Developers
Call Bullet API
Pull call outcomes and attribution into your CRM, reporting platform or custom application. Keys are restricted to the workspaces, tracking numbers and permissions you choose.
Bearer keys
Secrets are shown once and stored only as hashes.
Tenant isolation
Every request reapplies the key's workspace and number allowlist.
Stable v1 contract
JSON, ISO-8601 times, E.164 numbers and GBP values in pence.
Quick start
Create a key under Integrations → Developer API, store it in a server-side environment variable, then request your permitted workspaces.
curl https://callbullet.com/api/public/v1/workspaces \ -H "Authorization: Bearer $CALL_BULLET_API_KEY"
Endpoints
| Method | Path | Returns |
|---|---|---|
| GET | /account | Key owner, permissions and permitted workspace IDs |
| GET | /workspaces | Accessible client workspaces |
| GET | /workspaces/{workspace_id} | One workspace |
| GET | /workspaces/{workspace_id}/numbers | Tracking numbers and placements |
| GET | /workspaces/{workspace_id}/calls | Calls, outcomes, values and marketing fields |
| GET | /calls/{call_id} | One call |
| GET | /calls/{call_id}/attribution | Source evidence and confidence |
| GET | /calls/{call_id}/recording | Short-lived recording link when available |
| GET | /calls/{call_id}/transcript | Transcript and summary when available |
| GET | /workspaces/{workspace_id}/leads | Lead status, value and next action |
| GET | /integrations/google-ads/status | Google Ads delivery evidence |
| GET | /integrations/ga4/status | GA4 delivery evidence |
Calls and attribution
Call lists support from, to, updated_since, answered, direction, source, caller=first|repeat, lead_status, tag, number_id, sort, order, page and per_page.
GET https://callbullet.com/api/public/v1/workspaces/{workspace_id}/calls?from=2026-09-01T00:00:00Z&answered=true&per_page=100Responses include call outcome, duration, first/repeat caller, values, UTMs, landing/referrer URLs, click ID type, device, campaign and keyword data when captured. Attribution evidence and confidence use the dedicated sub-resource.
Outbound webhooks
Add an HTTPS destination under Integrations → Developer API for signed call.created, call.updated and call.completed events. Call Bullet retries failed deliveries and records every attempt.
X-Call-Bullet-Event: call.completed X-Call-Bullet-Delivery: <event UUID> X-Call-Bullet-Timestamp: <Unix timestamp> X-Call-Bullet-Signature: v1=<HMAC-SHA256(timestamp + "." + raw_body)>
Pagination, errors and limits
- Page size is capped at 100. Call-list responses include page, total_records, total_pages and has_next_page.
- Use updated_since for incremental CRM sync and retain call IDs as stable external identifiers.
- Errors use a consistent JSON envelope and request ID. Expect 401, 403, 404, 422 and 429.
- Read requests allow 120 per minute per key. A 429 response includes Retry-After.
- Recording links expire after 15 minutes. Never store or expose them as permanent public URLs.
Daily PPC reporting recipe
- Read calls incrementally using
updated_since. - Group by campaign, source, keyword and first-time caller.
- Calculate answered, missed, answer rate, qualified/won leads and total call value.
- Read Google Ads and GA4 status endpoints for accepted/failed delivery evidence.
- Label modelled advertising cost as estimated; do not present it as provider-billed spend.
Security
Keep keys in server-side secret storage. Never put them in browser code, mobile bundles, URLs, screenshots, logs or AI prompts. Use separate keys per integration, narrow scopes where practical, rotate suspected keys immediately and use the request ID when contacting support.
Versioning and support
The current API version is v1. Additive fields may appear without a version change; breaking changes receive a new version and migration notice. Contact info@callbullet.com with a request ID for support.