-applicants/{id}/status | hr.recruitment.manage | JobApplicantController |
GET | /api/job-applicants/pipeline | hr.recruitment.view | JobApplicantController |
GET | /api/job-offers | hr.recruitment.view | JobOfferController |
POST | /api/job-offers | hr.recruitment.offer.manage | JobOfferController |
DELETE | /api/job-offers/{id} | hr.recruitment.offer.manage | JobOfferController |
GET | /api/job-offers/{id} | hr.recruitment.view | JobOfferController |
PATCH | /api/job-offers/{id}/hiring-details | hr.recruitment.offer.manage | JobOfferController |
PATCH | /api/job-offers/{id}/status | hr.recruitment.offer.manage | JobOfferController |
GET | /api/job-openings | hr.recruitment.view | JobOpeningController |
POST | /api/job-openings | hr.recruitment.manage | JobOpeningController |
DELETE | /api/job-openings/{id} | hr.recruitment.manage | JobOpeningController |
GET | /api/job-openings/{id} | hr.recruitment.view | JobOpeningController |
PUT | /api/job-openings/{id} | hr.recruitment.manage | JobOpeningController |
PATCH | /api/job-openings/{id}/status | hr.recruitment.manage | JobOpeningController |
GET | /api/job-requisitions | hr.recruitment.view | JobRequisitionController |
POST | /api/job-requisitions | hr.recruitment.manage | JobRequisitionController |
DELETE | /api/job-requisitions/{id} | hr.recruitment.manage | JobRequisitionController |
GET | /api/job-requisitions/{id} | hr.recruitment.view | JobRequisitionController |
PUT | /api/job-requisitions/{id} | hr.recruitment.manage | JobRequisitionController |
PATCH | /api/job-requisitions/{id}/archive | hr.recruitment.manage | JobRequisitionController |
PATCH | /api/job-requisitions/{id}/restore | hr.recruitment.manage | JobRequisitionController |
PATCH | /api/job-requisitions/{id}/status | hr.recruitment.manage | JobRequisitionController |
GET | /api/leave-balances/me | employee.leave.balance.view | LeaveBalanceController |
GET | /api/leave-requests | hr.leave.requests.view | LeaveRequestController |
POST | /api/leave-requests | employee.leave.request | LeaveRequestController |
DELETE | /api/leave-requests/{id} | employee.leave.request | LeaveRequestController |
GET | /api/leave-requests/{id} | hr.leave.requests.view | LeaveRequestController |
POST | /api/leave-requests/{id}/approve | hr.leave.requests.approve | LeaveRequestController |
POST | /api/leave-requests/{id}/reject | hr.leave.requests.reject | LeaveRequestController |
GET | /api/leave-requests/me | employee.leave.history.view | LeaveRequestController |
GET | /api/leave-types | employee.leave.request or hr.leave.requests.view | LeaveTypeController |
PATCH | /api/notifications/{id}/read | employee.notifications.view | NotificationController |
GET | /api/notifications/me | employee.notifications.view | NotificationController |
PATCH | /api/notifications/me/read-all | employee.notifications.view | NotificationController |
GET | /api/overtime-requests | hr.overtime.requests.view or payroll.overtime.approve | OvertimeRequestController |
POST | /api/overtime-requests | employee.overtime.request | OvertimeRequestController |
DELETE | /api/overtime-requests/{id} | employee.overtime.request | OvertimeRequestController |
GET | /api/overtime-requests/{id} | hr.overtime.requests.view or payroll.overtime.approve | OvertimeRequestController |
PUT | /api/overtime-requests/{id} | employee.overtime.request | OvertimeRequestController |
PATCH | /api/overtime-requests/{id}/decision | hr.overtime.requests.approve or payroll.overtime.approve | OvertimeRequestController |
GET | /api/overtime-requests/me | employee.overtime.request | OvertimeRequestController |
GET | /api/pagibig-contribution-rates | payroll.pagibig.rates.manage | PagibigContributionRateController |
POST | /api/pagibig-contribution-rates | Any authenticated user | PagibigContributionRateController |
DELETE | /api/pagibig-contribution-rates/{id} | Any authenticated user | PagibigContributionRateController |
GET | /api/pagibig-contribution-rates/{id} | payroll.pagibig.rates.manage | PagibigContributionRateController |
PUT | /api/pagibig-contribution-rates/{id} | Any authenticated user | PagibigContributionRateController |
PUT | /api/pagibig-contribution-rates/cohorts | Any authenticated user | PagibigContributionRateController |
POST | /api/pagibig-contribution-rates/cohorts/duplicate | Any authenticated user | PagibigContributionRateController |
GET | /api/pagibig-contribution-rates/effective-dates | payroll.pagibig.rates.manage | PagibigContributionRateController |
GET | /api/payroll | payroll.dashboard.view or payroll.manage or payroll.approve | PayrollController |
POST | /api/payroll | payroll.manage | PayrollController |
GET | /api/payroll-changes | payroll.dashboard.view or payroll.manage or payroll.approve | PayrollChangesController |
GET | /api/payroll-settings | payroll.settings.manage or payroll.manage or payroll.ewt.manage or hr.employees.manage | PayrollSettingsController |
PUT | /api/payroll-settings | payroll.settings.manage | PayrollSettingsController |
GET | /api/payroll-settings-changes | payroll.settings.manage | PayrollSettingsChangesController |
GET | /api/payroll-settings/compliance-checklist | payroll.settings.manage | PayrollSettingsController |
GET | /api/payroll-settings/employee-view | isAuthenticated() — any authenticated user | PayrollSettingsController |
GET | /api/payroll-transactions | payroll.transactions.view or payroll.transactions.manage | PayrollTransactionController |
POST | /api/payroll-transactions | payroll.transactions.manage | PayrollTransactionController |
DELETE | /api/payroll-transactions/{id} | payroll.transactions.manage | PayrollTransactionController |
GET | /api/payroll-transactions/{id} | payroll.transactions.view or payroll.transactions.manage | PayrollTransactionController |
PUT | /api/payroll-transactions/{id} | payroll.transactions.manage | PayrollTransactionController |
GET | /api/payroll-transactions/types | payroll.transactions.view or payroll.transactions.manage | PayrollTransactionController |
DELETE | /api/payroll/{id} | payroll.manage | PayrollController |
GET | /api/payroll/{id} | payroll.dashboard.view or payroll.manage or payroll.approve | PayrollController |
PATCH | /api/payroll/{id}/decision | payroll.approve | PayrollController |
POST | /api/payroll/{id}/generate-payslips | payroll.manage | PayrollController |
PATCH | /api/payroll/{id}/status | payroll.manage | PayrollController |
GET | /api/payroll/next-period | payroll.manage | PayrollController |
GET | /api/payslip-history | payroll.payslip.view or payroll.manage or payroll.approve | PayslipHistoryController |
GET | /api/payslip-template-settings | isAuthenticated() — any authenticated user | PayslipTemplateSettingsController |
PUT | /api/payslip-template-settings | payroll.settings.manage | PayslipTemplateSettingsController |
GET | /api/payslip-templates | payroll.settings.manage | PayslipTemplateController |
POST | /api/payslip-templates | payroll.settings.manage | PayslipTemplateController |
DELETE | /api/payslip-templates/{id} | payroll.settings.manage | PayslipTemplateController |
PUT | /api/payslip-templates/{id} | payroll.settings.manage | PayslipTemplateController |
GET | /api/payslips | payroll.payslip.view or payroll.manage or payroll.approve | PayslipController |
GET | /api/payslips/{id} | payroll.payslip.view or payroll.manage or payroll.approve | PayslipController |
GET | /api/payslips/me | employee.payslip.view | PayslipController |
GET | /api/payslips/me/{id} | employee.payslip.view | PayslipController |
GET | /api/payslips/me/years | employee.payslip.view | PayslipController |
GET | /api/payslips/me/ytd | employee.payslip.view | PayslipController |
GET | /api/permissions | system.admin.permissions.view | PermissionController |
POST | /api/permissions | system.admin.permissions.create | PermissionController |
DELETE | /api/permissions/{id} | system.admin.permissions.delete | PermissionController |
GET | /api/permissions/{id} | system.admin.permissions.view | PermissionController |
PUT | /api/permissions/{id} | system.admin.permissions.edit | PermissionController |
GET | /api/philhealth-contribution-rates | payroll.philhealth.rates.manage | PhilhealthContributionRateController |
POST | /api/philhealth-contribution-rates | Any authenticated user | PhilhealthContributionRateController |
DELETE | /api/philhealth-contribution-rates/{id} | Any authenticated user | PhilhealthContributionRateController |
