Key Takeaways
- Webhooks are not on Free. Architect poll-with-backoff (or upgrade) before you promise “instant DLR” to a customer.
- A missing callback is not proof the SIM never submitted. Lookup-by-id is the support tool.
- Tight GET loops against every OTP are a hammer. Sleep, jitter, stop on 429.
- Paid webhooks still need HTTPS, HMAC, and idempotent handlers. Confirm live headers in Developer Center.
- Priced by devices and SMS send volume. You use your own phone and operator SMS credit. Free’s 300 SMS lifetime is for canaries, not a webhook farm.
Free does not mean unsigned callbacks
People search “free SMS server webhook” hoping localhost ngrok plus a lifetime plan equals Twilio-style callbacks. On this product, webhooks start on Starter. Free still pairs an Android phone and still meters send volume. SMS webhook integration. How an Android SMS gateway works. Developer Center.
If your architecture requires a POST to your URL before the OTP UI can proceed, you are not on the Free plan. You are on a ticket that Support will close.
Free poll vs paid webhook
| Free | Starter and up | |
|---|---|---|
| Outbound webhook | No — poll with backoff | Yes — signed HTTPS |
| In-product DLR | Basic, shorter retention | Longer windows; confirm live |
| OTP UX | Lookup / timeout, not callback-gated | Webhook + lookup backup |
| Localhost | Irrelevant | Still unreachable — public TLS |
Backoff, not a tight GET loop
Troubleshooting: webhooks troubleshooting. DLR shape: delivery reports. Limits: DLR limits. Load-test ethics: load test carefully— poll backoff is OEM/API courtesy, not filter evasion.
Ship DLR without a Free webhook
- Assume no webhook on Free. Do not open a ticket that the plan cannot fulfill. Poll or upgrade.
- Lookup by id with backoff. Jitter. Stop on 429. Do not poll every OTP in a 200ms loop.
- Treat 201 as queued, not delivered. Support UI must show unknown until DLR or timeout.
- Canary on staff numbers. Each canary spends Free lifetime SMS and pulsa. Budget it.
- Upgrade before webhook-only OTP. Signed HTTPS callbacks start on Starter. Confirm live behavior in Developer Center.
- When webhooks exist, verify HMAC and stay idempotent. Retries double-fire. TLS is the floor, not the proof of sender.
Hub: free SMS server. Setup: device setup.
When you do upgrade
HTTPS, HMAC, idempotent handlers, public cert. HTTPS webhook in-depth. Isolate OTP deviceIds so campaign traffic cannot starve callback processing. OTP verification.
Polling still spends airtime on canaries
Service pricing is based on device count and total SMS sent through the gateway. You need a working Android phone with a SIM and SMS credit from your mobile operator. Operator message costs are yours—we do not sell carrier SMS balance. Paid from $19/month. Device and SMS volume pricing.
Next steps
Poll with backoff on Free, or move to Starter for signed webhooks. Do not build webhook-only OTP on a plan that cannot fire them.
Related product pages
Jump to the live product docs for this topic—not another long-form article.
- SMS webhook integrationInbound and status events
- device and SMS volume pricingPlans and allowances
- Android SMS gateway product guideDefinition, product, and how to buy
- SMS API documentationLive endpoint reference





