Fixit backend release verdict
Production environment · 09 Oct 2026, 10:54
Fixit backend: ready for approvalEvery one of the 367 checks on the production environment gave the right answer. No issues found.
Overall score100%of checks gave the right answer
Features working15 / 15product features with no issues
Checks passed367142 work correctly · 225 block misuse
Issues0nothing to fix
Not tested99left out on purpose
How to read this. After every backend release an automated check uses the product the same way the app does, calling each feature's API 367 times in about five minutes. Nothing is changed or deleted. Works correctly: the feature returned the right information. Blocks misuse: we deliberately sent a wrong or unauthorised request and the system correctly refused it. Not tested: left out on purpose (payments, CRM and Meta/Google Ads are out of scope) or it would trigger a real action such as sending a message.
Feature health cards
One card per product feature. Click a card to see that feature's API calls.
Login & accountsWorking
Signing in with a phone number, sign-up and session handling
100% health
12 API calls4 work correctly8 block misuse0 issues0 not tested
Dashboards & reportingWorking
KPI tiles, funnels, charts and performance numbers
100% health
41 API calls39 work correctly2 block misuse0 issues0 not tested
Campaign managementWorking
Creating, listing and managing campaigns
100% health
28 API calls14 work correctly14 block misuse0 issues0 not tested
Lead managementWorking
Lead lists, search, lead details and status updates
100% health
24 API calls12 work correctly12 block misuse0 issues0 not tested
Workflows & follow-upsWorking
Automated follow-up flows and call/WhatsApp steps
100% health
16 API calls6 work correctly10 block misuse0 issues0 not tested
AI prompts & voice settingsWorking
The AI agent's prompts, voices and languages
100% health
18 API calls9 work correctly9 block misuse0 issues0 not tested
WhatsApp messagingWorking
WhatsApp templates and the WhatsApp Business connection
100% health
20 API calls8 work correctly11 block misuse0 issues1 not tested
Market intelligence & recommendationsWorking
Competitor insights and strategy recommendations
100% health
24 API calls20 work correctly4 block misuse0 issues0 not tested
Landing pages & contentWorking
Generated landing pages, brand kit and documents
100% health
24 API calls2 work correctly22 block misuse0 issues0 not tested
Knowledge baseWorking
Documents the AI agent learns from
100% health
8 API calls1 work correctly7 block misuse0 issues0 not tested
Team & company settingsWorking
Company profile, team members and preferences
100% health
56 API calls10 work correctly29 block misuse0 issues17 not tested
Integrations & connectionsWorking
Connected tools such as calling providers and Instagram
100% health
54 API calls12 work correctly30 block misuse0 issues12 not tested
Calls & voice agentWorking
Manual calls, call logging and the voice agent
100% health
8 API calls0 work correctly5 block misuse0 issues3 not tested
Admin tools (internal staff)Working
Fixit's internal admin screens
100% health
68 API calls1 work correctly59 block misuse0 issues8 not tested
System health & webhooksWorking
Health checks and messages from outside services
100% health
65 API calls4 work correctly3 block misuse0 issues58 not tested
Each feature's API calls
Click a feature to see every API call that was made for it, grouped by result. Features with issues open automatically.
Login & accounts
Working12 API calls · 4 work correctly · 8 block misuse · 0 issues · 0 not tested
Login & accounts
WorkingWorks correctly (4 API calls)
- ✓ Login step 1: look up the test phone before sending an OTP (public route, no token)
POST /api/inbound/check_phone_validation - ✓ View the nurturing agent number
GET /api/inbound/api/me - ✓ View the caller's own active sessions
GET /api/inbound/auth/sessions - ✓ Tell the admin UI whether to render for this caller
GET /api/inbound/auth/staff-status
Blocks misuse (8 API calls)
- ✓ Logout is protected: a request with no login token must be refused
POST /api/inbound/auth/logout - ✓ Phone validation rejects a malformed number ('not-a-phone')
POST /api/inbound/check_phone_validation - ✓ Registration needs a verified Firebase login; without one it must be refused (no account is created)
POST /api/inbound/auth/register - ✓ Blocks an invalid or unauthorised attempt to: end every active app session for the caller's own account
POST /api/inbound/auth/sessions/revoke-all - ✓ Blocks an invalid or unauthorised attempt to: revoke exactly one of the caller's own sessions, e.g. "log out that device"
DELETE /api/inbound/auth/sessions/{session_id} - ✓ Blocks an invalid or unauthorised attempt to: verifies the WhatsApp in-app admin panel password and, on success,
POST /api/inbound/auth/whatsapp-admin-verify - ✓ Blocks an invalid or unauthorised attempt to: legacy route: redirect to the new confirmation flow
GET /api/inbound/deletion-requests/{account_id}/{request_id}/verify - ✓ Blocks an invalid or unauthorised attempt to: public demo trigger: capture a lead and arm the engagement sequence
POST /api/inbound/qualifier-web/trigger
Dashboards & reporting
Working41 API calls · 39 work correctly · 2 block misuse · 0 issues · 0 not tested
Dashboards & reporting
WorkingWorks correctly (39 API calls)
- ✓ Overview dashboard: headline KPI tiles
GET /api/inbound/dashboards/overview/kpis - ✓ Overview dashboard: lead funnel trend chart
GET /api/inbound/dashboards/overview/lead-funnel-trend - ✓ Overview dashboard: revenue charts
GET /api/inbound/dashboards/overview/revenue-charts - ✓ Overview dashboard: cost funnel
GET /api/inbound/dashboards/overview/cost-funnel - ✓ Overview dashboard: spend funnel
GET /api/inbound/dashboards/overview/spend-funnel - ✓ Overview dashboard: campaigns-at-a-glance table
GET /api/inbound/dashboards/overview/campaigns-at-glance - ✓ Overview dashboard: how buyers find you
GET /api/inbound/dashboards/overview/buyers-find-you - ✓ Marketing dashboard: KPI tiles
GET /api/inbound/dashboards/marketing/overview/kpis - ✓ Marketing dashboard: pace-to-goal tracker
GET /api/inbound/dashboards/marketing/overview/pace-to-goal - ✓ Marketing dashboard: risk flags
GET /api/inbound/dashboards/marketing/overview/risk-flags - ✓ Marketing dashboard: campaign health
GET /api/inbound/dashboards/marketing/overview/campaign-health - ✓ Marketing dashboard: channel efficiency
GET /api/inbound/dashboards/marketing/overview/channel-efficiency - ✓ Engagement funnel metrics
GET /api/inbound/dashboards/engagement-funnel/metrics - ✓ Channel health metrics
GET /api/inbound/dashboards/channel-health/metrics - ✓ Channel analytics metrics
GET /api/inbound/dashboards/channel-analytics/metrics - ✓ Best times to reach leads
GET /api/inbound/dashboards/best-times/metrics - ✓ Follow-up effectiveness metrics
GET /api/inbound/dashboards/followup-effectiveness/metrics - ✓ Voice agent KPIs
GET /api/inbound/dashboards/voicebot/kpis - ✓ Sales dashboard: leads that need action
GET /api/inbound/dashboards/sales/needs-action - ✓ Best-performing prompts list
GET /api/inbound/best_performing_prompts - ✓ Lead conversion summary; also checks totalLeads and each outcome count is a number
GET /api/inbound/qualified_leads_summary - ✓ View action items for leads
GET /api/inbound/action_items - ✓ Analytics dashboard endpoint: returns agent performance and lead source analysis for the current user only
GET /api/inbound/analytics - ✓ KPI endpoint for dashboard overview cards:
GET /api/inbound/dashboard_overview_metrics - ✓ By-format and by-angle spend breakdown bars
GET /api/inbound/dashboards/marketing/creatives/breakdown - ✓ Creative performance table
GET /api/inbound/dashboards/marketing/creatives/table - ✓ Per-platform keyword strategy or audience performance drill-down
