TRAI & DLT Compliant 4.8/5 Rated
06 October 2026 · Guru SMS Team

SMS API Integration Guide for Developers in India

A developer-focused SMS API integration guide covering REST basics, authentication, sending messages, delivery webhooks, the OTP route and supported languages.

Adding SMS to an application is one of the highest-impact integrations a developer can ship. Order confirmations, OTPs, alerts and reminders all run on a few well-placed API calls. This guide is written for developers and walks through the practical mechanics of an SMS REST API in India: how authentication works, how to send a message, how to receive delivery status through webhooks, how the OTP route differs, and how to call the API from PHP, Python, Java and Node.js. Pricing is set per account, so this guide focuses on the technical workflow rather than rates.

REST API basics

A modern SMS API is a standard HTTPS REST service. You send a request to an endpoint, usually with JSON in the body, and receive a JSON response containing a message identifier and an accepted status. Because it is plain HTTP, you can integrate from any language or framework that can make a web request, and you can test calls quickly with curl or any HTTP client before writing application code. Our bulk SMS API follows this REST model, so the patterns below apply directly.

Authentication

Authentication is handled with an API key issued to your account. The key is typically passed either as a header, such as an Authorization bearer token, or as a parameter in the request. Treat the key like a password. Store it in environment variables or a secrets manager, never hard-code it in client-side code or commit it to version control, and rotate it if it is ever exposed. For server-to-server calls, always send requests over HTTPS so the key is never transmitted in clear text.

Sending an SMS

A send request needs a handful of fields: the destination number in international format, the message body, your registered sender ID or header, and the DLT template identifier that matches the message. Because India enforces DLT, the body must correspond to an approved template, with variable fields populated at send time. Here is a minimal example in each major language.

PHP

  • Use curl to POST a JSON payload with the API key in the header, the recipient, the sender ID, the template id and the message text, then read the returned message id from the JSON response.

Python

  • Use the requests library to post the same JSON payload, passing the API key in the headers dict, and parse response.json() to capture the message id and status.

Java

  • Use the built-in HttpClient to build a POST request with the JSON body and an Authorization header, send it, and deserialize the response body to read the status.

Node.js

  • Use fetch or axios to post the JSON payload with the API key header, then await the response and read the message id from the parsed JSON.

In every language the shape is identical: build JSON, attach the key, POST over HTTPS, read the response. A successful response means the platform has accepted the message for delivery, not that it has reached the handset, which is where webhooks come in.

Delivery webhooks

Acceptance and delivery are two different events. To know whether a message actually reached the phone, you register a webhook, also called a callback URL, on your account. The platform then sends an HTTP POST to that URL each time a delivery status changes, carrying the original message id and a status such as delivered, failed or expired. Your endpoint should do three things: respond quickly with a 200 so the platform does not retry unnecessarily, validate that the request is genuinely from the provider, and process the status asynchronously by writing it to a queue or database rather than blocking the response. This lets you reconcile every send against its real outcome and surface delivery analytics to your users.

The OTP route

One-time passwords have stricter needs than marketing messages: they must arrive in seconds, every time, at any hour. They run on a dedicated transactional route that is exempt from DND and promotional time windows. From a developer's perspective the API call is the same shape, but you target the OTP route and use a registered OTP template. Good practice is to generate the code server-side, set a short expiry, store a hashed version for verification, and rate-limit requests per number to prevent abuse. Our OTP SMS route delivers at 98-99% on a transactional path built for exactly this latency-sensitive use case.

Error handling and reliability

Build defensively. Check the HTTP status code and the response body, since a 200 with an error field in the JSON still means failure. Implement retries with exponential backoff for transient network errors, but make sends idempotent so a retry does not double-send. Log the message id from every response so you can trace a message end to end against its webhook status. Validate and normalise numbers to international format before sending to cut down on rejected requests.

Beyond SMS: WhatsApp and RCS

Once your SMS integration is solid, the same architecture extends to richer channels. The WhatsApp API lets you send template messages, media and interactive buttons, while RCS messaging brings branded, app-like experiences to the native messaging inbox. Reusing your send-and-webhook pattern across channels keeps your codebase clean and your fallback logic simple.

Frequently Asked Questions

What do I need before I can send my first SMS via the API?

An account with an API key, a DLT-registered sender ID and at least one approved template. The message body you send must match the registered template, with variables filled in at send time.

How do I know if a message was actually delivered?

Register a delivery webhook on your account. The platform posts status updates such as delivered or failed to your callback URL, referencing the message id returned when you sent the message.

Which programming languages are supported?

Any language that can make an HTTPS request works, including PHP, Python, Java, Node.js, C#, Go and Ruby. The API is plain REST with JSON, so there is no mandatory SDK.

Is the OTP API different from the regular send API?

The call has the same shape, but OTPs use a dedicated transactional route and an OTP template. That route is exempt from DND and time windows and is tuned for fast, reliable delivery.

Ready to integrate SMS, OTP, WhatsApp or RCS into your application? The Guru SMS team will provision your API key, help register your templates and support your developers through go-live. Visit our contact page or call +91-9853084604 to begin.

Want help with your messaging?

Fill this in — our team responds within a few working hours.

Your details are safe with us. No spam, ever.

Ready to reach every customer’s phone?

Talk to a messaging expert today — free demo, free DLT guidance, instant activation.