# Add a layer

`POST https://evohub.io/api/v1/schedules/{id}/layers`

Part of the [On-Call API](https://docs-dev.evohub.io/oncall.md) reference · operationId `createScheduleLayer`.

Adds a rotation layer. A layer runs its people in turn, handing over every
day or week from `rotation_start` (default: now; an unreadable value is
ignored). Restrict it to a shift — certain weekdays and a time window in the
schedule's timezone — with the three `restrict_*` fields; a window may cross
midnight. Leave them out for a layer that covers all day, every day.

A schedule that belongs to a team is visible only to callers in that team (and
to administrators acting in person); others get 404, as if it did not exist.

**Permission (API-key scope):** `oncall:schedule:write`.

## Authorization

Any one of:

- `bearerAuth` (oncall:schedule:write)
- `apiKeyHeader` (oncall:schedule:write)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Path parameters

- `id` (string, required, example `5b1c7d2e-8f3a-4b9c-a0d1-e2f3a4b5c6d7`): The schedule's id.

## Request body (required)

Content type: `application/json`

Type: `ScheduleLayerWrite`

On create `name` and `rotation_type` are required.

- `name` (string)
- `priority` (integer)
- `rotation_type` (RotationType, one of `daily`, `weekly`, `custom`)
- `rotation_start` (string (date-time)): Defaults to now on create.
- `handoff_day` (integer, min 0, max 6)
- `handoff_time` (string, example `09:00`): `HH:MM`
- `restrict_to_weekdays` (array of integer): 0 is Sunday.
- `restrict_start_time` (string): `HH:MM`; give the end too. Empty clears the window.
- `restrict_end_time` (string): `HH:MM`; may be earlier than the start for a shift across midnight.

## Responses

### 201 — The layer.

Content type: `application/json`

Type: `object`

- `data` (ScheduleLayer, required)
  - `id` (string)
  - `schedule_id` (string)
  - `name` (string)
  - `priority` (integer): Layers with a higher priority win over lower ones.
  - `rotation_type` (RotationType, one of `daily`, `weekly`, `custom`)
  - `rotation_start` (string (date-time)): When the rota's first turn started.
  - `handoff_day` (integer): Weekday of the handover for weekly rotas, 0 (Sunday) to 6.
  - `handoff_time` (string): `HH:MM` of the handover.
  - `restrict_to_weekdays` (array of integer)
  - `restrict_start_time` (string): `HH:MM`
  - `restrict_end_time` (string): `HH:MM`
  - `rotations` (array of ScheduleRotation)
    - `id` (string)
    - `layer_id` (string)
    - `user_id` (string)
    - `position` (integer): 0-based place in the rota.
    - `created_at` (string (date-time))
  - `created_at` (string (date-time))
  - `updated_at` (string (date-time))
- `success` (boolean, required, value `true`)

### 400 — The body is not JSON (`INVALID_BODY`); `name` or `rotation_type` is missing, a weekday is outside 0–6, or the shift window is incomplete or malformed (`VALIDATION_FAILED`).

Content type: `application/json`

Type: `ValidationError`

- `error` (object, required)
  - `code` (string, required, value `VALIDATION_FAILED`)
  - `message` (string, required)
  - `details` (array of object, required)
    - `field` (string)
    - `message` (string)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 403 — The key lacks the scope this endpoint needs (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 404 — No schedule with this id in your organization (`NOT_FOUND`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.

## Example request

```bash
curl -X POST 'https://evohub.io/api/v1/schedules/5b1c7d2e-8f3a-4b9c-a0d1-e2f3a4b5c6d7/layers' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer <TOKEN>' \
  -d '{
  "name": "Business hours",
  "handoff_day": 1,
  "handoff_time": "09:00",
  "rotation_type": "weekly",
  "rotation_start": "2026-09-01T06:00:00Z",
  "restrict_end_time": "18:00",
  "restrict_start_time": "09:00",
  "restrict_to_weekdays": [
    1,
    2,
    3,
    4,
    5
  ]
}'
```
