REST API
The Thirdlane Platform provides a comprehensive REST API for programmatic management of PBX resources, so external applications and scripts can create, read, update, and delete configuration objects instead of clicking through the GUI. Use it whenever you need to automate repetitive work - onboarding hundreds of users from an HR system, syncing configuration from a provisioning tool, or pulling call data into a dashboard - or to integrate Thirdlane with the rest of your stack.
The same object model powers both the GUI and the API, so anything you can configure by hand can generally be scripted, and changes made either way stay consistent.
API Documentation
Interactive API documentation is available on every Thirdlane installation. Access it from Tools > OpenAPI REST in Configuration Manager, or navigate to /apitest/openapi/ on your server.
The documentation is built on OpenAPI 3.1 specifications and provides:
- Browsable API reference — All endpoints grouped by category (Platform Administration and Tenant Configuration)
- Interactive testing — Execute API calls directly from the browser with your active session
- Tenant selector — Dynamically switch the target tenant for tenant-scoped operations
- Complete schemas — Request/response models with field descriptions, types, and examples
See the OpenAPI REST page for usage details and curl examples.
Covered APIs
The API covers 45+ entities across two categories. The interactive reference always shows the exact, current set for your installation.
Platform Administration (global scope):
- Organizations (tenants), Enterprises, Resellers, Administrators
- Servers, Locations, DIDs, SIP Trunks
- API Keys, Webhooks, System Webhooks
Tenant Configuration (tenant-scoped):
- User Extensions, Dynamic Agents, Queues, Hunt Groups, Pickup Groups
- Inbound Routes, Outbound Routes, Routing Conditions
- Voice Menus (IVR), Schedules, Feature Extensions, Special Endpoints, Office Modes
- Special Mailboxes, Conference Rooms, Company Directory, Managed Devices
- Departments, Emergency Locations, Tags, Click-to-Call Widgets
- Recordings (voice prompts), Connect Channels, Tenant Branding, Messaging Channels, Outbound Webhooks
- CRM: Contacts, Accounts, Leads, Lists, Import Maps, Custom Fields, Activities, Tasks, Campaigns, Deals
- Migration Import: recordings, voicemail, Music on Hold, and bulk CDR
Data import and media upload
Beyond configuration, a dedicated set of tenant-scoped endpoints imports historical data and media - recorded calls, voicemail messages and greetings, Music on Hold, voice prompts, and bulk Call Detail Records (CDR). These are source-neutral (not tied to any one PBX) and idempotent, so they suit both large migrations from another system and one-off uploads. See the Data Migration and Import guide for the full endpoint reference and a worked example.
Authentication
API requests can be authenticated using:
- Session cookie (
sid) — Used by the interactive documentation UI - Basic Authentication — Username and password for programmatic access
- API Keys — Create and manage keys in API Keys
Common Use Cases
- Provisioning automation — Bulk create users, extensions, and routes from external systems
- CRM integration — Look up caller information, log calls
- Monitoring — Pull CDR data, check user status
- Configuration management — Script repetitive configuration tasks
- Migration and media upload — Import call recordings, voicemail, hold music, prompts, and CDR from another system (see Data Migration and Import)
Integration Points
Beyond the REST API, the platform supports:
- Event Hooks — Trigger HTTP callbacks on PBX events
- Webhooks — Send notifications to external services
- CRM Integration — Built-in connectors for popular CRMs
- Automations — Zapier-based workflow automation
Best practices
- Authenticate with API keys, not passwords. Create a dedicated key per integration in API Keys so you can revoke one integration’s access without changing credentials everywhere else.
- Test in the interactive docs first. Use Tools > OpenAPI REST to explore an endpoint and confirm the request/response shape before writing code against it.
- Scope requests to the right tenant. For tenant-scoped entities, always target the intended tenant; the OpenAPI UI’s tenant selector shows the exact path your code should use.
- Prefer event hooks and webhooks for reacting to events rather than polling the API on a timer - they are timelier and lighter on the server.
- Automate provisioning in batches and check responses for per-record errors so a single bad row does not silently skip users.
Related documentation
- OpenAPI REST - usage details and curl examples
- Data Migration and Import - import recordings, voicemail, media, and CDR
- API Keys - create and manage authentication keys
- Event Hooks - trigger callbacks on PBX events
- Automations - no-code workflow integrations