FOR DEVELOPERS

SMS API for Bangladesh: a clean REST SMS gateway

The GotiSMS SMS API is a REST/JSON gateway for sending SMS to every Bangladeshi operator: one POST request with a Bearer API key sends to up to 1,000 recipients. Idempotency keys make retries safe, and API keys can be restricted to your server IPs.

REST and JSON

Plain HTTPS requests that work from any language or framework.

1,000 recipients per call

Send to up to 1,000 Bangladeshi numbers in a single request.

Idempotent by design

Retry with the same Idempotency-Key and nothing is sent or charged twice.

IP allow-list

Optionally lock each API key so it only works from your own servers.

Quick start

You can send your first message through the API in a few minutes:

  1. Create a GotiSMS account at gotisms.com/register and top up your Taka wallet.
  2. In the dashboard, create an API key. Optionally add your server IPs to its allow-list.
  3. Pick a sender: your default non-masking sender, or an approved masking sender ID.
  4. Send a POST request to https://api.gotisms.com/api/messages/send.

Every request is authenticated with the header Authorization: Bearer YOUR_API_KEY. The request body is JSON with four fields:

  • recipients: an array of Bangladeshi mobile numbers (up to 1,000).
  • senderId: the sender name or number to use.
  • message: the text, in English or Bangla.
  • category: "transactional" or "otp".

Full reference: API documentation.

Example: cURL

curl -X POST https://api.gotisms.com/api/messages/send \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: order-10482-shipped" \
  -d '{
    "recipients": ["01712345678", "8801812345678", "+8801912345678"],
    "senderId": "YourBrand",
    "message": "Your order #10482 has shipped and will arrive within 2 days.",
    "category": "transactional"
  }'

The three recipients above show the accepted number formats: local 01712345678, 8801712345678 with the country code, and +8801712345678 in international format. You can mix them in one request.

A success response means the messages were accepted for sending. It does not yet mean they were delivered; see the delivery reports section below.

Example: Node.js

Using the built-in fetch in Node.js 18 or later:

import { randomUUID } from 'node:crypto';

async function sendSms(recipients, message) {
  const res = await fetch('https://api.gotisms.com/api/messages/send', {
    method: 'POST',
    headers: {
      'Authorization': 'Bearer ' + process.env.GOTISMS_API_KEY,
      'Content-Type': 'application/json',
      'Idempotency-Key': randomUUID(),
    },
    body: JSON.stringify({
      recipients,
      senderId: 'YourBrand',
      message,
      category: 'transactional',
    }),
  });

  if (!res.ok) {
    throw new Error('GotiSMS error ' + res.status + ': ' + (await res.text()));
  }
  return res.json();
}

await sendSms(['01712345678'], 'Your appointment is confirmed for 10:30 tomorrow.');

In production, generate the idempotency key once per logical message and store it, so a retry reuses the same key. The integration tutorial walks through this pattern step by step.

Idempotency, limits and security

Idempotency-Key

Send an Idempotency-Key header with every request. If a request times out and you retry with the same key, GotiSMS recognises it as the same request. The same key never sends or charges twice.

Rate limits

LimitValue
Recipients per requestUp to 1,000
Requests per minute300 per API key (default)

The per-minute limit can be adjusted for higher-volume senders. Contact support if you need more.

Protecting your keys

  • Keep API keys on your server, never in mobile apps or browser code.
  • Use the optional IP allow-list so a key only works from your servers.
  • Create separate keys for separate systems, and revoke any key you suspect is exposed.
  • Review sign-in history and team roles in the dashboard regularly.

Delivery reports

An accepted request and a delivered message are two different things. After GotiSMS accepts your request, the message is passed to the operator, and the final status arrives later.

To track delivery:

  • Poll the reports endpoints from your backend to read the status of messages you have sent. A periodic job that checks recent sends works well.
  • Use the Campaigns page in the dashboard to see delivery results without writing any code.

Keep a record of what you sent and when, so you can match report entries back to your own orders, users or verification attempts. Endpoint details and response formats are in the API documentation.

Promotional messages through the API

The /api/messages/send endpoint is for transactional and OTP traffic, which can be sent at any time. Promotional campaigns follow different rules in Bangladesh: the exact text has to be approved by the operators, and sending is only allowed between 09:00 and 21:00 Bangladesh time.

For that reason, promotional messages go through a separate endpoint, POST /api/messages/campaign-requests. You submit the campaign, it goes through approval, and it is sent within the permitted window.

Please do not send marketing content under the transactional or OTP category. Keeping categories accurate protects your sender reputation and keeps your traffic flowing. See the OTP SMS page for verification-code best practices.

Frequently asked questions

Is the GotiSMS API REST or SOAP?

It is a REST API that accepts and returns JSON over HTTPS. You can call it from any language with an HTTP client.

How many numbers can I send to in one API request?

Up to 1,000 recipients per request. For larger lists, split them into batches of 1,000 or fewer.

Which phone number formats does the API accept?

Bangladeshi numbers as 01712345678, 8801712345678 or +8801712345678. You can mix formats in the same request.

How do I get delivery status from the API?

Read delivery status from the reports endpoints, or view it on the Campaigns page in the dashboard. An accepted send request does not by itself mean the message was delivered.

What is the API rate limit?

The default is 300 requests per minute per API key. It can be adjusted if your traffic needs more.

Can I send promotional SMS through the API?

Yes, through POST /api/messages/campaign-requests. Campaign text is approved by the operators and sent between 09:00 and 21:00 Bangladesh time.

Related

Ready to send your first SMS?

Create an account, top up with bKash and start sending in minutes.

Create free account