Announcing the end of HTTP support for Sinch Engage APIs
| Announced on | HTTP support ends |
|---|---|
| 30 September 2026 | After 30 October 2026 |
After 30 October 2026, Sinch Engage will no longer accept API requests sent over HTTP. If your integration connects using http:// URLs, you'll need to change them to https:// before then. It's a small change: your API, credentials and integration logic all stay the same.
What's happening?
Sinch Engage is permanently discontinuing support for insecure HTTP endpoints across all of our APIs. From 31 October 2026, requests sent over HTTP will be rejected. Requests sent over HTTPS aren't affected.
What isn't changing?
- This is not a migration to a new API.
- Your existing API endpoints, credentials and integration logic stay the same.
- Your account, numbers and pricing stay the same.
Why is Sinch making this change?
HTTPS encrypts the traffic between your system and ours. HTTP doesn't, which means anything sent over it, including your credentials and your customers' message content, can be read by others on the network. HTTPS is the industry standard for securing API traffic. Ending HTTP support helps keep your data safe and meets modern security requirements.
What do I need to do?
-
Check your integration. Look through your code, configuration files and settings for any
http://URLs that point to our APIs. -
Update the URL. Change
http://tohttps://For example:
Before After http://api.messagemedia.comhttps://api.messagemedia.comhttp://au.app.api.sinch.comhttps://au.app.api.sinch.comYou can find your account's specific API Base URL in API Settings.
- Test your integration. Send a test message and check that it works as expected.
- Make the change before 30 October 2026.
How can I tell if I'm affected?
You're affected if any system sends requests to our APIs using http://. Check for these signs:
-
http://in your code or settings. Search your code, environment variables and configuration files for our API addresses. - A plugin or third-party app. You connect another product (for example a CRM, booking system or website plugin) to your account, and it may be using HTTP.
- Scripts and scheduled jobs. Older scripts and automated tasks are easy to miss.
- An email from us. We're emailing customers whose integrations we've identified as using HTTP.
If you have more than one account, check each one. Not sure? Contact our Support team.
What happens if I don't update before the deadline?
From 31 October 2026:
- Requests sent over HTTP will be rejected, and the messages in them won't be sent.
- Automated messages, such as appointment reminders, alerts or verification codes, will stop. If your system doesn't check for errors, this may happen without you noticing.
We won't offer extensions. HTTP support will end for all customers at the same time.
We'll keep sending reminders as the deadline gets closer. We strongly recommend making the change as soon as you can.
Frequently asked questions
Do I need a new API key or new credentials?
No. Your existing credentials work over HTTPS exactly as they do now.
Do I need to change how my integration works?
No. You only need to change http:// to https:// in your endpoint URLs. Your requests, responses and integration logic stay the same.
I already use HTTPS. Do I need to do anything?
No.
I use a plugin, app or outside developer to connect to your service. What should I do?
Contact the provider or developer and ask them to switch to HTTPS before 30 October 2026. Share this article with them.
I only use the web app. Do I need to do anything?
No. Sending and receiving messages in the web app isn't affected.
Can I get an extension?
No. HTTP support will end for all customers after 30 October 2026.
Getting help
- Security Best Practices for Sinch Engage API Integration
- If you need help updating your integration, contact our Support team, or speak to your account representative.