GET /api/inbound/dashboards/marketing/mix/deep-dive - ✓ Segment table grouped by channel, brand, or project
GET /api/inbound/dashboards/marketing/mix/segments - ✓ Recommended agent actions from the latest F Intel Recommendation
GET /api/inbound/dashboards/marketing/overview/agent-moves - ✓ Counts of dropped leads, split into the two panels of "Why leads dropped"
GET /api/inbound/dashboards/sales/drop-reasons - ✓ Per-batch Dialed/Reached/Engaged/Qualified/Status for one prompt
GET /api/inbound/dashboards/voicebot/batch-performance - ✓ Outcome donut: answered / voicemail / no answer / failed / other
GET /api/inbound/dashboards/voicebot/call-outcomes - ✓ Stage funnel and themes for the prompt's current version
GET /api/inbound/dashboards/voicebot/call-progression - ✓ Daily call counts for the line chart
GET /api/inbound/dashboards/voicebot/call-volume - ✓ Pickup rate by 3-hour window, read from the durable fact table
GET /api/inbound/dashboards/voicebot/pick-rate-by-time - ✓ Cross-prompt table: Prompt · Calls · Pickup · Avg duration · Qualified
GET /api/inbound/dashboards/voicebot/prompt-comparison - ✓ View leaderboard ranking of all users in an organization based on qualified leads count
GET /api/inbound/leaderboard - ✓ View WhatsApp templates ranked by reply rate
GET /api/inbound/template_performance - ✓ View WhatsApp analytics data for graph visualization showing daily counts of sent, delivered, read, and failed messages
GET /api/inbound/whatsapp_analytics
Blocks misuse (2 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: the calls behind one theme, newest first, one page at a time
GET /api/inbound/dashboards/voicebot/theme-calls - ✓ Blocks an invalid or unauthorised attempt to: force a theme re-clustering run instead of waiting for the nightly job
POST /api/inbound/dashboards/voicebot/themes/resync
Campaign management
Working28 API calls · 14 work correctly · 14 block misuse · 0 issues · 0 not tested
Campaign management
WorkingWorks correctly (14 API calls)
- ✓ A logged-in user's token is accepted on a protected route
GET /api/inbound/campaign/user/campaign-names - ✓ Campaigns page: first page of the campaign list
GET /api/inbound/list-campaign - ✓ Campaign picker: names of the user's campaigns
GET /api/inbound/campaign/user/campaign-names - ✓ Current user's campaign details
GET /api/inbound/campaign/user - ✓ Project catalogs used by campaign filters
GET /api/inbound/project-catalogs - ✓ Check DND setting, first message, voice settings, prompt quality, and lead names
GET /api/inbound/api/sanity-check/campaign-config - ✓ Estimate whether the campaign owner's wallet has enough usable credits to run a
GET /api/inbound/api/sanity-check/credits - ✓ Count PENDING/HANDLING call cron-jobs scheduled in the next 30 minutes
GET /api/inbound/api/sanity-check/cron-jobs - ✓ Check provider slot-count keys in Redis
GET /api/inbound/api/sanity-check/redis-locks - ✓ For each unique telephony provider that will handle the selected batch leads,
GET /api/inbound/api/sanity-check/telephony - ✓ Probe the voice-bot /ready endpoint
GET /api/inbound/api/sanity-check/voice-bot - ✓ View Gupshup WABA health for the campaign's WhatsApp Business App
GET /api/inbound/api/sanity-check/waba-health - ✓ Search campaigns by name
GET /api/inbound/campaign/search-campaigns - ✓ View Campaign
GET /api/inbound/get-campaign
Blocks misuse (14 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: create a new campaign and associated records
POST /api/inbound/campaign/create-campaign - ✓ Blocks an invalid or unauthorised attempt to: duplicate a campaign: its settings, WhatsApp templates, prompts used by the
POST /api/inbound/campaign/duplicate-campaign - ✓ Blocks an invalid or unauthorised attempt to: bulk transfer or copy leads between campaigns
POST /api/inbound/campaign/process-leads - ✓ Blocks an invalid or unauthorised attempt to: [Deprecated] Toggle: ACTIVE <-> PAUSED. Use /pause and /resume instead
PATCH /api/inbound/campaign/toggle-campaign-status/{campaign_id} - ✓ Blocks an invalid or unauthorised attempt to: delete a campaign and all associated data
DELETE /api/inbound/campaign/{campaign_id} - ✓ Blocks an invalid or unauthorised attempt to: abort a campaign
PATCH /api/inbound/campaign/{campaign_id}/abort - ✓ Blocks an invalid or unauthorised attempt to: set or clear the campaign-level default WhatsApp template
PATCH /api/inbound/campaign/{campaign_id}/default-whatsapp-template - ✓ Blocks an invalid or unauthorised attempt to: pause an active campaign
PATCH /api/inbound/campaign/{campaign_id}/pause - ✓ Blocks an invalid or unauthorised attempt to: restart an aborted campaign
PATCH /api/inbound/campaign/{campaign_id}/restart - ✓ Blocks an invalid or unauthorised attempt to: resume a paused campaign
PATCH /api/inbound/campaign/{campaign_id}/resume - ✓ Blocks an invalid or unauthorised attempt to: create Campaign
POST /api/inbound/create-campaign - ✓ Blocks an invalid or unauthorised attempt to: generate Creative
POST /api/inbound/generate-creative - ✓ Blocks an invalid or unauthorised attempt to: reassign an agent for a particular lead
PUT /api/inbound/reassign_agent - ✓ Blocks an invalid or unauthorised attempt to: save Creative
POST /api/inbound/save-creative
Lead management
Working24 API calls · 12 work correctly · 12 block misuse · 0 issues · 0 not tested
Lead management
WorkingWorks correctly (12 API calls)
- ✓ Leads page: first page of the leads list
GET /api/inbound/leads_list - ✓ Leads page filtered to starred leads
GET /api/inbound/leads_list - ✓ Lead search by name or phone (searching '91')
GET /api/inbound/search_leads - ✓ View conversation transcripts for a lead
GET /api/inbound/conversation_transcript - ✓ View aggregated lead statistics
GET /api/inbound/lead_data - ✓ View lead intelligence for a lead
GET /api/inbound/lead_intelligence - ✓ View the org's selectable lead statuses as {value, label} for dropdowns
GET /api/inbound/leads/status-options - ✓ Per-lead engagement flow progress for the lead-detail canvas
GET /api/inbound/leads/{lead_id}/flow-progress - ✓ View lead by lead ID
GET /api/inbound/leads_by_name - ✓ View leads sorted by lead score in descending order
GET /api/inbound/leads_by_score - ✓ Group leads by excel batch ID
GET /api/inbound/leads_grouped_by_batch - ✓ Search Qualified Leads
GET /api/inbound/search_qualified_leads
Blocks misuse (12 API calls)
- ✓ Starring a lead must say which lead: an empty request must be rejected (nothing is written)
POST /api/inbound/star_lead - ✓ Blocks an invalid or unauthorised attempt to: add tags to a lead's lead data field
POST /api/inbound/add_lead_tags - ✓ Blocks an invalid or unauthorised attempt to: remove tag keys from a lead's lead data
POST /api/inbound/delete_lead_tags - ✓ Blocks an invalid or unauthorised attempt to: download leads as an Excel file
POST /api/inbound/leads/download - ✓ Blocks an invalid or unauthorised attempt to: add Lead Concern
POST /api/inbound/leads/{lead_id}/concerns - ✓ Blocks an invalid or unauthorised attempt to: clear Lead Concerns
DELETE /api/inbound/leads/{lead_id}/concerns - ✓ Blocks an invalid or unauthorised attempt to: create a new next step
POST /api/inbound/leads/{lead_id}/next-steps - ✓ Blocks an invalid or unauthorised attempt to: edit an existing next step
PATCH /api/inbound/leads/{lead_id}/next-steps/{step_id} - ✓ Blocks an invalid or unauthorised attempt to: delete an existing next step
DELETE /api/inbound/leads/{lead_id}/next-steps/{step_id} - ✓ Blocks an invalid or unauthorised attempt to: update lead status
PATCH /api/inbound/leads/{lead_id}/status - ✓ Blocks an invalid or unauthorised attempt to: delete leads matching the provided status filters within their org
DELETE /api/inbound/leads_list - ✓ Blocks an invalid or unauthorised attempt to: update Lead Status
POST /api/inbound/update_lead_status
Workflows & follow-ups
