twilio-verify-send-otp
Send and verify one-time passcodes (OTPs) via Twilio Verify over SMS (auto-upgraded to RCS where supported), voice, email, or WhatsApp. Covers creating a Verify Service, sending tokens, checking submitted codes, automatic WhatsApp-to-SMS fallback, and service configuration. TOTP is supported via the
- 0
- Installs
- —
- Rating
- —
- Success rate
- 2
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 d211062049b69a3d… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Overview
Use Twilio Verify to manage the full OTP lifecycle: code generation, delivery, expiry, rate limiting, and Fraud Guard protection. Use the Programmable Messaging API to build your own OTP message infrastructure and access features such as SMS Pumping Protection.
| Twilio Verify | Programmable Messaging API | |
|---|---|---|
| Code generation + expiry | Built-in (10min default, configurable). Also supports custom codes. | Build yourself |
| Rate limiting | Built-in (per-phone, per-service) | Build yourself |
| Fraud protection | Fraud Guard (geo-permissions, rate anomaly) | SMS Pumping Protection |
| A2P registration | Exempt — no 10DLC needed | Required — must register campaign |
| Multi-channel | One API, change channel param (SMS/Voice/Email/WhatsApp) | Separate integration per channel |
| Cost | Per confirmed verification + channel fee | Per-message pricing + build cost |
| Delivery confirmation | Yes — via List Attempts or Events API | Yes (via StatusCallback) |
When Programmable Messaging is justified: You need full control over message content, custom delivery logic, or SMS Pumping Protection features. For standard OTP/2FA flows, use Verify.
Verify supports SMS, voice, email, and WhatsApp — only the channel parameter changes per delivery method. RCS is not a channel value: Verify automatically upgrades an sms verification to RCS where the device supports it and falls back to SMS. TOTP (authenticator apps) is supported via the Verify Factors API, a separate implementation from channel-based OTP.
Prerequisites
- Twilio account (free trial works for testing)
— New to Twilio? See
twilio-account-setup— Verify requires no separate product activation — just create a Service below - Environment variables:
TWILIO_ACCOUNT_SIDTWILIO_AUTH_TOKENVERIFY_SERVICE_SID(created in Quickstart step 1) — Seetwilio-iam-auth-setupfor credential setup and best practices
- SDK:
pip install twilio/npm install twilio - For WhatsApp channel only: a registered production WhatsApp sender — see
twilio-whatsapp-manage-senders
Quickstart
Step 1 — Create a Verify Service (one-time)
Python
import os
from twilio.rest import Client
client = Client(os.environ["TWILIO_ACCOUNT_SID"], os.environ["TWILIO_AUTH_TOKEN"])
service = client.verify.v2.services.create(
friendly_name="My App Verification"
)
print(service.sid) # VAxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx — save as VERIFY_SERVICE_SID
Node.js
const twilio = require("twilio");
const client = twilio(process.env.TWILIO_ACCOUNT_SID, process.env.TWILIO_AUTH_TOKEN);
const service = await client.verify.v2.services.create({
friendlyName: "My App Verification",
});
console.log(service.sid); // VAxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Store the Service SID — reuse it for all verifications, do not recreate it each time.
Step 2 — Send a verification token
Python
verification = client.verify.v2 \
.services(os.environ["VERIFY_SERVICE_SID"]) \
.verifications \
.create(to="+15558675310", channel="sms")
print(verification.status) # pending
Node.js
const verification = await client.verify.v2
.services(process.env.VERIFY_SERVICE_SID)
.verifications.create({ to: "+15558675310", channel: "sms" });
console.log(verification.status); // pending
Step 3 — Check the submitted code
Python
check = client.verify.v2 \
.services(os.environ["VERIFY_SERVICE_SID"]) \
.verification_checks \
.create(to="+15558675310", code="123456")
if check.status == "approved":
print("Verified!")
else:
print("Invalid or expired code")
Node.js
const check = await client.verify.v2
.services(process.env.VERIFY_SERVICE_SID)
.verificationChecks.create({ to: "+15558675310", code: "123456" });
if (check.status === "approved") {
console.log("Verified!");
} else {
console.log("Invalid or expired code");
}
Key Patterns
Supported Channels
| Channel | channel value | Notes |
|---|---|---|
| SMS | sms | Default, widest coverage. Auto-upgrades to RCS where supported (see below) |
| Voice call | call | Reads code aloud |
email | Use email address in to | |
whatsapp | Requires own WhatsApp sender (see below) |
TOTP (authenticator apps): Supported via the Verify Factors API — a separate implementation from channel-based OTP. See Verify TOTP docs.
