OTP SMS GATEWAY
OTP SMS in Bangladesh: verification codes, any time of day
GotiSMS sends OTP and verification-code SMS to every Bangladeshi operator 24 hours a day, with no sending window. You call one REST endpoint with category "otp", and an Idempotency-Key header ensures a retried request never sends or charges twice.
OTP and transactional messages can be sent at any hour, every day.
The same Idempotency-Key never sends or charges a message twice.
Codes reach Grameenphone, Robi (incl. Airtel), Banglalink and Teletalk users.
One JSON request with a Bearer API key. Lock keys to your server IPs.
Why OTP SMS still matters
For logins, sign-ups, password resets and payment confirmations, SMS remains the most widely available second factor in Bangladesh. It works on every handset, including feature phones, and does not require the user to install anything.
GotiSMS treats OTP as its own category. Unlike promotional messages, which are restricted to 09:00–21:00 Bangladesh time, OTP and transactional messages can be sent at any time. A customer resetting a password at 2 a.m. gets the code just as they would at noon.
OTP traffic is sent through the same API as other transactional messages, using category: "otp", so there is no separate product to integrate.
Send an OTP with one request
Here is a minimal cURL example. Replace YOUR_API_KEY with a key from your dashboard and use your approved sender ID or default non-masking sender.
curl -X POST https://api.gotisms.com/api/messages/send \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: otp-7f3a9c21-login" \
-d '{
"recipients": ["01712345678"],
"senderId": "YourBrand",
"message": "Your YourBrand code is 482913. It expires in 5 minutes. Do not share it.",
"category": "otp"
}'
A successful response means the message was accepted, not yet delivered. Delivery status is available through the reports endpoints or on the Campaigns page. Full request and response details are in the API documentation.
Idempotency: retry without double-sending
Networks fail. A request might time out on your side even though GotiSMS received it. If your code simply retries, a naive gateway would send the customer two codes and charge you twice.
The Idempotency-Key header prevents that. Generate a unique key for each OTP you intend to send, for example from your verification attempt ID, and reuse the same key if you need to retry that request. GotiSMS recognises the key and will never send or charge for the same message twice.
Good practice:
- Create the key once, when the OTP is generated, and store it with the attempt.
- Use a new key when the user explicitly asks for a new code.
- Never reuse a key across different users or messages.
Keep OTP messages in a single SMS
Billing is per SMS part, and shorter messages also tend to be read faster. For OTP, aim for a single part:
- English (GSM-7) fits 160 characters in one SMS, which is plenty for a code, your brand name and an expiry note.
- Bangla (Unicode) fits only 70 characters. A Bangla OTP message can work well for local audiences, but keep it short.
- Avoid emoji and special symbols. One emoji switches the entire message to Unicode, cutting the limit from 160 to 70.
Many services send the OTP in English even when the app is in Bangla, because digits and a short English sentence fit comfortably in one part. If your users prefer Bangla, test the length using the live counter on the compose screen first. See our guide to SMS character limits.
Security tips for OTP
The SMS is only one part of a secure verification flow. On your side:
- Set a short expiry. Five to ten minutes is common. Reject codes after that.
- Never reuse codes. Generate a fresh random code for each attempt and invalidate it after one successful use.
- Rate-limit requests. Cap how many codes one number or IP can request per hour to block SMS pumping and abuse.
- Limit verification attempts. Lock the attempt after a few wrong guesses.
- Say "do not share" in the message. It reduces social-engineering attacks.
- Protect your API key. Keep it on your server only, and enable the IP allow-list on the key so it only works from your own servers.
More advice is in our article on OTP SMS best practices.
Sender ID and getting started
You can send OTP from your account's default non-masking sender right away. For higher trust, request a masking sender ID so codes arrive under your brand name; customers learn to recognise the genuine sender, which makes phishing harder.
To start:
- Create an account at gotisms.com/register and top up your Taka wallet with bKash or another method.
- Create an API key in the dashboard, optionally restricted to your server IPs.
- Send a test OTP to your own number with the example above.
- Check the delivery result, then wire it into your login or sign-up flow.
Need higher throughput than the default 300 requests per minute? Contact support to have it adjusted.
Frequently asked questions
Can I send OTP SMS at night in Bangladesh?
Yes. OTP and transactional messages have no sending window and can be sent at any time. Only promotional messages are limited to 09:00–21:00 Bangladesh time.
How do I avoid sending the same OTP twice on retry?
Send an Idempotency-Key header with each request and reuse the same key when retrying. GotiSMS will never send or charge twice for the same key.
Should I send OTP in Bangla or English?
English fits 160 characters in one SMS, while Bangla Unicode fits 70. English is usually the safer choice for keeping OTP to one part, but a short Bangla message works too.
Does an accepted API response mean the OTP was delivered?
No. Accepted means GotiSMS has taken the message for sending. Check the reports endpoints or the Campaigns page for the delivery status.
What is the API rate limit for OTP?
The default is 300 requests per minute per API key, and it can be adjusted for your traffic. Each request can include up to 1,000 recipients.
Related
Ready to send your first SMS?
Create an account, top up with bKash and start sending in minutes.
Create free account