DevelopersRead only

list_do_not_call

API reference — one of the tools an AI assistant can call on an Avrosh account.

What it does

Numbers this business must not call, with why each one is on the list and when. Search by any part of the number - it matches on the digits, so a number pasted in whatever format the operator's own system shows it still finds the entry. Entries that have been lifted are shown too, at the bottom, with the reason: the list is a record, not just a filter.

This is the exact text the model reads before deciding to call.

Parameters

business_idstringrequired

The id returned by list_businesses.

searchstringoptional

Any part of a number. Matched on digits.

Request

curl -X POST https://us.avrosh.com/mcp \
  -H "Authorization: Bearer $AVROSH_KEY" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"list_do_not_call","arguments":{"business_id":"926135ac-487d-4367-8bad-25397d0d4b87","search":"4567"}}}'

Response

The result arrives as an MCP content block; the JSON below is what the text field parses to.

{
  "entries": [
    {
      "id": "dnc_1…",
      "phone": "+6281234567890",
      "source": "refused",
      "note": "",
      "revokedAt": null
    }
  ]
}

Connecting

Paste the URL into your assistant and log in. Avrosh implements OAuth 2.1, so an MCP client discovers the authorisation server, registers itself, and opens a browser asking you to sign in here. That is the whole setup: nothing to copy, no key to keep, and nothing to rotate later.

https://us.avrosh.com/mcp

For something with no browser to log in with — a cron job, a script, an automation platform — there is a second door: a bearer key made in the dashboard under Docs, shown once because only its hash is stored, and revocable at any time.

curl https://us.avrosh.com/mcp \
  -H "Authorization: Bearer $AVROSH_KEY"

Either way the boundary is the same one: an assistant reaches every business on the account it signed in to, and no others. There are no scopes to configure and nothing to switch on — what bounds it is whose account it is, enforced in the database rather than by a permission anybody sets.