LiveKit Telephony
by LiveKit Incorporated HTTP API in Phone calling & voice transport
LiveKit Incorporated · livekit.com since 2000 · status page · who's behind it
LiveKit Telephony connects phone calls to LiveKit rooms as SIP participants. On LiveKit Cloud it covers SIP trunks to outside carriers, US inbound phone numbers, dispatch rules and transfers, managed through a Twirp API, server SDKs and the lk CLI.
Good for Teams that already run voice agents on LiveKit and want phone calls to arrive in the same rooms, bringing their own carrier for outbound and international calls.
Is this your product? Claim this listing or verify it
Assessment. Signed tokens separate the right to dial (sip.call) from the right to manage trunks (sip.admin), and per-minute prices are public with a free plan that needs no card. LiveKit's own phone numbers are US only and inbound only, so outbound calls need a third-party SIP trunk, and no 429 or retry guidance was found.
Facts
- Transport
- HTTP
- Auth
- API key
- Pricing
- Freemium · $1 / mo
- x402
- No
- Licence
- Proprietary cloud service under LiveKit's Terms of Service. The SIP service (livekit/sip), the protocol definitions, the CLI and the server SDKs are Apache 2.0
- Packages
npmlivekit-server-sdkpypilivekit-apigogithub.com/livekit/server-sdk-go/v2- Source
- github.com/livekit/sip
- llms.txt
- published
- Last release
- GitHub stars
- 480
- npm / week
- 2.9M
- PyPI / week
- 1.7M
- Countries with numbers
- United States only for LiveKit Phone Numbers (local and toll-free, inbound only). Other countries through a third-party SIP trunk
- SIP
- Inbound and outbound trunks over UDP, TCP or TLS with SRTP. No SIP REGISTER, SIPREC or video. Tested with Twilio, Telnyx, Exotel, Plivo, Wavix, Sinch and didlogic
- Media streams
- Call audio joins a LiveKit room as a participant track over WebRTC. Connectors bridge Twilio calls over websockets and WhatsApp Business voice calls
- Voice AI layer
- LiveKit Agents joins the same room. Agent session minutes on LiveKit Cloud are $0.01 a minute past the plan allowance, with models billed separately
- Recording
- Through the separate Egress service, written to the customer's own S3, GCS or Azure bucket. Audio-only transcode from $0.005 a minute past the allowance on Ship
- Transfer
TransferSIPParticipantsends SIP REFER for a cold transfer. Agent-assisted warm transfer runs through an Agents task marked beta, in Python only- Free tier
- Build plan, $0, no card. 1 US local number, 50 inbound minutes and 1,000 third-party SIP minutes a month, as a hard cap
- Rate limits
- 1,000 Server API requests a minute per project. 100 local numbers on Ship and 300 on Scale. Outbound ringing timeout capped at 80 seconds
- SLA
- 99.99% uptime listed for every plan as an objective. The terms give no credits outside a written Enterprise agreement
- Data retention
- Telemetry up to 60 days by default. Call detail records kept as long as law or carrier rules require, with no fixed period stated
- Regions
- Global SIP endpoint by default. Region-pinned endpoints for aus, eu, india, japan, sa, uk and us. The pricing page lists region pinning for Scale and Enterprise
- MCP server
- Docs only, at https://docs.livekit.io/mcp. No MCP server for call control was found
- Capabilities
- voice.calls voice.sip voice.numbers voice.transfer voice.streaming
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Token grants separate
sip.call(dial and transfer) fromsip.admin(trunks, dispatch rules, numbers), with a lifetime the issuer sets - Free Build plan with no card has one US local number, 50 inbound minutes and 1,000 third-party SIP minutes a month
- Per-minute and per-number prices are public, also as Markdown at livekit.com/pricing.md
- The SIP service is open source under Apache 2.0, with 12 tagged releases from 10 July to 5 October 2026
- Status page lists SIP per region and US Phone Numbers as separate components
Weaknesses
- LiveKit Phone Numbers are US only and inbound only, and
TransferSIPParticipantdoes not work on them yet - Outbound calls need a trunk from another carrier, billed by that carrier on top of LiveKit's SIP minutes
- No 429, Retry-After or idempotency guidance was found for the SIP API, so a retried
CreateSIPParticipantmay dial twice - The 99.99% uptime on the pricing page is an objective only, with no credits outside a written Enterprise agreement
- Sign-up and
lk cloud authneed a person in a browser, and no machine payment protocol was found - The terms bar benchmarking for competitive purposes without written consent
Before you call it notes for agents
- Ask the operator for a short-lived token with only the
sip.callgrant to dial or transfer. Trunk, dispatch rule and number changes needsip.admin - Use a third-party outbound trunk for outbound calls. LiveKit Phone Numbers only receive calls
