OneSignal

onesignal.comcontributed by Samuele Ongaro

ALMOST

A weekend of work, and real gaps remain.

Sends push notifications across web, mobile and other channels from one API, with segmentation, scheduling and delivery reporting on top of the platform services.

Promptfree, for everyone, and the only version there is
Build me push notifications that replace OneSignal — and read the obstacle first, because it decides everything.

**Delivery goes through Apple and Google, and there is no way around them.** Web push you can do yourself with VAPID keys and no account at all. Mobile push needs a registered application on each platform, which means developer accounts and a release process. That is the barrier, not the code — and the second half of the work is **token lifecycle management**, which is dull and unavoidable.

STACK
- Node 20+ with Fastify
- SQLite through better-sqlite3, WAL mode
- Web push directly with VAPID; APNs and FCM for mobile if you have the applications
- A worker for sending, separate from the web process
- Caddy in front

WEB PUSH, WHICH YOU CAN HAVE TODAY
- Generate a VAPID key pair once. No account, no fee, no third party
- A service worker on your site subscribes the browser and sends you an endpoint and two keys
- You encrypt the payload and POST it to that endpoint. The browser's own push service delivers it
- That is the whole protocol, and it works on every desktop browser and on Android. On iOS it works only for an installed web application, which is the caveat to write down

THE DATA MODEL
- devices: id, user_id, platform, token, endpoint, keys_json, app_version, os_version, language, timezone, created_at, last_seen_at, invalid_at, invalid_reason
- One row per device, never per user. A person has three, and two of them are dead
- notifications: id, title, body, url, data_json, image_path, kind, created_by, created_at
- targets: id, notification_id, device_id, scheduled_for, status, attempts, provider_message_id, sent_at, delivered_at, clicked_at, error — one row per device, which makes a resume exact and a duplicate impossible
- preferences: user_id, category, is_enabled, quiet_hours_json
- segments: saved rules over user properties and behaviour, evaluated at send time

TOKEN LIFECYCLE, WHICH IS THE UNGLAMOROUS HALF
- Tokens expire, are revoked, and migrate when an application is reinstalled. Sending to a dead token wastes quota and, in volume, harms your standing with the platform
- Every rejection tells you why. A permanent failure marks the device invalid immediately; a transient one retries with backoff. Never keep retrying a token the platform has told you is gone
- Deduplicate: the same user on the same device after a reinstall is one device, matched on the platform's own identifier where available
- Prune devices not seen in a long time, and record why they went
- Without this, a device table becomes mostly rubbish within a year and every send takes ten times longer than it should

SENDING
- The worker claims a batch of targets with a lease, sends, records the provider's response, and continues after a crash exactly where it stopped
- Rate limited to what each platform accepts, with backoff on throttling
- Batched where the platform supports it, one at a time where it does not
- A test send to your own devices required before any broadcast

RESPECTING THE PERSON
- Categories, with a preference per category. Everything opt-in
- Quiet hours in the recipient's own zone, enforced in the send path. A notification at three in the morning is an uninstall
- A frequency cap per person per day, enforced centrally rather than per campaign
- A clear way to turn each category off inside your application, not buried in system settings
- Push is the most intrusive channel there is. Every one of these rules is what keeps the permission you were granted

MEASURING
- Sent, delivered where the platform reports it, opened, and the resulting action
- Delivery is not guaranteed and not always reported. Say so beside the number rather than presenting a send count as a delivery count
- Per notification, per platform, per segment, computed at query time

OPERATIONS
- .env: DATABASE_PATH, BASE_URL, VAPID keys, APNS and FCM credentials, SESSION_SECRET
- Migrations on boot, each once; nightly backup off the machine
- Health endpoint reporting invalid-token rate and queue depth

WHAT MATTERS MOST
Token cleanup and quiet hours. The first keeps sending fast and your standing good; the second keeps the permission you were granted, and losing that permission is the one failure you cannot undo.

What you lose

  • Delivery across web push, iOS, Android, email and SMS from one API
  • Token lifecycle management: expiry, migration and cleanup across millions of devices
  • Segmentation and scheduled sends with timezone-aware delivery windows
  • Delivery and open reporting per platform, which the platforms make awkward to collect
  • Throughput to send millions of notifications in minutes

If you would rather not build

  • Pushover — paid, one-off, personal notifications

What it costs

read from their page 15 Aug 2026

PlanBilled monthlyBilled yearlyLast read
—$19/mo—15 Aug 2026

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

Novu

$0

Notification infrastructure with channels, templates and preferences, self-hostable.

novuhq/novufree · open source

Gotify

$0

Small self-hosted push server with its own Android client.

gotify/serverfree · open source

Why this verdict

our own opinion · changed only by a person

54/100

Verdict kinda at 54: web push alone is a weekend with the right library, and the retirement rules are what separate a working list from a rotting one. Native mobile push and the multi-channel story are where the product earns its fee.

History

tracked since 9 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 1/day
views0130 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about OneSignal

answered from the record above

Is OneSignal free?

No — the plan we track is $19 a month. Growth from $19/month, plus usage by channel — around $0.012 per monthly active user for mobile push.

Can you replace OneSignal by building your own?

ALMOST. A weekend of work, and real gaps remain. Replacement score 54 out of 100, build time a weekend. Read what you lose before you decide.

How much does OneSignal cost?

$19 a month on Growth — $228 a year. Recorded 14 Aug 2026.

What do you lose by replacing OneSignal?

Delivery across web push, iOS, Android, email and SMS from one API; Token lifecycle management: expiry, migration and cleanup across millions of devices; Segmentation and scheduled sends with timezone-aware delivery windows; Delivery and open reporting per platform, which the platforms make awkward to collect; Throughput to send millions of notifications in minutes. If any of those carry weight for you, keep paying.

Is there an open-source alternative to OneSignal?

Yes: Novu, Gotify. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 17 in Automation & notifications

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc