skills/ twilio/ai

twilio-iam-auth-setup

Set up and manage Twilio authentication credentials: Auth Tokens, API keys (Standard, Main, Restricted), Access Tokens for client-side SDKs, and credential rotation. Use this skill as a prerequisite foundation before making any Twilio API calls.

0
Installs
—
Rating
—
Success rate
2
Files scanned
Scan passedsecurity
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

2 files scannedscanner v1.2.0Oct 10, 2026

Content sha256 e35527c6395598cb… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Overview

Twilio supports multiple authentication methods. For most developers: use Auth Token for local prototyping, then move to API Keys in production.

MethodUse forSecurity
Account SID + Auth TokenLocal prototyping, initial testingFull account access — avoid in production
Account SID + API Key (Standard) + SecretAll production codeRecommended — revocable, no access to /Accounts or /Keys
Account SID + API Key (Restricted) + SecretFine-grained production accessBest — limit to specific resources only
Account SID + API Key (Main) + SecretAccount management automationFull access like Auth Token, but revocable

For beginners / vibe-coders: Start with Auth Token to get your first API call working, then create a Standard API Key before deploying anything. The key difference: if an API Key leaks, you revoke just that key. If your Auth Token leaks, your entire account is exposed until you rotate it.


Prerequisites

  • Twilio account — see twilio-account-setup if you don't have one
  • Access to the Twilio Console

Quickstart

Find your Account SID and Auth Token in the Console dashboard.

Python

import os
from twilio.rest import Client

client = Client(os.environ["TWILIO_ACCOUNT_SID"], os.environ["TWILIO_AUTH_TOKEN"])

Node.js

const client = require("twilio")(
    process.env.TWILIO_ACCOUNT_SID,
    process.env.TWILIO_AUTH_TOKEN
);

Never commit Auth Token to version control or use in production.


Key Patterns

API Keys (production)

Create: Console > Account > API keys & tokens > Create API key

Key typeAccessUse case
StandardAll resources except /Accounts and /Keys endpointsDefault for production apps
RestrictedOnly the specific resources you grantMulti-tenant apps, microservices, least-privilege
MainFull account access (like Auth Token)Account management automation (Console-only creation)

After creation, copy the API Key SID (SK...) and Secret — the secret is shown only once.

Python

client = Client(
    os.environ["TWILIO_API_KEY"],      # SK...
    os.environ["TWILIO_API_SECRET"],
    os.environ["TWILIO_ACCOUNT_SID"]   # required as third argument
)

Node.js

const client = require("twilio")(
    process.env.TWILIO_API_KEY,
    process.env.TWILIO_API_SECRET,
    { accountSid: process.env.TWILIO_ACCOUNT_SID }
);

Restricted API Keys

Restricted keys grant access only to specific Twilio API resources you define. Use them for least-privilege access in production.

Create via the v1 IAM API (not the v2010 /Keys.json endpoint — see CANNOT section):

Python

key = client.iam.v1.api_key.create(
    account_sid=os.environ["TWILIO_ACCOUNT_SID"],
    friendly_name="messaging-only-key",
    key_type="restricted",
    policy={
        "allow": [
            "/2010-04-01/Accounts/{AccountSid}/Messages*"
        ]
    }
)
# Store key.sid and key.secret securely — secret shown only once

Example permission patterns:

PermissionGrants access to
/2010-04-01/Accounts/{AccountSid}/Messages*Send and read messages
/2010-04-01/Accounts/{AccountSid}/Calls*Make and manage calls
/v2/Services/*/Verifications*Verify API only

Docs: Restricted API keys

Test Credentials

Make API calls without charges or sending real messages. Find at Console > Account > API keys & tokens > Test credentials.

