FAQ
Questions, answered
29 straight answers about sending, OTP, the API, billing and privacy. Can't find yours? Write to us and a person will reply.
Getting started
What is SMSRay?
SMSRay is an SMS API for Nepal by Lacspace. You can send one-time passwords (OTP), transactional messages and two-way SMS from real local mobile numbers across NTC, Ncell, Smart, with delivery receipts, signed webhooks and a live dashboard.
How do I create an account?
Go to app.smsray.in and sign in with your phone number or email address. We send you a one-time code, and your workspace is created when you verify it. There is no password to remember.
Why is my new workspace pending?
Every new workspace starts as pending until Lacspace reviews and activates it. This protects recipients and the shared SIM pool from abuse. While pending you can explore the dashboard, but sending requests are refused with a workspace_pending error. We may contact you about your use case before activating.
Which numbers can I send to?
Nepal mobile numbers only today (10 digits starting with 96, 97 or 98). Requests to other numbers are rejected with an invalid_request error and are not charged. International sending is not available yet.
Sending and delivery
Which networks do you support?
NTC, Ncell, Smart. Our pool holds SIM cards on each network, and the router prefers a SIM on the same network as the recipient (on-net) where one is available.
What number will my recipients see?
Messages are sent from a real local mobile number belonging to a Lacspace SIM in our managed pool. Custom alphanumeric sender names are not available today, so start your message with your app or business name so people know who it is from. OTP messages sent through the OTP endpoint include your app name automatically.
How does SMSRay choose which SIM sends my message?
The router prefers on-net SIMs, paces each SIM at no more than 30 sends per 30 minutes to stay under Android's sending limit, tracks daily quotas that reset on Nepal time, and skips SIMs that are stale, failing or out of quota. If a send fails, it is retried once on another SIM.
What do the message statuses mean?
A message moves through queued, submitting and submitted while it is being handed to a phone, then sent when the phone has sent it and delivered when the network confirms delivery. Undelivered, failed and rejected are final unsuccessful states. Webhooks simplify these into queued, sent, delivered, undelivered and failed.
How fast are messages delivered?
Most of the work happens within seconds of your API call, but final delivery depends on the mobile network and the recipient's phone (for example, if it is switched off). We don't promise a delivery time, so design important flows such as sign-in with a resend option.
Can people reply to my messages?
Yes. Replies to our pool numbers are delivered to you as message.inbound webhooks, linked to the message they answer where we can match them, and they appear in the Inbound section of your dashboard.
How are long messages and Nepali text counted?
Messages in the GSM-7 character set fit 160 characters in one segment, or 153 per segment when split. Messages that need Unicode (UCS-2), including Nepali in Devanagari and emoji, fit 70 characters in one segment, or 67 per segment when split. A message can use up to 6 segments.
OTP verification
How does the OTP API work?
Call POST /sms/otp/send with the phone number. We generate a 6-digit code and send it branded with the brand name set on your API client, for example "<App>: 482913 is your verification code. Valid for 5 minutes. Do not share it." When the user types the code, call POST /sms/otp/verify and we tell you whether it matches.
What limits apply to OTP?
A code expires after 5 minutes and allows 5 verification attempts. There is a 60-second resend cooldown, a maximum of 3 per 10 minutes for any number across all customers, and, if you pass the end user's IP address, a maximum of 10 per IP per 10 minutes.
What happens when a user enters the wrong code?
A wrong code is not an API error. The verify call returns 200 with verified set to false and a reason: invalid_code, too_many_attempts or no_active_otp. You decide what to show the user.
Do you store the OTP codes?
Only a SHA-256 hash of each code is stored, never the code itself, and the OTP text is shown as "(OTP hidden)" in message logs and the dashboard.
Developers
Is there an SDK?
Not yet. SMSRay is a plain REST API, so any HTTP client works. The documentation includes ready-to-copy examples in cURL, Node.js, Python and PHP.
How do I authenticate API requests?
Create an API key in the dashboard and send it in the x-api-key header with every request to https://api.smsray.in/api/sms/v1. Keys are stored as hashes, so copy yours when it is shown. Keep keys on your server, never in a browser or mobile app.
How do I retry safely without sending twice?
Send an Idempotency-Key header with POST requests. If you repeat a request with the same key within 24 hours, you get the original response back instead of a second message. Reusing a key with a different body returns idempotency_conflict.
How do webhooks work?
Set a webhook URL on your API client to receive message.status and message.inbound events. Each request is signed with HMAC-SHA256 in the x-lacspace-signature header (t=timestamp, v1=signature), which you should verify with a ±300 s tolerance. Failed deliveries are retried up to 8 times over about 10 hours, and delivery history is kept for 7 days.
Is there a rate limit?
Yes. Each API client can send 20 requests per second by default. Above that you get a 429 rate_limited response with a Retry-After header. Contact us if you need a higher limit.
Billing
How does pricing work?
SMSRay is prepaid. Your workspace has a balance, and each message is charged per segment at the rate agreed for your workspace. Rates depend on your volume and use case, so talk to our sales team for yours.
Am I charged for messages that fail?
If a message finally fails after routing and the retry on another SIM, its charge is refunded to your balance automatically. Requests that are rejected before sending, such as non-Nepal numbers, are not charged.
What happens when my balance runs out?
Send requests are refused with a 402 insufficient_balance error and nothing is sent. You can check your balance at any time with GET /sms/balance or in the dashboard.
Security and privacy
Who can see my messages?
Members of your workspace can see your messages in the dashboard. OTP text is always hidden. Lacspace staff access data only as needed to operate, secure and support the service. Every change in the portal is recorded in an audit log, and you can review and revoke your active sessions.
How long do you keep data?
OTP codes expire after 5 minutes, webhook delivery history is kept for 7 days, and message history is kept while your workspace is active so you can review it and reconcile billing. See the Privacy Policy for details.
Does SMSRay handle STOP or opt-out replies?
Automatic STOP handling is coming soon. Until then, replies reach you as inbound messages, and you are responsible for recording and honouring opt-out requests yourself, as our Anti-Spam Policy requires.
How do I report spam or abuse?
Email abuse@lacspace.com with the sending number, the date and time and the message text. For security vulnerabilities, write to security@lacspace.com.
Voice (coming soon)
Do you offer voice calls?
Not yet. Voice is coming soon, starting with missed-call verification, call alerts and voice OTP, and later IVR and AI voice agents. Nothing in the voice product is available today.
How can I hear when voice is available?
Email sales@lacspace.com and tell us what you would like to use voice for. We'll get in touch when it is ready.
Still have a question?
Email support@lacspace.com or use the contact form.
Send your first SMS today
Create a workspace in a minute with your phone number or email. No card needed to explore the dashboard.