Skip to navigation

New Features & Improvements

  1. Alert notifications — every alert on an account’s Alerts page can also be pushed, as it happens, to up to five destinations: a JSON webhook, Slack, PagerDuty or email. Add them in the account’s Settings → Notifications, and send a test to any one destination. An account is notified about the same type of alert at most once an hour. The same destinations can be managed through the API (/Accounts/{AccountSid}/AlertHooks).
  2. Support audio capture opt-out — jambonz support keeps SIP and RTP from calls for a few days to troubleshoot call quality. An account can now turn this off in Settings → Privacy, and an organization can allow it for all accounts, disable it for all accounts, or leave it to each account. Recent Calls SIP traces are not affected.
  3. Speechify text-to-speech — speechify is available as a TTS vendor, with speech credentials in the portal and API.
  4. KugelAudio text-to-speech — kugelaudio is available as a TTS vendor, including streaming TTS.
  5. Zoom Scribe speech-to-text — Zoom is available as an STT vendor.
  6. ElevenLabs eleven_v3 and eleven_v4 — streaming TTS with these models, including eleven_v3_conversational and its audio tags (such as [laughs]), uses ElevenLabs’ Text to Dialogue stream. The synthesizer language is now sent to ElevenLabs instead of being detected on each turn, and the models are listed in the portal.
  7. AssemblyAI Universal-3.6 Pro — new AssemblyAI credentials default to universal-3-6-pro, and assemblyAiOptions accepts languageCodes and voiceFocus. Newer models are now sent 16 kHz audio instead of 8 kHz.
  8. OpenAI GPT-Live — the GPT-Live speech-to-speech integration uses OpenAI’s GA protocol.
  9. Per-account API rate limits — the API server counts requests per account for call creation (4000/min) and call status reads (600/min), per caller address for everything else, and per address for sign-in and sign-up. Counts are shared by all API server workers, and a client over a limit receives 429. Every limit can be changed with an environment variable.
  10. SRTP for TLS-registered devices — calls to a SIP client that registered over TLS are offered SDES-SRTP, so encrypted signaling gets encrypted media. Set JAMBONES_DISABLE_SRTP_FOR_TLS to keep plain RTP. (jambonz.cloud keeps plain RTP for now.)
  11. AWS scale-in without SNS — SIP servers, RTP servers and feature servers drain on scale-in by polling the instance metadata service for their target lifecycle state. They no longer subscribe to an SNS topic or open a port for it. When a SIP server holding the carrier registrations scales in, it hands them to another SIP server before it stops. Registrations now use a Call-ID per SIP server, so a carrier sees a move between servers as a new registration.
  12. Enterprise user limits — an organization’s user limit can be raised per organization, and the portal’s Users view follows the limit the API reports.
  13. SIPREC application in the new portal — the account setting for the application that handles SIPREC calls is back in the new portal.
  14. Self-hosted updater — the update client upgrades itself when a release requires it and can apply several releases in one run.
  15. Security hardening — service-provider users can no longer write operator-only organization or account fields; carrier changes by non-admin users stay within their own organization or account; and calls from a registration trunk’s address now match only carriers that belong to the called SIP realm’s account.
  16. Fewer caller details in logs — caller transcripts and DTMF digits are logged at debug, not info.

