WhatsApp API Switching providers? Move your WhatsApp number to CommLeap and keep its display name and quality ratingSwitching WhatsApp providers? Migrate to CommLeap
SMS API

The SMS API for global A2P messaging

Reach customers on mobile networks worldwide with CommLeap's SMS API. Send alerts, one-time passcodes, reminders and two-way conversations through intelligent A2P routing — with sender registration and delivery receipts handled alongside you, and dedicated fraud controls coming soon.

Sender registration support Delivery receipts where carriers provide them
Capabilities

An enterprise SMS gateway, not just a send button

SMS remains the most widely supported mobile messaging channel. CommLeap wraps it in the routing, registration and compliance controls that business messaging at scale depends on, with dedicated fraud controls coming soon.

Intelligent route selection

Messages are matched to A2P routes by destination, sender type and message purpose, with rerouting rules for degraded routes configured with our team during onboarding.

Multiple sender types

Alphanumeric sender IDs where supported, local long codes, toll-free numbers and short codes — managed from one console.

Delivery receipts

Carrier delivery reports normalized into clear statuses and error codes, pushed to your webhook and visible in message logs.

Unicode & long messages

Send in Unicode scripts, with automatic concatenation, encoding detection and a segment count returned before cost surprises you.

Two-way SMS & keywords

Receive replies as structured events, trigger actions from keywords and route conversations to agents or automation.

Automatic opt-out handling

Standard STOP and HELP keywords are handled automatically, with an account-wide suppression list applied to API sends and campaigns.

Scheduling & quiet hours

Schedule sends in the recipient's time zone and hold non-urgent messages outside the sending hours you define.

Link tracking

Shorten links on a branded domain and receive click events per recipient, so you can measure engagement, not just delivery.

Traffic protection Coming soon

Country permissions, velocity limits and anomaly alerts, designed to help catch SMS pumping before it reaches your invoice, are coming soon.

Onboarding

From first conversation to registered senders

Sender rules differ by country, carrier and use case, and incomplete registrations are a common cause of delays. We work through them with you before your first production message.

Map your traffic

Tell us where you send, what you send and how much. We map each flow to a use case category and the destinations it touches.

Choose your senders

We recommend a sender mix per country — alphanumeric, long code, toll-free or short code — based on reach, two-way needs and lead time.

Register

We prepare 10DLC brand and campaign registrations, toll-free verification, short code applications and sender ID pre-registrations, including sample messages and opt-in evidence.

Test and ramp

Send test messages, confirm webhooks and opt-out handling, then ramp production volume while we monitor delivery.

Sender types

Choosing the right sender for each market

The sender your customers see affects trust, reply capability, throughput and how long it takes to go live. Most enterprises use more than one.

Sender typeWhat recipients seeRepliesTypical useRegistration notes
Alphanumeric sender IDYour brand name, up to 11 charactersGenerally one-wayAlerts, passcodes and notifications with strong brand recognitionNot supported in some countries, including the US and Canada; pre-registration required in many others
Long code (local number)A standard local phone numberTwo-wayConversational messaging, customer care, remindersIn the US, A2P use requires 10DLC brand and campaign registration; throughput depends on the result
Toll-free numberA toll-free numberTwo-wayNational notifications and support linesIn the US, toll-free numbers must be verified before sending A2P traffic
Short codeA short number, typically 5–6 digitsTwo-wayHigh-volume campaigns, passcodes and time-critical alertsCarrier-approved program, typically with the longest lead time (often several weeks); availability varies by country

Registration rules change — we keep track

Sender requirements vary by country and carrier and are updated regularly. CommLeap reviews your destinations during onboarding and helps you stay informed of new requirements as they come into effect; you remain responsible for your consent and content. For content that also qualifies as marketing, see how Campaigns & Journeys manages consent and audiences.

Encoding & delivery receipts

Know exactly what you send and what arrives

Every SMS is split into segments, and each segment is billed. Messages in the GSM-7 character set carry 160 characters in one segment, or 153 per segment when concatenated. A single emoji or a character outside GSM-7 switches the whole message to Unicode, which carries 70 characters, or 67 per segment.

CommLeap returns the encoding and segment count with every accepted message, and the console preview highlights characters — such as curly quotes pasted from a word processor — that would silently increase your segment count.

  • Normalized statuses: queued, sent, delivered, failed and expired
  • Carrier error codes mapped to readable reasons
  • Validity periods to help prevent stale messages being delivered late
Two-way SMS

Turn replies into actions and conversations

Two-way SMS lets customers confirm an appointment, approve a payment or ask a question without downloading anything. Inbound messages arrive at your webhook as structured events, matched to the original message where possible.

  • Keyword rules such as YES, NO, CONFIRM or custom codes, per number or campaign
  • Automatic STOP and HELP handling with localized equivalents
  • An account-wide suppression list applied across API sends and campaigns
  • Hand conversations to agents in the Omnichannel Inbox or to AI agents Coming soon
SMS for customer support
Fraud controls

Protection against SMS pumping and artificially inflated traffic Coming soon

Artificially inflated traffic targets sign-up and passcode forms: bots request messages to premium or unused number ranges, and the fraudster shares the termination revenue. The first sign is often an unexpected bill. CommLeap's fraud controls are coming soon and will be designed to help detect and limit the pattern early, with:

  • Country allowlists so you only send where you do business
  • Velocity limits by recipient, number prefix and source
  • Alerts when traffic to a destination departs from its normal pattern
  • Daily spend thresholds with notifications to your team
See the Verify API

Geo permissions Coming soon

Enable destinations deliberately rather than sending everywhere by default.

Anomaly alerts Coming soon

Unusual spikes in volume to a prefix or country will be surfaced for review.

