Key Takeaways
- Preorder webhooks are drop-release: SKU last-four and window — never a queue token or checkout OTP in SMS.
- Verify signatures before the SIM fires. A replayed preorder.released is a second stampede.
- Keep checkout OTP off the tablet that dumps drop-night bursts.
- Service pricing is devices plus SMS send volume. You bring the Android phone and operator credit.
- Free is 1 device, 300 SMS lifetime, 300 contacts. Developer is 25,000 SMS per year.
- Idempotency on release id, not on “SKU + today.”
Summary
Ecommerce webhooks in scenario 589 are preorder and drop-release: window open, SKU last-four, portal. Unlike order.paid, restock/cart, refund, subscription renew, gift-card, BOPIS, split-shipment, RMA labels, or COD confirm, this event is a queue you promised months ago.
Service pricing is devices plus SMS send volume. You bring the Android phone and operator SMS credit. Free is 1 device, 300 SMS lifetime, 300 contacts. Developer is 25,000 SMS per year. Starter, Professional, and Business list Unlimited SMS as platform send volume; devices and airtime stay metered.
A queue token in SMS is a checkout you leaked. Verify the webhook. Send the window. Keep the token in the app.
Key takeaways
- Preorder webhooks are drop-release: SKU last-four and window — never a queue token or checkout OTP in SMS.
- Verify signatures before the SIM fires. A replayed preorder.released is a second stampede.
- Keep checkout OTP off the tablet that dumps drop-night bursts.
- Service pricing is devices plus SMS send volume. You bring the Android phone and operator credit.
- Free is 1 device, 300 SMS lifetime, 300 contacts. Developer is 25,000 SMS per year.
- Idempotency on release id, not on “SKU + today.”
Related reading
Start from Twilio vs Android SMS gateway, compare device and SMS volume pricing, open device setup, and review GS1 product-id notes.
Context
Merch ops land here after a replayed preorder.released texted the same drop twice and support drowned. Checkout OTP cannot share that night burst.
Core scenario guidance
Verify signatures. Idempotency on release id. Template: window, last-four. Token in the app. Isolate OTP. Cap retries.
| Event | SMS body | Fail closed |
|---|---|---|
| preorder.released | Window + last-four | Queue token in body |
| preorder.delayed | New window | Replay of release |
| Idempotency | Release id | SKU + today |
| Checkout OTP | Separate device | Same SIM as drop burst |
Canary a staff drop after OS updates. MCP wraps REST. Developer Center owns fields.
Cost and ownership
Devices + volume + operator airtime on every replay. Developer is 25,000 SMS per year. Free (1 / 300 / 300) proves pairing, not a drop night.
Operations
Daily last-seen, battery, webhook fail, duplicate release ids. After SIM reseat, one staff drop. On-call before unattended drop nights.
Security and compliance
Drop events reveal demand. Encrypt at rest. Rotate webhook secrets. Never log queue tokens. Verify TLS on every callback.
Decision guide
Ship when signatures, release-id idempotency, and token isolation exist. Delay if the shop can replay release. If zero phone ops is mandatory, evaluate CPaaS for that slice.
Checklist
- Webhook signatures verified.
- Release id idempotent.
- No queue token in SMS.
- OTP isolated.
- Spare paired.
Next steps
Return to open-source Android SMS gateway, compare device and SMS volume pricing, open device setup, and confirm APIs in SMS API documentation.
Deep dive: production hardening
Webhook signature verification is non-negotiable. Dual-SIM merch tablets fail when the send slot swaps after reboot. Battery exemptions dominate overnight stockrooms.
Deep dive: scaling and failure modes
Scale is waitlist size times one release, not a blast of the catalog. Never claim unlimited free cloud SMS credits with no device or volume meter.
Deep dive: integration discipline
Developer Center owns live API parameters. Persist release id. MCP is a REST wrapper. If zero phone ops is mandatory, evaluate CPaaS. You bring the Android phone and operator credit.
Related product pages
Jump to the live product docs for this topic—not another long-form article.
- SMS webhook integrationInbound and status events
- transactional SMS for orders and alertsEvent-driven messages
- SMS API documentationLive endpoint reference
- device and SMS volume pricingPlans and allowances