Bug Fixes

  • Agent verb — the caller’s turn ends normally when Krisp is used only to predict interruptions; speech that arrives while the assistant is talking is held for the next turn instead of being dropped; interrupt prediction only interrupts the assistant while it is speaking; and VAD is used only for turn timing when the STT vendor reports the start of speech itself.
  • Answering machine detection — empty final transcripts no longer count as a human, Deepgram endpointing defaults to 150 ms during detection, and built-in voicemail hints are used when none are configured.
  • Gather with Deepgram — an interim word that Deepgram later drops no longer delays every following UtteranceEnd, and a deferred UtteranceEnd returns the transcript as soon as it is satisfied.
  • Soniox — v5 sub-word tokens are joined correctly (“I have Optum.”, not “I have O pt um.”).
  • Google Gemini transcription — SMART mode no longer fails with languageCodes set.
  • Deepgram warm connections — options that change between transcriptions (for example new Flux keyterms) are applied when a parked connection is reused.
  • TTS — a say no longer hangs when the TTS vendor rejects the request, and streaming TTS starts cleanly after a barge-in.
  • Conference — distributeDtmf and speakOnlyTo work without another join option set.
  • Media timeout — JAMBONES_MEDIA_TIMEOUT_MS now ends calls on mediajam feature servers.
  • Dialogflow — a dialogflow verb with no TTS vendor no longer looks up TTS credentials.
  • Debug logging — every leg of a call follows the account’s debug log setting.
  • SIP — a re-INVITE rejected with 422 no longer leaks resources in drachtio; licensed SBCs issue a fresh session token with each provisional and final response, so calls that ring longer than 40 seconds keep their audio; TLS registrations record their transport; and calls forwarded to a sips: Request-URI use a sips: Contact and From.
  • Billing — after a failed renewal the portal shows the suspended subscription and asks for a new card, instead of offering an upgrade that created a second subscription.
  • Portal — the call logs panel tells a failed request apart from a call with no logs.
  • License keys — whitespace pasted with a license key is trimmed.

Upgrade Notes (self-hosted)

  • Database — 11.1.6 adds the alert_hooks table and three columns; run the database upgrade before starting the new API server.
  • AWS scale-in — set AWS_LIFECYCLE_DRAIN=1 on inbound, sbc-sip-sidecar and feature-server, and on sbc-rtpengine-sidecar on dedicated RTP servers. Allow the instance roles autoscaling:DescribeAutoScalingInstances and autoscaling:DescribeLifecycleHooks (in addition to autoscaling:CompleteLifecycleAction). AWS_SNS_TOPIC_ARN no longer turns on draining, and the SNS topics and their open ports can be removed.
  • API server behind a reverse proxy — set JAMBONES_TRUST_PROXY=1 and have the proxy send X-Forwarded-For. Without both, all callers share one rate-limit counter.
  • Recordings — the API server’s built-in recording websocket is removed; recordings are handled by upload_recordings.
  • Audio capture opt-out — the Privacy settings appear in hosted portal builds with JAMBONES_OPT_OUT_VOIPMONITOR=true. The opt-out only takes effect if voipmonitor is configured with norecord-header = yes.

Component Versions

Component11.1.511.1.6
jambonz11.1.511.1.6
mediajam0.5.80.5.10
drachtio10.1.510.1.6
rtpengine14.1.1.8-jambonz1414.1.1.8-jambonz14
jambonz OSS (sbc-*)0.9.120.9.14
upload-recordings1.9.11.9.1
monitoring-agent10.2.210.2.2
pcap-server1.0.41.0.4
heplify-server1.0.41.0.4

Availability

jambonz.cloud - available now

self-hosted - coming soon

New Features & Improvements

  1. Modulate (Velma) streaming STT — modulate is available as a speech-to-text vendor, with speech credentials in the portal and API.
  2. Google Gemini transcription — Gemini can be selected as a speech-to-text vendor, including from the portal.
  3. Speechmatics STT in the agent verb — Speechmatics can be used as the recognizer for the agent verb.
  4. Azure Voice Live speech-to-speech — Azure Voice Live is available as a speech-to-speech vendor.
  5. xAI recognizer model option — xaiOptions.model pins the xAI transcription model instead of following xAI’s default.
  6. Inworld TTS 2 Flash — inworld-tts-2-flash is available alongside inworld-tts-2, a lower-latency, lower-cost variant with word timestamps.
  7. Per-call codec preference on dial — the dial verb accepts codecs, a list of codec names in preference order for the outbound leg (for example ["G722","PCMU"]). With no list set, the outbound offer leads with the codec negotiated on the A leg. An invalid or unsupported name drops the list, raises an invalid-app-payload alert, and falls back to default negotiation. codecs is also documented on the createCall REST API.
  8. Noise isolation on REST-created calls — noise isolation can be enabled when creating a call through the REST API, so it can be combined with answering machine detection without a separate config verb.
  9. Dialogflow CES session resume — a dialogflow CES session can be resumed.
  10. License details in the portal — self-hosted installs show the key details of the installed license in the portal.
  11. Nested transcribe data in the portal — transcripts from a background transcribe are displayed in the call view.
  12. Security hardening in the API server — this release includes fixes for issues found in a security review:
    • privilege-escalation fixes in user management;
    • an account can no longer write operator-only fields or limits;
    • password-reset links are single-use;
    • sign-in and password reset no longer reveal whether an account exists, and failed attempts are rate-limited;
    • customer-supplied destinations and speech-vendor addresses may no longer point inside the platform network;
    • the call-logs route can no longer read arbitrary CloudWatch log groups.

