Infobip
Global CPaaS provider whose AgentOS platform runs autonomous AI agents across more than fifteen channels, with customer-selected LLMs, a documented quality center, and a fully public developer surface.
Infobip is a global cloud communications platform, one of the largest CPaaS providers in the world, that has spent twenty years building the omnichannel messaging infrastructure it now uses to run autonomous AI agents.
Founded on 13 April 2006 in Vodnjan, Croatia by Silvio Kutic, Izabel Jelenic, and Roberto Kutic on a twenty five thousand euro loan, the company bootstrapped for roughly fourteen years to a billion dollar valuation before taking its first outside funding, over two hundred million dollars from One Equity Partners in 2020, followed by a raise of about five hundred million dollars in 2021.
It reaches billions of devices through direct operator connections in around one hundred ninety countries, and has been a Gartner Magic Quadrant Leader for CPaaS for four consecutive years.
AgentOS, released to customers on 1 April 2026, is the platform Infobip now sells. It consolidated four products that were previously separate, Moments, People, Answers, and Conversations, whose names were retired in March 2026 and which now exist as modules inside it.
AgentOS comprises five products that share data and context: AI Agents, the autonomous layer where agents use large language models, tools, and integrations to complete multi-step tasks; Automation Studio, for journey flows and no-code chatbots; Inbox, where conversations hand off to human agents with the full history intact; Insights and Analytics, which tracks performance, tool usage, and session-level detail across everything; and Customer Profiles, the customer data platform holding profiles, segments, and behavioral events. Voice AI agents extend the same agents onto phone calls.
Building an agent is a documented workflow rather than a black box. The customer writes instructions that act as the system prompt, attaches tools as reusable components, MCP servers, or partner integrations, optionally makes the agent an orchestrator that delegates to specialist subagents, and selects the underlying LLM against reasoning, latency, and cost.
Content-filter guardrails constrain what the agent will discuss, and each MCP connection carries an explicit list of the actions it is allowed to take. Agents are versioned, activated deliberately, and can be rolled back, exported, and imported. A dedicated Quality center lets teams build test groups and cases, run them, and review results, validating responses against expected answers and tracking quality over time.
Because Infobip owns the underlying network, it delivers agentic communication at carrier scale, and it pairs that with identity, authentication, and fraud prevention products for regulated industries.
The developer surface is unusually open: a public API reference, SDKs, roadmap, and integrations catalog all reachable without a login, and the legal tier (sub-processors, data transfer agreement, retention notice, downloadable certificates) published rather than gated.
Infobip is audited annually against ISO 27001, 27017, 27018, and 22301 and the ISAE 3000 standard, with reports available on request, and the platform offers SAML 2.0 single sign-on, custom role-based access control, two-factor authentication, and IP safelisting.
For a large enterprise that needs autonomous customer communication across every channel and country with carrier-grade reach and a real developer surface, Infobip is a strong option. AI agents run in five named data centers across Europe, Sweden, Germany, India, and the United States, with no self-hosted or single-tenant option, so a buyer with strict residency requirements should confirm placement in contract. A small team wanting a simple single-channel chatbot will find the platform far larger than it needs.
Vendor details
Canonical URL
https://www.infobip.com
Category
Customer support agent
Subcategory
Agentic CPaaS and customer engagement
Funding status
Independent, headquartered in London with roots in Vodnjan, Croatia, founded on April 13, 2006 by Silvio Kutic, Izabel Jelenic, and Roberto Kutic. Bootstrapped for roughly fourteen years on a twenty five thousand euro loan to a billion dollar valuation before its first external funding, over two hundred million dollars from One Equity Partners in 2020, followed by a raise of about five hundred million dollars in 2021 ahead of a planned public listing. Employs more than four thousand people across seventy five offices, reaches over seven billion devices in one hundred ninety countries, and is a four time Gartner Magic Quadrant Leader for CPaaS.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Spans more than fifteen natively integrated channels including SMS, RCS, WhatsApp, Viber, email, voice, video, live chat, mobile push, Messenger, Instagram, Telegram, Apple Messages for Business, Kakao, Line and Zalo, each published with its own REST API, backed by direct operator connections worldwide. Developers get a fully public API reference, SDKs, Postman collections, a GitHub organization and a published roadmap, plus the modular CPaaS X stack for platforms building on top. AI agents extend through three documented tool types: reusable Components running backend logic, MCP servers configured with an endpoint, authentication headers and a scoped allowed-functions list, and Exchange applications from the partner integrations catalog. Agent configurations can be viewed as code, exported and imported between workspaces.
