← Twilio Developer KitCONTENT HISTORY

Update to Twilio Developer Kit

Snapshot Sep 30, 2026 · 22:50 UTC · version 0.2.2

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "twilio-compliance-onboarding",
  "description": "Registrations required BEFORE Twilio traffic works. Covers messaging programs (A2P 10DLC, toll-free verification, WhatsApp WABA, RCS, short code, alphanumeric sender) and voice trust programs (STIR/SHAKEN, Voice Integrity, Branded Calling, CNAM). Each number/sender type has its own program — registration blocks traffic until complete.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 237
    }
  ],
  "skill_md_contents": "---\nname: twilio-compliance-onboarding\ndescription: >\n  Registrations required BEFORE Twilio traffic works. Covers messaging\n  programs (A2P 10DLC, toll-free verification, WhatsApp WABA, RCS, short\n  code, alphanumeric sender) and voice trust programs (STIR/SHAKEN, Voice\n  Integrity, Branded Calling, CNAM). Each number/sender type has its own\n  program — registration blocks traffic until complete.\n---\n\n## Overview\n\nMost Twilio channels require registration or approval before traffic flows. **Skipping this step is the #1 onboarding mistake** — developers build first, then discover messages are blocked or calls labeled as spam.\n\n**Lifecycle:** Choose numbers/senders (`twilio-numbers-senders`) → Register them (this skill) → Follow traffic rules (`twilio-compliance-traffic`)\n\n---\n\n## Decision Tree: What Do I Need to Register?\n\n### Messaging Programs\n\n| Sender type | Registration program | Timeline | Docs |\n|-------------|---------------------|----------|------|\n| US local (10DLC) | **A2P 10DLC** — brand + campaign | Brand: minutes. Campaign: 10-15 business days | [Overview](https://www.twilio.com/docs/messaging/compliance/a2p-10dlc) \\| [Quickstart](https://www.twilio.com/docs/messaging/compliance/a2p-10dlc/quickstart) |\n| US toll-free | **Toll-free verification** | 3-5 business days | [Console onboarding](https://www.twilio.com/docs/messaging/compliance/toll-free/console-onboarding) \\| [Requirements](https://help.twilio.com/articles/5377174717595-Toll-Free-Message-Verification-for-US-Canada) |\n| US short code | **Pre-approved at purchase** | 8-12 weeks provisioning | [Guidelines by country](https://www.twilio.com/en-us/guidelines/short-code) \\| [What is a short code?](https://help.twilio.com/articles/223182068-What-is-a-Messaging-Short-Code-) |\n| WhatsApp | **WABA + Meta Business Verification** | Minutes (sender) + weeks (Meta verification) | [Self sign-up](https://www.twilio.com/docs/whatsapp/self-sign-up) \\| [Getting started](https://help.twilio.com/articles/360007721954-Getting-Started-with-Twilio-for-WhatsApp) |\n| RCS | **Google + carrier approval** | 4-6 weeks minimum, longer multi-region | [RCS onboarding](https://www.twilio.com/docs/rcs/onboarding) \\| [Compliance guide](https://help.twilio.com/articles/49174994355355-RCS-Compliance-Onboarding-Guide) |\n| Alpha Sender ID | **Registration in some countries** | Varies by country | [How to register](https://help.twilio.com/articles/20153208099611-How-to-Register-an-Alphanumeric-Sender-ID) |\n| International numbers | **Regulatory bundle** (many countries) | Varies | [Getting started](https://www.twilio.com/docs/phone-numbers/regulatory/getting-started) \\| [How to submit](https://help.twilio.com/articles/8338625205147-How-to-Submit-a-Regulatory-Bundle-for-Phone-Number-Regulatory-Compliance) |\n| Twilio Verify | **Exempt** — no registration needed | Immediate | — |\n\n### Voice Trust Programs\n\n| Program | What it does | Vetting timeline | Docs |\n|---------|-------------|-----------------|------|\n| **STIR/SHAKEN** | Level A attestation = trusted caller ID | 24hr (Business Profile) + 72hr (Trust Product) | [Overview](https://www.twilio.com/docs/voice/trusted-calling-with-shakenstir) \\| [Onboarding](https://www.twilio.com/docs/voice/trusted-calling-with-shakenstir/shakenstir-onboarding) |\n| **Voice Integrity** | Registers numbers with carriers to remediate spam labels | 24-48hr (profile) + 24-48hr (remediation) | [Overview](https://www.twilio.com/docs/voice/spam-monitoring-with-voiceintegrity) \\| [Onboarding](https://www.twilio.com/docs/voice/spam-monitoring-with-voiceintegrity/voice-integrity-onboarding) |\n| **Branded