ManyDial Logo
Login

ManyDial API Documentation

Comprehensive guide to integrating with ManyDial's programmable voice platform. Build automated calls, verify orders, embed cloud call centers, or add headless agent calling to your own browser interface.

API Documentation for Caller ID Request
This document provides a detailed guide on how to integrate the Caller ID request API.
API Overview
1. Caller ID Request API
Endpoint:
https://api.manydial.com/v1/portal/callerId
Method:
POST
Purpose: Generate a dedicated caller ID (IP-based number) for initiating outbound calls via call center or automation systems.
Caller ID API Integration
Request URL:
bash
Request Headers:
Header
▲
Value
▲
Content-Type
multipart/formdata; boundary=<calculate when request is sent>
x-api-key
YOUR_SECRET_KEY
Request Body:
You must send the body as FormData, especially if uploading files.
Body Parameters:
Parameter
▲
Type
▲
Description
▲
Example
▲
Required
▲
ownerName
string
Full name of the business owner.
Abdul Karim
Yes
businessName
string
Registered or trade name of the business.
Karim Electronics
Yes
email
string
Email address of the business owner.
karim@example.com
Yes
phone
string
Phone number of the business owner.
+8801711000000
Yes
passportSizeImage
string
Base64 encoded string of the passport-size photograph of the owner.
data:image/png;base64,/9j/4AAQSkZJRgABAQAAAQABAAD...
Yes
nid
string
National ID number of the business owner.
1999000000000
Yes
dob
string
Date of birth of the business owner in YYYY-MM-DD format.
1980-05-20
Yes
gender
string
Gender of the business owner.
Male
Yes
fatherName
string
Father’s full name.
Mohammad Rahim
Yes
motherName
string
Mother’s full name.
Rahima Begum
Yes
resellerName
string
Name of the reseller (if any).
Rasel Telecom
No
resellerPhone
string
Phone number of the reseller.
+8801711999999
No
resellerNID
string
NID number of the reseller.
1999000000001
No
signature
string
Base64 encoded string of the digital signature.
data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAA...
Yes
seal
string
Base64 encoded string of the business seal or stamp.
data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAA...
Yes
date
string
Date of submission in YYYY-MM-DD format.
2025-05-14
Yes
flatNo
string
Flat number of the address.
A-2
Yes
houseNoOrName
string
House number or name.
12B
Yes
roadNoOrMoholla
string
Road number or moholla name.
Road 7
Yes
areaOrVillage
string
Area or village name.
Banani
Yes
division
string
Division name.
Dhaka
Yes
district
string
District name.
Dhaka
Yes
upazilaOrThana
string
Upazila or police thana name.
Gulshan
Yes
postCode
string
Postal code of the address.
1212
Yes
callerIdRequestHook
string
Webhook URL where caller ID request status updates will be sent (e.g., Approved, Rejected).
https://yourapi.com/webhook
Yes
smsEnabled
string
Specifies whether SMS functionality is enabled for sending messages from the call center or automated systems to customers. Allowed values: 'Yes' or 'No'.
Yes
Yes
callerIdPayload
string
Custom payload used for verification on your end.
Sample payload
Yes
Request Example:
javascript
Success Response Example:
json
Error Response Example:
json
json
API Documentation for Call Automation
This document provides a detailed guide on how to integrate the Call Automation API.
API Overview
1. Call Automation API
Endpoint:
https://api.manydial.com/v1/portal/call/dispatch
Method:
POST
Purpose: Trigger automated voice calls using a configurable call flow and dynamic caller ID per customer.
Authentication
For the POST API, the SECRET_KEY must be included in the request header as x-api-key.
Call Automation API Integration
Request URL:
bash
Request Headers:
Header
▲
Value
▲
Content-Type
multipart/formdata; boundary=<calculate when request is sent>
x-api-key
YOUR_SECRET_KEY
Request Body:
You must send the body as FormData, especially if uploading files.
Body Parameters:
Parameter
▲
Type
▲
Description
▲
Example
▲
Required
▲
callPayload
string
Unique information for verification. This payload will be returned when the webhook is triggered.
unique-verification-token-12345
Yes
callerId
string
The phone number from which the calls will be dispatched.
+8809999999
Yes
perCallDuration
string
The estimated duration of each call (in minutes).
5
Yes
messages
string
A stringified JSON object containing the messages to be converted into voice prompts.
{"welcome":"Hello","menuMessage1":"Press 1 for service details.","menuMessage11":"Our services are..."}
Yes
number
string
A specific customer number for calling.
+8801760399647
Yes
buttons
string
A stringified array that captures user interactions, such as which button was pressed during the call flow.
[{"id":"menuMessage1","key":"1","value":"Place Order"},{"id":"menuMessage2","key":"2","value":"Cancel Order"},{"id":"menuMessage11","key":"1","value":"Confirm Order"}]
