Enter your access seed to login. No email, no password.
new here?
Two-factor authentication
Enter the 6-digit code from your authenticator app, or one of your recovery codes.
Create Anonymous Account
No email, no password, no KYC. Your account is secured by a unique seed phrase you receive on the next step.
already have a seed?
Account Created
Here is your access seed:
Save this seed now — it will never be shown again
This seed is your only way to access your account. If you lose it, your balance is permanently lost. No recovery, no reset, no exceptions.
SmsNoKYC for Developers: SMS Verification You Can Script
Script the entire verification loop through one JSON interface. 116 countries, 133 services, 400 carrier routes and 15,400+ live prices sit behind a handful of endpoints: allocate a number, catch its incoming code, hold a rental for up to 90 days, settle in crypto. No API key exists here — a seed phrase is the only credential you will ever present.
Authentication required. Sessions ride on cookies. Sign in with your seed phrase — through the site or directly against the auth endpoint documented below — and every subsequent request inherits that session on its own.
Made for scripts, pipelines and autonomous agents
Legacy OTP vendors want contracts signed, compliance cleared and monthly minimums committed before your first request goes out. SmsNoKYC flips the order: hold a seed phrase, load a balance from $25 in any of 8 cryptocurrencies — Bitcoin, Monero, Ethereum, Litecoin, TRON, USDT and SOL among them — and start calling from whatever HTTPS client you already run. Billing is metered per number from $0.01, across 15,400+ live price points.
Day to day, the endpoints verify signup flows inside CI, feed OTP codes to headless browsers and scraper fleets, keep Telegram or WhatsApp accounts alive on dedicated 7 to 90 day rentals, and spread verification over 116 countries with explicit control of 400 carrier routes in three tiers — virtual, physical, premium. AI agents reach the same catalog through a native MCP server, covered on the agents page, so a tool-using model can buy numbers and read codes with no custom glue.
Authentication
Sessions are cookie-based — there is no bearer key to mint or rotate. Programmatic login takes three moves:
POST your seed phrase to /auth-api.php
Capture the cookie set on the response
Attach that cookie to every call that follows
POST/auth-api.php
Trades your seed phrase for a live session.
Parameter
Type
Required
Description
action
string
required
Must be "login"
seed
string
required
The 16-character seed tied to your account (format AbC3-dEf4-gHj5-kLm6)
cURL
Python
JavaScript
# Login and save session cookie
curl -X POST https://smsnokyc.com/auth-api.php \
-d "action=login&seed=AbC3-dEf4-gHj5-kLm6" \
-c cookies.txt
import requests
session = requests.Session()
resp = session.post("https://smsnokyc.com/auth-api.php", data={
"action": "login",
"seed": "AbC3-dEf4-gHj5-kLm6"
})
data = resp.json()
print(data) # {"success": true, "user": {...}}# session object now holds the cookie for all future requests
Responses arrive as JSON in every case. POST bodies may be sent as either application/json or application/x-www-form-urlencoded.
Rate Limits
Two rules govern request volume:
Endpoint
Limit
Window
Authentication
5 attempts
15 minutes
All other endpoints
No hard limit
—
Rate limiting: login accepts 5 attempts per 15 minutes; every other endpoint currently has no fixed ceiling, though sustained abuse can be slowed upstream. Space your calls sensibly.
Error Handling
Every failure comes back as a JSON object carrying an error field:
{
"error": "Description of what went wrong"
}
HTTP Code
Meaning
200
Success (check response body for application-level errors)
403
Invalid CSRF token
405
Wrong HTTP method (e.g. GET on a POST-only endpoint)
429
Rate limit exceeded
Application-level errors you will meet most often:
Error
Cause
"Login required"
Session expired or not authenticated
"Insufficient balance"
Not enough funds — includes need and have fields
"Service not available for this country"
No stock or service inactive for the selected country
"Missing country or service"
Required parameters were not provided
List Countries
GET/api.php?action=countries
Lists every country currently holding stock — 116 at last count. Open endpoint, no session required.
resp = session.get("https://smsnokyc.com/api.php", params={"action": "countries"})
countries = resp.json()
for c in countries:
print(c["code"], c["name"])
const resp = await fetch("https://smsnokyc.com/api.php?action=countries");
const countries = await resp.json();
Pulls the service sheet for one country, live price and stock included. Leave the country parameter off to receive the full 133-service catalog without pricing.
Operator types:virtual — VoIP-backed, lowest cost, occasionally rejected by strict platforms. physical — genuine SIM hardware, stronger acceptance. premium — highest acceptance and the quickest delivery, around 10 seconds.
