Skip to main content
Get a one-time link to the IVR designer

Authorizations

Authorization
string
header
required

Every request sends Authorization: Bearer <token>. The token is either a panel session (a JWT from /auth/login, 12 hours) or an API key ft_<id>_<secret>. An API key is accepted only from an address on its IP allowlist (403 ip_not_allowed otherwise; 403 ip_allowlist_required for an old key that has none), is limited to its rate per minute (429 rate_limited with Retry-After; X-RateLimit-Limit/Remaining/Reset on every response), and at most 60 call placements a minute.

Path Parameters

id
string<uuid>
required

Body

application/json
return_origin
string
required

The origin of the page that opens the designer: scheme, host and port, nothing else. The designer reports to this origin only (postMessage), so it must be exact. https, or http://localhost while developing; an origin the platform already admits browsers from is accepted as it is listed. A wildcard is refused.

Example:

"https://app.example.com"

panel_origin
string

Rarely needed. Which of the platform's panel addresses the link should open, when it has several; it must be one of them.

ttl_minutes
integer
default:120

How long the link, and the session it becomes, lasts.

Required range: 5 <= x <= 480

Response

The link

expires_at
string<date-time>
required

When the link, and the designer session, stops working.

flow_id
string<uuid>
required

The IVR the designer will open.

url
string
required

Open this in a popup (window.open). It works once: the designer trades it for a session as it loads, so a copied or reloaded link shows an expired message. The secret is in the URL fragment and is never sent to a server.