> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ondial.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List campaign contacts

> Paginated contacts for a campaign — not campaign CRUD.

<Note>
  There is **no** `POST /api/v1/campaigns`. Create and start campaigns in the dashboard. Use List campaigns and Get campaign to look up `campaignId` and templates.
</Note>


## OpenAPI

````yaml /openapi.json get /api/v1/campaigns/{campaignId}/contacts
openapi: 3.0.3
info:
  title: Ondial Public API
  version: 1.0.0
  description: >-
    Tenant API-key surface for lead ingest, contacts (including dial
    conversation + analysis), events, inbound agents, company profiles, and
    knowledge-base documents.


    **Campaign definition is UI-only** — create and start an API-ingest campaign
    in the dashboard, then push leads here.


    **Auth:** `Authorization: Bearer ond_live_…` or `ond_test_…` (or
    `X-API-Key`). Keys are requested in **API Access** with a friendly **key
    name**, then approved by Super Admin (not self-serve). Tenants can rename
    keys later without rotating the secret.


    **Scopes:** Company and knowledge-base routes require opt-in scopes
    (`companies:read`, `companies:write`, `knowledge:read`, `knowledge:write`)
    granted at key approval. Missing scope → `403 forbidden`.


    **Sandbox** keys never place PSTN dials or live WhatsApp/email and do not
    burn credits (KB upload skips debit).


    **Security:** Company responses never include SMTP/WhatsApp credentials. KB
    v1 is metadata-only — no file download.


    **Kill switch:** Super Admin can disable all `/api/v1/*` (`503` /
    `api_globally_disabled`) without stopping UI CSV campaigns.


    **Compliance:** Call channel requires `consent.outboundCall: true` and phone
    not on tenant/platform DNC.
servers:
  - url: https://dashboard.ondial.ai
    description: Production
  - url: http://localhost:3001
    description: Local
security:
  - BearerAuth: []
tags:
  - name: Core
    description: Auth check and lead ingest
  - name: Contacts
    description: Status, dials/conversation/analysis, cancel, delete, follow-ups, list
  - name: Events
    description: ERP event bus slice — eventType → campaign
  - name: Outbound
    description: >-
      Read-only campaign lookup for API / Custom CRM. Create and start campaigns
      in the dashboard.
  - name: Inbound agents
    description: Configure inbound agents; list/buy pool numbers; read credits
  - name: Companies
    description: >-
      Company profile CRUD (requires companies:read / companies:write scopes).
      Never returns SMTP or WhatsApp credentials.
  - name: Knowledge bases
    description: >-
      Knowledge document upload/list/delete (requires knowledge:read /
      knowledge:write scopes). Metadata only — no file download via API.
paths:
  /api/v1/campaigns/{campaignId}/contacts:
    get:
      tags:
        - Outbound
      summary: List campaign contacts
      description: >-
        Paginated contact list for a campaign you own. This is **not** campaign
        CRUD — campaigns are created in the UI.
      operationId: listCampaignContacts
      parameters:
        - name: campaignId
          in: path
          required: true
          schema:
            type: string
        - in: query
          name: cursor
          schema:
            type: string
        - name: limit
          in: query
          schema:
            type: integer
            default: 50
        - name: status
          in: query
          schema:
            type: string
        - name: source
          in: query
          schema:
            type: string
            example: api
      responses:
        '200':
          description: Page of contacts
          content:
            application/json:
              schema:
                type: object
                properties:
                  contacts:
                    type: array
                    items:
                      $ref: '#/components/schemas/ContactStatus'
                  nextCursor:
                    type: string
                    nullable: true
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
components:
  schemas:
    ContactStatus:
      type: object
      properties:
        contactId:
          type: string
        campaignId:
          type: string
        phone:
          type: string
        status:
          type: string
        callReceiveStatus:
          type: integer
        whatsappStatus:
          type: string
        whatsappQueueStatus:
          type: string
        emailStatus:
          type: string
        emailScheduledAt:
          type: string
          format: date-time
          nullable: true
        whatsappScheduledAt:
          type: string
          format: date-time
          nullable: true
        emailTemplateId:
          type: string
          nullable: true
        emailProfileId:
          type: string
          nullable: true
        whatsappTemplateId:
          type: string
          nullable: true
        whatsappProfileId:
          type: string
          nullable: true
        isFollowUp:
          type: boolean
        scheduledAt:
          type: string
          format: date-time
        requestedChannels:
          type: array
          items:
            type: string
        source:
          type: string
        sandbox:
          type: boolean
        deletedAt:
          type: string
          format: date-time
          nullable: true
        lastCall:
          $ref: '#/components/schemas/LastCallPointer'
    LastCallPointer:
      type: object
      nullable: true
      properties:
        callId:
          type: string
        status:
          type: string
        hasAnalysis:
          type: boolean
        startedAt:
          type: string
          format: date-time
          nullable: true
    ErrorBody:
      type: object
      properties:
        error:
          type: string
        reasonCode:
          type: string
        missing:
          type: array
          items:
            type: string
  responses:
    Unauthorized:
      description: Missing, invalid, or inactive API key
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error: Invalid or inactive API key
            reasonCode: unauthorized
    NotFound:
      description: Not found or not owned
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          example:
            error: Not found
            reasonCode: not_found
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: ond_live | ond_test
      description: >-
        Paste only your API key (`ond_live_…` or `ond_test_…`). Do not type the
        word Bearer — the playground adds it.

````