SMS API

Send SMS from your own software and receive replies and delivery receipts back, using a simple JSON API over HTTPS.

In short: POST a JSON message to https://api.everymessage.com/v1/submit with HTTP Basic authentication. Replies and delivery receipts arrive at your webhook as they happen, or you can collect them with a GET request.

Getting started

  1. Get your API keys. Contact us and we will issue an api_key and secret_key for your account.
  2. Send a message. Call Send SMS. Each request can carry many messages, each with many recipients.
  3. Handle replies. Choose a webhook or polling for inbound SMS.
  4. Track delivery. Ask for delivery receipts on the messages you need to confirm.

Authentication

Every request uses HTTP Basic authentication over HTTPS: your api_key is the username and your secret_key is the password.

Authorization: Basic base64(api_key:secret_key)

If your tooling cannot set headers, you can pass api_key and secret_key as query parameters instead. The header is preferred, because query strings can end up in logs.

Keep your keys on your server. Never put them in a web page or mobile app.

Responses

Every call returns the same JSON envelope. The result is in body.

Always check responseStatusReason. The API returns HTTP 200 even when a request is refused. On success the field is left out; otherwise it holds one of the reasons below.

{
  "apiName": "everymessage Web API",
  "apiVersion": "1.0.2",
  "apiTime": "11 October 2026 10:30:00",
  "apiState": "RUNNING",
  "responseStatusCode": 200,
  "processingTime": 42,
  "body": {}
}
FieldTypeDescription
apiNamestringAlways everymessage Web API.
apiVersionstringAPI version.
apiTimestringServer time (UTC) the response was produced.
apiStatestringRUNNING when the service is healthy.
responseStatusCodeintegerAlways 200.
responseStatusReasonstringLeft out on success. If present, the request was refused: see status reasons.
processingTimeintegerTime taken on our side, in milliseconds.
bodyobject / arrayThe result. Its shape depends on the endpoint.

Status reasons

responseStatusReasonMeaning
UNAUTHORIZEDThe keys are wrong, or the account is blocked.
INSUFFICIENT_DATAA required field is missing or the JSON could not be read.
INSUFFICIENT_CREDITSA prepay account does not have enough credit for the request.
USER_DAILY_CREDIT_LIMIT_REACHEDThe user’s daily sending limit has been reached.
COMPANY_DAILY_CREDIT_LIMIT_REACHEDThe company’s daily sending limit has been reached.
BLOCKEDThe request was blocked.
NO_CURRENT_ENTRIESA collect call found nothing new. This is not an error.
PROCESSING_FAILURESomething went wrong on our side. It is safe to retry after a short wait.

Fixed IP addresses

Webhooks to your systems come from 13.134.161.74. Add it to your firewall allow-list if you restrict inbound traffic. If your own firewall restricts outbound traffic to the API, ask us for the fixed addresses of api.everymessage.com.

Both directions run from UK and EU data centres.