Call Clearance
Vapi guide

How to check Do Not Call before Vapi dials

A Vapi agent only runs once the call is connected, so a compliance tool inside the agent fires after the phone has already rung. The check has to sit in front of the dial request. Here is how.

Why not a tool inside the agent?

By the time a Vapi agent can call a function, the number has been dialed and the person has picked up. If they were on the Do Not Call list, the violation already happened. The check has to happen before the call is created, which means wherever your code or workflow creates calls today, it sends the request through the check first.

The five-minute version

  1. Create a free Call Clearance account (no card) at api.callclearance.com/signup.
  2. On the dashboard, under Connect your voice AI, pick Vapi and paste your Vapi API key. It is stored encrypted and used only to place calls you send.
  3. Pick the phone number calls go out from and the assistant. Add each business you call for as a client; consent is kept per client, opt-outs apply to all of them.
  4. Wherever you create calls today (a script, Make, Zapier, GoHighLevel, your CRM), send them to POST https://api.callclearance.com/v1/call with the client ID and the number instead of calling Vapi directly. On allow, Call Clearance places the call through your own Vapi account. On block, nothing is dialed and you get the reason.
  5. Point Vapi's end-of-call-report server URL at your Call Clearance call hook. When a person says "stop calling me" on a call, the number is blocked across every client within seconds.
  6. Test it: record an opt-out for your own phone, then send a call to it. You get placed: false with the reason, and nothing rings.

The request

POST https://api.callclearance.com/v1/call
Authorization: Bearer cc_live_...
Content-Type: application/json

{ "client_id": "cl_8f2a", "to": "+14105550123" }

The answer is placed: true with the Vapi call id, or placed: false with reason (for example opted_out, national_dnc, no_consent, outside_calling_hours with a retry time) and an evidence_id for the Call Record either way. If you would rather keep placing calls yourself, use POST /v1/check with the same body and only dial on decision: "allow".

What gets checked

In order, stopping at the first problem: opt-outs from any channel, known TCPA litigators, the National Do Not Call Registry under the client's own FTC registration, state do-not-call lists, consent on file for that number and client, and calling hours in the called party's local time including the stricter rules in 25 states. Opt-outs, consent and hours run from the first call; the litigator, national and state checks run only once their data is set up, and say "skipped" until then (what runs today). Every check writes a Call Record: the answer, every check with its result and source, the consent relied on in the person's own words, and a seal that is published daily and timestamped on Bitcoin. A check that could not run says "skipped" with the reason; it never says "passed".

Fail closed

If the check errors, times out, or answers 402 (no credit), do not call. With a connected Vapi account that happens by itself: if the check does not finish, the call is not placed. From your own code, treat anything other than an explicit allow as a no.

For agencies. Each client is its own business on your account with its own consent and FTC registration. A "stop" to any client blocks the number for all of them, which is what the FCC's revocation rule expects. White-label Call Records on the Agency plan and up.

Check your first number in five minutes.

Free plan, no card. Opt-outs, consent and calling hours run from the first call; the national list switches on when a business's FTC registration is on file.