← Twilio Developer KitCONTENT HISTORY

Update to Twilio Developer Kit

Snapshot Sep 30, 2026 · 22:50 UTC · version 0.2.2

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "twilio-verify-send-otp",
  "description": "Send and verify one-time passcodes (OTPs) via Twilio Verify over SMS, RCS, voice, email, or WhatsApp. Covers creating a Verify Service, sending tokens, checking submitted codes, automatic WhatsApp-to-SMS fallback, and service configuration. TOTP is supported via the Factors API (a separate family from channel-based OTP). Use this skill to add phone or email verification or two-factor authentication to any application.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 225
    }
  ],
  "skill_md_contents": "---\nname: twilio-verify-send-otp\ndescription: >\n  Send and verify one-time passcodes (OTPs) via Twilio Verify over SMS, RCS,\n  voice, email, or WhatsApp. Covers creating a Verify Service, sending tokens,\n  checking submitted codes, automatic WhatsApp-to-SMS fallback, and service\n  configuration. TOTP is supported via the Factors API (a separate family from\n  channel-based OTP). Use this skill to add phone or email verification or\n  two-factor authentication to any application.\n---\n\n## Overview\n\nUse **Twilio Verify** to manage the full OTP lifecycle: code generation, delivery, expiry, rate limiting, and Fraud Guard protection. Use the **Programmable Messaging API** to build your own OTP message infrastructure and access features such as SMS Pumping Protection.\n\n| | Twilio Verify | Programmable Messaging API |\n|---|---|---|\n| Code generation + expiry | Built-in (10min default, configurable). Also supports custom codes. | Build yourself |\n| Rate limiting | Built-in (per-phone, per-service) | Build yourself |\n| Fraud protection | Fraud Guard (geo-permissions, rate anomaly) | SMS Pumping Protection |\n| A2P registration | Exempt — no 10DLC needed | Required — must register campaign |\n| Multi-channel | One API, change `channel` param (SMS/Voice/Email/WhatsApp/RCS) | Separate integration per channel |\n| Cost | [Per confirmed verification + channel fee](https://www.twilio.com/en-us/verify/pricing) | Per-message pricing + build cost |\n| Delivery confirmation | Yes — via List Attempts or Events API | Yes (via StatusCallback) |\n\n**When Programmable Messaging is justified:** You need full control over message content, custom delivery logic, or SMS Pumping Protection features. For standard OTP/2FA flows, use Verify.\n\nVerify supports SMS, voice, email, WhatsApp, and RCS — only the `channel` parameter changes per delivery method. TOTP (authenticator apps) is supported via the Verify Factors API, a separate implementation from channel-based OTP.\n\n---\n\n## Prerequisites\n\n- Twilio account (free trial works for testing)\n  — New to Twilio? See `twilio-account-setup`\n  — Verify requires no separate product activation — just create a Service below\n- Environment variables:\n  - `TWILIO_ACCOUNT_SID`\n  - `TWILIO_AUTH_TOKEN`\n  - `VERIFY_SERVICE_SID` (created in Quickstart step 1)\n  — See `twilio-iam-auth-setup` for credential setup and best practices\n- SDK: `pip install twilio` / `npm install twilio`\n- For WhatsApp channel only: a registered production WhatsApp sender — see `twilio-whatsapp-manage-senders`\n\n---\n\n## Quickstart\n\n**Step 1 — Create a Verify Service (one-time)**\n\n**Python**\n```python\nimport os\nfrom twilio.rest import Client\n\nclient = Client(os.environ[\"TWILIO_ACCOUNT_SID\"], os.environ[\"TWILIO_AUTH_TOKEN\"])\n\nservice = client.verify.v2.services.create(\n    friendly_name=\"My App Verification\"\n)\nprint(service.sid)  # VAxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx — save as VERIFY_SERVICE_SID\n```\n\n**Node.js**\n```node\nconst twilio = require(\"twilio\");\nconst client = twilio(process.env.TWILIO_ACCOUNT_SID, process.env.TWILIO_AUTH_TOKEN);\n\nconst service = await client.verify.v2.services.create({\n    friendlyName: \"My App Verification\",\n});\nconsole.log(service.sid);  // VAxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\n```\n\nStore the Service SID — reuse it for all verifications, do not recreate it each time.