Developer API
Build on Loomira
Create and manage voice agents, read calls and transcripts, manage knowledge and receive signed event webhooks — over a plain REST API, hosted entirely in the EU.
Open the interactive API referenceMCP server
Manage Loomira from Claude, Cursor or any MCP client — same API key, native MCP.
Build an agent via the API
From API key to live browser call, step by step — tools, activation, webhooks.
Web embed
Put the <loomira-call> button on your own site with two lines of HTML.
Authentication
Every request carries an API key in the X-Api-Key header. Create keys in the portal under Developer → API keys — the secret is shown exactly once. Keys carry scopes (read, write, admin for webhook configuration) and are rate-limited per key; watch the X-RateLimit-* response headers. API access is included on the Scale plan and above.
Quickstart
curl
# 1. Create an API key in the portal: Developer → API keys
# 2. Create your first agent
curl -X POST https://api.loomira.ai/v1/agents \
-H "X-Api-Key: lmk_..." \
-H "Content-Type: application/json" \
-d '{"name": "Reception Agent"}'
# 3. List calls (transcripts ride along on the call detail)
curl https://api.loomira.ai/v1/calls -H "X-Api-Key: lmk_..."Python
import httpx
API = "https://api.loomira.ai/v1"
HEADERS = {"X-Api-Key": "lmk_..."}
agent = httpx.post(f"{API}/agents", headers=HEADERS,
json={"name": "Reception Agent"}).json()
calls = httpx.get(f"{API}/calls", headers=HEADERS).json()TypeScript
const API = "https://api.loomira.ai/v1";
const headers = { "X-Api-Key": "lmk_...", "Content-Type": "application/json" };
const agent = await fetch(`${API}/agents`, {
method: "POST",
headers,
body: JSON.stringify({ name: "Reception Agent" }),
}).then(r => r.json());Webhooks & signature verification
Register HTTPS endpoints in the portal (Developer → Webhooks) or via POST /v1/webhooks. Loomira signs every delivery: X-Loomira-Signature carries sha256=<hex>, the HMAC-SHA256 of the raw request body under your endpoint's signing secret (shown once at creation); X-Loomira-Event names the event type. Events: call.started, call.completed, lead.captured, booking.created, transcript.ready, message.received. Failed deliveries retry (1m/5m/30m/2h/8h) and land in a redeliverable dead-letter log.
Endpoints can be scoped to a single agent: pass agent_id on POST /v1/webhooks to receive only that agent's events, or leave it null to receive every agent's. Re-pin with agent_id or unbind with clear_agent_id on PUT; list endpoints and deliveries filtered by ?agent_id=. Per-agent endpoints are also manageable in the portal, in the agent editor's Technical tab.
Verify a signature (Python)
import hashlib, hmac
def verify(secret: str, body: bytes, signature_header: str) -> bool:
expected = "sha256=" + hmac.new(secret.encode(), body,
hashlib.sha256).hexdigest()
return hmac.compare_digest(expected, signature_header)
# FastAPI example
@app.post("/webhooks/loomira")
async def receive(request: Request):
body = await request.body()
if not verify(SIGNING_SECRET, body,
request.headers["X-Loomira-Signature"]):
raise HTTPException(401)
event = request.headers["X-Loomira-Event"] # e.g. call.completed
...Postman
Import the live OpenAPI document straight into Postman: Import → Link and paste https://api.loomira.ai/v1/openapi.json. Postman generates the full collection with the X-Api-Key auth pre-configured.