Buy Number (SMS Activation)
POST/api.php?action=buy
Reserves a number for a single verification. It stays yours for 20 minutes; if no message shows up inside that window, the charge flows back to your balance automatically.
Order statuses:active — still listening for a message. completed — code captured. cancelled — closed by you. refunded — credited back automatically after a silent timeout. expired — window elapsed.
Locks in one or more dedicated numbers. Each stays exclusively yours for the whole term — 7 to 90 days — and accepts unlimited inbound SMS from any service.
The script below runs the whole loop in Python — session, catalog lookup, purchase, then polling until the code drops:
Python
import requests, time
BASE = "https://smsnokyc.com"
SEED = "AbC3-dEf4-gHj5-kLm6"
s = requests.Session()
# 1. Authenticate
s.post(f"{BASE}/auth-api.php", data={"action": "login", "seed": SEED})
# 2. Check balance
user = s.get(f"{BASE}/api.php?action=user").json()
print(f"Balance: ${user['balance']}")
# 3. Get services for USA
services = s.get(f"{BASE}/api.php?action=services&country=us").json()
whatsapp = next(svc for svc in services if svc["name"] == "WhatsApp")
print(f"WhatsApp: ${whatsapp['price']} ({whatsapp['stock']} in stock)")
# 4. Buy a number
order = s.post(f"{BASE}/api.php?action=buy", json={
"country": "us",
"service_id": whatsapp["id"]
}).json()
print(f"Order #{order['order_id']} created")
# 5. Poll for SMS codefor _ in range(60):
orders = s.get(f"{BASE}/api.php?action=orders").json()
my_order = next(o for o in orders if o["id"] == order["order_id"])
if my_order["sms_code"]:
print(f"SMS code: {my_order['sms_code']}")
print(f"Phone: {my_order['phone_number']}")
breakprint("Waiting for SMS...")
time.sleep(5)
else:
print("Timeout — balance will be refunded automatically")
Developer Questions, Answered
Which operations does the SmsNoKYC developer API expose?
Everything the dashboard does, a script can do: pull the catalog of 116 countries and 133 services, inspect 15,400+ live price points spread over 400 carrier routes, allocate a number for a one-time OTP, read the incoming code the moment it lands, hold a dedicated rental for 7, 14, 30 or 90 days, and audit every order. All of it is plain JSON over HTTPS, billed in crypto, with no identity step anywhere in the flow.
Is there an API key to generate before my first request?
Nothing to generate, nothing to rotate. Your seed phrase is the credential itself: POST it once to /auth-api.php, keep the session cookie the server returns, and send that cookie with each later call. No key dashboard, no OAuth handshake, no expiry calendar — one seed opens one session, and that is the whole model.
What does access to the API itself cost?
Access costs nothing — no monthly fee, no tier, no minimum call volume. You pay per number only: one-shot verification codes start at $0.01 and typically land between $0.20 and $1, while dedicated rentals open at $4.20 for a 7-day term. Balances are funded with 8 cryptocurrencies (minimum top-up $25), and an activation that never receives its SMS refunds itself without any action on your side.
Can I integrate from any language — or from an AI agent?
Anything that speaks HTTPS qualifies: Python, Node.js, Go, Rust, PHP, Ruby, Java, C#, or bare cURL inside a shell script. The reference ships runnable snippets in cURL, Python and JavaScript, and /openapi.json exposes a complete OpenAPI 3.0 document for generating typed clients. Autonomous agents are covered natively as well — a dedicated MCP server lets tool-using models buy numbers and collect codes on their own; the /agents page walks through the setup.
What happens when a purchased number stays silent?
You lose nothing. Every activation runs a 20-minute receive window; when it closes without a message, the platform cancels the order by itself and pushes the full charge back to your balance. No ticket, no form, no waiting on support. Buy again right away — moving up to a physical or premium operator tier usually raises the delivery rate.
How hard can I poll before throttling kicks in?
Only login carries a hard ceiling: 5 attempts per 15 minutes per IP, there to stop seed guessing. Catalog, purchase, order and rental endpoints have no fixed quota right now. Keep the cadence sane — checking the orders endpoint every 3 to 5 seconds catches every code — and hold sustained traffic under roughly 10 requests per second, since heavier bursts can be slowed at the edge layer.
Ship it
Grab a seed on the homepage, load $25 or more in crypto, and your first verification code is five requests away. Building on an LLM instead of a script? Point your model at the SmsNoKYC MCP server or follow the AI agent integration guide — the full catalog of 116 countries and 133 services becomes a tool call.
Anything the reference leaves open is covered in the help center, the SMS glossary decodes the jargon, and live activity shows the network in motion. Support runs on in-app tickets once you are signed in.