Create a key in the CRM under Integrations → API keys (organization admin, Pro / Enterprise plans) and choose its scopes. The key is shown once.
Send it on every request as Authorization: Bearer rcrm_… or X-API-Key: rcrm_…. Requests run inside the key's organization; records it creates are owned by the key's creator unless you pass owner_email.
Rate limit: 300 requests per minute per key (HTTP 429 with Retry-After). Bodies are JSON (Content-Type: application/json); form posts are also accepted.
curl -X GET "https://crm.simulatefin.com/api/v1/calls" \
-H "Authorization: Bearer rcrm_…"
GET/lookupcalls:read
Caller ID / screen pop: ?phone=0521234567 returns the client, its owner, the owner's extension and open deals.
curl -X GET "https://crm.simulatefin.com/api/v1/lookup?phone=0521234567" \
-H "Authorization: Bearer rcrm_…"
List responses: {"data": [...], "meta": {"page": 1, "per_page": 25, "total": 130}}. Single objects: {"data": {...}}. Dates are YYYY-MM-DD HH:MM:SS in the organization's time zone.
Webhooks
Subscribe a URL under Integrations → Webhooks. Events:
client.created, client.updated, client.status_changed, lead.web_form, deal.created, deal.stage_changed, task.created, task.completed, meeting.booked, email.received, quote.sent, quote.accepted, quote.rejected, invoice.paid, call.ringing, call.completed, call.missed, plus ping from the Test button.
Each delivery is an HTTP POST with a JSON body:
Headers: X-RoboCRM-Event, X-RoboCRM-Delivery (unique id — use it to ignore duplicates), X-RoboCRM-Timestamp, X-RoboCRM-Signature: t=<timestamp>,v1=<hex>
where v1 = HMAC-SHA256(secret, timestamp + "." + raw_body). Reject requests older than 5 minutes. Answer with any 2xx within 10 seconds; otherwise the delivery is retried after 1 min, 5 min, 30 min, 2 h and 6 h. After 30 failures in a row the webhook is paused and the admins are notified.
In Integrations → Telephony turn telephony on, set the country code and give every agent their PBX extension.
Create an API key with the scopes calls:write and calls:read for the PBX.
Call events — on every state change the PBX sends POST /calls with the same call_id:
ringing (the agent sees a pop-up with the caller's card), answered, and finally completed, missed, busy, failed or voicemail.
Numbers may be local (052-1234567) or international (+972521234567). The CRM matches the client by phone, maps the agent by extension (or agent_email),
logs the call on the client's timeline with duration and recording link, creates a lead for unknown callers and a "call back" task for missed calls (both optional), and fires call.completed / call.missed for automations and webhooks.
Caller ID — before ringing the agent, the PBX may call GET /lookup?phone=… to show the client name on the phone or route the call to the client's owner (owner_extension).
Click to call — set a Dial URL on the PBX side. When an agent clicks a phone number, the CRM sends
signed like webhooks with the dial secret (X-RoboCRM-Signature). The PBX rings the extension and then dials the number. Without a Dial URL the CRM opens a tel: link (softphone / mobile).