Integrations
Handling incoming messages safely
Implementation scenario · This is an example implementation, not a story about a named customer. Results depend on your integration, phone, network and carrier.
AI-generated scenario illustrationThe problem
A webhook carries external text. It is not a trusted command, HTML fragment or instruction for a system operator.
Build the solution
Persist the original event, verify its signature and escape displayed text. Match the sender on your backend. If you automate replies, implement explicit allowed rules in your application.
Check before launch
Limit data size and staff access to history. Do not execute code, links or instructions from SMS. A phone number alone is not sufficient identity proof.
How SIM Bridge works
Your backend creates a job through the API, and the connected Android sends SMS through your SIM. Store the message ID in your system and receive status changes through a webhook. A queued job is not yet a sent message: the phone must be available and the carrier must accept it.
Start with your own test number. Check Android permissions, screen-off connectivity, retries with the same Idempotency-Key, and unknown-status handling. Keep API keys out of browser code and public repositories.