Yes
deliveryHook
string
Your POST API URL to receive the call automation response for further operations.
https://yourapi.com/webhook
Yes
Messages Object Structure:
The messages parameter is a JSON object that provides prompts customers will hear during the call flow.
N.B: After the **record** is completed, the call will automatically end, and no further nested menu messages will be played and Record and Forward simultaneously is not possible.
Key
▲
Type
▲
Description
▲
Example
▲
welcome
string
The message played when the call is received.
Hello, press 1 for Bangla, 2 for English.
repeat
string
Number of times the welcome message should be repeated. Defaults to 1.
2
sms
string
The SMS message sent to the customer when they receive the call.
Thank you for choosing our service.
forward
string
The number to which the call will be forwarded after the welcome message is played. Must include the country code.
+8801760399647
menuMessage1
string
Message played when the customer presses 1.
Thank you for staying with us. Press 1 for support, 2 for billing.
repeat1
string
Number of times menuMessage1 should be repeated. Defaults to 1 if not provided.
2
sms1
string
The SMS message sent to the customer when they press 1.
You selected Support. Our representative will contact you shortly.
record1
string
Whether the system should record the customer's voice input after menuMessage1 is played. If set to 'Yes', the system will record the message.
Yes
menuMessage11
string
Message played if the customer presses 1 again (nested menu). Will not play if record1 is set to 'Yes'.
Our service includes A, B, and C. Press 1 for more details.
repeat11
string
Number of times menuMessage11 should be repeated.
3
record11
string
Whether the system should record the customer's voice input after menuMessage11 is played.
Yes
sms11
string
The SMS message sent to the customer when they press 1 again.
You selected detailed service information. Check our website for more.
menuMessage2
string
Message played when the customer presses 2.
Thank you for being with us. Press 1 for general inquiry, 2 for complaints.
repeat2
string
Number of times menuMessage2 should be repeated.
1
sms2
string
The SMS message sent to the customer when they press 2.
You selected General Inquiry. Please wait while we connect you.
record2
string
Whether the system should record the customer's voice input after menuMessage2 is played.
Yes
Example messages :
json
Example buttons :
N.B: The id in the buttons array corresponds to a key in the messages object.
json
Request Example:
javascript
Success Response Example:
json
Error Response Example:
json
json
Delivery Hook Response Documentation
The deliveryHook response provides detailed information about the call flow, user interactions, and any additional actions taken (such as forwarding, SMS sending, or call recording). Below is a breakdown of the response fields:
Response Structure:
json
Field Descriptions:
Field
▲
Type
▲
Description
▲
callPayload
string
A unique identifier for the call, typically used for tracking purposes.
callerId
string
The phone number that initiated the call.
number
string
The recipient's phone number where the call was made.
buttons
array
List of menu options pressed by the user during the call. Each object contains: - id: Unique ID of the menu item. - key: The digit pressed by the user. - value: Description of the action performed.
userPressed
string
The sequence of buttons pressed by the user.
actions
string
A summary of the actions performed based on user input, formatted as key: action name.
sms
array
List of SMS messages sent during the call process. Each object contains: - id: Unique ID of the SMS. - sms: The message content. - status: Pending, Delivered, or Failed.
duration
string
The total duration of the call in MM:SS format.
status
string
The final status of the call (ANSWER, NO ANSWER, BUSY, FAILED).
forwardNumber
string
The phone number to which the call was forwarded, if applicable.
recordAudioURL
string
URL to the recorded audio file if recording was enabled.
recordTranscribed
string
Transcribed text of the call if recording was enabled.
createdAt
string
Timestamp of when the call entry was created (ISO 8601 format).
updatedAt
string
Timestamp of the last update to this call entry (ISO 8601 format).
Example Use Cases
1. User Places an Order & SMS is Sent
A user receives a call and presses 1 to place an order. The system sends an SMS confirmation.
json
2. Call Forwarded to Another Number
A user presses 1 to place an order, and the call is forwarded to a customer service agent.
json
3. Call Recorded & Transcribed
A call is recorded for quality purposes, and a transcription is generated.
json