- Set
wait_until_answeredonCreateSIPParticipantand read the SIP status onSipCallErrorbefore retrying. Voicemail answers with 200 OK - Send every request as a JSON POST to
/twirp/livekit.SIP/<Method>or/twirp/livekit.PhoneNumberService/<Method>on the project's own host, with{}for an empty body - A released number is billed for the whole month, and the free Build allowance is a hard cap after which requests fail
Who's behind it provenance 81/100
- Legal entity namedLiveKit Incorporated20/20
- Domain agelivekit.com, registered 2000-02-24 (26 years)15/15
- Endpoint on the vendor's domain is not on livekit.com0/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 1 clause that costs points7.1/10
- Privacy policyread, states 6 of the 8 things a reader expects8.5/10
- Status pagestatus.livekit.io10/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service gives no date, states 6 of 7, 3 to know
TL;DR Gives no date. States 6 of the 7 things a reader expects. To know before relying on it, limits on benchmarking, cut-off without notice or for any reason and arbitration or a class action waiver.
Restricts benchmarking or competitive usecosts points
to build a competing product or service, or benchmark for competitive purposes, without LiveKit's
A clause against publishing test results or using the service to build something that competes.
Says access can be ended without notice or for any reason
LiveKit may terminate the Services under the Build subscription plan at any time.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
Any dispute arising out of or relating to this Agreement will be resolved by final and binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules before one arbitrator in Santa Clara County, California, in English.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
This Agreement shall be governed by the laws of the State of California without regard to its conflict of laws provisions.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the greater of $1,000 and the fees paid in the 12 months before the claim
…(A) LIVEKIT'S AND CUSTOMER'S TOTAL LIABILITY FOR DAMAGES ARISING OUT OF OR RELATING TO THIS AGREEMENT IS LIMITED TO THE GREATER OF THE FEES PAID AND PAYABLE BY CUSTOMER UNDER THIS AGREEMENT DURING THE 12-MONTH PERIOD BEFORE THE EVENT GIVING RISE TO LIABILITY AND ONE THOUSAND DOLLARS ($1,000);
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
LiveKit may monitor and block use of the Services if it detects violations and may suspend or reclaim numbers or resources where required.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 10 days of notice before a change
In the event of a claim or threatened claim under this Section by a third party, LiveKit may, at its sole option, (i) revise the Services so that they are no longer infringing, (ii) obtain the right for Customer to continue using the Services, or (iii) terminate this Agreement upon 10 days' notice.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Customer may not use the Services if Customer is a person barred from receiving the Services under the laws of the United States or other countries, including the country in which Customer is resident or from which Customer uses the Services.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Any availability or uptime targets published on LiveKit's pricing or documentation pages are service objectives only and do not entitle Customer to service credits, refunds, or other remedies unless expressly set forth in a separate written agreement with LiveKit for Enterprise customers.
Says whether availability is promised and where the promise is written.
Use of the Services for a use case classed as high-risk under the EU AI Act needs LiveKit's prior written consent.
as high-risk under the AI Act, Customer must first obtain LiveKit's prior written consent and
Noted by a second reader on 2026-10-08.
Third-party providers reached through the Services may train on data under their own terms, except providers used through LiveKit Inference.
Provider through the Services. Third-Party Service Providers may train on data as set forth in their
Noted by a second reader on 2026-10-08.
The customer must export its data before termination, and LiveKit is not responsible for storing customer data afterwards.
After termination, LiveKit is not responsible for storing any Customer Data.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 6,708 words
Privacy policy gives no date, states 6 of 8
TL;DR Gives no date. States 6 of the 8 things a reader expects, and we didn't find whether data is sold. The rules found no clause to flag.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This privacy policy (the “Privacy Policy”) explains how we collect, use, and disclose information from users of our Services (“Users”).
