Developer Center

Make your PBX part of your software.

A single API key, plain HTTP, JSON responses. From click-to-call and call control to auto call campaigns, voice assistant tasks and voice verification codes, everything is REST; results come back with HMAC-signed webhooks.

Quick start

Your first request in 2 minutes

Get your key from Panel > Auto Call > API tab (or from PBX Settings); send it with a Bearer header, X-Api-Key or ?key=.

  • The key is tied to your customer account; it cannot access another customer's data.
  • Read operations are GET, operations that change are POST; body is JSON or form.
  • The error response is always {"ok":false,"error":"…","code":"…"} is in the format.
  • Rate limit: 120 requests per minute per key; on excess 429.
# click-to-call: extension 1001 rings first, the destination is dialed when answered curl "https://api.buluthat.com/api/begin_call.php?key=K1234-…&extension=1001&destination=905321234567" # create campaign curl -X POST "https://api.buluthat.com/api/autocall.php?action=create_campaign" \ -H "Authorization: Bearer bt_xxxxxxxx" \ -H "Content-Type: application/json" \ -d '{"name":"Ödeme hatırlatma","campaign_type":"ivr", "tts_template":"Merhaba {sayin}, {tutar} tutarındaki ödemeniz…", "digit_labels":{"1":"Ödedim","2":"Yetkili"}}' # send voice verification code curl -X POST "https://api.buluthat.com/api/voice_otp.php?action=send" \ -H "X-Api-Key: bt_xxxxxxxx" -d "phone=905321234567" → {"ok":true,"id":8812,"code":"472915","expires_in":300}
Webhooks

Let the results come to you, so you don't have to ask.

Auto call result, voice assistant conversation summary, verification code status — every event is POSTed to your address as JSON; the X-Buluthat-Signature header is the HMAC-SHA256 signature. Failed deliveries are retried at intervals of 1 min → 6 hours.

Webhook document
// PHP: signature verification $raw = file_get_contents('php://input'); $sig = $_SERVER['HTTP_X_BULUTHAT_SIGNATURE'] ?? ''; $calc = hash_hmac('sha256', $raw, $secret); if (!hash_equals($calc, $sig)) { http_response_code(401); exit; } $event = json_decode($raw, true); // $event['event'] = 'call_finished' | 'session_ended' | 'otp_result' …
Byfix CRM bridge

The voice assistant finds the customer in the CRM, opens service records, leaves notes; "call with the assistant" is started from the CRM. Ready, a single key.

Detail
PHP client

A ready PHP class for voice verification codes; send/verify in two lines. Other endpoints are plain HTTP and can be called from any language.

Example
Embeddable live screen

Live transcript of an assistant conversation in an iframe inside the CRM; with a time-limited signed token, no panel session required.

embed_url