Calling (US)** | Verified name + logo on mobile caller ID | Public Beta (T-Mobile, Verizon) | [Overview](https://www.twilio.com/docs/voice/branded-calling) \\| [FAQ](https://help.twilio.com/articles/22312096414363-Branded-Calls-FAQ) |\n| **Branded Calling (Non-US)** | Verified caller ID branding for international numbers | Availability varies by country/carrier | [Overview](https://www.twilio.com/docs/voice/branded-calling) |\n| **CNAM** | Business name on outbound caller ID | 48-72hr propagation | [Overview](https://www.twilio.com/docs/voice/brand-your-calls-using-cnam) \\| [Getting started](https://help.twilio.com/articles/360051670533-Getting-Started-with-CNAM-Caller-ID) |\n\n**Voice trust priority:** STIR/SHAKEN first (required for Level A attestation) → Voice Integrity (spam label remediation) → Branded Calling (mobile only, beta) → CNAM (simplest, lowest impact). All voice programs require an approved Trust Hub Business Profile as prerequisite.\n\n---\n\n## A2P 10DLC — Deep Dive\n\nA2P 10DLC is the most common program and the most common source of onboarding delays.\n\n### Registration Flow\n\n1. **Create Customer Profile** — Business identity in Trust Hub (required for all programs)\n2. **Register Brand** — EIN, business name, address, website. TCR typically approves within minutes. Respond to OTP verification within 24 hours. [Brand best practices](https://help.twilio.com/articles/4405758341659-A2P-10DLC-Brand-Approval-Best-Practices)\n3. **Register Campaign** — Use case, 2+ sample messages, opt-in proof, privacy policy. Review takes 10-15 business days. [Campaign best practices](https://help.twilio.com/articles/11847054539547-A2P-10DLC-Campaign-Approval-Best-Practices)\n4. **Associate phone numbers** — Link numbers to campaign via Messaging Service\n\n### Message Flow (Opt-In Documentation)\n\nThe message flow field is the #1 reason campaigns get rejected. Reviewers click your links and follow your opt-in steps. If submitting via API, the field must be 40–2049 characters.\n\n**4 required elements:**\n1. Description of opt-in method(s) with clear language inviting users to sign up (no pre-checked boxes)\n2. Message frequency (e.g., \"Up to 4 msgs/month\")\n3. \"Message and data rates may apply\" disclosure\n4. Link(s) to opt-in image/mockup (must be publicly accessible)\n\n**Example of a strong message flow:**\n> \"Customers opt in by texting JOIN to 55555, or by checking the SMS opt-in box during checkout at shop.acme.com. The checkout page displays: 'Check this box to receive exclusive deals via text. Up to 4 msgs/month. Message and data rates may apply. Reply STOP to opt out. Reply HELP for help. Privacy Policy: acme.com/privacy. Terms: acme.com/tc.' In-store signage also promotes keyword opt-in with full disclosures. Screenshot of signage: [Google Drive link]\"\n\n**How to document opt-in by scenario:**\n| Scenario | What to provide |\n|----------|----------------|\n| Public website form | URL to your sign-up page |\n| Form behind login/paywall | Screenshot uploaded to Google Drive/OneDrive (set to \"anyone with link\"), include public link |\n| Verbal/phone opt-in | Full script of what you say and how customer confirms consent |\n| Paper form | Scan/photograph the form, upload publicly, include link |\n| Text keyword campaign | Screenshot of marketing materials showing keyword, upload publicly |\n\n**All links must be publicly accessible.** Non-English disclosures need a translated version included.\n\n### Consent Requirements\n\nThree tiers of consent (CTIA guidelines):\n\n| Tier | Required for | How to obtain |\n|------|-------------|---------------|\n| **Implied consent** | Transactional messages (order confirmations, account alerts) | Customer provides phone number during a transaction |\n| **Express consent** | Informational messages (appointment reminders, service updates) | Customer actively opts in (checkbox, keyword, form) |\n| **Express written consent** | Marketing/promotional messages | Signed consent with brand name, message frequency, \"Msg & data rates apply,\" opt-out instructions |\n\n**Critical rules:**\n- Consent is per-campaign. Signing up for order updates does NOT grant consent for promotions. Separate opt-ins required.