> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firetone.com.au/llms.txt
> Use this file to discover all available pages before exploring further.

# Merge two of your calls, or dial a third party into this one

> Two shapes, chosen by the body.

**Merge** (`with`: another call UUID): both parties and the caller's own leg from this call are moved into one mod_conference room, so all three hear each other. The other call's agent leg is left bridged to nobody and ends -- on a two-line softphone that reads as 'line 2 hung up, line 1 is now the conference'. Authorised twice, once per call, so an agent can merge only calls they are on; a call they are not on is 404, exactly like a call in another tenant.

**Add** (`destination`, optional `kind`, default `extension`): the switch dials that person into this call's room. The destination goes through the same ResolveDestination as transfer, so the allow-list holds and external numbers are refused -- a conference adds people here, not outside numbers.

The room is named after the call, so two conferences cannot land in one another's -- which would be a live audio bridge between unrelated customers.



## OpenAPI

````yaml /api-reference/openapi-public.json post /calls/{uuid}/conference
openapi: 3.0.3
info:
  description: >-
    The API your own systems use: place and follow calls, have an AI agent call
    someone, run campaigns and get their results, keep contacts in step with
    your CRM, and receive signed webhooks. Authenticate with an integration key
    (Authorization: Bearer ft_...), used only from the IP addresses it allows.
  title: FireTone API
  version: 0.1.0
servers:
  - description: Your platform's API host
    url: https://{host}/api/v1
    variables:
      host:
        default: api.firet.one
security:
  - bearerAuth: []
tags:
  - name: Auth
  - description: >-
      Live calls and what can be done to them: hang up, hold, transfer, park,
      merge, monitor, whisper; the Desk's own call.
    name: Calls
  - description: 'Outbound campaigns: contacts, attempts, outcomes.'
    name: Campaigns
  - description: 'Customers: who called, what is known about them, and their memory.'
    name: Contacts
  - description: What was said on an AI call, and the review of it.
    name: Conversations
  - description: >-
      Your own systems: HTTP connections an IVR calls mid-call, and webhooks for
      call events. Tenant URLs must be public https addresses.
    name: Integrations
  - name: Live
  - name: Provisioning
  - name: Reporting
  - description: Tickets raised by people, agents and the API.
    name: Tickets
  - description: Messages left for an extension or a queue.
    name: Voicemail
paths:
  /calls/{uuid}/conference:
    post:
      tags:
        - Calls
      summary: Merge two of your calls, or dial a third party into this one
      description: >-
        Two shapes, chosen by the body.


        **Merge** (`with`: another call UUID): both parties and the caller's own
        leg from this call are moved into one mod_conference room, so all three
        hear each other. The other call's agent leg is left bridged to nobody
        and ends -- on a two-line softphone that reads as 'line 2 hung up, line
        1 is now the conference'. Authorised twice, once per call, so an agent
        can merge only calls they are on; a call they are not on is 404, exactly
        like a call in another tenant.


        **Add** (`destination`, optional `kind`, default `extension`): the
        switch dials that person into this call's room. The destination goes
        through the same ResolveDestination as transfer, so the allow-list holds
        and external numbers are refused -- a conference adds people here, not
        outside numbers.


        The room is named after the call, so two conferences cannot land in one
        another's -- which would be a live audio bridge between unrelated
        customers.
      operationId: postCallsUuidConference
      parameters:
        - in: path
          name: uuid
          required: true
          schema:
            format: uuid
            type: string
      requestBody:
        content:
          application/json:
            schema:
              properties:
                destination:
                  description: Somebody to dial into this call's room.
                  type: string
                kind:
                  description: extension (default) or queue. external is refused.
                  type: string
                with:
                  description: Another call of the caller's own, to merge with this one.
                  format: uuid
                  type: string
              type: object
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  room:
                    type: string
                type: object
          description: Conferenced
        '400':
          description: >-
            `destination_refused`: not somewhere a conference may reach, with
            the reason. Or neither `with` nor `destination` was given.
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          description: >-
            No such call in scope, or not a call this agent is on -- including
            the call named in `with`.
        '409':
          description: '`not_bridged`: a leg talking to nobody cannot be conferenced.'
        '502':
          description: >-
            `conference_failed`: the switch refused; the message is the switch's
            own.
components:
  responses:
    Forbidden:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: Outside the caller's scope, or insufficient role
  schemas:
    Error:
      properties:
        error:
          properties:
            code:
              enum:
                - invalid_request
                - invalid_credentials
                - unauthenticated
                - forbidden
                - not_found
                - conflict
                - internal
              type: string
            message:
              type: string
          required:
            - code
            - message
          type: object
      required:
        - error
      type: object
  securitySchemes:
    bearerAuth:
      bearerFormat: JWT or API key
      description: >-
        Every request sends `Authorization: Bearer <token>`. The token is either
        a panel session (a JWT from /auth/login, 12 hours) or an API key
        `ft_<id>_<secret>`. An API key is accepted only from an address on its
        IP allowlist (403 ip_not_allowed otherwise; 403 ip_allowlist_required
        for an old key that has none), is limited to its rate per minute (429
        rate_limited with Retry-After; X-RateLimit-Limit/Remaining/Reset on
        every response), and at most 60 call placements a minute.
      scheme: bearer
      type: http

````