SMS2Webhook runs on your own phone and posts each incoming SMS to a webhook
URL that you configure. It is a building block for self-hosted automation:
point it at your own server to trigger workflows, archive messages, feed a
CRM or ticketing system, or expose SMS to your own dashboards.
What it sends
Every forwarded message is posted as JSON to the single endpoint you set. The
payload is your phone's own messaging row rather than a fixed shape, so the
fields present vary by device and Android version: the sender address, the
message body and the date timestamp are always there, and devices whose
messaging app records a SIM subscription include it as sub_id. Treat anything
beyond those as optional. If you configure an API key it is sent as anAuthorization: Bearer header.
What leaves the device
Message content is transmitted only to the webhook URL you enter. There
are no analytics, no advertising, no crash reporting and no third-party
servers. The local database stores a SHA-256 hash of each message for
deduplication, not the message text. Source code is public and auditable.
Because this is a self-hosted tool, the destination is yours to choose.
Review the URL you enter, and prefer HTTPS so message bodies are encrypted
in transit.
Permissions
RECEIVE_SMSandREAD_SMS— required to observe incoming messages and,
if you choose, to backfill your existing SMS history.INTERNET— to reach your webhook.CAMERA— optional, only for scanning the setup QR code.
The telephony and camera hardware features are declared optional, so the app
installs on devices without them.
Reliability
Uploads are queued in WorkManager with exponential backoff, so a webhook that
is briefly unreachable does not lose messages. A SHA-256 cache prevents the
same message being delivered twice.
Requirements
Android 9.0 (API 28) or later.