\n- Consent must be voluntary. If customers must opt in to messaging to complete a purchase or create an account, the registration **will be rejected**.\n- Brand name must appear in the consent disclosure — generic \"you agree to receive texts\" is insufficient.\n\n### Privacy Policy & Terms and Conditions\n\nBoth are required. Registrations without them are rejected.\n\n**Privacy policy must include:**\n- What data you collect and how it's used\n- That mobile information will NOT be shared with third parties for marketing (CTIA requirement)\n\n**Terms and conditions must include:**\n- Program/brand name and description\n- \"Message and data rates may apply\"\n- Message frequency or recurring message disclosure\n- Customer support contact information\n- **HELP and STOP opt-out instructions (displayed in bold)**\n- Link to privacy policy\n- \"Carriers are not liable for any delayed or undelivered messages\"\n\n**Pro tip:** Create messaging-specific privacy policies and terms rather than updating your main company documents. Dedicated policies are easier to keep current if requirements change.\n\n### Mixed Use Case Campaigns\n\nIf you send both marketing and transactional messages (e.g., order confirmations AND promotions), use the **Mixed** campaign use case:\n\n- Select \"Mixed\" as the campaign use case during registration\n- Allows 2-5 sub-use cases within one campaign (e.g., Customer Care, Marketing, Account Notification, 2FA, PSA)\n- Describe each sub-use case clearly in the campaign description\n- Sample messages must cover each declared sub-use case\n\n**Do NOT register separate campaigns** for each message type unless they use different phone numbers or have different opt-in flows. Mixed is the intended solution for multi-purpose messaging from the same sender.\n\n### Campaign Rejection Gotchas\n\n| Field | Common mistake | Correct approach |\n|-------|---------------|-----------------|\n| Campaign description | Vague (\"We send texts\") | Specific (\"Order confirmation and shipping updates for e-commerce purchases\") |\n| Sample messages | Don't match description or missing opt-out | Must reflect declared use case + include opt-out in every sample |\n| Opt-in description | \"Users sign up on our website\" | \"Users check SMS consent checkbox during account registration at checkout.example.com\" with link to screenshot |\n| URL shorteners | Using bit.ly links | Public URL shorteners are forbidden — use branded/vanity domains |\n| Privacy policy | States data IS shared | Must state data is NOT shared with third parties |\n| Links | Behind login or not accessible | All links must be publicly accessible to reviewers |\n| Consent | Single opt-in covering all message types | Each sub-use case in a Mixed campaign still needs its own documented opt-in method |\n| Mixed campaign | Leaving sub-use cases undescribed | Each sub-use case must be explained in description |\n\nFailed campaigns can now be edited directly in Console (API editing is private beta).\n\n### Registration Tiers\n\n| Tier | Daily segment limit (T-Mobile) | Notes |\n|------|-------------------------------|-------|\n| Sole Proprietor | ~1,000/day | Console only, 1 campaign, 1 number |\n| Low-Volume Standard | ~2,000/day | Requires EIN |\n| Standard | 2,000+ (scales with Trust Score) | Requires verified EIN |\n| High-volume (secondary vetting) | 200,000+/day | [Secondary vetting](https://help.twilio.com/articles/4403988619163-Secondary-Vetting-for-A2P-10DLC) |\n\nRussell 3000 companies qualify for 200,000 segments/day automatically.\n\n### Common Errors\n\n| Error | Meaning | Fix |\n|-------|---------|-----|\n| `30034` | Message from unregistered number | Complete A2P registration |\n| `30007` | Message filtered as spam | Check opt-in compliance and content |\n| Brand rejected | Business info doesn't match EIN records | Tax ID and business name must match exactly |\n\n---\n\n## Toll-Free Verification\n\nRequired for US/Canada toll-free SMS. Simpler than A2P 10DLC.