SautiKit
/ai-agents/pricing/docs/api/blog
sign inStart building
API Reference
API Reference
Get an API keyMint a bearer token in the dashboard
Overview
OAuth 2.1 authorization server metadata GETDynamic client registration POSTAuthorization endpoint GETToken endpoint POSTToken revocation endpoint POST
OAuth

Token revocation endpoint

POST
/oauth/revoke

RFC 7009. Always 200, whether or not the token existed.

Response Body

curl -X POST "https://example.com/oauth/revoke"
Empty

Token endpoint POST

RFC 6749 §3.2. Exchanges an authorization code (with PKCE verifier) or a refresh token.

Exchange a connection code for a device credential POST

Unauthenticated by design: the connection code IS the credential, which is what lets the agent app have no sign-in screen at all. Returns a long-lived per-device secret, shown ONCE, which the device then presents to mint short-lived WebRTC tokens and to heartbeat presence. Every failure except a full line answers `devices.code_invalid` without saying why — distinguishing expired from unknown from already-used would turn this into an oracle for whether six digits ever existed.

SautiKit

Programmable voice infrastructure for Africa. Buy numbers, place calls, and bill per second, all in local currency, via API.

All systems operational

Product

AI voice agentsBroadcastsNumbersCalls & routingRecordingsWallet & billingPricing

Developers

DocumentationAPI referenceVoice actionsWebhooksErrorsMCP serverQuickstartAI prompt

Compare

vs Africa's Talkingvs Twiliovs Infobipvs Vapi, Retell & BlandMigrate from Africa's TalkingAll comparisons

Company

AboutBlogConsole

© 2026 Sautikit. All rights reserved • Powered by Helloduty

Terms of ServicePrivacy Policy

Sautikit provides voice API services for application developers. Numbers provisioned on this platform are not configured for emergency calling (e.g. 999 / 112). Do not use Sautikit numbers as a replacement for a primary phone line.