Working16 API calls · 6 work correctly · 10 block misuse · 0 issues · 0 not tested
Workflows & follow-ups
WorkingWorks correctly (6 API calls)
- ✓ Workflows page: starter workflow templates
GET /api/inbound/predefined-flows - ✓ Workflows saved on the test account's first campaign
GET /api/inbound/engagement_flows/{campaign_id} - ✓ View WhatsApp followups
GET /api/inbound/control_table_and_followups - ✓ View followup history for a specific lead
GET /api/inbound/followup_history - ✓ IVR analytics for an outbound DTMF IVR step
GET /api/inbound/ivr_analytics - ✓ View IVR templates for a campaign
GET /api/inbound/ivr_flows/{campaign_id}
Blocks misuse (10 API calls)
- ✓ Saving a workflow needs a body: an empty request must be rejected (nothing is written)
POST /api/inbound/engagement_flow - ✓ Blocks an invalid or unauthorised attempt to: update WhatsApp followups
PUT /api/inbound/control_table_and_followups - ✓ Blocks an invalid or unauthorised attempt to: create a follow-up batch for specific leads and add to a queue
POST /api/inbound/create_followup_batch - ✓ Blocks an invalid or unauthorised attempt to: update a specific engagement flow by its ID
PUT /api/inbound/engagement_flow/{flow_id} - ✓ Blocks an invalid or unauthorised attempt to: delete a specific engagement flow by its ID
DELETE /api/inbound/engagement_flow/{flow_id} - ✓ Blocks an invalid or unauthorised attempt to: generate an engagement flow
POST /api/inbound/generate_engagement_flow - ✓ Blocks an invalid or unauthorised attempt to: create an IVR template. The payload validates the menu tree
POST /api/inbound/ivr_flow - ✓ Blocks an invalid or unauthorised attempt to: view a single IVR template by id
GET /api/inbound/ivr_flow/{ivr_flow_id} - ✓ Blocks an invalid or unauthorised attempt to: update an IVR template. When ``nodes`` is provided the tree is re-validated
PUT /api/inbound/ivr_flow/{ivr_flow_id} - ✓ Blocks an invalid or unauthorised attempt to: delete an IVR template
DELETE /api/inbound/ivr_flow/{ivr_flow_id}
AI prompts & voice settings
Working18 API calls · 9 work correctly · 9 block misuse · 0 issues · 0 not tested
AI prompts & voice settings
WorkingWorks correctly (9 API calls)
- ✓ Prompt library: predefined prompt templates
GET /api/inbound/prompts/predefined-prompts - ✓ Voice settings: available languages
GET /api/inbound/api/voice_settings/languages - ✓ Voice settings: available voice models
GET /api/inbound/api/voice_settings/voicebot_types - ✓ Voice settings: the user's starred voices
GET /api/inbound/api/voice_settings/favourites - ✓ Prompt library: defaults for a new prompt in that campaign
GET /api/inbound/api/user_prompts/new-defaults - ✓ Prompt library: prompts saved on that campaign
GET /api/inbound/api/user_prompts - ✓ Voice settings saved on that campaign's first prompt
GET /api/inbound/api/voice_settings - ✓ View a specific prompt by prompt ID,
GET /api/inbound/api/user_prompt - ✓ Percentage of this campaign's leads
GET /api/inbound/api/user_prompt/field_fill_rates
Blocks misuse (9 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: create a new prompt record for a
POST /api/inbound/api/user_prompts - ✓ Blocks an invalid or unauthorised attempt to: mark the supplied prompt as the active/default prompt for the campaign
POST /api/inbound/api/user_prompts/default - ✓ Blocks an invalid or unauthorised attempt to: delete a specific prompt record by prompt ID
DELETE /api/inbound/api/user_prompts/{prompt_id} - ✓ Blocks an invalid or unauthorised attempt to: create or update TTS parameters for a user
POST /api/inbound/api/voice_settings - ✓ Blocks an invalid or unauthorised attempt to: update TTS parameters for a user
PUT /api/inbound/api/voice_settings - ✓ Blocks an invalid or unauthorised attempt to: star a voice. Idempotent
POST /api/inbound/api/voice_settings/favourites - ✓ Blocks an invalid or unauthorised attempt to: unstar a voice. Idempotent
DELETE /api/inbound/api/voice_settings/favourites - ✓ Blocks an invalid or unauthorised attempt to: generate Tts
POST /api/inbound/prompts/generate-tts - ✓ Blocks an invalid or unauthorised attempt to: update user prompt and first message from frontend
POST /api/inbound/user_prompt
WhatsApp messaging
Working20 API calls · 8 work correctly · 11 block misuse · 0 issues · 1 not tested
WhatsApp messaging
WorkingWorks correctly (8 API calls)
- ✓ View the nurturing agent number
GET /api/inbound/api/get_nurturing_agent_number - ✓ Regenerate the signed link for a Gupshup app
GET /api/inbound/gupshup/regenerate-signed-link - ✓ Verify a Gupshup app
GET /api/inbound/gupshup/verify-app - ✓ View Waba Account
GET /api/inbound/gupshup/waba-account/{campaign_id} - ✓ View WhatsApp delivery funnel analytics for a campaign
GET /api/inbound/whatsapp-template/analytics - ✓ View all templates for a WhatsApp campaign
GET /api/inbound/whatsapp-template/get - ✓ View whether a custom template is configured for the organization
GET /api/inbound/whatsapp-template/is-custom-template - ✓ Cumulative per-template delivery funnel stats for a campaign
GET /api/inbound/whatsapp-template/template-stats
Blocks misuse (11 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: update the nurturing agent number
POST /api/inbound/api/update_nurturing_agent_number - ✓ Blocks an invalid or unauthorised attempt to: create a new Gupshup Partner App for WhatsApp onboarding
POST /api/inbound/gupshup/create-app - ✓ Blocks an invalid or unauthorised attempt to: delete or disconnect a Gupshup app subscriptions
DELETE /api/inbound/gupshup/delete-app - ✓ Blocks an invalid or unauthorised attempt to: view Gupshup integration details for all campaigns in an organization
GET /api/inbound/gupshup/get-app-info - ✓ Blocks an invalid or unauthorised attempt to: migrate a Gupshup app from its current source
POST /api/inbound/gupshup/transfer-integration - ✓ Blocks an invalid or unauthorised attempt to: check the approval status of a single template from Gupshup
GET /api/inbound/whatsapp-template/check-template-status - ✓ Blocks an invalid or unauthorised attempt to: create a template for a WhatsApp campaign
POST /api/inbound/whatsapp-template/create - ✓ Blocks an invalid or unauthorised attempt to: delete one or more templates for a WhatsApp campaign
DELETE /api/inbound/whatsapp-template/delete - ✓ Blocks an invalid or unauthorised attempt to: edit a template for a WhatsApp campaign
PATCH /api/inbound/whatsapp-template/edit - ✓ Blocks an invalid or unauthorised attempt to: proxy single-template analytics from Gupshup, cache result to DB, return
GET /api/inbound/whatsapp-template/gupshup-analytics/{gupshup_template_id} - ✓ Blocks an invalid or unauthorised attempt to: update the attempt number for one or more templates
PATCH /api/inbound/whatsapp-template/update-attempt-number
Not tested (1 API calls)
- – Handle Outperform WhatsApp webhook for inbound messages (Would trigger a real action (e.g. a webhook))
POST /api/inbound/outperform/whatsapp/webhook
Market intelligence & recommendations
Working24 API calls · 20 work correctly · 4 block misuse · 0 issues · 0 not tested
Market intelligence & recommendations
WorkingWorks correctly (20 API calls)
- ✓ Ad Placements
GET /api/inbound/intelligence/competition/ad-placements - ✓ Channel Partners
GET /api/inbound/intelligence/competition/channel-partners - ✓ Paid Channel performance heat-map, derived live from ``active ads``, not ``outcome index`` organic proxies
GET /api/inbound/intelligence/competition/channel-performance - ✓ Demand Index
GET /api/inbound/intelligence/competition/demand-index - ✓ Builder→project table. Builders aggregate their projects
GET /api/inbound/intelligence/competition/entities - ✓ Gaps
GET /api/inbound/intelligence/competition/gaps - ✓ KPI cards for the Competition tab
GET /api/inbound/intelligence/competition/kpis - ✓ Platform Strength
GET /api/inbound/intelligence/competition/platform-strength - ✓ Search Keywords
