curl --request POST \
--url https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"description": "Primary SMSC (US users)",
"tpsLimit": 50,
"allowedCidrs": [
"203.0.113.0/24"
],
"dlrMode": "both",
"dlrWebhookUrl": "https://example.com/smpp/dlr"
}
'import requests
url = "https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials"
payload = {
"description": "Primary SMSC (US users)",
"tpsLimit": 50,
"allowedCidrs": ["203.0.113.0/24"],
"dlrMode": "both",
"dlrWebhookUrl": "https://example.com/smpp/dlr"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
description: 'Primary SMSC (US users)',
tpsLimit: 50,
allowedCidrs: ['203.0.113.0/24'],
dlrMode: 'both',
dlrWebhookUrl: 'https://example.com/smpp/dlr'
})
};
fetch('https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'description' => 'Primary SMSC (US users)',
'tpsLimit' => 50,
'allowedCidrs' => [
'203.0.113.0/24'
],
'dlrMode' => 'both',
'dlrWebhookUrl' => 'https://example.com/smpp/dlr'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials"
payload := strings.NewReader("{\n \"description\": \"Primary SMSC (US users)\",\n \"tpsLimit\": 50,\n \"allowedCidrs\": [\n \"203.0.113.0/24\"\n ],\n \"dlrMode\": \"both\",\n \"dlrWebhookUrl\": \"https://example.com/smpp/dlr\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"description\": \"Primary SMSC (US users)\",\n \"tpsLimit\": 50,\n \"allowedCidrs\": [\n \"203.0.113.0/24\"\n ],\n \"dlrMode\": \"both\",\n \"dlrWebhookUrl\": \"https://example.com/smpp/dlr\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"description\": \"Primary SMSC (US users)\",\n \"tpsLimit\": 50,\n \"allowedCidrs\": [\n \"203.0.113.0/24\"\n ],\n \"dlrMode\": \"both\",\n \"dlrWebhookUrl\": \"https://example.com/smpp/dlr\"\n}"
response = http.request(request)
puts response.read_body{}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "RATE_LIMITED",
"message": "<string>",
"status": 429,
"retry_after": 2
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}Create SMPP credential
Issue a new BYO-SMPP credential — the bind identity (systemId, smppcred_…) plus a generated password your SMSC uses to bind to Orbit for inbound (MO / delivery-receipt) traffic. All body fields are optional config: description, tpsLimit (1–1000, plan-tier-capped), allowedCidrs (up to 16 IPv4/IPv6 CIDRs that gate the bind source), dlrMode (bind delivers receipts on the SMPP bind, webhook POSTs them, both), and dlrWebhookUrl (HTTPS-only, SSRF-checked; required when dlrMode is webhook or both). THE PLAINTEXT PASSWORD IS RETURNED EXACTLY ONCE in this response together with the credential record — store it now. Within 60 seconds it remains re-fetchable via GET /:id/reveal; after that it is unrecoverable and you must call /rotate. Owner / admin only — an owner/admin dashboard session, or an API key scoped smpp:write — rate-limited to 10/hour per tenant.
curl --request POST \
--url https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"description": "Primary SMSC (US users)",
"tpsLimit": 50,
"allowedCidrs": [
"203.0.113.0/24"
],
"dlrMode": "both",
"dlrWebhookUrl": "https://example.com/smpp/dlr"
}
'import requests
url = "https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials"
payload = {
"description": "Primary SMSC (US users)",
"tpsLimit": 50,
"allowedCidrs": ["203.0.113.0/24"],
"dlrMode": "both",
"dlrWebhookUrl": "https://example.com/smpp/dlr"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
description: 'Primary SMSC (US users)',
tpsLimit: 50,
allowedCidrs: ['203.0.113.0/24'],
dlrMode: 'both',
dlrWebhookUrl: 'https://example.com/smpp/dlr'
})
};
fetch('https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'description' => 'Primary SMSC (US users)',
'tpsLimit' => 50,
'allowedCidrs' => [
'203.0.113.0/24'
],
'dlrMode' => 'both',
'dlrWebhookUrl' => 'https://example.com/smpp/dlr'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials"
payload := strings.NewReader("{\n \"description\": \"Primary SMSC (US users)\",\n \"tpsLimit\": 50,\n \"allowedCidrs\": [\n \"203.0.113.0/24\"\n ],\n \"dlrMode\": \"both\",\n \"dlrWebhookUrl\": \"https://example.com/smpp/dlr\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"description\": \"Primary SMSC (US users)\",\n \"tpsLimit\": 50,\n \"allowedCidrs\": [\n \"203.0.113.0/24\"\n ],\n \"dlrMode\": \"both\",\n \"dlrWebhookUrl\": \"https://example.com/smpp/dlr\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.orbit.devotel.io/api/v1/messaging/smpp/credentials")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"description\": \"Primary SMSC (US users)\",\n \"tpsLimit\": 50,\n \"allowedCidrs\": [\n \"203.0.113.0/24\"\n ],\n \"dlrMode\": \"both\",\n \"dlrWebhookUrl\": \"https://example.com/smpp/dlr\"\n}"
response = http.request(request)
puts response.read_body{}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "RATE_LIMITED",
"message": "<string>",
"status": 429,
"retry_after": 2
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}Authorizations
Dashboard JWT token from Clerk
Headers
Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.
1 - 255Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.
true, false Body
Human-readable label, 1–200 characters (optional).
Inbound throughput cap, 1–1000 messages/second; additionally plan-tier-capped service-side (optional).
Up to 16 IPv4/IPv6 CIDR strings that gate which source IPs may bind (optional; empty means any).
Delivery-receipt delivery mode: bind, webhook or both (optional, defaults to bind).
HTTPS webhook endpoint for DLRs; required when dlrMode is webhook or both (optional otherwise).
Response
The created credential plus the one-shot plaintext password and a password_visible_once_warning reminder, wrapped in the standard { data, meta } envelope. Within 60 seconds the secret can be re-fetched via GET /:id/reveal; after that it is unrecoverable (use /rotate). A 403 fires when tpsLimit exceeds the plan tier and 422 when the body is invalid.
The created credential plus the one-shot plaintext password and a password_visible_once_warning reminder, wrapped in the standard { data, meta } envelope. Within 60 seconds the secret can be re-fetched via GET /:id/reveal; after that it is unrecoverable (use /rotate). A 403 fires when tpsLimit exceeds the plan tier and 422 when the body is invalid.