Notes:

  • If a call is forwarded, forwardNumber will include <forwardNumber>.
  • The recordAudioURL and recordTranscribed fields will be populated only if call recording is enabled.
  • The sms field tracks SMS status (Pending, Delivered, Failed).
Conclusion of Call Automation
This documentation provides a complete guide for using the Call Automation API and Delivery Report Using Webhook. By following these steps, you can easily integrate the system to dispatch calls and track call deliveries efficiently.
API Documentation for Call Center
This document provides a detailed guide on how to integrate the Call Center API and iframe integration for Call Center.
iFrame Integration
This section provides a detailed guide on how to embed the Call Center interface into your website using an iframe. This allows agents or clients to access the Call Center directly from your web application.
Prerequisites
You must have a valid callerId(usually your Call Center ID, e.g., +8809600000000).
You must have the agent's emailthat will be logged into the Call Center.
The agent must already be registered in the ManyDial system.
React
Parameters:
Parameter
▲
Type
▲
Required
▲
Description
▲
email
string
Yes
Email address of the agent.
callerId
string
Yes
Caller ID number of the Call Center.

Call Center CDN SDK

The headless browser SDK adds ManyDial calling to any web application without embedding the Call Center interface. Your application owns every button, incoming-call alert, ringtone and notification; the SDK owns the agent session, SIP/WebRTC connection and call commands.

Loading the script validates the existing API key, agent configuration and exact browser origin. Script loading and ready do not request microphone access, connect SIP or realtime services, or enable incoming calls. The agent becomes available only after a user-initiated login() succeeds.

Quick start

  1. Ask a ManyDial administrator to allowlist the exact origin that will host the SDK.
  2. Create or copy an active key from the existing API Integration page.
  3. Serve the page over HTTPS. For local development only, ManyDial can allowlist an exact http://localhost:<port> origin; every other origin must use HTTPS.
  4. Load the SDK with the agent email, Call Center caller ID and API key. The caller ID identifies the tenant, while the email identifies the agent.
  5. Await ready, subscribe to events, then call login() from a user gesture. Login activates calling; it does not authenticate the user into your application.
html

Automatic bootstrap request

No customer backend endpoint is required. The SDK sends the existing key directly to ManyDial in the X-API-Key header. ManyDial resolves the tenant from that key and then validates the active agent, approved Call Center, subscription, API Integration permission and exact request origin.

http

The API key must be active and the subscription's API Integration feature must equal Yes. Deleting or disabling the key blocks both new SDK sessions and every existing API operation that uses the same key. Treat API_KEY_INACTIVE as loss of authorization and return the host UI to a logged-out state.

The mutable /v1/ URL receives the current v1 release automatically; use an exact /vX.Y.Z/ URL when you need a pinned deployment.

The current release is v1.2.1. v1.2.0 remains the first supported immutable release of the direct API-key contract. Earlier SDK versions are retired and must not be used with the production backend.

Optional advanced security: Subresource Integrity (SRI) lets the browser reject a CDN file whose bytes differ from a pinned release. Use it only with an immutable /vX.Y.Z/ script URL. Copy files["manydial-call-center.min.js"].integrity from that release's /vX.Y.Z/manifest.json, then add it as integrity together with crossorigin="anonymous". Never pin SRI to the mutable /v1/ URL.

Microphone permission

In v1.2.1, login() obtains microphone access for outbound, inbound and both permission modes. The browser prompts only when permission has not already been granted. Call it from a clear user action such as an “Enable calls” button, on HTTPS (or localhost during development). A denied request rejects with MEDIA_PERMISSION_DENIED; a missing input device rejects with MICROPHONE_NOT_FOUND, and telephony stays logged out.

