Overview
Bananaflow AI uses webhooks to communicate with telephony providers for call events and audio streaming. For outbound calls, Bananaflow builds these URLs and hands them to the provider when it dials – you never configure them by hand. For inbound calls, you point your provider at a single dispatcher URL; see Inbound Calls. Every webhook path lives under/api/v1/telephony on https://app.bananaflow.ai. Audio streams use the same host over wss://app.bananaflow.ai.
Webhook Types
1. Answer Webhook
When an outbound call connects, the provider requests instructions. The path is provider-specific, and Bananaflow appends the routing parameters as a query string:
Telnyx, Asterisk ARI, and Exotel outbound have no answer webhook. Telnyx is call-control style – Bananaflow POSTs the stream and event URLs to Telnyx’s API instead of returning markup. ARI streams over a WebSocket only. Exotel Connect Voice AI attaches
StreamUrl at dial time.
- Twilio (TwiML)
- Vonage (NCCO)
123 is the workflow, 11 the organization, and 789 the workflow run.
2. Status Callbacks
Receive call lifecycle events. Each is keyed on the workflow run:
Providers report their own vocabulary; Bananaflow normalizes it into a common set of states:
initiated- Call request receivedringing- Call is ringingin-progress- Call is connected and streaminganswered- Call was answeredcompleted- Call ended normallybusy- Line was busyno-answer- Call not answeredcanceled- Call was canceled before connectingfailed- Call failederror- Provider reported an error
3. WebSocket Audio Stream
Real-time audio streaming for voice interaction. Endpoint:/api/v1/telephony/ws/{workflow_id}/{organization_id}/{workflow_run_id}
When the stream URL is signed, the URL Bananaflow hands the carrier gains a fourth segment holding the HMAC signature: /api/v1/telephony/ws/{workflow_id}/{organization_id}/{workflow_run_id}/{token}. It is a path segment rather than a query parameter because carriers do not reliably forward query strings – Twilio strips them from <Stream url> entirely.
Asterisk ARI instead connects to /api/v1/telephony/ws/ari and passes the same three values as query parameters, plus token when the URL is signed – see Asterisk ARI.
The Telnyx call-events webhook is the other exception: it takes ?token= in the query string, because Telnyx does preserve query strings on webhook POSTs (the restriction above is specific to carrier media-stream URLs). The route verifies it before any database lookup, so an unauthenticated caller cannot tell an existing run from a missing one by status code or by timing.
The organization_id segment is the tenant that owns the workflow. Bananaflow scopes every workflow and workflow-run lookup by it, so a run belonging to one organization can never be served under another’s id.
Audio Formats:
- Twilio / Plivo / Vobiz: 8kHz μ-law (MULAW), Base64-encoded in JSON messages
- Vonage: 16kHz Linear PCM, Binary frames
- Asterisk ARI: 8kHz Linear PCM via externalMedia
How It Works
Bananaflow AI automatically:- Builds the webhook and stream URLs for each call on
app.bananaflow.ai - Passes them to the telephony provider when initiating calls
- Verifies webhook signatures for security:
- Twilio: HMAC-SHA1 signature validation
- Plivo / Vobiz: HMAC-SHA256 signature validation
- Vonage: JWT token verification
- Processes status updates to track call lifecycle
- Manages WebSocket connections for audio streaming
- Handles provider-specific audio formats and protocols
Troubleshooting
Signature verification failures
Signature verification failures
- Providers sign the full URL, query string included, so the URL in your provider’s console must match the one Bananaflow set exactly
- Confirm the auth token or signing secret saved in Bananaflow matches your provider account
Status callbacks not received
Status callbacks not received
- Verify workflow_run_id is included in URL
- Check provider console for webhook errors
- Review webhook retry logs