Features
One API for every message that matters
Verification codes, receipts and replies, delivered across every major mobile network and tracked end to end. Here is everything SMSRay does today, and what is coming next.
OTP verification
Two calls. Zero code storage.
We generate a 6-digit code, send it with your app name, keep only its hash and check what your user types. You never store or compare codes yourself.
- Valid for 5 minutes, 5 attempts
- 60 s resend cooldown per number
- At most 3 per 10 minutes per number
- Optional per-end-user IP limit
- Code hidden in logs and the dashboard
- Wrong code is a clean 200, not an error
# 1. Send a code (6 digits, valid 5 minutes)
curl https://api.smsray.com/api/sms/v1/sms/otp/send \
-H "x-api-key: $SMSRAY_API_KEY" -H "content-type: application/json" \
-d '{ "to": "+9779801234567", "purpose": "login", "ip": "203.0.113.7" }'
# 2. Check what the user typed
curl https://api.smsray.com/api/sms/v1/sms/otp/verify \
-H "x-api-key: $SMSRAY_API_KEY" -H "content-type: application/json" \
-d '{ "to": "+9779801234567", "purpose": "login", "code": "482913" }'curl https://api.smsray.com/api/sms/v1/sms/send \
-H "x-api-key: $SMSRAY_API_KEY" \
-H "content-type: application/json" \
-H "Idempotency-Key: order-1042-shipped" \
-d '{ "to": "+9779801234567", "text": "Your order #1042 has shipped." }'Transactional SMS
Receipts, reminders and alerts that land once
Order updates, payment confirmations, appointment reminders, delivery notices. One POST with a number and text that matches your approved template; we count segments, reserve the cost and start delivery.
- Idempotency-Key: replays for 24 h return the original reply
- GSM-7: 160 chars, 153 per part after that
- Unicode and Nepali: 70 chars, 67 per part
- Up to 6 segments per message
- Per-key rate limit, 20 sends/s by default
- Check status any time with GET /sms/messages/:id
Two-way messaging
Customers can reply. You will hear it.
When a customer answers your message, the reply is matched to the most recent message you sent that number and pushed to your server.
Linked to the conversation
Each reply carries inReplyTo, the id of the message it answers, for replies within 72 hours.
In your dashboard inbox
Read replies next to the message log, and mark them read as your team works through them.
Conversation · 98XXXXXXXX
two-way{ "type": "message.inbound",
"from": "+9779801234567",
"text": "YES",
"inReplyTo": "2b1f6c1e-…" }To 98XXXXXXXX
Managed delivery · smart routing · automatic retries
Your app
POST /sms/send
SMSRay
Template check, routing, retries
- NET
Mobile networks
Delivered on any network
Recipient
Message on their phone
Network A
covered
Network B
covered
Network C
covered
Managed delivery
You call the API. We take it from there.
SMSRay delivers your messages over local mobile networks, whichever one your customer is on. Routing, retries and delivery reports are handled by the platform, so there is nothing to run on your side.
- Delivered on every major mobile network
- Smart routing for every message
- Automatic retries when an attempt fails
- Delivery reports by API, webhook and dashboard
- Messages that finally fail are credited back
- OTP works on day one with our built-in template
Template approval keeps delivery clean
Every custom message uses a template approved by SMSRay before it can be sent. Codes sent through our OTP API use our built-in template, so OTP works on day one. Review blocks spam and phishing before it reaches anyone, which protects deliverability for every sender. We aim to review new templates within one business day.
Signed webhooks
Events you can trust, retried until they land
Set one webhook URL per API client and receive message.status and message.inbound events, each signed so you can prove it came from us.
- HMAC-SHA256 over timestamp and raw body
- Rejected outside a ±300 s window to stop replays
- Rotate secrets with zero downtime (two signatures)
- 8 attempts with growing backoff
- Never sent twice for the same status
- Delivery history kept for 7 days
x-lacspace-event: message.status x-lacspace-signature: t=1791612907, v1=5f0c9a…e41b user-agent: lacspace-sms-webhooks/1
Attempt schedule
- #1now
- #2+10 s
- #3+30 s
- #4+2 min
- #5+10 min
- #6+30 min
- #7+1 h
- #8+3 h
A 2xx stops the ladder. Permanent 4xx responses (except 408 and 429) stop after 3 attempts. Each attempt is re-signed with a fresh timestamp.
