Key Takeaways
- Scenario 1873 is cash-on-delivery and pickup-window webhooks — not paid/shipped and not refunds.
- A COD “courier arriving” text must not share the PIN radio with staff OTP.
- Pickup PIN in SMS is high-stakes. Never log it. Rotate if the webhook retries after a screenshot leak.
- Priced by devices and SMS send volume. You use your own phone and operator SMS credit. Free is 1 / 300 / 300.
- Verify shop HMAC before you enqueue. Forged pickup-ready events steal parcels.
- Developer Center owns send fields. The shop owns COD webhook docs.
Summary
Scenario 1873 is ecommerce webhooks for COD and pickup windows on an Android gateway. The storefront says the parcel is payable or ready. Your worker authenticates the hook, then texts a window — and maybe a PIN. Priced by devices and SMS send volume. You use your own phone and operator SMS credit.
A pickup PIN that also lives in Slack is not a PIN. It is a shared password with extra airtime spend.
COD and pickup windows
Map fulfillment.ready_for_pickup / COD status to a worker, not a raw send URL. Shopify overview · gateway webhooks. Fields: Developer Center. Industry context: GSMA.
Event map
| Shop event | SMS job | SIM | Skip if |
|---|---|---|---|
| COD confirmed | Amount band + window | Transactional | Signature fail |
| pickup.ready | PIN + hours | PIN pool (not OTP staff) | PIN logged anywhere |
| pickup.expired | Reschedule stub | Transactional | Duplicate fulfillment id |
| staff login | OTP | Dedicated OTP phone | Shared with COD volume |
Pickup PIN hygiene
Idempotent on fulfillment id. Idempotent send. DLR ≠ collected — DLR.
Cost
Priced by devices and SMS send volume. You use your own phone and operator SMS credit. Free: 1 device, 300 SMS lifetime, 300 contacts. Developer: 25,000 SMS/year. Paid plans uncap platform volume; devices still meter. Pricing.
Ops
Canary a pickup fixture after OEM updates. Doze · setup. Spare before festival COD.
Security
Separate shop secrets from gateway callbacks. Trust Center · OTP. Abandoned-cart promo needs STOP elsewhere. STOP.
Checklist
- HMAC required.
- Same PIN on webhook retry.
- No PIN in chat logs.
- Staff OTP isolated.
- Airtime for window reminders; cap retries.
Next steps
Ecommerce templates · SMS API documentation.
Related product pages
Jump to the live product docs for this topic—not another long-form article.
- SMS webhook integrationInbound and status events
- transactional SMS for orders and alertsEvent-driven messages
- SMS API documentationLive endpoint reference
- device and SMS volume pricingPlans and allowances