GET | /api/philhealth-contribution-rates/{id} | payroll.philhealth.rates.manage | PhilhealthContributionRateController |
PUT | /api/philhealth-contribution-rates/{id} | Any authenticated user | PhilhealthContributionRateController |
PUT | /api/philhealth-contribution-rates/cohorts | Any authenticated user | PhilhealthContributionRateController |
POST | /api/philhealth-contribution-rates/cohorts/duplicate | Any authenticated user | PhilhealthContributionRateController |
GET | /api/philhealth-contribution-rates/effective-dates | payroll.philhealth.rates.manage | PhilhealthContributionRateController |
GET | /api/portal/admin/orders | inventory.portal.manage | PortalAdminController |
GET | /api/portal/admin/orders/{orderId} | inventory.portal.manage | PortalAdminController |
PUT | /api/portal/admin/orders/{orderId}/shipment | inventory.portal.manage | PortalAdminController |
POST | /api/portal/auth/login | Public — no authentication | PortalAuthController |
POST | /api/portal/auth/register | Public — no authentication | PortalAuthController |
GET | /api/portal/catalog/categories | PORTAL_CUSTOMER | PortalCatalogController |
GET | /api/portal/catalog/items | PORTAL_CUSTOMER | PortalCatalogController |
GET | /api/portal/catalog/items/{itemId} | PORTAL_CUSTOMER | PortalCatalogController |
GET | /api/portal/orders | PORTAL_CUSTOMER | PortalOrderController |
POST | /api/portal/orders | PORTAL_CUSTOMER | PortalOrderController |
DELETE | /api/portal/orders/{orderId} | PORTAL_CUSTOMER | PortalOrderController |
GET | /api/portal/orders/{orderId} | PORTAL_CUSTOMER | PortalOrderController |
GET | /api/portal/profile | PORTAL_CUSTOMER | PortalProfileController |
PATCH | /api/portal/profile | PORTAL_CUSTOMER | PortalProfileController |
POST | /api/portal/profile/change-password | PORTAL_CUSTOMER | PortalProfileController |
GET | /api/positions | hr.employees.view | PositionController |
POST | /api/positions | hr.employees.manage | PositionController |
DELETE | /api/positions/{id} | hr.employees.manage | PositionController |
GET | /api/positions/{id} | hr.employees.view | PositionController |
PUT | /api/positions/{id} | hr.employees.manage | PositionController |
PATCH | /api/positions/{id}/archive | hr.employees.manage | PositionController |
PATCH | /api/positions/{id}/restore | hr.employees.manage | PositionController |
GET | /api/positions/search | hr.employees.view | PositionController |
GET | /api/public/altcha/challenge | Public — no authentication | PublicAltchaController |
GET | /api/public/billing/checkout-links | Public — no authentication | PublicBillingController |
GET | /api/public/chatwoot | Public — no authentication | PublicChatwootController |
POST | /api/public/job-applications | Public — no authentication | PublicJobController |
GET | /api/public/job-openings | Public — no authentication | PublicJobController |
GET | /api/public/job-openings/{id} | Public — no authentication | PublicJobController |
POST | /api/public/signup | Public — no authentication | PublicSignupController |
POST | /api/public/signup/verify | Public — no authentication | PublicSignupController |
DELETE | /api/recognition-awards | payroll.manage | RecognitionAwardController |
GET | /api/recognition-awards | payroll.payslip.view or payroll.manage or payroll.approve | RecognitionAwardController |
GET | /api/recognition-awards/{id}/certificate | payroll.payslip.view or payroll.manage or payroll.approve | RecognitionAwardController |
POST | /api/recognition-awards/generate | payroll.manage | RecognitionAwardController |
GET | /api/recognition-awards/me | employee.payslip.view | RecognitionAwardController |
GET | /api/recognition-awards/me/{id}/certificate | employee.payslip.view | RecognitionAwardController |
GET | /api/recognition-awards/zip | payroll.payslip.view or payroll.manage or payroll.approve | RecognitionAwardController |
GET | /api/reimbursement-requests | payroll.reimbursement.manage | ReimbursementRequestController |
POST | /api/reimbursement-requests | employee.reimbursement.request | ReimbursementRequestController |
DELETE | /api/reimbursement-requests/{id} | employee.reimbursement.request | ReimbursementRequestController |
