Developers

Build on AnswerStack. Give nothing more access than it needs.

A REST API described in OpenAPI, an MCP server for AI assistants and agents, a signed webhook, and tokens scoped to exactly what each script, partner or app should do.

Three ways in

  • REST API

    Calls, transcripts, insights, bookings, callbacks, playbooks and knowledge over HTTPS and JSON, in an OpenAPI document that marks every route a token may use.

  • MCP server

    22 tools and 4 resources for AI assistants and agents, with sign-in and consent through our own OAuth server.

  • Webhook

    Contacts, call logs and follow-up tasks pushed to your endpoint as they happen, signed.

API tokens

A token for every job, and only for that job.

Each token carries scopes in plain words, the same permissions an AI assistant asks for, so there is one model to learn.

  • Personal tokens

    For your own scripts. Acts as you, never with more than your role allows, and ends after 30, 90 or 365 days, or when you leave.

  • Service identities

    For software, not people: a data warehouse, a partner’s system. A role ceiling, optional community limits, and IP allowlists.

  • Machine OAuth

    For partners that expect OAuth: client credentials for short-lived tokens to the MCP server.

List this week’s booked calls
curl "$ANSWERSTACK_API/v1/account/calls?outcome=booked&limit=50" \
  -H "Authorization: Bearer $ANSWERSTACK_TOKEN"
Every token in the account
  • Warehouse loader ans_svc_…7Q2KService identity · account:read, calls:read, insights:read · ends Sep 2027
  • Nightly export ans_pat_…OVyAPersonal · calls:read · last used today · ends in 72 days
API tokens · illustration with sample data
Making a personal token in the admin app: a name, a list of permissions in plain words with the ones that make changes marked, which communities it may see, and when it ends.
Scopes in plain words. The token is shown once.

MCP server

Your account, inside the AI tools your team already uses.

Add one address to any MCP client. The member signs in and chooses what it may do; the client can then ask about calls, trends, visits and open callbacks in plain language.

Add AnswerStack to an MCP client
{
  "mcpServers": {
    "answerstack": { "url": "https://api.example.com/mcp" }
  }
}

Your account’s address comes with your early access setup.

  • Ask for the least you need. A refused call names the scope to ask for.
  • What callers said comes back marked as untrusted text, so your agent never takes it as an instruction.
  • 60 requests a minute per token or connected app, and 10 changes a minute per app.
  • Account

    list_groupsget_usage

  • Calls

    search_callsget_callget_transcriptget_analytics

  • Insights

    get_scorecardcompare_insightsquery_insights

  • Bookings, visits and callbacks

    list_bookingsget_visitlist_visit_actionslist_callbackscomplete_callback

  • Playbooks

    list_playbooksget_playbook_versiondiff_playbook_versionsupdate_playbook_draftsimulate_booking_rules

  • Knowledge and communities

    search_knowledgeadd_knowledge_documentupdate_group_profile

Scopes, in plain words

The same list a member sees on the consent screen and when making a token. Scopes that make changes are marked.

ScopeWhat it allowsMakes changes
account:readSee your account, groups and phone numbersNo
analytics:readSee your call metrics and booking ratesNo
insights:readSee Insights: scorecards, comparisons and trends, peers kept anonymousNo
calls:readSee your calls: outcome, length, group and summaryNo
transcripts:readRead what was said on calls, and the answers callers gaveNo
recordings:readListen to call recordingsNo
contacts:readSee callers' names and phone numbersNo
bookings:readSee your bookingsNo
callbacks:readSee callbacksNo
callbacks:writeMark callbacks doneYes
playbooks:readRead your playbooks and their historyNo
playbooks:writeEdit playbook drafts (never publish them)Yes
knowledge:readSearch your knowledge documentsNo
knowledge:writeAdd knowledge documentsYes
groups:writeEdit and publish group profiles where they are not lockedYes
usage:readSee usage and invoicesNo

Security model

Built so a leaked token is a small problem.

  • Shown once, stored as a hash

    We keep only a fingerprint. Prefixes (ans_pat_, ans_svc_) make a leaked one easy to spot.

  • Scoped and narrowed

    Never more than its scopes, its owner’s role today, or the communities it was limited to.

  • Revoked at once

    Revoke a token or an app and it stops. Deactivating a member ends their tokens with them.

  • Audited

    Every change a token or app makes is logged, and each owner is emailed a week before a token ends.

Hear it answer for your community

Early access partners get a sample community set up with their own name and tour hours, a call from their own phone, and pilot pricing shaped around the parts they choose.