# Voxa > Voxa builds and runs AI voice agents that answer and place phone calls. Drive it from code with the REST API (/api/v1), webhooks and the MCP server. ## Get started - [Introduction](https://doc.voxa.abhinavyadav.in/overview.md): Voxa runs AI voice agents that answer and place phone calls, and it keeps a full record of every call: transcript, timeline, recording, cost and post-call analysis. - [Quickstart](https://doc.voxa.abhinavyadav.in/quickstart.md): This guide takes you from an empty workspace to a finished phone call with cURL: create an API key, create an agent, place a call, wait for it to end, and read what was said. - [Call flow](https://doc.voxa.abhinavyadav.in/concepts/call-flow.md): Every call in Voxa moves through a small set of statuses, and this page explains each one: how a call starts, what happens while it runs, how it ends, and what Voxa keeps afterwards. - [Glossary](https://doc.voxa.abhinavyadav.in/concepts/glossary.md): Short definitions of the words these docs use, with a link to the page that covers each one in depth. ## Agents - [Agents](https://doc.voxa.abhinavyadav.in/agents/overview.md): An agent is one complete voice agent configuration, and this page describes the agent object, its editor tabs and the endpoints that create and change it. - [Agent tab](https://doc.voxa.abhinavyadav.in/agents/agent.md): The Agent tab holds what the caller hears first and how the agent should behave: its name, welcome message and prompt, with {variables} you fill in for each call. - [LLM tab](https://doc.voxa.abhinavyadav.in/agents/llm.md): The LLM tab picks the model that decides what the agent says and calls its tools, and sets how varied and how long its replies are. - [Voice tab](https://doc.voxa.abhinavyadav.in/agents/voice.md): The Voice tab sets how the agent sounds: the text-to-speech model, the voice, the language it speaks and how fast it talks. - [Transcriber tab](https://doc.voxa.abhinavyadav.in/agents/transcriber.md): The Transcriber tab picks the speech-to-text service that turns the caller's speech into text and decides when the caller has finished speaking. - [Call tab](https://doc.voxa.abhinavyadav.in/agents/call.md): The Call tab controls how a conversation runs and ends: interruptions, silence handling, the "are you still there?" check, hanging up with a prompt, the maximum length, calling hours and recording. - [Tools](https://doc.voxa.abhinavyadav.in/agents/tools.md): Tools let the agent call your HTTP endpoints in the middle of a conversation, for example to check free slots, book an appointment or look up an order, and the built-in endcall lets it hang up. - [Analytics tab](https://doc.voxa.abhinavyadav.in/agents/analytics.md): The Analytics tab turns on post-call analysis: a short summary of each call and structured fields pulled from its transcript, saved on the call and sent in the call.completed webhook. - [Webhook and number](https://doc.voxa.abhinavyadav.in/agents/webhook-and-number.md): The Webhook & number tab sets where the agent's call events are posted and which phone number the agent answers and calls from. - [Versions](https://doc.voxa.abhinavyadav.in/agents/versions.md): Every change to an agent is saved as a version, with who made it and what changed field by field, so you can see an agent's history and restore an earlier configuration. ## Calls - [Outbound calls](https://doc.voxa.abhinavyadav.in/calls/outbound.md): You place an outbound call with one request; Voxa queues it, dials it when a call slot is free and the agent's calling hours are open, and records everything that happens. - [Inbound calls](https://doc.voxa.abhinavyadav.in/calls/inbound.md): When someone dials a phone number connected to one of your agents, that agent answers; this page explains how numbers are set up and how Voxa decides whether to take the call. - [Browser calls](https://doc.voxa.abhinavyadav.in/calls/browser.md): A browser call lets you talk to an agent through your microphone, with no phone involved, so you can test a prompt or a tool before the agent calls anyone. - [The call object](https://doc.voxa.abhinavyadav.in/calls/call-object.md): Every call in Voxa, outbound, inbound or in the browser, is stored as one call record, and this page describes each of its fields, how to read them, and what they look like