# Access Control Source: https://docs.retellai.com/accounts/access-control Manage your Retell workspace with role-based access control: invite members, assign Admin, Developer, Analyst, or Viewer roles, and control permissions. To keep your workspace safe, we have an RBAC (Role-Based Access Control) system. ### System Roles #### Admin Full control over workspace resources and members. Complete access to all features including billing, user management, and workspace settings. Can: * Invite, remove, and change roles for members * View and manage billing: usage, invoices, payment methods, subscriptions, and customer portal * Create, edit, and delete agents, conversation flows, Retell LLMs, knowledge bases, voices, and folders * Configure developer settings * Access all data, including raw transcripts and recordings * Manage telephony settings * Update or delete the workspace Cannot: * None — Admins have full permissions #### Developer Full functional access to build and test agents, view raw data, manage analytics and developer settings. Cannot manage billing or organization users. Can: * Build and edit agents, flows, LLMs, KBs, voices * Test and simulate; manage test cases and playground * View raw logs, transcripts, recordings, and analytics * Create exports; run calls and batch calls * Manage API/public keys and webhooks; adjust concurrency/CPS Cannot: * Manage billing (usage, invoices, payment methods, subscriptions) * Invite, remove, or change member roles * Update or delete the workspace #### Member Read-only access to agents, testing artifacts, scrubbed history, and analytics. Cannot make changes or view sensitive data. Can: * View agents and configurations (read‑only) * View tests, playground threads, and analytics * View scrubbed history; batch calls and phone resources * List workspace members Cannot: * Create, edit, or delete resources * Start calls/chats, run simulations, or change playground * Access API/public keys, webhooks, or raw transcripts/recordings * Manage billing, settings, or team members ### Invite User Now under the user management of your workspace, you (admin) can invite a user with a specific role. invite_user.jpeg ### Change User Role You can change the role of active users in the workspace. update_user_role.jpeg ### Remove User You can also remove a user from your workspace. # Manage your Retell AI account Source: https://docs.retellai.com/accounts/account Check account status, reset your password, change your email address, switch to Google SSO, stop charges, and delete your Retell AI account. To keep your information safe, we use **Auth0** as our login system. ## Account Status Your account could have the following statuses: * **Active**: Your account is active and all services are available. * **Verification Needed**: Your account is on hold for further verification due to high-volume calls. Please contact us via the Customer Support Portal or [support@retellai.com](mailto:support@retellai.com). Raise a ticket with your company's name, use case, and verification that you represent the company. * **Invoice Past Due**: Your account has a past due invoice and is at risk of automatic shutdown in 7 days. Please make a payment to keep your service active. * **Invoice Overdue**: Your account has an overdue balance, and your service has been temporarily deactivated. Please make a payment to restore your service. ## Reset your password If you want to change or reset your password: 1. Go to the login page. 2. Click the **"Don’t remember your password?"** link. 3. Enter your email address and follow the instructions sent to your inbox. For better security, we recommend using **Sign in with Google**. This provides an extra layer of protection and reduces the need to manage separate passwords. ### Important Note About SSO and Password-Based Sign-In Please note that **Google SSO** and **email-password sign-in** are treated as **separate accounts** in our system. They are not automatically linked. If you currently use one sign-in method (e.g., **email-password sign-in**) and wish to switch to the other (e.g., **Google SSO**), follow these steps: 1. Log in to your account using your current method (either Google SSO or email-password sign-in). 2. Click your profile photo at the bottom left of the dashboard. 3. Navigate to **"Workspace"** and send an invite to your email address. 4. Log out of your current account. 5. Open the invite email and use the **alternative sign-in method** to create a new account (e.g., sign in with Google if you currently use email, or sign up with email and password if you currently use Google SSO). This will create a separate account with the new sign-in method while maintaining access to your existing workspace. ## Change your email address You can change the email on your account after confirming the new address. Retell doesn't switch your email right away — it emails a verification link to the new address, and the change takes effect only once you open that link. Enter your new email address in your account settings. Retell sends a verification link to that address. Open the verification link sent to the new email. Your account email updates only after you confirm — until then, your current email stays active. While a change is pending, you can cancel it any time before confirming. Canceling discards the new address and leaves your current email and its verified status unchanged. Email changes are available only for accounts that sign in with an email and password. If you sign in with Google SSO or another social login, your email is managed by that provider — update it there, or see [switching sign-in methods](#important-note-about-sso-and-password-based-sign-in). SSO users should contact their administrator. ## Cancel or stop charges Retell