/secure/ takes HTTP Basic authentication, with your login as the username.
/ping takes none.
Credentials go in the header, nowhere else
username and password as body fields are not ignored — they come back as
400 Unknown argument. That refusal is usually the first sign of a payload copied from a different
gateway.
An SMPP login cannot use this API
This catches people out because the refusal does not say so. A403 Authentication failure covers
all three of: unknown login, wrong password, and a login of the wrong type.
The two 401s
They mean different things, and the distinction is worth branching on:
Executed against a live gateway:
IP allow lists
If your login has one, a request from anywhere else is403 Authorization failure — a different
message from the credential failure above, so the two are distinguishable in a log.
Your gateway operator sets this. It is worth asking whether one is configured before you move your
integration to new infrastructure.
Authentication runs before everything
Confirmed live: a POST with no credentials and an unparseable body returns the authentication error, not the parse error.Keeping the password safe
- Read it from the environment or a secret store, never from source.
- It is not rotated for you — if it leaks, ask your operator to change it.
- An unknown path under
/secure/returns401, not404, so the API will not confirm which endpoints exist to an unauthenticated caller. Do not build discovery on top of status codes.
Related
API errors
Every status, and which are worth retrying.
Quickstart
First message in four languages.