for common outcomes. - [Limits and billing](https://doc.voxa.abhinavyadav.in/calls/limits.md): Your workspace can run a fixed number of calls at once and pays for them from a prepaid balance, and this page explains both: concurrency, the queue, credits and how each one affects your calls. ## Webhooks - [Webhooks](https://doc.voxa.abhinavyadav.in/webhooks/overview.md): Voxa posts each event of every call to your server as it happens, signed with a secret only you and Voxa know, and retries deliveries that fail, so a slow or broken endpoint never affects a live call. - [Webhook events](https://doc.voxa.abhinavyadav.in/webhooks/events.md): This page lists every event Voxa sends during a call, when it is sent, and the fields it carries in data. ## MCP server - [MCP server](https://doc.voxa.abhinavyadav.in/mcp/overview.md): Connect Claude, Cursor or any other MCP client to your Voxa workspace, and build, test and run voice agents by asking for it in plain language. - [Connect an MCP client](https://doc.voxa.abhinavyadav.in/mcp/quickstart.md): Add Voxa's MCP server to your assistant, sign in once in the browser, and check the connection with a first prompt. - [Tools](https://doc.voxa.abhinavyadav.in/mcp/tools.md): Every tool the Voxa MCP server exposes, what it needs, and whether your assistant will ask before running it. - [Prompt cheatsheet](https://doc.voxa.abhinavyadav.in/mcp/prompts.md): Prompts to copy into a connected assistant, grouped by task, with the tools each one uses. ## Account - [Authentication](https://doc.voxa.abhinavyadav.in/authentication.md): Your code authenticates to Voxa with an API key, and this page covers keys, roles and permissions, rate limits, time zones and errors: the conventions every endpoint follows. - [Changelog](https://doc.voxa.abhinavyadav.in/changelog.md): Changes to Voxa that affect developers and console users, newest first. ## API reference - [OpenAPI spec](https://doc.voxa.abhinavyadav.in/openapi.json): every public operation, as OpenAPI 3.1 ### Agents - [List agents](https://doc.voxa.abhinavyadav.in/api-reference/agents/list-agents.md): `GET /api/v1/agents`. Every agent in the workspace, with its full configuration and the {variables} its text uses. - [Create an agent](https://doc.voxa.abhinavyadav.in/api-reference/agents/create-an-agent.md): `POST /api/v1/agents`. Only name is required; every other setting has a sensible default. {variables} in the welcome message or prompt are filled from userdata when a call is placed. - [Get an agent](https://doc.voxa.abhinavyadav.in/api-reference/agents/get-an-agent.md): `GET /api/v1/agents/{agent_id}`. One agent with its full configuration. - [Update an agent](https://doc.voxa.abhinavyadav.in/api-reference/agents/update-an-agent.md): `PUT /api/v1/agents/{agent_id}`. Replaces the whole configuration: read the agent, change what you need and send it all back. Fields you leave out go back to their defaults. - [Delete an agent](https://doc.voxa.abhinavyadav.in/api-reference/agents/delete-an-agent.md): `DELETE /api/v1/agents/{agent_id}`. Deletes the agent and its version history. Its past calls are kept. - [Duplicate an agent](https://doc.voxa.abhinavyadav.in/api-reference/agents/duplicate-an-agent.md): `POST /api/v1/agents/{agent_id}/duplicate`. Creates a copy named (copy) with the same configuration, without the phone number. - [List versions](https://doc.voxa.abhinavyadav.in/api-reference/agents/list-versions.md): `GET /api/v1/agents/{agent_id}/versions`. The agent's saved versions, newest first, with who made each change and what changed. Only the most recent versions are kept (10 by default). - [Get a version](https://doc.voxa.abhinavyadav.in/api-reference/agents/get-a-version.md): `GET /api/v1/agents/{agent_id}/versions/{version}`. One saved version, with the full configuration it had (config). Returns 404 for versions no longer kept. - [Restore a version](https://doc.voxa.abhinavyadav.in/api-reference/agents/restore-a-version.md): `POST /api/v1/agents/{agent_id}/versions/{version}/restore`. Puts an older configuration back. The restore is itself saved as a new version, so it can be undone. ### Calls - [Place a call](https://doc.voxa.abhinavyadav.in/api-reference/calls/place-a-call.md): `POST /api/v1/agents/{agent_id}/call`. Queues an outbound phone call. Calls are