SIP & browser tokens
Create browser token
Creates a short-lived browser token for an eligible active SIP identity.
/api/v1/sip/browser-tokenBefore you start
Create this request on your server with the account API key and a permitted SIP identity.
Result
Return the short-lived token to your browser client, not the account API key.
Charges and safe retries
Do not embed account API keys in websites or mobile applications.
Authentication
Send your account API key in the X-Api-Key header. Keep it on your server; never embed it in browser code.
Request examples
Replace the example values with your own inputs. Examples do not run on this page. Production requests can change your account or incur charges.
cURL
curl -X POST "https://api.illyvoip.com/api/v1/sip/browser-token" \
-H "X-Api-Key: ${ILLYVOIP_API_KEY:?Set ILLYVOIP_API_KEY}" \
-H "Content-Type: application/json" \
-d '{
"region": "de"
}'Node.js
const response = await fetch("https://api.illyvoip.com/api/v1/sip/browser-token", {
method: "POST",
headers: {
"X-Api-Key": process.env.ILLYVOIP_API_KEY,
'Content-Type': 'application/json'
},
body: JSON.stringify({
"region": "de"
})
});
const data = await response.json();
console.log(response.status, data);PHP
<?php
$ch = curl_init('https://api.illyvoip.com/api/v1/sip/browser-token');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'X-Api-Key: ' . getenv('ILLYVOIP_API_KEY'),
'Content-Type: application/json'
],
CURLOPT_POSTFIELDS => '{
"region": "de"
}',
]);
$response = curl_exec($ch);
$status = curl_getinfo($ch, CURLINFO_HTTP_CODE);
curl_close($ch);
echo $status . PHP_EOL;
echo $response;Python
import os
import json
import requests
response = requests.request(
"POST",
"https://api.illyvoip.com/api/v1/sip/browser-token",
headers={
"X-Api-Key": os.environ["ILLYVOIP_API_KEY"],
'Content-Type': 'application/json'
},
json=json.loads("{\n \"region\": \"de\"\n}"),
)
print(response.status_code)
print(response.json())Node.js examples run on the server (Node.js 22.17+). Python examples require requests; PHP examples require cURL. Set the environment variables referenced in each example.
Request body
application/json
Body required.
sip_user_idstringoptionalOptional active SIP identity whose available_actions includes browser_token.
regionstringoptionalOptional browser POP selection such as de, us, or sg.
hostnamestringoptionalAdditional properties: not allowed.
Full schema
{
"type": "object",
"additionalProperties": false,
"properties": {
"sip_user_id": {
"type": "string",
"description": "Optional active SIP identity whose `available_actions` includes `browser_token`."
},
"region": {
"type": "string",
"description": "Optional browser POP selection such as `de`, `us`, or `sg`."
},
"hostname": {
"type": "string"
}
}
}Example body
{
"sip_user_id": "YOUR_SIP_USER_ID",
"region": "de"
}Request behavior
Call this from your backend only using the account API key. Return the token payload to your frontend SDK instead of exposing the API key in browser code. The requested identity’s available_actions must include browser_token.
Response fields
status: Request outcome. Read the resource state separately; success does not always mean delivery or completion.token: Short-lived browser credential. Keep it private and respect its expiry.expires_at: Credential expiry time.expires_in: Credential lifetime in seconds.refresh_before_seconds: How early to refresh the credential before it expires.header_name: HTTP header used to send this credential.
HTTP responses
Expand a status to inspect its documented response format and examples. Example prices, IDs and timestamps are illustrative values, not quotes or account records.
200 Successful customer-facing response.
application/json
{
"status": "success",
"token": "YOUR_SHORT_LIVED_BROWSER_TOKEN",
"expires_at": "2026-09-07T12:15:00+00:00",
"expires_in": 900,
"refresh_before_seconds": 120,
"header_name": "X-Illy-Browser-Token"
}statusstringrequiredtokenstringrequiredexpires_atstringrequiredexpires_inintegerrequiredrefresh_before_secondsintegerrequiredheader_namestringrequiredAdditional properties: not allowed.
Full schema
{
"type": "object",
"additionalProperties": false,
"properties": {
"status": {
"type": "string",
"enum": [
"success"
]
},
"token": {
"type": "string"
},
"expires_at": {
"type": "string"
},
"expires_in": {
"type": "integer"
},
"refresh_before_seconds": {
"type": "integer"
},
"header_name": {
"type": "string"
}
},
"required": [
"status",
"token",
"expires_at",
"expires_in",
"refresh_before_seconds",
"header_name"
]
}400 The request body or browser-session selection is invalid.
application/json
statusstringrequiredmessagestringrequirederror_codestringoptionalPublic incident or validation code when the endpoint provides one.
fieldsobjectoptionalPublic validation details when supplied by the endpoint.
Additional properties: not allowed.
Full schema
{
"type": "object",
"additionalProperties": false,
"required": [
"status",
"message"
],
"properties": {
"status": {
"type": "string",
"enum": [
"error"
]
},
"message": {
"type": "string"
},
"error_code": {
"type": "string",
"nullable": true,
"description": "Public incident or validation code when the endpoint provides one."
},
"fields": {
"type": "object",
"additionalProperties": true,
"description": "Public validation details when supplied by the endpoint."
}
}
}401 The API key is missing or invalid.
application/json
statusstringrequiredmessagestringrequirederror_codestringoptionalPublic incident or validation code when the endpoint provides one.
fieldsobjectoptionalPublic validation details when supplied by the endpoint.