In practice
Your customer conversations are scattered across SMS, WhatsApp, email, voice, and social, each managed separately. Infobip AgentOS runs autonomous agents across all fifteen plus channels from one orchestration layer with a shared view of the customer.
You want an AI agent that can actually do things, not just chat. Infobip's built in MCP servers let agents act on third party systems to book a flight, verify identity, or resolve a billing issue end to end.
You need to automate customer communication at global scale without losing compliance. Infobip pairs agentic AI with carrier grade reach, identity, authentication, and fraud prevention across one hundred ninety countries.
Sources & related URLs
Research sources
Agentic Index coverage score
12.0 / 14 capabilities · 86%
| Integrations & Tool Calling | Full |
|---|---|
|
Three named tool types with authenticated action, configured per agent. In the Tools section a customer adds a Component, an MCP server or an Exchange application. Tools are documented as letting the agent call APIs, execute backend logic, retrieve external data and trigger automated workflows. Components encapsulate reusable logic and can orchestrate multiple API calls or backend processes for complex integrations. MCP servers are configured with a name, endpoint URL, HTTP headers for authentication tokens, and an Allowed functions field naming which actions the server may take when called, so the connection is authenticated and scoped rather than open. Exchange applications are selected from a published integrations catalog. Underneath sits the messaging estate the agent acts through: more than fifteen natively integrated channels each with its own API, plus the modular CPaaS X stack. Sourceinfobip.com/docs/ai-agents/ai-agents/configure-ai-agentread 2026-09-05 |
|
| Workflow Orchestration | Full |
|
Named multi-agent delegation plus a rule-based flow layer, both documented as product surfaces. An AI agent can be configured as an orchestrator that coordinates other agents: the customer adds subagents from a list, and the orchestrator delegates tasks to specialized agents, combines their responses and controls conversation routing, with the agents table showing a connected-subagents count for orchestrators. Each agent's Description field is documented as what other agents read to decide when to call it, which is a published delegation contract rather than an implied one. Beneath that, Automation Studio builds journey flows and chatbots that route on rules, triggers and Customer Profiles data, and the Agent connector element drops an AI agent into a chatbot so deterministic flows and autonomous agents combine in one path. Agents themselves execute multi-step tasks, calling tools in sequence to reach a goal. Sourceinfobip.com/docs/ai-agents/ai-agents/configure-ai-agentread 2026-09-05 |
|
| Knowledge Grounding & RAG | Full |
|
A maintained retrieval structure published as its own product line. Knowledge agents are documented as specialized agents for information retrieval from documents, URLs and files, purpose-built for FAQ-style interactions, and they sit alongside a Knowledge Base shared component available across AgentOS. The corpus is maintained rather than assembled per request: Quality center carries a dedicated Knowledge agents section that validates responses against expected answers and tracks quality over time, which only makes sense against a persistent body of content the customer curates. General-purpose AI agents reach the same material through tools and components. The Customer Profiles data platform is a database rather than a grounding corpus. Sourceinfobip.com/docs/ai-agents/knowledge-agents/overviewread 2026-09-05 |
|
| Human Oversight & Guardrails | Full |
|
A configuration surface the operator sets, plus a documented escape path to a person. Guardrails are an explicit field in the agent's Advanced settings with their own configuration page: the customer selects content filters that detect and block harmful content in agent conversations, controlling what the agent can and cannot discuss. Release control sits with the customer too, since a configured agent stays a draft until a named version is created and explicitly activated for production, with earlier versions available to roll back to. Scope on outbound action is set per tool, with each MCP server carrying an Allowed functions list naming what it may do when called. When automation reaches its limit the conversation transfers to Inbox with the complete history so the human agent does not restart the customer, and that human works with an Inbox copilot. No pre send approval step on an individual agent action is documented, so oversight comes from filters, scope and escalation rather than sign off on each action. Sourceinfobip.com/docs/ai-agents/ai-agents/configure-guardrailsread 2026-09-05 |
|
| Security, Identity & Governance | Full |
|