Python

client = Client(
    os.environ["TWILIO_TEST_ACCOUNT_SID"],
    os.environ["TWILIO_TEST_AUTH_TOKEN"]
)

Node.js

const client = require("twilio")(
    process.env.TWILIO_TEST_ACCOUNT_SID,
    process.env.TWILIO_TEST_AUTH_TOKEN
);

Magic test numbers:

  • +15005550006 — valid, can receive messages
  • +15005550001 — invalid number (triggers error 21211)
  • +15005550007 — number that cannot receive SMS (triggers error 21612)

Auth Token Rotation

Rotate your Auth Token if it's been exposed or as periodic security hygiene. Twilio uses a secondary token promotion model:

  1. Console > Account > API keys & tokens > Request a secondary Auth Token
  2. Update your application to use the secondary token
  3. Once confirmed working, promote the secondary to primary
  4. The old primary token is immediately invalidated

Python

# Promote secondary Auth Token to primary via API
from twilio.rest import Client

client = Client(os.environ["TWILIO_ACCOUNT_SID"], os.environ["TWILIO_AUTH_TOKEN"])
account = client.api.accounts(os.environ["TWILIO_ACCOUNT_SID"]).update(
    auth_token_promotion="promote"
)

Important: Auth Token rotation invalidates all active sessions using that token. Plan the switchover to minimize downtime.

API Keys cannot be rotated — if an API Key is compromised, delete it and create a new one:

  • Console > Account > API keys & tokens > select key > Delete
  • Or via API: client.keys(key_sid).delete()

Docs: Auth Token REST API

Access Tokens (client-side SDKs)

Short-lived JWTs for authenticating browser/mobile clients (Voice JS SDK, Conversations SDK, Video SDK). Generate server-side and pass to the client.

Python

from twilio.jwt.access_token import AccessToken
from twilio.jwt.access_token.grants import VoiceGrant

token = AccessToken(
    os.environ["TWILIO_ACCOUNT_SID"],
    os.environ["TWILIO_API_KEY"],
    os.environ["TWILIO_API_SECRET"],
    identity="user-123",
    ttl=3600
)
token.add_grant(VoiceGrant(outgoing_application_sid="APxxxx"))
print(token.to_jwt())

Node.js

const { AccessToken } = require("twilio").jwt;
const { VoiceGrant } = AccessToken;

const token = new AccessToken(
    process.env.TWILIO_ACCOUNT_SID,
    process.env.TWILIO_API_KEY,
    process.env.TWILIO_API_SECRET,
    { identity: "user-123", ttl: 3600 }
);
token.addGrant(new VoiceGrant({ outgoingApplicationSid: "APxxxx" }));
console.log(token.toJwt());

Available grant types: VoiceGrant, VideoGrant, ChatGrant (Conversations), SyncGrant

Environment Variable Reference

TWILIO_ACCOUNT_SID=ACxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

# Option 1: Auth Token (testing only)
TWILIO_AUTH_TOKEN=your_auth_token

# Option 2: API Key (production)
TWILIO_API_KEY=SKxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
TWILIO_API_SECRET=your_api_secret

# Test credentials
TWILIO_TEST_ACCOUNT_SID=ACxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
TWILIO_TEST_AUTH_TOKEN=your_test_auth_token

CANNOT

  • Standard keys cannot access /Accounts or /Keys endpoints — Returns error 20003 (401). Must use Auth Token or Main API Key for account management.
  • No restricted key creation via v2010 API — The v2010 /Keys.json endpoint silently ignores KeyType=restricted and Policy parameters, creating a standard key instead. Use the v1 IAM API.
  • Restricted keys cannot generate Access Tokens — Only Standard and Main keys can create client SDK tokens.
  • No individual Access Token revocation — Tokens are valid until expiration (max 24h). To revoke early, delete the API key that issued them.
  • Subaccount credentials cannot access parent or sibling resources — Each subaccount has its own Auth Token and API Keys. Use the subaccount's own credentials to access its resources — never the parent account's credentials.
  • API Keys cannot be rotated — No key rotation API exists. To replace a compromised key: create a new key, update your app, then delete the old key.
  • PKCV is an advanced feature for compliance-heavy industries — Public Key Client Validation adds client-certificate-style auth. Incompatible with Flex, Studio, and TaskRouter. Once enforcement is enabled, Auth Token authentication is disabled (one-way door). See PKCV docs — consider this only if your security team requires mutual TLS-equivalent authentication.
  • Test credentials work with only 4 endpoints — Messages, Calls, IncomingPhoneNumbers, and Lookups. All other endpoints return 403.
  • API Key Secret shown only at creation — Cannot be retrieved afterward. If lost, create a new key.
  • FriendlyName max 64 characters for keys — 65+ characters returns error 70001.
  • Restricted keys limited to 100 permissions per key — Exceeding this limit is rejected at creation.
  • Cannot create Main API Keys via REST API — Console only
  • Cannot set Access Token TTL beyond 24 hours — Maximum lifetime is 24h
  • Cannot use test credentials with real numbers — Test credentials only work with test magic numbers

