Voxbi Cockpit APIs
All endpoints

List contact

Returns a paginated list of contacts. Use the standard search, sort, page, and perPage query parameters; use filter[key]=value to narrow the result set. Multi-tenant scoping is enforced.

HTTP: bearerAuth

User bearer token. Default authentication for customer-facing endpoints. Obtain a token by calling POST /login with your credentials, then send it on every subsequent request as Authorization: Bearer <token>. The token inherits the permissions and PBX scope of the authenticated user.

HTTP Authorization Scheme
bearer
Bearer format
Bearer <token>
HTTP: IntegrationApiKey

API key created on the Cockpit Integrations page (an "API key" integration). It is a bearer token owned by the customer's PBX and limited to the scopes selected when the key was created (e.g. phone-numbers, push-configuration).

Send it in the Authorization header:

Authorization: Bearer <api_key>

Manage keys (create / reveal / revoke) from Integrations → New integration → API key.

HTTP Authorization Scheme
bearer
search query · string
Free-text search across the resource's searchable fields.
page query · integer
Page number to fetch. Defaults to `1`.
per_page query · integer
Number of items per page. Defaults to `25`, maximum `100`.
sort query · string
Field to sort by. Prefix with `-` for descending order (e.g. `-created_at`).
filter[key] query · string
Filter the list by one or more fields. Allowed keys: `id`, `name1`, `name2`, `email`, `company_name`, `department`, `job_title`, `is_private`, `is_blocked_globally`, `private_owner_id`. Apply several at once with filter[key1]=value1&filter[key2]=value2.
include query · string
Comma-separated related resources to embed (dot-nested where shown). Allowed: `numbers`, `groups`, `blockedByUsers`.
accept header · string
example: application/json

Responses

Response schema
dataarray<object>
Each item — Shared or personal address book entry. Phone numbers are held on the related `numbers` records. `handling_strategy` carries the polymorphic redirect target when inbound calls from this contact should be steered to a specific destination.
id*string · uuid
Contact identifier
read-only
example: 550e8400-e29b-41d4-a716-446655440000
pbx_id*string · uuid
Pbx identifier (tenant)
example: 550e8400-e29b-41d4-a716-446655440001
company_namestring | null
example: Acme Corp
departmentstring | null
example: Engineering
job_titlestring | null
example: Head of Product
name1string | null
Primary name (first name, given name)
example: Jane
name2string | null
Secondary name (last name, surname)
example: Smith
emailstring | null · email
example: jane.smith@example.com
notesstring | null
example: Calls every Monday morning
vipboolean
Whether the contact is flagged as VIP
example:
numbersarray<object>
Phone numbers attached to this contact. Embed via `?include=numbers`.
idstring · uuid
read-only
example: 550e8400-e29b-41d4-a716-446655440010
phone_numberstring
The phone number (E.164 preferred)
example: +12125550100
labelstring | null
Optional label for the number
example: Direct line
typestring
Kind of phone number
enum: business mobile other fax
example: business
speed_dialstring | null
Optional speed-dial code for this number
example: 201
created_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
updated_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
is_privateboolean
Private contacts are visible only to their `private_owner_id` user
example:
private_owner_idstring | null · uuid
Owner user when `is_private` is true
example: 550e8400-e29b-41d4-a716-446655440002
editableboolean
Whether the **calling user** may edit this contact. PRINCIPAL-CONDITIONAL: returned only for user-owned (Bearer) tokens and OMITTED entirely for PBX API-key tokens (which own all of their contacts).
example: 1
is_favoriteboolean
Whether this contact is one of the **calling user's** favourites. PRINCIPAL-CONDITIONAL: returned only for user-owned (Bearer) tokens and OMITTED entirely for PBX API-key tokens (a PBX has no per-user favourites).
example:
groupsarray<object>
Groups this contact belongs to. Embed via `?include=groups`.
Each item — Group of users that share routing defaults and (optionally) a common caller identity. Many fields are foreign keys pointing at defaults used when the group's users place or receive calls.
id*string · uuid
Group identifier
read-only
example: 550e8400-e29b-41d4-a716-446655440000
pbx_id*string · uuid
Pbx identifier (tenant)
example: 550e8400-e29b-41d4-a716-446655440001
default_internal_call_flow_idstring | null · uuid
Call flow used for internal calls reaching this group
example: 550e8400-e29b-41d4-a716-446655440002
default_external_call_flow_idstring | null · uuid
Call flow used for external calls reaching this group
example: 550e8400-e29b-41d4-a716-446655440003
extension_id_shown_outside_the_groupstring | null · uuid
Extension displayed to non-group members
example: 550e8400-e29b-41d4-a716-446655440005
default_caller_identity_idstring | null · uuid
Default caller identity applied to the group's outbound calls
example: 550e8400-e29b-41d4-a716-446655440004
external_uidstring | null
External identifier from a CRM or directory sync
example: grp-support
allow_call_pickupsboolean
Whether group members may pick up each others' ringing calls
example: 1
name*string
length: 0–64
example: Support team
descriptionstring | null
length: 0–255
example: First-line support
allow_default_pbxes_outgoing_phone_numbersboolean
Whether the group's CIDs include the PBX-default outbound numbers
example:
display_tab_to_everyone_inside_voxbiboolean
Whether the group's tab is shown to everyone in the PBX
example:
created_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
updated_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
usersarray<object>
Members of the group, each as a user reference. Returned only when requested via `?include=users`.
idstring · uuid
read-only
example: 550e8400-e29b-41d4-a716-446655440006
first_namestring | null
example: Jane
last_namestring | null
example: Smith
emailstring | null · email
example: jane.smith@example.com
is_blocked_globallyboolean
Whether inbound calls from this contact are blocked tenant-wide
example:
blocked_by_usersarray<object>
Users who have personally blocked this contact, each as a user reference. Embed via `?include=blockedByUsers`.
idstring · uuid
read-only
example: 550e8400-e29b-41d4-a716-446655440006
first_namestring | null
example: Jane
last_namestring | null
example: Smith
emailstring | null · email
example: jane.smith@example.com
handling_strategyobject | null
Optional polymorphic redirect target applied to inbound calls from this contact. `type` discriminates which `*_id` field is meaningful.
typestring
enum: call_flow extension user sip_device
example: call_flow
call_flow_idstring | null · uuid
extension_idstring | null · uuid
user_idstring | null · uuid
sip_device_idstring | null · uuid
created_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
updated_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
linksobject
firststring
The first page of the resource
example: http://localhost/api/v1/resources?page=1
laststring
The last page of the resource
example: http://localhost/api/v1/resources?page=1
prevnull | string
The previous page of the resource
nextnull | string
The next page of the resource
metaobject
current_pageinteger
The current page of the resource
≥ 1
example: 1
fromnull | integer
The first item of the resource
≥ 1
example: 1
last_pageinteger
The last page of the resource
≥ 1
example: 1
linksarray<object>
urlstring | null
The url of the resource (null for the boundary prev/next links)
example: http://localhost/api/v1/resources?page=1
labelstring
The label of the resource
example: first
activeboolean
The status of the resource
example: 1
pathstring
The path of the resource
example: http://localhost/api/v1/resources
per_pageinteger
The number of items per page of the resource
≥ 1
example: 15
tonull | integer
The last item of the resource
≥ 1
example: 1
totalinteger
The total number of items of the resource
≥ 0
example: 1
Authorization Token Missing. This error is returned when the authorization token is missing.
Response schema
errorstring
Error message
example: Authorization Token is missing
Unprocessable Parameters. This error is returned when a parameter is not valid.
Response schema
messagestring
example: The given data was invalid.
errorsobject
filterarray<string>
[]string
sortarray<string>
[]string
pagearray<string>
[]string
per_pagearray<string>
[]string
Server error. An unexpected condition was encountered on the server and the request could not be completed. The body is a generic JSON envelope with a `message` field. The response is logged on the server side; quote the request URL + timestamp when reporting an issue.
Response schema
messagestring
exceptionstring
Only present in non-production environments.
filestring
Only present in non-production environments.
lineinteger
Only present in non-production environments.
get https://cockpit.voxbi.com/api/v1/contacts
Base URL
Request sample
curl -X GET 'https://cockpit.voxbi.com/api/v1/contacts' \
  -H 'Authorization: Bearer YOUR_TOKEN'
const response = await fetch('https://cockpit.voxbi.com/api/v1/contacts', {
  method: 'GET',
  headers: {
    'Content-Type': 'application/json',
    'Authorization': `Bearer ${YOUR_TOKEN}`,
  },
});