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of twelve months
We retain Voice Samples for up to twelve (12) months;
Says when data sent to the service is deleted.
Says who else receives the data
This Privacy Policy does not apply to the extent we process information in the role of a processor or service provider on behalf of our customers (for example, your company when you use our tools at https://cloud.livekit.io/ or a third-party platform that uses our technology to power their AI agents).
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Not found in the text.
A plain statement either way.
Says what rights people have over their data
This means we have a legitimate interest that does not outweigh your privacy rights.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@livekit.io
If you learn that a child has provided us with Personal Data in violation of this Privacy Policy, then you may alert us at privacy@livekit.io.
An address or officer to send a request to.
Says where data is transferred or stored Relies on the Data Privacy Framework
Data Privacy Framework, the UK Extension to the EU-U.S.
The countries data goes to and the safeguard used.
The policy covers LiveKit's website and does not apply where LiveKit processes data as a processor for customers, such as through cloud.livekit.io.
This Privacy Policy does not apply to the extent we process information in the role of a processor or service provider on behalf of our customers
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 3,558 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
livekit.io answers 308 to livekit.com. Docs stay at docs.livekit.io, the dashboard at cloud.livekit.io and the status page at status.livekit.io.
The terms link is the Terms of Service Agreement for the Build, Ship and Scale plans of LiveKit Cloud, last updated 6 October 2026, between the customer and LiveKit Incorporated of San Francisco. Enterprise customers sign a separate agreement we did not see.
The privacy policy was last updated 6 October 2026. A Data Processing Addendum of the same date is at https://livekit.com/legal/data-processing-addendum and the sub-processor list (10 September 2026) at https://livekit.com/legal/sub-processors.
Each project's API answers on its own host under livekit.cloud and SIP at <subdomain>.sip.livekit.cloud, a second domain. LiveKit's disclosure policy lists *.livekit.cloud among its own systems.
livekit.com/.well-known/security.txt gives security@livekit.io, a PGP key and the policy at https://livekit.com/security/policy. It has no Expires field. livekit.com/security.txt returns 404.
No changelog page for LiveKit Cloud was found (livekit.com/changelog returns 404). Dated changes are in the livekit/sip release tags and CHANGELOG.md in livekit/protocol.
RDAP for livekit.com gives a registration date of 2000-02-24, long before the company existed. RDAP for livekit.io returned no events.
livekit/sip tagged v1.18.0 on 5 October 2026 and livekit-cli tagged v2.19.0 on 8 October 2026.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-09 09:03 UTC
- Vendor status page all systems normal, All Systems Operational · 1 minute ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/livekit-telephony.json
Notable
- LiveKit Phone Numbers are US only and inbound only, and forwarding with
TransferSIPParticipantis not yet supported on them source - The SIP API has 17 RPCs and the Phone Numbers API 6, defined as protobuf in livekit/protocol and called as JSON over Twirp source
- Outbound trunk settings can be stored or passed inline on each
CreateSIPParticipantcall source - Answering machine detection classifies an outbound call as human, IVR, voicemail, unavailable or uncertain inside the Agents framework source
- The terms forbid emergency calls (911, 112) and benchmarking for competitive purposes without written consent source
- The server SDK download counts cover every LiveKit server API, of which SIP is one part
- LiveKit Agents, the framework that usually answers these calls, is a separate product and is not graded here
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 13.0 | |
| Graded as a hosted service, LiveKit Cloud. Statuspage at status.livekit.io with SIP per region, Global SIP and US Phone Numbers as components (20). In the 90 days to 8 October the SIP incidents were all marked minor or none. Failed SIP transfers in US East ran about 72 minutes on 17 August, one-way audio on LiveKit Phone Numbers about 42 minutes on 2 September, and raised API latency on SIP twice on 15 September for about 70 minutes each. The two incidents marked major (2 and 15 September) hit the dashboard, analytics and billing API, not calls (20). The Server API limit is 1,000 requests a minute per project, with number limits of 100 on Ship and 300 on Scale (15). No 429, Retry-After, backoff or idempotency guidance was found for the SIP API (0). The pricing page lists 99.99% uptime for every plan, and section 2.5 of the terms calls such figures objectives with no credits outside a written Enterprise agreement, so no SLA is counted (0). The SIP API carries no beta label, though the warm transfer task in the Agents framework is marked beta, in Python only (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 13.7 | |