It is normally best to load the SDK at page startup and let login() request access. If your product requires “permission denied means the SDK is never loaded,” request access with the browser API first, then inject the script only after success. Render the real values into the authenticated page; the placeholders below are not production credentials. After the SDK is ready, call login() from a separate user click so browser media activation remains reliable.

html

Internal PBX login and logout confirmation prompts play through SDK-managed audio without appearing as customer calls. If browser autoplay policy blocks a prompt, the SDK emits AUDIO_PLAYBACK_BLOCKED once. This warning does not by itself mean login or logout failed; use the command promise and latest session state to determine the result.

Complete lifecycle and host UI

The SDK intentionally has no visual UI, ringtone or browser notification. Listen for incomingCall, show accessible answer/reject controls for manual-answer agents, and stop host-owned alerts whenever callStateChange leaves incoming. The event's autoAnswer value reflects the agent's ManyDial policy.

This concise example covers validation, telephony activation, incoming and outbound calls, media, breaks, logout and final cleanup. In a real application, enable each control from the latest SDK state.

html

Methods, events and state

MethodParametersResultValid useCommon errors
readyNonePromise<void>Once after script load; telephony remains inactiveINVALID_CONFIG, API_KEY_REQUIRED, INVALID_API_KEY, ORIGIN_NOT_ALLOWED
login(options?){ takeover?: boolean }Promise<ManyDialState>Logged out; call from a user gestureMEDIA_PERMISSION_DENIED, MICROPHONE_NOT_FOUND, SESSION_ACTIVE, LEGACY_SESSION_ACTIVE, SIP_REGISTRATION_FAILED
logout()NonePromise<void>Online or on break, with no ringing/active callACTIVE_CALL, INVALID_STATE, QUEUE_OPERATION_FAILED
destroy()NonePromise<void>Permanent integration teardown with no ringing/active callACTIVE_CALL; later commands return DESTROYED
call(number)Customer number: stringPromise<CallState>Online, idle, outbound/both permissionINVALID_NUMBER, PERMISSION_DENIED, ACTIVE_CALL, INSUFFICIENT_BALANCE, CALL_FAILED
answer() / reject()NonePromise<void>Manual incoming call is ringingNO_INCOMING_CALL, CALL_FAILED
hangup()NonePromise<void>Incoming, outgoing, connecting, active or held callNO_ACTIVE_CALL, CALL_FAILED
mute() / unmute()NonePromise<void>Active or held callNO_ACTIVE_CALL, CALL_FAILED
hold() / unhold()NonePromise<void>Active or held callNO_ACTIVE_CALL, CALL_FAILED
sendDtmf(digits)0-9, A-D, *, # or commaPromise<void>Active callNO_ACTIVE_CALL, DTMF_FAILED
getTransferTargets()NonePromise<TransferTarget[]>Active call; fetch when opening transfer UIACTIVE_CALL_REQUIRED, DATA_UNAVAILABLE
transfer(agentId)Opaque target ID: stringPromise<void>Active call and currently eligible targetACTIVE_CALL_REQUIRED, TRANSFER_TARGET_UNAVAILABLE, TRANSFER_FAILED
getQueueList()NonePromise<QueueEntry[]>Logged inNOT_LOGGED_IN, DATA_UNAVAILABLE
getTodayCallLogs()NonePromise<TodayCallLog[]>Logged inNOT_LOGGED_IN, DATA_UNAVAILABLE
getBreakTypes()Nonereadonly BreakDefinition[]Any stateNone
startBreak(type) / endBreak()BreakType / nonePromise<BreakState> / Promise<void>Online and idle / currently on breakACTIVE_CALL, INVALID_BREAK_TYPE, BREAK_ALREADY_ACTIVE, BREAK_NOT_ACTIVE, QUEUE_OPERATION_FAILED
getState()NoneManyDialStateAny stateNone
on(event, handler)Event name and callbackUnsubscribe functionSubscribe before login so no event is missedNone

on(event, handler) returns an unsubscribe function. Keep it and invoke it when the host component is removed. Only one call is supported per SDK instance.

  • Await command promises and drive controls from confirmed state rather than optimistic UI changes.
  • Hold/unhold preserves the previous mute state. RTP DTMF accepts 0-9, A-D, *, # and comma.
  • Call destroy() only when permanently disposing of the integration; it is terminal and is not a replacement for logout.

