.png)
Vapi Integration Guide
Integrate Vapi voice assistants with enterprise applications through REST APIs, server events, and real-time tool endpoints.
Vapi integration options at a glance
Vapi provides REST APIs for managing Assistants, Calls, Phone Numbers, Tools, Squads, and related configurations. It also supports server URLs and webhook-style events for call status changes, transcripts, end-of-call reports, and tool requests, although event coverage varies by use case. Vapi private API keys authenticate server-side requests, while public keys support selected client-side operations. File and knowledge-base capabilities are available in selected configurations, with current limits and formats requiring confirmation. Martini can consume the REST API, receive validated Vapi events, expose tool endpoints, and orchestrate transformations, business rules, retries, and downstream updates.
Common Vapi integration patterns
Common Vapi data objects used in integrations
Authentication and security considerations
Bearer-token authentication
Vapi server-side API requests use private API keys as bearer tokens. Martini can store the key in Secrets Management and add it to outbound REST requests without hard-coding it in workflows.
Key separation
Vapi public keys support selected client-side operations, while private keys are intended for server-side and administrative access. Private keys should not be exposed in browser code or logs.
Webhook validation
Incoming Vapi events should be authenticated or validated using the security options configured for the project. Martini workflows should reject malformed or unexpected payloads and record safe diagnostic information.
Data protection
Calls, transcripts, and recordings may contain sensitive information. Apply least privilege, data minimization, retention controls, redaction, encryption, and regional processing policies appropriate to the use case.
Operational considerations for Vapi integrations
Latency
Tool calls run during an active conversation. Keep synchronous workflows focused and avoid slow downstream operations that could cause timeouts or degrade the caller experience.
Events and idempotency
Vapi events may arrive asynchronously, rapidly, more than once, or out of order. Persist a stable event or Call identifier and apply state-transition rules before creating downstream records.
Pagination and rate limits
List endpoints may be paginated, and current Vapi rate limits should be confirmed for each account and endpoint. Scheduled workflows should use throttling, exponential backoff, and appropriate retries.
Schema changes
Assistant, Call, Tool, and server-event payloads can evolve. Map required fields, preserve useful unknown fields for diagnostics, and test against representative event variants.
Scheduling and sensitive content
Normalize time zones for appointment workflows and validate daylight-saving transitions. Define retention and access policies before storing transcripts or recordings.
Why use Martini instead of scripts or point-to-point integrations?
Centralized orchestration
Martini separates Vapi voice interactions from CRM, service, scheduling, commerce, database, and messaging operations in maintainable workflows.
Reusable APIs and workflows
Instead of duplicating integration logic in individual Tools or scripts, Martini can expose reusable APIs, apply shared validation, and provide a controlled façade over downstream systems.
Reliable processing
Martini provides a place to implement mapping, business rules, idempotency, retries, error handling, logging, and asynchronous post-call processing.
Developer control
Martini combines a low-code workflow experience with the flexibility to use custom logic when Vapi payloads or enterprise requirements need more than point-to-point configuration.