Key Takeaways
- Ecommerce webhooks tell your app the order moved. The Android phone only sends the SMS. Never let the shop platform POST straight to a raw send URL.
- Verify signatures, then enqueue. A forged “shipped” event will debit operator credit and lie to the buyer.
- Paid / shipped / pickup OTP / cart promo are different lanes. Cart blasts must not share the OTP SIM.
- Priced by devices and SMS send volume. You use your own phone and operator SMS credit. Free is 1 device, 300 SMS lifetime, 300 contacts.
- Webhook 200 is not a delivery report. Watch DLR on the SIM path separately.
- Developer Center owns live send fields; the shop owns its webhook docs.
Summary
Scenario 1993 is ecommerce webhooks driving SMS on an Android gateway: paid, fulfilled, out-for-delivery, pickup PIN. The storefront emits events. Your worker authenticates them and talks to the SIM. Priced by devices and SMS send volume. You use your own phone and operator SMS credit. This is not a hosted “unlimited SMS” pipe.
If any signed-looking POST can fire
POST /messages, you do not have a shop integration. You have an open radio.
Shop event → worker → SIM
Pattern: HTTPS webhook → verify → map template → enqueue with order-id idempotency → Android send → DLR webhook back to your app. Glue examples: Shopify overview · WordPress webhook pattern. Send fields: Developer Center. Shop platform docs stay authoritative for their signatures.
Event map
| Shop event | SMS job | SIM pool | Skip send if |
|---|---|---|---|
| order.paid | Receipt stub + link | Transactional | Signature fail or duplicate order id |
| fulfillment.shipped | Carrier + tracking URL | Transactional | Buyer STOP on transactional mute (policy) |
| pickup ready | PIN / window | Transactional; isolate if PIN-like | PIN logged to chat (do not send until logging is safe) |
| checkout abandoned | Promo nudge | Marketing MSISDN | No consent or quiet hours |
| staff / customer login | OTP | Dedicated OTP phone | Any campaign sharing that device |
Verify before you send
HMAC or platform secret on every hook. Reject unsigned bodies. Do not trust query-string “shared tokens” in logs. Gateway webhooks. Industry SMS context: GSMA.
Idempotency and radio retries
Shops retry webhooks. Your key is the shop event id plus template. Radio retries are a second counter — they burn airtime. Idempotent send · DLR. Accept on your webhook endpoint quickly; work async so the shop does not hammer you.
Cost
Priced by devices and SMS send volume. You use your own phone and operator SMS credit. Free: 1 device, 300 SMS lifetime, 300 contacts. Developer: 25,000 SMS/year. Paid plans uncap platform volume; devices still meter. Abandoned-cart loops can empty prepaid SIMs — cap retries. Pricing.
Ops
Alert on signature failure rate, queue depth, and DLR drop. After OEM updates, canary a paid-order fixture. Doze · setup.
Security
Separate secrets for shop hooks vs gateway callbacks. Never log OTP or pickup PINs. Trust Center. Promo STOP stays off the OTP inbox. STOP.
Checklist
- Signature verified in the worker, not “optional in staging.”
- Idempotency on shop event id.
- OTP SIM isolated from cart campaigns.
- DLR monitored separately from webhook 200s.
- Airtime budget includes radio retries.
- Spare device paired before a sale.
Next steps
Ecommerce templates · transactional SMS · SMS API documentation.
Related product pages
Jump to the live product docs for this topic—not another long-form article.
- SMS webhook integrationInbound and status events
- transactional SMS for orders and alertsEvent-driven messages
- SMS API documentationLive endpoint reference
- device and SMS volume pricingPlans and allowances