uses **post-usage billing** — there is no recurring subscription or fixed monthly fee on the pay-as-you-go plan. You are only charged for usage you actually incur (call minutes, phone numbers, knowledge bases, and other line items shown on the Billing page). To stop accruing charges without deleting your account, follow [Stop charges or close your account](/accounts/billing#stop-charges-or-close-your-account) on the Billing page. That guide covers stopping calls, releasing phone numbers, deleting extra knowledge bases, and settling any outstanding invoices. If you are on a custom or enterprise plan and need help confirming no recurring charges remain, contact [Retell support](https://support.retellai.com/). ## Delete your account Deleting your account permanently removes it along with all associated data. If you're the last member of any workspace, those workspaces are deleted too. This can't be undone. Before proceeding: * Ensure you have downloaded any important data you wish to keep. * Settle any outstanding invoices on the [Billing page](/accounts/billing). * Stop any ongoing usage — see [Stop charges or close your account](/accounts/billing#stop-charges-or-close-your-account) for the full checklist (release phone numbers, delete extra knowledge bases, stop calls). * Remove any connected third-party integrations. Account deletion is permanent and cannot be undone. All associated data, including billing history and user preferences, will be permanently removed. To also erase your personal data from the third-party services Retell uses — such as its CRM, support, and identity-verification providers — see [requesting erasure of your personal data](/general/compliance#how-do-i-request-erasure-of-my-personal-data). Workspace settings page with the delete workspace button Delete account # Add payment methods Source: https://docs.retellai.com/accounts/add-payment Add a Stripe payment method to your Retell workspace to buy credits, keep calling after the free trial, purchase phone numbers, and avoid service interruptions. Adding a payment method is required before you can purchase phone numbers or use Retell services beyond the free trial. We use Stripe to securely process all payments. Your payment method on file is used for: * **Credit-based accounts** — purchasing credits, auto-recharge top-ups, and the end-of-month invoice for subscription items (phone numbers, knowledge bases, CPS, and concurrency). * **Legacy monthly-billing accounts** — the end-of-period charge for your usage and recurring items. See [Billing overview](/accounts/billing) to check which billing version your account uses. Payment methods are scoped **per workspace**. Adding a card in one workspace does not carry it over to another workspace, even under the same login — each workspace has its own billing setup, invoices, and usage totals. If you create a second workspace, switch into it and repeat the steps below before starting calls there. See [Create and manage Retell workspaces](/accounts/workspace) for how to switch workspaces. ## Adding Your Payment Method Go to the Billing tab in your dashboard Billing tab in the dashboard Click "Change payment methods" to open payment settings Change payment methods button In the Stripe portal, click "Add payment method" and enter your payment details. Your payment information is securely handled by Stripe. Stripe payment details form # API Key Overview Source: https://docs.retellai.com/accounts/api-keys-overview How API keys authenticate your Retell REST API requests, SDK integrations, and webhook endpoints, plus best practices for storing and rotating keys safely. API keys are used to authenticate your requests to: * REST API endpoints * SDK integrations * CLI commands * Webhook endpoints Each workspace can have multiple API keys, all sharing the same permission level. ### REST API Authentication To authenticate your REST API requests, include your API key in the request headers: ```http theme={"dark"} Authorization: Bearer YOUR_API_KEY ``` Try out authentication in our [API Playground](/api-references/create-phone-call) to see it in action. ### Webhook API Key For enhanced security, we automatically designate one of your API keys for [webhook authentication](/features/secure-webhook). This designated webhook API key: * Is used to sign and verify webhook requests * Cannot be deleted * Ensures your webhook endpoints only receive legitimate requests Keep your API keys secure and never share them in public repositories or client-side code. # Retell AI billing: credits, auto recharge, and invoices Source: https://docs.retellai.com/accounts/billing How Retell billing works: prepaid credits and auto recharge on credit-based accounts, legacy end-of-month billing, usage tracking, and invoices. The Billing tab in your dashboard is where you manage payments, buy credits, track usage, and download invoices. Retell has two billing versions, and this page covers both. ## Which billing version am I on? Check the Billing tab to see which version applies to your workspace: * **Credit-based billing** — your Billing page shows a **Credits Balance** with **Buy credits** and **Auto recharge** buttons. You pay for usage upfront with prepaid credits. This applies to newer accounts. * **Monthly billing (legacy)** — your Billing page shows only monthly invoices, with no credit balance. Usage is billed at the end of each period. This applies to accounts created before credit-based billing was introduced. Billing is scoped **per workspace**, not per account. Every workspace, including new ones you create later, has its own payment method, credit balance, invoices, and usage totals. Adding a card in one workspace does not carry it over to another workspace under the same login: switch into each new workspace and add a payment method there before running calls. See [Create and manage Retell workspaces](/accounts/workspace) for how to switch workspaces. Choose your billing version below. ## How credit-based billing works Billing page on a credit-based account showing a Credits Balance of $100 with Buy credits and Auto recharge buttons in the top right Credit-based accounts pay for usage with a prepaid credit balance: * **Usage costs** — everything metered, such as per-minute call costs (voice, LLM, telephony) — are deducted from your credit balance in real time. * **Subscription items** — phone numbers, knowledge bases beyond the free tier, calls per second (CPS), and purchased [concurrency](/deploy/concurrency) — are not paid with credits. They are billed to your payment method on file at the end of each billing cycle. The billing cycle runs from the 1st of the month to the end of the month. Subscription items purchased mid-month are prorated for the portion of the month they were active. New accounts start with **\$10 in free trial credits** so you can test Retell before adding a payment method. The trial credit is granted once per email address. If you previously had a Retell account with the same email (including a deleted one), signing up again won't grant the credit a second time. When your credit balance reaches zero, new calls are blocked until you buy credits or auto recharge tops up your balance. Set up auto recharge to avoid interruptions. ## Buy credits Go to the **Billing** tab in your dashboard and click **Buy credits**. Enter the amount and click **Purchase**. The charge goes to your payment method on file, processed securely through Stripe (see [Add payment methods](/accounts/add-payment)). Buy Credits dialog with a dollar amount field set to 100 and Cancel and Purchase buttons Credits never expire, but they are non-refundable once purchased. ## Set up auto recharge Auto recharge buys credits automatically when your balance runs low, so calls are never blocked: Go to the **Billing** tab, click **Auto recharge**, and toggle **Auto Recharge** on. Set **When credits drop below** (the balance that triggers a recharge) and **Bring credits back to** (the balance restored on each recharge), then click **Save**. Auto Recharge Setting dialog with the toggle on, When credits drop below set to $10, and Bring credits back to set to $100 Each recharge is charged to your payment method on file. If a recharge payment fails, follow [Handle failed payments](/accounts/fail-payment). ## Subscription items and invoices At the end of each calendar month, you receive an invoice for subscription items: * Phone numbers [purchased through Retell](/deploy/purchase-number) * Knowledge bases beyond the free tier * Calls per second (CPS) upgrades * Purchased [concurrency](/deploy/concurrency) These are charged to your payment method on file and prorated if purchased mid-cycle. Download invoices from the Billing page by clicking the "Invoice" button next to the respective period. ## Stop charges or close your account To stop accruing charges on a credit-based account: 1. **Turn off auto recharge** so your balance is not topped up automatically. 2. **Release any phone numbers you own.** Numbers are billed monthly until released. Remove the number from the Phone Numbers page, or call the [Delete Phone Number API](/api-references/delete-phone-number). 3. **Delete knowledge bases beyond the free tier** and remove any CPS or concurrency upgrades. These are billed monthly until removed. 4. **Settle any outstanding invoices** on the Billing page. Remaining credits are non-refundable, so spend down your balance before closing your account. To close your account entirely, follow [Delete your account](/accounts/account#delete-your-account) after completing the steps above. ## Billing overview The Billing tab allows you to manage payments, track expenses, and download invoices: 1. Payment management: We use Stripe for secure and reliable payment processing. Update your payment methods by clicking the "Change payment methods" button. 2. Billing history: Review your monthly expenses, including cost breakdowns by category (e.g., Voice Infra, LLM). 3. Invoices: Download invoices by clicking the "Invoice" button next to the respective period. 4. Current charges: View ongoing costs for the current billing period, including itemized amounts and usage details. Legacy accounts use **post-usage billing**, not a prepaid credit balance. You are charged at the end of each billing period based on actual usage on the payment method you have on file. There is no manual top-up or auto recharge to configure. Make sure a valid payment method is added (see [Add payment methods](/accounts/add-payment)) to avoid service interruptions. If a charge fails, follow [Handle failed payments](/accounts/fail-payment). Billing page on a legacy account showing billing history with Change payment methods and Invoice buttons ## Stop charges or close your account Because legacy accounts use post-usage billing, there is no recurring subscription to cancel and no fixed monthly fee on the pay-as-you-go plan. You are only charged for usage you actually incur (call minutes, phone numbers, knowledge bases, and other line items shown on the Billing page). To stop accruing charges: 1. **Stop running calls.** Once no calls are made, no usage charges accrue for the next billing period. 2. **Release any phone numbers you own.** Numbers purchased through Retell are billed monthly until released. Remove the number from the Phone Numbers page in the dashboard, or call the [Delete Phone Number API](/api-references/delete-phone-number). 3. **Delete knowledge bases beyond the free tier.** Additional knowledge bases are billed monthly until deleted. 