A call ending locally, remotely or because of a system/PBX action is reported through callStateChange. When current becomes idle, clear the host's active-call UI. There is no separate callEnded event in v1.

Queue and today's calls

Both read methods require a logged-in session and return data scoped by the authenticated tenant and agent. After login, the SDK fetches the queue immediately and approximately every five seconds while online or on break. It emits queueListChange for the initial list and whenever that list changes.

Today's call logs are fetched after login and whenever a local call returns to idle. Listen for todayCallLogsChange, or call getTodayCallLogs() when the user requests an immediate refresh. Use getQueueList() the same way; do not add a second queue polling loop. Automatic reads stop after logout, session revocation or destroy(). A refresh failure reports an error without replacing the last rendered list with an empty one.

javascript
typescript

Queue entries contain call time, queue, caller number and call ID. Today's rows contain customer name, phone, duration, status, type, session ID, agent, creation time, hangup party and recording path. Treat those values as sensitive and do not copy complete rows into analytics or logs.

EventPayloadUse
ready{ state }Bootstrap is complete; the agent is still logged out.
sessionStateChange{ previous, current, state }Agent session status changed.
incomingCall{ callId, from, displayName, autoAnswer }Render the host incoming-call experience.
callStateChange{ previous, current, call }Update call controls from the latest call state.
breakStateChange{ previous, current, break }Update break controls and availability.
queueListChange{ entries: QueueEntry[] }Replace the displayed waiting-caller list.
todayCallLogsChange{ logs: TodayCallLog[] }Replace the displayed list of today's agent calls.
error{ error }Handle a safe ManyDialError and its request ID.

State values returned by getState()

  • Session: bootstrapping, logged_out, logging_in, online, on_break, logging_out, error, destroyed.
  • Call: idle, incoming, outgoing, connecting, active, held, ending; it also exposes direction, remote party, muted and held values.
  • Break: none, starting, active, ending; it also exposes the type, reporting label and server start time.
  • Connection: sipRegistered and realtimeConnected.

Events can arrive close together during reconnection. Render from the latest event payload or getState(); do not assume transport events occur exactly once.

Permissions and session rules

Your application must authenticate and authorize its own user before rendering the SDK credentials. ManyDial login() does not sign that user into the portal: it activates the already validated agent's telephony session. Calling it is valid for every permission mode. Outbound-only agents become ready to place calls but never join the inbound queue and never receive incoming calls.

PermissionLoginOutboundIncomingLogout
OutboundActivate telephony; do not join the inbound queueAllowedRejectedDeactivate telephony
InboundActivate telephony and automatically join the inbound queueRejectedAllowedAutomatically leave the inbound queue and deactivate telephony
BothActivate telephony and automatically join the inbound queueAllowedAllowedAutomatically leave the inbound queue and deactivate telephony
  • All calls are blocked while logged out or on break.
  • Logout during a ringing or active call returns ACTIVE_CALL and leaves the session and call unchanged.
  • When login returns SESSION_ACTIVE, replace the idle session only after explicit confirmation and login({ takeover: true }).
  • A takeover retry returning ACTIVE_CALL or AGENT_ON_BREAK is unsafe; finish the call or break first.
  • After AGENT_CONFIGURATION_CHANGED, keep the SDK logged out and retry login to fetch the current configuration.
  • Transfer target IDs are opaque. Fetch targets when opening the control and keep the original call until transfer(id) succeeds.

Agent breaks

Break APIs are always present, although a host may choose not to show them. Build options from getBreakTypes() so labels remain consistent with Agent Monitoring and Agent Break Reports.

salah → Salah Break
lunch → Lunch Break
tea → Tea Break
personal → Personal Break
meeting → Meeting
training → Training
other → Other
  • A break can start only while logged in, idle and not already on a break; end it before selecting another type.
  • Inbound/both agents automatically leave the inbound queue before a break and rejoin it when the break ends successfully. Outbound-only agents have no inbound queue membership to change.
  • A failed queue leave does not start the break; a failed queue rejoin leaves the break active so the host can retry.
  • ManyDial uses server timestamps. Live monitoring updates on refresh and historical reports update after normal aggregation.

