# Time-control reports

Report settings and monthly absence reports use the webhook owner's or OAuth session user's permissions. Bitrix24 enforces access. Employee IP addresses are personal data; they are returned with the visibility and values allowed by Bitrix24.

| Method | Path | Bitrix24 method |
| --- | --- | --- |
| GET | `/v1/workday/time-control/report-settings` | timeman.timecontrol.reports.settings.get |
| GET | `/v1/workday/time-control/reports` | timeman.timecontrol.reports.get |

Required report query: `userId`, `month` (1-12), `year`. Optional: `idleMinutes`, `workdayHours`. Bitrix24 only honors `idleMinutes` for a head; other callers have it silently ignored. Bitrix24 converts thresholds to integers, nonpositive workday hours to 1, and years outside 1900-3000 to the current year. Empty data yields an empty `report.days`. `report-settings` returns `active`, `userId`, `userAdmin`, `userHead`, `departments`, `minimumIdleForReport`, `reportViewType`. Response names use camelCase, including `ipStart`, `ipFinish`.

```bash
curl -H "X-Api-Key: YOUR_API_KEY" "https://vibecode.bitrix24.com/v1/workday/time-control/reports?userId=101&month=10&year=2026"
```

## Access and errors

Key scope: `timeman`. Bitrix24 enforces user permissions. 400 INVALID_PARAMS means invalid input; 403 means missing scope or Bitrix24 permissions; writes with a READONLY key return 403 WRITE_BLOCKED_READONLY_KEY; 409 TIMEMAN_MODULE_NOT_ENABLED means unavailable Time Management; 422 BITRIX_ERROR forwards a Bitrix24 business refusal with its text. Webhook credentials are scrubbed from responses.

[All endpoints](/docs/workday/endpoints)