4. **Settle any outstanding invoices** on the Billing page. If you also want to close your account entirely, follow [Delete your account](/accounts/account#delete-your-account) after completing the steps above. If you are on a custom/enterprise plan or need help confirming there are no remaining recurring charges, contact [Retell support](https://support.retellai.com/). ## View usage breakdown The Usage tab on the Billing page provides a breakdown of your workspace's activity and costs, regardless of billing version: 1. Total cost: Your total expenses for the selected billing period. 2. Call minutes: The total number of call minutes used. 3. Average cost per minute: The average cost for each minute of calls. 4. Daily or weekly call costs, making it easy to identify high-cost periods and track spending trends over time. 5. Cost by provider: A breakdown of expenses across voice infra, large language models (LLMs), telephony services, and concurrency usage. What each category covers: * **Voice infra**: Retell's conversation voice engine. This is the flat per-minute platform cost of running the real-time call, separate from LLM and telephony costs. * **LLM**: the per-minute cost of the language model your agent uses, which varies by model. * **Telephony**: per-minute call rates and monthly phone number fees for Retell-provided numbers. Custom telephony (SIP trunking) carries no Retell telephony charge. * **Concurrency**: monthly fees for purchased concurrency beyond the 20 free concurrent calls. See the [Retell pricing page](https://www.retellai.com/pricing) for current rates for each component. Certain call characteristics can adjust the billed duration; see [Exceptions to per-minute pricing](/accounts/billing-exceptions). Usage tab on the Billing page with total cost, call minutes, average cost per minute, and a cost-by-provider chart # Exceptions to Our Per-Minute Pricing Source: https://docs.retellai.com/accounts/billing-exceptions Billing adjustments that may affect Retell call costs: 10-second minimum for dynamic opening messages and extra charges for long prompt token counts. ## Overview While we generally bill based on actual call duration, certain call characteristics may result in adjusted billing to ensure fair pricing for our services. ## Rule 1: Minimum Duration for Dynamic Opening Messages **When it applies:** Calls shorter than 10 seconds that use dynamic opening messages when AI speaks first **Billing adjustment:** Minimum charge of 10 seconds Dynamic Message - AI Speaks first **Example:** * Call duration: 6 seconds * Dynamic opening messages: Enabled * Billed duration: 10 seconds (4 seconds additional charge) **Why:** Dynamic opening messages require processing time regardless of call length, so we ensure a minimum charge to cover these costs. ## Rule 2: LLM Price Scaling for > 4,000 Token Prompt Length **When it applies:** Agents that use more than 4,000 LLM tokens in their prompts **Billing adjustment:** Duration is scaled proportionally based on token usage **What's included in token calculation:** * global prompt * functions (tool descriptions) * state / node prompt * transcript between agent and user * tool call history and results * retrieved [knowledge base](/build/knowledge-base) content [Flex mode](/build/conversation-flow/flex-mode) is a common trigger for this rule. It compiles all node prompts, transitions, and tool descriptions into a single LLM context, which can push the token count well above 4,000. **Price calculation:** * Scaling Factor = Prompt LLM Tokens ÷ 4,000 * Billed Duration = Original Duration × Scaling Factor (rounded up) **Example:** * Call duration: 60 seconds * LLM tokens used: 4,800 * Scaling factor: 4,800 ÷ 4,000 = 1.2 * Billed duration: 72 seconds (12 seconds additional charge) Long token prompts pricing in dashboard **Why:** Larger LLM prompt lengths incur greater costs due to token-based pricing from our underlying model providers, so we scale the billing accordingly to reflect these increased expenses. # Data Retention Policy Source: https://docs.retellai.com/accounts/data-retention Configure per-agent data retention to automatically delete call and chat data — transcripts, recordings, and logs — after a set period for compliance. # Data Retention Policy Retell allows you to configure a data retention period per agent. After the retention period expires, call and chat data associated with that agent is automatically and permanently deleted. By default, data is kept indefinitely (no automatic deletion). ## How It Works * Data retention is configured **per agent** under Security & Fallback Settings * Expired data is automatically deleted on a daily basis * Deletion is **permanent and irreversible** — deleted data cannot be recovered * Applies to both voice calls and chats Retention dropdown showing available retention period options ## How to Configure 1. Navigate to your agent 2. Open **Security & Fallback Settings** 3. Under **Data Storage Settings**, select your preferred data storage mode 4. Use the **Retention** dropdown to set how long data is kept before automatic deletion The retention period applies regardless of which data storage mode you select (Everything, Everything except PII, or Basic Attributes Only). ## What Gets Deleted When the retention period expires, the following data is permanently removed: * **Call recordings** (audio files) * **Transcripts** * **Call and chat logs** * **Knowledge base retrieval logs** * **Dynamic variables and metadata** While some basic metadata is retained internally, the call or chat is effectively deleted and will no longer appear in session history or API responses. Deletion is irreversible. Make sure to export any data you need before the retention period expires. You can use [webhook events](/features/webhook-overview) to