1. Home
  2. SMS API for Developers
Developers

SMS API for Developers

An SMS API is a web interface that lets your software send and track text messages with an ordinary HTTP request instead of a phone. Ontech BulkSMS exposes a simple HTTP/JSON API and an SMPP 3.4 server, authenticated with per-account API keys and IP whitelisting.

Published 2026-09-13 · Updated 2026-09-13 · By Ontech Solutions Limited

Definition.

An SMS API is an HTTP interface that lets your software send text messages, check their delivery and read your balance with ordinary web requests. The API provider — an SMS gateway — holds the connections to the mobile networks, so your code never talks to MTN, Airtel or Zamtel directly.

How an SMS API works

  1. Your application makes an HTTP request to the send endpoint with the recipient's number, the message text, your sender ID and your credentials.
  2. The gateway authenticates and validates — key and IP whitelist, number format, blacklist, credit balance — and returns a response immediately, including a message ID.
  3. The gateway routes and submits the message to the recipient's network over its carrier connection.
  4. The network returns a delivery report, stored against the message ID. You poll it, receive it on a callback URL, or read it in the dashboard.

The Ontech BulkSMS API at a glance

EndpointMethodPurpose
/smsservice/httpapiGET / POSTSend one message; returns a message_id
/smsservice/jsonapiPOSTSend one or many messages in a JSON body
/smsservice/statusGETDelivery status for a message_id
/smsservice/balanceGETCredit balance (organisation-shared if applicable)
/smsservice/topup, /topup/statusPOST / GETStart a mobile money top-up and check it
/smsservice/contactsGET / POSTList and create contacts
/smsservice/templatesGET / POSTList and create message templates
/smsservice/plansGETThe volume rate card; optionally price an amount

All endpoints are on https://bulksms.ontech.co.zm, return JSON with a numeric status (100 success, 101 insufficient credit, 102 invalid user, 103 validation error, 104 rate limit), and accept the same authentication. The complete parameter reference is on the API documentation page and in the CloudService API guide (PDF).

Authentication

Generate credentials under API Keys → Generate Key in your dashboard. Each key has an Access ID and a Secret Key; pass either as api_key. Keys only work from the IP addresses you whitelist for them, so add your server's address before going live — a request from elsewhere returns 102 Invalid User. Username and password (your login email and password) are accepted as an alternative, but a key is the right choice for anything deployed.

Send a message

# HTTP API — GET or POST, query parameters
curl "https://bulksms.ontech.co.zm/smsservice/httpapi?\
api_key=YOUR_ACCESS_ID&phone=260970000000&sender_id=YOURBRAND&msg=Hello%20from%20the%20API"
# → {"status": 100, "message": "Success", "message_id": "…"}

# JSON API — many recipients in one request
curl -X POST https://bulksms.ontech.co.zm/smsservice/jsonapi \
  -H "Content-Type: application/json" \
  -d '{"auth": {"api_key": "YOUR_ACCESS_ID", "sender_id": "YOURBRAND"},
       "messages": [{"phone": "260970000000", "message": "Hello Mutale"},
                    {"phone": "260960000000", "message": "Hello Chanda"}]}'
# → {"status": 100, "message": "Success", "sent": 2}

Numbers are Zambian MSISDNs — 260 followed by nine digits; local forms such as 0970000000 are normalised. Non-Zambian numbers are rejected with a 103.

Check delivery

curl "https://bulksms.ontech.co.zm/smsservice/status?api_key=YOUR_ACCESS_ID&message_id=MESSAGE_ID"
# → {"status": 100, "message": "Success", "message_id": "…", "delivery_status": "delivered"}

delivery_status is one of delivered, failed, rejected, queued (not yet submitted), submitted (carrier accepted, no final report yet) or unknown. Rather than polling, register a callback URL under Webhooks and delivery updates are posted to you with retries. The delivery reports guide explains each state.

Limits and safeguards

How businesses integrate SMS into an application

The pattern is the same whether it is a loan system, a school platform or an online shop:

  1. Create an account, generate an API key, whitelist the server's IP, and request a sender ID.
  2. Identify the events that should produce a message — a payment, a booking, a due date, a code request — and write a template for each.
  3. At each event, build the message and call the send endpoint; store the returned message ID with the record it relates to.
  4. Register a callback URL (or poll status for the messages that matter) and store the delivery state alongside the message ID.
  5. Watch your balance (/balance) and set a low-balance alert in the dashboard so notifications never stop for want of credits.

Worked examples for the common cases: transactional notifications, one-time passwords and receiving replies. For the protocol-level alternative, see SMPP.

Developer resources

API documentation

Endpoints, parameters, status codes and the SMPP connection details.

CloudService API guide (PDF)

The full HTTP/JSON API reference for download.

Platform API guide (PDF)

The platform's internal REST API for deeper integrations.

API hub (sign in)

Key management, IP whitelisting, request logs and a Postman collection in your dashboard.

Frequently asked questions

What is an SMS API?

An SMS API (application programming interface) is an HTTP endpoint your application calls to send a text message, query its delivery status or read your balance. The API provider — the SMS gateway — handles the connection to the mobile networks so your code never talks to a carrier directly.

How does an SMS API work?

Your application sends an HTTP request containing the recipient's number, the message text and your credentials. The gateway validates the request, deducts credits, submits the message to the right network over SMPP and returns a message ID. The network later reports delivery, which you can poll or receive on a callback URL.

How do I authenticate to the Ontech BulkSMS API?

With an API key (your Access ID or Secret Key) generated under API Keys in your dashboard, or with your login email and password. API keys only work from IP addresses you whitelist for them.

Is there a rate limit?

Yes. API requests are limited to 60 per minute per account. Send many recipients in one JSON API request (the messages array) rather than one request each, or use an SMPP bind for sustained high-volume traffic.

How do businesses integrate SMS into an application?

Create an account, generate an API key and whitelist your server's IP, then call the send endpoint from your code wherever an event should trigger a message. Store the returned message ID and check delivery status, or register a callback URL to receive reports automatically.

Ready to start sending?

Create a free account with trial credits, or talk to us about enterprise and reseller arrangements.