Academy → Messaging ChannelsOfficial documentation · Arabic guidance

SMS (Twilio)

الرسائل النصية عبر Twilio

Intermediate to advanced5 min readLesson 143 questions✓ 2026-08-18
Before you read

What this page is, and what it holds.

This page covers SMS (Twilio). It carries a source warning and takes about 5 minutes to read. Open the channel to yourself first with an allowlist. An open channel means anyone can message your agent.

9sections
10code examples
1tables
2commands
783source words
The official one-line description

Set up Hermes Agent as an SMS chatbot via Twilio

What you will be able to do

Outcomes taken from this page, not a template.

  • Understand what بوابة المراسلة is and when you need it.
  • Run hermes gateway and hermes gateway setup and understand what happens next.
  • Read the table and take only the row that applies to you.
  • Set TWILIO_ACCOUNT_SID in the right place.
Identifiers you will meet

Exactly as they appear in Hermes.

Commands
  • hermes gateway
  • hermes gateway setup
Environment variables
  • TWILIO_ACCOUNT_SID
  • TWILIO_AUTH_TOKEN
  • TWILIO_PHONE_NUMBER
  • SMS_ALLOWED_USERS
  • SMS_HOME_CHANNEL
  • SMS_WEBHOOK_URL
  • SMS_WEBHOOK_PORT
  • SMS_INSECURE_NO_SIGNATURE
Page map

Jump to the part you need.

  1. 01Prerequisites
  2. 02Step 1: Get Your Twilio Credentials
  3. 03Step 2: Configure Hermes
  4. 04Step 3: Configure Twilio Webhook
  5. 05Step 4: Start the Gateway
  6. 06Environment Variables
  7. 07SMS-Specific Behavior
  8. 08Security
  9. 09Troubleshooting
The full official page

Nothing summarised away.

The documentation body below is reproduced from the official source so commands and identifiers stay exact. Each section carries a short note describing what it contains.

Hermes connects to SMS through the Twilio ↗ API. People text your Twilio phone number and get AI responses back — same conversational experience as Telegram or Discord, but over standard text messages.

---

Prerequisites

Explains the idea itself. Read it slowly; the later sections build on it.

  • Twilio account — Sign up at twilio.com ↗ (free trial available)
  • A Twilio phone number with SMS capability
  • A publicly accessible server — Twilio sends webhooks to your server when SMS arrives
  • aiohttp — cd ~/.hermes/hermes-agent && uv pip install -e ".[sms]"

---

Step 1: Get Your Twilio Credentials

Ordered, practical steps. Run one and confirm it worked before moving on.

  1. Go to the Twilio Console ↗
  2. Copy your Account SID and Auth Token from the dashboard
  3. Go to Phone Numbers → Manage → Active Numbers — note your phone number in E.164 format (e.g., +15551234567)

---

Step 2: Configure Hermes

Ordered, practical steps. Run one and confirm it worked before moving on. Commands here: hermes gateway setup.

Shell1 line
hermes gateway setup

Select SMS (Twilio) from the platform list. The wizard will prompt for your credentials.

Manual setup

Add to ~/.hermes/.env:

Shell9 lines
TWILIO_ACCOUNT_SID=ACxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
TWILIO_AUTH_TOKEN=your_auth_token_here
TWILIO_PHONE_NUMBER=+15551234567

# Security: restrict to specific phone numbers (recommended)
SMS_ALLOWED_USERS=+15559876543,+15551112222

# Optional: set a home channel for cron job delivery
SMS_HOME_CHANNEL=+15559876543

---

Step 3: Configure Twilio Webhook

Ordered, practical steps. Run one and confirm it worked before moving on.

Twilio needs to know where to send incoming messages. In the Twilio Console ↗:

  1. Go to Phone Numbers → Manage → Active Numbers
  2. Click your phone number
  3. Under Messaging → A MESSAGE COMES IN, set:
  4. Webhook: https://your-server:8080/webhooks/twilio
  5. HTTP Method: POST

Set SMS_WEBHOOK_URL to the same URL you configured in Twilio. This is required for Twilio signature validation — the adapter will refuse to start without it:

Shell2 lines
# Must match the webhook URL in your Twilio Console
SMS_WEBHOOK_URL=https://your-server:8080/webhooks/twilio

The webhook port defaults to 8080. Override with:

Shell1 line
SMS_WEBHOOK_PORT=3000

---

Step 4: Start the Gateway

Ordered, practical steps. Run one and confirm it worked before moving on. Commands here: hermes gateway.

