Skip to content
FirstSIDocs

3CX phone system

Connect the 3CX phone system read-only to see where an extension's calls go, monitor the trunks and the backup, and pre-diagnose telephony tickets.

FirstSI reads the 3CX phone system through its configuration API, read-only. Without opening the 3CX console, you can see where an extension's calls go depending on its status, what happens to an incoming number outside office hours, whether the carrier trunks are online and whether the backup has run. Pre-diagnostics uses it for tickets of the "telephony" type.

What FirstSI can read

SubjectContent
SystemVersion, registered extensions out of the total, phone system services (stopped or not), last backup
Carrier trunksEach trunk, online or not, number of simultaneous calls
ExtensionsPhone registered or not, current status (Available, Away, Out of office…), and for each status where calls go on no answer, when busy or when the phone is not registered
Incoming numbersDestination during office hours, outside them and on public holidays
Call queuesAgents of each queue, statistics over a period (calls received, answered)
Call logCalls received or made by an extension, with the route of each call: inbound rule, forwarding, voicemail, transfer, who hung up
Audit logWho changed the configuration, when, from which address and on which object
OtherDeclared public holidays, event log, addresses blocked by the anti-hacking protection

On the 3CX side: create the API client

In the 3CX management console, Integrations → API → Add:

  1. Enter a Client ID (a free number in the dial plan, usually 4 digits). Note it exactly as entered.
  2. Tick 3CX Configuration API Access.
  3. Choose the department and the role. To read every extension, the client must see all departments. Reports (call log, queue statistics, audit log) require the System Owner role; with a lower role, the configuration can be read but reports answer "access denied".
  4. Save, then copy the API key shown. It is not shown again.

On the FirstSI side: declare the connector

Connectors → New connector, type REST API:

FieldValue
Namea name containing "3CX": this is how pre-diagnostics recognises it
Base addressthe address of the 3CX console, for example https://pbx.example.com
AuthenticationApplication identity → token (OAuth client_credentials)
Token address (https)https://pbx.example.com/connect/token
Application ID (client_id)the Client ID created above
Secretthe API key created above
Executing agentan agent that can reach the phone system; none if the phone system is published on the Internet

Queries call /xapi/v1/…. A list returns at most 100 rows per call, and the call log is read over a short period: 7 days at most.

Useful queries

Write them like any REST query (see Connectors), then test and approve them. A good starting set:

The queries of a 3CX connector, all approved, including three probes (demo data).
The queries of a 3CX connector, all approved, including three probes (demo data).
QueryParametersUsed for
System statusnoneRegistered extensions, services, version
Carrier trunksnoneTrunks that are offline
BackupsnoneDate of the last successful backup
Extension detailsextension numberRegistration, current status
Extension forwardingextension numberWhere calls go for each status
Destination of a numberthe last digits of the numberOpen, closed, public holidays
Queues and agentsnone or queue numberWho answers in each queue
Calls received by an extensionextension, start, endLog with the route of each call
Extension statisticsextension, start, endReceived calls answered or not, outgoing calls, durations. Goes through the report of the extension's 3CX group: the 3CX per-extension report may answer "error 500"
Queue statisticsstart, endCalls received and answered per queue
Configuration changesobject (optional)Who changed a forwarding rule or office hours

Give each query a precise description: the AI Assistant reads it to pick the right one. Call logs contain phone numbers: tick Sensitive data (administrators only).

ProbeNormal ifSeverity, frequency
Carrier trunks offlineno rowscritical, every 15 min
Phone system services stoppedno rowscritical, every 15 min
Last backup less than 2 days oldat least one rowwarning, every 6 h

In pre-diagnostics

The telephony type runs three checks when a 3CX connector exists:

CheckWhat it says
Phone system statusCarrier trunks offline, stopped services, share of registered extensions, old backup
3CX extension and forwardingThe extension quoted in the ticket, or failing that the requester's one, found from their email address in the directory: phone registered, current status and where its calls go in that status; calls received over 48 h, answered or not, and the route of the last missed call
Incoming numberThe quoted number: its destination when open, closed and on public holidays, then the status and forwarding of the destination extension; duplicate rules are flagged

A "my phone no longer rings" ticket thus arrives with the most common answer: the extension was left in Away status, and its calls are going to voicemail.

Frequently asked questions

The token is refused (401). The Client ID or the key does not match. Copy the ID exactly as shown in Integrations → API, regenerate the key on the 3CX side if needed and enter it again in the connector.

The configuration can be read, but reports answer 403. The API client does not have the System Owner role.

Queries fail from time to time with 401. Another tool uses the same API client and cancels FirstSI's token. Give it its own client.

The call log answers "error 500". The period is too long or the extension does not exist: narrow it down to a few days and check the number.

Source: · FirstSI Docs · updated 2026-10-10