\n\n- Submit via Console (Active Numbers → Regulatory Information tab) or [API](https://www.twilio.com/docs/messaging/compliance/toll-free/api-onboarding)\n- Requires: paid account, Customer Profile, business name, website, use case description, sample message, opt-in type\n- **Unverified toll-free numbers cannot send SMS to US/Canada** — status shows \"Restricted\"\n- If rejected: resubmit within 7 days for priority review. After 7 days, number reverts to Restricted and resubmission goes to back of queue\n- ISVs must have an approved Primary Business Profile before submitting for secondary customers\n- 527 political organizations require Campaign Verify tokens before Console submission\n- Don't use multiple toll-free numbers for the same use case (\"snowshoeing\")\n\n**Docs:** [Console onboarding](https://www.twilio.com/docs/messaging/compliance/toll-free/console-onboarding) | [Why rejected?](https://help.twilio.com/articles/9321443984155-Why-Was-My-Toll-Free-Verification-Rejected-)\n\n---\n\n## WhatsApp WABA Registration\n\n### Self-Signup Flow (Direct Customers)\n\n1. Console → Messaging → Senders → WhatsApp Senders → \"Create new sender\"\n2. Select phone number (Twilio or non-Twilio — must not already be registered with WhatsApp)\n3. Click \"Continue with Facebook\" → Meta Embedded Signup popup\n4. Create or select Meta Business Portfolio\n5. Create or select WABA (all senders on same Twilio account must share one WABA)\n6. Set display name, category, description — Meta reviews display name post-registration\n7. Phone verification via OTP (SMS or voice)\n8. Registration completes within minutes\n\n### Post-Registration Requirements\n\n- **Meta Business Verification required** before production messaging — can take several weeks\n- If display name rejected by Meta, messaging is limited to 250 messages/24 hours\n- Outbound messages require pre-approved **Message Templates** (submitted to Meta, 24-48hr approval)\n- Free-form messages only within 24-hour service window after customer initiates\n\n### ISV Path\n\nEnroll in Meta's **Tech Provider Program** to onboard customers. Different flow from self-signup.\n\n**Docs:** [Self sign-up](https://www.twilio.com/docs/whatsapp/self-sign-up) | [WhatsApp hub](https://www.twilio.com/docs/whatsapp)\n\n---\n\n## RCS Onboarding\n\n4-6 weeks minimum. RCS has a detailed 7-part compliance process covering sender profile, privacy/ToS, eligibility, campaign details, opt-in/consent, sample messages, and common rejection reasons.\n\n**See `twilio-rcs-messaging` for the full onboarding guide, sending patterns, and device support.**\n\nQuick summary: Create RCS Sender in Console → complete compliance submission → Twilio specialist reviews → Google + carrier approval → add to Messaging Service → go live.\n\n**Docs:** [RCS onboarding](https://www.twilio.com/docs/rcs/onboarding) | [Compliance guide](https://help.twilio.com/articles/49174994355355-RCS-Compliance-Onboarding-Guide) | [Regional availability](https://www.twilio.com/docs/rcs/regional)\n\n---\n\n## CANNOT\n\n- **Cannot skip A2P registration for US 10DLC** — Mandatory for all senders, no exceptions for small volume\n- **Cannot register Sole Proprietor A2P via API** — Console only\n- **Cannot combine unrelated use cases without Mixed campaign** — Use the \"Mixed\" use case category to register 2-5 sub-use cases under one campaign\n- **Cannot require A2P registration for Verify traffic** — Twilio Verify is exempt from A2P registration\n- **Cannot use voice trust programs without Trust Hub** — All voice programs require an approved Trust Hub Primary Customer Profile\n- **Cannot use Branded Calling on landlines** — Mobile-only. US: Public Beta (T-Mobile, Verizon). Non-US: availability varies by country and carrier — check eligibility for your specific numbers. Use CNAM for landlines.\n\n---\n\n## Next Steps\n\n- **Channel overview and onboarding guide:** `twilio-messaging-overview`\n- **Choose the right number type first:** `twilio-numbers-senders`\n- **Follow traffic rules after registration:** `twilio-compliance-traffic`\n- **Set up Messaging Services for number pools:** `twilio-messaging-services`\n- **Send SMS after registration:** `twilio-sms-send-message`\n- **Secure your account:** `twilio-security-hardening`\n"
}

SHA-256: e10aed5deb359e20a279ccae2ea5d56a5676d72df490fa601411759105c6a5b3