{"info":{"name":"SendSMS","description":"Import this collection, set token to a secret from Users → API tokens, and set baseUrl if you are not calling production.","schema":"https://schema.getpostman.com/json/collection/v2.1.0/collection.json"},"auth":{"type":"bearer","bearer":[{"key":"token","value":"{{token}}","type":"string"}]},"variable":[{"key":"baseUrl","value":"https://sendsms.top"},{"key":"token","value":"sms_paste_the_token_here"}],"item":[{"name":"Who this token is","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{baseUrl}}/api/v1/me","description":"Who this token is. Returns the token name, role, company, and which actions that role is allowed to call. Access: Any token."}},{"name":"Wallet balance","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{baseUrl}}/api/v1/wallet","description":"Wallet balance. Integer credit balance for the token's company. One accepted outbound SMS costs one credit. Access: Any token."}},{"name":"Allocate credits","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{baseUrl}}/api/v1/wallet/allocate","description":"Allocate credits. Adds a positive integer number of credits to a company wallet. amount must be a positive integer. Access: Super.","body":{"mode":"raw","raw":"{\n  \"companyId\": \"00000000-0000-0000-0000-000000000000\",\n  \"amount\": 100,\n  \"reason\": \"October top-up\"\n}"}}},{"name":"Customers","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{baseUrl}}/api/v1/customers","description":"Customers. Up to 100 customers per page for the token's company, ordered by name. Use page and pageSize. pageSize max is 100. Access: Any token. Query: page=1 (Page number, starting at 1.) pageSize=50 (Rows per page, 1–100. Default 50.)"}},{"name":"Sent SMS","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{baseUrl}}/api/v1/sms/sent","description":"Sent SMS. Outbound messages for the token's company, 50 per page by default (max 100). status is our word, such as delivered. dlrStatus is the raw carrier code, such as DELIVRD. senderName is the API token when a token sent the message. createdByName is the person who created that token. Access: Any token. Query: page=1 (Page number, starting at 1.) pageSize=50 (Rows per page, 1–100. Default 50.)"}},{"name":"Inbox","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{baseUrl}}/api/v1/sms/inbox","description":"Inbox. Inbound messages for the token's company, 50 per page by default (max 100). Replies are not billed. unread=1 keeps messages that have not been opened. optOut=1 keeps opt-out replies. Access: Any token. Query: page=1 (Page number, starting at 1.) pageSize=50 (Rows per page, 1–100. Default 50.) unread=1 (1 to only include unread replies.) optOut=1 (1 to only include opt-out replies.)"}},{"name":"Send one SMS","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{baseUrl}}/api/v1/sms","description":"Send one SMS. Sends one message to one number. to is E.164 (+2782…) or a South African local number (082…). Optional senderId uses a registered SMSPortal sender; omit it for the account default. The response uses senderId and leaves from empty rather than naming the upstream provider. Optional clientReference is your own id, stored on the message and returned as clientReference. Optional sendAt is an ISO time, at least 15 seconds ahead and at most 30 days, to send later. The credit is taken when the message is actually sent, still one credit per message rather than per segment. Send Idempotency-Key to make a retry return the first result instead of sending twice. A View Only token receives 403. An empty wallet receives 402 and the provider is not called. An opted-out number receives 409 opted_out. GSM-7 is 160 characters (153 if concatenated). Unicode, including emoji, is UCS-2: 70 characters (67 if concatenated). Maximum 10 segments. Access: Normal, Admin, or Super.","body":{"mode":"raw","raw":"{\n  \"to\": \"+27821234567\",\n  \"body\": \"Hello from SendSMS\",\n  \"senderId\": \"ACME\",\n  \"clientReference\": \"order-19\"\n}"}}},{"name":"One message","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{baseUrl}}/api/v1/sms/{id}","description":"One message. Fetch one message in this company by id, including status, the raw carrier code, and your clientReference. 404 if it is not in the token's company. Access: Any token."}},{"name":"Send the same SMS to several numbers","request":{"method":"POST","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{baseUrl}}/api/v1/sms/bulk","description":"Send the same SMS to several numbers. Same body to 1–100 numbers. One credit per accepted number, taken when that number is sent. Opted-out numbers are skipped. Optional sendAt schedules every number in the batch. Access: Normal, Admin, or Super.","body":{"mode":"raw","raw":"{\n  \"to\": [\n    \"+27821234567\",\n    \"+27827654321\"\n  ],\n  \"body\": \"Hello from SendSMS\",\n  \"clientReference\": \"batch-1\"\n}"}}},{"name":"Read the delivery callback","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{baseUrl}}/api/v1/callback","description":"Read the delivery callback. The https URL that receives delivery reports and inbound replies for this company. The secret is not returned. Access: Normal, Admin, or Super."}},{"name":"Set the delivery callback","request":{"method":"PUT","header":[{"key":"Accept","value":"application/json"},{"key":"Content-Type","value":"application/json"}],"url":"{{baseUrl}}/api/v1/callback","description":"Set the delivery callback. Save an https URL and a secret of 16–128 characters. SendSMS POSTs { event, message } when a delivery report or inbound reply arrives. event is delivery or inbound. message is the same camelCase object as GET /api/v1/sms/{id}. Header X-SendSMS-Signature is sha256= plus the HMAC-SHA256 of the raw body using the secret. Private and loopback addresses are rejected. A failed callback does not change the message. Access: Normal, Admin, or Super.","body":{"mode":"raw","raw":"{\n  \"url\": \"https://hooks.example.com/sms\",\n  \"secret\": \"replace-with-a-long-secret\"\n}"}}},{"name":"Remove the delivery callback","request":{"method":"DELETE","header":[{"key":"Accept","value":"application/json"}],"url":"{{baseUrl}}/api/v1/callback","description":"Remove the delivery callback. Stop delivery and inbound callbacks for this company. Access: Normal, Admin, or Super."}},{"name":"Users","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{baseUrl}}/api/v1/users","description":"Users. Staff the token is allowed to see. A company admin sees one company. A super token sees every company. Other roles receive 403. Access: Admin or Super."}},{"name":"Audit log","request":{"method":"GET","header":[{"key":"Accept","value":"application/json"}],"url":"{{baseUrl}}/api/v1/audit","description":"Audit log. Company audit events, 50 per page. scope=platform is the platform-wide log and is Super only. Access: Any token; platform scope is Super. Query: page=1 (Page number, starting at 1.) scope=platform (Omit for the token's company. platform is Super only.)"}}]}