From twilio-developer-kit
Secure Twilio apps: credential management, webhook signature validation, PCI DSS/HIPAA compliance, SMS pumping prevention, geo-permissions, account isolation.
How this skill is triggered — by the user, by Claude, or both
Slash command
/twilio-developer-kit:twilio-security-hardeningThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Security hardening is an **ongoing** concern — not a one-time setup. This skill covers account-level security decisions and application-level protection patterns that prevent credential leaks, fraud, and compliance violations.
Security hardening is an ongoing concern — not a one-time setup. This skill covers account-level security decisions and application-level protection patterns that prevent credential leaks, fraud, and compliance violations.
Lifecycle: Choose numbers (twilio-numbers-senders) → Register (twilio-compliance-onboarding) → Follow traffic rules (twilio-compliance-traffic) → Secure everything (this skill)
| Credential | Scope | Revocable | Use when |
|---|---|---|---|
| Auth Token | Full account access | Only by rotating (invalidates all token-based integrations and webhook signature validation — API keys unaffected) | Avoid in production — use API keys instead |
| API Key + Secret | Scoped, revocable individually | Yes — revoke one without affecting others | Production applications, CI/CD, server-side code |
| Access Tokens | Short-lived, client-specific | Expire automatically | Client-side SDKs (Voice, Video, Conversations) |
Critical gotcha: Rotating your Auth Token invalidates all integrations authenticating with AccountSID:AuthToken and breaks webhook signature validation — it does NOT affect API keys (SK-prefixed), which are independent. Use API keys from the start so you rarely need to rotate the Auth Token.
twilio-account-setupDocs: See twilio-iam-auth-setup for full credential setup patterns.
Verify that webhook requests actually come from Twilio — not spoofed by attackers.
Always use the SDK validator — don't implement HMAC-SHA1 manually:
Node.js
const twilio = require("twilio");
app.post("/sms", (req, res) => {
const valid = twilio.validateRequest(
process.env.TWILIO_AUTH_TOKEN,
req.headers["x-twilio-signature"],
`https://yourdomain.com/sms`,
req.body
);
if (!valid) return res.status(403).send("Forbidden");
// Process webhook...
});
Note: Webhook signature validation always uses your Auth Token — not an API Key Secret. This is the one legitimate production use of the Auth Token. Keep it accessible for request validation but store it securely (environment variable or secrets manager).
Common mistakes:
Docs: See twilio-webhook-architecture for full webhook security patterns.
PCI Mode is IRREVERSIBLE and account-wide. Once enabled, it cannot be disabled — ever.
Recommendation: If you need PCI compliance for one use case, create a separate sub-account dedicated to payment-related calls. See twilio-account-setup for sub-account patterns.
For call recording during payment, pause recording when the customer gives card numbers:
client.calls(call_sid).recordings(recording_sid).update(status="paused")
Or use the <Pay> verb to handle payments without your application touching card data:
<Pay paymentConnector="stripe_connector" chargeAmount="49.99" currency="usd" />
Before handling Protected Health Information (PHI):
<Say>Attackers trigger thousands of OTP messages to premium-rate numbers, generating toll charges.
Layered defense:
twilio-lookup-phone-intelligence to check line type + SMS pumping risk score before sendingRestrict which countries can receive messages or calls from your account:
SMS pumping impact: Incidents can climb into tens of thousands of dollars. Twilio does not publish most-targeted prefixes — the general guidance is to restrict message termination to countries where you do business via geo-permissions. Customers using Fraud Guard can view estimated fraud savings in their Fraud Guard reports.
AccountSID:AuthToken and webhook signature validation simultaneously. API keys are unaffected.Both API keys and Auth Tokens follow the same workflow:
Manage keys at: https://console.twilio.com/account/keys-credentials/api-keys (per account).
Key enabler: use a secrets manager (AWS Secrets Manager, HashiCorp Vault, etc.) to inject credentials at runtime. This makes rotation near-instantaneous with no downtime — no code changes, no redeployments. Organizations that hard-code credentials into repos, deployment scripts, or .env files must manually update every location before deleting the old key.
For ISVs managing many sub-accounts, automate this with the API Keys REST API across accounts.
twilio-iam-auth-setuptwilio-webhook-architecturetwilio-account-setuptwilio-lookup-phone-intelligencetwilio-compliance-trafficclaude plugin install twilio-developer-kit@claude-plugins-officialConfigures Twilio accounts for HIPAA compliance: BAA execution, HIPAA project designation, eligible services, and per-product requirements for Voice, SMS, and Flex.
Build communication features with Twilio: SMS, voice calls, WhatsApp Business API, and 2FA verification. Covers simple notifications to complex IVR systems with code patterns for sending and managing messages.
Builds Twilio communication features: SMS, voice calls, WhatsApp Business API, and 2FA verification. Covers notifications, IVR systems, and multi-channel auth with compliance and error handling guidance.