Configure in the ConsoleWebhook URL and method are configured per trunk in the Vobiz Console → SIP → Outbound Trunks. You can also set them when creating or updating a trunk via the API.
Configuration
Each trunk can optionally have a webhook configured with two fields:Security validation
When a webhook URL is configured, Vobiz validates it against SSRF attacks before accepting it. The following are blocked:- Schemes: Only http and https are allowed.
- Localhost: 127.0.0.1, ::1, and 0.0.0.0 are blocked.
- Private IP ranges: 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 are blocked.
- Link-local addresses: 169.254.0.0/16 is blocked, including the AWS metadata endpoint (169.254.169.254).
- IPv6: ULA (fc00::/7) and multicast (ff00::/8) addresses are blocked.
Webhook events
Vobiz delivers three event types to your configured webhook URL.recording.completed is sent only when recording is enabled on the trunk.
CallInitiated
Fired for every outbound call attempt during call admission, whether the call is allowed or rejected. Use this event for real-time call monitoring and rejection alerting. Fires when:- Call is admitted -
Allowed: true - Call is rejected -
Allowed: falsewith aReason
- Insufficient balance
- CLI ownership validation failed
- Aadhaar verification pending
- KYC verification required
- Rate limit or concurrent call limit exceeded
- No routes available
Hangup
Fired when a call ends. Includes the full call record - duration, billable seconds, ring time, cost, currency, voice quality (MOS), the bridged-leg UUID, and hangup cause details (name, code, and which party released the call).Hangup Payload
recording.completed
Fired when a call recording is ready, ifrecording is enabled on the trunk. The X-Vobiz-Event header is set to recording.completed. Unlike the call events, this payload uses snake_case field names.
recording.completed payload
HTTP request details
Headers sent with every webhook
Timeouts
Verify the request
Trunk webhooks are not currently signed. To verify a request came from Vobiz, allow-list the Vobiz callback IPs listed on IP Whitelisting, and use an unguessable path or token in your webhook URL.Link events for the same call
UseSIPCallID to link CallInitiated and Hangup for the same call. In Hangup, CallUUID is Vobiz’s internal call ID and can differ from CallInitiated. X-Vobiz-Request-ID is unique per delivery; use it only to de-duplicate retries.
Behavior & reliability
Non-blocking
All webhooks are sent asynchronously. Webhook requests never delay the SIP call flow - call admission and CDR processing proceed independently of webhook delivery.Fail-open
Webhook failures do not affect calls:- If the webhook URL is unreachable, the call still proceeds normally.
- Non-2xx responses are logged but do not affect the call.
- Network timeouts are logged as errors with no retry.