Use company SMS from your tools
Bring the same company numbers into a test, script, or assistant. Choose the interface that fits where the work runs, then grant access to the numbers it needs.
Choose by execution environment
| Where the work runs | Start with | What it does for you |
|---|---|---|
| JS/TS test or service | SDK | Typed API wrappers and local polling inside your code |
| Terminal or coding assistant | CLI and skill | Connection, number selection, and code retrieval |
| Another language or custom tool | HTTP API | Language-neutral requests and JSON results |
| Event-driven service | Webhooks | Signed receipt notifications, followed by an authorized read |
| Hosted assistant | Platform guide | Its supported connection and execution route |
Scroll horizontally to see all columns.
The SDK guide explains installation and the public interface. Each integration guide names the route you can use in that host.
Keep message receipt inside your application flow
A test should read like a test. The SDK records the inbox position, waits for the first later message, and returns the recognized code for the application to use.
const number = phonekit.number(testPhoneNumber)
const after = await number.mark()
await requestVerification(testPhoneNumber)
const code = await number.waitForOtp({ after, timeoutMs: 120_000 })
await completeVerification(code)The complete Playwright recipe supplies setup and the final signed-in assertion. The API reference documents the underlying requests when you want to build another client.
Give each connection a useful scope
A local CLI connection starts with a person reviewing read access in the browser. CI, service jobs and hosted connections receive explicitly selected permissions and separate readable/managed line grants. Existing keys remain read-only. Put a test credential in its runner's secret store and give an operations tool access to the account numbers it uses.
Authorized management credentials can acquire, configure and release lines within server-enforced allowances. The application or outside service sends the verification SMS. Phonekit's receiving interface fits alongside the sender you already use.
Programmatic access on every plan
API access is part of every plan. Choose your workspace and numbers for the work, then use them from your browser or software without a higher-plan API unlock.
Webhook events carry receipt metadata. Your handler acknowledges the event and retrieves the message through its permitted read interface. This supports background work while keeping the SMS content in the authorized inbox/API path.
Questions you may have
Should my browser app import the SDK?
Use the SDK in the test runner or server that holds the scoped API key. A public browser bundle would expose that credential. Browser tests can receive a code in their runner and enter it into the application under test.
Does Phonekit replace our SMS sending provider?
Phonekit supplies the receiving number and message access. Your application continues requesting delivery through its configured SMS or authentication provider. The provider recipes show the two sides together.
Does a webhook contain the code?
The event contains message and number metadata, not the SMS body or code. Fetch the message using an authorized read. The webhook receiver guide shows that complete sequence.
Which interface should I give an agent?
The skill can use authenticated MCP when installed, or the CLI in an environment that runs commands. Choose one route for the workflow and preserve its cursor. Hosted OAuth connections need acceptance in the actual host. Use the SDK when building your own JS/TS agent tool. Follow the platform guides for the actual setup.