Skip to content
SMSRay

Built on

The technology behind SMSRay

Proven, boring-in-a-good-way building blocks: modern web apps at the edge, a small Node.js API, a managed database, and security and reliability controls built into every request.

People

Browser

smsray.com, the portal and admin

Developers

Your backend

REST + JSON over HTTPS

Web · edge

Next.js + React

On the Vercel edge network

API

Node.js

On AWS, ap-south-1

Data

MongoDB

Secrets hashed · audit log · idempotency records

Let's Encrypt TLSHMAC webhooksRate limitsIP allowlists
Diagram: browsers reach the SMSRay web apps, built with Next.js and React on the Vercel edge network. Your backend calls the SMSRay API, a Node.js service on AWS in ap-south-1, with an API key. The API stores data in MongoDB. Everything runs over TLS.

The stack

Six layers, one platform

Grouped the way you would review a vendor: where it runs, where data lives, how it's protected and what happens when something fails.

Web

Fast pages, served from the edge

smsray.com, the customer portal and the admin are web apps built with Next.js and React, served from the Vercel edge network.

  • Next.js
  • React
  • Vercel edge
  • @lacspace/components
  • Interfaces built with the Lacspace component kit (@lacspace/components and friends), published openly on npm
  • Light and dark themes, responsive from small phones up
  • Server-rendered pages, so content loads without waiting on scripts

API

A small, predictable REST API

The SMSRay API is a Node.js service running on AWS in the ap-south-1 region.

  • Node.js
  • AWS ap-south-1
  • REST + JSON
  • One versioned base URL and one auth header (x-api-key)
  • One error shape everywhere: error, code and optional details
  • A per-client send rate limit (default 20 per second) that keeps traffic smooth
API reference

Data

Stored carefully, kept to what's needed

Workspaces, messages, templates and logs live in MongoDB.

  • MongoDB
  • OTP codes stored only as SHA-256 hashes, hidden in logs
  • API keys and session tokens stored as hashes, never readable again
  • Idempotency records kept for 24 hours so retries never double-send
Privacy Policy

Security

Secrets hashed, traffic encrypted

Security controls are built into the platform, not bolted on per customer.

  • Let's Encrypt TLS
  • HMAC-SHA256
  • HTTPS everywhere, with TLS certificates from Let's Encrypt
  • HMAC-signed webhooks, checked within ±300 s, with secret rotation
  • IP allowlists and scoped API keys
  • Audit logs of every dashboard change: who, when and from where
  • Template approval, so every custom message is reviewed before it can be sent
Security

Reliability

Built so a retry is always safe

Networks blip and servers restart. The platform is designed so nothing gets lost or sent twice.

  • Webhooks retried up to 8 times with backoff (10 s, 30 s, 2 min, 10 min, 30 min, 1 h, 3 h, 6 h)
  • Idempotency keys on every POST: send the same request twice, get one message
  • Automatic retries on delivery, with failed messages credited back
  • Rate limits that protect every workspace from a noisy neighbour
Webhooks

Developer experience

Test first, then go live

Everything a developer needs to integrate in an afternoon, and to trust it in production.

  • Test mode, so you can build your integration without sending real SMS
  • Docs with copy-paste cURL, Node.js, Python and PHP samples
  • A built-in OTP API that works on day one with our approved template
  • Free SMS length and cost calculator, plus llms.txt for AI assistants
Quickstart

Open by default

Built with packages anyone can use

This website runs on open Lacspace packages from the public npm registry, released under the Lacspace Free Licence v1.0. The code samples in our docs use the same licence, so you can paste them straight into your product.

Who builds it

SMSRay is a product of Lacspace

The same team designs the API, runs the platform and answers your support email.

See it working in your app

Talk to sales and we'll set up your workspace. Build against test mode, then go live with OTP on day one.

Already a customer? Log in