Connect Twilio and test SMS delivery.
Channels & providers contains the administrator-only Twilio credential form and an explicit Send test SMS action. Saving provider settings does not turn on SMS, enable an automation, or send a message. Do not write the underlying options directly.
Access and dependencies
- Open GymCore Admin > Communications & Automations > Channels & providers with
gymcore_manage_communicationsor the administrator fallbackmanage_options. - Name the Twilio account owner, approved credential workflow, sending number or Messaging Service, consented test destination, maintenance window, and rollback owner.
- Treat the Auth Token as a secret. Do not paste it into tickets, screenshots, lead notes, documentation, or test-message content.
Current product boundary
The old sms Settings alias redirects to Channels & providers. Only a site administrator with manage_options can view or change Twilio credentials. Other communications managers can see provider status but not credential values or the test control.
The test action sends one real SMS to the billing phone on the current administrator profile after an explicit confirmation. It does not activate the SMS channel or any automation. A saved configuration or accepted test request is not proof of carrier delivery.
Safe procedure
-
Open Channels & providers as a site administrator and record the current provider status without exposing credentials.
-
Enter the Twilio account SID, Auth Token, and either a Messaging Service SID or a From number, then select Save Twilio settings.
Expected: The page confirms that settings were saved. This does not enable SMS or an automation.
-
Rotate an exposed token at Twilio first. Keep the old/rollback path only as allowed by the provider owner and maintenance plan.
-
Confirm the current administrator profile has a staff-owned billing phone, then select Send test SMS once and accept the explicit confirmation.
Expected: GymCore reports the test request result. The action sends one real SMS only to that billing phone.
-
Compare the GymCore result with Twilio’s message SID, destination, sender/service, timestamp, and final status.
Expected: Channels & providers reports readiness and Twilio reports the final message status. A local accepted response is not carrier delivery.
Recover
Disable the approved sending workflow before investigating unexpected sends. Revoke an exposed token at Twilio. Do not repeatedly retry an ambiguous message, and do not claim rollback until both GymCore and Twilio show the intended state.
Source-reviewed against: Gym Core 2.1.0 integrated source and the 2026-07-28 feature/settings inventory. No installed provider delivery is claimed.
Need help?
Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.