Guides
SIP
When the voice agent and simple forwarding aren't enough and you want to connect a number to your own softphone or phone system (PBX), you need a SIP trunk provider - volai is one. This page is a step-by-step guide.
1Inbound calls to your SIP server
Set the number's routing to mode: "sip" and give it your sipUri - from there the call goes straight to you, not to our agent or forwarding:
curl -X PATCH "https://volai.cz/v1/numbers/+420601234567" \
-H "Authorization: Bearer vk_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"routing": {"mode": "sip", "sipUri": "sip:reception@your-server.com"}}'Only the inbound minute is billed - 0.50 CZK/min (~EUR 0.02), no extra agent - the full request shape and the other routing modes are in the REST API reference.
Authentication with your PBX
We first send the call to your SIP server as an unauthenticated INVITE to sipUri. A PBX that answers it with a login challenge (401/407) and refuses the call without more never gets it in this shape - there's no one to answer the challenge. So add sipUsername and sipPassword to the routing as well - filling in both makes our network answer the challenge (SIP digest) and dial the called number. Verified with a live call to Vapi's native SIP number, which accepts credentials regardless of their content. Whether your own PBX also connects the call is up to it - it has to actually answer the INVITE with a challenge and accept the username and password you give it; we don't guarantee that for every PBX (in testing it failed, for example, against Twilio's SIP domain). Without sipUsername and sipPassword, routing stays in today's unauthenticated form. Add the credentials like this:
curl -X PATCH "https://volai.cz/v1/numbers/+420601234567" \
-H "Authorization: Bearer vk_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"routing": {"mode": "sip", "sipUri": "sip:reception@your-server.com", "sipUsername": "reception", "sipPassword": "supersecret123"}}'We always send the called number exactly as it appears in sipUri before the @ sign - we never add or strip a prefix or a leading zero, so the target PBX has to handle exactly what you put there.
Neither sipUsername nor sipPassword may contain a colon, @ sign, whitespace, quote or backslash, and each can be at most 64 characters.
Filling in just one of the two is rejected - the API returns "Please fill in both username and password, or leave both empty."
A colon in the user part of sipUri (before the @ sign) and a port in the host (after the colon following the server, e.g. :5060) are both not yet supported together with sipUsername and sipPassword - both return the same hard error. Both keep working unchanged without credentials.
Who else sees the username and password
The username and password travel with the call into our network and stay in the routing records - you are not the only one who can see them. Set up an account on your PBX dedicated to us, not your main admin password.
Partial updates: an omitted field keeps its stored value
If your PATCH sends only sipUri and omits sipUsername and sipPassword , both fields stay unchanged - you don't need to resend them on every edit to sipUri. A field omitted from the body entirely always keeps its stored value; authentication is only cleared by an explicit empty string on BOTH fields. The one exception is changing the server: if you also edit the part after the @ sign, you must send the password again - we never send a stored password to a different server than the one you entered it for. Check the current state with the hasSipPassword field in the response.
Call didn't connect? Allow us by IP
Sipa authentication only works against a target that challenges the INVITE and accepts the credentials (verified with Vapi) - otherwise you won't get the call through, whether you fill in credentials or not. Our signalling comes from the range 81.31.45.0/24, most often from 81.31.45.51 and 81.31.45.56. Allow that whole range on your PBX and you won't need credentials at all - it recognizes the call by source address, not by username and password.
2SIP credentials for a number
Fetch the line's credentials with a single call:
curl "https://volai.cz/v1/numbers/+420601234567/sip" \
-H "Authorization: Bearer vk_YOUR_KEY"{
"server": "sip.volai.cz",
"username": "123456",
"password": "a1b2c3d4e5f6",
"outboundTrunkAddress": "sip.volai.cz",
"port": 5060,
"transport": "tcp",
"inboundSignallingCidrs": ["81.31.45.0/24"]
}Setup in a softphone (Zoiper, Linphone)
Both apps ask for essentially the same thing, just under different names - look for "Add account" / "SIP account":
| Field | Value |
|---|---|
| Server / Domain | sip.volai.cz |
| Username | from the response above (username) |
| Password | from the response above (password) |
| Transport | TCP |
| Port | 5060 (default SIP port - leave blank if the field offers an empty option) |
Client asks you to fill in a realm?
Leave the field empty - most clients pick up the realm from the server's challenge. Your client's log may show a technical domain belonging to our network, which is expected. If your client requires a realm as mandatory, contact support.
After saving, the softphone should register (an "online"/"registered" status icon) and calls to the number will start ringing directly in it.
3Outbound calls from a SIP client
Once the softphone is registered, it can dial out through this line on its own - you don't need to call any of our APIs for that, you dial directly from the client like from an ordinary phone line.
Minutes come out of your volai credit
Outbound calls placed through a SIP client are billed at the same rate as an outbound call through the API - 0.92 CZK/min (~EUR 0.04) and deducted from your credit - not from some separate SIP account. Rates exclude VAT, like the whole price list.
The connection runs directly between your client and the server sip.volai.cz, not through our API, so minutes can't be blocked at the exact moment of dialing. A call dialed directly from a SIP client is billed retroactively from the network's call records - no sooner than 10 minutes after it ends, usually within half an hour. The call won't show up on your credit at the moment of dialing. Daily call limits and credit checks at the moment of dialing don't apply to these calls - they only monitor API calls. So your credit can drop below zero, and the same debt rules apply as usual. When your credit drops to zero, new billable API/MCP actions start getting rejected (a call needs a balance of at least 5 CZK). If the debt exceeds 50 CZK, you'll get a warning email - and if it isn't settled within a week, the number is released back into stock (which permanently ends SIP access). So keep an eye on your credit ahead of time, not once it's already at zero.
Have a voice AI agent, not a softphone?
This step assumes a client that can register with the line (SIP REGISTER) - a softphone, a PBX. A platform that just sends an authenticated call once without a persistent registration (typically voice AI agents like ElevenLabs) needs a different approach - see Bring your own agent.
Take the platform's outbound trunk address from the outboundTrunkAddress field, not from server above - full details on that page.
4Limits
- One registration per line - one set of credentials supports one registered device at a time. If you sign in with a second client, the first one will most likely lose its registration - don't rely on multiple devices on one line at once.
- Outbound from your own agent yes, full trunk peering no - the line's credentials let YOUR client register with US as a phone. Outbound calls from your own voice agent (ElevenLabs or another platform) DO work today though - through the relay, see Bring your own agent. You still can't connect your PBX as a peer carrier with its own routing for INBOUND calls from outside though - use
forwardrouting to your PBX's number for that. - Voice only - no video or other SIP extensions.
Related
REST API
Complete reference for every endpoint: numbers, calls, SMS, SMS numbers for receiving, agents and their drafts, tools, recordings, webhooks, do-not-call list, relay, account, tasks, credit, documents, calendars and integrations.
Voice agent
System prompt, tools, handoff to a human, recordings and structured call data.
Bring your own agent
Connect a third-party platform (ElevenLabs, Asterisk...) - no agent surcharge.