Voxbi Cockpit APIs
All endpoints

Create a contact

Create an address-book contact. A contact is either private (owned by private_owner_id) or shared with a set of groups (the two are mutually exclusive). Phone numbers are sent in the nested contactPhoneNumbers[] array. is_private is derived from private_owner_id server-side and must not be sent.

The optional handling_strategy defines per-contact inbound routing.

HTTP: bearerAuth

User bearer token. Default authentication for customer-facing endpoints. Obtain a token by calling POST /login with your credentials, then send it on every subsequent request as Authorization: Bearer <token>. The token inherits the permissions and PBX scope of the authenticated user.

HTTP Authorization Scheme
bearer
Bearer format
Bearer <token>
HTTP: IntegrationApiKey

API key created on the Cockpit Integrations page (an "API key" integration). It is a bearer token owned by the customer's PBX and limited to the scopes selected when the key was created (e.g. phone-numbers, push-configuration).

Send it in the Authorization header:

Authorization: Bearer <api_key>

Manage keys (create / reveal / revoke) from Integrations → New integration → API key.

HTTP Authorization Scheme
bearer
accept header · string
example: application/json

Request body · required

Request schema
name1*string
Primary name (first / given name)
length: 3–64
name2string | null
Secondary name (last / surname)
length: 3–64
emailstring | null · email
length: 0–50
company_namestring | null
length: 2–64
departmentstring | null
length: 2–64
job_titlestring | null
length: 3–32
notesstring | null
length: 0–500
private_owner_idstring | null · uuid
When set, contact is private and visible only to this user. Mutually exclusive with `groups`.
groupsarray<string>
Groups this contact is shared with. Mutually exclusive with `private_owner_id`.
[]string · uuid
contactPhoneNumbersarray<object>
Phone numbers attached to the contact. When present, must contain at least one entry.
items: 1–∞
phone_number*string
length: 0–24pattern: ^\+?\d*$
labelstring | null
length: 0–64
type*string
Channel category (work, mobile, fax, etc.)
speed_dialstring | null
Speed-dial code (auto-prefixed with `*#`)
handling_strategyobject | null
Optional inbound-routing override for calls from this contact

