Inbound SIP
Connect a SIP provider to a self-hosted Orbitali gateway.
Inbound SIP is available when your Orbitali operator enables its Asterisk gateway. Use Phone numbers → SIP connections to create a connection, add an E.164 number and assign an existing agent.
Configure the provider to send calls to sip:+<called-number>@<gateway-address>:25483, using TCP or UDP and G.711 PCMU/PCMA. Authentication uses the generated username/password or a provider IPv4 source allowlist. Keep the authentication username separate from the caller ID. REGISTER, outbound SIP and transfers are not supported.
IP allowlists cannot overlap another connection, including a disabled connection. Providers sharing IP ranges across tenants should use credential authentication. A source allowlist authorizes every call from that range, so use only the provider ranges assigned to your connection. IPv6 allowlists are currently unsupported.
Passwords are returned only when created or rotated. After rotation, update the provider and wait for Configuration applied. That status confirms loading the configuration; Verified by a successful call requires a completed call with media in both directions on the same revision. Perform a real speech and interruption test as well.
Public API
Authenticate with the existing Authorization: Bearer <API key> header. All operations are account-scoped and return 404 when SIP is disabled.
| Method | Path | Purpose |
|---|---|---|
| GET | /public/v1/telephony/sip/connections | List connection details and provisioning status; no passwords |
| POST | /public/v1/telephony/sip/connections | Create a connection; returns { connection, password? } |
| PUT | /public/v1/telephony/sip/connections/:id | Replace configuration; use enabled: false to disable |
| POST | /public/v1/telephony/sip/connections/:id/rotate | Rotate credentials; returns the new password once |
| DELETE | /public/v1/telephony/sip/connections/:id | Delete a connection and its linked numbers |
| POST | /public/v1/telephony/sip/numbers | Manually add a number; returns { id } |
Connection input:
{
"displayLabel": "Office inbound",
"authMode": "credentials",
"sourceCidrs": [],
"enabled": true
}
For IP authentication use authMode: "ip" and a nonempty sourceCidrs array, for example ["192.0.2.0/24"]. Updating requires the complete input; changing authentication mode generates new credentials. Conflicting allowlists return HTTP 409 and SIP_ALLOWLIST_OVERLAP.
Number input:
{
"connectionId": "00000000-0000-4000-8000-000000000001",
"phoneNumber": "+34910000001",
"friendlyName": "Office"
}
Use the existing agent phone-number assignment API after adding the number. The same number may exist on separate SIP connections; routing always requires the authenticated connection and called number together. Unknown/unassigned numbers and admission failures are rejected before answering. Existing consent, retention and usage accounting apply; transfer tools are unavailable on SIP calls.
The MCP tools list_sip_connections, save_sip_connection, rotate_sip_password, delete_sip_connection and add_sip_number expose the same workflow. Use assign_phone_number to select the agent.
KrosAI is the first planned interoperability target. Compatibility remains unverified until an actual inbound call succeeds, including speech, interruption, hangup and accounting.