The dashboard
Everything about your messages, on one screen
Sign in with a one-time code to your phone or email. Search the log, send a test, manage keys and teammates, follow delivery live and see analytics for your traffic.
Sent today
1,284
Delivered
1,251
Balance
NPR —
| To | Type | Message | Seg | Status |
|---|---|---|---|---|
| 98•••••213 | otp | (OTP hidden) | 1 | delivered |
| 97•••••480 | transactional | Your order #1042 has shipped. | 1 | sent |
| 98•••••771 | transactional | Payment of NPR 2,500 received. Thank you! | 1 | delivered |
| 98•••••034 | otp | (OTP hidden) | 1 | queued |
| 96•••••915 | promotional | Dashain offer: 20% off all plans this week… | 2 | delivered |
Messages
Every send with status, segments and delivery timeline
Inbound
Replies, linked to the message they answer
API clients
Keys, webhook URL and signing secret
Members
Invite teammates by phone, set roles
Security
Your signed-in sessions, sign out any of them
Workspaces and team
Bring your team. Keep control.
Every account gets its own workspace. Invite teammates by phone number and decide who can change what.
| What you can do | Member | Owner |
|---|---|---|
| Read messages, replies, stats and members | ||
| Send from the dashboard | ||
| Manage your own profile and sessions | ||
| Create API clients, rotate keys, set webhooks | — | |
| Invite, promote and remove members | — | |
| Rename the workspace | — |
Invite by phone
Add a teammate by phone number. They join your workspace the first time they sign in. A workspace always keeps at least one owner.
Set up for you
Our team creates your workspace and owner account. From there you add API keys, webhooks and teammates yourself.
Security built in
Secure by default, not as an add-on
The protections below are on for every workspace from day one.
Hashed API keys
Keys are shown once and stored only as hashes. Rotate a key whenever you like.
Passwordless sign-in
One-time codes to your phone or email. Sessions live in httpOnly cookies.
Audit log
Every change in the dashboard is recorded with who, when and from where.
Approved templates
Custom messages are reviewed before they can be sent, so spam and phishing never leave the platform.
Side by side
SMSRay vs a typical bulk-SMS gateway
What you get with SMSRay out of the box. Other providers differ, so check the details with whoever you use today.
| Capability | SMSRay | Typical bulk-SMS gateway |
|---|---|---|
| Pricing | Published monthly plans in NPR, from NPR 3,000 | Often quote-only |
| OTP generation and checking | Built in: we create, send, hash and verify the code | Usually build-it-yourself on top of plain send |
| Delivery receipts | Status per message: queued → sent → delivered, by API and webhook | Varies by provider |
| Webhook authenticity | HMAC-SHA256 signature with timestamp and secret rotation | Varies; sometimes unsigned |
| Safe retries | Idempotency-Key replays for 24 h, never a second SMS | Varies; retries can double-send |
| Replies from customers | Delivered to you as message.inbound, linked to the original | Often a separate product or not offered |
| Failed messages | Automatic retries; a message that finally fails is credited back | Varies by provider |
| Spam protection | Every custom template reviewed before it can be sent | Varies by provider |
| Unicode and Nepali | Exact GSM-7 / UCS-2 segment counts, never split mid-character | Varies by provider |
Plain REST
Six endpoints, one header (x-api-key) and one error shape. Examples in cURL, Node.js, Python, PHP and Go.
Learn morePredictable errors
Every error is { error, code } with a stable code like insufficient_balance or rate_limited, plus Retry-After where it applies.
Learn moreBalance by API
Check your workspace balance with GET /sms/balance before a big send, and get a clean 402 if it runs short.
Learn more{ "error": "Rate limit exceeded", "code": "rate_limited" }
// HTTP 429 · Retry-After: 1Coming soon
On the roadmap
These are not available yet. We will announce each one when it ships.
Quiet hours
Hold non-urgent messages overnight, Nepal time.
Workflow automation
Scheduled sends, keyword auto-replies and webhook-triggered SMS.
Contacts and lists
Contact lists and groups in the dashboard.
Bulk campaigns
Schedule one approved message to a whole list.
Voice
Missed-call verification, call alerts and voice OTP.
Send your first SMS this week
Plans from NPR 3,000 a month. Tell us what you send and we'll set up your account, so OTP works on day one.
Already a customer? Log in