GET | /api/reimbursement-requests/{id} | payroll.reimbursement.manage | ReimbursementRequestController |
PUT | /api/reimbursement-requests/{id} | employee.reimbursement.request | ReimbursementRequestController |
PATCH | /api/reimbursement-requests/{id}/decision | payroll.reimbursement.manage | ReimbursementRequestController |
GET | /api/reimbursement-requests/me | employee.reimbursement.request | ReimbursementRequestController |
GET | /api/reimbursement-transactions | payroll.reimbursement.transactions.view or payroll.reimbursement.transactions.manage | ReimbursementTransactionController |
POST | /api/reimbursement-transactions | payroll.reimbursement.transactions.manage | ReimbursementTransactionController |
DELETE | /api/reimbursement-transactions/{id} | payroll.reimbursement.transactions.manage | ReimbursementTransactionController |
GET | /api/reimbursement-transactions/{id} | payroll.reimbursement.transactions.view or payroll.reimbursement.transactions.manage | ReimbursementTransactionController |
PUT | /api/reimbursement-transactions/{id} | payroll.reimbursement.transactions.manage | ReimbursementTransactionController |
GET | /api/reimbursement-transactions/payment-methods | payroll.reimbursement.transactions.view or payroll.reimbursement.transactions.manage | ReimbursementTransactionController |
GET | /api/reports/bir-alphalist | hr.employees.view | ReportingController |
GET | /api/reports/headcount-by-department | hr.employees.view | ReportingController |
GET | /api/reports/hr-analytics/attendance-monthly | hr.dashboard.view | ReportingController |
GET | /api/reports/hr-analytics/drilldown | hr.dashboard.view | ReportingController |
GET | /api/reports/hr-analytics/headcount-movement | hr.dashboard.view | ReportingController |
GET | /api/reports/hr-analytics/leave | hr.dashboard.view | ReportingController |
GET | /api/reports/hr-analytics/leave-monthly | hr.dashboard.view | ReportingController |
GET | /api/reports/hr-analytics/overtime-by-department | hr.dashboard.view | ReportingController |
GET | /api/reports/hr-analytics/summary | hr.dashboard.view | ReportingController |
GET | /api/reports/hr-analytics/workforce | hr.dashboard.view | ReportingController |
GET | /api/reports/leave-by-status | hr.leave.requests.view | ReportingController |
GET | /api/reports/overtime-monthly | hr.overtime.requests.view or payroll.dashboard.view | ReportingController |
GET | /api/reports/payroll-monthly | payroll.dashboard.view or hr.employees.view | ReportingController |
GET | /api/reports/recruitment-summary | hr.recruitment.view | ReportingController |
GET | /api/reports/reimbursement-by-status | payroll.reimbursement.manage | ReportingController |
GET | /api/reports/year-end-tax-adjustment | hr.employees.view or payroll.manage | ReportingController |
GET | /api/roles | system.admin.roles.view | RoleController |
POST | /api/roles | system.admin.roles.create | RoleController |
DELETE | /api/roles/{id} | system.admin.roles.delete | RoleController |
GET | /api/roles/{id} | system.admin.roles.view | RoleController |
PUT | /api/roles/{id} | system.admin.roles.edit | RoleController |
PUT | /api/roles/{id}/permissions | system.admin.role.permissions.manage | RoleController |
GET | /api/saved-views | Any authenticated user | SavedViewController |
POST | /api/saved-views | Any authenticated user | SavedViewController |
DELETE | /api/saved-views/{id} | Any authenticated user | SavedViewController |
GET | /api/sss-contribution-rates | payroll.sss.rates.manage | SssContributionRateController |
POST | /api/sss-contribution-rates | Any authenticated user | SssContributionRateController |
DELETE | /api/sss-contribution-rates/{id} | Any authenticated user | SssContributionRateController |
GET | /api/sss-contribution-rates/{id} | payroll.sss.rates.manage | SssContributionRateController |
PUT | /api/sss-contribution-rates/{id} | Any authenticated user | SssContributionRateController |
PUT | /api/sss-contribution-rates/cohorts | Any authenticated user | SssContributionRateController |
POST | /api/sss-contribution-rates/cohorts/duplicate | Any authenticated user | SssContributionRateController |
GET | /api/sss-contribution-rates/effective-dates | payroll.sss.rates.manage | SssContributionRateController |