Framework and server-rendered applications

Vanilla JavaScript can use the global directly. React, Vue and Angular should load the script once, subscribe during component setup and invoke every returned unsubscribe function during cleanup. TypeScript consumers should vendor the release's complete declaration tree because index.d.ts references declaration files in subdirectories.

javascript (ES module)

Java, Python and PHP may render these attributes into an authenticated page, but SIP, WebRTC, events and SDK methods always execute in the user's browser. The API key is therefore visible to that browser even when it originated in server-side configuration.

server-rendered HTML

Errors

Failed commands reject with a ManyDialError containing a stable code, safe message and optional requestId. Use the rejection for action-specific UI and the error event for shared logging; avoid showing both as duplicate notifications.

  • Configuration: INVALID_CONFIG, INVALID_REQUEST, ORIGIN_REQUIRED, ORIGIN_NOT_ALLOWED, BOOTSTRAP_FAILED, BOOTSTRAP_EXPIRED, AGENT_NOT_AVAILABLE, AGENT_CONFIGURATION_CHANGED, UNSUPPORTED_PHONE_TYPE.
  • API-key authorization: API_KEY_REQUIRED, INVALID_API_KEY, API_KEY_INACTIVE.
  • Eligibility and billing: API_INTEGRATION_REQUIRED, SUBSCRIPTION_INACTIVE, INSUFFICIENT_BALANCE, CALL_CONFIGURATION_UNAVAILABLE.
  • Agent data: DATA_UNAVAILABLE.
  • Media: MEDIA_PERMISSION_DENIED, MICROPHONE_NOT_FOUND, AUDIO_PLAYBACK_BLOCKED.
  • Sessions/auth: SESSION_ACTIVE, SESSION_CONFLICT, SESSION_RECOVERY_PENDING, SESSION_BUSY, SESSION_LOGGED_OUT, LEGACY_SESSION_ACTIVE, TAKEOVER_NOT_ALLOWED, SESSION_EXPIRED, ACCESS_TOKEN_REQUIRED, INVALID_ACCESS_TOKEN, INVALID_REFRESH_TOKEN, UNAUTHORIZED, SESSION_TAKEN_OVER.
  • Actions: AGENT_ON_BREAK, ACTIVE_CALL, ACTIVE_CALL_REQUIRED, PERMISSION_DENIED, ON_BREAK, NO_INCOMING_CALL, NO_ACTIVE_CALL, CALL_FAILED, TRANSFER_FAILED, TRANSFER_TARGET_UNAVAILABLE, DTMF_FAILED.
  • Break/queue: BREAK_ALREADY_ACTIVE, BREAK_NOT_ACTIVE, INVALID_BREAK_TYPE, QUEUE_OPERATION_FAILED.
  • Connectivity/availability: NETWORK_ERROR, REQUEST_TIMEOUT, RATE_LIMITED, NOT_AVAILABLE, MONITORING_UNAVAILABLE, SIP_CONNECTION_FAILED, SIP_REGISTRATION_FAILED.
  • Lifecycle/input: NOT_READY, NOT_LOGGED_IN, ALREADY_LOGGED_IN, INVALID_NUMBER, INVALID_STATE, INVALID_SESSION_STATE, INVALID_CALL_STATE, INVALID_BREAK_STATE, INVALID_MONITORING_STATE, INVALID_COMMAND_ID, COMMAND_ID_REUSED, DESTROYED, INTERNAL_ERROR.

INVALID_API_KEY means the supplied key is malformed, unknown or inactive. API_KEY_INACTIVE means the key that authorized an existing session has since been deleted or disabled; require a new authorized login after the account owner restores a key. SUBSCRIPTION_INACTIVE blocks SDK initialization or session continuation until the account owner restores service. INSUFFICIENT_BALANCE rejects a new charged outbound call before dialing; keep the existing agent state unchanged and direct the account owner to add balance.

