Inbound API
Three endpoints take data from your software. Each needs a key with the matching scope. See API keys and scopes. The full request and response definitions are in the live API reference.
| Endpoint | Scope | Most per request |
|---|---|---|
POST /api/integrations/v1/inbound/leads |
leads:write |
5,000 leads |
POST /api/integrations/v1/inbound/dnc |
dnc:write |
10,000 numbers |
POST /api/integrations/v1/inbound/outcomes |
outcomes:write |
1,000 outcomes |
Send leads
Section titled “Send leads”list_id is the id of a VoDialer list. GET /api/core/v1/lists shows them, with a read key. Send leads as an array, or put one lead’s fields at the top level.
curl -X POST https://YOUR-HOST/api/integrations/v1/inbound/leads \ -H "Authorization: Bearer $VODIALER_KEY" \ -H "Content-Type: application/json" \ -H "Idempotency-Key: crm-batch-2026-10-06-001" \ -d '{ "list_id": "0192b2c0-0000-7000-8000-0000000000bb", "leads": [ { "external_id": "A-1001", "phone": "(312) 555-0718", "first_name": "Ana", "last_name": "Diaz", "state": "FL", "zip": "33101", "date_of_birth": "1952-02-03" }, { "external_id": "A-1002", "phone": "+14155552671", "first_name": "Sam" } ] }'phoneis required, in any common format. It is stored in international form,+1…for US numbers.- Optional:
external_id(100 characters),first_nameandlast_name(80),state(two letters),zip(10),date_of_birth(YYYY-MM-DD),language,consent_cert_urlandconsent_at(see consent certificates). - A lead that repeats a number in the same request is counted in
duplicates_in_request. A lead that fails a check is listed inrejectedwith itsindexand areason. The others still go in. - The answer has
received,forwarded,duplicates_in_request,rejected,core(the list import’s own summary) andconsent.
The people arrive in the list unchecked. See adding a list.
Send do-not-call numbers
Section titled “Send do-not-call numbers”curl -X POST https://YOUR-HOST/api/integrations/v1/inbound/dnc \ -H "Authorization: Bearer $VODIALER_KEY" -H "Content-Type: application/json" \ -d '{ "numbers": ["(312) 555-0718", "+14155552671"] }'You can send one number as "phone" instead. The numbers go into your company’s do-not-call list with the source api. The answer has received, accepted, rejected and compliance.
Send outcomes
Section titled “Send outcomes”An outcome says what happened to a person after the hand-over. Identify the person with journey_id, or with external_id or phone. Give at least one result field: enrolled, carrier, plan, active_30d, active_90d, chargeback, revenue_cents.
curl -X POST https://YOUR-HOST/api/integrations/v1/inbound/outcomes \ -H "Authorization: Bearer $VODIALER_KEY" -H "Content-Type: application/json" \ -d '{ "outcomes": [ { "external_id": "A-1001", "enrolled": true, "carrier": "Acme Health", "revenue_cents": 45000 }, { "phone": "+14155552671", "enrolled": false } ] }'The answer has received, applied_by_journey, sent_for_matching, rejected and core. Outcomes sent by external_id or phone are matched to a person by VoDialer.
Retrying safely
Section titled “Retrying safely”Send an Idempotency-Key header, 1 to 128 visible characters, on every write. Use a new key for each batch.
| You send | You get |
|---|---|
| A new key | The request runs. |
| The same key and the same body | The first answer again, with Idempotent-Replayed: true. |
| The same key and a different body | 422. The body is compared byte for byte. |
| The same key while the first is running | 409. Wait and retry. |
A request that fails frees its key, so you can send it again. Keys are kept for 7 days and belong to one endpoint of your company. Without a key the request still works, but a retry runs twice.
Errors use the shape in API keys and scopes. Requests over the batch limits get 422.