GET | /api/staffing-plans | hr.recruitment.staffing.manage | StaffingPlanController |
POST | /api/staffing-plans | hr.recruitment.staffing.manage | StaffingPlanController |
DELETE | /api/staffing-plans/{id} | hr.recruitment.staffing.manage | StaffingPlanController |
GET | /api/staffing-plans/{id} | hr.recruitment.staffing.manage | StaffingPlanController |
PUT | /api/staffing-plans/{id} | hr.recruitment.staffing.manage | StaffingPlanController |
POST | /api/staffing-plans/{id}/items | hr.recruitment.staffing.manage | StaffingPlanController |
DELETE | /api/staffing-plans/{id}/items/{itemId} | hr.recruitment.staffing.manage | StaffingPlanController |
POST | /api/system-admin/demo-data/generate | system.admin.demo.data.manage | DemoDataController |
POST | /api/system-admin/demo-data/reset | system.admin.demo.data.manage | DemoDataController |
GET | /api/system-admin/demo-data/status | system.admin.demo.data.manage | DemoDataController |
GET | /api/timesheets | hr.timesheets.view | TimesheetController |
POST | /api/timesheets | hr.timesheets.manage | TimesheetController |
DELETE | /api/timesheets/{id} | hr.timesheets.manage | TimesheetController |
GET | /api/timesheets/{id} | hr.timesheets.view | TimesheetController |
PUT | /api/timesheets/{id} | hr.timesheets.manage | TimesheetController |
PATCH | /api/timesheets/{id}/status | hr.timesheets.manage | TimesheetController |
POST | /api/timesheets/{id}/submit | employee.timesheet.view | TimesheetController |
POST | /api/timesheets/clock-in | employee.timesheet.view | TimesheetController |
POST | /api/timesheets/clock-out | employee.timesheet.view | TimesheetController |
GET | /api/timesheets/me | employee.timesheet.view | TimesheetController |
GET | /api/tin-compliance | payroll.tin.compliance.manage | TinComplianceController |
POST | /api/tin-compliance | payroll.tin.compliance.manage | TinComplianceController |
DELETE | /api/tin-compliance/{id} | payroll.tin.compliance.manage | TinComplianceController |
GET | /api/tin-compliance/{id} | payroll.tin.compliance.manage | TinComplianceController |
PUT | /api/tin-compliance/{id} | payroll.tin.compliance.manage | TinComplianceController |
DELETE | /api/user-nav-preference | Any authenticated user | UserNavPreferenceController |
GET | /api/user-nav-preference | Any authenticated user | UserNavPreferenceController |
PUT | /api/user-nav-preference | Any authenticated user | UserNavPreferenceController |
GET | /api/users | system.admin.users.view | UserController |
POST | /api/users | system.admin.users.create | UserController |
DELETE | /api/users/{id} | system.admin.users.delete | UserController |
GET | /api/users/{id} | system.admin.users.view | UserController |
PUT | /api/users/{id} | system.admin.users.edit | UserController |
POST | /api/webhooks/{provider} | Public — no authentication | BillingWebhookController |
GET | /api/withholding-tax-brackets | payroll.withholdingtax.rates.manage | WithholdingTaxBracketController |
POST | /api/withholding-tax-brackets | Any authenticated user | WithholdingTaxBracketController |
DELETE | /api/withholding-tax-brackets/{id} | Any authenticated user | WithholdingTaxBracketController |
GET | /api/withholding-tax-brackets/{id} | payroll.withholdingtax.rates.manage | WithholdingTaxBracketController |
PUT | /api/withholding-tax-brackets/{id} | Any authenticated user | WithholdingTaxBracketController |
PUT | /api/withholding-tax-brackets/cohorts | Any authenticated user | WithholdingTaxBracketController |
POST | /api/withholding-tax-brackets/cohorts/duplicate | Any authenticated user | WithholdingTaxBracketController |
GET | /api/withholding-tax-brackets/effective-dates | payroll.withholdingtax.rates.manage | WithholdingTaxBracketController |
GET | /api/work-suspensions | payroll.holidays.manage or payroll.manage | WorkSuspensionController |
POST | /api/work-suspensions | payroll.holidays.manage | WorkSuspensionController |
DELETE | /api/work-suspensions/{id} | payroll.holidays.manage | WorkSuspensionController |
Generated page
This page is rebuilt from the source on every docs build by docs-site/scripts/gen-code-wiki.mjs. Editing it has no effect — change the code, or, if what you want to say is prose, write it in docs/.