Call Bullet

Call Bullet API

Pull call outcomes and attribution into your CRM, reporting platform or custom application. Keys are restricted to the workspaces, tracking numbers and permissions you choose.

Bearer keys

Secrets are shown once and stored only as hashes.

Tenant isolation

Every request reapplies the key's workspace and number allowlist.

Stable v1 contract

JSON, ISO-8601 times, E.164 numbers and GBP values in pence.

Quick start

Create a key under Integrations → Developer API, store it in a server-side environment variable, then request your permitted workspaces.

curl https://callbullet.com/api/public/v1/workspaces \
  -H "Authorization: Bearer $CALL_BULLET_API_KEY"

Endpoints

MethodPathReturns
GET/accountKey owner, permissions and permitted workspace IDs
GET/workspacesAccessible client workspaces
GET/workspaces/{workspace_id}One workspace
GET/workspaces/{workspace_id}/numbersTracking numbers and placements
GET/workspaces/{workspace_id}/callsCalls, outcomes, values and marketing fields
GET/calls/{call_id}One call
GET/calls/{call_id}/attributionSource evidence and confidence
GET/calls/{call_id}/recordingShort-lived recording link when available
GET/calls/{call_id}/transcriptTranscript and summary when available
GET/workspaces/{workspace_id}/leadsLead status, value and next action
GET/integrations/google-ads/statusGoogle Ads delivery evidence
GET/integrations/ga4/statusGA4 delivery evidence

Calls and attribution

Call lists support from, to, updated_since, answered, direction, source, caller=first|repeat, lead_status, tag, number_id, sort, order, page and per_page.

GET https://callbullet.com/api/public/v1/workspaces/{workspace_id}/calls?from=2026-09-01T00:00:00Z&answered=true&per_page=100

Responses include call outcome, duration, first/repeat caller, values, UTMs, landing/referrer URLs, click ID type, device, campaign and keyword data when captured. Attribution evidence and confidence use the dedicated sub-resource.

Outbound webhooks

Add an HTTPS destination under Integrations → Developer API for signed call.created, call.updated and call.completed events. Call Bullet retries failed deliveries and records every attempt.

X-Call-Bullet-Event: call.completed
X-Call-Bullet-Delivery: <event UUID>
X-Call-Bullet-Timestamp: <Unix timestamp>
X-Call-Bullet-Signature: v1=<HMAC-SHA256(timestamp + "." + raw_body)>

Pagination, errors and limits

  • Page size is capped at 100. Call-list responses include page, total_records, total_pages and has_next_page.
  • Use updated_since for incremental CRM sync and retain call IDs as stable external identifiers.
  • Errors use a consistent JSON envelope and request ID. Expect 401, 403, 404, 422 and 429.
  • Read requests allow 120 per minute per key. A 429 response includes Retry-After.
  • Recording links expire after 15 minutes. Never store or expose them as permanent public URLs.

Daily PPC reporting recipe

  1. Read calls incrementally using updated_since.
  2. Group by campaign, source, keyword and first-time caller.
  3. Calculate answered, missed, answer rate, qualified/won leads and total call value.
  4. Read Google Ads and GA4 status endpoints for accepted/failed delivery evidence.
  5. Label modelled advertising cost as estimated; do not present it as provider-billed spend.

Security

Keep keys in server-side secret storage. Never put them in browser code, mobile bundles, URLs, screenshots, logs or AI prompts. Use separate keys per integration, narrow scopes where practical, rotate suspected keys immediately and use the request ID when contacting support.

Versioning and support

The current API version is v1. Additive fields may appear without a version change; breaking changes receive a new version and migration notice. Contact info@callbullet.com with a request ID for support.