Base URL
Authentication
All authenticated endpoints require an API key:tc_... value); only a hash and the tc_xxxxxxxx prefix are stored.
Platform credential
The two bootstrap endpoints —POST /v1/projects and POST /v1/api-keys — sit before any API key exists, so they are gated by a single platform credential instead:
PLATFORM_API_KEY setting. The gate fails closed: if PLATFORM_API_KEY is unset, every bootstrap call is rejected. This identifies a privileged caller (the platform builder), not a user — everything after bootstrap uses project-scoped tc_... keys.
Roles
Resource Lifecycle
The typical setup order — each resource is scoped to the project of the API key that creates it: Behaviour is checked with the same key:POST /v1/eval-scenarios saves a test and POST /v1/eval-runs executes it on a worker, answering 202 with a batch id rather than a verdict. See Evals.
What is not here
Endpoints under/webhooks/ are absent on purpose. Twilio and Meta call those — you configure the URL and never request it yourself — so they are part of the platform’s plumbing rather than its API. Your own webhooks work the other way round: TurnCall calls you. Subscribe with POST /v1/webhooks and see Server events for the envelope and its signature.
Response Format
Success
Error
code is a stable machine-readable string; error is the human-readable message. details and request_id are included when available.