OTP conversion

Verify tracks which codes are actually entered, exposing requests that never convert.

Spend controls Coming soon

Thresholds and notifications will help keep a runaway flow from becoming a runaway invoice.

Omnichannel fallback

The SMS fallback behind WhatsApp and RCS Coming soon

Richer channels deliver better experiences, but not every customer can receive them. Automatic cross-channel fallback is coming soon to CommLeap, and SMS will become the safety net: send on WhatsApp or RCS (coming soon) first, and if the message fails or is not delivered within the time you set, the same request will fall back to SMS automatically.

You will keep one message ID, one webhook stream and one report showing which channel reached each customer — so critical notifications have a backup path without duplicate logic in your code.

What is CPaaS?
Use cases

What enterprises send with the CommLeap SMS API

From regulated alerts to high-volume bulk SMS, the same API and controls apply across every flow.

Passcodes & verification

One-time passcodes for sign-up, login and step-up checks, with dedicated fraud controls coming soon. Authentication

Account & fraud alerts

Transaction confirmations, balance alerts and two-way payment approvals. Banking

Delivery updates

Dispatch, out-for-delivery and exception notices with tracking links. Logistics

Appointment reminders

Reminders with reply-to-confirm that help reduce missed appointments. Healthcare

Bulk SMS campaigns

Segmented offers to opted-in audiences with scheduling and click tracking. Marketing

Customer care

Two-way conversations handled by agents and automation in one inbox. Support

Travel disruption

Gate changes, delays and rebooking prompts that reach travelers on the move. Travel

Workforce alerts

Shift changes, incident notices and on-call escalation for internal teams. Notifications

SMS API for developers

Send an SMS with one API call

Post a recipient, sender and message to the unified messages endpoint. The response tells you the encoding and segment count; delivery receipts and replies arrive as webhook events, with signed (HMAC) webhooks coming soon.

  • Idempotency keys to prevent retried requests from sending twice
  • Scheduling and validity periods per message
  • Events: message.sent, message.delivered, message.failed and message.inbound
Developer overview
FAQ

SMS API questions, answered

What is an SMS API?

An SMS API lets your software send and receive text messages over HTTP instead of through a phone. Your application calls the API with a recipient, sender and message body; the provider routes the message to mobile carriers and reports delivery back to you through webhooks. CommLeap's SMS API uses the same endpoint and event model as our WhatsApp and email channels, and RCS Business Messaging (coming soon) will use it too.

What is the difference between A2P and P2P SMS?

P2P (person-to-person) SMS is traffic between individuals. A2P (application-to-person) SMS is sent by a business system — alerts, one-time passcodes, reminders and campaigns. Carriers treat A2P traffic differently, often requiring registered senders and dedicated routes, so business messaging should always be sent as A2P.

Do we need to register our sender before sending?

It depends on the country and sender type. In the US, A2P traffic on local numbers requires 10DLC brand and campaign registration through The Campaign Registry, toll-free numbers must be verified before sending, and short codes go through a carrier approval process. Many other countries require alphanumeric sender IDs to be pre-registered. CommLeap helps you identify what applies to each destination and prepares the submissions with you.

How are long messages and emoji handled?

Messages using the standard GSM-7 character set fit 160 characters in a single segment, or 153 per segment when concatenated. Messages that contain emoji or characters outside GSM-7 are sent as Unicode (UCS-2), which fits 70 characters in one segment or 67 per segment when concatenated. Each segment is billed, so the CommLeap API returns the encoding and segment count for every message.

How does CommLeap handle STOP and HELP replies?

Standard opt-out keywords such as STOP, END, CANCEL, UNSUBSCRIBE and QUIT are recognized automatically: the number is added to your suppression list, a single confirmation can be sent, and future messages to that recipient are blocked until they opt back in. HELP replies return your configured support message. You can add custom keywords and localized equivalents for other markets. Customers may also opt out in their own words or through other channels — in the US, FCC rules require honoring any reasonable opt-out request within 10 business days — so you remain responsible for recording and honoring those requests too.

What is SMS pumping and how do you protect against it?

SMS pumping, also called artificially inflated traffic, happens when fraudsters trigger large volumes of messages — usually one-time passcodes — to number ranges that earn them revenue. CommLeap's dedicated fraud controls are coming soon: they will be designed to limit exposure with country allowlists, velocity limits by number and prefix, anomaly alerts and spend controls. Pairing SMS with our Verify API adds conversion tracking for OTP flows.

Can SMS be used as a fallback for WhatsApp or RCS?

Automatic SMS fallback is coming soon. Once it launches, you will be able to add a fallback list to a WhatsApp message — or an RCS message, when RCS Business Messaging (also coming soon) is available — and CommLeap will send an SMS if the richer message cannot be delivered, or is not delivered within the time you set. One request, one webhook stream and one report will cover every attempt.

How is SMS priced?

SMS is priced per segment, and rates depend on the destination country and, in some markets, on the carrier and sender type. Registration and number fees may also apply. Request a quote for your destinations.

Do Canadian anti-spam rules apply to SMS campaigns?

Yes. Canada's Anti-Spam Legislation (CASL) applies to commercial electronic messages, including SMS, sent to or from Canada. In general you need the recipient's express or implied consent, each message must identify the sender and include contact information, and it must offer an unsubscribe mechanism that is honored within 10 business days. CommLeap provides consent records, opt-out handling and quiet hours to support these practices; you remain responsible for your consent and message content. See the CRTC's CASL guidance.

Plan your SMS rollout with CommLeap

Share your destination countries, use cases and expected volumes. We'll recommend the right sender mix, prepare your registrations and plan your path to production.

  • Solution design with a named specialist
  • WhatsApp onboarding and verification support
  • Transparent, volume-based pricing