The contract is protobuf in livekit/protocol (17 SIP RPCs, 6 phone number RPCs), called as JSON over Twirp. No OpenAPI document was found, and we counted the protobuf files as the similar spec (25). llms.txt per docs section and every page as Markdown (10). Reference tables give each parameter's purpose, and the guides say when to use an inline trunk or a stored one (15 of 20). Typed fields with enums for transport, encryption and number status and required fields marked, with metadata as a free string (13 of 15). Examples in six languages and the CLI, a call outcome table and a troubleshooting guide by SIP code. No full list of Twirp errors was found, and the reference still shows TransferSIPParticipant returning an empty message where the protocol changelog says it now returns a response object (11 of 15). The Twirp path has no version. Changes are dated in livekit/sip release tags and the protocol CHANGELOG.md, with no cloud changelog page found (10 of 15). | |||
| Agent ergonomics | 13%16.2 | 10.7 | |
List calls take a limit and ID, number or status filters, with no field selection (15 of 25). A Pagination type with after_id and limit on the SIP list calls (18 of 20). wait_until_answered returns a SipCallError with the carrier's SIP status code, and the docs map codes to outcomes. Twirp errors are named only in passing (15 of 20). No idempotency key was found, so a retried CreateSIPParticipant can place a second call (3 of 20). A call needs a trunk, a number and a room name, and SIP clients ship in Go, JavaScript, Python, Ruby, Kotlin and Rust plus the lk CLI (15). | |||
| Security & auth | 14%17.5 | 10.7 | |
A project key and secret sign JWTs whose sip grant is admin or call, with a lifetime the signer sets. Keys rotate in the dashboard. The key pair itself can mint any grant, so scoping depends on the operator handing an agent a token and not the secret (25 of 30). call without admin is a least-privilege mode for dialling, inbound trunks can be limited by number, IP range or credentials, and no read-only grant or confirmation step for dialling or renting numbers was found (8 of 20). Calls carry untrusted caller speech, and no prompt-injection guidance was found in the telephony docs (5 of 15). The security overview says project configuration changes are logged, with export to a SIEM still on the roadmap, and the dashboard shows call logs (8 of 15). security.txt with a disclosure policy and safe harbour, a Hall of Fame with no cash bounty stated, SOC 2 Type II, six-monthly penetration tests, ISO 27001 in progress, and no published advisories on livekit/sip, livekit/livekit or livekit/livekit-cli (15 of 20). | |||
| Payments & pricing | 10%12.5 | 5.0 | |
No x402, MPP or L402 found (0). Per-minute and per-number prices are public without a login, also as Markdown (20). The Build plan is free with no card and includes a US local number, 50 inbound minutes and 1,000 third-party SIP minutes a month (20). An account is created in a browser and lk cloud auth opens one, and no programmatic sign-up or key API was found (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.9 | |
| livekit-cli v2.19.0 was tagged on 8 October 2026 and livekit/sip v1.18.0 on 5 October (30). livekit/sip has 12 tags from v1.7.0 on 10 July to v1.18.0 (20). Of the 30 newest open issues and pull requests on livekit/sip, 22 have at least one comment. We read the counts and not who replied. Paid plans add email support and there is a community Slack (17 of 25). Current server SDKs, with livekit-server-sdk 2.19.1 on npm and livekit-api 1.2.1 on PyPI from 27 August 2026 (15). livekit/sip runs unit tests with the race detector and integration tests in CI and has Renovate configured. We did not see the latest run's result (8 of 10). | |||
| Transparency & trusteditorial 69, provenance 81 | 7%8.8 | 6.6 | |
| The SIP service, protocol, CLI and SDKs are Apache 2.0, and the security page says the same code runs on LiveKit Cloud. The cloud control plane and LiveKit Phone Numbers are closed, under clear terms (25 of 30). Terms, privacy policy and DPA all dated 6 October 2026 agree. The DPA lists retention by data category, user content is deleted after delivery unless recording is on, telemetry is kept up to 60 days and backups up to 30. Call detail records have no fixed period, and the sub-processor list names no telephony carrier for LiveKit Phone Numbers (22 of 30). No deprecation policy was found. Deprecated fields are flagged in the reference without dates, and the terms give 30 days' notice of changes to the agreement (5 of 20). The sub-processor list gives each entity, its activity and its country, all in the United States, with a way to subscribe to changes, and the docs list the SIP regions (17 of 20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 67.5 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 20 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on LiveKit Telephony, or have the agent fetch /fixes/livekit-telephony.md. A fix counts at the next check, once it's public.
Show it
# Fix list: LiveKit Telephony
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/livekit-telephony, the October 2026 research run, assessed 8 October 2026. Grade B, 67.5 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on LiveKit Telephony: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Payments & pricing, 40 out of 100, up to 7.5 more on the total
Why it scored 40: No x402, MPP or L402 found (0). Per-minute and per-number prices are public without a login, also as Markdown (20). The Build plan is free with no card and includes a US local number, 50 inbound minutes and 1,000 third-party SIP minutes a month (20). An account is created in a browser and `lk cloud auth` opens one, and no programmatic sign-up or key API was found (0).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## 2. Reliability, 65 out of 100, up to 7 more on the total
Why it scored 65: Graded as a hosted service, LiveKit Cloud. Statuspage at status.livekit.io with SIP per region, Global SIP and US Phone Numbers as components (20). In the 90 days to 8 October the SIP incidents were all marked minor or none. Failed SIP transfers in US East ran about 72 minutes on 17 August, one-way audio on LiveKit Phone Numbers about 42 minutes on 2 September, and raised API latency on SIP twice on 15 September for about 70 minutes each. The two incidents marked major (2 and 15 September) hit the dashboard, analytics and billing API, not calls (20). The Server API limit is 1,000 requests a minute per project, with number limits of 100 on Ship and 300 on Scale (15). No 429, Retry-After, backoff or idempotency guidance was found for the SIP API (0). The pricing page lists 99.99% uptime for every plan, and section 2.5 of the terms calls such figures objectives with no credits outside a written Enterprise agreement, so no SLA is counted (0). The SIP API carries no beta label, though the warm transfer task in the Agents framework is marked beta, in Python only (10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 3. Security & auth, 61 out of 100, up to 6.8 more on the total
Why it scored 61: A project key and secret sign JWTs whose `sip` grant is `admin` or `call`, with a lifetime the signer sets. Keys rotate in the dashboard. The key pair itself can mint any grant, so scoping depends on the operator handing an agent a token and not the secret (25 of 30). `call` without `admin` is a least-privilege mode for dialling, inbound trunks can be limited by number, IP range or credentials, and no read-only grant or confirmation step for dialling or renting numbers was found (8 of 20). Calls carry untrusted caller speech, and no prompt-injection guidance was found in the telephony docs (5 of 15). The security overview says project configuration changes are logged, with export to a SIEM still on the roadmap, and the dashboard shows call logs (8 of 15). security.txt with a disclosure policy and safe harbour, a Hall of Fame with no cash bounty stated, SOC 2 Type II, six-monthly penetration tests, ISO 27001 in progress, and no published advisories on livekit/sip, livekit/livekit or livekit/livekit-cli (15 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 4. Agent ergonomics, 66 out of 100, up to 5.5 more on the total
Why it scored 66: List calls take a limit and ID, number or status filters, with no field selection (15 of 25). A `Pagination` type with `after_id` and `limit` on the SIP list calls (18 of 20). `wait_until_answered` returns a `SipCallError` with the carrier's SIP status code, and the docs map codes to outcomes. Twirp errors are named only in passing (15 of 20). No idempotency key was found, so a retried `CreateSIPParticipant` can place a second call (3 of 20). A call needs a trunk, a number and a room name, and SIP clients ship in Go, JavaScript, Python, Ruby, Kotlin and Rust plus the `lk` CLI (15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 5. Schema & documentation, 84 out of 100, up to 2.6 more on the total
Why it scored 84: The contract is protobuf in livekit/protocol (17 SIP RPCs, 6 phone number RPCs), called as JSON over Twirp. No OpenAPI document was found, and we counted the protobuf files as the similar spec (25). llms.txt per docs section and every page as Markdown (10). Reference tables give each parameter's purpose, and the guides say when to use an inline trunk or a stored one (15 of 20). Typed fields with enums for transport, encryption and number status and required fields marked, with metadata as a free string (13 of 15). Examples in six languages and the CLI, a call outcome table and a troubleshooting guide by SIP code. No full list of Twirp errors was found, and the reference still shows `TransferSIPParticipant` returning an empty message where the protocol changelog says it now returns a response object (11 of 15). The Twirp path has no version. Changes are dated in livekit/sip release tags and the protocol `CHANGELOG.md`, with no cloud changelog page found (10 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## 6. Transparency & trust, 75 out of 100, up to 2.2 more on the total
Made of editorial 69, provenance 81.
Why it scored 75: The SIP service, protocol, CLI and SDKs are Apache 2.0, and the security page says the same code runs on LiveKit Cloud. The cloud control plane and LiveKit Phone Numbers are closed, under clear terms (25 of 30). Terms, privacy policy and DPA all dated 6 October 2026 agree. The DPA lists retention by data category, user content is deleted after delivery unless recording is on, telemetry is kept up to 60 days and backups up to 30. Call detail records have no fixed period, and the sub-processor list names no telephony carrier for LiveKit Phone Numbers (22 of 30). No deprecation policy was found. Deprecated fields are flagged in the reference without dates, and the terms give 30 days' notice of changes to the agreement (5 of 20). The sub-processor list gives each entity, its activity and its country, all in the United States, with a way to subscribe to changes, and the docs list the SIP regions (17 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Endpoint on the vendor's domain: is not on livekit.com (0 of 15)
- Terms of service: read, states 6 of the 7 things a reader expects, and has 1 clause that costs points (7.1 of 10)
- Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10)
## 7. Maintenance & community, 90 out of 100, up to 0.9 more on the total
Why it scored 90: livekit-cli v2.19.0 was tagged on 8 October 2026 and livekit/sip v1.18.0 on 5 October (30). livekit/sip has 12 tags from v1.7.0 on 10 July to v1.18.0 (20). Of the 30 newest open issues and pull requests on livekit/sip, 22 have at least one comment. We read the counts and not who replied. Paid plans add email support and there is a community Slack (17 of 25). Current server SDKs, with livekit-server-sdk 2.19.1 on npm and livekit-api 1.2.1 on PyPI from 27 August 2026 (15). livekit/sip runs unit tests with the race detector and integration tests in CI and has Renovate configured. We did not see the latest run's result (8 of 10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- The lead gave livekit.io as the vendor's site. It now redirects to livekit.com, and the listing uses livekit.com
- Which carrier supplies LiveKit Phone Numbers. The sub-processor list of 10 September 2026 names none
- Whether unanswered or failed outbound attempts count as billed SIP minutes
- How long call detail records are kept. The terms say as long as law or carrier rules require
- Whether the SIP API returns 429 with a Retry-After header at the 1,000 requests a minute limit. No call was made to the API
- unchecked: trust.livekit.io, where the SOC 2 report and penetration test summaries sit behind an NDA request
- unchecked: the Enterprise agreement and its support and uptime SLA, which are not published
- unchecked: who answered the open issues on livekit/sip, and whether the latest CI run on its default branch passed
- unchecked: the Egress docs for recording a SIP call, so `voice.recording` is left out of the capabilities
- The npm and PyPI download counts are for the whole server SDKs, not for SIP use
## Weaknesses
- LiveKit Phone Numbers are US only and inbound only, and `TransferSIPParticipant` does not work on them yet
- Outbound calls need a trunk from another carrier, billed by that carrier on top of LiveKit's SIP minutes
- No 429, Retry-After or idempotency guidance was found for the SIP API, so a retried `CreateSIPParticipant` may dial twice
- The 99.99% uptime on the pricing page is an objective only, with no credits outside a written Enterprise agreement
- Sign-up and `lk cloud auth` need a person in a browser, and no machine payment protocol was found
- The terms bar benchmarking for competitive purposes without written consent
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Ask the operator for a short-lived token with only the `sip.call` grant to dial or transfer. Trunk, dispatch rule and number changes need `sip.admin`
- Use a third-party outbound trunk for outbound calls. LiveKit Phone Numbers only receive calls
- Set `wait_until_answered` on `CreateSIPParticipant` and read the SIP status on `SipCallError` before retrying. Voicemail answers with 200 OK
- Send every request as a JSON POST to `/twirp/livekit.SIP/<Method>` or `/twirp/livekit.PhoneNumberService/<Method>` on the project's own host, with `{}` for an empty body
- A released number is billed for the whole month, and the free Build allowance is a hard cap after which requests fail
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- The lead gave livekit.io as the vendor's site. It now redirects to livekit.com, and the listing uses livekit.com
- Which carrier supplies LiveKit Phone Numbers. The sub-processor list of 10 September 2026 names none
