IOSOR Learn

Inbound events and inbox on rented numbers: two-way ops without webhook chaos

How B2B teams receive SMS and voice events on rented numbers, build an inbox UX, and handle retries/idempotency — white-label and prepaid-honest.

Outbound gets the roadmap slides; inbound gets the pager. When customers reply STOP, send a photo, or call back on a rented number, your platform must deliver events reliably into your systems — with an inbox story support can trust. A two-way product without inbound discipline is a one-way promise with a complaint queue. Inbound is where the ledger meets the real world, and where compliance risks live or die.

IOSOR assigns rented numbers with inbound webhooks and client-safe errors — no third-party portal for day-two ops, white-label catalog honesty. Near USD 1,000+ monthly platform usage, webhook auth evidence, STOP handling logs, and inbox correlation IDs become commercial review material. Evidence first, then scale.

Event types you must plan for

Event Product surface Ops need
Inbound SMS Thread / ticket Deduped webhook + storage
Delivery receipts Status timeline Correlation to outbound send
Voice callbacks Queue / voicemail Recording policy + consent
Keyword STOP/HELP Compliance log Immediate suppression

Webhook discipline for inbound

  • Authenticate inbound requests to prevent spoofed events.
  • Idempotent handlers — retries are normal and expected.
  • Persist the event before side effects like CRM updates or auto-replies.
  • Dead-letter queue with replay tools for when your stack blinks.

Inbox UX without fraud holes

An inbox is not a chat toy — it is evidence. Agents should never see raw upstream payloads; they need a clean interface that hides the plumbing while preserving the truth. White-label errors stay usable; secrets and diagnostics stay in ops. Rate-limited auto-replies without consent context become a loop that burns prepaid and angers the recipient.

Rented number lifecycle ties to inbox

Numbers renew on a UTC calendar-month rhythm; releases must stop inbound events cleanly. Document owners for renew vs retire — finance should not learn a number died from angry customers. Pair with local and toll-free rental reality. When a number is released, your webhook should return a 410 Gone or 404 to signal the upstream to stop trying. This prevents «ghost» events from haunting your logs after the billing cycle ends.

Red flags

Here is the trap: treating inbound as a free or low-priority stream. If your system accepts webhooks without checking signatures, an attacker can flood your inbox with fake messages, triggering expensive auto-replies. Another red flag is the lack of correlation IDs; if you cannot link an inbound SMS to the outbound message that prompted it, your support team is flying blind.

Start with IOSOR

Assign one rented two-way number. Send a test MO. Open the inbox and confirm one row with DID, tenant, and correlation id. Replay the same event from the dead-letter and confirm no second row. Hand support the STOP path they will read aloud. This is an inbox artifact on a rented DID, not a gateway lock and not a flood throttle.

Related: inbound auto-reply loops Buffer Inbound Webhook Processing Against Carrier Latency Spikes.

IOSOR takeaway

A rented-number inbox is a support row. Webhook 2xx with no row is a silent drop.

Do: bind each MO to a row an agent can open. Don't: leave inbound in a raw log and call that an inbox.

Was this guide helpful?

Related guides