twilio-account-setup
Create and configure a Twilio account from scratch. Covers free trial signup, trial limitations, getting credentials (Account SID and Auth Token), buying a phone number, verifying recipient numbers for trial use, SDK installation, first API call, subaccount management (creation, inheritance, credent
- 0
- Installs
- —
- Rating
- —
- Success rate
- 2
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 928eb452eb4629a9… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Overview
Every Twilio skill requires an active Twilio account and credentials. This skill covers the one-time setup steps that are prerequisites for all other Twilio skills.
Quickstart
- Sign up at twilio.com/try-twilio -- enter name, email, password
- Verify your email and personal phone number
- Get your credentials from Console > Account > API keys & tokens:
export TWILIO_ACCOUNT_SID=ACxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
export TWILIO_AUTH_TOKEN=your_auth_token
-
Buy a phone number at Console > Phone Numbers > Buy a number
-
Install the SDK and send your first message:
Python
pip install twilio
import os
from twilio.rest import Client
client = Client(os.environ["TWILIO_ACCOUNT_SID"], os.environ["TWILIO_AUTH_TOKEN"])
message = client.messages.create(
to="+15558675310", # must be verified on trial accounts
from_="+15017122661", # your Twilio number
body="Hello from Twilio!"
)
print(f"Sent: {message.sid}")
Node.js
npm install twilio
const twilio = require("twilio");
const client = twilio(process.env.TWILIO_ACCOUNT_SID, process.env.TWILIO_AUTH_TOKEN);
const message = await client.messages.create({
to: "+15558675310", // must be verified on trial accounts
from: "+15017122661", // your Twilio number
body: "Hello from Twilio!",
});
console.log(`Sent: ${message.sid}`);
You're ready to use any Twilio skill. Trial accounts have restrictions -- see Constraints below.
Key Patterns
Verify Recipient Numbers (trial accounts only)
Trial accounts can only send to verified phone numbers (up to 5 per account).
- Go to Console > Phone Numbers > Verified Caller IDs
- Click Add a new Caller ID and verify via SMS code
Verified numbers work across both messaging and voice. Remove this restriction by upgrading your account.
Enable Specific Products
Some products require explicit activation:
| Product | How to enable |
|---|---|
| AI Assistants | Console > Explore Products > AI Assistants > Get started |
| Conversations | Console > Conversations > Manage > Overview > Enable Conversations |
| Verify | Console > Verify > Services > Create new |
| WhatsApp (sandbox) | Console > Messaging > Try it out > Send a WhatsApp message |
| ConversationRelay | Console > Voice > ConversationRelay > complete onboarding form |
SDK Installation
| Language | Install | SDK package |
|---|---|---|
| Python | pip install twilio | twilio |
| Node.js | npm install twilio | twilio |
| Java | Maven/Gradle | com.twilio.sdk:twilio |
| C# | dotnet add package Twilio | Twilio |
| Ruby | gem install twilio-ruby | twilio-ruby |
| PHP | composer require twilio/sdk | twilio/sdk |
| Go | go get github.com/twilio/twilio-go | twilio-go |
Initialize the Client
Always load credentials from environment variables -- never hardcode them.
Python
import os
from twilio.rest import Client
client = Client(os.environ["TWILIO_ACCOUNT_SID"], os.environ["TWILIO_AUTH_TOKEN"])
Node.js
const twilio = require("twilio");
const client = twilio(process.env.TWILIO_ACCOUNT_SID, process.env.TWILIO_AUTH_TOKEN);
For production, use API Keys instead of Auth Token. See twilio-iam-auth-setup.
Twilio CLI Setup
The CLI is useful for quick operations and local webhook testing.
# Install (macOS)
brew tap twilio/brew && brew install twilio
# Install (npm -- all platforms)
npm install -g twilio-cli
# Login (creates an API key automatically)
twilio login
# Verify setup
twilio phone-numbers:list
The CLI stores profiles for switching between accounts:
# List profiles
twilio profiles:list
# Switch active profile
twilio profiles:use my-project
# Use environment variables instead of profiles
export TWILIO_ACCOUNT_SID=ACxxxxxxxx
export TWILIO_AUTH_TOKEN=xxxxxxxx
Precedence: --profile flag > environment variables > active profile.