Bug Fixes

  • AWS autoscale scale-in — SIP servers now complete scale-in once every inbound and outbound process is idle, and reject new INVITEs while draining. Feature servers coordinate the lifecycle action across all pm2 workers instead of completing it when the first worker goes idle.
  • Call sessions after a lost app connection — a WebSocket app connection that dies can no longer leak a call session, and connect failures stop retrying after their budget.
  • Calls transferred between feature servers — pre-answer call statuses are no longer re-sent, and SIPREC recording continues across the transfer.
  • Dial with no actionHook — the call ends when dial finishes with no actionHook, or with a failed one.
  • Max call duration — the timer is cleared when jambonz ends the call.
  • Dialogflow CES — the verb completes when the stream errors, and cleans up on end_session.
  • Google speech-to-speech — toolHook replies no longer end the Gemini session.
  • Webhooks — non-2xx webhook responses now write a webhook-status-failure alert, and late webhooks are sent after the shared client has closed.
  • Media server connection errors — handled instead of crashing the feature server.
  • DTMF privacy — DTMF digit values are no longer logged.
  • tag data in LLM tool calls — the tag verb’s customerData is included in the llm:tool-call hook.
  • IMDSv2 — EC2 instance metadata is read with IMDSv2 tokens in the SNS lifecycle notifiers.
  • SIP realm validation — account sip_realm values are trimmed and validated, and self-hosted installs no longer call a DNS provider for them.
  • Portal — Home’s live counters refresh, and paid customers are no longer asked to re-enter a card to change plan.

Component Versions

Component11.1.411.1.5
jambonz11.1.411.1.5
mediajam0.5.40.5.8
drachtio10.1.410.1.5
rtpengine14.1.1.8-jambonz1114.1.1.8-jambonz14
jambonz OSS (sbc-*)0.9.90.9.12
upload-recordings1.9.01.9.1
monitoring-agent10.2.110.2.2
pcap-server1.0.41.0.4
heplify-server1.0.41.0.4

Availability

jambonz.cloud - available now

self-hosted

  • AWS - available now
  • Azure - available now (amd64 and arm64)

New Features & Improvements

  1. Roark and Coval as call-evaluation vendors — a call’s recording and transcript can be posted to an evaluation provider for automated scoring. Both vendors are selectable in the portal’s call-evaluation vendor selector, with credentials stored and masked like any other vendor key.
  2. Signup links in the evaluation credential form — when no evaluation API key is set, the portal shows a signup link for the selected vendor (Coval or Roark) and hides it once a key is entered. The verbose help text under the key field was removed and the Test link placement made consistent across the hosted console.
  3. sip_reason_header in the status callback — the SIP Reason header is now included in status callback payloads, so the reason a call ended is available to applications without inspecting SIP traces.
  4. Presigned GCS URLs for recordings — upload-recordings 1.9.0 generates presigned URLs for recordings stored in Google Cloud Storage, matching the behaviour already available for S3.
  5. Portal alerts when a recording upload fails — a failed POST from upload-recordings now raises an alert in the portal instead of failing silently.