dialled by a worker as soon as one of your workspace's call slots is free and, unless ignorecallwindow is set, inside the agent's calling hours (call.callstarthour to call.callendhour). - [List calls](https://doc.voxa.abhinavyadav.in/api-reference/calls/list-calls.md): `GET /api/v1/calls`. Calls in the workspace, newest first, without transcripts. Page with limit and skip; total is the number of calls matching the filters. - [Get a call](https://doc.voxa.abhinavyadav.in/api-reference/calls/get-a-call.md): `GET /api/v1/calls/{call_id}`. One call with its transcript, usage, cost, and post-call analytics (summary, extracted). - [List call events](https://doc.voxa.abhinavyadav.in/api-reference/calls/list-call-events.md): `GET /api/v1/calls/{call_id}/events`. The call's timeline, oldest first: every step from call.queued to call.completed, with latencies (latencyms) for model and speech steps. The same events are sent to your webhooks. - [Download a recording](https://doc.voxa.abhinavyadav.in/api-reference/calls/download-a-recording.md): `GET /api/v1/calls/{call_id}/recording`. The call's stereo WAV recording (caller on the left channel, agent on the right). Add download=true to get it as an attachment. Returns 404 when the call wasn't recorded. - [End or cancel a call](https://doc.voxa.abhinavyadav.in/api-reference/calls/end-or-cancel-a-call.md): `POST /api/v1/calls/{call_id}/hangup`. Cancels a queued call, or hangs up a call that is ringing or in progress. ### Webhooks - [List event types](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/list-event-types.md): `GET /api/v1/webhooks/events`. Every event type an endpoint can subscribe to. Subscribe to for all of them. - [List endpoints](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/list-endpoints.md): `GET /api/v1/webhooks`. The workspace's webhook endpoints, newest first. Secrets are never returned here, only a hint. - [Create an endpoint](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/create-an-endpoint.md): `POST /api/v1/webhooks`. Registers a URL to receive call events. The signing secret is in this response only: store it to verify signatures. At most 20 endpoints per workspace. - [Update an endpoint](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/update-an-endpoint.md): `PATCH /api/v1/webhooks/{endpoint_id}`. Changes only the fields you send. - [Delete an endpoint](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/delete-an-endpoint.md): `DELETE /api/v1/webhooks/{endpoint_id}`. Stops deliveries to this endpoint. - [Rotate an endpoint's secret](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/rotate-an-endpoint-s-secret.md): `POST /api/v1/webhooks/{endpoint_id}/rotate-secret`. Issues a new signing secret, returned once. Deliveries are signed with it from now on. - [Send a test event](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/send-a-test-event.md): `POST /api/v1/webhooks/{endpoint_id}/test`. Sends a ping event right away (one attempt, no retries) and returns the delivery, including what your server answered. - [Get the default secret hint](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/get-the-default-secret-hint.md): `GET /api/v1/webhooks/default-secret`. A hint of the workspace's default secret, which signs deliveries to agents' own webhookurl. - [Rotate the default secret](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/rotate-the-default-secret.md): `POST /api/v1/webhooks/default-secret/rotate`. Issues a new default secret, returned once. - [List deliveries](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/list-deliveries.md): `GET /api/v1/webhooks/deliveries`. The delivery log, newest first. status takes several values separated by commas (pending, delivered, failed). - [Get a delivery](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/get-a-delivery.md): `GET /api/v1/webhooks/deliveries/{delivery_id}`. One delivery with the exact body sent and the response received. - [Retry a delivery](https://doc.voxa.abhinavyadav.in/api-reference/webhooks/retry-a-delivery.md): `POST /api/v1/webhooks/deliveries/{delivery_id}/retry`. Sends the delivery once more, now. It does not restart the automatic retry schedule. ### Catalog - [Get the catalog](https://doc.voxa.abhinavyadav.in/api-reference/catalog/get-the-catalog.md): `GET /api/v1/catalog`. The