OTP SMS API Documentation
Integrate NinzaSMS OTP delivery into your application using HTTP requests, Bearer authentication, JSON payloads and PHP cURL. This guide explains the request structure, parameters, response format and basic error handling.
1. API Overview
The NinzaSMS API allows an application to submit OTP delivery requests. Your application authenticates with its API key, submits the required parameters and checks the returned JSON response.
| API format | JSON |
|---|---|
| HTTP method | POST |
| Authentication | Bearer API key |
| Content-Type | application/json |
| Response format | JSON |
status field.
An HTTP response alone does not prove that an OTP was
delivered to the recipient.
2. Authentication
Send your API key in the HTTP Authorization header using the Bearer format.
Authorization: Bearer YOUR_API_KEY
Content-Type: application/json
Replace YOUR_API_KEY with the API key
associated with your NinzaSMS account. Keep the key
on your server and never expose it in browser-side
JavaScript or public repositories.
3. API Endpoint
Public endpoint configured in this documentation:
POST https://ninzasms.in.net/auth/api/send_sms.php
4. Request Parameters
| Parameter | Required | Description |
|---|---|---|
sender_id |
Yes | Account user ID expected by the supplied backend. |
numbers |
Yes | Recipient mobile number. Follow the format accepted by your API. |
variables_values |
No | OTP or variable value. The supplied backend uses this field for OTP processing. |
message |
No | Optional message field supported by the supplied backend. |
rout |
No |
sms is the default route;
waninza selects the
WhatsApp route in the supplied code.
|
The exact accepted number formats, OTP length, message template rules and route availability depend on the active backend implementation and account setup.
5. JSON Request Example
Example request body for the SMS route:
{
"sender_id": 123,
"numbers": "9876543210",
"variables_values": "123456",
"rout": "sms"
}
Replace the example user ID, mobile number and OTP with your own server-side values. The example OTP is for demonstration only.
cURL command
curl -X POST \
"https://ninzasms.in.net/auth/api/send_sms.php" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"sender_id": 123,
"numbers": "9876543210",
"variables_values": "123456",
"rout": "sms"
}'
6. PHP cURL Integration
Run this example from your backend PHP application.
It sends a JSON request and checks the HTTP code and
the API's status field.
<?php
$apiKey = 'YOUR_API_KEY';
/*
* Confirm this endpoint matches your deployed backend.
*/
$apiUrl = 'https://ninzasms.in.net/auth/api/send_sms.php';
$payload = [
'sender_id' => 123,
'numbers' => '9876543210',
'variables_values' => '123456',
'rout' => 'sms',
];
$ch = curl_init($apiUrl);
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CONNECTTIMEOUT => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer ' . $apiKey,
'Content-Type: application/json',
'Accept: application/json',
],
CURLOPT_POSTFIELDS => json_encode($payload),
]);
$responseBody = curl_exec($ch);
$curlError = curl_error($ch);
$httpCode = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
curl_close($ch);
if ($responseBody === false) {
error_log('NinzaSMS cURL error: ' . $curlError);
exit('Unable to connect to the OTP service.');
}
$response = json_decode($responseBody, true);
if (!is_array($response)) {
error_log('NinzaSMS returned a non-JSON response. HTTP: ' . $httpCode);
exit('Invalid response received from the OTP service.');
}
if (
$httpCode >= 200 &&
$httpCode < 300 &&
isset($response['status']) &&
(int) $response['status'] === 1
) {
echo 'API accepted the request: ';
echo htmlspecialchars(
(string) ($response['msg'] ?? 'Success'),
ENT_QUOTES,
'UTF-8'
);
} else {
$message = (string) (
$response['msg'] ?? 'OTP request failed.'
);
echo 'Request failed: ';
echo htmlspecialchars($message, ENT_QUOTES, 'UTF-8');
}
?>
This example checks the JSON status returned by the API. A success response means the API reported success; it does not independently verify handset delivery.
7. JSON Response Examples
Successful request
{
"status": 1,
"msg": "✅ OTP Sent Successfully",
"balance": 4.6
}
Illustrative response. The balance value depends on the account and transaction.
WhatsApp route success
{
"status": 1,
"msg": "✅ OTP Sent via WhatsApp",
"balance": 4.9
}
The supplied response helper uses a WhatsApp-specific
success message when the route is
waninza.
Invalid mobile number
{
"status": 0,
"msg": "❌ Invalid mobile number. Please provide a valid 10-digit number.",
"balance_deducted": false,
"otp_sent": false
}
Insufficient balance
{
"status": 0,
"msg": "❌ Insufficient balance. Please recharge your account."
}
Authentication error
{
"status": 0,
"msg": "Invalid API Key."
}
Gateway unavailable
{
"status": 0,
"msg": "⚠️ Your network issue, please try again."
}
Examples above reflect the supplied
response_helper.php. Actual responses can
include additional fields depending on the endpoint
and execution path.
8. HTTP Status Codes and Errors
| HTTP code | Meaning in the supplied helper |
|---|---|
200 |
Success response. Check
status as well.
|
400 |
General request error; used for invalid numbers. |
401 |
Authentication error. |
402 |
Insufficient account balance. |
503 |
Gateway or service failure. |
Your application should handle both HTTP errors and JSON responses gracefully. Do not assume that every failed request can safely be retried: a timeout may happen after a request was already processed.
9. Security and Responsible Use
- Keep API keys private and store them in server-side configuration.
- Use HTTPS for API requests.
- Validate mobile numbers and user input on your server.
- Apply rate limits and abuse prevention to OTP endpoints.
- Avoid logging API keys, OTP values or other sensitive information.
- Use OTP messaging only for authorized recipients and legitimate purposes.
- Follow applicable telecom, consent, sender registration and DLT requirements for your use case.
10. Frequently Asked Questions
How do I authenticate API requests?
Include your API key in the
Authorization header using
Bearer YOUR_API_KEY.
How do I check whether the request succeeded?
Parse the JSON response and check whether
status equals 1.
Also inspect the HTTP status and handle errors.
Can I use the WhatsApp route?
The supplied backend recognizes
rout: "waninza" for its WhatsApp route.
Actual availability depends on the configured
service and connected account.
Why might the API return an error?
Possible causes include an invalid API key, invalid mobile number, insufficient balance, rate limiting or temporary service failure.
Does a success response guarantee handset delivery?
Not by itself. The response reflects what the API reports. Delivery confirmation requires reliable delivery-status information from the actual sending service, if available.
What should I do if the endpoint does not work?
Verify your API key and request format, and inspect server-side logs without exposing credentials.
Start Your Integration
Use the request and response examples above as a starting point. Before deploying, test with your own account and verify the actual endpoint, route behavior, billing behavior and delivery reporting.
Visit NinzaSMSBulk SMS Without DLT: What Should Businesses Check?
If you are searching for bulk SMS without DLT, confirm the applicable requirements for your message category, route and telecom operator. NinzaSMS does not promise a blanket exemption from DLT or other telecom rules. Ask support to confirm the appropriate compliant option for your use case.