capture call data in real time, or use the [Get Call](/api-references/get-call) / [Get Chat](/api-references/get-chat) API to retrieve data before it expires. ## Available Retention Periods | Option | Duration | | ------------ | ------------------------------- | | Keep forever | No automatic deletion (default) | | 1 day | 24 hours after call/chat starts | | 3 days | | | 7 days | | | 30 days | 1 month | | 60 days | 2 months | | 90 days | 3 months | | 180 days | 6 months | | 365 days | 1 year | | 730 days | 2 years | ## API Configuration You can set the retention period via the API when creating or updating an agent: ```json theme={"dark"} { "data_storage_retention_days": 90 } ``` * **Field**: `data_storage_retention_days` * **Type**: integer (1–730) or `null` * **Default**: `null` (keep forever) See the [Update Agent](/api-references/update-agent) or [Create Agent](/api-references/create-agent) API reference for details. ## Related * [Data Storage Settings](/accounts/privacy-disable) — control what types of data are stored * [Secure URLs](/accounts/signed-secure-url) — configure URL expiration for recordings and logs # Handle failed payments Source: https://docs.retellai.com/accounts/fail-payment Resolve failed Retell payments: contact your bank to allowlist transactions, request written confirmation, and update your payment method on Stripe. If your payment fails, follow these steps to resolve the issue: 1. Contact your bank to ensure the transaction isn't being blocked 2. Request to allowlist transactions from Retell 3. Return to the Retell Dashboard and retry the payment 1. Obtain written confirmation from your bank that Retell has been allowlisted * Statement should be on bank letterhead * Should explicitly confirm that transactions from Retell are now approved 2. Email the statement to [support@retellai.com](mailto:support@retellai.com) 3. Include your Retell account details in the email 1. Consider adding a different payment method 2. Go to the "Billing" tab 3. Click "Change payment methods" 4. Add a new card or payment method If you continue experiencing issues, please contact our support team via the [Customer Support Portal](https://support.retellai.com/) or at [support@retellai.com](mailto:support@retellai.com) for further assistance. # KYC Verification Source: https://docs.retellai.com/accounts/kyc Complete KYC verification — automatic, Persona-based, or manual review — to unlock outbound calling, phone number purchases, and SMS on your Retell account. Before you can make outbound calls with Retell, you’ll need to complete KYC (Know Your Customer) verification. Depending on your account information, there are a few ways to pass KYC. ### How to Pass KYC #### Automatic verification We may automatically verify your account based on the information you provided during registration. If this applies, your KYC will be approved without any additional steps. #### Verification via Persona If automatic verification is not possible, you will be asked to complete KYC through Persona using your government-issued ID. You can go to “Phone Numbers”, click on any of your numbers, and you’ll see the interface where you can start the KYC process. KYC verification section on the phone number page We currently support verification in 83 countries. If your country is not listed, [contact our support team](/general/support) with your company name, use case, and proof you represent the company. We will review your case based on risk and business needs and may enable verification for your country. #### Manual review If neither automatic nor Persona verification applies, your KYC goes to manual review, which takes longer than the other paths. If your verification is delayed, [reach out to support](/general/support) with your workspace id, company name, use case, and proof you represent the company so we can prioritize it. ### ID Verification Restrictions Each person can verify only one account. Our system detects duplicate identities, so even using a different government ID may be flagged as a duplicate. If your previous account was verified and later deleted, [contact our support team](/general/support) to request a manual review. # Manage API keys and permission scopes Source: https://docs.retellai.com/accounts/manage-api-keys Create, delete, and rotate Retell API keys, set a webhook signing key, and restrict permissions with read or edit scopes for Build, Monitor, and Deploy. The "API Keys" section belongs to System "Settings". The "API Keys" section allows you to manage your authentication credentials for accessing the API. Here's what you can do: 1. **Create a new API key** * Click the "Add" button * Give your key a descriptive name to identify its purpose 2. **Delete an existing API key** * Locate the key you want to remove * Click the delete (trash) icon * Confirm the deletion when prompted 3. **Set a webhook API key** * Select an existing API key * Click "Set as Webhook Key" to designate it for webhook authentication * Only one key can be set as the webhook key at a time 4. **Restrict an API key's permissions** * Enable "Restrict permissions" when creating or editing a key * Grant each permission group **No Access**, **Read**, or **Edit** * See [Restrict API key permissions](#restrict-api-key-permissions) for details Keep your API keys secure and never share them publicly. If a key is compromised, delete it immediately and create a new one. API Keys management interface ## Restrict API key permissions By default, an API key has **full access** to every API endpoint that supports API key authentication. To limit what a key can do, enable **Restrict permissions** when you create or edit the key, then choose an access level for each permission group. Scoped keys are useful when you share a