Introduction and authentication
The DevSMS API is a REST interface that returns JSON. Every request goes over HTTPS with an Authorization header. The main endpoints are /api/sms/send, /api/balance, /api/sms/history, /api/sms/status and /api/devices. The versioned API v1 (last section) adds duplicate protection, error codes and key abilities.
https://devsms.uz/apiAuthorization: Bearer YOUR_API_TOKENImportant
- Token: send
Authorization: Bearer YOUR_API_TOKENwith every request. Get your token on the API keys page of the cabinet (/app/api-keys). - A blocked account gets
403and the textSizning hisobingiz bloklanganon every endpoint; a missing or invalid token gets401. - A personal key over the plan limit gets
403witherror_code: token_locked_by_plan: the oldest keys keep working up to the plan limit. Upgrade or delete an older key — the next one works immediately. The main (legacy) API key is never blocked. - Limits:
/api/sms/sendallows 300 requests per minute per user and 500 requests per minute per IP; beyond that you get429. Other endpoints have no limit. - Response shape: on success
{"success":true,"message":"…","data":{…}}, on error{"success":false,"error":"…"}(some errors carry extra keys:charged,sms_id,reject_streak). - Phone numbers are accepted in any format:
998901234567,+998 (90) 123-45-67,901234567. International numbers are accepted only if international SMS is enabled for your account. - Times use the
Y-m-d H:i:sformat in Tashkent time (UTC+5).