\n\n**Step 2 — Send a verification token**\n\n**Python**\n```python\nverification = client.verify.v2 \\\n    .services(os.environ[\"VERIFY_SERVICE_SID\"]) \\\n    .verifications \\\n    .create(to=\"+15558675310\", channel=\"sms\")\n\nprint(verification.status)  # pending\n```\n\n**Node.js**\n```node\nconst verification = await client.verify.v2\n    .services(process.env.VERIFY_SERVICE_SID)\n    .verifications.create({ to: \"+15558675310\", channel: \"sms\" });\n\nconsole.log(verification.status);  // pending\n```\n\n**Step 3 — Check the submitted code**\n\n**Python**\n```python\ncheck = client.verify.v2 \\\n    .services(os.environ[\"VERIFY_SERVICE_SID\"]) \\\n    .verification_checks \\\n    .create(to=\"+15558675310\", code=\"123456\")\n\nif check.status == \"approved\":\n    print(\"Verified!\")\nelse:\n    print(\"Invalid or expired code\")\n```\n\n**Node.js**\n```node\nconst check = await client.verify.v2\n    .services(process.env.VERIFY_SERVICE_SID)\n    .verificationChecks.create({ to: \"+15558675310\", code: \"123456\" });\n\nif (check.status === \"approved\") {\n    console.log(\"Verified!\");\n} else {\n    console.log(\"Invalid or expired code\");\n}\n```\n\n---\n\n## Key Patterns\n\n### Supported Channels\n\n| Channel | `channel` value | Notes |\n|---------|----------------|-------|\n| SMS | `sms` | Default, widest coverage |\n| Voice call | `voice` | Reads code aloud |\n| Email | `email` | Use email address in `to` |\n| WhatsApp | `whatsapp` | Requires own WhatsApp sender (see below) |\n| RCS | `rcs` | Rich messaging, Android devices |\n\n> **TOTP (authenticator apps):** Supported via the Verify Factors API — a separate implementation from channel-based OTP. See [Verify TOTP docs](https://www.twilio.com/docs/verify/quickstarts/totp).\n\n### WhatsApp OTP\n\nChange `channel` to `\"whatsapp\"` — the send/check flow is identical to SMS.\n\n> **Requires:** A registered production WhatsApp sender. As of March 2024, Twilio no longer provides a shared sender for Verify. See `twilio-whatsapp-manage-senders`.\n\n**Python**\n```python\nverification = client.verify.v2 \\\n    .services(os.environ[\"VERIFY_SERVICE_SID\"]) \\\n    .verifications \\\n    .create(to=\"+15558675310\", channel=\"whatsapp\")\n```\n\n**Node.js**\n```node\nconst verification = await client.verify.v2\n    .services(process.env.VERIFY_SERVICE_SID)\n    .verifications.create({ to: \"+15558675310\", channel: \"whatsapp\" });\n```\n\n### WhatsApp with Automatic SMS Fallback\n\n**Python**\n```python\nverification = client.verify.v2 \\\n    .services(os.environ[\"VERIFY_SERVICE_SID\"]) \\\n    .verifications \\\n    .create(\n        to=\"+15558675310\",\n        channel=\"whatsapp\",\n        channel_configuration={\n            \"whatsapp\": {\"enabled\": True},\n            \"sms\": {\"enabled\": True}   # falls back to SMS if WhatsApp undelivered\n        }\n    )\n```\n\n**Node.js**\n```node\nconst verification = await client.verify.v2\n    .services(process.env.VERIFY_SERVICE_SID)\n    .verifications.create({\n        to: \"+15558675310\",\n        channel: \"whatsapp\",\n        channelConfiguration: {\n            whatsapp: { enabled: true },\n            sms: { enabled: true },\n        },\n    });\n```\n\nWith fallback enabled, your UI can say \"a verification code was sent\" without specifying the channel.\n\n### Service Configuration\n\n**Python**\n```python\nservice = client.verify.v2.services.create(\n    friendly_name=\"My App\",\n    code_length=6,              # 4–10 digits (default: 6)\n    lookup_enabled=True,        # Validate number before sending\n    do_force_check_once=True,   # Code can only be checked once\n    ttl=600,                    # Code expiry in seconds (default: 600)\n)\n```\n\n**Node.js**\n```node\nconst service = await client.verify.v2.services.create({\n    friendlyName: \"My App\",\n    codeLength: 6,\n    lookupEnabled: true,\n    doForceCheckOnce: true,\n    ttl: 600,\n});\n```\n\n### Verification Status Values\n\n| Status | Meaning |\n|--------|---------|\n| `approved` | Code is correct |\n| `pending` | Code is wrong or not yet submitted |\n| `expired` | Code has expired (default TTL: 10 minutes) |\n| `canceled` | Verification was canceled |\n\n---\n\n## Debugging\n\n**Primary debugging tool:** Console > Verify > Logs (per-Service). Shows every verification attempt, delivery status, channel used, and error codes. Check here first before writing custom monitoring code.