Use the developer API and API keys

Create a server-side key, use the live contract and retry purchases without accidental duplicates.

On this page
  1. Create and protect a key
  2. Read the live API contract
  3. Handle purchases safely
  4. Interpret errors and integrate messages

See how it works

Illustrated walkthrough · fictional sample data

Step 1 of 5

Create a server-side key

Create an API key in Developers and keep it on your server. It scopes requests to your account, wallet and owned orders; never put it into public frontend code.

This demonstration does not change your account.

Read all steps
  1. Create a server-side key

    Create an API key in Developers and keep it on your server. It scopes requests to your account, wallet and owned orders; never put it into public frontend code.

    API key
    ••••••••
    Scope
    This account and store only
  2. Use the live contract

    Use the developer docs and schema on your store’s host. Authenticate with X-API-Key or Bearer. Read balance, services and durations before constructing a purchase.

    Base URL
    https://sms.red/api/v1/developer
    Authentication
    X-API-Key: <server-held key>
    Read before purchase
    Balance → services → rental durations
  3. Submit with a fresh idempotency key

    Use a fresh key for a new purchase: 8–128 ASCII letters, digits, underscore or hyphen. Set the current duration in milliseconds and a maxPrice ceiling from your approved quote.

    Idempotency key
    demo-purchase-1042
    Request fields
    durationMs · maxPrice
  4. Recover an unclear reply

    Check the purchase attempt or owned orders first. Retry with the same idempotency key for the same purchase; creating a fresh key can create another charge.

    Existing attempt
    demo-purchase-1042
    Next action
    Read attempt → reuse same key if retrying
  5. Handle errors and rotate keys

    401: check missing, disabled, rotated or wrong-store credentials. 404: check ownership or availability. 400: check fields, funds and price limits. Disable, delete or regenerate keys from the dashboard as needed; only documented API actions are available.

    401
    Check key and store
    404
    Check owned resource / stock
    400
    Check request, balance and ceiling

Create and protect a key

Open Developers and the API keys area. Create a labelled key and save the displayed credential securely. Keys are account-scoped: calls use that account's wallet and orders in its store. They do not provide admin access or let you switch accounts through a request.

Use disable, delete or regenerate when available to revoke an old key. Regeneration invalidates the previous credential. Keep keys on your server, outside public browser code, screenshots and repositories.

Read the live API contract

SMS.Red's base is https://sms.red/api/v1/developer. On a partner storefront use that store's own hostname. Authentication accepts X-API-Key or Authorization: Bearer YOUR_API_KEY. Use interactive API documentation and the current schema rather than guessing request fields.

Read balance and services before purchasing. Service listings distinguish otp and rent, country, stock and offered durations; durations use milliseconds. Purchase requests select the actual service identifier, country, duration and price ceiling. Optional provider or description fields depend on the documented operation.

Handle purchases safely

Use a new Idempotency-Key for each intended purchase and the same key when retrying that purchase. Keys accept 8–128 ASCII letters, digits, underscores or hyphens. After a timeout, inspect the documented purchase-attempt lookup before deciding to start another order. Changing payload under the same key can produce a conflict.

GET /api/v1/developer/balance
X-API-Key: YOUR_API_KEY

This example is a read request with a placeholder, not a real credential. Follow the live purchase examples for paid operations. Read owned orders and messages through their documented endpoints; cancellation remains subject to order eligibility and confirmation.

Interpret errors and integrate messages

A 401 can mean missing, disabled, rotated or wrong-store credentials. A 404 can mean unavailable or unowned data. A 400 can reflect validation, funds or price conditions. For an unclear server result, preserve the purchase key and inspect the attempt instead of blindly creating a new key.

Use Webhooks for incoming message events. Do not assume the API exposes every dashboard control; check the current contract for each operation.

Need help with your account?

Open Support
SMS.Red

Gain access to thousands of services by starting to use our SMS activation numbers today

SMS.Red © 2025 - 2026All rights reservedmekbuda