skills/ twilio/ai

twilio-isv-sms-best-practices

Best practices for ISVs (Independent Software Vendors) building SMS features into multi-tenant SaaS platforms using Twilio. Covers customer onboarding for A2P and toll-free compliance, subaccount architecture, sender management, billing patterns, and common ISV pitfalls. Use this when building SMS c

0
Installs
—
Rating
—
Success rate
2
Files scanned
Scan passedmethodology
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

2 files scannedscanner v1.2.0Oct 10, 2026

Content sha256 a5ff0cfd62a1f9df… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Overview

ISVs face unique challenges when building SMS into their platforms: each customer needs their own number registration, sender pool management, compliance isolation, and usage tracking. This skill consolidates the architectural patterns and operational knowledge specific to multi-tenant SMS platforms.


Are You an ISV?

Before following this skill, determine whether you are an Independent Software Vendor (ISV) or a direct customer.

Direct Customer

Your company sends messages for your own products and services. Your end users know they are interacting with your brand.

Example: A shoe company called CoolShoes sends marketing messages and order updates for their own products. Even if CoolShoes owns multiple brands (CoolShoes and CoolShirts), they are still a direct customer because both brands are operated by the same company.

Follow the direct customer onboarding process — not this ISV skill.

ISV (Independent Software Vendor)

Your company provides messaging services to other businesses, who are represented by their own brands. Your end users think they are interacting with your client's brand, not yours.

Example: HotelTech Inc. sells a technology platform for hotels. When hotel SleepWell Inn uses the service, hotel visitors receive messages that appear to come from SleepWell Inn. Visitors likely don't know HotelTech powers the interaction.

Follow this ISV skill.

Still Not Sure? Two Key Questions

1. Who do your end users think they are receiving messages from?

  • Your brand → You are a direct customer
  • Your client's brand → You are an ISV

2. How much control do your clients have over message contents?

ScenarioClassificationExample
Templated messages with little/no customizationDirect customerEventSite sends templated event reminders to attendees. Event organizers can only customize basic details (event name, date). End users interact with EventSite brand.
Clients can customize and send messages on their own behalfISVPoweringEvents provides a platform where car dealership CarWorld can write and send customized messages about their Cars & Coffee events. Attendees don't know PoweringEvents exists — messages appear to come from CarWorld.

If you give clients the ability to send customized messages that end users perceive as coming directly from your client, you are an ISV.


Prerequisites

  • Twilio parent account (for your platform)
  • Understanding of A2P 10DLC requirements — See twilio-compliance-onboarding for registration basics
  • Understanding of Messaging Services — See twilio-messaging-services for sender pool management
  • Environment variables:
    • TWILIO_ACCOUNT_SID (parent account)
    • TWILIO_AUTH_TOKEN (parent account) — See twilio-iam-auth-setup for credential security
  • SDK: pip install twilio / npm install twilio

Key Architecture Patterns

Subaccount Strategy

Recommended approach: Create one Twilio subaccount per customer.

Why subaccounts:

  • Billing isolation: Each customer's usage appears on their own Twilio account, making cost tracking and pass-through billing straightforward
  • Compliance isolation: One customer's compliance violations or spam complaints do not affect other customers
  • Credential isolation: Each customer has their own Account SID and Auth Token, limiting the blast radius if credentials are compromised
  • Separate rate limits: Each subaccount has its own throughput and sending limits

Customer Onboarding Flow: A2P 10DLC

Use this flow when your customer needs to send SMS via 10-digit long code (local) numbers in the United States or Canada.

The full onboarding overview includes all necessary API calls to complete A2P campaign registration for your customers.

Timeline: 13-20 business days total (3-5 days for Brand + 10-15 days for campaign). Start early.

Do not skip this step. Unregistered traffic gets blocked (error 30034).

Step 1: Create Secondary Customer Profile

As an ISV, you create a Secondary Customer Profile for each of your clients in their own subaccount. This profile contains your client's business information.

Step 2: Register Brand

Required fields for Standard Brand:

  • Legal business name (must match EIN records exactly)
  • EIN (Employer Identification Number) or business tax ID
  • Business type (private, public, non-profit, government)
  • Business address
  • Website URL (must be publicly accessible)
  • Business registration country
  • Contact: first name, last name, email, phone

Once you have customer's business information, submit Brand registration using the Customer Profile Bundle SID from Step 1.

Each Standard Brand is assigned a Trust Score, which affects each campaign's throughput and the T-Mobile daily message limit for the Brand.

