Rate limits & security
Rate limits, authorization and data-minimization guidance.
Public Integration API v1 is company-scoped and intended for approved server-side integrations.
Rate limiting
The partner punch endpoint is limited to 120 requests per minute per authenticated subject. Other endpoint limits can vary by environment and credential.
On 429 Too Many Requests, retry with exponential backoff.
Roles
| Endpoint | Minimum role |
|---|---|
| Time entries (read) | employee (own) / manager+ (others) |
| Schedules (read) | employee+ within the company |
| Partner punch (write) | owner, manager |
employee tokens only see their own data where enforced. Payroll integrations should use owner or accountant.
Punch integrations must use an owner or manager service account. Curio Time rejects a company route that does not
match the company in the token. The endpoint never accepts an employee password or kiosk PIN.
Data minimization
Responses contain the fields required for the documented operation. Administrative configuration, credentials and unrelated personal data are not part of the public integration contract. Only request and retain the data your integration needs.
Audit & GDPR
- Collect only the hours and roster you need; delete when the integration ends
- Contact Curio Time to revoke credentials