Shell1 line
hermes gateway

You should see:

Text1 line
[sms] Twilio webhook server listening on 127.0.0.1:8080, from: +1555***4567

If you see Refusing to start: SMS_WEBHOOK_URL is required, set SMS_WEBHOOK_URL to the public URL configured in your Twilio Console (see Step 3).

Text your Twilio number — Hermes will respond via SMS.

---

Environment Variables

A lookup table. Do not read it all; find the row that applies to you.

VariableRequiredDescription
TWILIO_ACCOUNT_SIDYesTwilio Account SID (starts with AC)
TWILIO_AUTH_TOKENYesTwilio Auth Token (also used for webhook signature validation)
TWILIO_PHONE_NUMBERYesYour Twilio phone number (E.164 format)
SMS_WEBHOOK_URLYesPublic URL for Twilio signature validation — must match the webhook URL in your Twilio Console
SMS_WEBHOOK_PORTNoWebhook listener port (default: 8080)
SMS_WEBHOOK_HOSTNoWebhook bind address (default: 127.0.0.1)
SMS_INSECURE_NO_SIGNATURENoSet to true to disable signature validation (local dev only — not for production)
SMS_ALLOWED_USERSNoComma-separated E.164 phone numbers allowed to chat
SMS_ALLOW_ALL_USERSNoSet to true to allow anyone (not recommended)
SMS_HOME_CHANNELNoPhone number for cron job / notification delivery
SMS_HOME_CHANNEL_NAMENoDisplay name for the home channel (default: Home)

---

SMS-Specific Behavior

Explains the idea itself. Read it slowly; the later sections build on it.

  • Plain text only — Markdown is automatically stripped since SMS renders it as literal characters
  • 1600 character limit — Longer responses are split across multiple messages at natural boundaries (newlines, then spaces)
  • Echo prevention — Messages from your own Twilio number are ignored to prevent loops
  • Phone number redaction — Phone numbers are redacted in logs for privacy

---

Security

Carries a warning. Read it before running anything here. The upstream warning appears below.

Webhook signature validation

Hermes validates that inbound webhooks genuinely originate from Twilio by verifying the X-Twilio-Signature header (HMAC-SHA1). This prevents attackers from injecting forged messages.

SMS_WEBHOOK_URL is required. Set it to the public URL configured in your Twilio Console. The adapter will refuse to start without it.

For local development without a public URL, you can disable validation:

Shell2 lines
# Local dev only — NOT for production
SMS_INSECURE_NO_SIGNATURE=true

User allowlists

The gateway denies all users by default. Configure an allowlist:

Shell5 lines
# Recommended: restrict to specific phone numbers
SMS_ALLOWED_USERS=+15559876543,+15551112222

# Or allow all (NOT recommended for bots with terminal access)
SMS_ALLOW_ALL_USERS=true

---

Troubleshooting

A troubleshooting section. Find the symptom that matches yours rather than reading it end to end.

Messages not arriving

  1. Check your Twilio webhook URL is correct and publicly accessible
  2. Verify TWILIO_ACCOUNT_SID and TWILIO_AUTH_TOKEN are correct
  3. Check the Twilio Console → Monitor → Logs → Messaging for delivery errors
  4. Ensure your phone number is in SMS_ALLOWED_USERS (or SMS_ALLOW_ALL_USERS=true)

Replies not sending

  1. Check TWILIO_PHONE_NUMBER is set correctly (E.164 format with +)
  2. Verify your Twilio account has SMS-capable numbers
  3. Check Hermes gateway logs for Twilio API errors

Webhook port conflicts

If port 8080 is already in use, change it:

Shell1 line
SMS_WEBHOOK_PORT=3001

Update the webhook URL in Twilio Console to match.

Knowledge check

3 questions answered by this page alone.

Every option is a real identifier from the Hermes documentation. The wrong ones are real too, just from other pages.

1. Which of these environment variables actually appears in this lesson?
2. Which warning does the source state in this lesson?
3. Which of these headings does not appear in this lesson?