SMS (Twilio)

TWILIO_SID=ACxxxxxxxxxxxxx
TWILIO_TOKEN=your_auth_token
TWILIO_FROM=+1555XXXXXXX        # your A2P-10DLC-registered number, or MGxxx Messaging Service SID

A2P-10DLC registration is the Operator's responsibility. Register your brand and campaign in the Twilio Console before enabling SMS for tenants. Using an unregistered number results in carrier filtering.

The Diagnostics → A2P SMS sender probe will:

  • FAIL if TWILIO_SID / TWILIO_TOKEN / TWILIO_FROM are not set.
  • FAIL if prior sends produced a 401/403 (credentials revoked). Clear the dead-credential flag: php artisan tinker --execute "\App\Models\AppSetting::remove('sms.credentials.dead');" after rotating keys.
  • WARN if TWILIO_WEBHOOK_SKIP_VALIDATION=true (remove this in production — it disables inbound STOP/HELP signature validation).

Inbound keyword behaviour

Customer texts Effect
STOP, UNSUBSCRIBE, CANCEL, END, QUIT Opts the phone number out of all SMS (transactional included). Does not cancel appointments — only marketing consent / SMS delivery.
START, UNSTOP Clears a prior STOP so SMS can resume.
HELP, INFO Returns a short help line (requires a valid webhook signature when TWILIO_TOKEN is set).

If TWILIO_TOKEN is empty, unsigned inbound STOP requests are logged and ignored (no suppression is written). Configure TWILIO_TOKEN and point Twilio's inbound webhook at POST /webhooks/sms/inbound/{tenant} before relying on keyword opt-out.