Integrations & API

Plugs into the tools your reps already live in.

CRM sync, webhooks, and a REST API for numbers, calls, and analytics.

Developer-first API

Provision numbers, read health scores, and pull CDRs over a documented REST API.

The API is resource-oriented and returns JSON. Timestamps are UTC in ISO 8601, amounts are integer cents. No SDK is required: any HTTP client will do.

curl "https://api.xetel.de/v1/rates/lookup?dst=4989" \
  -H "Authorization: Bearer xe_live_9f3a72c1" \
  -H "Accept: application/json"

Resources

What the API covers.

Numbers

List your inventory, check availability, assign numbers, and release them. Every number carries its state and health score.

Calls

Place a click-to-call, query live calls, end a call. The leg to the agent seat is set up first, then the destination is dialled.

Call detail records

Completed calls with timestamp, direction, presented number, destination, duration, and outcome. Paginated for loading into a data warehouse.

Metrics

Answer rate and health score per number and per campaign over a period — without having to aggregate raw call records yourself.

Users and extensions

Create users, set roles and teams, assign extensions. Suitable for provisioning from an identity directory.

Queues

Read queue state: waiting calls, longest wait, logged-in agents. The basis for building your own wallboard.

Webhooks

Events instead of polling.

Rather than polling the API every second, you register an endpoint and receive events as they happen.

Call started

Fires once a call is connected. Carries direction, presented number, and destination — enough to open the record in your CRM.

Call ended

Carries duration, outcome, and the recording identifier if recording is enabled. Suitable for logging the activity in your CRM.

Number flagged

Fires when a number's health score drops below the threshold and the number starts resting. Suitable for alerting your operations team.

Voicemail received

Carries the number, timestamp, and recording identifier. Suitable for raising a service ticket.

Delivery

Every delivery is signed; verify the signature before processing the body. If your endpoint does not return 2xx, we retry with increasing intervals. Events can arrive more than once — process them idempotently using the event identifier.

CRM integration

Three patterns cover almost everything.

Nearly every CRM integration is a combination of these three patterns. Ready-made connectors for Salesforce, HubSpot, Microsoft Dynamics, and Zoho, and custom systems, are offered as professional services.

Click to call

A click on a number in the CRM places a call through the API. The agent's seat rings first, then the destination is dialled. The presented number determines campaign attribution.

Screen pop on ring

The call-started event carries the caller's number. Your application looks up the record and opens it on the agent's screen before they answer.

Write the activity back

On the call-ended event you create a CRM activity with duration, outcome, and a link to the recording. Call reporting and CRM reporting then agree.

Authentication and limits

Access, errors, rate limits.

Key in the header

Every request carries an API key in the Authorization header. Keys are created in the portal, scoped, and revoked individually.

One key per integration

Use a separate key per integration. If one is compromised you revoke that key alone instead of taking down every connection.

Rate limiting

Requests are limited per key. Beyond the limit the API returns status 429 together with an indication of when to retry.

Error format

Errors come with the appropriate HTTP status and a stable error code in the body. Handle the code, not the message text.

Retries

Write requests accept an idempotency key. Repeating a request with the same key does not place a second call.

TLS only

The API is reachable over HTTPS only. Unencrypted requests are rejected, not redirected.

From experience

What usually goes wrong in an integration.

Most problems in telephony integrations are not specific to XETEL. They show up the same way with every provider.

Number format

Handle numbers consistently in E.164 with a leading plus. Store local numbers without a country code and you will not find the record when the inbound call arrives.

Time zones

The API returns timestamps in UTC. Convert only at display time. Reports that store local time drift apart across daylight-saving changes.

Duplicate activities

Webhooks can arrive more than once. Without checking the event identifier you end up with duplicate activities in the CRM — the most common first-integration bug.

Synchronous processing

Accept the event, acknowledge with 2xx, then process it. Waiting on the CRM inside the webhook handler produces timeouts and therefore retries.

Withheld numbers

Not every inbound call carries a number. Your screen pop needs a defined path for the case where there is none.

Keys in source control

API keys belong in configuration, not in the repository. One key per integration keeps the blast radius small if something leaks.

Frequently asked questions

Are there ready-made CRM connectors?

The API and webhooks are included in the platform licence. Ready-made connectors for Salesforce, HubSpot, Microsoft Dynamics, Zoho, and custom systems are professional services and are quoted individually.

Do I need an SDK?

No. The API is REST with JSON. Any HTTP client will do. A single curl call is enough to get started.

How do I secure webhooks?

Every delivery is signed. Verify the signature before processing the body, and process events idempotently using the event identifier, since a delivery can repeat.

What is the rate limit?

The limit applies per API key and is documented per resource. Beyond it the API returns status 429 together with the earliest permitted retry.

Can I load call records into our data warehouse?

Yes. Call detail records are retrievable per period with pagination and include timestamp, direction, presented number, destination, duration, and outcome.

What happens if our webhook endpoint goes down?

If your endpoint does not return a 2xx status, we retry with increasing intervals. For longer outages you can backfill the affected records through the API.