- Whether unanswered or failed outbound attempts count as billed SIP minutes
- How long call detail records are kept. The terms say as long as law or carrier rules require
- Whether the SIP API returns 429 with a Retry-After header at the 1,000 requests a minute limit. No call was made to the API
- unchecked: trust.livekit.io, where the SOC 2 report and penetration test summaries sit behind an NDA request
- unchecked: the Enterprise agreement and its support and uptime SLA, which are not published
- unchecked: who answered the open issues on livekit/sip, and whether the latest CI run on its default branch passed
- unchecked: the Egress docs for recording a SIP call, so
voice.recordingis left out of the capabilities - The npm and PyPI download counts are for the whole server SDKs, not for SIP use
Sources 37
- telephony docs index docs.livekit.io · seen 2026-10-08
- telephony introduction and SIP support table docs.livekit.io · seen 2026-10-08
- LiveKit Phone Numbers, limits and CLI docs.livekit.io · seen 2026-10-08
- SIP API reference docs.livekit.io · seen 2026-10-08
- Phone Numbers API reference docs.livekit.io · seen 2026-10-08
- outbound calls, call outcomes and SipCallError docs.livekit.io · seen 2026-10-08
- cold transfer by SIP REFER docs.livekit.io · seen 2026-10-08
- agent-assisted transfer (beta workflow) docs.livekit.io · seen 2026-10-08
- answering machine detection docs.livekit.io · seen 2026-10-08
- SIP region pinning docs.livekit.io · seen 2026-10-08
- Connectors API docs.livekit.io · seen 2026-10-08
- SIP troubleshooting guide docs.livekit.io · seen 2026-10-08
- quotas, rate limits and metered resources docs.livekit.io · seen 2026-10-08
- access tokens and the SIP grant docs.livekit.io · seen 2026-10-08
- webhooks, signing and retries docs.livekit.io · seen 2026-10-08
- CLI install and project linking docs.livekit.io · seen 2026-10-08
- docs MCP server docs.livekit.io · seen 2026-10-08
- pricing as Markdown livekit.com · seen 2026-10-08
- terms of service, 6 October 2026 livekit.com · seen 2026-10-08
- privacy policy, 6 October 2026 livekit.com · seen 2026-10-08
- data processing addendum livekit.com · seen 2026-10-08
- sub-processor list, 10 September 2026 livekit.com · seen 2026-10-08
- security page and compliance livekit.com · seen 2026-10-08
- security overview livekit.com · seen 2026-10-08
- vulnerability disclosure policy livekit.com · seen 2026-10-08
- security.txt livekit.com · seen 2026-10-08
- robots.txt, no Content-Signal line livekit.com · seen 2026-10-08
- status incidents feed status.livekit.io · seen 2026-10-08
- status components status.livekit.io · seen 2026-10-08
- livekit/sip repository, tags and CI (shallow clone) github.com · seen 2026-10-08
- livekit/sip stars, licence and open issues api.github.com · seen 2026-10-08
- livekit-cli tags (shallow clone) github.com · seen 2026-10-08
- protocol definitions and changelog (shallow clone) github.com · seen 2026-10-08
- livekit/sip advisories, none published api.github.com · seen 2026-10-08
- npm weekly downloads, livekit-server-sdk api.npmjs.org · seen 2026-10-08
- PyPI recent downloads, livekit-api pypistats.org · seen 2026-10-08
- RDAP for livekit.com rdap.org · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $1 / mo Free Build plan with no card. It includes 1 US local number, 50 US local inbound minutes and 1,000 third-party SIP minutes a month as a hard cap. Ship starts at $50 a month and Scale at $500, with third-party SIP minutes at $0.004 and $0.003 past the allowance, US local inbound at $0.01 a minute, toll-free inbound at $0.02, local numbers $1 a month and toll-free $2. A third-party carrier bills its own trunk and number charges. A number released mid-month is billed for the full month. Enterprise is priced by sales (https://livekit.com/pricing.md, checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Third-party SIP minutes, Ship plan | $0.004 | per minute of call | past 5,000 included minutes, carrier charges extra |
| Third-party SIP minutes, Scale plan | $0.003 | per minute of call | past 50,000 included minutes, carrier charges extra |
| US local inbound minutes | $0.01 | per minute of call | LiveKit Phone Numbers, past 100 (Ship) or 1,000 (Scale) included minutes |
| US toll-free inbound minutes | $0.02 | per minute of call | Ship and Scale only |
| US local number | $1 | per month (plan) | first number free on every plan |
| US toll-free number | $2 | per month (plan) | Ship and Scale only |
| Ship plan | $50 | per month (plan) | starting price |
| Scale plan | $500 | per month (plan) | starting price |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/livekit-telephony.xml, or this listing's score history at history.json.