Timeline: 3-5 business days.

Step 3: Create Campaign

Create a campaign for your customer's use case.

Critical ISV consideration: Each customer needs their own campaigns. Do NOT share campaigns across customers — it violates carrier policies and creates compliance risk.

Create the campaign with:

  • Brand registration SID
  • Use case (e.g., "2FA", "MARKETING", "MIXED")
  • Clear description matching the actual use case
  • 2+ sample messages that match the use case exactly
  • Opt-in/opt-out details
  • Whether messages contain embedded links or phone numbers

Timeline: 10-15 business days.

Step 4: Provision Numbers and Create Messaging Service

  1. Buy 10DLC numbers for the customer
  2. Create a Messaging Service
  3. Link the campaign to the Messaging Service
  4. Add the number to the Messaging Service

Customer Onboarding Flow: Toll-Free Verification

Use this flow when your customer needs to send SMS via toll-free numbers (800, 888, etc.).

Timeline: 3-5 business days.

Do not skip this step. Unregistered traffic gets blocked (error 30032).

When to use toll-free vs. 10DLC:

  • Toll-free: Lower throughput (~3 SMS/sec per number, can be raised via Traffic Optimization Engine), one number per use case
  • 10DLC: Higher throughput (3.75 - 225 SMS/sec per campaign), can have multiple numbers per campaign

Step 1: Buy Toll-Free Number

Purchase a toll-free number for the customer in their subaccount.

Step 2: Submit Toll-Free Verification

Submit toll-free verification with:

  • Business name and website
  • Notification email
  • Use case summary and categories
  • Production message sample
  • Opt-in type (VERBAL, WEB_FORM, etc.)
  • Opt-in image URLs (screenshots of opt-in flow)
  • Expected monthly message volume
  • Toll-free phone number SID
  • Status callback URL

Timeline: 3-5 business days.


Multi-Tenancy Patterns

API Key Isolation

Create API keys per customer instead of sharing parent account credentials.

Generate API keys per customer with a descriptive friendly name. Store the API key SID and secret securely; use them to provision resources in the customer's account on their behalf.

Only use a customer's dedicated API key — not your parent account credentials. This limits the blast radius if a customer's key is compromised.


Operational Patterns

Throughput Management

Throughput per Brand type:

Brand typeSMS/sec per campaignT-Mobile SMS daily cap (per Brand)Total SMS daily cap (per Brand)
Sole Proprietor~11,000 messages3,000 messages
Low-Volume Standard~3.752,000 messages6,000 messages
Standard~12-225 (varies by Trust Score)2,000+ messages (varies by Trust Score)Unlimited

ISV strategy:

  • Use Standard Brands for your customers unless they lack an EIN (use Sole Proprietor) or you are sure they will never send more than 6,000 SMS per day (use Low Volume Standard Brand)
  • Submit a support case to apply for secondary vetting if you want to upgrade from a Low Volume Standard Brand to a Standard Brand

Common ISV Pitfalls

1. Sharing Campaigns Across Customers

DON'T: Use a single shared campaign SID for all customers in your parent account.

Problem: Violates carrier policies. One customer's spam complaint affects all customers. Campaign rejection or shutdown blocks everyone.

DO: Each customer has their own campaigns in their own subaccount.

2. Building Before Registering

DON'T:

  • Launch SMS feature to customers
  • Let them send messages
  • Register for A2P later when messages start failing

Problem: Messages blocked immediately (error 30034). Customers can't send. Scramble to register takes 10-15 business days.

DO:

  • Build A2P registration into customer onboarding flow
  • Block SMS feature until Brand + campaign approved
  • Show registration status in customer dashboard
  • Set expectation: "SMS will be available in 10-15 business days"

3. Missing Mandatory Registration Fields

Common rejections:

FieldCommon mistakeFix
Opt-in description"Users can opt in on our website""Users check 'I agree to receive SMS' checkbox at checkout.acme.com/register"
Message samplesGeneric ("We send notifications")Exact examples matching use case ("Your order #12345 has shipped")
Business nameMarketing name instead of legal nameMust match EIN records exactly
Website URLLocalhost, staging URL, or 404 pageLive, publicly accessible production URL

4. Storing Credentials Insecurely

DON'T: Store credentials in plain text.

Problem: Credential leaks expose customer accounts.

DO: Encrypt credentials at rest using strong encryption (e.g., Fernet). Store encrypted values and decrypt only when needed for API calls.

