PHP SDK
The Orbit PHP SDK wraps the platform’s core API resources — messaging (SMS, WhatsApp, email), voice, contacts, campaigns, verify (OTP), and webhook signature verification — with typed clients. It requires PHP 8.1+ withext-curl, ext-json, and ext-openssl.
Pre-publish — source-only. This SDK is not yet on Packagist —
any
composer require against it fails today. Until first publish,
vendor the source from the monorepo (packages/sdk-php/) or call the
REST API directly. See
PHP: core-scope, not full parity
on the SDK index for exactly what is and isn’t wrapped, and the low-level
$client->request(method: ..., path: ..., ...) escape hatch for uncovered routes
(worked example below).Installation
Not installable from Packagist yet. Vendor the SDK source from the monorepo (packages/sdk-php/) via a Composer path repository, or call the REST API
directly with any HTTP client until the first release ships (coordinates change).
Client initialization
ORBIT_API_KEY):
Quickstart: send your first SMS
A runnable end-to-end — the key comes fromORBIT_API_KEY, never from
source. Copy it into first-send.php and run it with php first-send.php:
ORBIT_API_KEY at a sandbox key prefixed dv_test_sk_ first —
sandbox sends are simulated, free, and never reach a carrier. Swap in your
live key (dv_live_sk_...) when you’re ready to send for real; the code
does not change.
The response shape above comes from the
Messages API reference — its language
tabs include this exact call.
Messaging
Voice
Verify (OTP)
The send-and-check round trip is the most common first integration on the platform — here as a complete flow. Send the code, keep the returned verification id, and check the code the user typed in against it:valid: false — it never throws
for a bad guess (only for transport/auth failures), so branch on the flag.
The Verify API reference covers the full
contract, and Starter examples ships a complete
OTP sign-in starter repo (orbit-otp-nextjs).
Contacts
$client->contacts also exposes get, update, and delete by id.
Campaigns
Paginate a list
List endpoints are cursor-paginated — readmeta.pagination.cursor and
meta.pagination.has_more off each response and pass the cursor back as a
query param until has_more is false. Page through SMS messages with the
escape hatch:
Error handling
All Orbit-originated errors inherit fromDevotel\Orbit\Errors\OrbitError:
Idempotency-Key header (UUIDv4); override it per call with your own stable key (idempotencyKey: 'job-7a3b9d-attempt-1').
Covered route missing? Use the escape hatch
The typed clients wrap 8 core resources; the rest of the API — contact segments, event sinks, frequency caps, and everything else listed as out of scope on the SDK index — is reachable through$client->request(method, path, ...). It returns the raw JSON body as an array. Fetch a segment by id:
Webhook signature verification
t=<unix_ts>,v1=<hex_hmac> format (same as Stripe) with a 5-minute replay window enforced by default.