Origin, CSP and security

  • Allowlist exact origins only: scheme, hostname and non-default port. Exact http://localhost:<port> origins are supported only for local development; every other origin must use HTTPS. Do not add paths or wildcards.
  • Public CDN CORS only permits downloading JavaScript; it does not authorize an SDK session.
  • Origin is defense-in-depth, not authentication. A non-browser client can forge it.
  • The browser-visible API key has the same full authority on existing /portal/* APIs; it is not scoped only to this SDK.
  • Render the key only inside the intended authenticated portal. Anyone who can inspect the page, run injected JavaScript or use a privileged extension can copy it.
  • Do not put the key in URLs, analytics, error reports or logs. Deleting or disabling it revokes both SDK and existing API access.
  • A restrictive CSP and XSS prevention remain essential because injected code on an allowlisted authenticated page can act as that agent.
http

Add the exact SIP WebSocket origin supplied for your environment to connect-src when it differs from the API origin. Do not add unsafe-inline only for this SDK; use a same-origin host script or the host's existing CSP nonce/hash policy.

Current direct-SIP limitation: the SDK intentionally reuses the agent's existing iframe SIP username, password and call prefix. The password is delivered to the logged-in browser. API-key revocation and SDK session tokens protect the HTTP/realtime boundary, but they cannot stop someone holding that SIP credential from using a separate SIP client. Outbound call:authorize is a balance/eligibility preflight only; direct SIP call and automatic inbound-queue operations do not carry the ManyDial API key. If compromise is suspected, separately rotate the shared SIP credential and verify queue state; rotation or endpoint restrictions can also affect the existing iframe. API-key/session revocation does not by itself end an active PBX call or guarantee queue removal.

