SendIt External API
Send SMS, launch campaigns, and track delivery programmatically from your own
application. Every request authenticates with a single X-API-Token header —
no OAuth flow, no expiring session.
Getting started
Three steps between reading this page and your first delivered SMS.
| 1 | Create an organization account, then generate an API token from
Account Settings → API Tokens (requires the Account Admin or Admin
role). The plaintext token is shown once — store it in a secrets manager, never in a
repository. |
|---|---|
| 2 | Every code sample below already uses this SendIt instance's own address — no placeholder to find and swap out. |
| 3 | Send your first request with any snippet on this page — try SMS → Send a single SMS first. |
Authentication
Every endpoint resolves its organization exclusively from this header — never from anything in the request body. A token can only ever act as its own organization.
| Base URL | |
|---|---|
| Header | X-API-Token: <your-plaintext-token> |
Rate limiting
Requests are limited per token on a sliding window — default 60
requests / 60 seconds, configurable per deployment. Every response carries these headers so
an integration can back off proactively instead of waiting for a 429.
X-RateLimit-Limit | Requests allowed in the current window |
|---|---|
X-RateLimit-Remaining | Requests left in the current window |
X-RateLimit-Window | Window length in seconds (429 responses only) |
Error codes
Every error response shares the same {"error": "message"}
JSON shape.
SMS
cm.intelso.dev.sendit.api.external.SmsManagementEndPoint
— /api/v1/sms/**
Campaigns
cm.intelso.dev.sendit.api.external.CampaignManagementEndPoint
— /api/v1/campaigns/**
