Skip to main content
POST
Create SMPP credential

Authorizations

Authorization
string
header
required

Dashboard JWT token from Clerk

Headers

Idempotency-Key
string

Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.

Required string length: 1 - 255
X-Test-Mode
enum<string>

Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.

Available options:
true,
false

Body

application/json
description
any

Human-readable label, 1–200 characters (optional).

tpsLimit
any

Inbound throughput cap, 1–1000 messages/second; additionally plan-tier-capped service-side (optional).

allowedCidrs
any

Up to 16 IPv4/IPv6 CIDR strings that gate which source IPs may bind (optional; empty means any).

dlrMode
any

Delivery-receipt delivery mode: bind, webhook or both (optional, defaults to bind).

dlrWebhookUrl
any

HTTPS webhook endpoint for DLRs; required when dlrMode is webhook or both (optional otherwise).

Response

The created credential plus the one-shot plaintext password and a password_visible_once_warning reminder, wrapped in the standard { data, meta } envelope. Within 60 seconds the secret can be re-fetched via GET /:id/reveal; after that it is unrecoverable (use /rotate). A 403 fires when tpsLimit exceeds the plan tier and 422 when the body is invalid.

The created credential plus the one-shot plaintext password and a password_visible_once_warning reminder, wrapped in the standard { data, meta } envelope. Within 60 seconds the secret can be re-fetched via GET /:id/reveal; after that it is unrecoverable (use /rotate). A 403 fires when tpsLimit exceeds the plan tier and 422 when the body is invalid.