FlowSMS API Reference
Welcome to the FlowSMS API. Our RESTful API allows you to seamlessly integrate carrier-grade messaging directly into your applications. All requests must be made over HTTPS and use JSON payloads.
Authentication
Authenticate your API requests using a Bearer token in the Authorization header or by providing the X-API-Key header. You can generate API keys from your portal dashboard.
Authorization: Bearer YOUR_API_KEY // OR X-API-Key: YOUR_API_KEY
POST /api/v1/sms/send
Dispatches an SMS message to a specified recipient. The cost of the message is calculated dynamically based on the destination network and message length.
| Parameter | Description |
|---|---|
| to string Required | Recipient phone number in E.164 format (e.g. +15550192834). |
| text string Required | The message body. Long messages will be automatically split and concatenated. |
| sender_id string | Custom alphanumeric Sender ID (up to 11 characters). Default is FLOWSMS. |
curl -X POST https://flowsms.cc/api/v1/sms/send \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"to": "+447700900077",
"text": "Your verification code is 123456.",
"sender_id": "AUTH"
}'
{
"success": true,
"message_id": "msg_9f8e7d6c",
"cost": 0.045,
"status": "queued"
}
GET /api/v1/balance
Retrieve your current available wallet balance.
curl -X GET https://flowsms.cc/api/v1/balance \ -H "Authorization: Bearer YOUR_API_KEY"
GET /api/v1/rates
Query the current SMS termination rate for a specific country or prefix.
| Parameter | Description |
|---|---|
| prefix string Required | The country calling code (e.g. 44, 1). |
curl -X GET "https://flowsms.cc/api/v1/rates?prefix=44" \ -H "Authorization: Bearer YOUR_API_KEY"
GET /api/v1/messages
Retrieve a paginated list of your sent messages and their delivery statuses.
{
"success": true,
"data": [
{
"message_id": "msg_9f8e7d6c",
"recipient": "+447700900077",
"status": "delivered",
"sent_at": "2026-10-02T14:30:00Z"
}
],
"pagination": { "page": 1, "total_pages": 5 }
}
Webhook HMAC Signatures
To securely verify that incoming webhook payloads originate from FlowSMS, we sign all requests using HMAC-SHA256.
The signature is included in the X-FlowSMS-Signature header.
1. Extract the raw request body as a string.
2. Retrieve the X-FlowSMS-Signature header.
3. Compute the HMAC-SHA256 hash of the raw body using your Webhook Secret.
4. Compare the computed hash (hex-encoded) to the signature header.
const crypto = require('crypto');
function verifyWebhook(rawBody, signature, secret) {
const hash = crypto.createHmac('sha256', secret)
.update(rawBody)
.digest('hex');
return crypto.timingSafeEqual(Buffer.from(hash), Buffer.from(signature));
}