Get started
Going live
What changes when the same code runs with a live key.
The code you wrote against a test key is the code you run live: the address, the requests and the answers are the same. What changes is that calls ring real phones, conversations cost credit, and your receivers hear about real people.
Before the first live call
- A live key. On API keys, make one with Live, limited to the projects — or the agents — it needs. Asking for it takes your password again, and every owner of the organization is emailed. A live key never works from a browser: keep it on your server.
- A number to call from. An agent that calls out needs a verified number on its
Connect → Caller ID tab. Without one, a call is refused with
caller_id_unavailable. - Countries. The deployment calls only the countries it allows, never emergency or service
numbers, and premium-rate numbers only where it has said so. Anything else is refused with
destination_not_allowed. Send numbers in full international format:+, the country code, then the number. - Consent. Call people who agreed to hear from you, at hours that suit them. The platform records who placed every call — the key's name is on it in the audit log.
- Live receivers. A webhook receiver is either live or test. Add a live one for your production server; your test receivers keep getting test events only.
Limits
| Limit | Default | When it is reached |
|---|---|---|
| Calls at the same time, per organization | 10 | 429 concurrency_limit_reached |
| Calls a day, per organization | 2,000 | 429 daily_limit_reached |
| Requests a minute, per key | 600 reads, 120 writes, 1,200 chat messages | 429 rate_limited |
GET /v1/me shows your key's limits and how many of your calls are in progress. Our staff can
raise an organization's limits. See Rate limits.
#!/bin/sh
# Check your key
curl -sS --fail-with-body -X GET "https://api.aigently.ai/v1/me" \
-H "Authorization: Bearer $AIGENTLY_API_KEY"
Credit
Live conversations are charged from the organization's credit, as conversations from the console
are; the API itself costs nothing. When the credit runs out, new calls and chats are refused with
402 insufficient_credit, and reading conversations keeps working.
Keep it safe
- Rotate a key that may have leaked — the old secret keeps working for the time you choose, so your servers can be updated first. Revoke a key nobody uses.
- Check every webhook's signature before you act on it (how).
- Build each call's
Idempotency-Keyfrom your own data, so a retry can never call twice.