const data = await response.json();
console.log(data);
import requests

response = requests.get('https://cockpit.voxbi.com/api/v1/contacts',
    headers={'Authorization': f'Bearer {YOUR_TOKEN}'}
)
response.raise_for_status()
data = response.json()
print(data)
<?php
$context = stream_context_create([
    'http' => [
        'method'  => 'GET',
        'header'  => "Content-Type: application/json\r\nAuthorization: Bearer YOUR_TOKEN",
    ],
]);

$response = file_get_contents('https://cockpit.voxbi.com/api/v1/contacts', false, $context);
$data = json_decode($response, true);
print_r($data);
No example for this status.
Host string
example: cockpit.voxbi.com
Date string
example: Mon, 16 Oct 2023 14:08:48 GMT
Connection string
example: close
Cache-Control string
example: no-cache, private
Content-Type string
example: application/json
X-RateLimit-Limit integer
example: 60
X-RateLimit-Remaining integer
example: 59
Vary string
example: Origin
{}
"error": "Authorization Token is missing"
}
Cache-Control string
example: private, must-revalidate
Connection string
example: keep-alive
Content-Type string
example: application/json
Vary string
example: Origin
X-RateLimit-Limit integer
Max requests allowed in the current rate-limit window.
example: 60
X-RateLimit-Remaining integer
Requests remaining in the current rate-limit window.
example: 57
{}
"errors": {}
"filter": [],
"The filter field must be an array."
],
"sort": [],
"The sort field must be a string."
],
"page": [],
"The page field must be an integer."
],
"per_page": []
"The per page field must be an integer."
]
}
}
Cache-Control string
example: private, must-revalidate
Connection string
example: keep-alive
Content-Type string
example: application/json
Vary string
example: Origin
X-RateLimit-Limit integer
Max requests allowed in the current rate-limit window.
example: 60
X-RateLimit-Remaining integer
Requests remaining in the current rate-limit window.
example: 57
{}
"message": "Server Error"
}