WhatsApp OTP
Change channel to "whatsapp" — the send/check flow is identical to SMS.
Requires: A registered production WhatsApp sender. As of March 2024, Twilio no longer provides a shared sender for Verify. See
twilio-whatsapp-manage-senders.
Python
verification = client.verify.v2 \
.services(os.environ["VERIFY_SERVICE_SID"]) \
.verifications \
.create(to="+15558675310", channel="whatsapp")
Node.js
const verification = await client.verify.v2
.services(process.env.VERIFY_SERVICE_SID)
.verifications.create({ to: "+15558675310", channel: "whatsapp" });
WhatsApp with Automatic SMS Fallback
Python
verification = client.verify.v2 \
.services(os.environ["VERIFY_SERVICE_SID"]) \
.verifications \
.create(
to="+15558675310",
channel="whatsapp",
channel_configuration={
"whatsapp": {"enabled": True},
"sms": {"enabled": True} # falls back to SMS if WhatsApp undelivered
}
)
Node.js
const verification = await client.verify.v2
.services(process.env.VERIFY_SERVICE_SID)
.verifications.create({
to: "+15558675310",
channel: "whatsapp",
channelConfiguration: {
whatsapp: { enabled: true },
sms: { enabled: true },
},
});
With fallback enabled, your UI can say "a verification code was sent" without specifying the channel.
Service Configuration
Python
service = client.verify.v2.services.create(
friendly_name="My App",
code_length=6 # 4–10 digits (default: 6)
)
Node.js
const service = await client.verify.v2.services.create({
friendlyName: "My App",
codeLength: 6
});
Verification Status Values
| Status | Meaning |
|---|---|
approved | Code is correct |
pending | Code is wrong or not yet submitted |
expired | Code has expired (default TTL: 10 minutes) |
canceled | Verification was canceled |
Debugging
Primary debugging tool: Console > Verify > Logs (per-Service). Shows every verification attempt, delivery status, channel used, and error codes. Check here first before writing custom monitoring code.
Common Errors
| Code | Meaning | Fix |
|---|---|---|
| 60200 | Invalid parameter | Check to format and channel value |
| 60202 | Max check attempts reached | Issue a new verification |
| 60203 | Max send attempts reached | Wait before retrying |
| 60212 | Service not found | Verify VERIFY_SERVICE_SID is correct |
| 60410 | Geo-permission not enabled | Enable country in Console |
Built-in protections (no custom code needed):
- Rate limiting: 5 verifications per phone per service per 10 minutes
- Max check attempts: 5 per verification (6th attempt → error 60202)
- Phone number validation: Verify checks line type before sending (if
lookup_enabled=True) - Fraud Guard: geo-permissions, rate anomaly detection, SMS pumping protection
International OTP traffic warning: International numbers are high-risk for SMS pumping — fraudsters trigger OTPs to premium-rate destinations to generate revenue. Verify's Fraud Guard handles this automatically when enabled. If you're building custom OTP with Programmable Messaging instead, enable SMS Pumping Protection on your Messaging Service (see twilio-messaging-services). Always restrict geo-permissions to only countries where you have real users.
CANNOT
- No built-in channel fallback — Must implement retry logic manually (e.g., SMS → voice → email). Use
channel_configurationfor WhatsApp→SMS only. - No webhook on verification completion — Must poll
verification_checks. Rate-limited: 60/min, 180/hr, 250/day. - Cannot retrieve the actual code sent — Code is never returned in any API response. By design.
- Sending on a new channel with the same
toreuses the pending verification — the same Verification SID and code are kept, just delivered over the new channel (e.g. switchingsms→callfor the same phone number). A differentto(e.g. an email address) starts a separate verification. To force a fresh code on the sameto, cancel the pending one first. - Cannot extend TTL on an existing verification — Default 10 minutes, and not a per-verification or Service create/update param. Contact Twilio Support to change the default on your Service (adjustable 2 min–24 hr).
- Verification SID deleted after approval — Fetching an approved verification returns 404. Canceled verifications remain fetchable.
autochannel not universally available — Returns error 60200 on accounts without Fraud Guard enabled.- Email channel requires Mailer configuration —
channel: 'email'without a configured Mailer returns error 60217. - No real-time delivery push notification — Delivery status is available via List Attempts or Events API (pull-based), not via a push webhook.
- FriendlyName rejects embedded digit strings — avoid embedding 5 or more digits in a Service name; it can trigger error 60200. Use words.
- Wrong code does not throw an exception — Check returns
status: "pending", not an error. You must checkstatus === "approved"explicitly. - Cannot re-check an approved verification — Each verification is single-use. Once
approved, subsequent checks return 404. - Cannot send to arbitrary numbers on trial accounts — Trial accounts have limited verification destinations
- Cannot customize WhatsApp OTP template — Uses a fixed Meta authentication template
- Cannot use WhatsApp channel for PSD2 compliance mode — PSD2 payee/amount parameters not supported on WhatsApp
Next Steps
- Register a WhatsApp sender:
twilio-whatsapp-manage-senders - Validate phone numbers before sending:
twilio-lookup-phone-intelligence - Credential setup:
twilio-iam-auth-setup
Files
2- SKILL.md
d429cf42ce10.9 KB - agents/openai.yaml
ba4c553e11430 B
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from twilio/ai8
Create and configure a Twilio account from scratch. Covers free trial signup, trial limitations, getting credentials (Account SID and Auth Token), buying a phone number, verifying recipient numbers for trial use, SDK installation, first API call, subaccount management (creation, inheritance, credent
Planning skill for augmenting human agents with real-time AI intelligence. Qualifies the developer's use case across coaching, compliance, QA, and routing to recommend the right Conversation Intelligence + Conversation Memory + TaskRouter architecture. Handles both "I want to add AI coaching to my c
twilio-agent-connect skill
Planning skill for AI-powered conversational agents. Qualifies the developer's use case across outcome sophistication, entry point, and customer profile to recommend the right Twilio Conversations architecture and implementation skills. Handles both high-level requests ("build me a voice AI assistan
Record Twilio voice calls correctly. Covers the critical distinction between Record verb (voicemail) and Dial record (call recording), dual-channel for QA, mid-call pause for PCI, Conference recording, and the ConversationRelay workaround. Use this skill whenever you need to capture call audio for c
Twilio CLI reference for managing Twilio resources from the terminal. Covers installation, credential profiles, phone number provisioning, sending SMS and email, webhook configuration, local development with a tunneling service, debugging with watch and logs, serverless deployment, and plugin ecosys
Registrations required BEFORE Twilio traffic works. Covers messaging programs (A2P 10DLC, toll-free verification, WhatsApp WABA, RCS, short code, alphanumeric sender) and voice trust programs (STIR/SHAKEN, Voice Integrity, Branded Calling, CNAM). Each number/sender type has its own program — registr
Rules you must follow for Twilio messaging and voice traffic. Covers TCPA (consent tiers, quiet hours, DNC), GDPR (EU consent, right to deletion), PCI DSS (payment recording, Pay verb), HIPAA (BAA, PHI), FDCPA (debt collection limits), CAN-SPAM, WhatsApp policies, SHAKEN/STIR, and consent management
Related knowledge skillsscan passed
PostHog error tracking for Go
Stop hook that blocks Claude from finishing until quality checks pass. Detects rationalization patterns (surface text heuristics), stale learning logs (filesystem mtime), and low disk space. Complements self-audit by mechanically enforcing learning capture habits. Use when Claude should be mechanica