
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
MCP server for SMS + OTP. Twilio alternative for AI agents — let Claude Code, Cursor, Windsurf, and OpenCode send SMS, OTPs, and verification codes through your own Android phone. Free 5-day trial at sms8.io. No per-message fees, no markups, no A2P 10DLC.
Plug SMS into any AI coding tool that speaks the Model Context Protocol. Your assistant can now send SMS, generate and verify OTPs, wait for incoming codes, list inbox messages, and configure webhooks — through your own Android phone rather than Twilio.
Add to any MCP client config and you're done:
{
"mcpServers": {
"sms8": {
"command": "npx",
"args": ["-y", "sms8-mcp"],
"env": { "SMS8_API_KEY": "sk_xxx" }
}
}
}
Exposes 9 tools to your AI assistant:
| Tool | What it does |
|---|---|
setup_sms8 | Validate the API key, return account context and code samples |
send_sms | Send one SMS to one phone number |
send_otp | Generate and send a verification code |
verify_otp | Compare a typed code against the latest issued OTP |
wait_for_otp | Block until an OTP arrives on the paired Android; extract the code |
list_devices | List paired Android phones (model, primary flag, enabled) |
get_messages | Recent inbox or sent items, filter by direction, limit, phone |
get_balance | Account credits + expiry + paired-device count |
create_webhook | Register an inbound-SMS webhook URL |
send_otp → wait_for_otp lets agents handle phone verification in tests, signups, password resetsYou don't have to install anything — npx -y sms8-mcp does it on demand inside the MCP config. The launcher is ~10 KB.
To install globally:
npm install -g sms8-mcp
Node 18 or newer.
~/.claude/config.json or per-project .mcp.json:
{
"mcpServers": {
"sms8": {
"command": "npx",
"args": ["-y", "sms8-mcp"],
"env": { "SMS8_API_KEY": "sk_xxx" }
}
}
}
~/.cursor/mcp.json:
{
"mcpServers": {
"sms8": {
"command": "npx",
"args": ["-y", "sms8-mcp"],
"env": { "SMS8_API_KEY": "sk_xxx" }
}
}
}
~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"sms8": {
"command": "npx",
"args": ["-y", "sms8-mcp"],
"env": { "SMS8_API_KEY": "sk_xxx" }
}
}
}
Add to opencode.json:
{
"mcp": {
"sms8": {
"command": "npx",
"args": ["-y", "sms8-mcp"],
"env": { "SMS8_API_KEY": "sk_xxx" }
}
}
}
Connect directly to the hosted MCP — no local install needed. Add https://mcp.sms8.io as a connector in claude.ai → Settings → Connectors. Then ask: "Send SMS via SMS8 to +1234 saying Hi".
After adding the connector and restarting your client:
npx -y sms8-mcp over stdiohttps://mcp.sms8.io, adding Authorization: Bearer <SMS8_API_KEY> to each callRound-trip is typically under 4 seconds.
| Variable | Default | Purpose |
|---|---|---|
SMS8_API_KEY | (required) | Your API key from app.sms8.io |
SMS8_BASE_URL | https://mcp.sms8.io | Override server (rare; for self-hosted) |
If you want to call SMS8 from shell scripts, cron, CI without an AI loop, use the companion package sms8-cli:
npx sms8-cli send +14155550100 "Hi"
npx sms8-cli otp send +14155550100
CODE=$(npx sms8-cli otp wait +14155550100 --timeout=120)
MIT
FAQs
MCP server for SMS + OTP. Twilio alternative for AI agents — let Claude Code, Cursor, Windsurf, and OpenCode send SMS, OTPs, and verification codes through your own Android phone. Free 5-day trial at sms8.io. No per-message fees, no markups, no A2P 10DLC.
The npm package sms8-mcp receives a total of 21 weekly downloads. As such, sms8-mcp popularity was classified as not popular.
We found that sms8-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.