SMS APIs are the backbone of modern application messaging - powering appointment reminders, authentication codes, order notifications, and bulk marketing campaigns programmatically. If you're building an application that needs to send or receive SMS in Australia, this guide walks you through everything: what an SMS API is, how to authenticate, how to send and receive messages, handle delivery receipts, and avoid the common pitfalls.
What is an SMS API?
An SMS API (Application Programming Interface) is a service endpoint that allows your application to send and receive SMS messages programmatically - without manual intervention. Rather than logging into a dashboard to send messages, your code makes HTTP requests to the API, which routes messages through carrier networks to the recipient's handset.
SMS APIs are used for:
- Transactional messages - order confirmations, delivery updates, password resets, 2FA codes
- Appointment reminders - automated notifications triggered by booking system events
- Bulk campaigns - sending a promotional message to thousands of contacts programmatically
- Two-way conversations - receiving customer replies and routing them to agents or automated flows
REST API vs SMPP - Which Should You Use?
| Feature | REST API | SMPP |
|---|---|---|
| Protocol | HTTPS / JSON | Binary TCP |
| Ease of integration | Very easy | Complex |
| Throughput | Moderate (hundreds/sec) | Very high (thousands/sec) |
| Best for | Most applications | Telcos, very high volume |
| Library support | Excellent | Limited |
| Real-time connection | No (stateless) | Yes (persistent) |
For the vast majority of Australian developers and businesses, a REST API is the right choice. It's simpler to integrate, well-supported by every major programming language, and more than capable of handling thousands of messages per hour. SMPP is only worth the added complexity if you're processing millions of messages per day at telco-grade throughput.
The remainder of this guide focuses on REST API integration.
Authentication
Most SMS APIs use one of two authentication methods:
API Key (Bearer Token)
You generate an API key from your provider dashboard and include it in the HTTP Authorization header. This is the most common and simplest approach.
Authorization: Bearer YOUR_API_KEY Content-Type: application/json
Basic Auth
Some APIs use HTTP Basic Authentication with a username (often your account ID) and API key as the password, Base64-encoded.
Security note: Never hardcode API keys in your source code. Use environment variables or a secrets manager. Treat your API key like a password - rotate it immediately if it's ever exposed.
Sending a Message
The core operation of any SMS API is sending a message. Here's how a typical REST request looks across three common languages.
cURL
curl -X POST https://api.monstersms.ai/v1/messages \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"from": "MyBusiness",
"to": "+61412345678",
"body": "Hi Sarah, your order #4821 has shipped! Track: https://track.example.com/4821 Reply STOP to opt out.",
"reference": "order-4821"
}'
Python
import requests
import os
API_KEY = os.environ.get("SMS_API_KEY")
API_URL = "https://api.monstersms.ai/v1/messages"
def send_sms(to, body, reference=None):
headers = {
"Authorization": f"Bearer {API_KEY}",
"Content-Type": "application/json"
}
payload = {
"from": "MyBusiness",
"to": to,
"body": body,
}
if reference:
payload["reference"] = reference
response = requests.post(API_URL, json=payload, headers=headers)
response.raise_for_status()
return response.json()
# Example usage
result = send_sms(
to="+61412345678",
body="Hi Sarah, your order has shipped! Reply STOP to opt out.",
reference="order-4821"
)
print(f"Message ID: {result['id']}, Status: {result['status']}")
Node.js
const axios = require('axios');
const API_KEY = process.env.SMS_API_KEY;
const API_URL = 'https://api.monstersms.ai/v1/messages';
async function sendSMS(to, body, reference) {
try {
const response = await axios.post(
API_URL,
{
from: 'MyBusiness',
to,
body,
reference,
},
{
headers: {
Authorization: `Bearer ${API_KEY}`,
'Content-Type': 'application/json',
},
}
);
return response.data;
} catch (error) {
console.error('SMS send failed:', error.response?.data || error.message);
throw error;
}
}
// Example usage
sendSMS(
'+61412345678',
'Hi Sarah, your order has shipped! Reply STOP to opt out.',
'order-4821'
).then(result => {
console.log(`Message ID: ${result.id}, Status: ${result.status}`);
});
Sending Bulk Messages
To send to multiple recipients simultaneously, most APIs accept an array of numbers or a dedicated bulk endpoint:
curl -X POST https://api.monstersms.ai/v1/messages/bulk \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"from": "MyBusiness",
"recipients": [
{ "to": "+61412345678", "body": "Hi Sarah, your order has shipped!" },
{ "to": "+61498765432", "body": "Hi James, your order has shipped!" }
],
"scheduled_at": "2026-02-21T09:00:00+11:00"
}'
Receiving Replies - Webhooks
To enable two-way SMS, your application needs to receive incoming messages. SMS APIs use webhooks - HTTP POST requests sent to a URL you specify whenever a message arrives on your virtual number.
Setting Up a Webhook
- Expose a publicly accessible HTTPS endpoint in your application
- Configure the webhook URL in your SMS provider dashboard or via API
- Handle incoming POST requests containing the inbound message data
- Return a 200 OK response promptly (process asynchronously if needed)
{
"id": "inbound_abc123",
"from": "+61412345678",
"to": "+61800123456",
"body": "STOP",
"received_at": "2026-02-21T09:14:33Z",
"type": "inbound"
}
const express = require('express');
const app = express();
app.use(express.json());
app.post('/webhooks/sms-inbound', async (req, res) => {
const { from, body, to, id } = req.body;
// Always respond 200 quickly
res.status(200).json({ received: true });
// Process asynchronously
setImmediate(async () => {
const normalised = body.trim().toUpperCase();
if (normalised === 'STOP') {
await handleUnsubscribe(from);
console.log(`Unsubscribed: ${from}`);
} else if (normalised === 'YES') {
await handleConfirmation(from);
} else {
// Route to AI agent or human agent queue
await routeToAgent(from, body);
}
});
});
app.listen(3000, () => console.log('Webhook listener running on :3000'));
Delivery Receipts
Delivery receipts (DLRs) tell you whether your message was successfully delivered to the handset. Like inbound messages, they arrive via webhook:
{
"message_id": "msg_xyz789",
"reference": "order-4821",
"status": "delivered",
"delivered_at": "2026-02-21T09:01:12Z",
"to": "+61412345678"
}
Common status values:
delivered- successfully received by the handsetfailed- undeliverable (invalid number, handset off for extended period)queued- accepted by the carrier, awaiting deliverysent- submitted to carrier network, delivery unconfirmedundelivered- carrier attempted delivery but failed
Rate Limits
Australian SMS APIs typically apply rate limits to prevent abuse and ensure network stability. Common limits:
- Per-second (TPS): 10–100 messages per second, depending on account tier
- Per-day: Usually aligned to your plan's monthly allowance
- Burst limits: Some APIs allow short bursts above the sustained rate
When you exceed a rate limit, the API returns HTTP 429 Too Many Requests. Implement exponential backoff in your retry logic:
import time
import requests
def send_with_retry(payload, headers, max_retries=3):
for attempt in range(max_retries):
response = requests.post(
"https://api.monstersms.ai/v1/messages",
json=payload,
headers=headers
)
if response.status_code == 200:
return response.json()
elif response.status_code == 429:
wait = 2 ** attempt # 1s, 2s, 4s
print(f"Rate limited. Retrying in {wait}s...")
time.sleep(wait)
else:
response.raise_for_status()
raise Exception("Max retries exceeded")
Error Handling
Always handle API errors gracefully. Common HTTP status codes and what they mean:
- 400 Bad Request - invalid payload (check your JSON structure, phone number format)
- 401 Unauthorized - invalid or missing API key
- 402 Payment Required - insufficient credits on your account
- 403 Forbidden - action not permitted (e.g., sending to an opted-out number)
- 422 Unprocessable Entity - validation error (invalid phone number format, message too long)
- 429 Too Many Requests - rate limit hit, back off and retry
- 500 / 503 - server-side error, retry with backoff
Phone number formatting: Australian mobile numbers should be submitted in E.164 format: +61 followed by the 9-digit number (drop the leading 0). For example, 0412 345 678 becomes +61412345678. Always validate and normalise numbers before sending.
Choosing an SMS API Provider in Australia
When evaluating providers, consider:
Australian Routing
Messages should route through Australian carriers for reliability and latency. Offshore routing adds delay and can reduce delivery rates.
Compliance Support
Look for providers that handle unsubscribe suppression automatically and maintain opt-out lists across your account.
Delivery Receipts
Real carrier-level delivery receipts (not just gateway receipts) are essential for accurate campaign measurement.
Two-Way Numbers
Dedicated virtual numbers allow recipients to reply. Shared shortcodes are cheaper but limit two-way capability.
Documentation Quality
Clear, accurate API docs with code examples in multiple languages save hours of integration time.
Support Availability
When something breaks in production, Australian business-hours support is worth its weight in gold.
Monster SMS API Features
Monster SMS provides a clean REST API built for Australian developers and businesses:
- Simple JSON API with API key authentication
- Send individual messages and bulk campaigns
- Inbound message webhooks for two-way SMS
- Delivery receipt callbacks
- Automatic STOP/unsubscribe handling (compliant with the Spam Act)
- Scheduled message sending
- Australian virtual numbers for dedicated two-way messaging
- AI agent integration for automated reply handling
- Detailed message logs and analytics via dashboard and API
The free to start — 100 messages on sign-up, with competitive per-message rates for top-ups.
Getting started: Sign up at app.monstersms.ai/sign-up, generate your API key from the developer settings panel, and you can be sending test messages within minutes.
Start Integrating SMS Into Your Application
Monster SMS provides a clean Australian SMS API with webhooks, two-way messaging, and full compliance support. Free plan included.
Start Free - 100 Messages