GET /api/inbound/intelligence/competition/search-keywords - ✓ Theme Density
GET /api/inbound/intelligence/competition/theme-density - ✓ Viewer's display currency, resolved the same way as the rest of
GET /api/inbound/intelligence/currency - ✓ Facet counts so the UI can show totals beside each filter
GET /api/inbound/intelligence/explorer/filters - ✓ Explorer Items
GET /api/inbound/intelligence/explorer/items - ✓ Presence & sentiment per channel
GET /api/inbound/intelligence/pulse/channels - ✓ The five KPI cards at the top of the Pulse tab
GET /api/inbound/intelligence/pulse/kpis - ✓ Two columns: what's working, what's not
GET /api/inbound/intelligence/pulse/signals - ✓ Paid vs organic, for spend and reach
GET /api/inbound/intelligence/pulse/split - ✓ Strategy Parameters
GET /api/inbound/intelligence/strategy/parameters - ✓ Strategy Playbook
GET /api/inbound/intelligence/strategy/playbook - ✓ Strategy Recommendations
GET /api/inbound/intelligence/strategy/recommendations
Blocks misuse (4 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: view scraped comments/replies for a single post or video
GET /api/inbound/intelligence/explorer/items/{item_id}/comments - ✓ Blocks an invalid or unauthorised attempt to: recommend Campaign Objective
GET /api/inbound/recommend-campaign-objective - ✓ Blocks an invalid or unauthorised attempt to: recommend Platform Split
GET /api/inbound/recommend-platform-split - ✓ Blocks an invalid or unauthorised attempt to: recommend Strategy
GET /api/inbound/recommend-strategy
Landing pages & content
Working24 API calls · 2 work correctly · 22 block misuse · 0 issues · 0 not tested
Landing pages & content
WorkingWorks correctly (2 API calls)
- ✓ View all brand kits associated
GET /api/inbound/brand-kit - ✓ View Sites
GET /api/inbound/landing-page/sites
Blocks misuse (22 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: generate a presigned URL for a blob in Azure Blob Storage
POST /api/inbound/api/blob/presigned-url - ✓ Blocks an invalid or unauthorised attempt to: generate a presigned URL for a blob in Azure Blob Storage
GET /api/inbound/api/blob/presigned-url - ✓ Blocks an invalid or unauthorised attempt to: extract structured lead data from an Excel or CSV file at the given URL
POST /api/inbound/api/document/extract - ✓ Blocks an invalid or unauthorised attempt to: preview how a default country code would recover country-code-less numbers
POST /api/inbound/api/document/revalidate-phones - ✓ Blocks an invalid or unauthorised attempt to: upload Leads
POST /api/inbound/api/document/upload - ✓ Blocks an invalid or unauthorised attempt to: update the brand kit
PUT /api/inbound/brand-kit - ✓ Blocks an invalid or unauthorised attempt to: delete a brand asset by its filename
DELETE /api/inbound/brand-kit/assets - ✓ Blocks an invalid or unauthorised attempt to: upload a brand asset file directly to S3 and register it
POST /api/inbound/brand-kit/assets/upload - ✓ Blocks an invalid or unauthorised attempt to: use the LLM to suggest fonts matching a vibe description
POST /api/inbound/brand-kit/suggest-fonts - ✓ Blocks an invalid or unauthorised attempt to: analyse the brief and return structured questions about missing/vague info
POST /api/inbound/landing-page/clarify - ✓ Blocks an invalid or unauthorised attempt to: score an arbitrary public URL on SEO, AEO, and GEO findability
POST /api/inbound/landing-page/findability-score-by-url - ✓ Blocks an invalid or unauthorised attempt to: generate Site
POST /api/inbound/landing-page/generate - ✓ Blocks an invalid or unauthorised attempt to: view the current status and metadata for a generation run
GET /api/inbound/landing-page/generation/{site_id} - ✓ Blocks an invalid or unauthorised attempt to: edit all pages of a generated site by sending instructions to the LLM
POST /api/inbound/landing-page/generation/{site_id}/edit - ✓ Blocks an invalid or unauthorised attempt to: edit a specific HTML element on a generated page by CSS selector
POST /api/inbound/landing-page/generation/{site_id}/edit-element - ✓ Blocks an invalid or unauthorised attempt to: score a generated site on SEO, AEO, and GEO findability
GET /api/inbound/landing-page/generation/{site_id}/findability-score - ✓ Blocks an invalid or unauthorised attempt to: view all log entries for a generation run, ordered by creation time
GET /api/inbound/landing-page/generation/{site_id}/logs - ✓ Blocks an invalid or unauthorised attempt to: publish a generated site to a custom deploy path
POST /api/inbound/landing-page/sites/{site_id}/publish - ✓ Blocks an invalid or unauthorised attempt to: serve Brand Asset
GET /api/inbound/sites/serve-asset/{s3_key} - ✓ Blocks an invalid or unauthorised attempt to: serve Published Site
GET /api/inbound/sites/{deploy_path} - ✓ Blocks an invalid or unauthorised attempt to: serve Published Site Page
GET /api/inbound/sites/{deploy_path}/{page_path} - ✓ Blocks an invalid or unauthorised attempt to: serve Site Page
GET /api/inbound/sites/{org_id}/{site_id}/pages/{page_path}
Knowledge base
Working8 API calls · 1 work correctly · 7 block misuse · 0 issues · 0 not tested
Knowledge base
WorkingWorks correctly (1 API calls)
- ✓ Every knowledge base owned by the caller's org,
GET /api/inbound/knowledge-bases
Blocks misuse (7 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: create a knowledge base from a website URL and queue its first crawl
POST /api/inbound/knowledge-bases - ✓ Blocks an invalid or unauthorised attempt to: one knowledge base belonging to the caller's org
GET /api/inbound/knowledge-bases/{kb_id} - ✓ Blocks an invalid or unauthorised attempt to: rename a knowledge base, toggle its 24-hour sync, or retune its no results gate
PATCH /api/inbound/knowledge-bases/{kb_id} - ✓ Blocks an invalid or unauthorised attempt to: delete a knowledge base, its vectors and its page rows
DELETE /api/inbound/knowledge-bases/{kb_id} - ✓ Blocks an invalid or unauthorised attempt to: add a PDF the crawler cannot reach
POST /api/inbound/knowledge-bases/{kb_id}/documents - ✓ Blocks an invalid or unauthorised attempt to: the per-URL ingest result list
GET /api/inbound/knowledge-bases/{kb_id}/pages - ✓ Blocks an invalid or unauthorised attempt to: queue a re-crawl of one knowledge base
POST /api/inbound/knowledge-bases/{kb_id}/sync
Team & company settings
Working56 API calls · 10 work correctly · 29 block misuse · 0 issues · 17 not tested
Team & company settings
WorkingWorks correctly (10 API calls)
- ✓ View all feedback for a specific lead, ordered by updated at
GET /api/inbound/api/feedback/{lead_id} - ✓ View Profile
GET /api/inbound/company-profile - ✓ Authorize Google Analytics Route
GET /api/inbound/company-profile/google-analytics/authorize - ✓ View Google Analytics Connection Route
GET /api/inbound/company-profile/google-analytics/connection - ✓ View Google Analytics Properties Route
GET /api/inbound/company-profile/google-analytics/properties - ✓ View Mcp Connector Url Route
GET /api/inbound/company-profile/mcp/connector-url - ✓ View Projects Route
GET /api/inbound/company-profile/projects - ✓ View the org's {canonical status: alias label} map
GET /api/inbound/org/lead-status-aliases - ✓ Everyone in the caller's workspace, pending invites included
GET /api/inbound/org/members - ✓ View the authenticated user's org custom url and custom company name from d org if they exist,
GET /api/inbound/user/custom-url
Blocks misuse (29 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: update an existing feedback entry
PUT /api/inbound/api/feedback - ✓ Blocks an invalid or unauthorised attempt to: create a new feedback entry for a lead
POST /api/inbound/api/feedback - ✓ Blocks an invalid or unauthorised attempt to: delete a feedback entry
DELETE /api/inbound/api/feedback - ✓ Blocks an invalid or unauthorised attempt to: paginated consent audit history for DSAR/compliance lookups
