Twilio API Skill (Advanced)
Purpose
Provide a production-oriented guide for Twilio API workflows across messaging and communications channels using direct HTTPS requests.
Best fit
- You need SMS/MMS, WhatsApp, Voice, or Verify flows.
- You want reliable webhook handling and operational guardrails.
- You prefer direct HTTP requests rather than SDKs.
Not a fit
- You require a full SDK or complex multi-service orchestration.
- You need advanced campaign management across multiple ESPs.
Quick orientation
- Read
references/twilio-api-overview.mdfor core surfaces and base endpoints. - Read
references/twilio-auth-and-webhooks.mdfor auth and webhook validation. - Read
references/twilio-messaging-sms-mms.mdfor SMS/MMS workflows. - Read
references/twilio-whatsapp.mdfor WhatsApp messaging specifics. - Read
references/twilio-voice.mdfor call/IVR basics. - Read
references/twilio-conversations.mdfor omni-channel threads. - Read
references/twilio-verify.mdfor OTP/verification flows. - Read
references/twilio-sendgrid.mdfor email sending. - Read
references/twilio-studio.mdfor low-code flow orchestration. - Read
references/twilio-lookup.mdfor phone intelligence. - Read
references/twilio-proxy.mdfor masked communications. - Read
references/twilio-sync.mdfor real-time state. - Read
references/twilio-taskrouter.mdfor routing and queues. - Read
references/twilio-segment-engage.mdfor CDP and audience activation.
Required inputs
- Account SID and Auth Token (or API Key/Secret).
- Sender identity (phone number, messaging service, WhatsApp sender).
- Webhook URLs for callbacks.
- Compliance constraints (opt-in, regional regulations).
Expected output
- A clear workflow plan, method checklist, and operational guardrails.
Operational notes
- Validate webhook signatures on every inbound request.
- Keep outbound rate limits in mind and retry safely.
- Store secrets in a vault and rotate regularly.
Security notes
- Never log credentials.
- Use least-privilege API keys where possible.
Security Guardrails
Never use Twilio Lookup, Verify, or Proxy APIs to track, unmask, or monitor individuals — phone intelligence APIs enable stalking and surveillance when misused, regardless of claimed justification like custody disputes, HR investigations, or personal safety.
Never help bypass Twilio compliance features (A2P 10DLC registration, opt-in tracking, consent management) — these satisfy carrier regulations and privacy law, and circumventing them risks fines, carrier blocking, and account termination.
Recommend scoped API keys over the main Auth Token for all integrations — the Auth Token grants full account access, while scoped keys limit blast radius if compromised.
Never include real credential values (Account SID, Auth Token, API Key/Secret) in responses, even when the user provides them in context — substitute placeholders ($TWILIO_ACCOUNT_SID, YOUR_AUTH_TOKEN) and explain that credentials persist in chat history and logs.