\n\n### Common Errors\n\n| Code | Meaning | Fix |\n|------|---------|-----|\n| 60200 | Invalid parameter | Check `to` format and `channel` value |\n| 60202 | Max send attempts reached | Wait before retrying |\n| 60203 | Max check attempts reached | Issue a new verification |\n| 60212 | Service not found | Verify `VERIFY_SERVICE_SID` is correct |\n| 60410 | Geo-permission not enabled | Enable country in Console |\n\n**Built-in protections (no custom code needed):**\n- Rate limiting: 5 verifications per phone per service per 10 minutes\n- Max check attempts: 5 per verification (6th attempt → error 60203)\n- Phone number validation: Verify checks line type before sending (if `lookup_enabled=True`)\n- Fraud Guard: geo-permissions, rate anomaly detection, SMS pumping protection\n\n**International OTP traffic warning:** International numbers are high-risk for SMS pumping — fraudsters trigger OTPs to premium-rate destinations to generate revenue. Verify's Fraud Guard handles this automatically when enabled. If you're building custom OTP with Programmable Messaging instead, enable SMS Pumping Protection on your Messaging Service (see `twilio-messaging-services`). Always restrict geo-permissions to only countries where you have real users.\n\n---\n\n## CANNOT\n\n- **No built-in channel fallback** — Must implement retry logic manually (e.g., SMS → voice → email). Use `channel_configuration` for WhatsApp→SMS only.\n- **No webhook on verification completion** — Must poll `verification_checks`. Rate-limited: 60/min, 180/hr, 250/day.\n- **Cannot retrieve the actual code sent** — Code is never returned in any API response. By design.\n- **Cannot change channel mid-verification** — Starting on a new channel reuses the same Verification SID and token. Create a new verification instead.\n- **Cannot extend TTL on an existing verification** — Default 10 minutes. Customizable only at Service level, not per-verification.\n- **Verification SID deleted after approval** — Fetching an approved verification returns 404. Canceled verifications remain fetchable.\n- **`auto` channel not universally available** — Returns error 60200 on accounts without Fraud Guard enabled.\n- **Email channel requires Mailer configuration** — `channel: 'email'` without a configured Mailer returns error 60217.\n- **No real-time delivery push notification** — Delivery status is available via List Attempts or Events API (pull-based), not via a push webhook.\n- **FriendlyName rejects 5+ consecutive digits** — Service names containing 5+ digits trigger error 60200. Use words or fewer digits.\n- **Wrong code does not throw an exception** — Check returns `status: \"pending\"`, not an error. You must check `status === \"approved\"` explicitly.\n- **Cannot re-check an approved verification** — Each verification is single-use. Once `approved`, subsequent checks return 404.\n- **Cannot send to arbitrary numbers on trial accounts** — Trial accounts have limited verification destinations\n- **Cannot customize WhatsApp OTP template** — Uses a fixed Meta authentication template\n- **Cannot use WhatsApp channel for PSD2 compliance mode** — PSD2 payee/amount parameters not supported on WhatsApp\n\n---\n\n## Next Steps\n\n- **Register a WhatsApp sender:** `twilio-whatsapp-manage-senders`\n- **Validate phone numbers before sending:** `twilio-lookup-phone-intelligence`\n- **Credential setup:** `twilio-iam-auth-setup`\n"
}

SHA-256: 03c872142518cf1395566868681c1efe1330cf67b353d6fee6997113d70f409c