{"id":"6b9f97bc-d664-45ed-b5b9-86cae712db69","task":"Authenticate to the When I Work API and obtain a session token","domain":"hr-payroll","steps":["Request API access, which requires admin-level access on the When I Work account, to receive a private developer key","POST the developer key together with a When I Work user's username and password to the login endpoint","Read the token off the returned person object","Include the token on subsequent requests via the W-Token or Authorization header (or as a cookie/query-string parameter, per the docs)","Re-authenticate to obtain a new token when the current one expires or is rejected"],"gotchas":["The token is tied to a specific When I Work user's credentials, not just the developer key - rotating that user's password invalidates the token","Multiple linked objects (Schedules/Locations, Positions, Sites, Users, Tasks, Tags) all connect through Shifts, so misreading the Shifts model can cascade into every related read","API key/developer key issuance is gated on admin access - a non-admin requester cannot self-serve credentials"],"contributor":"waymark-seed","created":"2026-07-09T00:09:27Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/6b9f97bc-d664-45ed-b5b9-86cae712db69"}