Versioning and browser support

  • Use /vX.Y.Z/ for deterministic production upgrades and rollback; matching SHA-384 SRI is optional defense-in-depth.
  • Use /v1/ only when automatic compatible updates are acceptable; never attach a fixed SRI value to this mutable URL.
  • Test a new exact version on cdn-staging.manydial.com, then update the production URL and, if used, its SRI value together.
  • Supported v1 targets are current desktop Chrome/Edge, Firefox and Safari on HTTPS with WebRTC, WebSocket and microphone access.
  • Native iOS, Android, React Native and Flutter applications require a separate native SDK; mobile background calls and OS call integration are not supported.
Call Center API Overview
1. Call Center Request API
Endpoint:
https://api.manydial.com/v1/portal/call-center
Method:
POST
Purpose: Initialize a call center instance with a specific caller ID, call prefix, agent limit, and optional redirection on incoming calls.
2. Call Center Renew API
Endpoint:
https://api.manydial.com/v1/portal/call-center/renew
Method:
POST
Purpose: Renew the call center instance with a new caller ID, call prefix, agent limit, and optional redirection on incoming calls.
3. Call Center Agent Request API
Endpoint:
https://api.manydial.com/v1/portal/agent-request
Method:
POST
Purpose: Register or onboard agents to a call center with defined roles, phone type, and call permissions.
4. Call Center Agent Delete API
Endpoint:
https://api.manydial.com/v1/portal/agent/delete?email={email}&callerId={callerId}
Method:
DELETE
Purpose: Delete agents from a call center by their IDs.
5. Call Center Agent List API
Endpoint:
https://api.manydial.com/v1/portal/call-center/agent-list?callerId={callerId}
Method:
GET
Purpose: Retrieve a list of agents registered to a call center.
6. Call Center Click To Call API
Endpoint:
https://api.manydial.com/v1/portal/click-to-call
Method:
POST
Purpose: Initiate a call from an agent to a customer number using the registered caller ID and agent email from diferent page.
Authentication
For the POST API, the SECRET_KEY must be included in the request header as x-api-key.
Call Center Request API Integration
Request URL:
bash
Request Headers:
Header
▲
Value
▲
Content-Type
application/json
x-api-key
YOUR_SECRET_KEY
Request Body:
Parameter
▲
Type
▲
Description
▲
Example
▲
Required
▲
callerId
string
Unique caller ID for the call center (usually the shop or service number).
+8809600000000
Yes
callPrefix
string
Prefix code used to identify the agent. Must start with 1000, 2000, ..., or 9000.
1000
Yes
totalAgents
string
Maximum number of agents allowed in the call center.
5
Yes
statusHook
string
Webhook URL where call center request status updates will be sent (e.g., Approved, Rejected).
https://yourapi.com/webhook
Yes
endCallHook
string
Webhook URL to receive detailed information when a call ends (e.g., duration, billing).
https://yourapi.com/webhook
Yes
redirectUrl
string
Optional URL to open in a new tab when an agent receives an incoming call. Add base URL here. The dynamic parameter 'phone' will be replaced with the caller's phone number.
https://yourapi.com/agent-dashboard?phone=011960000000
No
domainUrl
string
Where the call center iframe will be loaded.
https://yourapi.com/call-center
Yes
Request Example:
javascript
Success Response Example:
json
Error Response Example:
json
json
json
Call Center Request Update Body:
json
Call End Hook Body:
json
Call Center Renew API Integration
Request URL:
bash
Request Headers:
Header
▲
Value
▲
Content-Type
application/json
x-api-key
YOUR_SECRET_KEY
Request Body:
Parameter
▲
Type
▲
Description
▲
Example
▲
Required
▲
callerId
string
Unique caller ID for the call center (usually the shop or service number).
+8809600000000
Yes
expireDate
string
Expiration date for the call center (YYYY-MM-DD).
2025-05-14
Yes
Request Example:
javascript
Success Response Example:
json
Error Response Example:
json
json
json
Call Center Agent Create API Integration
Request URL:
bash
Request Headers:
Header
▲
Value
▲
Content-Type
application/json
x-api-key
YOUR_SECRET_KEY
Request Body:
Parameter
▲
Type
▲
Description
▲
Example
▲
Required
▲
callerId
string
Unique caller ID for the call center (usually the shop or service number).
+8809600000000
Yes
name
string
Name of the agent.
John Doe
Yes
email
string
Email address of the agent.
john@example.com
Yes
phone
string
Phone number of the agent.
+8801934567890
Yes
password
string
Password for the agent's account.
password@123
Yes
callPermission
string
Call permission for the agent (inbound/outbound/both).
inbound
Yes
isIncomingCallAutoConnect
boolean
Whether to automatically connect incoming calls to the agent.
true
No
phoneType
string
Phone type for the agent (WEBPHONE/IPPHONE).
WEBPHONE
Yes
expireDate
string
Expiration date for the agent's account. Format: YYYY-MM-DD
2023-12-31
Yes
Request Example:
javascript
Success Response Example:
json
Error Response Example:
json
json
json
json
Call Center Agent Delete API Integration
Request URL:
bash
Request Headers:
Header
▲
Value
▲
Content-Type
application/json
x-api-key
YOUR_SECRET_KEY
Request Query:
Parameter
▲
Type
▲
Description
▲
Example
▲
Required
▲
callerId
string
Unique caller ID for the call center (usually the shop or service number).
+8809600000000
Yes
email
string
Email address of the agent.
john@example.com
Yes
Request Example:
javascript
Success Response Example:
json
Error Response Example:
json
json
json
Call Center Agent List API Integration
Request URL:
bash
Request Headers:
Header
▲
Value
▲
Content-Type
application/json
x-api-key
YOUR_SECRET_KEY
Request Query:
Parameter
▲
Type
▲
Description
▲
Example
▲
Required
▲
callerId
string
Unique caller ID for the call center (usually the shop or service number).
+8809600000000
Yes
Request Example:
javascript
Success Response Example:
json
Error Response Example:
json
json
json
Call Center Click To Call API Integration
Request URL:
bash
Request Headers:
Header
▲
Value
▲
Content-Type
application/json
x-api-key
YOUR_SECRET_KEY
Request Body:
Parameter
▲
Type
▲
Description
▲
Example
▲
Required
▲
callerId
string
Unique caller ID for the call center (usually the shop or service number).
+8809600000000
Yes
email
string
Email address of the agent.
john@example.com
Yes
number
string
Number of the customer you want to call from the call center.
01934567890
Yes
payload
string
Custom payload that can contain any data (e.g., JSON, Array) but must be sent as a string. This same payload will be returned in the call end webhook, allowing you to verify and match the call with your system data.
{"orderId":12345,"customer":"John Doe"}
No
Request Example:
javascript
Success Response Example:
json
Error Response Example:
json
json
Conclusion of Call Center
This documentation provides a complete guide for using the Call Center API and Call Center iframe. By following these steps, you can easily integrate the system to your website.
whatsapp