> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firetone.com.au/llms.txt
> Use this file to discover all available pages before exploring further.

# Who is in a room now

> The switch's members (id, call uuid, name, number, muted, talking, joined_at) with the daemon's roles folded in, plus the session's locked, recording and all_muted state and whether THIS caller may control the room. Live rooms are keyed by the SWITCH'S room name (ft-room-<id> for a dial-in room, ft-conf-<call> for a merged call), so a merged call gets the same list and controls. Reading a dial-in room needs conferences:read; acting on it conferences:control -- or being in it. A merged room follows the call-control rule: an agent may act on a room made from a call one of whose legs is theirs.



## OpenAPI

````yaml /api-reference/openapi-public.json get /conferences/{room}
openapi: 3.0.3
info:
  description: >-
    The API your own systems use: place and follow calls, have an AI agent call
    someone, run campaigns and get their results, keep contacts in step with
    your CRM, and receive signed webhooks. Authenticate with an integration key
    (Authorization: Bearer ft_...), used only from the IP addresses it allows.
  title: FireTone API
  version: 0.1.0
servers:
  - description: Your platform's API host
    url: https://{host}/api/v1
    variables:
      host:
        default: api.firet.one
security:
  - bearerAuth: []
tags:
  - name: Auth
  - description: >-
      Live calls and what can be done to them: hang up, hold, transfer, park,
      merge, monitor, whisper; the Desk's own call.
    name: Calls
  - description: 'Outbound campaigns: contacts, attempts, outcomes.'
    name: Campaigns
  - description: 'Customers: who called, what is known about them, and their memory.'
    name: Contacts
  - description: What was said on an AI call, and the review of it.
    name: Conversations
  - description: >-
      Your own systems: HTTP connections an IVR calls mid-call, and webhooks for
      call events. Tenant URLs must be public https addresses.
    name: Integrations
  - name: Live
  - name: Provisioning
  - name: Reporting
  - description: Tickets raised by people, agents and the API.
    name: Tickets
  - description: Messages left for an extension or a queue.
    name: Voicemail
paths:
  /conferences/{room}:
    get:
      tags:
        - Calls
      summary: Who is in a room now
      description: >-
        The switch's members (id, call uuid, name, number, muted, talking,
        joined_at) with the daemon's roles folded in, plus the session's locked,
        recording and all_muted state and whether THIS caller may control the
        room. Live rooms are keyed by the SWITCH'S room name (ft-room-<id> for a
        dial-in room, ft-conf-<call> for a merged call), so a merged call gets
        the same list and controls. Reading a dial-in room needs
        conferences:read; acting on it conferences:control -- or being in it. A
        merged room follows the call-control rule: an agent may act on a room
        made from a call one of whose legs is theirs.
      operationId: getConferencesRoom
      parameters:
        - in: path
          name: room
          required: true
          schema:
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LiveRoom'
          description: The room as it is now.
        '404':
          description: No such live room in scope, or you may not control it.
        '502':
          description: The switch refused or is not connected; the message is the switch's.
components:
  schemas:
    LiveRoom:
      description: >-
        A room while it is up. `room` is the switch's name for it, which every
        control is addressed to; `room_id` is the dial-in room behind it, and is
        absent for a room made by merging two calls.
      properties:
        all_muted:
          type: boolean
        can_control:
          description: >-
            Whether THIS caller may run the room: answered once here, so a
            client draws the controls it has rather than discovering a 404 per
            button.
          type: boolean
        locked:
          type: boolean
        members:
          items:
            $ref: '#/components/schemas/LiveRoomMember'
          type: array
        organisation_id:
          format: uuid
          type: string
        recording:
          type: boolean
        room:
          type: string
        room_id:
          format: uuid
          type: string
        room_name:
          type: string
        run_seconds:
          type: integer
        session_id:
          format: uuid
          type: string
        started_at:
          format: date-time
          type: string
      required:
        - room
        - organisation_id
        - session_id
        - started_at
        - locked
        - recording
        - members
        - can_control
      type: object
    LiveRoomMember:
      description: >-
        One leg in a live room, as the switch has it with the daemon's roles
        folded in.
      properties:
        call_uuid:
          format: uuid
          type: string
        id:
          description: 'The switch''s member number: what mute and kick are addressed to.'
          type: integer
        joined_at:
          format: date-time
          type: string
        muted:
          type: boolean
        name:
          type: string
        number:
          type: string
        role:
          enum:
            - participant
            - moderator
          type: string
        talking:
          type: boolean
      required:
        - id
        - call_uuid
        - role
        - muted
        - talking
      type: object
  securitySchemes:
    bearerAuth:
      bearerFormat: JWT or API key
      description: >-
        Every request sends `Authorization: Bearer <token>`. The token is either
        a panel session (a JWT from /auth/login, 12 hours) or an API key
        `ft_<id>_<secret>`. An API key is accepted only from an address on its
        IP allowlist (403 ip_not_allowed otherwise; 403 ip_allowlist_required
        for an old key that has none), is limited to its rate per minute (429
        rate_limited with Retry-After; X-RateLimit-Limit/Remaining/Reset on
        every response), and at most 60 call placements a minute.
      scheme: bearer
      type: http

````