S

SMS Gateway Developer Docs

Centralized transactional, OTP, and promotional SMS API

Back to dashboard

Send SMS through one gateway

Apps send SMS requests to this Worker using an account app API key. The gateway validates the request, stores the message, queues delivery, and sends through active provider profiles such as Fast2SMS and 2Factor.

Endpoint active on this deployment

Quick Start

  1. Create or select an account in the dashboard.
  2. Add at least one app key for that account.
  3. Add sender IDs if you want to restrict API callers to approved DLT headers.
  4. Add at least one active provider profile, such as Fast2SMS or 2Factor.
  5. Call POST /api/v1/send with the app key in the Authorization header.

Authentication

Every API request uses a gateway app API key. The key is shown only once when you create an app key in the dashboard.

HeaderValue
AuthorizationBearer YOUR_APP_API_KEY
Content-Typeapplication/json

Do not expose app API keys in public frontend code. Keep them in backend environment variables.

Send Endpoint

MethodPathDescription
POST/api/v1/sendQueue an SMS for delivery.

Payload Reference

FieldRequiredDescription
toYesOne phone number or an array of phone numbers. Use E.164 style, for example +919876543210.
messageYesSMS body. Keep the text aligned with your approved DLT template when required.
messageTypeNotransactional, otp, or promotional. Defaults to transactional.
senderIdNoDLT sender/header. If omitted, the provider profile default is used.
templateIdNoDLT template ID for providers/routes that require it.
entityIdNoDLT entity ID. Request value overrides the provider profile default.
variablesNoNamed template values passed to provider adapters.
idempotencyKeyNoPrevents duplicate queued messages for the same app key and key.

Full JSON example

Provider Setup

ProviderCredential fieldsNotes
fast2smsapiKey, optional endpointTransactional messages use the DLT manual route, OTP uses OTP route, promotional uses quick route.
twofactorapiKey, optional smsEndpoint, otpEndpoint, templateNameEndpoint overrides are available because 2Factor account/API versions can differ.

Examples

cURL

JavaScript fetch

Node.js service function

Python requests

PHP cURL

Responses

StatusMeaning
202Message accepted and queued.
200Same idempotency key was already used and the existing message was returned.
400Invalid payload or sender ID is not configured.
401Missing or invalid app API key.
404Active app key was not found.

Error Handling

Errors return a JSON object with an error message. Failed sends are visible in the dashboard and metrics pages.

Recommended Practices

  • Use idempotencyKey for OTPs, alerts, payment events, and any retryable workflow.
  • Keep account-specific app keys so each application can be paused or revoked independently.
  • Maintain provider failover by configuring more than one active profile per account.
  • Match message text, template ID, sender ID, and entity ID with your DLT approvals.
  • Use transactional as the default message type; set otp or promotional only when needed.