opr8r
Talk to us
§ 00
HOW IT WORKS

How Opr8r works

Opr8r is a compliance layer that runs between your product and the carrier network. You send messages through one API; Opr8r registers your campaigns, checks consent and policy on every send, and logs every event — inside a Telnyx account you own.

§ 01

The send pipeline

One call to POST /v1/send enters a fixed sequence of gates. Each gate can only pass, hold, or refuse — and every outcome is written to the ledger before your request returns.

01
consent refuses 409 consent_opted_out

Is there a recorded opt-in for this (number, recipient) pair, and has it not been revoked? Consent is global — it isn't scoped to a message class.

02
cap refuses 409 recipient_cap_exceeded

Per-recipient frequency cap and per-number rate limit, checked before anything leaves the platform.

03
quiet hours holds until the window opens

Default 21:00–08:00 in the recipient number's local timezone. Held sends are not dropped — they auto-release at 08:00 local.

04
transmit — with re-check the gate that matters

Consent is checked again at the moment of transmission, not just at enqueue. A STOP that lands while a message sits in the queue wins.

05
● delivery status

Carrier status flows back as message.sent, message.delivered, or message.failed — signed webhooks, with the failure reason attached.

Gates run in order and short-circuit. You always get one answer with one reason — never a partial send and never a silent drop.

§ 02

Inbound & keywords

Everything a recipient sends back arrives at the platform first. Compliance keywords are handled there and never reach your application; everything else routes to you untouched.

STOP

Consent revoked in the ledger, confirmation sent per CTIA, consent.revoked fired to you. Future sends refuse.

HELP

Standard help reply with the brand name and opt-out instructions. Logged, not forwarded.

START

Consent restored with a new ledger entry and its own timestamp and source. consent.granted fired to you.

EVERYTHING ELSE

Routed to you as message.received with the original body, the number it arrived on, and the recipient. Opr8r doesn't own an inbox — replies are your product's job.

§ 03

Voice — missed-call text-back

A texting number can also take calls. Opr8r forwards them without answering, and tells you when one is missed so your product can follow up in the channel the caller is already holding.

01Call arrives on your Opr8r-managed number and is forwarded to the business line. Opr8r never answers it.
02Nobody picks up — call.missed fires to your webhook with the caller number and duration.
03Your product decides what to say and calls POST /v1/send.
04The text-back runs the same pipeline as everything else. ● delivered

A missed call is not consent. The text-back still needs an opt-in on record, or it refuses like any other send.

§ 04

Integration surface

Three things to integrate: one endpoint, one webhook receiver, one embed. An afternoon of work, not a migration.

1 · SEND
POST /v1/send

{
  "to": "+15125550142",
  "body": "Sorry we missed you — how can we help?",
  "message_class": "missed_call_textback",
  "idempotency_key": "mc_5a71…"
}
2 · WEBHOOKS
X-Switchboard-Signature: t=1786…,v1=8b3f…

# verify before you trust the body
expected = hmac_sha256(secret, t + "." + raw_body)
constant_time_compare(expected, v1)
message.sent · message.delivered · message.failed
message.received · consent.granted · consent.revoked · call.missed
3 · OPT-IN WIDGET
<script
  src="https://cdn.opr8r.ai/optin.js"
  data-key="pk_live_…"
  data-origin="https://app.yourproduct.com">
</script>
Submits write the opt-in evidence — timestamp, source, IP, and the exact disclosure text shown — straight to the ledger.
§ 05

Model C ownership

Opr8r operates inside a Telnyx account that belongs to you. We hold credentials to run the pipeline; we don't hold the account, the numbers, or the brand.

YOUR ACCOUNT

The Telnyx account, the 10DLC brand, the campaigns, and the numbers are registered in your legal entity's name. Carrier invoices go to you directly.

PER-TENANT INGRESS

Each tenant gets its own webhook ingress and its own credential pair. One tenant's traffic and one tenant's consent state never cross into another's.

LEAVING

Rotate the key. Access ends; the account, numbers, brand, campaigns, and the exported ledger stay with you. No migration project.

Add compliant texting to your product.

Tell us what you're building and who you send to. If we're a fit, you'll know on the first call — and if we're not, we'll say so.

Talk to us Read the docs