Features
Built for scale.
Designed for developers.
Every feature, end-to-end. From API to delivery receipt.
OTP in one request
POST /v1/otp/send returns a reference_id. Verify later with POST /v1/otp/verify.
Distributed GSM network
Traffic is spread across regional delivery nodes inside Turkmenistan, with automatic failover when a node drops out.
Per-app API keys
Each key has its own OTP length (4–10) and expiry (60–600s). Raw key shown once, bcrypt-hashed in DB.
Client dashboard
Timeseries charts, status breakdown, and per-API-key usage. Filter by date range and granularity.
JWT + refresh tokens
Access token expires in 15 min. Refresh issues a new pair on every call. Bcrypt-hashed credentials.
Per-client rate limiting
100 req/min sliding window, tracked per client. 429 returned when the limit is exceeded.
Phone OTP hardening
6-digit codes via SMS. 5 attempts max per code. Codes expire in 5 minutes. One-time use only.
Webhooks (coming)
Delivery receipts pushed to your URL. Signed with HMAC-SHA256. Retries with exponential backoff.
Message lifecycle
1
pending
2
queued
3
sending
4
sent
5
delivered