Component Versions

Component11.1.311.1.4
jambonz11.1.311.1.4
upload-recordings1.8.61.9.0
mediajam0.5.40.5.4
drachtio10.1.410.1.4
rtpengine14.1.1.8-jambonz1114.1.1.8-jambonz11
jambonz OSS (sbc-*)0.9.90.9.9
monitoring-agent10.2.110.2.1
pcap-server1.0.41.0.4
heplify-server1.0.41.0.4

Availability

AWS — AMIs are published for all nine deployment variants (mini, fs, sip-rtp, sip, rtp, web, monitoring, web-monitoring, recording) on both amd64 and arm64, in all 30 supported regions. The AMIs and their EBS snapshots are public, so generate-cf.sh can copy them from any account. A mini deployment was verified end to end on this release.

Debian packages — jambonz-mini and jambonz-common 11.1.4 are published in the apt repository for both amd64 and arm64, alongside upload-recordings 1.9.0. See the Debian package instructions.

Bug Fixes

  1. drachtio could not reach a MySQL server on a non-standard port — license validation opens a connection to the jambonz database to check the licensed domain, and the port was not configurable: drachtio always used 3306. Where the database listens elsewhere, that connection blocked for the full TCP timeout on every attempt (roughly two minutes), the license never validated, and the server refused every call with 480 Temporarily Unavailable - Unlicensed. Registrations still succeeded, which made the symptom look like a media or networking fault rather than a licensing one. drachtio 10.1.4 adds JAMBONES_MYSQL_PORT (default 3306), and the self-hosting images now pass the port through. This affected Exoscale medium and large only, where the managed database service allocates a per-service port.

Availability

Exoscale — qcow2 images are published for all nine deployment variants at 11.1.3. Exoscale templates cannot be shared between accounts, so deploying starts by registering the images into your own account:

cd terraform/exoscale
./prepare-images.sh --version 11.1.3

then terraform apply in provision-vm-mini, provision-vm-medium or provision-vm-large. Both the mini and medium layouts were verified end to end on this release. The large layout carries the same fixes but has not yet been deployment-tested.

New Features & Improvements

  1. Mutual TLS (mTLS) for self-hosted servers — drachtio can present a client certificate on outbound TLS connections, so a carrier or SIP peer that requires mutual authentication can be reached from a self-hosted deployment. See Mutual TLS for how to obtain a client certificate and configure it.
  2. nineninesix.ai TTS — Added nineninesix.ai (gepard-1.0) as a text-to-speech vendor for say, with speech-credential support in the API and the portal. The model emits no word timestamps, so playout tracking is unavailable on it.
  3. Sub-account cap per enterprise organization — An enterprise organization can be limited to a maximum number of sub-accounts.

Bug Fixes

  • 3DS authentication on capacity changes — Changing subscription capacity failed on any card requiring SCA/3DS, because the API returned a bare failure and dropped the client_secret, so the browser could never present the challenge. Cards that always require authentication — every Indian-issued card, for one — could not complete a capacity change at all. The API now returns the client_secret, and the portal runs the challenge instead of reporting success while the capacity was unchanged.
  • India e-mandate ceiling — Registers an e-mandate ceiling with headroom, and surfaces invoices that require additional factor authentication.
  • stt_ms reported 0 on the agent verb — stopTalking was clobbered after the final transcript, so speech-to-text latency always came back as zero.
  • tts_ms missing or wrong on the agent verb — Vendor TTS time is now reported in tts_ms, and a flush race that dropped the measurement entirely is fixed.
  • noResponseTimeout with the greeting disabled — The agent verb now arms noResponseTimeout at the start of the call when no greeting is configured.
  • TTS connect-failure alerts were dropped — A streaming connect failure passed an object into the InfluxDB vendor tag, and the tag escaper threw on it, losing the alert.
  • Speechmatics credential test — Testing a Speechmatics credential crashed, and the preview sent an invalid StartRecognition message.
  • Enterprise cold login — A cold login landed enterprise users on Accounts instead of Home, because beta eligibility was read before the JWT had populated access.
  • Google OAuth rootDomain — Fixed the root domain used for Google OAuth.
  • app_env dropdown — The dropdown now shows the initially selected option.

Availability

AWS — AMIs are published for all nine deployment variants on both amd64 and arm64, in all 30 regions the CloudFormation templates support. See the AWS installation instructions to deploy a self-hosted cluster.

Debian packages — jambonz-mini 11.1.2 is published in the apt repository for both amd64 and arm64, installable on a fresh Debian 12 (bookworm) host with apt-get install jambonz-mini. See the Debian package instructions.

New Features & Improvements

  1. Deepgram Flux TTS — Added Deepgram’s Flux model as a text-to-speech vendor across the feature-server, API server, and webapp.
  2. Gradium TTS — Added Gradium as a text-to-speech vendor.
  3. Inworld streaming TTS — Inworld TTS streams with word-level alignment, and the API adds the inworld-tts-2 generation. The older tts-1 generation is deprecated.
  4. Qwen Omni-Realtime (speech-to-speech) — Added Alibaba’s Qwen Omni-Realtime (Qwen-Audio-3.0) as a speech-to-speech vendor for the agent verb.
  5. OpenAI GPT live — Added OpenAI’s GPT live models for speech-to-speech, and OpenAI live transcription is selectable for transcribe.
  6. xAI and Resemble in the portal — The webapp exposes xAI and Resemble text-to-speech options in Extra Options.
  7. Speechmatics filtering — Speechmatics accepts filtering configuration.
  8. Dialogflow CX tool calls — Dialogflow CX supports a client-side tool-call round trip through toolHook.
  9. Dialogflow CES tool calls, streaming playout, and observability — Dialogflow CES supports the same client-side tool-call round trip, streams playout as it arrives, and reports turn-by-turn detail. Recent Calls in the portal has a turn-by-turn transcript view for Dialogflow sessions.
  10. Per-member conference recording — listen accepts scope=members at the conference level, producing one fork per participant instead of a single mixed stream.
  11. Remote party on conference participants — Conference participants report the remote party’s number.
  12. SRTP on outbound SIP URI calls — dial accepts srtpEncryption for SIP URI targets, and the SBC honors the X-Jambonz-SRTP header on forwarded SIP URI calls. rtcp-mux is now the default for SRTP on both inbound and outbound.
  13. transfer onholdHook — The transfer verb and handoff accept an onholdHook.
  14. Multi-arch Docker images — The feature-server, API server, webapp, inbound, and outbound images are built for both amd64 and arm64.

Removals

  1. SMPP removed — SMPP support has been removed from the feature-server, API server, and webapp.
  2. FreeSWITCH dependencies removed — Integration tests run against mediajam, and the cron jobs no longer reference FreeSWITCH.

Bug Fixes

  • transfer/handoff caller ID — A transfer or handoff no longer loses the caller ID.
  • Speech-to-speech teardown — Speech-to-speech sessions are torn down cleanly.
  • DTMF — lcc_DTMF prefers RFC 2833 through the media server.
  • say on the streaming path — The say verb executes correctly when streaming.
  • Ultravox errors — A failed call registration reports the real underlying error rather than a generic failure.
  • Outbound SDP — The SBC no longer emits an SDP m= line with no audio codec.
  • 3PCC detection — Inbound no longer misidentifies certain calls as third-party call control.
  • CLI environment — The API server loads the ecosystem environment in the bin/ and upgrade-db CLIs.
  • SSO login — SSO login no longer returns a 500 for enterprise users, and service-provider-scoped users are no longer redirected to registration after signing in.
  • Enterprise upgrade billing — Upgrading an enterprise account keeps the customer’s existing Stripe subscription.
  • Portal — Users land on Home after opting into the new console; the carrier KYC prompt is hidden when prepaid isn’t offered; the placeholder “Est. next invoice” card is parked; and the enterprise welcome dialog no longer pushes account creation.