GET /sipflow, or send a share key k for a stored trace. GET /sipflow/export takes the same fields as query parameters.by) in its territory. Office Manager and the other domain-tier scopes see calls that have their own domain as a party domain. User-tier scopes see only calls where their own user is the originating or terminating party. A call outside your scope answers the same 404 as a call that does not exist. A scope without the call-trace privilege gets 403; by default Office Manager, Reseller, Super User, and Super User Read Only hold it. Every call ID you send must match a CDR in your scope inside the window; the rest are ignored, and if none remain the answer is 404. A share key needs no token and exports read-only; with a token, the stored call must be in your scope.export_format picks:image (the default): the SVG ladder diagram, image/svg+xml, sent inlinecsv: the event rows with a header row, text/csv, as an attachmentbase64: base64 of the PHP-serialized raw rows, text/plain. The cluster's servers use this format with each other; integrations should use csv. Times in CSV and base64 rows, and in the call_trace_text block headers, are YYYY-MM-DD_HH:MM:SS in UTC (an underscore, no offset); the millisecond Unix time is the UnixTsm column.GET /sipflow.Authorization: Bearer ********************image/svg+xml; export_format=csv answers text/csv and export_format=base64 answers text/plain, as the description lists.curl --location 'https://awqacore01.crexendocloud.com/ns-api/v2/sipflow/export' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data-raw '{
"start_time": "2026-09-01T14:30:00+00:00",
"end_time": "2026-09-01T14:34:10+00:00",
"callids": "0f1e2d3c4b5a69788796a5b4c3d2e1f0@192.0.2.10",
"export_format": "csv"
}'<svg width="100%" xmlns="http://www.w3.org/2000/svg"></svg>