GET /api/inbound/api/v1/consent/audit - ✓ Blocks an invalid or unauthorised attempt to: most recent consent record for a visitor or user
GET /api/inbound/api/v1/consent/latest - ✓ Blocks an invalid or unauthorised attempt to: persist one append-only cookie consent audit event
POST /api/inbound/api/v1/consent/log - ✓ Blocks an invalid or unauthorised attempt to: put Company
PUT /api/inbound/company-profile/company - ✓ Blocks an invalid or unauthorised attempt to: disconnect Google Analytics Route
POST /api/inbound/company-profile/google-analytics/disconnect - ✓ Blocks an invalid or unauthorised attempt to: exchange Google Analytics Code Route
POST /api/inbound/company-profile/google-analytics/oauth/exchange - ✓ Blocks an invalid or unauthorised attempt to: select Google Analytics Property Route
POST /api/inbound/company-profile/google-analytics/select-property - ✓ Blocks an invalid or unauthorised attempt to: sync Google Analytics Route
POST /api/inbound/company-profile/google-analytics/sync-now - ✓ Blocks an invalid or unauthorised attempt to: create Project Route
POST /api/inbound/company-profile/projects - ✓ Blocks an invalid or unauthorised attempt to: update Project Route
PUT /api/inbound/company-profile/projects/{project_catalog_id} - ✓ Blocks an invalid or unauthorised attempt to: delete Project Route
DELETE /api/inbound/company-profile/projects/{project_catalog_id} - ✓ Blocks an invalid or unauthorised attempt to: view Competitors Route
GET /api/inbound/company-profile/projects/{project_catalog_id}/competitors - ✓ Blocks an invalid or unauthorised attempt to: create Competitor Route
POST /api/inbound/company-profile/projects/{project_catalog_id}/competitors - ✓ Blocks an invalid or unauthorised attempt to: update Competitor Route
PUT /api/inbound/company-profile/projects/{project_catalog_id}/competitors/{entity_id} - ✓ Blocks an invalid or unauthorised attempt to: remove Competitor Route
DELETE /api/inbound/company-profile/projects/{project_catalog_id}/competitors/{entity_id} - ✓ Blocks an invalid or unauthorised attempt to: set Tracking Route
PATCH /api/inbound/company-profile/projects/{project_catalog_id}/competitors/{entity_id}/tracking - ✓ Blocks an invalid or unauthorised attempt to: view Company Profile Prompt
GET /api/inbound/company-profile/prompt - ✓ Blocks an invalid or unauthorised attempt to: save Company Profile Prompt Route
POST /api/inbound/company-profile/save-prompt - ✓ Blocks an invalid or unauthorised attempt to: create the Invited member, approve the phone for login, and email a sign-in link
POST /api/inbound/org/invites - ✓ Blocks an invalid or unauthorised attempt to: reissue the sign-in email for a still-pending invite. The member row is untouched
POST /api/inbound/org/invites/{handle}/resend - ✓ Blocks an invalid or unauthorised attempt to: replace the org's lead-status alias map
PUT /api/inbound/org/lead-status-aliases - ✓ Blocks an invalid or unauthorised attempt to: revoke a pending invite, or remove an active member
DELETE /api/inbound/org/members/{handle} - ✓ Blocks an invalid or unauthorised attempt to: reset a revoked member to Invited so they can sign in again on the same number
POST /api/inbound/org/members/{handle}/reinvite - ✓ Blocks an invalid or unauthorised attempt to: change a member to admin or user. The workspace owner stays super user
PATCH /api/inbound/org/members/{handle}/role - ✓ Blocks an invalid or unauthorised attempt to: hand the workspace owner role to someone else. Superuser only, self-service
POST /api/inbound/org/ownership/transfer - ✓ Blocks an invalid or unauthorised attempt to: store feedback submitted from the Fixi widget, scoped to the caller's org
POST /api/inbound/user-feedback
Not tested (17 API calls)
- – View Google Lead Forms Connection (Out of scope (payments, CRM, ads))
GET /api/inbound/company-profile/google-lead-forms/connection - – Every sheet syncing into one campaign, or (Out of scope (payments, CRM, ads))
GET /api/inbound/company-profile/google-lead-forms/connections - – Disconnect one sheet (Out of scope (payments, CRM, ads))
POST /api/inbound/company-profile/google-lead-forms/disconnect - – Import Google Lead Forms (Out of scope (payments, CRM, ads))
POST /api/inbound/company-profile/google-lead-forms/import - – Activate Meta Lead Ads Route (Out of scope (payments, CRM, ads))
POST /api/inbound/company-profile/meta-lead-ads/activate - – Connect Meta Lead Ads Route (Out of scope (payments, CRM, ads))
POST /api/inbound/company-profile/meta-lead-ads/connect - – View Meta Lead Ads Connection Route (Out of scope (payments, CRM, ads))
GET /api/inbound/company-profile/meta-lead-ads/connection - – Every Meta ad-account activation row for the org (Out of scope (payments, CRM, ads))
GET /api/inbound/company-profile/meta-lead-ads/connections - – Delete Meta Lead Ads Connection Route (Out of scope (payments, CRM, ads))
POST /api/inbound/company-profile/meta-lead-ads/delete - – Disconnect Meta Lead Ads Route (Out of scope (payments, CRM, ads))
POST /api/inbound/company-profile/meta-lead-ads/disconnect - – Discover Meta Lead Ads Route (Out of scope (payments, CRM, ads))
GET /api/inbound/company-profile/meta-lead-ads/discover - – Primary discovery path: resolve a pasted Page link/ID straight to its (Out of scope (payments, CRM, ads))
POST /api/inbound/company-profile/meta-lead-ads/find-page - – View Meta Lead Pages Route (Out of scope (payments, CRM, ads))
GET /api/inbound/company-profile/meta-lead-ads/pages - – Sync Meta Lead Ads Route (Out of scope (payments, CRM, ads))
POST /api/inbound/company-profile/meta-lead-ads/sync-now - – Credit movements newest first, plus how much this plan cycle has consumed - (Out of scope (payments, CRM, ads))
GET /api/inbound/user/credit-ledger - – Where this plan cycle's credits went, biggest activity first (Out of scope (payments, CRM, ads))
GET /api/inbound/user/credit-usage - – View the authenticated user's live credit wallet balance (Out of scope (payments, CRM, ads))
GET /api/inbound/user/wallet-balance
Integrations & connections
Working54 API calls · 12 work correctly · 30 block misuse · 0 issues · 12 not tested
Integrations & connections
WorkingWorks correctly (12 API calls)
- ✓ View Connections
GET /api/inbound/connections/telephony - ✓ Exotel Stream Url
GET /api/inbound/connections/telephony/exotel/stream-url - ✓ View Config
GET /api/inbound/integration/config - ✓ View Deliveries
GET /api/inbound/integration/deliveries - ✓ Instagram Posts
GET /api/inbound/integration/instagram/posts - ✓ Instagram Prompts
GET /api/inbound/integration/instagram/prompts - ✓ Instagram Settings
GET /api/inbound/integration/instagram/settings - ✓ Instagram Status
GET /api/inbound/integration/instagram/status - ✓ Instagram Threads
GET /api/inbound/integration/instagram/threads - ✓ View Keys
GET /api/inbound/integration/keys - ✓ View Mapping
GET /api/inbound/integration/mapping - ✓ View Webhooks
GET /api/inbound/integration/webhooks
Blocks misuse (30 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: create Connection
POST /api/inbound/connections/telephony - ✓ Blocks an invalid or unauthorised attempt to: update Connection
PUT /api/inbound/connections/telephony/{connection_id} - ✓ Blocks an invalid or unauthorised attempt to: delete Connection
DELETE /api/inbound/connections/telephony/{connection_id} - ✓ Blocks an invalid or unauthorised attempt to: make Default
POST /api/inbound/connections/telephony/{connection_id}/default - ✓ Blocks an invalid or unauthorised attempt to: what this line currently does
GET /api/inbound/connections/telephony/{connection_id}/inbound - ✓ Blocks an invalid or unauthorised attempt to: start taking calls on this line's numbers
POST /api/inbound/connections/telephony/{connection_id}/inbound - ✓ Blocks an invalid or unauthorised attempt to: stop taking calls, and rotate the URL secret so the old one is dead
