> ## Documentation Index
> Fetch the complete documentation index at: https://apidocs.vodex.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Test a custom tool

> Call your own tool server once, with the exact envelope an assistant
sends mid-call, and get back what it said. The point is to find a broken
URL, a wrong auth header or a slow endpoint while you are configuring an
assistant — not while a customer is on the phone.

The URL passes the **same** gate as a saved tool and as the webhook
endpoint: https only, no credentials in the URL, no private or
link-local destination. This endpoint deliberately cannot reach an
address the save path would refuse.

A URL that fails that gate is **`200` with `ok: false`**, not a `4xx` —
the failure is a result to display in a form, not a malformed request.
Only a missing `tool.server.url` is a `400`.

The body posted to your server is:

```json
{
  "type": "tool.call",
  "id": "console-test",
  "calls": [{ "toolCallId": "test", "name": "<tool.name>", "arguments": { } }]
}
```




## OpenAPI

````yaml /openapi/api-public-v1.yaml post /console/tools/test
openapi: 3.0.3
info:
  title: Vodex API (v1)
  description: >
    The **public Vodex `/v1` REST API** — everything a customer's own systems

    integrate with: assistants, telephony (numbers, trunks, carrier

    integrations), calls and recordings, batch dialing, the SMS channel, and

    outbound webhooks.


    This is deliberately a **subset**. Account and console-only routes

    (`/v1/auth/*`, `/v1/api-keys`, `/v1/usage`), platform provisioning

    (`/v1/platform/*`), Vodex support operations, and endpoints other systems

    call inward (carrier delivery receipts, the agent worker, cron) are not

    part of the published surface and are not documented here.


    The **data plane** (LiveKit SFU + SIP + the agent worker) is not an HTTP

    API and is not described here: a call reaches the worker over LiveKit, with

    its config carried in participant metadata or read from the config snapshot

    this API publishes.


    ## Authentication


    | Credential | Sent as | Scope |

    |---|---|---|

    | **Tenant API key** | `Authorization: Bearer vdx_live_…` | One customer,
    full access — the credential for everything in this document |


    Mint an API key in the console (**Settings → API keys**). The plaintext is

    shown **once**, by the call that creates it, and no endpoint reads one back

    — a lost key is replaced, not recovered.


    Every route here also answers a signed-in console session, because the

    console is built on this same API. That is **not** an integration

    credential and is deliberately not described as one: it is the console's

    own cookie, it carries a role an API key never has, and it is free to

    change. Integrate with `vdx_live_`.


    ## Customers and tenants


    One thing, two words, and they are not interchangeable:


    - **Customer** is the product word — what a human calls the account, and
      what the console shows you.
    - **Tenant** is the same thing's identity on the wire and in storage:
      `tenantId` on every response.

    **A *workspace* is a third thing, and not a synonym for either.** Tenancy

    is mapped at the customer level deliberately: integrations (carrier, SMS,

    provider credentials) live above the workspaces that use them, so mapping

    workspaces to tenants would fragment one customer's telephony across

    tenants that then have to share credentials. A workspace is therefore a

    **label inside the tenant** (`externalWorkspaceRef`) — for filtering and

    attribution, never isolation. Anything that must not be shared between one

    customer's workspaces needs its own tenant.


    ## Tenancy


    There is **no tenant parameter**. Every tenant-scoped route derives its

    tenant from the credential and binds it for the whole request, so a caller

    cannot ask for another tenant's data by changing a query string. An id that

    belongs to somebody else answers `404`, never `403` — "no such call" is the

    only thing worth confirming.


    ## Response shapes


    Resources are returned **flat**, at the top level (`{ "id": "…", … }`) —

    there is no envelope object. Collections vary by age of the endpoint:


    - Newer lists are `{ "<plural>": [ … ], "total": n, "limit": n, "offset": n
    }`
      (`calls`, `batches`, `rows`, `attempts`, `messages`).
    - Older lists return a **bare JSON array** (`/v1/phone-numbers`,
      `/v1/sip-trunks`, `/v1/integrations`, `/v1/carriers`,
      `/v1/console/assistants`, `/v1/sms/configurations`).

    Deletes and side-effecting no-content operations return `{ "ok": true }`.


    ## Errors


    ```json

    { "error": "human-readable message" }

    ```


    A flat string, not a coded object — HTTP status is the machine signal.

    The one exception is quota exhaustion (`402`), which adds a stable

    `code: "quota_exhausted"` plus the counters the console renders.


    ## Pagination


    `?limit=` and `?offset=`, with `total` in the body. Defaults and ceilings

    differ per endpoint (calls 25/100, batch rows 50/500, attempts 100/500) and

    are stated on each operation.


    ## Conventions


    - **Phone numbers** are E.164 strings (`+14155551234`); `+91…` numbers are
      served from Mumbai, `+1…` from us-central1.
    - **Money** is a JSON number of **USD** (`costUsd`), not a decimal string.

    - **Timestamps** are ISO‑8601 UTC strings, except the calls list, which
      reports `mtime` / `startedAt` as epoch **milliseconds** and durations as
      **milliseconds**.
    - **Ids** are unprefixed: batches, rows, attempts and SMS rows are UUIDs;
      a call id is its LiveKit room name (`call-…`, or `console-…` for web
      calls); a phone number's id is `num-<digits>`; a trunk's is `trunk-…`.
    - **Secrets** (`vdx_live_…`, `whsec_…`) are returned exactly once, by the
      call that mints them. No endpoint reads one back — carrier and provider
      credentials are stored in Secret Manager and echoed only as a
      non-reversible fingerprint.
    - **Idempotency**: `POST /v1/sms` and `POST /v1/batches` **require** an
      `Idempotency-Key` header. Only successful (2xx) responses are replayed;
      a failed attempt releases the key so a corrected retry can reuse it.