Attestation and access are both documented. Infobip's own Information Security Terms state it is regularly audited against ISO/IEC 27001, 27017, 27018 and 22301 and the ISAE 3000 standard, assessed annually, with certificates available for download at infobip.com/certificates and a full or summary copy of current reports provided on written request, which is an obtainable report rather than an asserted badge. A dedicated HIPAA attestation under SSAE 18 is published in Infobip's own newsroom. The legal tier is public rather than gated: sub-processor list, data transfer agreement, data retention notice and privacy notice all publish at named URLs. On access, the docs cover single sign on through any SAML 2.0 identity provider with SP-initiated flow and identity-provider groups mapped to custom roles and re-synchronized on every login, role-based access control with predefined and custom roles governing per-feature permissions, two-factor authentication configurable as remembered or on each login, password validity and maximum login attempt policies, IP safelisting, and separate API access permissions. Infobip's identity, authentication and fraud prevention products are things it sells to its customers, not controls over the customer's own tenant. Sourceinfobip.com/docs/essentials/manage-my-account/account-settingsread 2026-09-05 |
|
| Observability & Auditability | Full |
|
Per-run visibility plus change control, both named in the docs. Insights and Analytics is one of the five AgentOS products and is documented as monitoring AI agent performance, tool usage and session tracking through dedicated dashboards, with every interaction across all five products feeding it and the output covering performance metrics, root causes and AI-driven recommendations. Tool usage and session tracking is a record of what an individual agent did, not only an aggregate. From inside an agent, Go to Session history opens previous sessions with their associated analytics, and View as code renders the running configuration. Change is auditable separately: agents autosave up to ten draft versions, named versions are created and activated deliberately, and version history records what was live when. No immutable audit log with actor and timestamp for configuration changes is documented, so what exists is execution visibility plus version control rather than a compliance grade trail. Sourceinfobip.com/docs/insights-and-analyticsread 2026-09-05 |
|
| Memory & State Persistence | Partial |
|
A customer data store is documented and an agent memory layer is not, and these are different things. Customer Profiles is AgentOS's customer data platform, holding person and company profiles, attributes, segments and behavioral events, with interaction history available to AI agents so they can personalize responses and make context-aware decisions across sessions. Agents also carry session state within a conversation, and past sessions are viewable through Session history. A database is not a memory layer whoever writes it, and Customer Profiles is published as exactly that, a store the customer loads and queries rather than state the agent forms and retains. There is no agent memory product, no documented scope, lifetime or deletion control for retained agent state, and no memory entry in the AgentOS product set. Sourceinfobip.com/docs/customer-profilesread 2026-09-05 |
|
| Deployment & Data Residency | Partial |
|
Multi-region placement is documented by name, customer-controlled selection of it is not. The AI Agents documentation states outright that AI agents are available only in the following data centers: Europe (EU1), Sweden (SE1), Germany (FR4), India (MUNM) and United States (NY2), so an account sits in a named region across three continents and the buyer can tell which. Around that Infobip publishes the full legal tier rather than gating it: a sub-processor list, a data transfer agreement, a data retention notice and a privacy notice, each at its own public URL, plus an infrastructure overview and network connectivity options in the docs. No self service or documented mechanism for the customer to choose or move their region is published, placement appears to be set at account provisioning, and no on premise, private cloud or single tenant deployment is offered. Sourceinfobip.com/docs/ai-agents/ai-agents/overviewread 2026-09-05 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Adoptable units the buyer picks from a list rather than assembles. Agent instructions can be populated from predefined templates named in the docs as Appointment booking agent, Order status assistant and Sales representative, and Automation Studio carries its own predefined and custom templates to speed up journey and chatbot creation. Agents are portable as assets: an existing agent can be duplicated, exported to a.export file and imported into another workspace, so a configured agent moves as a unit. Components are reusable logic blocks selected from a list and shared across agents. Above all of it, AgentOS itself ships as five named products a customer switches on rather than builds. The template set is small, and there is no browsable marketplace of ready made agents. Sourceinfobip.com/docs/ai-agents/ai-agents/configure-ai-agentread 2026-09-05 |
