HTTP API
The HTTP API supports health checks, static SIP webhooks, management, media commands, and recording streaming.
Auth
When bearer auth is enabled, command and recording routes require:
http
Authorization: Bearer <token>GET /healthz remains unauthenticated.
Health
http
GET /healthzResponse:
json
{ "ok": true, "calls": 0 }Calls And Sessions
GET /callsGET /calls/:callIdGET /sessionsGET /sessions/:sessionIdPOST /callsDELETE /sessions/:sessionIdPOST /calls/:callId/reinvitePOST /calls/:callId/bye
Media Commands
POST /sessionsPOST /sessions/:sessionId/webrtc/offersPOST /sessions/:sessionId/webrtc/from-offerPOST /endpoints/:endpointId/webrtc/answerPOST /endpoints/:endpointId/webrtc/offer-answerPOST /endpoints/:endpointId/webrtc/ice-restartPOST /sessions/:sessionId/rtp/offersPOST /sessions/:sessionId/rtp/from-offerPOST /endpoints/:endpointId/rtp/answerPOST /endpoints/:endpointId/rtp/reinvitePOST /sessions/:sessionId/media/playPOST /sessions/:sessionId/media/bridgePOST /media/bridges/:endpointId/unbridgeDELETE /media/bridges/:endpointIdPOST /sessions/:sessionId/media/gatherPOST /sessions/:sessionId/media/play-and-gatherPOST /sessions/:sessionId/media/leave-messagePOST /media/endpoints/:endpointId/dtmfPOST /media/endpoints/:endpointId/directionDELETE /media/endpoints/:endpointId
Recordings
POST /sessions/:sessionId/recordingsPOST /recordings/:recordingId/stopGET /recordingsGET /recordings/:backendIdGET /recordings/:backendId/*POST /recordings/mergeDELETE /recordings/:backendId/*
Streaming routes return PCAP bytes and should be consumed as binary streams.
GET /recordings scans rtpbridge recording indexes and can fan out across multiple configured backends. Production archival flows should usually choose deterministic filePath values, persist the returned backendId, and then download or merge explicit { backendId, path } targets without a prefix scan.