All pages

Get started

Going live

What changes when the same code runs with a live key.

View as Markdown

The code you wrote against a test key is the code you run live: the address, the requests and the answers are the same. What changes is that calls ring real phones, conversations cost credit, and your receivers hear about real people.

Before the first live call

  • A live key. On API keys, make one with Live, limited to the projects — or the agents — it needs. Asking for it takes your password again, and every owner of the organization is emailed. A live key never works from a browser: keep it on your server.
  • A number to call from. An agent that calls out needs a verified number on its Connect → Caller ID tab. Without one, a call is refused with caller_id_unavailable.
  • Countries. The deployment calls only the countries it allows, never emergency or service numbers, and premium-rate numbers only where it has said so. Anything else is refused with destination_not_allowed. Send numbers in full international format: +, the country code, then the number.
  • Consent. Call people who agreed to hear from you, at hours that suit them. The platform records who placed every call — the key's name is on it in the audit log.
  • Live receivers. A webhook receiver is either live or test. Add a live one for your production server; your test receivers keep getting test events only.

Limits

Limit Default When it is reached
Calls at the same time, per organization 10 429 concurrency_limit_reached
Calls a day, per organization 2,000 429 daily_limit_reached
Requests a minute, per key 600 reads, 120 writes, 1,200 chat messages 429 rate_limited

GET /v1/me shows your key's limits and how many of your calls are in progress. Our staff can raise an organization's limits. See Rate limits.

Check your key
#!/bin/sh
# Check your key
curl -sS --fail-with-body -X GET "https://api.aigently.ai/v1/me" \
  -H "Authorization: Bearer $AIGENTLY_API_KEY"

Credit

Live conversations are charged from the organization's credit, as conversations from the console are; the API itself costs nothing. When the credit runs out, new calls and chats are refused with 402 insufficient_credit, and reading conversations keeps working.

Keep it safe

  • Rotate a key that may have leaked — the old secret keeps working for the time you choose, so your servers can be updated first. Revoke a key nobody uses.
  • Check every webhook's signature before you act on it (how).
  • Build each call's Idempotency-Key from your own data, so a retry can never call twice.