The SIP Caller REST API authenticates requests with API keys. Each API key has a secret token, which your application sends in the Authorization header of every request.
API keys are created from the Web Console, in Settings > API Keys, by a user with the Administrator role. When creating the key, you choose:
When the key is created, SIP Caller shows its token only once. Copy it and store it in a safe place, such as a secrets manager. SIP Caller doesn't store the token, so it can't be recovered: if you lose it, create a new API key.
See API Keys for a step-by-step guide.
Send the token as a Bearer token in the Authorization header:
Authorization: Bearer API_KEY_TOKEN
Every request must be authenticated. Keep in mind that:
ACCOUNT_ID in the URL must be the account where the key was created.Each endpoint requires the API key to have at least one of the following roles:
| Role | Allows |
|---|---|
| Campaign Admin | Full access to campaigns, campaign numbers, black lists, contact lists and campaign reports. |
| Campaign Reader | Read-only access to campaigns, campaign numbers, black lists, contact lists and campaign reports. |
| Campaign Number Admin | Read, add and delete the numbers of campaigns. Can be restricted to specific campaigns. |
| Campaign Number Provider | Add numbers to campaigns, without being able to read or delete them. Can be restricted to specific campaigns. |
Grant each application only the roles it needs. For example, a web form that pushes new leads to a campaign only needs the Campaign Number Provider role, restricted to that campaign.
| Status | When |
|---|---|
401 Unauthorized | The Authorization header is missing, or the token is malformed, invalid or expired. |
403 Forbidden | The token is valid, but the API key was deleted, belongs to another account, or doesn't have a role that allows the operation. |
See Errors for the format of error responses.
To revoke the access of an application, delete its API key from Settings > API Keys. Requests made with the token of a deleted key fail immediately with 403 Forbidden.
We recommend rotating keys periodically: create a new key, update your application to use it, and then delete the old one.
/v1/accounts/ACCOUNT_ID/campaigns
curl -G 'https://api.sipcaller.com/v1/accounts/ACCOUNT_ID/campaigns' \
-H 'Authorization: Bearer API_KEY_TOKEN' \
--data-urlencode 'range=[0,9]'Response
200 OK
[
{
"id": "0192831a-fbbe-735f-b385-a3252781817d",
"name": "Q3 Sales Follow-up",
"state": "Active"
...
}
]