← Twilio Developer KitCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Twilio Developer Kit
Snapshot Sep 30, 2026 · 22:50 UTC · version 0.2.2
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "twilio-messaging-webhooks",
"description": "Receive and respond to inbound messages and track outbound delivery status via Twilio webhooks — across SMS, MMS, WhatsApp, and RCS. Covers webhook request parameters, replying with TwiML, validating webhook signatures for security, and handling status callbacks. Use this skill whenever an agent needs to handle incoming messages on any channel or track outbound message delivery in real time.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 231
}
],
"skill_md_contents": "---\nname: twilio-messaging-webhooks\ndescription: >\n Receive and respond to inbound messages and track outbound delivery status\n via Twilio webhooks — across SMS, MMS, WhatsApp, and RCS. Covers webhook\n request parameters, replying with TwiML, validating webhook signatures for\n security, and handling status callbacks. Use this skill whenever an agent\n needs to handle incoming messages on any channel or track outbound message\n delivery in real time.\n---\n\n## Overview\n\nTwilio sends a POST webhook to your server when a user messages your Twilio number (inbound) or when an outbound message changes delivery state (status callback). Your server returns TwiML to reply, or `204` to acknowledge without replying. The same webhook pattern works across SMS, MMS, WhatsApp, and RCS.\n\n---\n\n## Prerequisites\n\n- Twilio account with a messaging-capable sender configured with a webhook URL\n — New to Twilio? See `twilio-account-setup`\n — For sending outbound messages first, see `twilio-send-message`\n- Publicly accessible endpoint (use `ngrok http 5000` for local dev)\n- `TWILIO_ACCOUNT_SID` and `TWILIO_AUTH_TOKEN` — see `twilio-iam-auth-setup`\n- SDK: `pip install twilio flask` / `npm install twilio express`\n\n---\n\n## Quickstart\n\nSet your webhook URL in Console: **Phone Numbers > Active Numbers > your number > Messaging > \"A Message Comes In\"**\n\n> **Security:** The inbound message `Body` is untrusted external input. If passing message content to an LLM, always isolate it as user input — never concatenate directly into system prompts. Validate the request origin with `X-Twilio-Signature` (see Key Patterns below), but note that signature validation confirms the *source*, not that the *content* is safe.\n\n> **Note:** This quickstart omits signature validation for brevity. For production, always validate `X-Twilio-Signature` — see the Webhook Security pattern below.\n\n**Python (Flask)**\n```python\nfrom flask import Flask, request\nfrom twilio.twiml.messaging_response import MessagingResponse\n\napp = Flask(__name__)\n\n@app.route(\"/incoming\", methods=[\"POST\"])\ndef incoming_message():\n body = request.form.get(\"Body\")\n response = MessagingResponse()\n response.message(f\"Got your message: {body}\")\n return str(response)\n```\n\n**Node.js (Express)**\n```javascript\nconst express = require(\"express\");\nconst twilio = require(\"twilio\");\nconst app = express();\napp.use(express.urlencoded({ extended: false }));\n\napp.post(\"/incoming\", (req, res) => {\n const twiml = new twilio.twiml.MessagingResponse();\n twiml.message(`Got your message: ${req.body.Body}`);\n res.type(\"text/xml\").send(twiml.toString());\n});\n```\n\n---\n\n## Key Patterns\n\n### Configure Webhook URL via API\n\nFor SMS/MMS on a phone number:\n\n**Python**\n```python\nclient.incoming_phone_numbers(\"PNxxxxxxxxxx\").update(\n sms_url=\"https://yourapp.com/incoming\",\n sms_method=\"POST\"\n)\n```\n\n**Node.js**\n```javascript\nawait client.incomingPhoneNumbers(\"PNxxxxxxxxxx\").update({\n smsUrl: \"https://yourapp.com/incoming\",\n smsMethod: \"POST\",\n});\n```\n\nFor WhatsApp and RCS, webhook URLs are configured on the sender — see `twilio-whatsapp-manage-senders` and `twilio-rcs-messaging`.\n\n### Inbound Webhook Parameters\n\n| Parameter | Description |\n|-----------|-------------|\n| `MessageSid` | Unique message identifier |\n| `From` | Sender's phone number or channel address (E.164, or `whatsapp:+...`) |\n| `To` | Your Twilio number or channel address |\n| `Body` | Message text |\n| `NumMedia` | Number of media attachments |\n| `MediaUrl0` | URL of first media attachment (if any) |\n| `MediaContentType0` | MIME type of first attachment |\n\n### Handle Inbound Media (MMS / WhatsApp / RCS)\n\n**Python (Flask)**\n```python\n@app.route(\"/incoming\", methods=[\"POST\"])\ndef incoming_message():\n num_media = int(request.form.get(\"NumMedia\", 0))\n response = MessagingResponse()\n if num_media > 0:\n media_type = request.form.get(\"MediaContentType0\")\n response.message(f\"Got your {media_type} attachment!