|
| Triggers & Channel Coverage | Full |
|
A very wide channel surface, with three documented ways for work to start. Channels: WhatsApp, SMS, RCS, MMS, email, voice, live chat, video, in-app messaging, mobile push, Viber, Messenger, Instagram, Telegram, Apple Messages for Business, Kakao, Line and Zalo, each published with its own API page, and all of them flowing through the same system. Initiation is documented three ways: inbound, where a customer reaches out on any supported channel; event-driven, where Automation Studio journey flows are triggered by customer behavior or profile changes; and scheduled, where journeys start on dates. Voice is first-class rather than bolted on, with a Transfer call to AI agent element placing an agent inside an IVR flow, and Broadcast handles outbound at volume. Sourceinfobip.com/docs/automation-studioread 2026-09-05 |
|
| Model Flexibility & Routing | Full |
|
The customer picks the model, and it is a field in the product rather than an inference. Under Advanced settings when configuring an AI agent, Model is documented as: select the LLM model that best matches your requirements for reasoning capability, latency and cost. That is per-agent selection by the buyer against stated trade-offs, and it sits alongside Guardrails and structured output in the same settings panel. The Instructions field is described as acting as the system prompt for the underlying language model, confirming the customer configures the model layer directly. Third party agents reaching Infobip through MCP is interoperability, not model choice. Sourceinfobip.com/docs/ai-agents/ai-agents/configure-ai-agentread 2026-09-05 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
An open, fully public developer surface, which is unusual. Infobip publishes an API reference, SDKs, release notes, an integrations catalog and a public roadmap, all reachable without a login, plus Postman collections, a GitHub organization and a developer Discord. Every channel is exposed as its own REST API and the modular CPaaS X stack is sold specifically for platforms building on top. On the agent side extensibility runs both directions: MCP servers let an Infobip agent call outside systems with scoped allowed functions, and an agent's configuration can be viewed as code, exported to a portable file and imported elsewhere, with structured output constrained by a customer-defined JSON schema. Components let a developer encapsulate backend logic the agent then calls, and Exchange applications add partner integrations. Sourceinfobip.com/docs/apiread 2026-09-05 |
|
| Testing, Debugging & Optimization | Full |
|
A dedicated evaluation product with a readable comparable result. AgentOS ships Quality center, documented as tools to monitor, evaluate and improve agent response quality, where the customer creates test groups, defines test cases, runs tests and reviews results to confirm agents behave as expected. For Knowledge agents it is stated as validating responses against expected answers and tracking quality over time, which is a scored comparison rather than a bare pass gate. Separately, the build flow carries a pre-publish step, Test an AI agent, described as validating agent responses and behavior before publishing, and agent versioning lets a team activate a specific version and roll back a bad one. The artifact under test is the customer's own agent. Sourceinfobip.com/docs/ai-agents/quality-center/overviewread 2026-09-05 |
|
| Browser & Computer Use | Not documented |
|
No browser control, hosted session, virtual desktop or interface automation appears anywhere in the AgentOS documentation, and the route out is stated positively rather than as a silence. An Infobip agent reaches the world through exactly three documented tool types, all programmatic: Components running backend logic, MCP servers called at an endpoint URL with scoped allowed functions, and Exchange applications from the integrations catalog. Its output side is the messaging estate, more than fifteen channels each with its own API. Nothing in the agent configuration surface offers a browser, a screen or a pointer. Sourceinfobip.com/docs/ai-agents/ai-agents/configure-ai-agentread 2026-09-05 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Infobip has acquired SocketLabs, a US-based email infrastructure provider known for high-volume email routing. The transaction integrates SocketLabs' vendor-agnostic observability and intelligent routing analytics into Infobip's platform to enhance its AI-powered Email Deliverability Agent.