Accounts and Subaccounts
Creating a new Twilio account: Accounts can only be created from the Console UI — there is no API for creating top-level accounts. A new account is automatically created when a user signs up. Additional accounts can be created from Console > My Accounts (or "View all accounts").
To see all your accounts: Console > My Accounts shows all accounts and subaccounts you have access to. For Organization-wide visibility, see Console > Admin > Accounts (requires Organization admin role). See twilio-organizations-setup for Organization-level governance.
Subaccounts
Subaccounts are child accounts under your main (parent) account. Use them for multi-tenant apps, per-customer isolation, or team separation.
How they differ from the parent account:
- Resources (numbers, calls, messages) are isolated — a subaccount cannot see the parent's resources or other subaccounts' resources
- Billing is consolidated to the parent — a single Twilio balance for all subaccounts
- Voice and SMS permissions inherit from the parent
- Phone numbers can be transferred between parent and subaccounts
Create via Console: Console > My Accounts > Create Subaccount
Create via API:
Python
subaccount = client.api.accounts.create(friendly_name="Customer A")
print(f"Subaccount SID: {subaccount.sid}")
# Store securely — auth_token is only shown at creation time
# e.g., secrets_manager.store("subaccount_auth_token", subaccount.auth_token)
Node.js
const subaccount = await client.api.accounts.create({ friendlyName: "Customer A" });
console.log(`Subaccount SID: ${subaccount.sid}`);
Subaccount Credential Isolation
Always use the subaccount's own credentials (API Keys or Auth Token) when accessing subaccount resources — do NOT use the parent account's credentials as a shortcut.
Python — access subaccount resources
# Correct: use subaccount credentials
sub_client = Client(subaccount.sid, subaccount.auth_token)
call = sub_client.calls.create(
to="+15558675310",
from_="+15017122661", # number owned by this subaccount
url="https://yourapp.com/voice"
)
# Also correct: parent credentials with subaccount SID (v2010 API only)
parent_client = Client(os.environ["TWILIO_ACCOUNT_SID"], os.environ["TWILIO_AUTH_TOKEN"])
calls = parent_client.api.accounts(subaccount.sid).calls.list()
Critical: Resources on separate subdomains (studio.twilio.com, taskrouter.twilio.com) require subaccount-specific credentials. Parent account credentials will not work on these subdomains.
Subaccount Limits
- Default limit: 1,000 subaccounts per parent account
- Trial accounts: Can create only 1 subaccount — upgrade to create more
- At the limit: Contact Twilio Support with your use case to request an increase
- Closing: Set status to
closedvia API or Console. Closed subaccounts are automatically deleted after 30 days - Suspension cascade: Suspending the parent account automatically suspends ALL subaccounts
Upgrade from Trial
- Click Upgrade at the top of the Console, or go to Console > Admin > Account billing
- Provide name, address, and payment details
- Your trial phone number carries over; trial balance does not
Trial Restrictions at a Glance
| Feature | Trial | Upgraded |
|---|---|---|
| Phone numbers | 1 | Unlimited |
| Send to unverified numbers | No | Yes |
| Outbound message prefix | Yes (visible to recipient) | No |
| Verified caller IDs | Up to 5 | Not needed |
| A2P 10DLC registration | No | Yes |
| Daily WhatsApp messages | 50 | Unlimited |
| ConversationRelay | No | Yes (after onboarding) |
| Voice: outbound calls | Domestic only | International |
CANNOT
- Cannot create top-level accounts via API — Only Console UI. A new account is created at signup; additional accounts from Console > My Accounts.
- Cannot create more than 1 subaccount on trial — Upgrade your account first, then you can create up to 1,000.
- Cannot access subdomain resources with parent credentials — Studio, TaskRouter, and other subdomain APIs require subaccount-specific credentials. Parent credentials return auth errors.