DELETE /api/inbound/connections/telephony/{connection_id}/inbound - ✓ Blocks an invalid or unauthorised attempt to: point some of this line's numbers at one campaign's prompt
PUT /api/inbound/connections/telephony/{connection_id}/inbound/numbers - ✓ Blocks an invalid or unauthorised attempt to: verify
POST /api/inbound/connections/telephony/{connection_id}/verify - ✓ Blocks an invalid or unauthorised attempt to: only fields actually sent are applied, so a partial save cannot blank the rest
PUT /api/inbound/integration/config - ✓ Blocks an invalid or unauthorised attempt to: one delivery
GET /api/inbound/integration/deliveries/{event_id} - ✓ Blocks an invalid or unauthorised attempt to: re-queue one delivery. The stored payload is replayed verbatim, never recomputed
POST /api/inbound/integration/deliveries/{event_id}/replay - ✓ Blocks an invalid or unauthorised attempt to: instagram Connect
POST /api/inbound/integration/instagram/connect - ✓ Blocks an invalid or unauthorised attempt to: instagram Connect Complete
POST /api/inbound/integration/instagram/connect/complete - ✓ Blocks an invalid or unauthorised attempt to: instagram Disconnect
DELETE /api/inbound/integration/instagram/connection - ✓ Blocks an invalid or unauthorised attempt to: instagram Post Comments
GET /api/inbound/integration/instagram/posts/{thread_id}/comments - ✓ Blocks an invalid or unauthorised attempt to: instagram Create Prompt
POST /api/inbound/integration/instagram/prompts - ✓ Blocks an invalid or unauthorised attempt to: instagram Update Prompt
PUT /api/inbound/integration/instagram/prompts/{prompt_id} - ✓ Blocks an invalid or unauthorised attempt to: instagram Delete Prompt
DELETE /api/inbound/integration/instagram/prompts/{prompt_id} - ✓ Blocks an invalid or unauthorised attempt to: instagram Update Settings
PUT /api/inbound/integration/instagram/settings - ✓ Blocks an invalid or unauthorised attempt to: instagram Thread Messages
GET /api/inbound/integration/instagram/threads/{thread_id}/messages - ✓ Blocks an invalid or unauthorised attempt to: mint a key. The secret is returned here and never again
POST /api/inbound/integration/keys - ✓ Blocks an invalid or unauthorised attempt to: revoke Key
POST /api/inbound/integration/keys/{key_id}/revoke - ✓ Blocks an invalid or unauthorised attempt to: stamp attribution server-side
PUT /api/inbound/integration/mapping - ✓ Blocks an invalid or unauthorised attempt to: propose rows only. Nothing is stored until the UI sends confirmed rows back
POST /api/inbound/integration/mapping/suggest - ✓ Blocks an invalid or unauthorised attempt to: create Webhook
POST /api/inbound/integration/webhooks - ✓ Blocks an invalid or unauthorised attempt to: update Webhook
PUT /api/inbound/integration/webhooks/{endpoint_id} - ✓ Blocks an invalid or unauthorised attempt to: delete Webhook
DELETE /api/inbound/integration/webhooks/{endpoint_id} - ✓ Blocks an invalid or unauthorised attempt to: re-arm an auto-disabled endpoint. Deliberate and separate from editing, so nobody turns delivery back on by saving an unrelated field
POST /api/inbound/integration/webhooks/{endpoint_id}/enable - ✓ Blocks an invalid or unauthorised attempt to: send one signed sample event now, so the client can verify their receiver
POST /api/inbound/integration/webhooks/{endpoint_id}/test
Not tested (12 API calls)
- – Connect (Out of scope (payments, CRM, ads))
POST /api/inbound/connections/google/connect - – Delete Connection (Out of scope (payments, CRM, ads))
DELETE /api/inbound/connections/google/{connection_id} - – Revoke Connection (Out of scope (payments, CRM, ads))
PATCH /api/inbound/connections/google/{connection_id}/revoke - – Verify Connection (Out of scope (payments, CRM, ads))
PATCH /api/inbound/connections/google/{connection_id}/verify - – View Connection (Out of scope (payments, CRM, ads))
GET /api/inbound/connections/google/{org_id} - – View Connections (Out of scope (payments, CRM, ads))
GET /api/inbound/integration/crm/connections - – Create Connection (Out of scope (payments, CRM, ads))
POST /api/inbound/integration/crm/connections - – View Connection (Out of scope (payments, CRM, ads))
GET /api/inbound/integration/crm/connections/{connection_id} - – Update Connection (Out of scope (payments, CRM, ads))
PUT /api/inbound/integration/crm/connections/{connection_id} - – Delete Connection (Out of scope (payments, CRM, ads))
DELETE /api/inbound/integration/crm/connections/{connection_id} - – Set Connection Enabled (Out of scope (payments, CRM, ads))
POST /api/inbound/integration/crm/connections/{connection_id}/enabled - – Connection state for the two CRM rows on the integrations tab (Out of scope (payments, CRM, ads))
GET /api/inbound/integration/crm/status
Calls & voice agent
Working8 API calls · 0 work correctly · 5 block misuse · 0 issues · 3 not tested
Calls & voice agent
WorkingBlocks misuse (5 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: initiate a manual outbound call
POST /api/inbound/create-manual-call - ✓ Blocks an invalid or unauthorised attempt to: create a follow-up batch for a single lead
POST /api/inbound/demo/create-call - ✓ Blocks an invalid or unauthorised attempt to: log the outcome of a rep-dialed manual call and resume the lead's flow
POST /api/inbound/log-manual-call-outcome - ✓ Blocks an invalid or unauthorised attempt to: setup Sip Inbound
POST /api/inbound/sip-inbound/setup - ✓ Blocks an invalid or unauthorised attempt to: view Sip Inbound Status
GET /api/inbound/sip-inbound/{org_id}
Not tested (3 API calls)
- – Teardown Sip Inbound (Would trigger a real action (e.g. a webhook))
DELETE /api/inbound/sip-inbound/{org_id} - – Route an inbound Twilio call to the campaign that owns the dialled number (Would trigger a real action (e.g. a webhook))
POST /api/inbound/twilio/inbound/{inbound_token} - – Twilio SMS delivery status callback (Would trigger a real action (e.g. a webhook))
POST /api/inbound/twilio/sms/status
Admin tools (internal staff)
Working68 API calls · 1 work correctly · 59 block misuse · 0 issues · 8 not tested
Admin tools (internal staff)
WorkingWorks correctly (1 API calls)
- ✓ Check if the authenticated user is a super user
GET /api/inbound/api/check_super_user
Blocks misuse (59 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: view Audit Log
GET /api/inbound/admin-audit-log/list - ✓ Blocks an invalid or unauthorised attempt to: view Audit Log Stats
GET /api/inbound/admin-audit-log/stats - ✓ Blocks an invalid or unauthorised attempt to: view Insights
GET /api/inbound/admin-feedback/insights - ✓ Blocks an invalid or unauthorised attempt to: view Insight
GET /api/inbound/admin-feedback/insights/{insight_id} - ✓ Blocks an invalid or unauthorised attempt to: escalate Insight
POST /api/inbound/admin-feedback/insights/{insight_id}/escalate - ✓ Blocks an invalid or unauthorised attempt to: called by the Cursor automation, not the admin UI
PATCH /api/inbound/admin-feedback/insights/{insight_id}/notion - ✓ Blocks an invalid or unauthorised attempt to: update Insight Status
PATCH /api/inbound/admin-feedback/insights/{insight_id}/status - ✓ Blocks an invalid or unauthorised attempt to: view Stats
GET /api/inbound/admin-feedback/stats - ✓ Blocks an invalid or unauthorised attempt to: classify any unprocessed feedback into the ledger and refresh linked Notion statuses
POST /api/inbound/admin-feedback/sync - ✓ Blocks an invalid or unauthorised attempt to: view User Insights
GET /api/inbound/admin-feedback/users/{user_id}/insights - ✓ Blocks an invalid or unauthorised attempt to: every purged account still recoverable from S3, newest first
GET /api/inbound/admin-lookup/backups - ✓ Blocks an invalid or unauthorised attempt to: what a backup holds, without restoring it
GET /api/inbound/admin-lookup/backups/detail - ✓ Blocks an invalid or unauthorised attempt to: write a purged account's documents back into the database