  version: 1.0.0
  contact:
    name: Vodex Platform
    url: https://vodex.ai
  license:
    name: Proprietary
    url: https://vodex.ai/terms
servers:
  - url: https://apiv2.vodex.ai/v1
    description: Production
security:
  - ApiKeyBearer: []
tags:
  - name: Assistants
    description: Assistant configurations (the agent's engine, prompt, slots, tools).
  - name: Console
    description: Reference data (model catalog, voices) and the web-call token.
  - name: Usage
    description: Minute usage against the plan.
  - name: Calls
    description: Place calls, read the call log, fetch traces and recordings.
  - name: Phone Numbers
    description: Number inventory and assistant mapping.
  - name: SIP Trunks
    description: Customer-owned (BYO) SIP trunks.
  - name: Carriers
    description: Carrier registry — what can be connected, and how.
  - name: Integrations
    description: Connected carrier accounts and their numbers.
  - name: Batches
    description: Batch dialing — lists in, calls out.
  - name: Number Rotation
    description: Per-number spacing, daily caps, and cooldown.
  - name: Callbacks
    description: >-
      "Call me Tuesday afternoon" — appointments booked mid-call, and dialed
      later.
  - name: SMS
    description: SMS configurations, credentials, preview, send, and message log.
  - name: Webhooks
    description: Outbound webhook configuration and delivery records.
  - name: Tenants
    description: Recording retention.
paths:
  /console/tools/test:
    post:
      tags:
        - Assistants
      summary: Test a custom tool
      description: |
        Call your own tool server once, with the exact envelope an assistant
        sends mid-call, and get back what it said. The point is to find a broken
        URL, a wrong auth header or a slow endpoint while you are configuring an
        assistant — not while a customer is on the phone.

        The URL passes the **same** gate as a saved tool and as the webhook
        endpoint: https only, no credentials in the URL, no private or
        link-local destination. This endpoint deliberately cannot reach an
        address the save path would refuse.

        A URL that fails that gate is **`200` with `ok: false`**, not a `4xx` —
        the failure is a result to display in a form, not a malformed request.
        Only a missing `tool.server.url` is a `400`.

        The body posted to your server is:

        ```json
        {
          "type": "tool.call",
          "id": "console-test",
          "calls": [{ "toolCallId": "test", "name": "<tool.name>", "arguments": { } }]
        }
        ```
      operationId: testTool
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - tool
              properties:
                tool:
                  type: object
                  required:
                    - server
                  properties:
                    name:
                      type: string
                      description: Sent as `calls[0].name`. Defaults to `test`.
                    description:
                      type: string
                    server:
                      type: object
                      required:
                        - url
                      properties:
                        url:
                          type: string
                          format: uri
                          example: https://tools.example.com/vodex
                        authHeader:
                          type: string
                          default: Authorization
                          description: Header the secret is sent in.
                        secretRef:
                          type: string
                          description: >-
                            A literal value, or an `sm://` reference resolved
                            from Secret Manager. Omit to send no auth header.
                        timeoutMs:
                          type: integer
                          default: 2000
                          description: Clamped to 200–5000 whatever is asked for.
                arguments:
                  type: object
                  description: Sent as `calls[0].arguments`. Defaults to `{}`.
      responses:
        '200':
          description: >-
            The attempt's result — including the failures, which are results
            rather than errors.
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                    description: True when your server answered with a status under 400.
                  status:
                    type: integer
                    nullable: true
                    description: Absent when nothing answered.
                  ms:
                    type: integer
                    description: Round trip in milliseconds.
                  body:
                    type: string
                    description: Your server's response, truncated to 4000 characters.
                  error:
                    type: string
                    description: >-
                      Why there is no response — a rejected URL, a transport
                      failure, or `No response within <timeoutMs>ms`.
              examples:
                answered:
                  summary: The tool server answered
                  value:
                    ok: true
                    status: 200
                    ms: 143
                    body: '{"result":"ok"}'
                rejected:
                  summary: The URL failed the gate — still a 200
                  value:
                    ok: false
                    error: tool server URL must not resolve to a private address
                timedOut:
                  summary: Nothing answered in time
                  value:
                    ok: false
                    ms: 2000
                    error: No response within 2000ms
        '400':
          description: '`tool.server.url` missing.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
          example: not found
  responses:
    Unauthorized:
      description: No usable credential.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    ApiKeyBearer:
      type: http
      scheme: bearer
      description: 'Tenant API key (`vdx_live_…`) as `Authorization: Bearer`.'

````