key with a third party or want to limit it to a single integration. Each group offers up to three access levels: * **No Access** — the key cannot call any endpoint in this group. * **Read** — the key can call read-only endpoints in this group (for example, listing or fetching resources). * **Edit** — the key can call both read and write endpoints in this group. Selecting **Edit** also grants Read access. Some groups are action-only and have no separate **Read** level — their Read column shows a dash (–). For those groups you can only choose **No Access** or **Edit**. ### Permission groups | Group | Permission | Access levels | Grants access to | | ----------- | ---------- | ----------------------- | ------------------------------------------------------------------------------------------------------ | | **Build** | Agent | No Access · Read · Edit | Agents and chat agents, conversation flows, Retell LLMs, knowledge bases, voices, and folders | | **Build** | Testing | No Access · Read · Edit | Test cases and results, batch test jobs, playground threads and completions, and web-call testing | | **Monitor** | History | No Access · Read · Edit | Call and chat history, transcripts, recordings, and call metadata | | **Monitor** | Export | No Access · Edit | Creating and managing export requests for history data | | **Deploy** | Call | No Access · Edit | Creating and managing web, phone, and batch calls, chat sessions, and live-call controls | | **Deploy** | Phone | No Access · Read · Edit | Phone numbers, A2P campaigns, business profiles, branded call and phone verification, and SMS webhooks | Grant the narrowest access a key needs. For example, a key that only pulls call history needs just **History → Read**, while a key that places outbound calls needs **Call → Edit**. Restrictions apply only to API requests made with that key, and you can change them anytime by editing the key. A key created without restrictions keeps full access. # Data Storage Settings Source: https://docs.retellai.com/accounts/privacy-disable Control how Retell stores sensitive call data — recordings, transcripts, dynamic variables, caller IDs, KB logs — with per-agent privacy settings. # Data Storage Privacy Settings By default, we store potentially sensitive data related to your calls, including: * Call logs * Transcriptions * Call recordings * Caller ID for inbound call * Callee ID for outbound call * Knowledge base retrieved contents logs * Dynamic variables * Metadata ## How to Manage Data Storage You can opt out of sensitive data storage at any time: 1. Navigate to your agent 2. Under **Security & Fallback Settings → Data Storage Settings**, select: * **Everything** — store transcripts, recordings, and logs * **Everything except PII** — store content, excluding PII when possible * **Basic Attributes Only** — store only metadata (no transcripts/recordings/logs) Privacy settings showing Data Storage Settings options You can also configure a **data retention period** to automatically delete stored data after a set number of days. See [Data Retention Policy](/accounts/data-retention) for details. ## What Happens When You Change Storage Settings When you opt out: * You will continue to receive [webhook events](/features/webhook-overview), where you can access the transcript, call recording, and other sensitive data in it * The call recording link will expire after 10 minutes upon receiving the webhook * **Everything**: All artifacts (transcripts, recordings, logs) are stored * **Everything except PII**: Artifacts are stored with PII removed according to the categories you select in your `pii_config`. See [PII scrubbing](#pii-scrubbing) below for exactly which fields are affected. * **Basic Attributes Only**: No transcripts/recordings/logs are stored; if you query the call with the get call API later, you will not get these fields ## PII scrubbing When you choose "Everything except PII", you can configure which personally identifiable information (PII) is removed after the call completes. Scrubbing is applied across the **transcript, recording, public logs, and structured fields on the call record itself** (dynamic variables, metadata, call analysis, tool call arguments and results). PII configuration is defined on the agent. Per-call storage behavior can still be limited via `data_storage_setting` inherited onto the call. ### Content categories When any of these categories are selected, occurrences are detected post-call and replaced with `[category number]` placeholders (e.g. `[email 1]`, `[person name 2]`): * `person_name` * `address` * `email` * `ssn` * `passport` * `driver_license` * `credit_card` * `bank_account` * `password` * `pin` * `medical_id` * `date_of_birth` * `customer_account_number` These placeholders are written into the scrubbed copies of: * **Transcript** — user and agent utterances * **Recording** — audio is replaced with a beep over the PII intervals (surfaced as `scrubbed_recording_url`) * **Public logs** — log file content * **Dynamic variables** — `retell_llm_dynamic_variables`, collected dynamic variables, and override dynamic variables (surfaced as their `scrubbed_*` counterparts) * **Metadata** — `metadata` (surfaced as `scrubbed_metadata`) * **Call analysis** — `call_analysis.call_summary` and `call_analysis.custom_analysis_data` (surfaced as `scrubbed_call_analysis`) * **Tool calls** — arguments and results * **DTMF digits** — replaced with `[PII INFO]` whenever any PII category is enabled, to avoid exposing touch-tone passwords or PINs * **SMS message text** (for chat agents) The raw originals are deleted under "Everything except PII" — only the scrubbed versions remain. ### `phone_number` (directional) `phone_number` behaves differently from the content categories. Selecting it redacts the **customer's** phone number from the call record itself, not just the transcript: * **Inbound calls**: `from_number` is removed * **Outbound calls**: `to_number` is removed * **SMS chats**: `user_number` is removed The opposite-direction number (your Retell number) is preserved. The field is removed entirely from the call object — there is no placeholder. If you need to keep the customer's number visible for downstream systems, do not include `phone_number` in your categories. ### What is always preserved Regardless of the categories you configure, these fields are never altered or removed by PII scrubbing: * **Identifiers**: `call_id`, `agent_id` * **Timing**: `start_timestamp`, `end_timestamp`, `duration_ms` * **Outcome**: `call_status`, `disconnection_reason`, `call_successful`, `user_sentiment`, `in_voicemail` * **Operational**: `direction`, `transfer_destination`, `call_latency`, `cost_metadata`, `call_cost`, `custom_attributes` * **Tool call records** — the name, timing, and success of each tool call (their *arguments and results* are still scrubbed when content categories are selected) To remove these fields as well, use the **Basic Attributes Only** storage setting or configure a [data retention period](/accounts/data-retention). PII scrubbing configuration Example of PII scrubbing result ## Announce a recording disclaimer Retell does not have a dedicated setting for playing a "this call may be recorded" announcement, but you can have the agent say it as its first utterance. Recording, when enabled, runs for the entire call, so the disclaimer itself is captured in the recording. * **Single or multi-prompt agents** — put the disclaimer text in the agent's **Begin Message** (for example, `"This call may be recorded for quality assurance."`) so it is spoken before any user turn. * **Conversation flow agents** — add a conversation node at the start of the flow with the disclaimer as its static text, enable **Skip Response** so the agent moves on without waiting for a user reply, and enable **Block Interruptions** so the user can't cut it off. See [Conversation Node](/build/conversation-flow/conversation-node). If you don't want the disclaimer stored, switch that agent's storage to **Basic Attributes Only** — no recording is retained, but the agent still speaks the announcement live. # Public keys Source: https://docs.retellai.com/accounts/public-keys Use Retell AI public keys for web calls and the website widget: authenticate browser requests, restrict allowed domains, and configure reCAPTCHA protection. Public keys authenticate the Retell website widget and browser web calls. You can include public keys in frontend code; keep [API keys](/accounts/api-keys-overview) on your server. Use public keys for: * Embedding the [website widget](/deploy/chat-widget) * Starting [web calls](/deploy/web-call) with `RetellClient.createWebCall()` Edit Public Key dialog showing allowed domains, reCAPTCHA protection, and the score threshold. ## Create or edit a public key 1. Open **API Keys → Public Keys** in the Retell dashboard. 2. Add a public key or select an existing one to edit. 3. Add the domains that can use it, such as `example.com` or `app.example.com`. Add `localhost` for local development. 4. Save the key and copy its value into your widget configuration or Web SDK client. Only allow domains you control, and remove domains you no longer use. ## Google reCAPTCHA v3 protection (optional) Enable Google reCAPTCHA v3 to help limit automated abuse. When enabled, creating a web call or starting a widget conversation requires a valid reCAPTCHA token. To enable reCAPTCHA: 1. Edit the public key and enable **Abuse Prevention (Google reCAPTCHA)**. 2. Add your reCAPTCHA **secret key** from [Google's reCAPTCHA console](https://www.google.com/recaptcha). 3. Set the **Score Threshold**. The dashboard defaults to 0.5 (as of September 2026). Requests below the threshold are rejected; higher thresholds can also reject more legitimate users. 4. Save your changes. Your frontend uses the reCAPTCHA **site key** to obtain tokens; keep the secret key in the dashboard. Follow [Google's reCAPTCHA v3 guide](https://developers.google.com/recaptcha/docs/v3) to obtain a fresh token when the user starts a call. For the Web SDK, pass it as `recaptchaToken` to `createWebCall()`. For the website widget, configure its [reCAPTCHA site key](/deploy/chat-widget#recaptcha-protection). # Opt in to secure URL Source: https://docs.retellai.com/accounts/signed-secure-url Opt in to secure URLs so Retell-generated call recording and log links automatically expire after 24 hours, preventing unauthorized access if a link leaks. # Secure URL By default, the URLs we generate for call recordings and logs do not expire, allowing you to easily share the links with other people. However, if security is a concern and you want to prevent unauthorized access in case the URL is leaked, you can opt in for secure URLs. Secure URLs automatically expire 24 hours after they are generated, providing an additional layer of security. ## How to Opt In You can opt in to secure URLs at any time: 1. Navigate to your agent 2. Toggle the "Opt In Secure URL" switch Privacy settings showing the Opt In Secure URL toggle ## What Happens When You Opt In * Every time you request the URLs of your call's recording and log, we will generate a URL with a signature that will expire 24 hours after it is generated. * Accessing the resource using the URL after 24 hours will be denied. * Files created before secure URLs were enabled will still be generated without signatures. ## What Happens When You Opt Out After Opt In * Files created while secure URLs were enabled will continue to generate signed URLs with 24-hour expiration whenever you request their URLs, even after you