Help index · Messaging & records
Integrations (InstaCRM and plugins)
Bolt-on API key, signed webhooks, recent calls, click-to-dial, and CRM iframe handoff — not a CRM.
Tenant admins open Admin → Integrations (/admin/integrations). This is a bolt-on so another app (InstaCRM) can screen-pop and click-to-dial. Octone does not become a CRM.
API key
- Click Generate API key (or Rotate).
- Copy the key once. It starts with
oct_and is not shown again. - Your app sends
Authorization: Bearer oct_…on every plugin request.
Webhook (screen-pop)
Save a Webhook URL. Octone POSTs, fire-and-forget, on:
call.startedcall.answeredcall.endedsms.received
Optional signing secret (shown once). When set, Octone sends:
| Header | Value |
|---|---|
X-Octone-Event | event name |
X-Octone-Timestamp | unix seconds |
X-Octone-Signature | v1= HMAC-SHA256 hex of timestamp + "." + raw body |
Call payload
json { "event": "call.started", "id": "evt_…", "createdAt": "2026-08-24T15:00:00.000Z", "tenantId": "…", "data": { "callId": "…", "direction": "inbound", "from": "+13125550100", "to": "+13125550199", "status": "initiated", "startedAt": "…", "answeredAt": null, "endedAt": null, "durationSec": null, "extension": { "id": "…", "ext": "101", "label": "Front desk" } } }
call.answered / call.ended use the same data shape with later timestamps and status (answered, completed, missed, …).
SMS payload
json { "event": "sms.received", "data": { "messageId": "…", "from": "+1…", "to": "+1…", "body": "Hello", "createdAt": "…" } }
REST
All three require the Bearer key.
- GET
/api/plugins/me—{ tenant: { id, name, slug } } - GET
/api/plugins/calls?limit=50— recent call log rows (id, direction, from, to, status, times, extension). Optionaldirection=inboundoroutbound. - GET
/api/plugins/lookup?number=— resolve recent calls and SMS for a number (CRM screen-pop). - POST
/api/plugins/calls/:id/disposition— set a hangup disposition code (answered,voicemail,callback,sale,not_interested,wrong_number,other). Agents can also POST/api/calls/:id/dispositionfrom the softphone. - POST
/api/plugins/dial— click-to-dial as a person:
json { "to": "+13125551212", "userId": "…" }
or { "to": "+13125551212", "extension": "101" }. Octone rings that person's desk (or cell if they are out of office), then connects the destination. The company DID is the caller ID.
No carrier brand or portal is required for this integration.
CRM iframe (module mode)
InstaCRM can embed Octone at https://octone.co/?mode=module. Because third-party iframes do not send Octone’s normal SameSite=lax cookies, CRM sends a short-lived handoff JWT (postMessage type octone:init, origin allowlisted). Octone verifies it (iss instaarch-crm, aud octone) and mints a normal octone_session for that person — the same user record as cookie login. Standalone octone.co sign-in is unchanged.
The plugin API key and webhooks above stay the server-to-server path (screen-pop, click-to-dial, call list). Module mode adds Create job and Link to job on call and contact views; it does not replace the plugin.
The CRM email must already exist as an Octone user in the company whose slug matches the JWT tenant_slug. Octone will not create a person from the iframe.