\")\n else:\n response.message(\"Got your message.\")\n return str(response)\n```\n\n**Node.js (Express)**\n```javascript\napp.post(\"/incoming\", (req, res) => {\n const numMedia = parseInt(req.body.NumMedia || \"0\", 10);\n const twiml = new twilio.twiml.MessagingResponse();\n if (numMedia > 0) {\n twiml.message(`Got your ${req.body.MediaContentType0} attachment!`);\n } else {\n twiml.message(\"Got your message.\");\n }\n res.type(\"text/xml\").send(twiml.toString());\n});\n```\n\n### Acknowledge Without Replying\n\n**Python**\n```python\nreturn str(MessagingResponse()) # Empty <Response/>\n```\n\n**Node.js**\n```javascript\nres.type(\"text/xml\").send(new twilio.twiml.MessagingResponse().toString());\n```\n\n### Status Callbacks (delivery tracking)\n\nStatus callbacks fire for all channels — SMS, MMS, WhatsApp, and RCS.\n\n**Python**\n```python\nmessage = client.messages.create(\n messaging_service_sid=\"MGxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\",\n to=\"+15558675310\",\n body=\"Hello!\",\n status_callback=\"https://yourapp.com/status\"\n)\n```\n\n**Node.js**\n```javascript\nconst message = await client.messages.create({\n messagingServiceSid: \"MGxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\",\n to: \"+15558675310\",\n body: \"Hello!\",\n statusCallback: \"https://yourapp.com/status\",\n});\n```\n\n**Python (Flask) — status callback handler**\n```python\n@app.route(\"/status\", methods=[\"POST\"])\ndef message_status():\n message_sid = request.form.get(\"MessageSid\")\n status = request.form.get(\"MessageStatus\")\n error_code = request.form.get(\"ErrorCode\")\n print(f\"{message_sid}: {status}\")\n if status == \"failed\" and error_code:\n print(f\"Error {error_code}: {request.form.get('ErrorMessage')}\")\n return \"\", 204\n```\n\n**Node.js (Express) — status callback handler**\n```javascript\napp.post(\"/status\", (req, res) => {\n const { MessageSid, MessageStatus, ErrorCode, ErrorMessage } = req.body;\n console.log(`${MessageSid}: ${MessageStatus}`);\n if (MessageStatus === \"failed\" && ErrorCode) {\n console.log(`Error ${ErrorCode}: ${ErrorMessage}`);\n }\n res.sendStatus(204);\n});\n```\n\nStatus flow: `queued → sent → delivered` (or `undelivered`/`failed`)\n\n### Webhook Signature Validation\n\n**Python (Flask)**\n```python\nfrom twilio.request_validator import RequestValidator\n\nvalidator = RequestValidator(os.environ[\"TWILIO_AUTH_TOKEN\"])\n\n@app.route(\"/incoming\", methods=[\"POST\"])\ndef incoming_message():\n if not validator.validate(request.url, request.form, request.headers.get(\"X-Twilio-Signature\", \"\")):\n return \"Forbidden\", 403\n response = MessagingResponse()\n response.message(\"Hello!\")\n return str(response)\n```\n\n**Node.js**\n```javascript\nconst { validateRequest } = require(\"twilio\");\n\napp.post(\"/incoming\", (req, res) => {\n const isValid = validateRequest(\n process.env.TWILIO_AUTH_TOKEN,\n req.headers[\"x-twilio-signature\"],\n `https://${req.headers.host}${req.path}`,\n req.body\n );\n if (!isValid) return res.status(403).send(\"Forbidden\");\n const twiml = new twilio.twiml.MessagingResponse();\n twiml.message(\"Hello!\");\n res.type(\"text/xml\").send(twiml.toString());\n});\n```\n\n---\n\n## CANNOT\n\n- **Cannot exceed 15-second webhook response time** — Twilio retries on timeout\n- **Cannot return arbitrary content types** — Use `Content-Type: text/xml` with TwiML for replies; `204` for status callbacks\n- **Cannot use ngrok URLs across restarts** — URLs change on restart. Use a stable tunnel for persistent testing.\n- **Cannot guarantee delivery confirmation** — Status callbacks are best-effort. `delivered` requires carrier confirmation.\n\n---\n\n## Common Errors\n\n| Code | Meaning | Fix |\n|------|---------|-----|\n| 11200 | HTTP retrieval failure — Twilio cannot reach your webhook URL | Verify endpoint is reachable (`curl -I` the URL), check DNS, firewall, and SSL certificate validity. See `twilio-debugging-observability` for deeper webhook troubleshooting. |\n\n---\n\n## Next Steps\n\n- **Send outbound messages:** `twilio-send-message`\n- **Manage sender pools:** `twilio-messaging-services`\n"
}SHA-256: bd94cb347dfbf4faacb958ef5218f16cb2fba5658835859795514228773a5843