FAQ
Questions, answered
31 straight answers about sending, OTP, the API, pricing and privacy. Can't find yours? Write to us and a person will reply.
Getting started
What is SMSRay?
SMSRay is an SMS and OTP API by Lacspace. You integrate our API or dashboard to send one-time passwords (OTP), transactional messages and two-way SMS, and we deliver them over local mobile networks, with delivery reports, signed webhooks, analytics and a live dashboard.
How do I create an account?
Accounts are created by the SMSRay team, so there is no self sign-up. Talk to sales at sales@lacspace.com or through the contact page, and we'll set up your workspace and plan. You then sign in at app.smsray.com with a one-time code sent to your phone number or email. There is no password to remember.
Why do I need an approved template?
Every custom message uses a template approved by SMSRay before it can be sent. Review blocks spam and phishing before it reaches anyone, which protects deliverability for every sender. We aim to review new templates within one business day. Codes sent through our OTP API use our built-in template, so OTP works on day one.
Which numbers can I send to?
Your workspace sends to the countries it is enabled for. Nepal is live today (mobile numbers starting with 96, 97 or 98); more countries are on the way. A number in a country we don't deliver to yet is rejected with a 422 destination_not_supported error and is not charged.
Sending and delivery
Which networks do you support?
All of them. SMSRay is network-agnostic: it is built to connect to any mobile network, and today it delivers to every Nepal mobile number, whichever network the subscriber is on. Smart routing and automatic retries are handled by the platform. Nepal today, more countries on the way.
What sender will my recipients see?
Messages are delivered with a sender set by SMSRay. A custom sender name is available on Enterprise where the networks allow it. Start each template with your app or business name so people know who it is from; OTP messages sent through the OTP endpoint include your app name automatically.
How does delivery work?
You call the API and we take care of the rest. SMSRay's managed delivery sends each message over the recipient's mobile network, retries automatically if an attempt fails, and reports the result back to you by API, webhook and dashboard.
What do the message statuses mean?
A message moves through queued, submitting and submitted while it is being handed to the network, then sent once it is on its way and delivered when the network confirms delivery to the phone. Undelivered, failed and rejected are final unsuccessful states. Webhooks simplify these into queued, sent, delivered, undelivered and failed.
How fast are messages delivered?
Most of the work happens within seconds of your API call, but final delivery depends on the mobile network and the recipient's phone (for example, if it is switched off). We don't promise a delivery time, so design important flows such as sign-in with a resend option.
Can people reply to my messages?
Yes. Replies to your messages are delivered to you as message.inbound webhooks, linked to the message they answer where we can match them, and they appear in the Inbound section of your dashboard.
How are long messages and Nepali text counted?
1 SMS is up to 160 English (GSM-7) characters, or up to 70 characters in Nepali or other Unicode text (including emoji). Longer messages use more SMS: 153 or 67 characters per part. A message can use up to 6 parts.
OTP verification
How does the OTP API work?
Call POST /sms/otp/send with the phone number. We generate a 6-digit code and send it branded with the brand name set on your API client, for example "<App>: 482913 is your verification code. Valid for 5 minutes. Do not share it." When the user types the code, call POST /sms/otp/verify and we tell you whether it matches.
What limits apply to OTP?
A code expires after 5 minutes and allows 5 verification attempts. There is a 60-second resend cooldown, a maximum of 3 per 10 minutes for any number across all customers, and, if you pass the end user's IP address, a maximum of 10 per IP per 10 minutes.
What happens when a user enters the wrong code?
A wrong code is not an API error. The verify call returns 200 with verified set to false and a reason: invalid_code, too_many_attempts or no_active_otp. You decide what to show the user.
Do you store the OTP codes?
Only a SHA-256 hash of each code is stored, never the code itself, and the OTP text is shown as "(OTP hidden)" in message logs and the dashboard.
Developers
Is there an SDK?
Not yet. SMSRay is a plain REST API, so any HTTP client works. The documentation includes ready-to-copy examples in cURL, Node.js, Python and PHP.
How do I authenticate API requests?
Create an API key in the dashboard and send it in the x-api-key header with every request to https://api.smsray.com/api/sms/v1. Keys are stored as hashes, so copy yours when it is shown. Keep keys on your server, never in a browser or mobile app.
How do I retry safely without sending twice?
Send an Idempotency-Key header with POST requests. If you repeat a request with the same key within 24 hours, you get the original response back instead of a second message. Reusing a key with a different body returns idempotency_conflict.
How do webhooks work?
Set a webhook URL on your API client to receive message.status and message.inbound events. Each request is signed with HMAC-SHA256 in the x-lacspace-signature header (t=timestamp, v1=signature), which you should verify with a ±300 s tolerance. Failed deliveries are retried up to 8 times over about 10 hours, and delivery history is kept for 7 days.
Is there a rate limit?
Yes. Each API client can send 20 requests per second by default. Above that you get a 429 rate_limited response with a Retry-After header. Contact us if you need a higher limit.
Billing
How much does SMSRay cost?
Starter is NPR 3,000 per month for 4,500 SMS (about NPR 0.67 per SMS). Business is NPR 5,000 per month for 10,000 SMS (NPR 0.50 per SMS). Enterprise is priced for your volume, with promotional SMS, dedicated support and a custom sender name where available. Every plan includes the REST API, dashboard, delivery reports and webhooks, the OTP API and analytics.
Do unused SMS roll over?
No. Unused SMS expire at the end of each monthly period. If you need more within a month, top up at your plan's rate (NPR 0.67 per SMS on Starter, NPR 0.50 on Business). Top-ups are added to the current month and expire with it.
Can I send promotional SMS?
Starter and Business include OTP and transactional SMS. Promotional SMS, with approved templates, is available on Enterprise.
Am I charged for messages that fail?
If a message finally fails after our automatic retries, its cost is credited back to your balance automatically. Requests that are rejected before sending, such as numbers in countries we don't deliver to yet, are not charged.
What happens when my balance runs out?
Send requests are refused with a 402 insufficient_balance error and nothing is sent until you top up or your next monthly period starts. You can check your balance at any time with GET /sms/balance or in the dashboard.
Security and privacy
Who can see my messages?
Members of your workspace can see your messages in the dashboard. OTP text is always hidden. Lacspace staff access data only as needed to operate, secure and support the service. Every change in the portal is recorded in an audit log, and you can review and revoke your active sessions.
How long do you keep data?
OTP codes expire after 5 minutes, webhook delivery history is kept for 7 days, and message history is kept while your workspace is active so you can review it and reconcile billing. See the Privacy Policy for details.
Does SMSRay handle STOP or opt-out replies?
Automatic STOP handling is coming soon. Until then, replies reach you as inbound messages, and you are responsible for recording and honouring opt-out requests yourself, as our Anti-Spam Policy requires.
How do I report spam or abuse?
Email abuse@lacspace.com with the sender shown on the message, the date and time and the message text. For security vulnerabilities, write to security@lacspace.com.
Voice (coming soon)
Do you offer voice calls?
Not yet. Voice is coming soon, starting with missed-call verification, call alerts and voice OTP, and later IVR and AI voice agents. Nothing in the voice product is available today.
How can I hear when voice is available?
Email sales@lacspace.com and tell us what you would like to use voice for. We'll get in touch when it is ready.
Still have a question?
Email support@lacspace.com or use the contact form.
Send your first SMS this week
Plans from NPR 3,000 a month. Tell us what you send and we'll set up your account, so OTP works on day one.
Already a customer? Log in