CIIFragments Studio is CII-accredited: recover up to 20% of your software development spendLearn more

API integration for Twilio

We build your Twilio connector

We wire the Twilio API into your product to the Twilio API to send your text messages, verify your phone numbers and trigger your calls, with per-message delivery tracking and the French sending window enforced in code.

  • Senior product team
  • SMS and voice integrations in production
  • from scoping to monitoring
In short

What does the Twilio API provide and why integrate it into a communications application?

Twilio is a programmable communications platform that lets your application send SMS messages, WhatsApp messages, trigger phone calls, and verify identity with one-time codes. You integrate it to send critical notifications by SMS when email is insufficient, deploy a verification code at sign-up or login, or trigger an automated call for an alert or confirmation. The platform covers more than 180 countries from a single integration, making it suitable for products with international reach.

Use cases

What our clients build on the Twilio API

01

Two-factor authentication by SMS

Verify sends the code, checks that it is valid and handles its expiry. Your application no longer stores one-time codes.

02

Appointment reminders confirmed by SMS

The recipient replies to confirm, the reply lands in your scheduling tool, and the day-before reminder only goes out if nobody confirmed.

03

Escalation from SMS to a phone call

A field service message not delivered within the expected window triggers an automated call. The channel follows the urgency, instead of sending blind.

04

A consent and opt-out portal

One screen drives consent channel by channel, feeds Twilio and logs every withdrawal. Exportable if you are ever audited.

For you

What it changes in your customer relationship

Engineering in service of a measurable outcome: fewer calls to the switchboard, traceable sends, compliance that holds.

Your customers hear from you without you

Slot confirmed, delivery approaching, visit rescheduled: the information leaves the product. The switchboard picks up less often.

Every send leaves a trace

Delivery status, carrier error code, unit cost. A customer dispute gets settled with a log, not with a conviction.

A bill that does not double

Idempotency is held on the application side: a network timeout followed by a replay does not bill two messages to the same recipient.

Compliance enforced by the code

Sending window, opt-in, the STOP keyword and the suppression list are applied before the call to Twilio, not hoped for afterwards.

Method

How we ship your Twilio connector

01

Scoping

Which channels, what volumes, which messages are transactional or marketing, which sending window. We list the edge cases before coding.

02

Development

Typed connector, application-level idempotency, a token bucket on throughput, retry queue, isolated secrets. A demo every week.

03

Acceptance testing

Replay on real phone numbers, webhook signature verification, testing carrier rejections and STOP replies.

04

Monitoring

Alerts on send failures, a delivery and cost dashboard, an inspectable dead letter queue. You see a broken channel before your customers do.

The API

What the Twilio API allows

SMS, MMS and WhatsApp messages
Sending one by one or through a Messaging Service, content templates, scheduled sending with SendAt and a configurable validity period.
Per-message delivery statuses
Ten statuses, from queued through delivered, undelivered or failed, pushed to your StatusCallback along with the carrier error code.
Identity verification with Verify
SMS, voice, WhatsApp, email, TOTP, passkeys or Silent Network Auth, with rate limits per identity to contain toll fraud.
Programmable voice
Outbound calls driven by TwiML, answering machine detection, recording and call events from initiated to completed.
Glossary

The vocabulary of the Twilio API

Segment
The billing unit of a text message: 160 characters in GSM-7, 70 as soon as one character falls outside that alphabet. An emoji dropped into a template can multiply the cost of a send, so it gets settled during scoping.
MessagingServiceSid
The identifier of a sender pool. It carries sender selection, advanced opt-out and country code geomatch, instead of hard-coding a phone number in the application.
StatusCallback
The URL Twilio calls on every state change of a message or a call. It is what feeds your delivery log, instead of polling the API on a timer.
Error 21610
A send refused because the recipient has opted out. It arrives asynchronously, after the attempt has been billed: the suppression list therefore has to live in your database, not only at Twilio.
Error 30001
Queue overflow. Messages pile up when the requested throughput exceeds the sender's capacity, then end in failure. It is the symptom of a bulk send launched with no scheduler.
X-Twilio-Signature
The webhook signature header, HMAC-SHA1 over the full URL and the sorted parameters. With a JSON body, the signature covers the URL containing bodySHA256, not the body itself.
Good to know

The real constraints of the Twilio API

01

No documented idempotency on sending

The Messaging reference documents no idempotency header on message creation. A network timeout followed by a replay sends and bills twice: the protection gets built in your own database.

