Authentication
Base URL, API key header, permissions and rate limits — as published on developer.ringover.com
Source
This page mirrors the "Authentication" / "Permissions" / "Rate Limiting" sections of the official Ringover API Documentation. The OpenAPI document behind API Reference does not declare servers or securitySchemes, so the facts below come from the published docs, not from the local spec.
Base URL
| Region | Base URL |
|---|---|
| Europe | https://public-api.ringover.com/v2 |
| United States | https://public-api-us.ringover.com/v2 |
Authentication
Every request must include your API key in the Authorization header — no Bearer prefix:
Authorization: your-api-key-hereTo create a key:
- Open the Ringover Dashboard
- Go to Developer → API Keys
- Click Create an API key, select a user, set a label
- Configure the key's permissions (see below)
curl --header "Authorization: your-api-key-here" \
https://public-api.ringover.com/v2/callsPermissions
Each API key has 7 permission categories, each set to None, Read, Write, or Read+Write:
| Category | Controls access to |
|---|---|
| Calls | Call history, archives, live call controls, callbacks |
| Contacts | Contact CRUD and phone number management |
| Users | User listing, plannings, presences, groups, user blacklists |
| Numbers | Phone number listing, team blacklist |
| IVRs | IVR/scenario listing, tag management |
| Conversations | SMS/Chat conversations, messages, SMS sending |
| Empower | AI call analysis, summaries, moments, analytics |
Monitoring flag (Supervision)
In addition to Read/Write, each key has a Monitoring toggle controlling data scope:
| Monitoring | Effect |
|---|---|
| OFF | Access to your own data only (your calls, your numbers, your conversations…) |
| ON | Access to the entire team's data (all users, all calls, all conversations…) |
Monitoring does not grant extra permissions — it widens the scope of existing ones. Some routes require Monitoring ON and return 401 without it; others ignore the flag. Each endpoint in the API Reference should state its own requirement.
Special cases
- Campaigns, Tasks, WhatsApp — no specific permission required; a valid API key is enough.
- Empower — has its own role system (Admin / Supervisor / User) in addition to the Empower permission.
- Transcriptions — access controlled by a team-level setting, not by token permissions.
- Conferences — all routes require Monitoring ON.
Rate limiting
2 requests/second per API key. Exceeding it returns 429 Too Many Requests.
The MCP endpoint (see Webhooks for webhooks, or the API Reference for /mcp) has its own, separate limits: 1 req/s (burst 10) at the HTTP level, and roughly 1 call every 3 seconds per team+tool at the tool level.
SCIM 2.0 provisioning
Ringover also exposes a SCIM 2.0 server (RFC 7643/7644) for identity-provider provisioning (Okta, Microsoft Entra ID, …), reusing the same API key:
- Base URL (Europe only):
https://public-api.ringover.com/v2/scim/v2 - Media type:
application/scim+json - Permissions:
Users Readfor reads,Users Writefor provisioning; Monitoring must be ON to operate on the whole team.