Key Takeaways
- RMA-label webhooks are return-ready: last-four and drop-off window — never a raw label token or QR payload in SMS.
- Verify signatures before the SIM fires. A replayed return.label_created is a second trip to the locker.
- Keep checkout OTP off the tablet that dumps returns bursts.
- Service pricing is devices plus SMS send volume. You bring the Android phone and operator credit.
- Free is 1 device, 300 SMS lifetime, 300 contacts. Developer is 25,000 SMS per year.
- Idempotency on return id, not on “customer phone + today.”
Summary
Ecommerce webhooks in scenario 469 are RMA label-created events: drop-off window, carrier, order last-four. Unlike order.paid, restock/cart, refund money, subscription renew, gift-card issued, BOPIS pickup, or split-shipment boxes, this event is the customer sending something back.
Service pricing is devices plus SMS send volume. You bring the Android phone and operator SMS credit. Free is 1 device, 300 SMS lifetime, 300 contacts. Developer is 25,000 SMS per year. Starter, Professional, and Business list Unlimited SMS as platform send volume; devices and airtime stay metered.
A label token in SMS is a free return for whoever finds the phone. Verify the webhook. Keep the barcode in the app.
Key takeaways
- RMA-label webhooks are return-ready: last-four and drop-off window — never a raw label token or QR payload in SMS.
- Verify signatures before the SIM fires. A replayed return.label_created is a second trip to the locker.
- Keep checkout OTP off the tablet that dumps returns bursts.
- Service pricing is devices plus SMS send volume. You bring the Android phone and operator credit.
- Free is 1 device, 300 SMS lifetime, 300 contacts. Developer is 25,000 SMS per year.
- Idempotency on return id, not on “customer phone + today.”
Related reading
Start from Twilio vs Android SMS gateway, compare device and SMS volume pricing, open device setup, and review GS1 return-logistics notes.
Context
Returns desks land here after a replayed return.label_created printed two labels and a stranger dropped the wrong bag. Checkout OTP cannot share that Saturday burst.
Core scenario guidance
Verify signatures. Idempotency on return id. Template: window, last-four, carrier. Token in the app. Isolate OTP. Cap retries.
| Event | SMS body | Fail closed |
|---|---|---|
| return.label_created | Window + last-four | Raw label token |
| return.received | Optional ACK | Refund amount in SMS |
| Idempotency | Return id | Phone + today |
| Checkout OTP | Separate device | Same SIM as RMA burst |
Canary a staff RMA after OS updates. MCP wraps REST. Developer Center owns fields.
Cost and ownership
Devices + volume + operator airtime on every replay. Developer is 25,000 SMS per year. Free (1 / 300 / 300) proves pairing, not a returns DC.
Operations
Daily last-seen, battery, webhook fail, duplicate return ids. After SIM reseat, one staff RMA. On-call before unattended peak days.
Security and compliance
Return events reveal that a parcel is in transit backwards. Encrypt at rest. Rotate webhook secrets. Never log label tokens. Verify TLS on every callback.
Decision guide
Ship when signatures, idempotency, and token isolation exist. Delay if the shop can replay labels. If zero phone ops is mandatory, evaluate CPaaS for that slice.
Checklist
- Webhook signatures verified.
- Return id idempotent.
- No label token in SMS.
- OTP isolated.
- Spare paired.
Next steps
Return to open-source Android SMS gateway, compare device and SMS volume pricing, open device setup, and confirm APIs in SMS API documentation.
Deep dive: production hardening
Webhook signature verification is non-negotiable. Dual-SIM returns tablets fail when the send slot swaps after reboot. Battery exemptions dominate overnight docks.
Deep dive: scaling and failure modes
Scale is RMAs times events, not a blast of the catalog. Never claim unlimited free cloud SMS credits with no device or volume meter.
Deep dive: integration discipline
Developer Center owns live API parameters. Persist return id. MCP is a REST wrapper. If zero phone ops is mandatory, evaluate CPaaS. You bring the Android phone and operator credit.
Related product pages
Jump to the live product docs for this topic—not another long-form article.
- SMS webhook integrationInbound and status events
- transactional SMS for orders and alertsEvent-driven messages
- SMS API documentationLive endpoint reference
- PHP REST send samplesPHP code examples





