
API integration for Twilio
We build your Twilio connector
We wire the Twilio API into your product to the Twilio API to send your text messages, verify your phone numbers and trigger your calls, with per-message delivery tracking and the French sending window enforced in code.
- Senior product team
- SMS and voice integrations in production
- from scoping to monitoring
What does the Twilio API provide and why integrate it into a communications application?
Twilio is a programmable communications platform that lets your application send SMS messages, WhatsApp messages, trigger phone calls, and verify identity with one-time codes. You integrate it to send critical notifications by SMS when email is insufficient, deploy a verification code at sign-up or login, or trigger an automated call for an alert or confirmation. The platform covers more than 180 countries from a single integration, making it suitable for products with international reach.
What our clients build on the Twilio API
Two-factor authentication by SMS
Verify sends the code, checks that it is valid and handles its expiry. Your application no longer stores one-time codes.
Appointment reminders confirmed by SMS
The recipient replies to confirm, the reply lands in your scheduling tool, and the day-before reminder only goes out if nobody confirmed.
Escalation from SMS to a phone call
A field service message not delivered within the expected window triggers an automated call. The channel follows the urgency, instead of sending blind.
A consent and opt-out portal
One screen drives consent channel by channel, feeds Twilio and logs every withdrawal. Exportable if you are ever audited.
What it changes in your customer relationship
Engineering in service of a measurable outcome: fewer calls to the switchboard, traceable sends, compliance that holds.
Your customers hear from you without you
Slot confirmed, delivery approaching, visit rescheduled: the information leaves the product. The switchboard picks up less often.
Every send leaves a trace
Delivery status, carrier error code, unit cost. A customer dispute gets settled with a log, not with a conviction.
A bill that does not double
Idempotency is held on the application side: a network timeout followed by a replay does not bill two messages to the same recipient.
Compliance enforced by the code
Sending window, opt-in, the STOP keyword and the suppression list are applied before the call to Twilio, not hoped for afterwards.
How we ship your Twilio connector
Scoping
Which channels, what volumes, which messages are transactional or marketing, which sending window. We list the edge cases before coding.
Development
Typed connector, application-level idempotency, a token bucket on throughput, retry queue, isolated secrets. A demo every week.
Acceptance testing
Replay on real phone numbers, webhook signature verification, testing carrier rejections and STOP replies.
Monitoring
Alerts on send failures, a delivery and cost dashboard, an inspectable dead letter queue. You see a broken channel before your customers do.
What the Twilio API allows
- SMS, MMS and WhatsApp messages
- Sending one by one or through a Messaging Service, content templates, scheduled sending with SendAt and a configurable validity period.
- Per-message delivery statuses
- Ten statuses, from queued through delivered, undelivered or failed, pushed to your StatusCallback along with the carrier error code.
- Identity verification with Verify
- SMS, voice, WhatsApp, email, TOTP, passkeys or Silent Network Auth, with rate limits per identity to contain toll fraud.
- Programmable voice
- Outbound calls driven by TwiML, answering machine detection, recording and call events from initiated to completed.
The vocabulary of the Twilio API
- Segment
- The billing unit of a text message: 160 characters in GSM-7, 70 as soon as one character falls outside that alphabet. An emoji dropped into a template can multiply the cost of a send, so it gets settled during scoping.
- MessagingServiceSid
- The identifier of a sender pool. It carries sender selection, advanced opt-out and country code geomatch, instead of hard-coding a phone number in the application.
- StatusCallback
- The URL Twilio calls on every state change of a message or a call. It is what feeds your delivery log, instead of polling the API on a timer.
- Error 21610
- A send refused because the recipient has opted out. It arrives asynchronously, after the attempt has been billed: the suppression list therefore has to live in your database, not only at Twilio.
- Error 30001
- Queue overflow. Messages pile up when the requested throughput exceeds the sender's capacity, then end in failure. It is the symptom of a bulk send launched with no scheduler.
- X-Twilio-Signature
- The webhook signature header, HMAC-SHA1 over the full URL and the sorted parameters. With a JSON body, the signature covers the URL containing bodySHA256, not the body itself.
The real constraints of the Twilio API
No documented idempotency on sending
The Messaging reference documents no idempotency header on message creation. A network timeout followed by a replay sends and bills twice: the protection gets built in your own database.