Additional properties: not allowed.
Full schema
{
"type": "object",
"additionalProperties": false,
"required": [
"status",
"message"
],
"properties": {
"status": {
"type": "string",
"enum": [
"error"
]
},
"message": {
"type": "string"
},
"error_code": {
"type": "string",
"nullable": true,
"description": "Public incident or validation code when the endpoint provides one."
},
"fields": {
"type": "object",
"additionalProperties": true,
"description": "Public validation details when supplied by the endpoint."
}
}
}403 Only an authenticated account owner may issue a browser token.
application/json
statusstringrequiredmessagestringrequirederror_codestringoptionalPublic incident or validation code when the endpoint provides one.
fieldsobjectoptionalPublic validation details when supplied by the endpoint.
Additional properties: not allowed.
Full schema
{
"type": "object",
"additionalProperties": false,
"required": [
"status",
"message"
],
"properties": {
"status": {
"type": "string",
"enum": [
"error"
]
},
"message": {
"type": "string"
},
"error_code": {
"type": "string",
"nullable": true,
"description": "Public incident or validation code when the endpoint provides one."
},
"fields": {
"type": "object",
"additionalProperties": true,
"description": "Public validation details when supplied by the endpoint."
}
}
}409 The requested SIP identity is unavailable or no longer eligible.
application/json
statusstringrequiredmessagestringrequirederror_codestringoptionalPublic incident or validation code when the endpoint provides one.
fieldsobjectoptionalPublic validation details when supplied by the endpoint.
Additional properties: not allowed.
Full schema
{
"type": "object",
"additionalProperties": false,
"required": [
"status",
"message"
],
"properties": {
"status": {
"type": "string",
"enum": [
"error"
]
},
"message": {
"type": "string"
},
"error_code": {
"type": "string",
"nullable": true,
"description": "Public incident or validation code when the endpoint provides one."
},
"fields": {
"type": "object",
"additionalProperties": true,
"description": "Public validation details when supplied by the endpoint."
}
}
}413 The JSON request body is too large.
application/json
statusstringrequiredmessagestringrequirederror_codestringoptionalPublic incident or validation code when the endpoint provides one.
fieldsobjectoptionalPublic validation details when supplied by the endpoint.
Additional properties: not allowed.
Full schema
{
"type": "object",
"additionalProperties": false,
"required": [
"status",
"message"
],
"properties": {
"status": {
"type": "string",
"enum": [
"error"
]
},
"message": {
"type": "string"
},
"error_code": {
"type": "string",
"nullable": true,
"description": "Public incident or validation code when the endpoint provides one."
},
"fields": {
"type": "object",
"additionalProperties": true,
"description": "Public validation details when supplied by the endpoint."
}
}
}429 The API request rate limit was exceeded.
application/json
statusstringrequiredmessagestringrequirederror_codestringoptionalPublic incident or validation code when the endpoint provides one.
fieldsobjectoptionalPublic validation details when supplied by the endpoint.
Additional properties: not allowed.
Full schema
{
"type": "object",
"additionalProperties": false,
"required": [
"status",
"message"
],
"properties": {
"status": {
"type": "string",
"enum": [
"error"
]
},
"message": {
"type": "string"
},
"error_code": {
"type": "string",
"nullable": true,
"description": "Public incident or validation code when the endpoint provides one."
},
"fields": {
"type": "object",
"additionalProperties": true,
"description": "Public validation details when supplied by the endpoint."
}
}
}500 An unexpected backend error occurred and an incident code was returned.
application/json
statusstringrequiredmessagestringrequirederror_codestringoptionalPublic incident or validation code when the endpoint provides one.
fieldsobjectoptionalPublic validation details when supplied by the endpoint.
Additional properties: not allowed.
Full schema
{
"type": "object",
"additionalProperties": false,
"required": [
"status",
"message"
],
"properties": {
"status": {
"type": "string",
"enum": [
"error"
]
},
"message": {
"type": "string"
},
"error_code": {
"type": "string",
"nullable": true,
"description": "Public incident or validation code when the endpoint provides one."
},
"fields": {
"type": "object",
"additionalProperties": true,
"description": "Public validation details when supplied by the endpoint."
}
}
}503 SIP connection setup is temporarily unavailable. Retry later; contact support if it persists.
application/json
statusstringrequiredmessagestringrequirederror_codestringoptionalPublic incident or validation code when the endpoint provides one.
fieldsobjectoptionalPublic validation details when supplied by the endpoint.
Additional properties: not allowed.
Full schema
{
"type": "object",
"additionalProperties": false,
"required": [
"status",
"message"
],
"properties": {
"status": {
"type": "string",
"enum": [
"error"
]
},
"message": {
"type": "string"
},
"error_code": {
"type": "string",
"nullable": true,
"description": "Public incident or validation code when the endpoint provides one."
},
"fields": {
"type": "object",
"additionalProperties": true,
"description": "Public validation details when supplied by the endpoint."
}
}
}Sandbox scenarios
Use https://sandbox-api.illyvoip.com with Sandbox credentials and the X-Illyvoip-Sandbox-Scenario header. Omit the header for the documented success default. This header belongs to sandbox requests.
success, not-found, rate-limited, forbidden, service-unavailable
Try this operation in Sandbox · Environment setup and limitations