Connect your Twilio account
In Settings → Connections, add a Twilio connection with:
Reliant checks the pair with Twilio before saving, so a typo is caught right away. The connection is labelled with the account’s name in Twilio.
Twilio connects with the Account SID and Auth Token, not an API key. Twilio signs every incoming-message webhook with the account’s primary Auth Token, and an API key cannot verify those signatures. If you rotate the Auth Token in Twilio, reconnect with the new one: until you do, sends fail with error 20003 and incoming messages for that connection stop arriving.
Sending messages
Thetwilio/message.send@1 action (also offered to agents as a tool) sends from one of your numbers:
- SMS / MMS: E.164 numbers (
+15551234567). Attach media withmedia_url(a list of public URLs). - WhatsApp: prefix both
toandfromwithwhatsapp:(whatsapp:+15551234567). - Outside WhatsApp’s 24-hour window: WhatsApp only allows free-form text within 24 hours of the person’s last message to you. Outside that window, send an approved template with
content_sid(andcontent_variables) instead ofbody. A free-form send outside the window fails with error 63016, and the error message says so.
message.get (a message’s delivery status), message.list (history, filtered by to, from or date) and phone_number.list (your numbers and where each one’s incoming messages go today).
Errors your workflow can act on are classified for you:
Starting a run when a message arrives
Add a trigger with the Message received event (twilio/message.received@1). In workflow YAML:
trigger.payload:
A trigger can be narrowed by equality on these attributes:
To reply, use
twilio/message.send@1 with to set to the incoming from and from set to the incoming to.
Point your numbers at Reliant
Twilio has no app-wide webhook. Each phone number decides where its incoming messages go, so you set it once per number:- Open the trigger in Reliant and copy its Webhook URL. It is the same for every number and every trigger:
https://<your Reliant host>/integrations/twilio/events. - In the Twilio Console, open Phone Numbers → Manage → Active numbers, pick the number, and under Messaging configuration set A message comes in to Webhook, the URL from step 1, HTTP POST. Save.
- For a Messaging Service, set the same URL under the service’s Integration → Incoming Messages → Send a webhook.
- For WhatsApp:
- Sandbox (Messaging → Try it out → Send a WhatsApp message): set When a message comes in to the URL. Each tester first sends
join <your keyword>to the sandbox number, and sandbox sessions expire after three days. The sandbox can only message people who have joined it (error 63015 otherwise). - Approved sender (WhatsApp Senders, via Self Sign-up): set the sender’s incoming-message webhook to the URL. This needs a Meta Business Manager account, a display name Meta has approved, and Meta-approved templates for anything outside the 24-hour window.
- Sandbox (Messaging → Try it out → Send a WhatsApp message): set When a message comes in to the URL. Each tester first sends
How incoming messages are verified and routed
Every message Twilio sends to Reliant is signed with the account’s Auth Token. Reliant checks the signature against the Auth Token saved in each Twilio connection for that account, and a message reaches a trigger only through a connection whose own token verified it. So:- People on different Twilio accounts never see each other’s messages, even though their numbers all point at the same URL.
- Several people on the same Twilio account each receive the message, through their own connection, wherever their trigger matches it. Use
toto give each person their own number. - A connection with an outdated Auth Token receives nothing until it is reconnected.
- A message that arrives more than once (Twilio retries) starts at most one run: messages are deduplicated on their
MessageSid.
For operators
The Twilio integration needs no app registration and no deployment secret. It needs only:PUBLIC_URLset to the externally reachable https base of the api-server. Twilio signs the exact URL it was configured with, so Reliant rebuilds that URL fromPUBLIC_URLrather than from the request it receives behind the ingress. WithoutPUBLIC_URL, Twilio triggers are not offered.- The
/integrations/twilio/eventspath routed to the api-server, publicly reachable over https with a certificate Twilio trusts (Twilio refuses self-signed certificates).