Get past platform barriers. Effortlessly.

SMS codes, email codes and captchas behind one API. Send one request: it waits until the code arrives, then returns it. No polling loops, no webhook servers, no juggling vendors.

Read the docs

Private beta. Join the waitlist.

  • Node.js and PHP SDKs
  • Runs on the edge
api.clearance.rest

Your request

GET /numbers/sms/wait

number=+14155550100

code_regex=\d{6}

The wait

200 OK

6.8 s

What comes back

482913code

{
  "success": true,
  "code": "482913",
  "from": "+15559998888",
  "body": "Your code is 482913"
}

Providers behind the key

Numbers
TwilioHero SMSReal SIM cards
Email
GmailOutlookCloudflare Email Routing
Captchas
Capsolver2CaptchaNoneCap

Product

Three barriers. One API key.

Phone verification, email confirmation and captchas usually mean three vendors, three SDKs and three sets of edge cases. Here they share one key, one auth model and one way of waiting.

Numbers

Every SMS code, one call away

Rent a number or bring a real SIM, trigger the verification, and wait for the SMS. The same call works for every kind of number.

GET /numbers/sms/wait

  • Temporary numbers for one-off verifications, by country and service
  • Dedicated virtual numbers you keep, with SMS routed for you
  • Real SIM cards in Android phones for services that reject virtual numbers
  • Filter by sender or text, extract the code with a regex

Emails

Inbound email, without an inbox to babysit

Wait for the confirmation email and get the code, whether the address lives on your own domain or in a connected mailbox.

GET /emails/get-email

  • Unlimited addresses on your own domain through Cloudflare Email Routing
  • Connect Gmail and Outlook with OAuth; passwords never change hands
  • Shareable authorization links so others can connect their mailbox
  • Full message back: text, HTML, headers and attachments

Captchas

Any captcha, any solver, one contract

Describe the captcha and get the solution in the same request. The request and response look the same whichever solver does the work.

POST /captchas/resolve

  • 13 captcha types, from reCAPTCHA and Turnstile to DataDome and AWS WAF
  • Automatic solver selection, with per-project defaults per captcha type
  • Switch solvers without changing a line of code
  • Real-browser hCaptcha solving where API tokens fall short

How it works

The wait is the API.

Every verification step hides the same chore: trigger it, then poll, parse and retry until the code shows up. clearance.rest turns that whole loop into a single call.

WithoutPolling, parsing, three vendors11 lines
// Trigger the sign-up, then...
const deadline = Date.now() + 120_000;
let code;
while (!code && Date.now() < deadline) {
  const inbox = await provider.listMessages(number);
  const msg = inbox.find((m) => m.at > startedAt);
  code = msg?.body.match(/\d{6}/)?.[0];
  if (!code) await sleep(3000);
}
// + a webhook endpoint, retries, a second
//   vendor for email, a third for captchas
With clearance.restOne call5 lines
const { code } = await clearanceRest.numbers.wait({
  number: '+14155550100',
  codeRegex: '\\d{6}',
  timeout: 120_000,
});
Request open until the SMS arrives
code → "482913"
  1. Send one request

    Name the number, the address or the captcha. Add a regex to filter messages and one to pull out the code.

  2. We hold it open

    The request stays open until a matching SMS or email lands, or the solver finishes. If it already arrived, you get it at once.

  3. Get the code back

    The response is the result: the extracted code, the full message and the metadata. You set the longest wait with one header.

In depth

When virtual numbers get rejected, plug in a real one.

Some services only accept real carrier numbers. Put a SIM in any Android phone, install the SIM Bridge app and scan your project's QR code. Every SMS it receives reaches the same/sms/wait call as any other number.

  • Verified by the phone's holder, attached with your QR
  • Messages forwarded in the background, even after a restart
  • Live status: active, offline or SIM removed

Thirteen captcha types. Zero solver lock-in.

Every type has a closed, validated contract, and every solver returns the same response shape. Pick a solver per request, set a default per project, or let clearance.rest choose one that supports your request.

  • reCAPTCHA v2
  • reCAPTCHA v3
  • Turnstile
  • hCaptcha
  • GeeTest v3
  • GeeTest v4
  • AWS WAF
  • DataDome
  • Cloudflare Challenge
  • FunCaptcha
  • MTCaptcha
  • Image to text
  • Coordinates

SolversCapsolver2CaptchaNoneCapNoneCap (browser)

Every inbox, one call.

Confirmation links and one-time codes land wherever your users and workflows live. You write the same code for all of them.

For developers

Ten lines, not ten services.

One key authenticates everything. Bound the wait with a header, and the response is the result.

Read the docs
curl -G https://api.clearance.rest/numbers/sms/wait \
  -H "X-API-Key: $CLEARANCE_REST_API_KEY" \
  -H "X-Service-Timeout: 120000" \
  --data-urlencode "number=+14155550100" \
  --data-urlencode "code_regex=\d{6}"

Typed errors and deadlines
Both SDKs set a hard deadline and raise typed errors, including timeouts.
Signed webhooks
Subscribe to number and mailbox events. Every delivery is HMAC-signed and retried with backoff.
Inventory with metadata
Keep your own ownership data on numbers and mailboxes, and assign safely with If-Match.
Console
Projects and API keys, usage, an inbox for received messages and a quick cURL builder.
OpenAPI and llms.txt
A full API reference, and docs your AI agents can read directly.
Runs on the edge
Node, Cloudflare Workers and the browser, with the same SDK.

FAQ

Good questions.

When can I get access?

clearance.rest is in a private beta. Join the waitlist and we will email you when your spot opens.

How much will it cost?

Pricing is not announced yet. Waitlist members will hear about it first.

Do I need accounts at the providers?

Yes. Numbers, mailboxes and captcha solving run on provider accounts (Twilio, Hero SMS, Capsolver, 2Captcha and so on). You connect them once, and your code never touches them.

What happens if the code never arrives?

The request ends at the timeout you set with the X-Service-Timeout header, and the response says so. The SDKs raise a typed timeout error.

Do I need to host a webhook to receive codes?

No. A wait is a single request that stays open. Webhooks are optional, for hearing about changes to your numbers and mailboxes.

Which languages can I use?

Anything that speaks HTTP. There are official SDKs for Node.js (also Cloudflare Workers and browsers) and PHP.

Still curious? Read the docs.

Private beta

Be first through the gate.

Join the waitlist. Tell us what you need to get past and we will prioritise your invite.

What do you need to get past?