An SMS API lets applications send text messages programmatically: one-time passcodes, appointment reminders, delivery notices, alerts and sometimes marketing. Organisations integrate it through a REST endpoint or an SMS gateway and rely on it for routes into mobile operator networks in many countries.
Sovereignty here is shaped by the supply chain. A single message often passes through an aggregator, one or more carriers and sometimes a roaming hub, and every hop can log the number, the content and the timing. A provider based in Europe may still route via partners elsewhere, and a US-headquartered platform such as Twilio is subject to US law wherever its servers stand.
When selecting a European provider, ask where messages are routed and how long content and metadata are retained, whether message bodies can be masked or deleted after delivery, and which carriers and sub-processors take part. Check the processor agreement, support for sender ID registration per country, delivery reporting, and whether numbers and templates can be moved elsewhere. For authentication use cases, also weigh whether another channel could reduce your exposure.