| Calls | Where the key goes | Name |
|---|---|---|
SMS, one-time codes, balance, sender names (/api/SendSMS, /api/Verify, /api/CheckBalance and the others without /partners/ in the address), POST form | JSON body | api_id |
| The same calls, GET form | Query string | api_id |
Viber and WhatsApp (/api/partners/viber-…, /api/partners/whatsapp-…, /api/partners/senders) | Request header | apiId |
SMS records (/api/partners/SmsDataRecords) | JSON body for the list call, query string for the single record | apiId |
HTTP/1.1 401 Unauthorized
{"message": "Access denied: your IP is not in the allowed list. Configure your allowed IPs in the partner portal."}Authorization: Bearer <token>.{
"data": [
{
"requiresTwoFactor": false,
"token": {
"token": "<login token>",
"refreshToken": "<refresh token>",
"tokenLifeTime": "00:15:00"
}
}
]
}tokenLifeTime ends, with Refresh the login token. Send the token yourequiresTwoFactor: true and no token from this call.