Key Takeaways
- A Go webhook receiver is HTTPS + HMAC on your public endpoint. There is no official Go SDK from us — net/http or your router is enough.
- Verify the signature on the raw body before json.Unmarshal side effects. Retries will double-fire.
- 201 on send is not this handler. This path is DLR and inbound after GSM.
- Webhooks start on Starter. On Free, poll with backoff. Do not build webhook-only OTP in Go on Free.
- Priced by devices and SMS send volume. You use your own phone and operator SMS credit. Confirm live header names in Developer Center.
Go hears DLR; the SIM still sent it
Receiving Android SMS gateway API webhooks in Go is a signed POST to your handler. GSM already happened on a paired phone. SMS webhook integration. Developer Center. Go documentation.
If your first line is json.Unmarshal into a struct that marks OTP delivered, you built a forgeable login.Handler checklist
| Step | Do | Do not |
|---|---|---|
| TLS | Public CA, :443 | HTTP “for staging” |
| Body | Read once, HMAC raw bytes | Re-serialize then sign |
| Authz | Constant-time compare | Log the secret |
| Dedupe | Event id unique index | Apply twice on retry |
| Reply | 2xx after persist | 2xx before write (replay storm) |
Verify before you decode side effects
Live header names are not this article. HTTPS webhook in-depth. Delivery reports. Troubleshooting: webhooks troubleshooting.
Ship a net/http receiver
- Expose public HTTPS, not HTTP. Expired certs look like a radio outage. They are not.
- Read the raw body, then HMAC. Header names live in Developer Center. Do not HMAC a re-serialized JSON tree.
- Reject before business logic. Wrong signature → 401. Do not enqueue OTP “delivered” on a forged POST.
- Key the event id in a table. Retries duplicate. INSERT … ON CONFLICT is the handler.
- Keep OTP deviceIds off promo traffic. A campaign burst must not starve DLR processing for login codes.
- Timeout unknown DLR in the product UI. A missing callback is not proof the SIM never submitted. Lookup-by-id is the backup.
Send side is still POST /api/v1/messages with Bearer and deviceIds — confirm fields live. No packaged SDK.
Free has no outbound webhooks
Free webhook in-depth. Poll with backoff on Free. Do not open a ticket that the plan cannot fulfill.
Callbacks are not free SMS
Service pricing is based on device count and total SMS sent through the gateway. You need a working Android phone with a SIM and SMS credit from your mobile operator. Operator message costs are yours—we do not sell carrier SMS balance. Paid from $19/month. Device and SMS volume pricing.
Next steps
Public TLS, raw HMAC, idempotent table, OTP isolated. Then stop publishing a “Complete Go SDK” that does not exist.
Related product pages
Jump to the live product docs for this topic—not another long-form article.
- SMS webhook integrationInbound and status events
- SMS API documentationLive endpoint reference
- device and SMS volume pricingPlans and allowances
- Android SMS gateway product guideDefinition, product, and how to buy