models and languages an agent can use: LLM models, text-to-speech and speech-to-text models, and transcriber providers. - [List voices](https://doc.voxa.abhinavyadav.in/api-reference/catalog/list-voices.md): `GET /api/v1/voices`. Voices for voice.voiceid, filtered by language, gender or a search term. - [Preview a voice](https://doc.voxa.abhinavyadav.in/api-reference/catalog/preview-a-voice.md): `GET /api/v1/voices/{voice_id}/preview`. Speaks text with the voice and returns MP3 audio. - [List providers](https://doc.voxa.abhinavyadav.in/api-reference/catalog/list-providers.md): `GET /api/v1/providers`. Every speech, model and telephony provider, and whether your workspace may use it (usable). ### Phone numbers - [List phone numbers](https://doc.voxa.abhinavyadav.in/api-reference/numbers/list-phone-numbers.md): `GET /api/v1/numbers`. The phone numbers assigned to your workspace, and the agent that answers each. - [Connect a number to an agent](https://doc.voxa.abhinavyadav.in/api-reference/numbers/connect-a-number-to-an-agent.md): `POST /api/v1/numbers/{number}/connect`. Routes inbound calls on one of your numbers to an agent. The number moves off any other agent. ### Tools - [Test a tool](https://doc.voxa.abhinavyadav.in/api-reference/tools/test-a-tool.md): `POST /api/v1/tools/test`. Runs an HTTP tool once with the arguments you give, exactly as an agent would mid-call, and shows what the model would receive. ### Workspace - [Get the workspace](https://doc.voxa.abhinavyadav.in/api-reference/workspace/get-the-workspace.md): `GET /api/v1/workspace`. The workspace your key (or X-Workspace-ID) points at: its status, credit balance and member count. - [Rename the workspace](https://doc.voxa.abhinavyadav.in/api-reference/workspace/rename-the-workspace.md): `PATCH /api/v1/workspace`. PATCH /api/v1/workspace - [Get call limits](https://doc.voxa.abhinavyadav.in/api-reference/workspace/get-call-limits.md): `GET /api/v1/workspace/limits`. How many calls may run at once, how many are running and queued, and any pending request for a higher limit. - [List limit requests](https://doc.voxa.abhinavyadav.in/api-reference/workspace/list-limit-requests.md): `GET /api/v1/workspace/limits/requests`. Requests for a higher concurrency limit, newest first. - [Request a higher limit](https://doc.voxa.abhinavyadav.in/api-reference/workspace/request-a-higher-limit.md): `POST /api/v1/workspace/limits/requests`. Asks the Voxa team to raise the concurrent-call limit. Only one request can wait for review at a time. - [List members](https://doc.voxa.abhinavyadav.in/api-reference/workspace/list-members.md): `GET /api/v1/members`. Everyone in the workspace and their role. - [Change a member's role](https://doc.voxa.abhinavyadav.in/api-reference/workspace/change-a-member-s-role.md): `PATCH /api/v1/members/{user_id}`. Only an owner can grant or take away the owner role, and a workspace always keeps one owner. - [Remove a member](https://doc.voxa.abhinavyadav.in/api-reference/workspace/remove-a-member.md): `DELETE /api/v1/members/{user_id}`. The last owner can't be removed. - [List invites](https://doc.voxa.abhinavyadav.in/api-reference/workspace/list-invites.md): `GET /api/v1/invites`. Pending invites that haven't expired. - [Invite a member](https://doc.voxa.abhinavyadav.in/api-reference/workspace/invite-a-member.md): `POST /api/v1/invites`. Emails an invite link. A newer invite to the same email replaces the older one. Plans cap members, counting pending invites. - [Revoke an invite](https://doc.voxa.abhinavyadav.in/api-reference/workspace/revoke-an-invite.md): `DELETE /api/v1/invites/{invite_id}`. DELETE /api/v1/invites/{invite_id} - [List API keys](https://doc.voxa.abhinavyadav.in/api-reference/workspace/list-api-keys.md): `GET /api/v1/keys`. Active keys. Only the prefix of each key is shown. - [Create an API key](https://doc.voxa.abhinavyadav.in/api-reference/workspace/create-an-api-key.md): `POST /api/v1/keys`. The full key is in this response only; store it somewhere safe. Keys act as a developer in this workspace. - [Revoke an API key](https://doc.voxa.abhinavyadav.in/api-reference/workspace/revoke-an-api-key.md): `DELETE /api/v1/keys/{key_id}`. The key stops working immediately. - [Get KYC](https://doc.voxa.abhinavyadav.in/api-reference/workspace/get-kyc.md): `GET /api/v1/kyc`. The workspace's business details and uploaded documents. - [Save KYC details](https://doc.voxa.abhinavyadav.in/api-reference/workspace/save-kyc-details.md): `PUT /api/v1/kyc`. Saves the business details as a draft. Can't be changed once submitted or approved (409). - [Upload a KYC document](https://doc.voxa.abhinavyadav.in/api-reference/workspace/upload-a-kyc-document.md): `POST /api/v1/kyc/documents`. A PDF, PNG or JPG, sent as multipart/form-data. kind is one of the document kinds in Get settings lists (kycdocumentkinds). - [Download a KYC document](https://doc.voxa.abhinavyadav.in/api-reference/workspace/download-a-kyc-document.md): `GET /api/v1/kyc/documents/{doc_id}`. GET /api/v1/kyc/documents/{doc_id} - [Delete a KYC document](https://doc.voxa.abhinavyadav.in/api-reference/workspace/delete-a-kyc-document.md): `DELETE /api/v1/kyc/documents/{doc_id}`. DELETE /api/v1/kyc/documents/{doc_id} - [Submit KYC](https://doc.voxa.abhinavyadav.in/api-reference/workspace/submit-kyc.md): `POST /api/v1/kyc/submit`. Sends the details and documents for review. Every required field and document must be there (422 names what's missing). - [Search](https://doc.voxa.abhinavyadav.in/api-reference/workspace/search.md): `GET /api/v1/search`. Finds agents, calls and members by name, number or id, limited to what your role can see. - [Get settings lists](https://doc.voxa.abhinavyadav.in/api-reference/workspace/get-settings-lists.md): `GET /api/v1/masters`. Lists the console's forms use: business types, KYC document kinds, languages, Indian states, the currency and the GST rate. ### Billing - [Get the balance](https://doc.voxa.abhinavyadav.in/api-reference/billing/get-the-balance.md): `GET /api/v1/billing`. Credits left, the price per minute, and roughly how many minutes that buys. - [List credit changes](https://doc.voxa.abhinavyadav.in/api-reference/billing/list-credit-changes.md): `GET /api/v1/billing/ledger`. Every change to the balance (top-ups, call charges, adjustments), newest first. - [List payments](https://doc.voxa.abhinavyadav.in/api-reference/billing/list-payments.md): `GET /api/v1/billing/payments`. The last 100 top-up payments. - [Start a top-up](https://doc.voxa.abhinavyadav.in/api-reference/billing/start-a-top-up.md): `POST /api/v1/billing/topup`. Creates a payment for a credit pack (packid) or a custom amount (amountpaise). GST is added on top. - [Complete a payment](https://doc.voxa.abhinavyadav.in/api-reference/billing/complete-a-payment.md): `POST /api/v1/billing/payments/{payment_id}/complete`. The payment gateway's callback (simulated). A created payment completes once; on success the credits are added and an invoice is issued. - [Get the plan](https://doc.voxa.abhinavyadav.in/api-reference/billing/get-the-plan.md): `GET /api/v1/billing/plan`. Your plan, any overrides the Voxa team set for your workspace, and the values in effect. - [List credit packs](https://doc.voxa.abhinavyadav.in/api-reference/billing/list-credit-packs.md): `GET /api/v1/billing/packs`. Credit packs on sale. - [List invoices](https://doc.voxa.abhinavyadav.in/api-reference/billing/list-invoices.md): `GET /api/v1/billing/invoices`. GET /api/v1/billing/invoices - [Download an invoice](https://doc.voxa.abhinavyadav.in/api-reference/billing/download-an-invoice.md): `GET /api/v1/billing/invoices/{invoice_id}/pdf`. The invoice as a PDF. ### Observability - [Get call stats](https://doc.voxa.abhinavyadav.in/api-reference/observability/get-call-stats.md): `GET /api/v1/stats`. Totals, a per-day series and the busiest agents over the last days days (India time). - [List server logs](https://doc.voxa.abhinavyadav.in/api-reference/observability/list-server-logs.md): `GET /api/v1/logs`. Log lines for your workspace, newest first. level=warning shows warnings and errors; source matches a prefix. - [List log sources](https://doc.voxa.abhinavyadav.in/api-reference/observability/list-log-sources.md): `GET /api/v1/logs/sources`. GET /api/v1/logs/sources - [List audit events](https://doc.voxa.abhinavyadav.in/api-reference/observability/list-audit-events.md): `GET /api/v1/audit`. Who changed what in the workspace, newest first. - [Get server settings](https://doc.voxa.abhinavyadav.in/api-reference/observability/get-server-settings.md): `GET /api/v1/settings`. Which providers the server has keys for, its public URL, version and retention settings. ### Account and sign-in - [Sign up](https://doc.voxa.abhinavyadav.in/api-reference/account/sign-up.md): `POST /api/v1/auth/signup`. Creates a user and a workspace (waiting for KYC) and signs in. Returns a session token for Authorization: Bearer. - [Sign in](https://doc.voxa.abhinavyadav.in/api-reference/account/sign-in.md): `POST /api/v1/auth/login`. Exchanges an email and password for a session token. With two-step verification on, the answer is {"requires2fa": true, "challenge": "..."