isaharVoice
← All integrations
API and webhooks

Connect isahar Voice with your own systems

Read account data through the API, add notes to calls and send call requests to agents. Webhooks let your applications receive important events as soon as they occur.

Basic Auth · Explicit key permissions · JSON responses

Start with an API key

Create the key in the administration panel and choose exactly what it can access. You receive an ID and a secret when the key is created. The secret is shown only once and cannot be retrieved later.

  • Authenticate using HTTP Basic Auth
  • keyId is the username
  • The secret is the password
  • Send every request to https://api.voice.isahar.io
Open the interactive documentation →

What you can do with the API

Calls, agents, queues and numbers

Access account data without manual exports or database access. Every response is isolated to the organization associated with the API key.

GET /v1/pingGET /v1/callsGET /v1/calls/:idGET /v1/agentsGET /v1/agents/:idGET /v1/queuesGET /v1/queues/:idGET /v1/numbers
Add notes from your own CRM

Add a note to an existing call and make it visible in isahar Voice. This operation requires thenotes:write permission and a unique Idempotency-Key.

POST /v1/calls/:call_id/notes

Notes cannot be edited or deleted through the API.

Agent-confirmed click-to-dial

Your system can send a call request to an available agent. The agent sees the destination in the application and chooses whether to accept or reject it. The call never starts automatically.

POST /v1/agents/:agent_id/dial
Requires the calls:dial scope
The agent must be available
The source number must belong to the account
The request expires if the agent does not respond
The call starts only after the agent confirms it

For write requests, send an Idempotency-Key header. Reuse the same key when retrying the same action to prevent duplicate notes or call requests.

Idempotency-Key: <unique-identifier>

Find exactly the calls you need

Filter and sort the call list directly in the request instead of downloading the entire history.

fromtodirectionstatusagent_idqueue_idphone_numberpageper_pageorder

Give each key only the access it needs

Read
calls:readagents:readqueues:readnumbers:read
Write
notes:writecalls:dial

Write permissions are never granted by default. They must be selected explicitly when the key is created. A legacy key without explicit scopes has read-only access.

Rename keys
Revoke keys
Rotate secrets
Review important actions in the audit log
Use the secret rotation grace period to update an integration without downtime
Webhooks

Receive events as soon as they happen

Register one or more URLs and choose the events you want to receive. Your CRM, internal dashboard or alerting system can then react without repeated polling.

call.createdcall.endedcall.missedrecording.ready
Example payload
Secure delivery
Every request is signed using HMAC-SHA256
The signature is sent in the X-Isahar-Signature header
The signature format is t=timestamp,v1=signature
The signed timestamp lets you reject stale deliveries; we recommend a maximum tolerance of five minutes
A maximum of five attempts are made: the initial delivery and four retries
The delay between attempts increases progressively
After repeated failures, the webhook is disabled and administrators are notified by email
The dashboard includes delivery history, test delivery and manual retry controls
Call ends↓Signed webhook↓CRM / dashboard / alerting system

Errors that are easy to trace

Every error uses the same structure and includes a request_idthat you can use when investigating an issue.

  • X-Request-Id is also returned as a response header
  • HTTP status codes include 400, 401, 403, 404, 409, 422, 429 and 500
  • Resources belonging to another account are returned as not found, without revealing that they exist

Clear limits, no surprises

The API applies limits per key and per account to protect data and service availability.

The default general limit is 60 requests per minute
Click-to-dial has a separate default limit of 10 requests per minute
Responses include X-RateLimit-* headers
When a limit is exceeded, the API returns 429 with a Retry-After header

Building an integration with isahar Voice?

Explore the endpoints, test requests directly in the documentation and connect calls with the systems your team already uses.

isahar Voice · a product by isahar