Connect
Install
brew install livekit-cli
First request
curl -X POST https://<your LiveKit URL domain>/twirp/livekit.SIP/ListSIPInboundTrunk \
-H "Authorization: Bearer <token-with-sip-admin>" \
-H 'Content-Type: application/json' \
-d '{}'
Through letme picks today, calling later
GET https://letme.dev/livekit-telephony
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Twilio Programmable Voice API + MCP ATelnyx Voice API + MCP BBSignalWire Voice API BBandwidth Voice API + MCP BSinch Voice API + MCP BPlivo Voice API C
Head to head Bandwidth Voice API + MCP vs LiveKit Telephony · Exotel Voice API + MCP vs LiveKit Telephony · Infobip Calls API + MCP vs LiveKit Telephony · jambonz vs LiveKit Telephony · LiveKit Telephony vs Plivo Voice API · LiveKit Telephony vs SignalWire Voice API · LiveKit Telephony vs Sinch Voice API + MCP · LiveKit Telephony vs Telnyx Voice API + MCP · LiveKit Telephony vs Twilio Programmable Voice API + MCP · LiveKit Telephony vs Vonage Voice API + MCP · LiveKit Telephony vs Voximplant
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Twilio Programmable Voice API + MCP Twilio | A | 80.4 | voice.calls voice.numbers voice.streaming voice.sip voice.transfer | no |
| Telnyx Voice API + MCP Telnyx | BB | 74.2 | voice.calls voice.numbers voice.streaming voice.sip voice.transfer | no |
| SignalWire Voice API SignalWire | B | 67.1 | voice.calls voice.numbers voice.streaming voice.sip voice.transfer | no |
| Bandwidth Voice API + MCP Bandwidth | B | 63.7 | voice.calls voice.numbers voice.streaming voice.sip voice.transfer | no |
| Sinch Voice API + MCP Sinch | B | 62.7 | voice.calls voice.numbers voice.streaming voice.sip voice.transfer | no |
| Plivo Voice API Plivo | C | 60.4 | voice.calls voice.numbers voice.streaming voice.sip voice.transfer | no |
Machine-readable
- JSON
/api/v1/tools/livekit-telephony.json· historyhistory.json· badge/badges/livekit-telephony.svg· changes feed/feeds/tools/livekit-telephony.xml - Markdown
/tools/livekit-telephony.md· slim/tools/livekit-telephony.min.md(or sendAccept: text/markdown) - Fix list
/fixes/livekit-telephony.md·/fixes/livekit-telephony.json - From a terminal
anchor tool livekit-telephony --md(the CLI) · over MCPget_tool {"slug": "livekit-telephony"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/livekit-telephony"><img src="https://www.anchorterminal.com/badges/livekit-telephony.svg" alt="LiveKit Telephony on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/livekit-telephony)<a href="https://www.anchorterminal.com/tools/livekit-telephony">LiveKit Telephony on Anchor Terminal</a>It counts on a page on livekit.com or one of its subdomains, or the README of github.com/livekit/sip.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "livekit-telephony", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