}: finish with Sign in with a code. Repeated failures from one address return 429 for a few minutes. - [Sign in with a code](https://doc.voxa.abhinavyadav.in/api-reference/account/sign-in-with-a-code.md): `POST /api/v1/auth/login/2fa`. The second step of signing in: the challenge from Sign in (valid 5 minutes) and a code from the authenticator app or a recovery code. - [Who am I](https://doc.voxa.abhinavyadav.in/api-reference/account/who-am-i.md): `GET /api/v1/auth/me`. The caller, the current workspace and its permissions. Works with an API key too: then the user is the key (key:) with the developer role. - [Sign out](https://doc.voxa.abhinavyadav.in/api-reference/account/sign-out.md): `POST /api/v1/auth/logout`. Ends the current session. With an API key it does nothing. - [Get an invite](https://doc.voxa.abhinavyadav.in/api-reference/account/get-an-invite.md): `GET /api/v1/invites/{token}`. What an invite link is for, before accepting it. No authentication: the token is the secret. - [Accept an invite](https://doc.voxa.abhinavyadav.in/api-reference/account/accept-an-invite.md): `POST /api/v1/invites/{token}/accept`. Joins the workspace and signs in. New users also send name; existing users send their current password. - [Get your account](https://doc.voxa.abhinavyadav.in/api-reference/account/get-your-account.md): `GET /api/v1/account`. Needs a signed-in user session (Authorization: Bearer from Sign in); API keys get 403. - [Update your name](https://doc.voxa.abhinavyadav.in/api-reference/account/update-your-name.md): `PATCH /api/v1/account`. Needs a signed-in user session (Authorization: Bearer from Sign in); API keys get 403. - [Delete your account](https://doc.voxa.abhinavyadav.in/api-reference/account/delete-your-account.md): `DELETE /api/v1/account`. Signs out everywhere and removes you from every workspace. The last owner of a workspace with other members must hand over ownership first (409). - [Change your email](https://doc.voxa.abhinavyadav.in/api-reference/account/change-your-email.md): `POST /api/v1/account/email`. Needs a signed-in user session (Authorization: Bearer from Sign in); API keys get 403. - [Change your password](https://doc.voxa.abhinavyadav.in/api-reference/account/change-your-password.md): `POST /api/v1/account/password`. Signs out your other sessions. - [List your sessions](https://doc.voxa.abhinavyadav.in/api-reference/account/list-your-sessions.md): `GET /api/v1/account/sessions`. Needs a signed-in user session (Authorization: Bearer from Sign in); API keys get 403. - [Revoke a session](https://doc.voxa.abhinavyadav.in/api-reference/account/revoke-a-session.md): `DELETE /api/v1/account/sessions/{session_id}`. Needs a signed-in user session (Authorization: Bearer from Sign in); API keys get 403. - [Sign out other sessions](https://doc.voxa.abhinavyadav.in/api-reference/account/sign-out-other-sessions.md): `POST /api/v1/account/sessions/revoke-others`. Needs a signed-in user session (Authorization: Bearer from Sign in); API keys get 403. - [Start two-step setup](https://doc.voxa.abhinavyadav.in/api-reference/account/start-two-step-setup.md): `POST /api/v1/account/2fa/setup`. Returns a secret and an otpauth:// URL for an authenticator app. Confirm with Turn on two-step verification. - [Turn on two-step verification](https://doc.voxa.abhinavyadav.in/api-reference/account/turn-on-two-step-verification.md): `POST /api/v1/account/2fa/enable`. Confirms setup with a code from the app and returns one-time recovery codes (shown once). - [Turn off two-step verification](https://doc.voxa.abhinavyadav.in/api-reference/account/turn-off-two-step-verification.md): `POST /api/v1/account/2fa/disable`. Needs a signed-in user session (Authorization: Bearer from Sign in); API keys get 403.