Responses

Response schema
dataobject
Shared or personal address book entry. Phone numbers are held on the related `numbers` records. `handling_strategy` carries the polymorphic redirect target when inbound calls from this contact should be steered to a specific destination.
id*string · uuid
Contact identifier
read-only
example: 550e8400-e29b-41d4-a716-446655440000
pbx_id*string · uuid
Pbx identifier (tenant)
example: 550e8400-e29b-41d4-a716-446655440001
company_namestring | null
example: Acme Corp
departmentstring | null
example: Engineering
job_titlestring | null
example: Head of Product
name1string | null
Primary name (first name, given name)
example: Jane
name2string | null
Secondary name (last name, surname)
example: Smith
emailstring | null · email
example: jane.smith@example.com
notesstring | null
example: Calls every Monday morning
vipboolean
Whether the contact is flagged as VIP
example:
numbersarray<object>
Phone numbers attached to this contact. Embed via `?include=numbers`.
idstring · uuid
read-only
example: 550e8400-e29b-41d4-a716-446655440010
phone_numberstring
The phone number (E.164 preferred)
example: +12125550100
labelstring | null
Optional label for the number
example: Direct line
typestring
Kind of phone number
enum: business mobile other fax
example: business
speed_dialstring | null
Optional speed-dial code for this number
example: 201
created_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
updated_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
is_privateboolean
Private contacts are visible only to their `private_owner_id` user
example:
private_owner_idstring | null · uuid
Owner user when `is_private` is true
example: 550e8400-e29b-41d4-a716-446655440002
editableboolean
Whether the **calling user** may edit this contact. PRINCIPAL-CONDITIONAL: returned only for user-owned (Bearer) tokens and OMITTED entirely for PBX API-key tokens (which own all of their contacts).
example: 1
is_favoriteboolean
Whether this contact is one of the **calling user's** favourites. PRINCIPAL-CONDITIONAL: returned only for user-owned (Bearer) tokens and OMITTED entirely for PBX API-key tokens (a PBX has no per-user favourites).
example:
groupsarray<object>
Groups this contact belongs to. Embed via `?include=groups`.
Each item — Group of users that share routing defaults and (optionally) a common caller identity. Many fields are foreign keys pointing at defaults used when the group's users place or receive calls.
id*string · uuid
Group identifier
read-only
example: 550e8400-e29b-41d4-a716-446655440000
pbx_id*string · uuid
Pbx identifier (tenant)
example: 550e8400-e29b-41d4-a716-446655440001
default_internal_call_flow_idstring | null · uuid
Call flow used for internal calls reaching this group
example: 550e8400-e29b-41d4-a716-446655440002
default_external_call_flow_idstring | null · uuid
Call flow used for external calls reaching this group
example: 550e8400-e29b-41d4-a716-446655440003
extension_id_shown_outside_the_groupstring | null · uuid
Extension displayed to non-group members
example: 550e8400-e29b-41d4-a716-446655440005
default_caller_identity_idstring | null · uuid
Default caller identity applied to the group's outbound calls
example: 550e8400-e29b-41d4-a716-446655440004
external_uidstring | null
External identifier from a CRM or directory sync
example: grp-support
allow_call_pickupsboolean
Whether group members may pick up each others' ringing calls
example: 1
name*string
length: 0–64
example: Support team
descriptionstring | null
length: 0–255
example: First-line support
allow_default_pbxes_outgoing_phone_numbersboolean
Whether the group's CIDs include the PBX-default outbound numbers
example:
display_tab_to_everyone_inside_voxbiboolean
Whether the group's tab is shown to everyone in the PBX
example:
created_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
updated_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
usersarray<object>
Members of the group, each as a user reference. Returned only when requested via `?include=users`.
idstring · uuid
read-only
example: 550e8400-e29b-41d4-a716-446655440006
first_namestring | null
example: Jane
last_namestring | null
example: Smith
emailstring | null · email
example: jane.smith@example.com
is_blocked_globallyboolean
Whether inbound calls from this contact are blocked tenant-wide
example:
blocked_by_usersarray<object>
Users who have personally blocked this contact, each as a user reference. Embed via `?include=blockedByUsers`.
idstring · uuid
read-only
example: 550e8400-e29b-41d4-a716-446655440006
first_namestring | null
example: Jane
last_namestring | null
example: Smith
emailstring | null · email
example: jane.smith@example.com
handling_strategyobject | null
Optional polymorphic redirect target applied to inbound calls from this contact. `type` discriminates which `*_id` field is meaningful.
typestring
enum: call_flow extension user sip_device
example: call_flow
call_flow_idstring | null · uuid
extension_idstring | null · uuid
user_idstring | null · uuid
sip_device_idstring | null · uuid
created_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
updated_atstring | null · date-time
read-only
example: 2024-03-01T08:29:07Z
Authorization Token Missing. This error is returned when the authorization token is missing.
Response schema
errorstring
Error message
example: Authorization Token is missing
Unprocessable Parameters. This error is returned when a parameter is not valid.
Response schema
messagestring
example: The given data was invalid.
errorsobject
filterarray<string>
[]string
sortarray<string>
[]string
pagearray<string>
[]string
per_pagearray<string>
[]string
Server error. An unexpected condition was encountered on the server and the request could not be completed. The body is a generic JSON envelope with a `message` field. The response is logged on the server side; quote the request URL + timestamp when reporting an issue.
Response schema
messagestring
exceptionstring
Only present in non-production environments.
filestring
Only present in non-production environments.
lineinteger
Only present in non-production environments.
post https://cockpit.voxbi.com/api/v1/contacts
Base URL
Request sample
curl -X POST 'https://cockpit.voxbi.com/api/v1/contacts' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  --data '{"name1":"Jane","name2":"Smith","email":"jane.smith@example.com","company_name":"Acme Corp","department":"Engineering","job_title":"Head of Product","notes":"Calls every Monday morning","groups":["550e8400-e29b-41d4-a716-446655440010"],"contactPhoneNumbers":[{"phone_number":"+12125550100","label":"Mobile","type":"mobile","speed_dial":"12"}]}'
const response = await fetch('https://cockpit.voxbi.com/api/v1/contacts', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',
    'Authorization': `Bearer ${YOUR_TOKEN}`,
  },
  body: JSON.stringify({
    "name1": "Jane",
    "name2": "Smith",
    "email": "jane.smith@example.com",
    "company_name": "Acme Corp",
    "department": "Engineering",
    "job_title": "Head of Product",
    "notes": "Calls every Monday morning",
    "groups": [
        "550e8400-e29b-41d4-a716-446655440010"
    ],
    "contactPhoneNumbers": [
        {
            "phone_number": "+12125550100",
            "label": "Mobile",
            "type": "mobile",
            "speed_dial": "12"
        }
    ]
}),
});