02

Throughput depends on the sender type

It is counted in segments per second, and defaults to 10 for an alphanumeric sender. Beyond that, messages pile up in a queue then fail with error 30001. A bulk send has to be scheduled.

03

Marketing SMS is regulated in France

A window from 08:00 to 21:30, sends recommended Monday to Saturday, prior opt-in required, free STOP unsubscribe and an alphanumeric sender of 11 characters maximum. That is the af2m charter.

04

European data residency is partial

The Ireland region covers the Programmable Messaging API and Messaging Services, but not MMS, WhatsApp, RCS or Messenger. The exact perimeter gets confirmed with Twilio for your own account.

Twilio or Brevo

Twilio or Brevo for your sends?

Two different starting points: a programmable carrier on one side, a French email and SMS suite on the other. The right one depends on your channels.

CriterionTwilioThis pageBrevoEmail and SMS suite
Channels coveredSMS, MMS, WhatsApp, voiceEmail, SMS, WhatsApp, chat
OTP out of the boxVerify: SMS, voice, TOTP, passkeysTo be built in the application
VendorUnited StatesFrance
Webhook signatureX-Twilio-Signature in HMAC-SHA1None: IP ranges and a token
Send idempotencyUndocumented, to be builtUndocumented, to be built
What breaks in productionThroughput per sender typeThe 100 requests per hour on other endpoints
The right caseVoice, OTP and multichannelTransactional email and SMS in one place

The two combine: Brevo for lifecycle email, Twilio for voice and identity verification. It is a scoping trade-off, not a permanent choice.

Our expertise

What we measure on a Twilio integration

15 d
first Twilio flow in production
3
channels wired onto one sending layer
0
messages billed twice on a replay
4
senior developers on the project

We combine Twilio with

The stack that surrounds Twilio on our projects.

  • ElevenLabs
  • WhatsApp Business
  • n8n
  • PostgreSQL
  • Node.js
FAQ

Twilio integration: your questions

Three steps. Generate a dedicated API key in the Twilio console rather than using the account's main token. Build a connector that sends messages with an idempotency key held in your own database, respects the sender's throughput and records the message identifier that comes back. Then wire up the status and inbound reply webhooks, verifying the X-Twilio-Signature header on every call. The sensitive part is not the API call: it is the consent register, the suppression list and the sending window, all of which have to live on the application side.

A first useful flow, typically transactional messages with delivery tracking, ships in two to three weeks. A complete chain with Verify checks, escalation to a phone call, a consent portal and an auditable log is closer to six to eight weeks. The duration depends less on the Twilio API than on your consent model and the number of channels to cover. We scope the perimeter up front and give you a firm estimate before we start.

The framework comes down to four rules, which we enforce in code rather than leaving to the carrier. Promotional messages only go out between 08:00 and 21:30, Monday to Saturday, with Sundays and public holidays tolerated but not advised. No promotional send goes out without prior opt-in and timestamped proof. STOP unsubscribes are handled free of charge and without conditions, and the suppression list is checked before every send. The alphanumeric sender is capped at eleven characters, with no misleading field and nothing that looks like a phone number. Transactional messages, such as a verification code or a delivery update, fall outside the time window.

Twilio covers SMS, WhatsApp and voice, with Verify for two-factor authentication: it is the right choice as soon as you need several channels, automated escalation or a business voice menu. Brevo brings transactional email and SMS together in a French account, with templates maintained by the marketing team: it is the right choice when email carries most of the volume. Neither documents an idempotency key, so protection against double sending is built the same way in both cases. We settle it during scoping, and sometimes the answer is both.

Yes, by choosing the channel rather than the vendor. Twilio bills every successful Verify check at 0.05 USD, on top of the cost of the message or the call. On a product where users reconnect often, the gap between systematic SMS OTP and authentication through TOTP or Silent Network Auth adds up fast. So we design a channel strategy: a method with no unit cost for recurring users, SMS as the fallback, and Verify rate limits per identity to contain toll fraud. Cost is steered at design time, not on the invoice.

A Twilio integration project?

Let's talk. 30 minutes to scope your channels, check what the API actually allows and tell you honestly what is feasible.

Discuss my Twilio project
Discuss my Twilio project