Throughput depends on the sender type
It is counted in segments per second, and defaults to 10 for an alphanumeric sender. Beyond that, messages pile up in a queue then fail with error 30001. A bulk send has to be scheduled.
Marketing SMS is regulated in France
A window from 08:00 to 21:30, sends recommended Monday to Saturday, prior opt-in required, free STOP unsubscribe and an alphanumeric sender of 11 characters maximum. That is the af2m charter.
European data residency is partial
The Ireland region covers the Programmable Messaging API and Messaging Services, but not MMS, WhatsApp, RCS or Messenger. The exact perimeter gets confirmed with Twilio for your own account.
Twilio or Brevo for your sends?
Two different starting points: a programmable carrier on one side, a French email and SMS suite on the other. The right one depends on your channels.
| Criterion | TwilioThis page | BrevoEmail and SMS suite |
|---|---|---|
| Channels covered | SMS, MMS, WhatsApp, voice | Email, SMS, WhatsApp, chat |
| OTP out of the box | Verify: SMS, voice, TOTP, passkeys | To be built in the application |
| Vendor | United States | France |
| Webhook signature | X-Twilio-Signature in HMAC-SHA1 | None: IP ranges and a token |
| Send idempotency | Undocumented, to be built | Undocumented, to be built |
| What breaks in production | Throughput per sender type | The 100 requests per hour on other endpoints |
| The right case | Voice, OTP and multichannel | Transactional email and SMS in one place |
The two combine: Brevo for lifecycle email, Twilio for voice and identity verification. It is a scoping trade-off, not a permanent choice.
What we measure on a Twilio integration
The other messaging APIs
If voice and multichannel are not on the agenda, these options are worth discussing during scoping.
TwilioWe build your Twilio connectorThis page
BrevoTransactional email and SMS in a French account, templates included.
RingoverFrench telephony: calls, screen pop and SMS from your business software.
MailjetEmail at volume, a French vendor, with no voice and no dedicated OTP.
ResendWe build your Resend connectorWe combine Twilio with
The stack that surrounds Twilio on our projects.
Twilio integration: your questions
Three steps. Generate a dedicated API key in the Twilio console rather than using the account's main token. Build a connector that sends messages with an idempotency key held in your own database, respects the sender's throughput and records the message identifier that comes back. Then wire up the status and inbound reply webhooks, verifying the X-Twilio-Signature header on every call. The sensitive part is not the API call: it is the consent register, the suppression list and the sending window, all of which have to live on the application side.
A first useful flow, typically transactional messages with delivery tracking, ships in two to three weeks. A complete chain with Verify checks, escalation to a phone call, a consent portal and an auditable log is closer to six to eight weeks. The duration depends less on the Twilio API than on your consent model and the number of channels to cover. We scope the perimeter up front and give you a firm estimate before we start.
The framework comes down to four rules, which we enforce in code rather than leaving to the carrier. Promotional messages only go out between 08:00 and 21:30, Monday to Saturday, with Sundays and public holidays tolerated but not advised. No promotional send goes out without prior opt-in and timestamped proof. STOP unsubscribes are handled free of charge and without conditions, and the suppression list is checked before every send. The alphanumeric sender is capped at eleven characters, with no misleading field and nothing that looks like a phone number. Transactional messages, such as a verification code or a delivery update, fall outside the time window.
Twilio covers SMS, WhatsApp and voice, with Verify for two-factor authentication: it is the right choice as soon as you need several channels, automated escalation or a business voice menu. Brevo brings transactional email and SMS together in a French account, with templates maintained by the marketing team: it is the right choice when email carries most of the volume. Neither documents an idempotency key, so protection against double sending is built the same way in both cases. We settle it during scoping, and sometimes the answer is both.
Yes, by choosing the channel rather than the vendor. Twilio bills every successful Verify check at 0.05 USD, on top of the cost of the message or the call. On a product where users reconnect often, the gap between systematic SMS OTP and authentication through TOTP or Silent Network Auth adds up fast. So we design a channel strategy: a method with no unit cost for recurring users, SMS as the fallback, and Verify rate limits per identity to contain toll fraud. Cost is steered at design time, not on the invoice.
A Twilio integration project?
Let's talk. 30 minutes to scope your channels, check what the API actually allows and tell you honestly what is feasible.
Discuss my Twilio project