Bears on: Observability / auditability
View sourcePricing
No published platform rate. Channel messaging is pay-as-you-go per message by country and message type; the AgentOS subscription and processing fee are quoted through sales
per message and interaction by channel and country, plus platform tier
What is public
Channel rate cards are public and detailed: SMS pay-as-you-go with a cost estimator, and WhatsApp priced per message across utility, authentication, international authentication, marketing and free-form categories, with a calculator for destination country, currency and expected volume. A dedicated AgentOS pricing page publishes the structure but no figures, stating that the processing fee applies to outbound messages only, that inbound is always free, and that CPaaS delivery fees vary by region and volume. The platform subscription itself is not published.
Billing mechanics
Layered. An AgentOS platform subscription sits underneath, quoted through sales. On top, a processing fee is charged per outbound message, with inbound messages stated as always free. Beneath both, CPaaS delivery fees cover carrier and channel costs for WhatsApp, SMS, RCS and others, varying by region and volume. Channel pricing is pay-as-you-go with published rate cards and a calculator taking destination country, currency and expected volume by category.
Cost watchouts
Premium channels such as voice and international SMS, plus carrier and operator fees, ride on top of the platform cost and can dominate the bill.
Variable cost rationale
Cost is dominated by per message and per interaction charges that vary by channel and destination country, with telco fees passed through, so spend scales directly with volume and geography rather than a flat platform fee.
Additional watchouts
Three layers compound, so a channel rate card alone will understate the bill: model the platform subscription, the outbound processing fee and carrier delivery together. WhatsApp is priced per message with separate rates for utility, authentication, international authentication, marketing and free-form, so the message mix matters as much as the volume. Rates vary widely by destination country and telco surcharges apply. The 60-day trial is a capped sandbox for evaluation, sending only to your own verified number or address on shared test senders, so it will not support a realistic pilot.
Sales call required
Mixed (some tiers require a call)
Free / trial
60-day free trial with capped test volumes to a verified number or address; self-serve signup. No persistent free tier.
Key ambiguities
The AgentOS platform subscription and the per-message processing fee are both unpublished, so the agentic layer cannot be costed from public pages even though channel rates can.
Related vendors
- Decagon — AI agent platform purpose-built for customer support, with deep…
- 5.Y — Singapore early-stage platform whose GLUCOSE product deploys…
- Ada — Agentic customer experience platform whose AI agents autonomously…
- Aisera — Enterprise agentic AI platform that orchestrates specialized agents…
- ASAPP — Generative AI for enterprise contact centers that plugs into…
- Assembled — AI customer support orchestration platform that unifies autonomous…
Alternatives to Infobip
The closest documented capability profiles to Infobip among customer support agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- ElevenAgents12.5 / 14Fuller documented coverage on Deployment & Data Residency
- Five911.5 / 14A lighter documented profile than Infobip
- Gallabox11.5 / 14A lighter documented profile than Infobip
- Quiq11.5 / 14A lighter documented profile than Infobip
- Ada11.0 / 14A lighter documented profile than Infobip
- Aisera11.0 / 14A lighter documented profile than Infobip
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded