Developer API

Build on Loomira

Create and manage voice agents, read calls and transcripts, manage knowledge and receive signed event webhooks — over a plain REST API, hosted entirely in the EU.

Open the interactive API reference

Authentication

Every request carries an API key in the X-Api-Key header. Create keys in the portal under Developer → API keys — the secret is shown exactly once. Keys carry scopes (read, write, admin for webhook configuration) and are rate-limited per key; watch the X-RateLimit-* response headers. API access is included on the Scale plan and above.

Quickstart

curl

# 1. Create an API key in the portal: Developer → API keys
# 2. Create your first agent
curl -X POST https://api.loomira.ai/v1/agents \
  -H "X-Api-Key: lmk_..." \
  -H "Content-Type: application/json" \
  -d '{"name": "Reception Agent"}'

# 3. List calls (transcripts ride along on the call detail)
curl https://api.loomira.ai/v1/calls -H "X-Api-Key: lmk_..."

Python

import httpx

API = "https://api.loomira.ai/v1"
HEADERS = {"X-Api-Key": "lmk_..."}

agent = httpx.post(f"{API}/agents", headers=HEADERS,
                   json={"name": "Reception Agent"}).json()
calls = httpx.get(f"{API}/calls", headers=HEADERS).json()

TypeScript

const API = "https://api.loomira.ai/v1";
const headers = { "X-Api-Key": "lmk_...", "Content-Type": "application/json" };

const agent = await fetch(`${API}/agents`, {
  method: "POST",
  headers,
  body: JSON.stringify({ name: "Reception Agent" }),
}).then(r => r.json());

Webhooks & signature verification

Register HTTPS endpoints in the portal (Developer → Webhooks) or via POST /v1/webhooks. Loomira signs every delivery: X-Loomira-Signature carries sha256=<hex>, the HMAC-SHA256 of the raw request body under your endpoint's signing secret (shown once at creation); X-Loomira-Event names the event type. Events: call.started, call.completed, lead.captured, booking.created, transcript.ready, message.received. Failed deliveries retry (1m/5m/30m/2h/8h) and land in a redeliverable dead-letter log.

Endpoints can be scoped to a single agent: pass agent_id on POST /v1/webhooks to receive only that agent's events, or leave it null to receive every agent's. Re-pin with agent_id or unbind with clear_agent_id on PUT; list endpoints and deliveries filtered by ?agent_id=. Per-agent endpoints are also manageable in the portal, in the agent editor's Technical tab.

Verify a signature (Python)

import hashlib, hmac

def verify(secret: str, body: bytes, signature_header: str) -> bool:
    expected = "sha256=" + hmac.new(secret.encode(), body,
                                    hashlib.sha256).hexdigest()
    return hmac.compare_digest(expected, signature_header)

# FastAPI example
@app.post("/webhooks/loomira")
async def receive(request: Request):
    body = await request.body()
    if not verify(SIGNING_SECRET, body,
                  request.headers["X-Loomira-Signature"]):
        raise HTTPException(401)
    event = request.headers["X-Loomira-Event"]  # e.g. call.completed
    ...

Postman

Import the live OpenAPI document straight into Postman: Import → Link and paste https://api.loomira.ai/v1/openapi.json. Postman generates the full collection with the X-Api-Key auth pre-configured.