curl --request POST \
--url https://{host}/api/v1/tickets \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"subject": "<string>",
"body": "<string>",
"contact_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"organisation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"team_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
subject: '<string>',
body: JSON.stringify('<string>'),
contact_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
organisation_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
team_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a'
})
};
fetch('https://{host}/api/v1/tickets', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/api/v1/tickets"
payload = {
"subject": "<string>",
"body": "<string>",
"contact_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"organisation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"team_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"body": "<string>",
"call_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"contact_e164": "<string>",
"contact_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"organisation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"priority": "low",
"ref": 123,
"resolved_at": "2023-11-07T05:31:56Z",
"source": "agent",
"status": "open",
"subject": "<string>",
"team_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"update_count": 123,
"updated_at": "2023-11-07T05:31:56Z"
}{
"error": {
"code": "invalid_request",
"message": "<string>"
}
}{
"error": {
"code": "invalid_request",
"message": "<string>"
}
}Raise a ticket
Always recorded with source ‘human’. Nothing may claim that except this path: the action handler records ‘agent’ or ‘flow’, and the distinction tells whoever picks the ticket up how much to trust the wording. A contact or team outside the caller’s scope is refused — the foreign key proves the row exists, not that the caller may see it.
curl --request POST \
--url https://{host}/api/v1/tickets \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"subject": "<string>",
"body": "<string>",
"contact_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"organisation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"team_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
subject: '<string>',
body: JSON.stringify('<string>'),
contact_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
organisation_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
team_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a'
})
};
fetch('https://{host}/api/v1/tickets', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/api/v1/tickets"
payload = {
"subject": "<string>",
"body": "<string>",
"contact_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"organisation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"team_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"body": "<string>",
"call_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"contact_e164": "<string>",
"contact_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"organisation_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"priority": "low",
"ref": 123,
"resolved_at": "2023-11-07T05:31:56Z",
"source": "agent",
"status": "open",
"subject": "<string>",
"team_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"update_count": 123,
"updated_at": "2023-11-07T05:31:56Z"
}{
"error": {
"code": "invalid_request",
"message": "<string>"
}
}{
"error": {
"code": "invalid_request",
"message": "<string>"
}
}Authorizations
Every request sends Authorization: Bearer <token>. The token is either a panel session (a JWT from /auth/login, 12 hours) or an API key ft_<id>_<secret>. An API key is accepted only from an address on its IP allowlist (403 ip_not_allowed otherwise; 403 ip_allowlist_required for an old key that has none), is limited to its rate per minute (429 rate_limited with Retry-After; X-RateLimit-Limit/Remaining/Reset on every response), and at most 60 call placements a minute.
Headers
Any string up to 255 characters. A retry with the same key and the same body gets the first answer again (with Idempotent-Replayed: true) instead of doing it twice; the same key with a different body is 409 idempotency_mismatch; while the first is still running, 409 idempotency_in_progress. Kept 24 hours.
255Body
Response
Created
low, normal, high, urgent Per-organisation, so a customer can read it out. Not a global sequence, which would leak one tenant's volume into another's numbering.
Who raised it: a model mid-call, a person in the panel, or an IVR flow node.
agent, human, flow open, pending, resolved, closed