Twilio Compliance Onboarding

作者 twilio8aba46fb65dc無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Registrations required BEFORE Twilio traffic works. Covers messaging programs (A2P 10DLC, toll-free verification, WhatsApp WABA, RCS, short code, alphanumeric sender) and voice trust programs (STIR/SHAKEN, Voice Integrity, Branded Calling, CNAM). Each number/sender type has its own program — registration blocks traffic until complete.

僅含說明Business & Finance
AI 產生的概覽

說明 Twilio 訊息與語音在流量可用前必須完成的合規註冊,涵蓋 A2P 10DLC、免付費電話、WhatsApp、RCS 與語音信任計畫。

功能
說明每種 Twilio 傳送端與號碼類型需要哪個註冊或審核計畫,並提供時程與文件連結。詳細說明 A2P 10DLC 流程、選擇加入訊息流文件、同意層級、隱私政策與條款要求、混合用途活動、註冊層級以及常見被拒原因。也概述免付費電話驗證、WhatsApp WABA 註冊、RCS 導入,以及 STIR/SHAKEN、Voice Integrity、Branded Calling 與 CNAM 等語音信任計畫。
適用情境
在準備傳送 Twilio 簡訊、WhatsApp 或 RCS 流量,或進行可信外撥時使用,用來確認哪些註冊必須先完成。也適用於活動或驗證被拒後需要修正送審資料的情況。這是流量開通前的入門指南,而非傳送或程式開發指南。
執行需求
不需要指令碼或工具,內容僅為說明。文中引用 Twilio 主控台與 API 註冊流程以及外部 Twilio 文件連結,但使用此技能不需要憑證、套件或執行環境。

Overview

Most Twilio channels require registration or approval before traffic flows. Skipping this step is the #1 onboarding mistake — developers build first, then discover messages are blocked or calls labeled as spam.

Lifecycle: Choose numbers/senders (twilio-numbers-senders) → Register them (this skill) → Follow traffic rules (twilio-compliance-traffic)


Decision Tree: What Do I Need to Register?

Messaging Programs

Sender typeRegistration programTimelineDocs
US local (10DLC)A2P 10DLC — brand + campaignBrand: minutes. Campaign: 10-15 business daysOverview | Quickstart
US toll-freeToll-free verification3-5 business daysConsole onboarding | Requirements
US short codePre-approved at purchase8-12 weeks provisioningGuidelines by country | What is a short code?
WhatsAppWABA + Meta Business VerificationMinutes (sender) + weeks (Meta verification)Self sign-up | Getting started
RCSGoogle + carrier approval4-6 weeks minimum, longer multi-regionRCS onboarding | Compliance guide
Alpha Sender IDRegistration in some countriesVaries by countryHow to register
International numbersRegulatory bundle (many countries)VariesGetting started | How to submit
Twilio VerifyExempt — no registration neededImmediate—

Voice Trust Programs

ProgramWhat it doesVetting timelineDocs
STIR/SHAKENLevel A attestation = trusted caller ID24hr (Business Profile) + 72hr (Trust Product)Overview | Onboarding
Voice IntegrityRegisters numbers with carriers to remediate spam labels24-48hr (profile) + 24-48hr (remediation)Overview | Onboarding
Branded Calling (US)Verified name + logo on mobile caller IDPublic Beta (T-Mobile, Verizon)Overview | FAQ
Branded Calling (Non-US)Verified caller ID branding for international numbersAvailability varies by country/carrierOverview
CNAMBusiness name on outbound caller ID48-72hr propagationOverview | Getting started

Voice trust priority: STIR/SHAKEN first (required for Level A attestation) → Voice Integrity (spam label remediation) → Branded Calling (mobile only, beta) → CNAM (simplest, lowest impact). All voice programs require an approved Trust Hub Business Profile as prerequisite.


A2P 10DLC — Deep Dive

A2P 10DLC is the most common program and the most common source of onboarding delays.

Registration Flow

  1. Create Customer Profile — Business identity in Trust Hub (required for all programs)
  2. Register Brand — EIN, business name, address, website. TCR typically approves within minutes. Respond to OTP verification within 24 hours. Brand best practices
  3. Register Campaign — Use case, 2+ sample messages, opt-in proof, privacy policy. Review takes 10-15 business days. Campaign best practices
  4. Associate phone numbers — Link numbers to campaign via Messaging Service

Message Flow (Opt-In Documentation)

The message flow field is the #1 reason campaigns get rejected. Reviewers click your links and follow your opt-in steps. If submitting via API, the field must be 40–2049 characters.