Next Steps

  • Account setup and phone numbers: twilio-account-setup
  • Security best practices (credential management, key rotation): twilio-security-hardening
  • Restricted API keys (fine-grained permissions): Docs
  • Auth Token rotation: REST API

Files

2
9.8 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from twilio/ai8

twilio-account-setup

Create and configure a Twilio account from scratch. Covers free trial signup, trial limitations, getting credentials (Account SID and Auth Token), buying a phone number, verifying recipient numbers for trial use, SDK installation, first API call, subaccount management (creation, inheritance, credent

Scan passed 0
twilio-agent-augmentation-architect

Planning skill for augmenting human agents with real-time AI intelligence. Qualifies the developer's use case across coaching, compliance, QA, and routing to recommend the right Conversation Intelligence + Conversation Memory + TaskRouter architecture. Handles both "I want to add AI coaching to my c

Scan passed 0
twilio-agent-connect

twilio-agent-connect skill

Scan passed 0
twilio-ai-agent-architect

Planning skill for AI-powered conversational agents. Qualifies the developer's use case across outcome sophistication, entry point, and customer profile to recommend the right Twilio Conversations architecture and implementation skills. Handles both high-level requests ("build me a voice AI assistan

Scan passed 0
twilio-call-recordings

Record Twilio voice calls correctly. Covers the critical distinction between Record verb (voicemail) and Dial record (call recording), dual-channel for QA, mid-call pause for PCI, Conference recording, and the ConversationRelay workaround. Use this skill whenever you need to capture call audio for c

Scan passed 0
twilio-cli-reference

Twilio CLI reference for managing Twilio resources from the terminal. Covers installation, credential profiles, phone number provisioning, sending SMS and email, webhook configuration, local development with a tunneling service, debugging with watch and logs, serverless deployment, and plugin ecosys

Scan passed 0
twilio-compliance-onboarding

Registrations required BEFORE Twilio traffic works. Covers messaging programs (A2P 10DLC, toll-free verification, WhatsApp WABA, RCS, short code, alphanumeric sender) and voice trust programs (STIR/SHAKEN, Voice Integrity, Branded Calling, CNAM). Each number/sender type has its own program — registr

Scan passed 0
twilio-compliance-traffic

Rules you must follow for Twilio messaging and voice traffic. Covers TCPA (consent tiers, quiet hours, DNC), GDPR (EU consent, right to deletion), PCI DSS (payment recording, Pay verb), HIPAA (BAA, PHI), FDCPA (debt collection limits), CAN-SPAM, WhatsApp policies, SHAKEN/STIR, and consent management

Scan passed 0

Related security skillsscan passed

auth

Implement JWT/cookie authentication and authorization in tRPC using createContext for user extraction, t.middleware with opts.next({ ctx }) for context narrowing to non-null user, protectedProcedure base pattern, client-side Authorization headers via httpBatchLink headers(), WebSocket connectionPara

Scan passed 0
security-and-hardening

Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data,

Scan passed 0
ponytail-audit

Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split. Ranked, each finding explained in plain English. One-shot report, changes nothing. Use for "audit this codebase", "review the whole repo", "find

Scan passed 0
llm-trading-agent-security

Security patterns for autonomous trading agents with wallet or transaction authority. Covers prompt injection, spend limits, pre-send simulation, circuit breakers, MEV protection, and key handling. Use when an autonomous agent holds wallet or transaction authority and its limits, simulation, or key

Scan passed 0
firebase-security-rules-auditor

Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or

Scan passed 0
securing-s3-buckets

Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations. Use when the user wants to secure a new bucket, audit an existing bucket, fix a security finding, configure encryption, or enable logging and monitoring. Do NOT

Scan passed 0