# Call recording

`POST /v1/calls/:callId/record`

**Scope:** `telephony` | **Authentication:** `X-Api-Key` | **URL:** `https://vibecode.bitrix24.com/v1`

POST /v1/calls/:callId/record calls telephony.externalCall.attachRecord for a completed external call. Body: {fileName,fileContent} with base64 or {recordUrl,fileName?}. fileName must end in .mp3 or .wav; without fileName in URL mode the name comes from the URL path. recordUrl must be public HTTPS without credentials; private addresses are forbidden. Limit: 2 MiB decoded file and 3 MiB JSON; exceeding it returns 413 PAYLOAD_TOO_LARGE. fileName without fileContent and recordUrl: 400 MISSING_REQUIRED_FIELDS. uploadUrl is never returned. Response: data: {fileId}. Unfinished call: upstream refusal 422; a missing call may return 404 ENTITY_NOT_FOUND. Upload replaces the previous call recording. 429 LARGE_BODY_BACKEND_BUSY means large-body admission is busy.

Errors: 400 invalid parameters; 401 key or token; 403 scope, Bitrix24 permissions or READONLY writes; 422 upstream refusal; 429 limits; 502 unavailable Bitrix24 account; 503 timeout or freeze.

## Request parameters

| Field | Type | Required | Meaning |
|---|---|---|---|
| callId | string | yes | ID of a finished call from [register](/docs/telephony/crm/register). |
| fileName | string | yes for inline | Filename ending in .mp3 or .wav; for URL mode defaults to the URL filename. |
| fileContent | string | inline mode | Base64 audio, at most 2 MiB decoded; mutually exclusive with recordUrl. |
| recordUrl | string | URL mode | Public HTTPS URL without credentials or private addresses; mutually exclusive with fileContent. |

## Response fields

| Field | Meaning |
|---|---|
| success | Boolean result |
| data | Result described above; credentials are omitted |

## Examples

### cURL Personal key

```bash
curl -X POST 'https://vibecode.bitrix24.com/v1/calls/YOUR_COMPLETED_CALL_ID/record' \
  -H 'X-Api-Key: FAKE_VIBE_API_KEY' \
  -H 'Content-Type: application/json' \
  --data '{"fileName":"record.wav","fileContent":"UklGRjQAAABXQVZFZm10IBAAAAABAAEAQB8AAIA+AAACABAAZGF0YRAAAAAAAAAAAAAAAAAAAAAAAAAA"}'
```

### cURL OAuth

```bash
curl -X POST 'https://vibecode.bitrix24.com/v1/calls/YOUR_COMPLETED_CALL_ID/record' \
  -H 'X-Api-Key: FAKE_VIBE_API_KEY' \
  -H 'Authorization: Bearer FAKE_APP_SESSION_TOKEN' \
  -H 'Content-Type: application/json' \
  --data '{"fileName":"record.wav","fileContent":"UklGRjQAAABXQVZFZm10IBAAAAABAAEAQB8AAIA+AAACABAAZGF0YRAAAAAAAAAAAAAAAAAAAAAAAAAA"}'
```

### JavaScript Personal key

```javascript
const response = await fetch('https://vibecode.bitrix24.com/v1/calls/YOUR_COMPLETED_CALL_ID/record', {
  method: 'POST',
  headers: {"X-Api-Key": "FAKE_VIBE_API_KEY", "Content-Type": "application/json"},
  body: JSON.stringify({"fileName": "record.wav", "fileContent": "UklGRjQAAABXQVZFZm10IBAAAAABAAEAQB8AAIA+AAACABAAZGF0YRAAAAAAAAAAAAAAAAAAAAAAAAAA"}),
});
console.log(await response.json());
```

### JavaScript OAuth

```javascript
const response = await fetch('https://vibecode.bitrix24.com/v1/calls/YOUR_COMPLETED_CALL_ID/record', {
  method: 'POST',
  headers: {"X-Api-Key": "FAKE_VIBE_API_KEY", "Authorization": "Bearer FAKE_APP_SESSION_TOKEN", "Content-Type": "application/json"},
  body: JSON.stringify({"fileName": "record.wav", "fileContent": "UklGRjQAAABXQVZFZm10IBAAAAABAAEAQB8AAIA+AAACABAAZGF0YRAAAAAAAAAAAAAAAAAAAAAAAAAA"}),
});
console.log(await response.json());
```

Observed on the test account 2026-10-02; the example shows nonsecret response fields.

```json
{
  "success": true,
  "data": {
    "fileId": 10209
  }
}
```

## Errors

| HTTP | Code |
|---|---|
| 400 | INVALID_PARAMS / MISSING_REQUIRED_FIELDS / READONLY_FIELD |
| 401 | MISSING_API_KEY / INVALID_API_KEY / TOKEN_MISSING |
| 403 | SCOPE_DENIED / WRITE_BLOCKED_READONLY_KEY / BITRIX_ACCESS_DENIED |
| 422 | BITRIX_ERROR |
| 429 | RATE_LIMITED |
| 502 | BITRIX_UNAVAILABLE |
| 503 | BITRIX_TIMEOUT |
| 404 | ENTITY_NOT_FOUND |
| 413 | PAYLOAD_TOO_LARGE |
| 429 | LARGE_BODY_BACKEND_BUSY |

[Error reference](/docs/errors)

403 when the key has no telephony scope:

```json
{
  "success": false,
  "error": {
    "code": "SCOPE_DENIED",
    "message": "This endpoint requires 'telephony' scope"
  }
}
```

## See also

[Calls](/docs/calls)

[SIP](/docs/voximplant-sip)