opt out. * Only files created after you opt out will generate non-expiring URLs. # Create and manage Retell workspaces Source: https://docs.retellai.com/accounts/workspace Create and manage Retell workspaces, find your workspace ID, invite teammates to collaborate, switch between workspaces, and safely delete a workspace. Learn how to create and manage workspaces, and collaborate with team members. ## Default Workspace When you first create an account, a default workspace is automatically created for you. This workspace serves as your primary environment for managing projects and collaborating with team members. ## Find your workspace ID / org ID Sometimes we might ask for your workspace ID / org ID when debugging issues related to your account. You can find it in your workspace settings page. Open **Settings** from the sidebar: Retell sidebar with Settings highlighted under System Then open **Workspace** → **General**. Your workspace ID appears under **Workspace ID**: Workspace General settings showing Workspace Name and Workspace ID ## Creating Additional Workspaces To create a new workspace: 1. Click the workspace selector in the top left corner of the dashboard 2. Select **Add another workspace** 3. Enter your workspace name 4. Click **Save** Workspace dropdown with Add another workspace highlighted ## Managing Team Members ### Inviting Members To invite team members to your workspace: 1. Open **Settings** → **Workspace** → **Users** 2. Click **Invite a member** 3. Enter their email address and select a role 4. Send the invitation If a team member does not receive the invitation email, you can resend it by inviting them again with the same email address. Workspace Users page with Invite a member button and member list Invite a member dialog with email field and role options Admin, Developer, and Member ### Invitation Process * Invited members receive an email with a link to join the workspace * They can create a new account or use an existing one * Once accepted, they have immediate access Email invitation to join a Retell AI workspace with Accept Invitation button ## Leave a Workspace To leave a workspace: 1. Open **Settings** → **Workspace** → **Users** 2. Click **Leave Workspace** 3. Confirm your action **Important considerations before leaving:** * If you are the only member, leaving permanently deletes the workspace and all its data, and a final invoice is generated for any outstanding usage — the same as [deleting the workspace](#delete-workspace). Your account stays active and you keep access to any other workspaces. * If other members remain but you are the workspace's last admin, you can't leave until another member has the Admin role. Assign Admin to someone else first, or delete the workspace. * You can rejoin a workspace if another member invites you back. Users page with Leave Workspace button ## Delete Workspace Only a workspace **Admin** can delete a workspace. In **Settings** → **Workspace** → **General**, open the options menu (⋯) and select **Delete**, then type the workspace name to confirm. Before deletion, please note: * All workspace data will be permanently deleted and cannot be recovered * A final invoice will be generated and charged for any usage up to the deletion date * All team members will lose access to the workspace * Any active API keys will be invalidated You can't delete your only workspace on its own. If this is the only workspace on your account, deletion is blocked — to remove it, [delete your account](/accounts/account#delete-your-account) from account settings instead. If there is no payment method on file when you delete the workspace, the final invoice is still generated for any outstanding usage and remains due. Add a valid payment method before deleting (see [Add payment methods](/accounts/add-payment)) so the final charge can settle automatically. If a charge fails afterward, follow [Handle failed payments](/accounts/fail-payment) or contact Retell support to resolve the balance. Workspace General settings with Delete option in the options menu Confirmation dialog requiring the workspace name before deleting # Agent workflow Source: https://docs.retellai.com/agent/agent-workflow Run pre-call and post-call functions on a Retell AI agent: look up the caller before the agent speaks, then log the outcome and create follow-ups. An agent's **Workflow** page is where you run functions outside the conversation: before the agent speaks, so it starts already knowing who it's talking to, and after the session ends, so your systems are updated without anyone touching them. Voice agents call these **pre-call** and **post-call functions**; chat agents get the same two slots, named **pre-chat** and **post-chat functions**. A function can be a tool from a [connected provider](/integrations/overview), an HTTP request to your own endpoint, a code snippet, or an SMS. Each slot is a dependency graph rather than a flat list. Functions with no dependency all start at once, and a function that depends on another waits for its output.
The agent's Workflow page, with Workflow highlighted in the left rail next to Agent and Simulation. A flow runs from Dial in/out through pre-call functions, Call started, the Agent node with a knowledge base attached and an Add webhook slot below, Call ended, Post-call data extraction, and Post-call functions. A tool menu for a connection named salesforce retell is open over the pre-call functions node, listing Salesforce tools with Search Contact selected and its description shown. Blue rings mark the Workflow nav item and the Add buttons on the pre-call and post-call function nodes.
Everything below works the same on both channels except where noted. A video walkthrough of the Workflow page, covering pre-call and post-call functions: