Go: Receive Android SMS Gateway API Webhooks

Featured illustration for Go: Receive Android SMS Gateway API Webhooks

Receive Android SMS Gateway API webhooks in Go: HowTo, checklist, HMAC verify, and OTP/auto-reply adjacency.

Written by the SMS Gateway team for operators who run phones and airtime themselves — not for theoretical cloud SMS demos.

InformationAndroid SMS GatewayAPIDevelopers
Article
Published
January 12, 2025
Updated
February 22, 2025
Reading time
17 minute read

Key Takeaways

  • A Go webhook receiver is HTTPS + HMAC on your public endpoint. There is no official Go SDK from us — net/http or your router is enough.
  • Verify the signature on the raw body before json.Unmarshal side effects. Retries will double-fire.
  • 201 on send is not this handler. This path is DLR and inbound after GSM.
  • Webhooks start on Starter. On Free, poll with backoff. Do not build webhook-only OTP in Go on Free.
  • Priced by devices and SMS send volume. You use your own phone and operator SMS credit. Confirm live header names in Developer Center.

Go hears DLR; the SIM still sent it

Receiving Android SMS gateway API webhooks in Go is a signed POST to your handler. GSM already happened on a paired phone. SMS webhook integration. Developer Center. Go documentation.

If your first line is json.Unmarshal into a struct that marks OTP delivered, you built a forgeable login.
HMAC first, then Go decode — TLS is the floor not the proofHMACnet/http
Decode after the stamp matches. Not before.

Handler checklist

StepDoDo not
TLSPublic CA, :443HTTP “for staging”
BodyRead once, HMAC raw bytesRe-serialize then sign
AuthzConstant-time compareLog the secret
DedupeEvent id unique indexApply twice on retry
Reply2xx after persist2xx before write (replay storm)

Verify before you decode side effects

Live header names are not this article. HTTPS webhook in-depth. Delivery reports. Troubleshooting: webhooks troubleshooting.

Ship a net/http receiver

  1. Expose public HTTPS, not HTTP. Expired certs look like a radio outage. They are not.
  2. Read the raw body, then HMAC. Header names live in Developer Center. Do not HMAC a re-serialized JSON tree.
  3. Reject before business logic. Wrong signature → 401. Do not enqueue OTP “delivered” on a forged POST.
  4. Key the event id in a table. Retries duplicate. INSERT … ON CONFLICT is the handler.
  5. Keep OTP deviceIds off promo traffic. A campaign burst must not starve DLR processing for login codes.
  6. Timeout unknown DLR in the product UI. A missing callback is not proof the SIM never submitted. Lookup-by-id is the backup.

Send side is still POST /api/v1/messages with Bearer and deviceIds — confirm fields live. No packaged SDK.

Free has no outbound webhooks

Free webhook in-depth. Poll with backoff on Free. Do not open a ticket that the plan cannot fulfill.

Callbacks are not free SMS

Service pricing is based on device count and total SMS sent through the gateway. You need a working Android phone with a SIM and SMS credit from your mobile operator. Operator message costs are yours—we do not sell carrier SMS balance. Paid from $19/month. Device and SMS volume pricing.

Next steps

Public TLS, raw HMAC, idempotent table, OTP isolated. Then stop publishing a “Complete Go SDK” that does not exist.

Jump to the live product docs for this topic—not another long-form article.

FAQ

Frequently asked questions

Direct answers about android sms gateway api.

Is there a go get SMS Gateway SDK?

No. REST HTTPS/JSON with a Bearer on send, HMAC on receive. Language samples are examples, not a module we vendor.

Can I bind localhost:8080 for production webhooks?

The control plane cannot reach your laptop. Use a public certificate on :443. ngrok is a demo, not an SLA.

Does HTTP 200 from my handler mean delivered?

It means you accepted the callback. The radio already did (or failed) its job. Idempotency is still required.

Do webhooks exist on Free?

No. Free is 300 SMS lifetime and in-product DLR. Poll with backoff or upgrade.
Keep learning

Topically related guides—chosen by subject overlap, not a fixed sitewide footer.

Information
android sms gateway api webhook

Android Sms Gateway Api Webhook: In-Depth Guide

Android Sms Gateway Api Webhook: In-Depth Guide. Long-tail article focused on exact query "android sms gateway api webhook". Expand with examples, limits, FAQ, and links to hub C. Priced by devices and SMS send volume; BYO phone and operator credit. Developer Center owns live API parameters.

Dec 24, 202516 min
Read article
Information
android sms gateway troubleshooting webhook timeout

Android SMS Gateway Troubleshooting: Webhook timeout

Android SMS Gateway Troubleshooting: Webhook timeout. KB article diagnosing webhook timeout. Symptoms, likely causes, validation steps, recovery. Priced by devices and SMS send volume; BYO phone and operator credit.

Jul 6, 202516 min
Read article
Information
create_webhook via mcp android sms gateway

Create_webhook Via Mcp Android Sms Gateway: In-Depth Guide

Create_webhook Via Mcp Android Sms Gateway: In-Depth Guide. Long-tail article focused on exact query "create_webhook via mcp android sms gateway". Expand with examples, limits, FAQ, and links to hub C. Priced by devices and SMS send volume; BYO phone and operator credit. Developer Center owns live API parameters.

Jun 20, 202616 min
Read article

Browse the full Android SMS gateway knowledge base or return to how an Android SMS gateway works.

Get started

Test the gateway on your own Android phone

Install the app, pair one device, and validate your API flow before choosing a paid plan.

You supply the phone, SIM, and operator SMS credit.