Make your PBX part of your software.
A single API key, plain HTTP, JSON responses. From click-to-call and call control to auto call campaigns, voice assistant tasks and voice verification codes, everything is REST; results come back with HMAC-signed webhooks.
Your first request in 2 minutes
Get your key from Panel > Auto Call > API tab (or from PBX Settings); send it with a Bearer header, X-Api-Key or ?key=.
- The key is tied to your customer account; it cannot access another customer's data.
- Read operations are GET, operations that change are POST; body is JSON or form.
- The error response is always
{"ok":false,"error":"…","code":"…"}is in the format. - Rate limit: 120 requests per minute per key; on excess 429.
API headers
Under each heading: endpoint address, parameters, sample request and response.
Overview
Authentication, request format, error codes, rate limits
ReadAPI Security
Keys and scopes, allowed IP, HMAC request signing, key renewal, request log
ReadCall Management
Click-to-call, end, transfer, mute
ReadQueues
Queue list, waiting calls, add/remove members
ReadAgent Statuses
Extension statuses and queue memberships
ReadBlocklist
List, add and delete blocked numbers
ReadAudio Files
Announcement list, upload, update, delete
ReadAuto Call
Create campaign, add numbers, get results, webhook
ReadVoice Assistant
Conversations, notes, appointments, task calls, embedding
ReadVoice Verification (OTP)
Send code, verify, status, webhook
ReadSMS API
Bulk / personalized SMS, OTP SMS, delivery report, inbound SMS, blocklist
ReadWebhooks
Signature verification, retry policy, event schemas
ReadEmbed (CRM iframe)
In your PBX screens and WebPhone software: code, signed link, JavaScript events
ReadLet the results come to you, so you don't have to ask.
Auto call result, voice assistant conversation summary, verification code status — every event is POSTed to your address as JSON; the X-Buluthat-Signature header is the HMAC-SHA256 signature. Failed deliveries are retried at intervals of 1 min → 6 hours.
Byfix CRM bridge
The voice assistant finds the customer in the CRM, opens service records, leaves notes; "call with the assistant" is started from the CRM. Ready, a single key.
DetailPHP client
A ready PHP class for voice verification codes; send/verify in two lines. Other endpoints are plain HTTP and can be called from any language.
ExampleEmbeddable live screen
Live transcript of an assistant conversation in an iframe inside the CRM; with a time-limited signed token, no panel session required.
embed_url