# Sendblue: an iMessage API on Mac minis and iPhones since 2020, with its endpoints, limits and prices

slug: sendblue · https://miscsubjects.com/a/sendblue · category: reference · tags: imessage, messaging-api, sendblue, vendor-reference · updated 2026-09-22T05:10:25.194Z

Sendblue is a cloud iMessage API that has run since 2020 on Apple hardware the company owns. Its own description on 2026-09-21: "Sendblue runs on real Apple hardware — Mac Minis and iPhones — using standard Apple IDs and the native iMessage protocol." A customer gets a phone number on one of those devices, sends by HTTP, and receives replies by webhook; when a recipient has no iMessage the message falls to RCS and then SMS at no extra charge, a cascade Sendblue calls "iMessage → RCS → SMS".

Two terms recur. A **line** is one phone number provisioned on Sendblue's platform. A **verified contact**, on the free plan, is a recipient who has texted the customer's Sendblue number once; without that text the free plan refuses to message them.

## Authentication and base URL

Every request carries two headers, `sb-api-key-id` and `sb-api-secret-key`, against `https://api.sendblue.com` (the older host `api.sendblue.co` still answers). Sendblue blocks requests from browsers: "All requests must come from a backend server". Keys come from a dashboard or from the command-line tool, which also creates the account: `npm install -g @sendblue/cli` then `sendblue setup` asks for an email, sends a code, assigns a number and writes the keys to disk. A variant for AI agents, `npx -y @sendblue/cli@latest sandbox init`, shows a Sendblue number and a challenge phrase; whoever texts that phrase from a phone becomes the verified owner, so the agent never types a phone number.

## The endpoints

Sendblue's core surface, from its own index on 2026-09-21: `POST /api/send-message` (one recipient; fields `number`, `from_number`, `content`, `media_url`, `status_callback`, `send_style`), `POST /api/send-group-message`, `POST /api/send-typing-indicator`, `POST /api/send-reaction`, `POST /api/mark-read`, `POST /api/send-carousel` (2 to 20 images), `GET /api/evaluate-service` (does this number take iMessage), `POST /api/upload-file` and `POST /api/upload-media-object`, `GET /api/v2/messages`, full contact CRUD at `/api/v2/contacts` with opt-out and block, webhook CRUD at `/api/account/webhooks`, `GET /api/lines`, `POST /accounts/lines/add-line`, and `POST /facetime/start-call`. Text is capped at 18,996 characters; media at 100 MB on iMessage and 5 MB on SMS. `from_number` is required on every send and must be a Sendblue number on the account.

Statuses run REGISTERED, PENDING, QUEUED, ACCEPTED, SENT, DELIVERED, with DECLINED and ERROR as terminal failures. Message effects are sent by name in `send_style`: 13 of them, from `celebration` and `fireworks` to `invisible`, `gentle`, `loud` and `slam`. A `.caf` audio file renders as an inline voice note; a `.vcf` file delivers a contact card; an inline reply names the original by `reply_to: { message_handle }`. App Cards, a Sendblue name for iMessage app bubbles, are sent on `send-message` and updated in place by `POST /api/messages/{handle}/update-app-card`.

## Webhooks

Seven webhook types exist: `receive`, `outbound`, `typing_indicator`, `call_log`, `line_blocked`, `line_assigned` and `contact_created`. An inbound message arrives as `{from_number, to_number, content, media_url, service, group_id, date_sent}`; the receiver answers with any 2xx. Media URLs expire after 30 days. Webhooks are signed with a secret and must be served over HTTPS. `call_log` fires only for outbound calls placed from the dashboard.

## Limits

Sendblue's published limits on 2026-09-21: 1 message per second per dedicated number; the AI Agent plan allows 1,000 inbound contacts per day per line on a rolling 24 hours and 200 follow-ups per day per line; the Blue Ocean outbound plan allows 50 new outbound contacts per day per line, 15 per hour, and 5 messages to a contact who has not replied; the send queue holds 1,500 messages and returns 429 beyond that; iMessage detection is limited to 30 checks an hour and 100 a day per line; the contacts API to 100 requests per 10 seconds. Opt-out words (stop, unsubscribe, cancel, opt out, revoke, end, quit) are detected on every plan.

## Plans and prices

From sendblue.com/pricing on 2026-09-21: Free at $0, a shared line for prototyping with no outbound to unverified contacts and no webhooks; AI Agent at $100 per dedicated line per month, "inbound-first" with 1,000 inbound contacts a day, webhooks, media, typing and reactions, unable to start a conversation with a contact who has not texted first; Blue Ocean and Enterprise at custom, volume-based prices for full outbound, multiple lines, SOC 2 and HIPAA terms and an account manager. No per-message fee, no A2P registration, no carrier surcharge, and international messaging included; all lines carry US area codes.

## Beyond messaging

Two products sit next to the messaging API. FaceTime Audio calls start from `POST /facetime/start-call`, which returns Agora WebRTC credentials that the customer's own client joins; ordinary phone calls route through the customer's Twilio account with a verified caller id. Agent sandboxes are "isolated cloud Linux machines controlled over the Sendblue API": `POST /v3/sandboxes` creates one, `/exec` runs a command, `/files` reads and writes, and a fresh free account receives $100 of sandbox compute after phone verification; a sandbox sleeps after 10 idle minutes and resets its filesystem on wake.

Developer packaging: `npm install sendblue` and `pip install sendblue` SDKs; a local Model Context Protocol server, `npx -y sendblue-api-mcp@latest`, with 18 tools; a Vercel Chat SDK adapter; connectors for GoHighLevel, Close, HubSpot, Salesforce, Follow Up Boss, Monday, Zapier, Make and Slack; and a Chrome extension for click-to-text from any web page.

## Compliance as Sendblue states it

Sendblue's docs list "SOC 2 Type 2, HIPAA (dedicated instance required), TCPA compliant", TLS everywhere, HTTPS required for webhooks, and webhook signing secrets. Its own count of scale on the home page on 2026-09-21: "Installed 35,214+ times to generate over $2.1B+ revenue", a figure stated without a window or method. The service is not an Apple program; Sendblue's argument for legitimacy is that messages "go through the same system any normal iMessage user would use", and the same fact means an Apple block on a line ends that line.

## Sources

1. Sendblue API quickstart for AI assistants — https://sendblue.com/llms.txt
2. Sendblue docs index for machine readers — https://docs.sendblue.com/llms.txt
3. Sendblue pricing — https://sendblue.com/pricing
4. Sendblue rate limits section — https://sendblue.com/llms.txt
5. Sendblue home page — https://sendblue.com

