> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firetone.com.au/llms.txt
> Use this file to discover all available pages before exploring further.

# List extensions

> SIP passwords are never included. Sort keys: caller_id_name, created_at, enabled, number. An unknown sort key is a 400.



## OpenAPI

````yaml /api-reference/openapi-public.json get /extensions
openapi: 3.0.3
info:
  description: >-
    The API your own systems use: place and follow calls, have an AI agent call
    someone, run campaigns and get their results, keep contacts in step with
    your CRM, and receive signed webhooks. Authenticate with an integration key
    (Authorization: Bearer ft_...), used only from the IP addresses it allows.
  title: FireTone API
  version: 0.1.0
servers:
  - description: Your platform's API host
    url: https://{host}/api/v1
    variables:
      host:
        default: api.firet.one
security:
  - bearerAuth: []
tags:
  - name: Auth
  - description: >-
      Live calls and what can be done to them: hang up, hold, transfer, park,
      merge, monitor, whisper; the Desk's own call.
    name: Calls
  - description: 'Outbound campaigns: contacts, attempts, outcomes.'
    name: Campaigns
  - description: 'Customers: who called, what is known about them, and their memory.'
    name: Contacts
  - description: What was said on an AI call, and the review of it.
    name: Conversations
  - description: >-
      Your own systems: HTTP connections an IVR calls mid-call, and webhooks for
      call events. Tenant URLs must be public https addresses.
    name: Integrations
  - name: Live
  - name: Provisioning
  - name: Reporting
  - description: Tickets raised by people, agents and the API.
    name: Tickets
  - description: Messages left for an extension or a queue.
    name: Voicemail
paths:
  /extensions:
    get:
      tags:
        - Provisioning
      summary: List extensions
      description: >-
        SIP passwords are never included. Sort keys: caller_id_name, created_at,
        enabled, number. An unknown sort key is a 400.
      operationId: getExtensions
      parameters:
        - $ref: '#/components/parameters/limit'
        - $ref: '#/components/parameters/offset'
        - $ref: '#/components/parameters/organisationId'
        - $ref: '#/components/parameters/sort'
        - $ref: '#/components/parameters/order'
        - $ref: '#/components/parameters/q'
        - $ref: '#/components/parameters/filterEnabled'
        - $ref: '#/components/parameters/filterNumber'
        - $ref: '#/components/parameters/filterCodecProfile'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExtensionPage'
          description: OK
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
components:
  parameters:
    limit:
      in: query
      name: limit
      schema:
        default: 50
        maximum: 500
        type: integer
    offset:
      in: query
      name: offset
      schema:
        default: 0
        type: integer
    organisationId:
      description: Narrow to one organisation. Outside your scope returns 403.
      in: query
      name: organisation_id
      schema:
        format: uuid
        type: string
    sort:
      description: >-
        Sort key. Each list accepts its own allow-list of keys, given in that
        endpoint's description; anything else is a 400. ORDER BY cannot be
        parameterised, so the key is looked up rather than interpolated. Every
        sort carries a tiebreak on the primary key, so paging stays disjoint
        when the sort column has duplicates.
      in: query
      name: sort
      schema:
        type: string
    order:
      description: >-
        Sort direction. Defaults to ascending, except the call log, which reads
        newest first.
      in: query
      name: order
      schema:
        enum:
          - asc
          - desc
        type: string
    q:
      description: >-
        Free-text search across the list's searchable columns (case-insensitive
        substring). % and _ in the term match themselves.
      in: query
      name: q
      schema:
        type: string
    filterEnabled:
      description: Only rows with this enabled state.
      in: query
      name: enabled
      schema:
        type: boolean
    filterNumber:
      description: Match extensions starting with this.
      in: query
      name: number
      schema:
        type: string
    filterCodecProfile:
      description: Filter on codec profile.
      in: query
      name: codec_profile
      schema:
        type: string
  schemas:
    ExtensionPage:
      properties:
        items:
          items:
            $ref: '#/components/schemas/Extension'
          type: array
        limit:
          type: integer
        offset:
          type: integer
        total:
          type: integer
      required:
        - items
        - total
        - limit
        - offset
      type: object
    Extension:
      description: >-
        The SIP password is deliberately absent: it is returned once at creation
        and never readable afterwards.
      properties:
        caller_id_name:
          type: string
        caller_id_number:
          type: string
        codec_profile:
          enum:
            - standard
            - low_bandwidth
            - g711_ulaw
            - g711_alaw
            - opus_8k
            - opus_16k
            - opus_32k
            - g729
            - ilbc
            - g726
          type: string
        codec_string:
          description: >-
            The extension's own codec list, in order, comma-separated from the
            catalogue (PCMA,PCMU,G729), as a trunk's codec_string. Empty: the
            codec profile decides. When set it is exactly what the phone is
            offered, and every call from or to the extension is steered from it.
          type: string
        default_region:
          description: >-
            Overrides the organisation's dial-from country for this extension.
            Empty inherits it. ISO-3166 alpha-2.
          type: string
        enabled:
          type: boolean
        has_pin:
          description: >-
            Whether this agent can sign in to the Desk. The PIN belongs to the
            agent and IS the login (migration 0061): there is no separate panel
            user to create first. Never the PIN itself and never a hash.
          type: boolean
        id:
          format: uuid
          type: string
        login_team_id:
          description: >-
            The team the agent's sign-in is scoped to when they are on more than
            one. Null means the one team they are on.
          format: uuid
          nullable: true
          type: string
        number:
          type: string
        organisation_id:
          format: uuid
          type: string
        record_calls:
          description: >-
            Switches call recording on at this level. It cannot switch recording
            off: a call is recorded if ANY of its organisation, team, extension,
            queue, trunk or process has this set.
          type: boolean
        voicemail_email:
          description: >-
            Where a new message in this extension's mailbox is emailed, the
            recording attached (10 MB or less). Empty sends nothing.
          type: string
        voicemail_enabled:
          description: A call nobody answers goes to this extension's mailbox.
          type: boolean
        voicemail_sms:
          description: >-
            The mobile (E.164) a new voicemail is texted to: who, how long, and
            where to listen. Empty sends nothing.
          type: string
      required:
        - id
        - organisation_id
        - number
        - enabled
      type: object
    Error:
      properties:
        error:
          properties:
            code:
              enum:
                - invalid_request
                - invalid_credentials
                - unauthenticated
                - forbidden
                - not_found
                - conflict
                - internal
              type: string
            message:
              type: string
          required:
            - code
            - message
          type: object
      required:
        - error
      type: object
  responses:
    BadRequest:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: The request is not valid. The message names every field that is wrong.
    Unauthorized:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: Missing, invalid or expired token
    Forbidden:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: Outside the caller's scope, or insufficient role
  securitySchemes:
    bearerAuth:
      bearerFormat: JWT or API key
      description: >-
        Every request sends `Authorization: Bearer <token>`. The token is either
        a panel session (a JWT from /auth/login, 12 hours) or an API key
        `ft_<id>_<secret>`. An API key is accepted only from an address on its
        IP allowlist (403 ip_not_allowed otherwise; 403 ip_allowlist_required
        for an old key that has none), is limited to its rate per minute (429
        rate_limited with Retry-After; X-RateLimit-Limit/Remaining/Reset on
        every response), and at most 60 call placements a minute.
      scheme: bearer
      type: http

````