Connector · SMS, WhatsApp and verification

Twilio, behind your codes and alerts.

How our notifications module sends SMS and WhatsApp through Twilio, and how our authentication module uses Twilio Verify for one-time codes: what your customers receive, what your team sees, and how we get you live.

Website
twilio.com
Modules
Notifications, Authentication
Contract
We help you get it

Who Twilio is

Twilio is a cloud communications company, founded in 2008 to make the global telephone network simple to use from software. Its APIs cover SMS, WhatsApp, voice and, through SendGrid, email, along with Verify, a service that sends and checks one-time codes.

Developers use it to add messaging and verification to their products without dealing with carriers one by one. That is why it is one of the providers our notifications and authentication modules connect to.

What it does in your platform

  • Notifications

    Sends the platform's SMS and WhatsApp messages: payment and security alerts, delivery updates and, for customers who opted in, campaigns. Every status change, from sent to delivered or failed, comes back to the module, and a critical message that fails goes out again on another channel or provider.

  • Authentication

    Twilio Verify sends and checks the one-time codes the module uses as a second factor, and as the fallback on devices that do not support passkeys, by SMS, WhatsApp, voice or email. For payments, Verify offers a PSD2 mode that ties each code to the amount and the payee.

How the connection works

Two connectors talk to Twilio's REST APIs: Programmable Messaging in the notifications module and Verify in the authentication module. Your apps never hold Twilio's credentials, and every callback Twilio sends is signed.

  1. A customer confirms a payment

    The authentication module asks Twilio Verify to send a one-time code to the customer's phone, by SMS or WhatsApp.

  2. Verify sends the code

    Twilio generates and stores the code and delivers it, while Fraud Guard blocks suspicious SMS traffic, such as SMS pumping, before anything is sent.

  3. The code is checked

    The customer types it in your app, and the module checks it with Verify before the payment goes ahead.

  4. The payment alert goes out

    The notifications module sends the alert by SMS or WhatsApp through Twilio's messaging API, from your sender.

  5. Twilio reports the status

    Twilio calls the platform back at every status change, from sent to delivered or failed, and signs each callback with an X-Twilio-Signature header.

  6. A fallback for what matters

    If the alert fails, the module sends it again through another channel or provider within seconds.

Next to other providers

In the notifications module, each channel runs on the provider you prefer, with a second one standing by for critical messages: Twilio can carry your SMS and WhatsApp with Vonage, Infobip or Bird as the backup, or the other way round.

In the authentication module, Verify sits next to passkeys and authenticator apps as one of the second factors your customers can use. Templates, preferences and sign-in rules belong to the platform, so moving away from Twilio later does not change your apps.

When Twilio fits best

A strong fit when

  • You want messaging and one-time codes from one provider, under one account.
  • You confirm payments under PSD2 and want each code tied to the amount and the payee.
  • You want SMS for EU customers processed and stored in the EU, through Twilio's Ireland region.

Also worth a look

  • Another SMS provider, such as Vonage, Infobip or Bird, as the backup for critical messages.
  • Passkeys, which can replace one-time codes on the devices that support them.

How we get you live

  • The contract

    We help you get your Twilio account and contract in place, for messaging, for Verify, or both.

  • Senders and services

    We register your senders and your WhatsApp sender with you, set up a Messaging Service, and create the Verify service with the channels you need, in PSD2 mode where you confirm payments.

  • The keys

    Twilio's API keys and auth token stay in your platform's secrets, and a callback without a valid signature is rejected.

  • A full test run

    Messaging runs first with Twilio's test credentials and the Twilio Sandbox for WhatsApp, then codes and alerts go to your team's own phones before your first customer.

Questions

Asked about this connector.

How do we get started with Twilio?

Talk to us. We help you get the Twilio account and contract in place, register your senders, set up messaging and Verify and connect them to your platform, then test codes and alerts on your team's phones before launch.

Can SMS data stay in the EU?

Yes, with Twilio's Ireland region: message bodies and phone numbers are processed and stored in the EU up to the point they reach the carriers. Carriers themselves may process data elsewhere.

Which channels can Verify use?

SMS, WhatsApp, voice and email, among others. A one-time code that does not arrive falls back to another provider or channel within seconds.

What does Twilio do against SMS fraud?

Verify's Fraud Guard is on by default: it watches SMS traffic for unusual patterns such as SMS pumping, and blocks suspicious destinations before codes are sent.

Start your project

Tell us the idea. We'll show you the platform.

One call is enough to map your product to the modules that already exist.

  • Response in under one business day
  • NDA on request
  • No obligation
What are you building?