4 required elements:

  1. Description of opt-in method(s) with clear language inviting users to sign up (no pre-checked boxes)
  2. Message frequency (e.g., "Up to 4 msgs/month")
  3. "Message and data rates may apply" disclosure
  4. Link(s) to opt-in image/mockup (must be publicly accessible)

Example of a strong message flow:

"Customers opt in by texting JOIN to 55555, or by checking the SMS opt-in box during checkout at shop.acme.com. The checkout page displays: 'Check this box to receive exclusive deals via text. Up to 4 msgs/month. Message and data rates may apply. Reply STOP to opt out. Reply HELP for help. Privacy Policy: acme.com/privacy. Terms: acme.com/tc.' In-store signage also promotes keyword opt-in with full disclosures. Screenshot of signage: [Google Drive link]"

How to document opt-in by scenario:

ScenarioWhat to provide
Public website formURL to your sign-up page
Form behind login/paywallScreenshot uploaded to Google Drive/OneDrive (set to "anyone with link"), include public link
Verbal/phone opt-inFull script of what you say and how customer confirms consent
Paper formScan/photograph the form, upload publicly, include link
Text keyword campaignScreenshot of marketing materials showing keyword, upload publicly

All links must be publicly accessible. Non-English disclosures need a translated version included.

Consent Requirements

Three tiers of consent (CTIA guidelines):

TierRequired forHow to obtain
Implied consentTransactional messages (order confirmations, account alerts)Customer provides phone number during a transaction
Express consentInformational messages (appointment reminders, service updates)Customer actively opts in (checkbox, keyword, form)
Express written consentMarketing/promotional messagesSigned consent with brand name, message frequency, "Msg & data rates apply," opt-out instructions

Critical rules:

  • Consent is per-campaign. Signing up for order updates does NOT grant consent for promotions. Separate opt-ins required.
  • Consent must be voluntary. If customers must opt in to messaging to complete a purchase or create an account, the registration will be rejected.
  • Brand name must appear in the consent disclosure — generic "you agree to receive texts" is insufficient.

Privacy Policy & Terms and Conditions

Both are required. Registrations without them are rejected.

Privacy policy must include:

  • What data you collect and how it's used
  • That mobile information will NOT be shared with third parties for marketing (CTIA requirement)

Terms and conditions must include:

  • Program/brand name and description
  • "Message and data rates may apply"
  • Message frequency or recurring message disclosure
  • Customer support contact information
  • HELP and STOP opt-out instructions (displayed in bold)
  • Link to privacy policy
  • "Carriers are not liable for any delayed or undelivered messages"

Pro tip: Create messaging-specific privacy policies and terms rather than updating your main company documents. Dedicated policies are easier to keep current if requirements change.

Mixed Use Case Campaigns

If you send both marketing and transactional messages (e.g., order confirmations AND promotions), use the Mixed campaign use case:

  • Select "Mixed" as the campaign use case during registration
  • Allows 2-5 sub-use cases within one campaign (e.g., Customer Care, Marketing, Account Notification, 2FA, PSA)
  • Describe each sub-use case clearly in the campaign description
  • Sample messages must cover each declared sub-use case

Do NOT register separate campaigns for each message type unless they use different phone numbers or have different opt-in flows. Mixed is the intended solution for multi-purpose messaging from the same sender.

Campaign Rejection Gotchas

FieldCommon mistakeCorrect approach
Campaign descriptionVague ("We send texts")Specific ("Order confirmation and shipping updates for e-commerce purchases")
Sample messagesDon't match description or missing opt-outMust reflect declared use case + include opt-out in every sample
Opt-in description"Users sign up on our website""Users check SMS consent checkbox during account registration at checkout.example.com" with link to screenshot
URL shortenersUsing bit.ly linksPublic URL shorteners are forbidden — use branded/vanity domains
Privacy policyStates data IS sharedMust state data is NOT shared with third parties
LinksBehind login or not accessibleAll links must be publicly accessible to reviewers
ConsentSingle opt-in covering all message typesEach sub-use case in a Mixed campaign still needs its own documented opt-in method
Mixed campaignLeaving sub-use cases undescribedEach sub-use case must be explained in description

Failed campaigns can now be edited directly in Console (API editing is private beta).

Registration Tiers

TierDaily segment limit (T-Mobile)Notes
Sole Proprietor~1,000/dayConsole only, 1 campaign, 1 number
Low-Volume Standard~2,000/dayRequires EIN
Standard2,000+ (scales with Trust Score)Requires verified EIN
High-volume (secondary vetting)200,000+/daySecondary vetting

Russell 3000 companies qualify for 200,000 segments/day automatically.

Common Errors

ErrorMeaningFix
30034Message from unregistered numberComplete A2P registration
30007Message filtered as spamCheck opt-in compliance and content
Brand rejectedBusiness info doesn't match EIN recordsTax ID and business name must match exactly

Toll-Free Verification

Required for US/Canada toll-free SMS. Simpler than A2P 10DLC.

