> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firetone.com.au/llms.txt
> Use this file to discover all available pages before exploring further.

# Transfer a live call to an extension or queue

> Blind transfer. NEVER external, and that is a policy rather than an omission: an agent transferring a customer to a premium-rate number is toll fraud billed to their own employer, and a blind transfer hands the call away entirely, so unlike a conference leg there is nothing left to observe. The same rule the AI transfer action states, resolved through the same allow-list, so there are not two that drift apart.\n\nThe call re-enters the `firetone` XML context, so it goes back through the ordinary router, trunk selection and billing gate rather than a second path that must be kept in step.\n\nRequires calls:control.



## OpenAPI

````yaml /api-reference/openapi-public.json post /calls/{uuid}/transfer
openapi: 3.0.3
info:
  description: >-
    The API your own systems use: place and follow calls, have an AI agent call
    someone, run campaigns and get their results, keep contacts in step with
    your CRM, and receive signed webhooks. Authenticate with an integration key
    (Authorization: Bearer ft_...), used only from the IP addresses it allows.
  title: FireTone API
  version: 0.1.0
servers:
  - description: Your platform's API host
    url: https://{host}/api/v1
    variables:
      host:
        default: api.firet.one
security:
  - bearerAuth: []
tags:
  - name: Auth
  - description: >-
      Live calls and what can be done to them: hang up, hold, transfer, park,
      merge, monitor, whisper; the Desk's own call.
    name: Calls
  - description: 'Outbound campaigns: contacts, attempts, outcomes.'
    name: Campaigns
  - description: 'Customers: who called, what is known about them, and their memory.'
    name: Contacts
  - description: What was said on an AI call, and the review of it.
    name: Conversations
  - description: >-
      Your own systems: HTTP connections an IVR calls mid-call, and webhooks for
      call events. Tenant URLs must be public https addresses.
    name: Integrations
  - name: Live
  - name: Provisioning
  - name: Reporting
  - description: Tickets raised by people, agents and the API.
    name: Tickets
  - description: Messages left for an extension or a queue.
    name: Voicemail
paths:
  /calls/{uuid}/transfer:
    post:
      tags:
        - Live
      summary: Transfer a live call to an extension or queue
      description: >-
        Blind transfer. NEVER external, and that is a policy rather than an
        omission: an agent transferring a customer to a premium-rate number is
        toll fraud billed to their own employer, and a blind transfer hands the
        call away entirely, so unlike a conference leg there is nothing left to
        observe. The same rule the AI transfer action states, resolved through
        the same allow-list, so there are not two that drift apart.\n\nThe call
        re-enters the `firetone` XML context, so it goes back through the
        ordinary router, trunk selection and billing gate rather than a second
        path that must be kept in step.\n\nRequires calls:control.
      operationId: postCallsUuidTransfer
      parameters:
        - in: path
          name: uuid
          required: true
          schema:
            format: uuid
            type: string
      requestBody:
        content:
          application/json:
            schema:
              properties:
                destination:
                  description: The extension number or queue name.
                  type: string
                kind:
                  description: extension (default) or queue. `external` is refused.
                  type: string
              required:
                - destination
              type: object
        required: true
      responses:
        '204':
          description: Transferred
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: >-
            The destination is not one this organisation may transfer to, or
            none was given. The reason is returned verbatim.
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          description: >-
            No such call, or not one you may act on. An agent may act only on a
            call they are on; a colleague's call returns this same 404, so the
            refusal cannot be used to discover who is talking to whom.
        '502':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: The switch refused
components:
  schemas:
    Error:
      properties:
        error:
          properties:
            code:
              enum:
                - invalid_request
                - invalid_credentials
                - unauthenticated
                - forbidden
                - not_found
                - conflict
                - internal
              type: string
            message:
              type: string
          required:
            - code
            - message
          type: object
      required:
        - error
      type: object
  responses:
    Forbidden:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: Outside the caller's scope, or insufficient role
  securitySchemes:
    bearerAuth:
      bearerFormat: JWT or API key
      description: >-
        Every request sends `Authorization: Bearer <token>`. The token is either
        a panel session (a JWT from /auth/login, 12 hours) or an API key
        `ft_<id>_<secret>`. An API key is accepted only from an address on its
        IP allowlist (403 ip_not_allowed otherwise; 403 ip_allowlist_required
        for an old key that has none), is limited to its rate per minute (429
        rate_limited with Retry-After; X-RateLimit-Limit/Remaining/Reset on
        every response), and at most 60 call placements a minute.
      scheme: bearer
      type: http

````