Skip to main content

PHP SDK

The Orbit PHP SDK wraps the platform’s core API resources — messaging (SMS, WhatsApp, email), voice, contacts, campaigns, verify (OTP), and webhook signature verification — with typed clients. It requires PHP 8.1+ with ext-curl, ext-json, and ext-openssl.
Pre-publish — source-only. This SDK is not yet on Packagist — any composer require against it fails today. Until first publish, vendor the source from the monorepo (packages/sdk-php/) or call the REST API directly. See PHP: core-scope, not full parity on the SDK index for exactly what is and isn’t wrapped, and the low-level $client->request(method: ..., path: ..., ...) escape hatch for uncovered routes (worked example below).

Installation

Not installable from Packagist yet. Vendor the SDK source from the monorepo (packages/sdk-php/) via a Composer path repository, or call the REST API directly with any HTTP client until the first release ships (coordinates change).

Client initialization

Or read the key from an environment variable (ORBIT_API_KEY):
Tune timeouts and retries with the direct constructor:

Quickstart: send your first SMS

A runnable end-to-end — the key comes from ORBIT_API_KEY, never from source. Copy it into first-send.php and run it with php first-send.php:
Point ORBIT_API_KEY at a sandbox key prefixed dv_test_sk_ first — sandbox sends are simulated, free, and never reach a carrier. Swap in your live key (dv_live_sk_...) when you’re ready to send for real; the code does not change. The response shape above comes from the Messages API reference — its language tabs include this exact call.

Messaging

Voice

Verify (OTP)

The send-and-check round trip is the most common first integration on the platform — here as a complete flow. Send the code, keep the returned verification id, and check the code the user typed in against it:
A wrongly-typed or expired code reports valid: false — it never throws for a bad guess (only for transport/auth failures), so branch on the flag. The Verify API reference covers the full contract, and Starter examples ships a complete OTP sign-in starter repo (orbit-otp-nextjs).

Contacts

$client->contacts also exposes get, update, and delete by id.

Campaigns

Paginate a list

List endpoints are cursor-paginated — read meta.pagination.cursor and meta.pagination.has_more off each response and pass the cursor back as a query param until has_more is false. Page through SMS messages with the escape hatch:
The full pagination model (cursor vs. offset endpoints, page-size caps, and why cursors are not bookmarkable) is in the Pagination guide.

Error handling

All Orbit-originated errors inherit from Devotel\Orbit\Errors\OrbitError:
Every non-GET request automatically carries an Idempotency-Key header (UUIDv4); override it per call with your own stable key (idempotencyKey: 'job-7a3b9d-attempt-1').

Covered route missing? Use the escape hatch

The typed clients wrap 8 core resources; the rest of the API — contact segments, event sinks, frequency caps, and everything else listed as out of scope on the SDK index — is reachable through $client->request(method, path, ...). It returns the raw JSON body as an array. Fetch a segment by id:
The escape hatch carries the same auth, retry, and error model as the typed clients — treat it as a first-class client, not a fallback cURL call.

Webhook signature verification

Signatures use the t=<unix_ts>,v1=<hex_hmac> format (same as Stripe) with a 5-minute replay window enforced by default.