- Cannot undo a closed subaccount after 30 days — Closed subaccounts are permanently deleted. Suspension is reversible; closure is not.
- Cannot transfer trial balance to a paid account — Trial credits are forfeited on upgrade.
- Cannot send to unverified numbers on trial — Only verified Caller IDs (up to 5) can receive messages or calls.
- Auth Token rotation invalidates ALL API keys — This is a one-way door. Use API Keys from day one. See
twilio-security-api-auth. - API Key secrets shown only once at creation — Store them immediately. Cannot be retrieved afterward.
- AI Assistants and ConversationRelay require approval — Limited access products. Activation is not instant.
Next Steps
- Organization governance (SSO, SCIM, multi-team):
twilio-organizations-setup - Secure credential management and API Keys:
twilio-security-api-auth - Send your first SMS:
twilio-sms-send-message - Send your first WhatsApp message:
twilio-whatsapp-send-message - Receive incoming messages:
twilio-messaging-webhooks - US SMS compliance (A2P 10DLC):
twilio-compliance-onboarding - Webhook setup:
twilio-webhook-architecture
Files
2- SKILL.md
8d509add5710.6 KB - agents/openai.yaml
504b1ecf90447 B
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from twilio/ai8
Planning skill for augmenting human agents with real-time AI intelligence. Qualifies the developer's use case across coaching, compliance, QA, and routing to recommend the right Conversation Intelligence + Conversation Memory + TaskRouter architecture. Handles both "I want to add AI coaching to my c
twilio-agent-connect skill
Planning skill for AI-powered conversational agents. Qualifies the developer's use case across outcome sophistication, entry point, and customer profile to recommend the right Twilio Conversations architecture and implementation skills. Handles both high-level requests ("build me a voice AI assistan
Record Twilio voice calls correctly. Covers the critical distinction between Record verb (voicemail) and Dial record (call recording), dual-channel for QA, mid-call pause for PCI, Conference recording, and the ConversationRelay workaround. Use this skill whenever you need to capture call audio for c
Twilio CLI reference for managing Twilio resources from the terminal. Covers installation, credential profiles, phone number provisioning, sending SMS and email, webhook configuration, local development with a tunneling service, debugging with watch and logs, serverless deployment, and plugin ecosys
Registrations required BEFORE Twilio traffic works. Covers messaging programs (A2P 10DLC, toll-free verification, WhatsApp WABA, RCS, short code, alphanumeric sender) and voice trust programs (STIR/SHAKEN, Voice Integrity, Branded Calling, CNAM). Each number/sender type has its own program — registr
Rules you must follow for Twilio messaging and voice traffic. Covers TCPA (consent tiers, quiet hours, DNC), GDPR (EU consent, right to deletion), PCI DSS (payment recording, Pay verb), HIPAA (BAA, PHI), FDCPA (debt collection limits), CAN-SPAM, WhatsApp policies, SHAKEN/STIR, and consent management
Build multi-party calls using Twilio Conference. Covers warm transfer, cold transfer, coaching (whisper), hold vs mute, participant modes, and supervisor barge. Use this skill for any contact center, support line, or scenario requiring transfers, holds, or multi-party calls.
Related security skillsscan passed
Manage the experimental Nasiko CLI lifecycle through ECC — read-only status checks, consent-gated install of the pinned qualified version with dry-run preview, and ownership-checked uninstall, under explicit telemetry and secrets boundaries. Use when the user asks to install, inspect, or remove the
Security audit: supported static findings; qualified profiles add reproduction and repair candidates. (gstack)
Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the use
Create a vanilla tRPC client with createTRPCClient<AppRouter>(), configure link chain with httpBatchLink/httpLink, dynamic headers for auth, transformer on links (not client constructor). Infer types with inferRouterInputs and inferRouterOutputs. AbortController signal support. TRPCClientError typin
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data,
Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split. Ranked, each finding explained in plain English. One-shot report, changes nothing. Use for "audit this codebase", "review the whole repo", "find