  • Submit via Console (Active Numbers → Regulatory Information tab) or API
  • Requires: paid account, Customer Profile, business name, website, use case description, sample message, opt-in type
  • Unverified toll-free numbers cannot send SMS to US/Canada — status shows "Restricted"
  • If rejected: resubmit within 7 days for priority review. After 7 days, number reverts to Restricted and resubmission goes to back of queue
  • ISVs must have an approved Primary Business Profile before submitting for secondary customers
  • 527 political organizations require Campaign Verify tokens before Console submission
  • Don't use multiple toll-free numbers for the same use case ("snowshoeing")

Docs: Console onboarding | Why rejected?


WhatsApp WABA Registration

Self-Signup Flow (Direct Customers)

  1. Console → Messaging → Senders → WhatsApp Senders → "Create new sender"
  2. Select phone number (Twilio or non-Twilio — must not already be registered with WhatsApp)
  3. Click "Continue with Facebook" → Meta Embedded Signup popup
  4. Create or select Meta Business Portfolio
  5. Create or select WABA (all senders on same Twilio account must share one WABA)
  6. Set display name, category, description — Meta reviews display name post-registration
  7. Phone verification via OTP (SMS or voice)
  8. Registration completes within minutes

Post-Registration Requirements

  • Meta Business Verification required before production messaging — can take several weeks
  • If display name rejected by Meta, messaging is limited to 250 messages/24 hours
  • Outbound messages require pre-approved Message Templates (submitted to Meta, 24-48hr approval)
  • Free-form messages only within 24-hour service window after customer initiates

ISV Path

Enroll in Meta's Tech Provider Program to onboard customers. Different flow from self-signup.

Docs: Self sign-up | WhatsApp hub


RCS Onboarding

4-6 weeks minimum. RCS has a detailed 7-part compliance process covering sender profile, privacy/ToS, eligibility, campaign details, opt-in/consent, sample messages, and common rejection reasons.

See twilio-rcs-messaging for the full onboarding guide, sending patterns, and device support.

Quick summary: Create RCS Sender in Console → complete compliance submission → Twilio specialist reviews → Google + carrier approval → add to Messaging Service → go live.

Docs: RCS onboarding | Compliance guide | Regional availability


CANNOT

  • Cannot skip A2P registration for US 10DLC — Mandatory for all senders, no exceptions for small volume
  • Cannot register Sole Proprietor A2P via API — Console only
  • Cannot combine unrelated use cases without Mixed campaign — Use the "Mixed" use case category to register 2-5 sub-use cases under one campaign
  • Cannot require A2P registration for Verify traffic — Twilio Verify is exempt from A2P registration
  • Cannot use voice trust programs without Trust Hub — All voice programs require an approved Trust Hub Primary Customer Profile
  • Cannot use Branded Calling on landlines — Mobile-only. US: Public Beta (T-Mobile, Verizon). Non-US: availability varies by country and carrier — check eligibility for your specific numbers. Use CNAM for landlines.

Next Steps

  • Channel overview and onboarding guide: twilio-messaging-overview
  • Choose the right number type first: twilio-numbers-senders
  • Follow traffic rules after registration: twilio-compliance-traffic
  • Set up Messaging Services for number pools: twilio-messaging-services
  • Send SMS after registration: twilio-sms-send-message
  • Secure your account: twilio-security-hardening

來源與署名

來源:twilio/ai位於skills/twilio/twilio-compliance-onboarding提交8aba46f

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 twilio/ai 的技能

Twilio Voice Twiml

twilio

使用 TwiML 建構 Twilio 語音通話邏輯,涵蓋核心動詞、SDK 產生方式和 IVR 範例。

Software Development2026年10月8日

Twilio Isv Sms Best Practices

twilio

給 ISV 的多租戶 Twilio SMS 建置指南,涵蓋 A2P 與免付費號碼註冊、子帳戶及常見陷阱。

Software Development2026年10月8日

Twilio Security Compliance Hipaa

twilio

指導為 HIPAA 合規設定 Twilio 帳戶,涵蓋 BAA、HIPAA 專案指定、合格服務及各產品要求。

Security2026年10月8日

Twilio Reliability Patterns

twilio

Handle rate limits, retries, and failures when building on Twilio at scale. Covers 429 exponential backoff with jitter, per-number throughput limits, StatusCallback resilience, thin-receiver pattern, and fallback chains. Use this skill whenever sending messages or making calls at volume, or when building production-grade Twilio integrations.

待分類2026年10月8日

Twilio Organizations Setup

twilio

Set up and manage Twilio Organizations for centralized account and user governance. Covers the Organization > Account > Subaccount hierarchy, roles (Owner/Admin/Standard), managed vs independent accounts, domain registration, SSO enforcement, SCIM provisioning, and Organization merging. Use this skill when managing multiple Twilio accounts or users across teams.

待分類2026年10月8日

Twilio Numbers Senders

twilio

指導在開發前選擇合適的 Twilio 號碼類型和傳送者,涵蓋合規計畫、輸送量和可用性。

Communication2026年10月8日