curl --request POST \
--url https://{host}/api/v1/calls/{uuid}/transfer \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"destination": "<string>",
"kind": "<string>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({destination: '<string>', kind: '<string>'})
};
fetch('https://{host}/api/v1/calls/{uuid}/transfer', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/api/v1/calls/{uuid}/transfer"
payload = {
"destination": "<string>",
"kind": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"error": {
"code": "invalid_request",
"message": "<string>"
}
}{
"error": {
"code": "invalid_request",
"message": "<string>"
}
}{
"error": {
"code": "invalid_request",
"message": "<string>"
}
}Transfer a live call to an extension or queue
Blind transfer. NEVER external, and that is a policy rather than an omission: an agent transferring a customer to a premium-rate number is toll fraud billed to their own employer, and a blind transfer hands the call away entirely, so unlike a conference leg there is nothing left to observe. The same rule the AI transfer action states, resolved through the same allow-list, so there are not two that drift apart.\n\nThe call re-enters the firetone XML context, so it goes back through the ordinary router, trunk selection and billing gate rather than a second path that must be kept in step.\n\nRequires calls:control.
curl --request POST \
--url https://{host}/api/v1/calls/{uuid}/transfer \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"destination": "<string>",
"kind": "<string>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({destination: '<string>', kind: '<string>'})
};
fetch('https://{host}/api/v1/calls/{uuid}/transfer', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/api/v1/calls/{uuid}/transfer"
payload = {
"destination": "<string>",
"kind": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"error": {
"code": "invalid_request",
"message": "<string>"
}
}{
"error": {
"code": "invalid_request",
"message": "<string>"
}
}{
"error": {
"code": "invalid_request",
"message": "<string>"
}
}Authorizations
Every request sends Authorization: Bearer <token>. The token is either a panel session (a JWT from /auth/login, 12 hours) or an API key ft_<id>_<secret>. An API key is accepted only from an address on its IP allowlist (403 ip_not_allowed otherwise; 403 ip_allowlist_required for an old key that has none), is limited to its rate per minute (429 rate_limited with Retry-After; X-RateLimit-Limit/Remaining/Reset on every response), and at most 60 call placements a minute.
Path Parameters
Body
Response
Transferred