Skip to main content
Version: 1.28 (Current)

Twilio

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens, APIs, Twilio account

The Twilio add-on sends and receives text messages (SMS) through your Twilio account. One of its actions sends a new SMS to a phone number. The other two work together in an API endpoint that Twilio calls when someone texts your Twilio number: one reads the incoming message and the other sends the reply.

note

The add-on is installed separately as the DnnSharp.TwilioSms package, and needs the TWILIOSMS feature in your license. If it isn't licensed, the actions fail with a "not licensed" error. If you don't see the Twilio actions or the Twilio API keys credential type connector type, the add-on isn't installed. You also need a Twilio account with a phone number that can send SMS.

Choosing an action​

ActionWhat it doesUse it to
Send SMS using TwilioSends an SMS to one number through the Twilio API and returns the message SID. It needs a Twilio connector.Send a confirmation code, or notify staff when an order ships.
Twilio Parse Webhook SMSReads the incoming SMS from the current request into tokens: sender, receiving number, text and media links.Handle a keyword such as STATUS 1234 or a STOP reply.
Twilio Send Response to SMS WebhookReturns TwiML that replies to the sender, redirects Twilio to another URL, or just acknowledges the SMS. It ends the action list.Reply to an incoming SMS with an order status.

Sending or replying?​

  • Sending (Send SMS using Twilio). Your site calls Twilio with the Account SID and Auth Token from a connector of type Twilio API keys credential type. It works anywhere, such as forms, workflows and API endpoints. It sends to one number, so use Execute Actions for Each List Entry to reach several.
  • Replying (the two webhook actions). Twilio calls your API endpoint, and the response tells Twilio what to send back. No connector is needed. Start the endpoint with Parse Webhook SMS and always end it with Send Response, even with empty parameters, or Twilio logs an error. Twilio waits about 15 seconds for the response, so move slow work to Execute Actions Asynchronously. See How receiving SMS works.

Security​

  • The webhook isn't verified. The actions don't check Twilio's signature, so anyone who knows the endpoint URL can post a fake SMS. Restrict the endpoint to API keys, and don't treat the sender's number as proof of identity. See Securing the webhook.
  • Message text is untrusted. Don't put the incoming text into SQL, HTML or the reply. The reply isn't escaped, so the sender's text could add their own TwiML. See TwiML escaping.

Delivery and cost​

  • Accepted isn't delivered. A message SID means Twilio accepted the message. Use Status Callback URL to track delivery.
  • Replies are charged like any other SMS, and long messages are split into several.
  • Trial accounts can only send to numbers verified in the Twilio Console.

For SMS through Clickatell, see Clickatell. For the connector actions, see Connectors. For all add-ons, see Add-ons.

Revised 10/02/2026