POST /api/inbound/admin-lookup/backups/restore - ✓ Blocks an invalid or unauthorised attempt to: calls that already look wrong
GET /api/inbound/admin-lookup/bad-calls - ✓ Blocks an invalid or unauthorised attempt to: call Detail
GET /api/inbound/admin-lookup/call/{call_sid} - ✓ Blocks an invalid or unauthorised attempt to: call Recording
GET /api/inbound/admin-lookup/call/{call_sid}/recording - ✓ Blocks an invalid or unauthorised attempt to: view Calling Numbers
GET /api/inbound/admin-lookup/calling-numbers - ✓ Blocks an invalid or unauthorised attempt to: create Calling Number
POST /api/inbound/admin-lookup/calling-numbers - ✓ Blocks an invalid or unauthorised attempt to: ``acefone enabled`` is the flag the dialer actually honours
PATCH /api/inbound/admin-lookup/calling-numbers/{caller_id} - ✓ Blocks an invalid or unauthorised attempt to: delete Calling Number
DELETE /api/inbound/admin-lookup/calling-numbers/{caller_id} - ✓ Blocks an invalid or unauthorised attempt to: find the call sid when the client only gave you a number and a rough time
GET /api/inbound/admin-lookup/calls - ✓ Blocks an invalid or unauthorised attempt to: flip a campaign between DND and NONDND dialing
PATCH /api/inbound/admin-lookup/campaign/{campaign_id}/telecom-category - ✓ Blocks an invalid or unauthorised attempt to: view Country Telephony
GET /api/inbound/admin-lookup/country-telephony - ✓ Blocks an invalid or unauthorised attempt to: repoint a country to a different telephony provider
PATCH /api/inbound/admin-lookup/country-telephony/{country} - ✓ Blocks an invalid or unauthorised attempt to: legacy deboard
POST /api/inbound/admin-lookup/deboard - ✓ Blocks an invalid or unauthorised attempt to: open a scheduled deletion for any account
POST /api/inbound/admin-lookup/deletion-requests - ✓ Blocks an invalid or unauthorised attempt to: cancel any pre-completed request
POST /api/inbound/admin-lookup/deletion-requests/{account_id}/{request_id}/cancel - ✓ Blocks an invalid or unauthorised attempt to: paste any id
GET /api/inbound/admin-lookup/id - ✓ Blocks an invalid or unauthorised attempt to: org 360
GET /api/inbound/admin-lookup/org/{org_id} - ✓ Blocks an invalid or unauthorised attempt to: staff override for when the current owner has already left and can't
POST /api/inbound/admin-lookup/org/{org_id}/transfer-ownership - ✓ Blocks an invalid or unauthorised attempt to: resolve any phone number to the org/campaign/prompt/integration behind it
GET /api/inbound/admin-lookup/phone - ✓ Blocks an invalid or unauthorised attempt to: view Providers
GET /api/inbound/admin-lookup/providers - ✓ Blocks an invalid or unauthorised attempt to: change a provider's concurrency cap
PATCH /api/inbound/admin-lookup/providers/{provider_name} - ✓ Blocks an invalid or unauthorised attempt to: back up to S3, then irreversibly delete the account and everything it owns
POST /api/inbound/admin-lookup/purge-account - ✓ Blocks an invalid or unauthorised attempt to: what deleting this target would actually take out
GET /api/inbound/admin-lookup/purge-account/preview - ✓ Blocks an invalid or unauthorised attempt to: view Org Plans
GET /api/inbound/admin-org-plans/list - ✓ Blocks an invalid or unauthorised attempt to: view Org Plan Stats
GET /api/inbound/admin-org-plans/stats - ✓ Blocks an invalid or unauthorised attempt to: view Org Plan Detail
GET /api/inbound/admin-org-plans/{org_id} - ✓ Blocks an invalid or unauthorised attempt to: add Credits Route
POST /api/inbound/admin-org-plans/{org_id}/add-credits - ✓ Blocks an invalid or unauthorised attempt to: every user registered under this org
GET /api/inbound/admin-org-plans/{org_id}/members - ✓ Blocks an invalid or unauthorised attempt to: patch Org Plan
PATCH /api/inbound/admin-org-plans/{org_id}/plan - ✓ Blocks an invalid or unauthorised attempt to: update Plan Expiry Route
PATCH /api/inbound/admin-org-plans/{org_id}/plan-expiry - ✓ Blocks an invalid or unauthorised attempt to: view Org Plan History
GET /api/inbound/admin-org-plans/{org_id}/plan-history - ✓ Blocks an invalid or unauthorised attempt to: revert Org Plan Route
POST /api/inbound/admin-org-plans/{org_id}/revert-plan - ✓ Blocks an invalid or unauthorised attempt to: view Registrations
GET /api/inbound/admin-registrations/list - ✓ Blocks an invalid or unauthorised attempt to: view Registration Stats
GET /api/inbound/admin-registrations/stats - ✓ Blocks an invalid or unauthorised attempt to: view Registration Detail
GET /api/inbound/admin-registrations/{phone_number} - ✓ Blocks an invalid or unauthorised attempt to: same validation + same `approve registration` call as the email-link's
POST /api/inbound/admin-registrations/{phone_number}/approve - ✓ Blocks an invalid or unauthorised attempt to: revoke login + MCP access. Reversible
POST /api/inbound/admin-registrations/{phone_number}/deactivate - ✓ Blocks an invalid or unauthorised attempt to: stream Recording
GET /api/inbound/admin/call-recordings/api/recording/stream - ✓ Blocks an invalid or unauthorised attempt to: proxy-stream an Exotel recording to the UI
GET /api/inbound/admin/call-recordings/api/recording/stream/exotel - ✓ Blocks an invalid or unauthorised attempt to: create a client under the authenticated super user/admin. The client is a normal
POST /api/inbound/internal/add-client - ✓ Blocks an invalid or unauthorised attempt to: view call metrics for a specific batch
GET /api/inbound/internal/batch/{batch_id}/call-metrics - ✓ Blocks an invalid or unauthorised attempt to: clear Redis cache based on user phone number and/or function name
DELETE /api/inbound/internal/cache/clear - ✓ Blocks an invalid or unauthorised attempt to: calculate overall pick rate for all CallingNumber records
GET /api/inbound/internal/calling-numbers/pick-rates - ✓ Blocks an invalid or unauthorised attempt to: deboard a broker: delete all data for the given user ID,
POST /api/inbound/internal/deboard-broker - ✓ Blocks an invalid or unauthorised attempt to: upsert Enterprise Plan Route
PUT /api/inbound/internal/enterprise-plans/{org_id} - ✓ Blocks an invalid or unauthorised attempt to: resync Custom Plan Features Route
POST /api/inbound/internal/enterprise-plans/{org_id}/resync - ✓ Blocks an invalid or unauthorised attempt to: onboard a new user: create org, baseline campaign,
POST /api/inbound/internal/onboard-user
Not tested (8 API calls)
- – View Catalog Plans (Out of scope (payments, CRM, ads))
GET /api/inbound/admin-org-plans/catalog-plans - – Cancel Org Subscription Route (Out of scope (payments, CRM, ads))
POST /api/inbound/admin-org-plans/{org_id}/cancel-subscription - – Pause Org Subscription Route (Out of scope (payments, CRM, ads))
POST /api/inbound/admin-org-plans/{org_id}/pause-subscription - – Reconcile Subscription Status Route (Out of scope (payments, CRM, ads))
GET /api/inbound/admin-org-plans/{org_id}/reconcile-subscription - – Resume Org Subscription Route (Out of scope (payments, CRM, ads))
POST /api/inbound/admin-org-plans/{org_id}/resume-subscription - – Plans this dashboard's approve action can grant (Out of scope (payments, CRM, ads))
GET /api/inbound/admin-registrations/plans - – Refund Payment Route (Out of scope (payments, CRM, ads))
POST /api/inbound/internal/admin-org-plans/{org_id}/payments/{payment_id}/refund - – Update Gupshup subscription for a campaign (Out of scope (payments, CRM, ads))
PATCH /api/inbound/internal/gupshup/update-subscription
System health & webhooks
Working65 API calls · 4 work correctly · 3 block misuse · 0 issues · 58 not tested
System health & webhooks
WorkingWorks correctly (4 API calls)
- ✓ Root
GET / - ✓ Health
GET /api/voicebot/fixi/health - ✓ Slow/full dependency probe, incl. external TTS+S3 (plan.md §5 keeps these
GET /api/voicebot/health - ✓ Section 5: the single /ready for the whole merged process
