Quickstart
From API key to your first verified OTP in about five minutes. OTP uses SMSRay's built-in template, so it works on day one.
Sign in and open your workspace
Talk to sales and pick a plan (see pricing); the SMSRay team creates your workspace. Then sign in at app.smsray.com with your phone number or email — we send you a one-time code, no password needed.
Activation
pending. You can create keys and call the GET endpoints straight away; POST requests return 403 workspace_pending until activation.Create an API key
In the dashboard, open Clients and create an API client — one per app or environment works well. Give it a brand name: it appears at the start of every OTP message. You get two secrets, shown once. The portal's developer page shows your keys and live examples pre-filled for them.
ls_live_…— your API key, sent asx-api-key.whsec_…— your webhook signing secret.
Store them in your secret manager or environment, never in client-side code:
export SMSRAY_API_KEY="ls_live_..."Test mode
Send your first OTP
Send a code to your own mobile number. Use E.164 (+9779801234567); the national format of your workspace's country works too. OTP uses SMSRay's built-in template, so it works on day one — no template approval needed.
curl https://api.smsray.com/api/sms/v1/sms/otp/send \
-H "x-api-key: $SMSRAY_API_KEY" \
-H "content-type: application/json" \
-d '{ "to": "+9779801234567", "purpose": "login", "ip": "203.0.113.7" }'The reply comes back in milliseconds and the SMS arrives a moment later:
{ "success": true, "otpId": "9d5c0b7e-…", "messageId": "4f8a2c61-…", "expiresInSeconds": 300 }Verify the code
Post the 6 digits from the SMS with the same to and purpose. A wrong code is a normal 200 answer with verified: false — always read verified.
curl https://api.smsray.com/api/sms/v1/sms/otp/verify \
-H "x-api-key: $SMSRAY_API_KEY" \
-H "content-type: application/json" \
-d '{ "to": "+9779801234567", "purpose": "login", "code": "482913" }'{ "success": true, "verified": true }Send an SMS and track it
Approved templates
curl https://api.smsray.com/api/sms/v1/sms/send \
-H "x-api-key: $SMSRAY_API_KEY" \
-H "content-type: application/json" \
-H "Idempotency-Key: order-1042-shipped" \
-d '{ "to": "+9779801234567", "text": "Your order #1042 has shipped." }'You get a messageId back immediately. The status moves from queued to sent to delivered; look it up any time:
curl https://api.smsray.com/api/sms/v1/sms/messages/<messageId> \
-H "x-api-key: $SMSRAY_API_KEY"Add a webhook
Polling is fine for testing. In production, set a webhook URL (https://) on your API client and SMSRay POSTs a signed message.status event on every change, plus message.inbound when someone replies. Set up webhooks.