Start Here

Quickstart

Transmit sends one-time passcodes over SMS or email, delivers one message to a whole list of phone numbers or email addresses, and tells your servers what happened through signed webhooks. This page takes you from zero to a delivered code.

The general flow

  • Get a key: Create an API key on the API Keys page of your dashboard. It is shown once — store it as a server-side secret.
  • Call the API: Send JSON from your server with the key as a bearer token. Sends return 202 immediately; delivery happens in the background.
  • Hear back: Register a webhook endpoint and Transmit POSTs a signed event when a code is sent, a code is verified, or a broadcast is queued.

Base URL

Every endpoint below is relative to this URL, and every public route is versioned under /v1.

https://api.transmitinfra.com/v1

Your first request

Situation: a user is signing up and you want to confirm their phone number. Send them a six-digit code:

curl -X POST https://api.transmitinfra.com/v1/otp/send \
  -H "Authorization: Bearer $TRANSMIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "channel": "sms",
    "phone": "+220833001234"
  }'

Result: the code is queued for delivery and you get back an otpId. Keep it — it is what you verify against once the user types the code in.

{
  "data": {
    "otpId": "9c1f0b7a-4d2e-4f61-9a3c-6b0e2d81f5aa",
    "message": "OTP sent successfully"
  }
}

Next, verify the code the user enters.

Response envelope

Successful payloads always sit under data, so your client reads the same path on every route. Failures replace it with error — the two never appear together.

// every success
{ "data": { ... } }

// every failure
{ "error": { "message": "message: Message exceeds 160 characters for SMS", "code": "VALIDATION_ERROR" } }

Conventions

  • JSON everywhere: Send Content-Type: application/json on every write. Bodies are capped at 1 MB, except broadcast sends, which accept 5 MB.
  • Phone numbers: E.164 with the country code, e.g. +220833001234. Numbers are normalised, so two spellings of one number are treated as the same number. Gambian numbers in the old 7-digit format are converted to the 9-digit plan (Africell 87, QCell 83, Comium 86) before sending; Gamcel numbers stay 7 digits.
  • Timestamps: ISO 8601 in UTC, e.g. 2026-09-01T06:00:00.000Z.
  • Server-side only: The /v1 API sends no CORS headers, so browsers refuse to call it. That is deliberate — an API key never belongs in front-end code.
Sends answer 202 Accepted, not 200. The request was accepted and queued; a carrier failure afterwards does not change that response.