See twilio-iam-auth-setup for credential security best practices.


Constraints

  • A2P campaign registration is per customer use case in their own subaccount — cannot be shared across tenants
  • Campaign approval takes 10-15 business days — factor into onboarding timeline
  • Each campaign supports only one use case; customers with multiple use cases need to use a "Mixed" use case or multiple campaigns
  • Trial accounts cannot complete A2P registration — must upgrade first

Next Steps

  • A2P registration details: twilio-compliance-onboarding
  • Messaging Service configuration: twilio-messaging-services
  • Send SMS patterns: twilio-sms-send-message
  • Credential security: twilio-iam-auth-setup
  • Subaccount architecture: twilio-account-setup
  • General compliance guidance: twilio-compliance-traffic

Files

2
11.5 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from twilio/ai8

twilio-account-setup

Create and configure a Twilio account from scratch. Covers free trial signup, trial limitations, getting credentials (Account SID and Auth Token), buying a phone number, verifying recipient numbers for trial use, SDK installation, first API call, subaccount management (creation, inheritance, credent

Scan passed 0
twilio-agent-augmentation-architect

Planning skill for augmenting human agents with real-time AI intelligence. Qualifies the developer's use case across coaching, compliance, QA, and routing to recommend the right Conversation Intelligence + Conversation Memory + TaskRouter architecture. Handles both "I want to add AI coaching to my c

Scan passed 0
twilio-agent-connect

twilio-agent-connect skill

Scan passed 0
twilio-ai-agent-architect

Planning skill for AI-powered conversational agents. Qualifies the developer's use case across outcome sophistication, entry point, and customer profile to recommend the right Twilio Conversations architecture and implementation skills. Handles both high-level requests ("build me a voice AI assistan

Scan passed 0
twilio-call-recordings

Record Twilio voice calls correctly. Covers the critical distinction between Record verb (voicemail) and Dial record (call recording), dual-channel for QA, mid-call pause for PCI, Conference recording, and the ConversationRelay workaround. Use this skill whenever you need to capture call audio for c

Scan passed 0
twilio-cli-reference

Twilio CLI reference for managing Twilio resources from the terminal. Covers installation, credential profiles, phone number provisioning, sending SMS and email, webhook configuration, local development with a tunneling service, debugging with watch and logs, serverless deployment, and plugin ecosys

Scan passed 0
twilio-compliance-onboarding

Registrations required BEFORE Twilio traffic works. Covers messaging programs (A2P 10DLC, toll-free verification, WhatsApp WABA, RCS, short code, alphanumeric sender) and voice trust programs (STIR/SHAKEN, Voice Integrity, Branded Calling, CNAM). Each number/sender type has its own program — registr

Scan passed 0
twilio-compliance-traffic

Rules you must follow for Twilio messaging and voice traffic. Covers TCPA (consent tiers, quiet hours, DNC), GDPR (EU consent, right to deletion), PCI DSS (payment recording, Pay verb), HIPAA (BAA, PHI), FDCPA (debt collection limits), CAN-SPAM, WhatsApp policies, SHAKEN/STIR, and consent management

Scan passed 0

Related methodology skillsscan passed

service-oriented-architecture

Break a tRPC backend into multiple services with custom routing links that split on the first path segment (op.path.split('.')) to route to different backend service URLs. Define a faux gateway router that merges service routers for the AppRouter type without running them in the same process. Share

Scan passed 0
open-code-review-delegate

Delegation mode for open-code-review (OCR). Instead of OCR calling an LLM endpoint, this skill instructs the host agent to perform the code review itself, using OCR only for deterministic engineering: file selection and rule resolution. Use when the host agent should drive the review with its own LL

Scan passed 0
using-agent-skills

Discovers and invokes agent skills. Use when starting a session, or when you need to decide which skill or workflow applies to the piece of work at hand. This is the meta-skill that governs how all other skills are discovered and invoked.

Scan passed 0
ponytail-review

Quality review of a change: is the logic right, is it safe, does it hold under real load, is risky code tested, is it fast enough, and is every line needed. Reads the connected code, not only the diff. Each finding is explained in plain English. Use for "review this", "code review", "review the last

Scan passed 0
scientific-thinking-literature-review

Systematic literature-review workflow for academic, biomedical, technical, and scientific topics, including search planning, source screening, synthesis, citation checks, and evidence logging. Use when the task is to find, screen, synthesize, and cite a body of academic or technical literature.

Scan passed 0