Who Twilio is
Twilio is a cloud communications company, founded in 2008 to make the global telephone network simple to use from software. Its APIs cover SMS, WhatsApp, voice and, through SendGrid, email, along with Verify, a service that sends and checks one-time codes.
Developers use it to add messaging and verification to their products without dealing with carriers one by one. That is why it is one of the providers our notifications and authentication modules connect to.
What it does in your platform
Notifications
Sends the platform's SMS and WhatsApp messages: payment and security alerts, delivery updates and, for customers who opted in, campaigns. Every status change, from sent to delivered or failed, comes back to the module, and a critical message that fails goes out again on another channel or provider.
Authentication
Twilio Verify sends and checks the one-time codes the module uses as a second factor, and as the fallback on devices that do not support passkeys, by SMS, WhatsApp, voice or email. For payments, Verify offers a PSD2 mode that ties each code to the amount and the payee.
How the connection works
Two connectors talk to Twilio's REST APIs: Programmable Messaging in the notifications module and Verify in the authentication module. Your apps never hold Twilio's credentials, and every callback Twilio sends is signed.
A customer confirms a payment
The authentication module asks Twilio Verify to send a one-time code to the customer's phone, by SMS or WhatsApp.
Verify sends the code
Twilio generates and stores the code and delivers it, while Fraud Guard blocks suspicious SMS traffic, such as SMS pumping, before anything is sent.
The code is checked
The customer types it in your app, and the module checks it with Verify before the payment goes ahead.
The payment alert goes out
The notifications module sends the alert by SMS or WhatsApp through Twilio's messaging API, from your sender.
Twilio reports the status
Twilio calls the platform back at every status change, from sent to delivered or failed, and signs each callback with an X-Twilio-Signature header.
A fallback for what matters
If the alert fails, the module sends it again through another channel or provider within seconds.
Next to other providers
In the notifications module, each channel runs on the provider you prefer, with a second one standing by for critical messages: Twilio can carry your SMS and WhatsApp with Vonage, Infobip or Bird as the backup, or the other way round.
In the authentication module, Verify sits next to passkeys and authenticator apps as one of the second factors your customers can use. Templates, preferences and sign-in rules belong to the platform, so moving away from Twilio later does not change your apps.
When Twilio fits best
A strong fit when
- You want messaging and one-time codes from one provider, under one account.
- You confirm payments under PSD2 and want each code tied to the amount and the payee.
- You want SMS for EU customers processed and stored in the EU, through Twilio's Ireland region.
Also worth a look
- Another SMS provider, such as Vonage, Infobip or Bird, as the backup for critical messages.
- Passkeys, which can replace one-time codes on the devices that support them.
How we get you live
The contract
We help you get your Twilio account and contract in place, for messaging, for Verify, or both.
Senders and services
We register your senders and your WhatsApp sender with you, set up a Messaging Service, and create the Verify service with the channels you need, in PSD2 mode where you confirm payments.
The keys
Twilio's API keys and auth token stay in your platform's secrets, and a callback without a valid signature is rejected.
A full test run
Messaging runs first with Twilio's test credentials and the Twilio Sandbox for WhatsApp, then codes and alerts go to your team's own phones before your first customer.