GET /ready
Blocks misuse (3 API calls)
- ✓ Blocks an invalid or unauthorised attempt to: verify webhook endpoint for WhatsApp Business API
GET /api/inbound/webhook - ✓ Blocks an invalid or unauthorised attempt to: view Twiml
POST /api/inbound/webhook/acefone/twiml - ✓ Blocks an invalid or unauthorised attempt to: twiML for direct Twilio calls: connect the call to our media stream WS
GET /api/voicebot/manual-call/twiml
Not tested (58 API calls)
- – Root endpoint for this domain (Runs inside the system, not reachable from outside)
GET /api/agent/ - – Health Check (Runs inside the system, not reachable from outside)
GET /api/agent/health - – Verify webhook endpoint for WhatsApp Business API (Runs inside the system, not reachable from outside)
GET /api/agent/webhook - – Receive and process incoming WhatsApp messages (Runs inside the system, not reachable from outside)
POST /api/agent/webhook - – Real Estate Faq Chat (Would trigger a real action (e.g. a webhook))
POST /api/inbound/bot/real-estate-faq-chat - – One-time OAuth initialization for an organization (Out of scope (payments, CRM, ads))
POST /api/inbound/crm/auth/init - – Check if OAuth is initialized for an organization (Out of scope (payments, CRM, ads))
GET /api/inbound/crm/auth/status - – Generate access token from refresh token and store it in Redis (Out of scope (payments, CRM, ads))
GET /api/inbound/crm/auth/token - – Insert a call record into Outperform CRM (Out of scope (payments, CRM, ads))
POST /api/inbound/crm/calls/insert - – Batch sync call records from F Call Records to Outperform CRM (Out of scope (payments, CRM, ads))
GET /api/inbound/crm/calls/sync-batch - – Sync a call record from F Call Records to Outperform CRM (Out of scope (payments, CRM, ads))
POST /api/inbound/crm/calls/sync-from-record - – View chatbot conversations from Outperform CRM (Out of scope (payments, CRM, ads))
GET /api/inbound/crm/chatbot-conversations - – View contacts from Outperform CRM (Out of scope (payments, CRM, ads))
GET /api/inbound/crm/contacts - – Create or update a contact in Outperform CRM (Out of scope (payments, CRM, ads))
POST /api/inbound/crm/contacts - – View WhatsApp conversations from Outperform CRM (Out of scope (payments, CRM, ads))
GET /api/inbound/crm/conversations - – Pull deals from the configured CRM for the given org and (Out of scope (payments, CRM, ads))
GET /api/inbound/crm/deals/sync - – View labels/tags from Outperform CRM (Out of scope (payments, CRM, ads))
GET /api/inbound/crm/labels - – Push lead updates from our system back to Outperform CRM (Out of scope (payments, CRM, ads))
GET /api/inbound/crm/leads/push-updates - – Update a lead in Outperform CRM (Out of scope (payments, CRM, ads))
POST /api/inbound/crm/leads/update - – Send a session message (Out of scope (payments, CRM, ads))
POST /api/inbound/crm/messages/send - – Send a template message (Out of scope (payments, CRM, ads))
POST /api/inbound/crm/messages/template - – Posthog Webhook (Would trigger a real action (e.g. a webhook))
POST /api/inbound/posthog/webhook - – Cancel the authenticated org's own subscription, effective at the end of the current billing period (Out of scope (payments, CRM, ads))
POST /api/inbound/razorpay/cancel-subscription - – Create a Razorpay order for a one-time credit pack purchase (Out of scope (payments, CRM, ads))
POST /api/inbound/razorpay/generate-credit-purchase - – Subscribe an org to a USD credit subscription plan tier (Starter/Growth/ (Out of scope (payments, CRM, ads))
POST /api/inbound/razorpay/generate-credit-subscription - – Generate Invoice (Out of scope (payments, CRM, ads))
POST /api/inbound/razorpay/generate-invoice - – Generate Subscription (Out of scope (payments, CRM, ads))
POST /api/inbound/razorpay/generate-subscription - – View organization details by the business org ID, never the Mongo id (Out of scope (payments, CRM, ads))
GET /api/inbound/razorpay/org-details/{org_id} - – Pause the authenticated org's own subscription. Billing pauses immediately; plan/credits are untouched (Out of scope (payments, CRM, ads))
POST /api/inbound/razorpay/pause-subscription - – The authenticated org's own billing history, newest first (Out of scope (payments, CRM, ads))
GET /api/inbound/razorpay/payment-history - – View the authenticated org's current membership/plan status, for UI display (Out of scope (payments, CRM, ads))
GET /api/inbound/razorpay/plan-status - – Resume the authenticated org's own paused subscription (Out of scope (payments, CRM, ads))
POST /api/inbound/razorpay/resume-subscription - – View subscription status from Razorpay (Out of scope (payments, CRM, ads))
GET /api/inbound/razorpay/subscription-status - – Main webhook endpoint for Razorpay subscription and credit purchase events (Out of scope (payments, CRM, ads))
POST /api/inbound/razorpay/webhook - – Receive and process incoming WhatsApp messages (Would trigger a real action (e.g. a webhook))
POST /api/inbound/webhook - – Call Missed Click (Would trigger a real action (e.g. a webhook))
POST /api/inbound/webhook/acefone/call-missed-click - – Handle Exotel Status Callbacks (Would trigger a real action (e.g. a webhook))
POST /api/inbound/webhook/acefone/exotel/status/{webhook_secret} - – Handle Twilio Status Callbacks. Uses print for debugging output (Would trigger a real action (e.g. a webhook))
POST /api/inbound/webhook/acefone/twilio/status - – Recording Status (Would trigger a real action (e.g. a webhook))
POST /api/inbound/webhook/acefone/twilio/status/recording - – Zernio Webhook (Would trigger a real action (e.g. a webhook))
POST /api/inbound/webhook/zernio - – The campaigns this key may submit to, (Out of scope (payments, CRM, ads))
GET /api/public/v1/campaigns - – Contract §4.1. Always 202 on a well-formed envelope; read ``results[]`` (Out of scope (payments, CRM, ads))
POST /api/public/v1/leads - – Contract §4.3 (Out of scope (payments, CRM, ads))
GET /api/public/v1/leads - – Contract §4.2 (Out of scope (payments, CRM, ads))
GET /api/public/v1/leads/by-external-id/{external_id} - – Contract §4.2 (Out of scope (payments, CRM, ads))
GET /api/public/v1/leads/{lead_id} - – Every call attempt for this lead (Out of scope (payments, CRM, ads))
GET /api/public/v1/leads/{lead_id}/calls - – Contract §4.4 (Out of scope (payments, CRM, ads))
GET /api/public/v1/leads/{lead_id}/events - – Contract §4.7. Two distinct 409s, both deliberate (Out of scope (payments, CRM, ads))
POST /api/public/v1/leads/{lead_id}/link - – Contract §4.6 (Out of scope (payments, CRM, ads))
POST /api/public/v1/leads/{lead_id}/opt-out - – 302 to the playable asset. The provider is never visible to the client (Out of scope (payments, CRM, ads))
GET /api/public/v1/recordings/{call_id} - – The conversation transcript. It lives in Mongo, so there is nothing to redirect to (Out of scope (payments, CRM, ads))
GET /api/public/v1/transcripts/{call_id} - – ExoML for Exotel direct calls: connects the answered call to our media stream WS (Would trigger a real action (e.g. a webhook))
POST /api/voicebot/manual-call/exoml - – ExoML for Exotel direct calls: connects the answered call to our media stream WS (Phone-provider callback)
GET /api/voicebot/manual-call/exoml - – Pod-to-pod: the provider says this call is over, so end its browser leg if this pod holds it (Would trigger a real action (e.g. a webhook))
POST /api/voicebot/manual-call/internal/{session_id}/end - – Root endpoint for this domain (Runs inside the system, not reachable from outside)
GET /api/workers/ - – Health Check (Runs inside the system, not reachable from outside)
GET /api/workers/health - – Real-time resource monitoring endpoint (Runs inside the system, not reachable from outside)
GET /api/workers/monitor - – Detailed subprocess monitoring endpoint (Runs inside the system, not reachable from outside)
GET /api/workers/monitor/subprocesses