curl --request PUT \
--url https://app.thinnest.ai/api/v1/sms/provider \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"provider": "exotel",
"credentials": {
"accountSid": "acme1",
"apiKey": "a1b2c3d4e5f6",
"apiToken": "••••••",
"region": "in"
},
"senderHeader": "ACMEIN",
"dltEntityId": "1201159123456789012"
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
provider: 'exotel',
credentials: {accountSid: 'acme1', apiKey: 'a1b2c3d4e5f6', apiToken: '••••••', region: 'in'},
senderHeader: 'ACMEIN',
dltEntityId: '1201159123456789012'
})
};
fetch('https://app.thinnest.ai/api/v1/sms/provider', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/sms/provider"
payload = {
"provider": "exotel",
"credentials": {
"accountSid": "acme1",
"apiKey": "a1b2c3d4e5f6",
"apiToken": "••••••",
"region": "in"
},
"senderHeader": "ACMEIN",
"dltEntityId": "1201159123456789012"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text){
"provider": "exotel",
"senderHeader": "ACMEIN",
"dltEntityId": "1201159123456789012",
"status": "untested",
"lastError": null,
"fields": {
"accountSid": "acme1",
"apiKey": "a1b2c3d4e5f6",
"region": "in"
},
"secretsSaved": [
"apiToken"
]
}Connect SMS Provider
Connects your SMS provider, or replaces the one connected. A secret you leave out keeps the one saved, for the same provider; switching provider needs every field. The connection’s status goes back to untested until Send Test SMS succeeds. Needs a full key.
What each provider asks for in credentials:
msg91:authKeyexotel:accountSid,apiKey,apiToken,region(inorsg)gupshup:userId,passwordinfobip:baseUrl(your own, likexxxxx.api.infobip.com),apiKeyvonage:apiKey,apiSecretfast2sms:apiKey
curl --request PUT \
--url https://app.thinnest.ai/api/v1/sms/provider \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"provider": "exotel",
"credentials": {
"accountSid": "acme1",
"apiKey": "a1b2c3d4e5f6",
"apiToken": "••••••",
"region": "in"
},
"senderHeader": "ACMEIN",
"dltEntityId": "1201159123456789012"
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
provider: 'exotel',
credentials: {accountSid: 'acme1', apiKey: 'a1b2c3d4e5f6', apiToken: '••••••', region: 'in'},
senderHeader: 'ACMEIN',
dltEntityId: '1201159123456789012'
})
};
fetch('https://app.thinnest.ai/api/v1/sms/provider', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/sms/provider"
payload = {
"provider": "exotel",
"credentials": {
"accountSid": "acme1",
"apiKey": "a1b2c3d4e5f6",
"apiToken": "••••••",
"region": "in"
},
"senderHeader": "ACMEIN",
"dltEntityId": "1201159123456789012"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text){
"provider": "exotel",
"senderHeader": "ACMEIN",
"dltEntityId": "1201159123456789012",
"status": "untested",
"lastError": null,
"fields": {
"accountSid": "acme1",
"apiKey": "a1b2c3d4e5f6",
"region": "in"
},
"secretsSaved": [
"apiToken"
]
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Headers
Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace. Refused with 404 (Workspace not found.) when the id is unknown, is not one of your customers, or is not an org_… id; 410 when that customer was deleted (restore it with POST /customers/{id}/restore until it is erased); 403 when the key belongs to one customer workspace (it cannot act as another); 400 when your workspace is not a developer workspace. /customers/* and GET /customers/usage are your own workspace's and refuse the header with 400: call them without it.
"org_3fKq9TzQ1mN8vB2xR7cLpA"
Body
msg91, exotel, gupshup, infobip, vonage, fast2sms The provider's own fields, as listed above.
Show child attributes
Show child attributes
Your six-letter sender header, as registered on your DLT portal.
"ACMEIN"
Your Principal Entity ID from your DLT portal (digits only).
"1201159123456789012"
Response
The connection as saved.
The workspace's own SMS provider. Secrets are never returned.
msg91, exotel, gupshup, infobip, vonage, fast2sms "ACMEIN"
"1201159123456789012"
From the last Send Test SMS since it was saved.
untested, working, failing Why the last test failed.
The provider's fields that are not secret.
Show child attributes
Show child attributes
The secret fields held, by name.