Skip to main content

Custom SMS Provider Configuration Guide

Overview​

CloudBase Authentication supports login via phone number SMS verification codes. To use SMS verification code login, you need to integrate an SMS service provider to send verification code messages.

You can integrate the Tencent Cloud SMS provider (TENCENT_CN for Mainland China, TENCENT_INTL for International/Hong Kong, Macao, Taiwan), or integrate other SMS providers through cloud functions.

Once configured, the verification code SMS triggered during signup/login will be sent through your configured SMS provider, giving you full control over the signature, template, and daily sending limit.

Prerequisites​

Before calling the configuration API, you need to complete the following preparations in Tencent Cloud:

Step 1: Enable Tencent Cloud SMS Service​

  1. Log in to the Tencent Cloud SMS Console, agree to the service agreement, and enable the SMS service.
  2. Go to Application Management > Application List, click Create Application, fill in the application name, and record the SdkAppId after creation.
tip

If the SMS service and the CloudBase environment use the same Tencent Cloud account, you can integrate via CAM authorization without providing SecretId and SecretKey.

If you use a cross-account SMS service, go to API Key Management to create or view your SecretId and SecretKey.

warning

SecretKey is a sensitive credential. Keep it secure and avoid leaking it.

Step 2: Apply for an SMS Signature​

The SMS signature appears at the beginning of the SMS sent to users, for example 【Tencent Cloud】. Go to the Tencent Cloud SMS Console to apply for an SMS signature. After approval, record the Signature Content for later use.

Step 3: Apply for an SMS Template​

The SMS template defines the body content of the verification code SMS. Variable parts are represented by placeholders {1}, {2}. Go to the Tencent Cloud SMS Console to apply for an SMS template. After approval, record the Template ID (TemplateId) for later use.

SMS template example:

Your verification code is: {1}, valid for {2} minutes. Do not share it with others.

For template application and review standards, refer to: SMS Body Template Review Standards

After Completing the Preparations, You Should Have Obtained the Following Information​

ParameterDescriptionHow to Obtain
SdkAppIdSMS Application IDSMS Console > Application Management
SecretIdAPI Key ID (required for cross-account scenarios)API Key Management
SecretKeyAPI Key (required for cross-account scenarios)API Key Management
SignNameSMS Signature ContentSMS Console > Signature Management (after approval)
TemplateIdSMS Template IDSMS Console > Body Template Management (after approval)

API Reference​

Interface Information​

ItemDescription
Interface NameModifyLoginConfig (Modify Login Policy)
Request Domaintcb.tencentcloudapi.com
API Version2018-06-08
HTTP MethodPOST
Rate Limit20 requests/sec

Input Parameters​

Top-Level Parameters​

ParameterTypeRequiredDescription
EnvIdStringYesCloudBase environment ID
PhoneNumberLoginBooleanYesPhone number SMS login switch
EmailLoginBooleanYesEmail login switch
UserNameLoginBooleanYesUsername/password login switch
AnonymousLoginBooleanYesAnonymous login switch
SmsVerificationConfigObjectNoSMS verification code sending channel configuration, see details below

SmsVerificationConfig (SMS Channel Configuration)​

ParameterTypeRequiredDescription
TypeStringNoSMS sending channel type. template: use a custom SMS provider template (Tencent Cloud SMS uses this value)
SmsDayLimitIntegerNoDaily sending limit per phone number, default 30, -1 means no limit
TemplateProviderObjectRequired when Type is templateProvider SMS template configuration, see SMSProviderTemplateConfig below

SMSProviderTemplateConfig (Provider Template Configuration)​

ParameterTypeRequiredDescription
VendorStringYesSMS provider. TENCENT_CN: Tencent Cloud SMS (Mainland China); TENCENT_INTL: Tencent Cloud SMS (International/Hong Kong, Macao, Taiwan)
TemplateIdStringYesSMS template ID (approved template)
SdkAppIdStringNoTencent Cloud SMS application ID
SignNameStringNoSMS signature content (approved signature)
SecretIdStringNoTencent Cloud API key ID (required for cross-account scenarios; CAM authorization can be used for the same account)
SecretKeyStringNoTencent Cloud API key (required for cross-account scenarios; CAM authorization can be used for the same account)
SenderIdStringNoSender ID, required for some international SMS scenarios
TemplateExtendParamArray of ObjectNoTemplate custom extension parameters, see SMSTemplateParams below

SMSTemplateParams (Template Extension Parameters)​

ParameterTypeDescription
KeyStringParameter key (fill in when using named placeholders)
ValueStringParameter value

Request Examples​

Configure Tencent Cloud Mainland China SMS (TENCENT_CN)​

{
"EnvId": "your-env-id",
"PhoneNumberLogin": true,
"EmailLogin": false,
"UserNameLogin": false,
"AnonymousLogin": false,
"SmsVerificationConfig": {
"Type": "template",
"SmsDayLimit": 100,
"TemplateProvider": {
"Vendor": "TENCENT_CN",
"SdkAppId": "1400000000",
"SecretId": "AKIDxxxxxxxx",
"SecretKey": "xxxxxxxxxxxxxxxx",
"SignName": "CloudBase",
"TemplateId": "123456"
}
}
}

Configure Tencent Cloud International/Hong Kong, Macao, Taiwan SMS (TENCENT_INTL)​

{
"EnvId": "your-env-id",
"PhoneNumberLogin": true,
"EmailLogin": false,
"UserNameLogin": false,
"AnonymousLogin": false,
"SmsVerificationConfig": {
"Type": "template",
"SmsDayLimit": 100,
"TemplateProvider": {
"Vendor": "TENCENT_INTL",
"SdkAppId": "1400000000",
"SecretId": "AKIDxxxxxxxx",
"SecretKey": "xxxxxxxxxxxxxxxx",
"SignName": "CloudBase",
"TemplateId": "789012"
}
}
}

Output Parameters​

ParameterTypeDescription
RequestIdStringUnique request ID, used for troubleshooting

Response Example​

{
"Response": {
"RequestId": "70b8908d-5c99-4a20-be23-f84aff0bfd37"
}
}

Notes​

  1. Signature and template must be approved in advance: Before calling the API, ensure that both the Tencent Cloud SMS signature and template have been approved, otherwise SMS sending will fail.

  2. Configure Mainland China and international scenarios separately: The SignName and TemplateId for Mainland China SMS and International/Hong Kong, Macao, Taiwan SMS are managed separately. Choose the corresponding configuration based on your user base.

  3. Set SmsDayLimit reasonably: It is recommended to set a daily limit based on your business volume to prevent abnormal traffic abuse, while avoiding setting it too low to affect normal user logins.

  4. Store SecretKey securely: Do not hardcode the SecretKey in front-end code. It is recommended to call the API through a backend service.

  5. Configuration takes effect immediately: Once the API call succeeds, the configuration takes effect immediately. All users logging in under this CloudBase environment will use the new SMS channel.