## Create a work report

`POST /v1/workday/work-reports`

Creates an employee's work report for a period. The new report is not submitted; submit it with a separate call.

Requires the `timeman` scope. Bitrix24 checks the credential owner’s permissions. READONLY keys can read reports and cannot write them.

## Request fields (body)

| Field | Type | Required | Description |
|------|-----|:-----:|----------|
| `userId` | integer | yes | ID of the employee the report belongs to. List: [`GET /v1/users`](/docs/entities/users/list) |
| `reportText` | string \| null | no | Report text. Returned as `report` and `reportPlain` |
| `reportExtended` | string \| null | no | Additional report text. Returned as `reportExtended` |
| `plansText` | string \| null | no | Plans. Returned as `plans` |
| `type` | string \| null | no | Report type: `REPORT`, `AI_REPORT`, `ROBOT_REPORT`, `AI_DAY_PLAN`, or `ROBOT_DAY_PLAN`. If omitted or set to any other value, `REPORT` is used |
| `dateFrom` | string \| null | no | Start of the report period in ISO 8601 format with a time zone. The time is dropped; only the date is stored |
| `dateTo` | string \| null | no | End of the report period in the same format. The time is dropped; only the date is stored |
| `tasks` | array \| null | no | Tasks in the report |
| `tasks[].id` | integer | yes | Task ID. List: [`GET /v1/tasks`](/docs/entities/tasks/list) |
| `tasks[].time` | number | no | Time spent on the task, in seconds. The fractional part is dropped |
| `tasks[].title` | string | no | Task title in the report |
| `events` | array \| null | no | Calendar events in the report |
| `events[].id` | integer | yes | Event ID. List: [`GET /v1/calendar-events`](/docs/entities/calendar-events/list) |
| `events[].ownerId` | integer | no | ID of the event owner. List: [`GET /v1/users`](/docs/entities/users/list) |
| `events[].title` | string | no | Event title in the report |
| `autoFillDailyReports` | boolean | no | Defaults to `false` |

## Examples

### curl — personal key

```bash
curl -X POST https://vibecode.bitrix24.com/v1/workday/work-reports \
  -H "X-Api-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "userId": 101, "reportText": "Weekly report" }'
```

### curl — OAuth application

```bash
curl -X POST https://vibecode.bitrix24.com/v1/workday/work-reports \
  -H "X-Api-Key: YOUR_APP_KEY" \
  -H "Authorization: Bearer USER_SESSION_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{ "userId": 101, "reportText": "Weekly report" }'
```

### JavaScript — personal key

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/workday/work-reports', {
  method: 'POST',
  headers: {
    'X-Api-Key': 'YOUR_API_KEY',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    userId: 101,
    reportText: 'Weekly report',
  }),
})
const { data } = await res.json()
```

### JavaScript — OAuth application

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/workday/work-reports', {
  method: 'POST',
  headers: {
    'X-Api-Key': 'YOUR_APP_KEY',
    'Authorization': 'Bearer USER_SESSION_TOKEN',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    userId: 101,
    reportText: 'Weekly report',
  }),
})
const { data } = await res.json()
```

## Response fields

| Field | Type | Description |
|------|-----|----------|
| `success` | boolean | `true` when the report is created |
| `data` | object | The created report. All fields — [Report fields](/docs/workday/work-reports/fields) |

## Response example

The main report fields are shown. For the full list, see [Report fields](/docs/workday/work-reports/fields):

```json
{
  "success": true,
  "data": {
    "id": 143,
    "userId": 101,
    "active": false,
    "reportType": "day",
    "reportDate": "2026-10-06T18:22:40.000Z",
    "dateFrom": "2026-10-05T21:00:00.000Z",
    "dateTo": "2026-10-05T21:00:00.000Z",
    "report": "Weekly report",
    "type": "REPORT",
    "mark": "N",
    "approve": "N"
  }
}
```

## Error response example

400 — `userId` is missing:

```json
{
  "success": false,
  "error": {
    "code": "INVALID_PARAMS",
    "message": "Expected a positive integer"
  }
}
```

## Errors

| HTTP | Code | Description |
|------|-----|----------|
| 400 | `INVALID_PARAMS` | `userId` is missing, a field has the wrong type, a date has no time zone, or the body contains an unknown field such as `files` |
| 403 | `BITRIX_ACCESS_DENIED` | The credential owner lacks the required Bitrix24 permissions |
| 409 | `TIMEMAN_MODULE_NOT_ENABLED` | Time Management is not available on this portal |
| 422 | `BITRIX_ERROR` | Bitrix24 refused the operation |
| 502 | `BITRIX_UNAVAILABLE` | Bitrix24 is unavailable or returned a response of an unexpected shape |
| 401 | `MISSING_API_KEY` | The `X-Api-Key` header was not passed |
| 401 | `TOKEN_MISSING` | An app key was sent without a session token in `Authorization: Bearer` |
| 401 | `INVALID_SESSION` | The session token is invalid or has expired |
| 403 | `WRITE_BLOCKED_READONLY_KEY` | The key is READONLY and cannot create reports |
| 403 | `SCOPE_DENIED` | The key lacks the `timeman` scope |
| 429 | `RATE_LIMITED` | The general request limit was exceeded |

The full list of common API errors — [Errors](/docs/errors).

## Known specifics

- **The period can shift.** If the period overlaps a report the employee already has, the period start moves to the day after that report. The period chosen when `dateFrom` and `dateTo` are omitted shifts the same way. The resulting period is returned in the `dateFrom` and `dateTo` fields of the response.
- **The employee and tasks are not checked for existence.** A report is created even with a nonexistent `userId` or `tasks[].id`. Only the credential owner’s permissions are checked.

## See also

- [Submit a work report](/docs/workday/work-reports/submit)
- [List work reports](/docs/workday/work-reports/list)
- [Work reports](/docs/workday/work-reports)
- [Daily reports](/docs/workday/daily-reports)
- [Workday](/docs/workday)