const data = await response.json();
console.log(data);
import requests

response = requests.post('https://cockpit.voxbi.com/api/v1/contacts',
    headers={'Authorization': f'Bearer {YOUR_TOKEN}'},
    json={
    "name1": "Jane",
    "name2": "Smith",
    "email": "jane.smith@example.com",
    "company_name": "Acme Corp",
    "department": "Engineering",
    "job_title": "Head of Product",
    "notes": "Calls every Monday morning",
    "groups": [
        "550e8400-e29b-41d4-a716-446655440010"
    ],
    "contactPhoneNumbers": [
        {
            "phone_number": "+12125550100",
            "label": "Mobile",
            "type": "mobile",
            "speed_dial": "12"
        }
    ]
}
)
response.raise_for_status()
data = response.json()
print(data)
<?php
$context = stream_context_create([
    'http' => [
        'method'  => 'POST',
        'header'  => "Content-Type: application/json\r\nAuthorization: Bearer YOUR_TOKEN",
        'content' => '{
    \"name1\": \"Jane\",
    \"name2\": \"Smith\",
    \"email\": \"jane.smith@example.com\",
    \"company_name\": \"Acme Corp\",
    \"department\": \"Engineering\",
    \"job_title\": \"Head of Product\",
    \"notes\": \"Calls every Monday morning\",
    \"groups\": [
        \"550e8400-e29b-41d4-a716-446655440010\"
    ],
    \"contactPhoneNumbers\": [
        {
            \"phone_number\": \"+12125550100\",
            \"label\": \"Mobile\",
            \"type\": \"mobile\",
            \"speed_dial\": \"12\"
        }
    ]
}',
    ],
]);

$response = file_get_contents('https://cockpit.voxbi.com/api/v1/contacts', false, $context);
$data = json_decode($response, true);
print_r($data);
Sample request
{}
"name1": "Jane",
"name2": "Smith",
"email": "jane.smith@example.com",
"company_name": "Acme Corp",
"department": "Engineering",
"job_title": "Head of Product",
"notes": "Calls every Monday morning",
"groups": [],
"550e8400-e29b-41d4-a716-446655440010"
],
"contactPhoneNumbers": []
{}
"phone_number": "+12125550100",
"label": "Mobile",
"type": "mobile",
"speed_dial": "12"
}
]
}
No example for this status.
{}
"error": "Authorization Token is missing"
}
Cache-Control string
example: private, must-revalidate
Connection string
example: keep-alive
Content-Type string
example: application/json
Vary string
example: Origin
X-RateLimit-Limit integer
Max requests allowed in the current rate-limit window.
example: 60
X-RateLimit-Remaining integer
Requests remaining in the current rate-limit window.
example: 57
{}
"errors": {}
"filter": [],
"The filter field must be an array."
],
"sort": [],
"The sort field must be a string."
],
"page": [],
"The page field must be an integer."
],
"per_page": []
"The per page field must be an integer."
]
}
}
Cache-Control string
example: private, must-revalidate
Connection string
example: keep-alive
Content-Type string
example: application/json
Vary string
example: Origin
X-RateLimit-Limit integer
Max requests allowed in the current rate-limit window.
example: 60
X-RateLimit-Remaining integer
Requests remaining in the current rate-limit window.
example: 57
{}
"message": "Server Error"
}