Skip to content
CAI
Software that uses CAICheck a score

twilio/twilio-ruby

62.4

Adequate · 19 September 2026

5.6k

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is the official Ruby SDK for the Twilio API, providing a client library to interact with Twilio's communication services. It handles core operations such as managing accounts, making calls, sending SMS/MMS, and generating TwiML responses, while supporting modern authentication methods like OAuth 2.0 alongside legacy credentials. The library includes utilities for webhook signature validation, JWT token generation for various Twilio products, and robust HTTP request handling with regional routing and pagination support.

How it got here

2009–2011 — Library restructuring and API modernization

8 changes.

The project underwent a significant architectural shift, replacing a monolithic entry point with a modular, autoload-based structure and introducing a dedicated configuration block. This period also focused on modernizing the API surface by adding new V1 resources for accounts and credentials while deprecating legacy methods, alongside routine dependency updates and cleanup of version control artifacts.

2012–2015 — SDK framework and security overhaul

9 changes.

This period focused on modernizing the Twilio Ruby SDK by replacing the HTTP layer with Faraday and introducing a robust core framework for request handling and serialization. Significant work was also dedicated to security, specifically implementing Rack middleware for webhook authentication, alongside comprehensive RSpec test coverage for the new components.

2016–2017 — JWT and TwiML refactoring

9 changes.

This period focused on rewriting the TwiML generation library to use Nokogiri and a block-based DSL, while introducing a centralized architecture for JWT token generation across multiple Twilio services. Comprehensive test suites were added to cover the new JWT capabilities, TwiML responses, request validation, and HTTP client behavior. The development workflow was also improved by adding a pre-commit hook to enforce test execution.

2021–2025 — REST framework and OAuth 2.0 overhaul

5 changes.

This period focused on a comprehensive rewrite of the REST client framework, introducing token-based pagination, metadata support, and regional URI handling. It also integrated OAuth 2.0 client credentials authentication as a modern alternative to legacy methods, accompanied by extensive integration tests for the new API capabilities.

Features

Added Twilio webhook authentication middleware

A new Rack middleware, \Rack::TwilioWebhookAuthentication\, has been introduced to validate incoming Twilio webhook signatures. It checks the \X-Twilio-Signature\ header against the request URL and parameters using a provided auth token (or a dynamic lookup based on \AccountSid\). Requests to protected paths that fail validation are rejected with a 403 status. The middleware also handles edge cases such as percent-encoded paths and dot-segments to ensure robust path matching.

lib/rack · high confidence

Initial project scaffolding and configuration

The repository has been initialized with essential configuration files, including a Dockerfile for building the image, a Makefile for build and test automation, and RuboCop configuration files (.rubocop.yml, .rubocop\_todo.yml) to enforce code style. Standard documentation and contribution guidelines (README.md, CONTRIBUTING.md, CODE\_OF\_CONDUCT.md, UPGRADE.md) and issue/PR templates have also been added.

(repo-wide) · high confidence

Introduction of OAuth 2.0 client credentials authentication strategy

The library now supports authenticating via OAuth 2.0 client credentials. This change introduces a new \AuthStrategy\ abstraction and specific implementations for token-based authentication (\TokenAuthStrategy\) and no-auth scenarios (\NoAuthStrategy\). It adds credential providers (\OrgsCredentialProvider\ and \ClientCredentialProvider\) that manage client IDs and secrets, utilizing internal token managers to fetch and cache access tokens. Users can now configure the client to use organization-level tokens or standard client credentials flow instead of relying solely on legacy Account SID and Auth Token methods.

_lib/twilio-ruby/auth\strategy, lib/twilio-ruby/credential · high confidence

New Accounts V1 API resources for credentials, consents, and contacts

The \lib/twilio-ruby/rest/accounts\ module now includes a generated V1 API implementation, adding support for managing AWS and public key credentials, bulk messaging consents, bulk contacts, messaging geopermissions, and safelists. The legacy top-level methods (\auth\_token\_promotion\, \credentials\, \secondary\_auth\_token\) are retained but deprecated, warning users to migrate to the new \v1\ namespace (e.g., \client.accounts.v1.credentials\).

lib/twilio-ruby/rest · high confidence

New Ruby SDK usage examples for core APIs and OAuth

Added three new example scripts demonstrating how to use the Twilio Ruby SDK. examples/examples.rb provides a comprehensive reference for managing accounts, calls, SMS/MMS (including media\_url), phone numbers, conferences, and queues. examples/print\_call\_log.rb shows how to iterate through paginated call logs. examples/public\_oauth.rb demonstrates authenticating with public OAuth using ClientCredentialProvider.

examples · high confidence

Removals

Removed Subversion metadata files

The Subversion version-control metadata (\.svn\ directory and associated property files) has been removed from the package directory. This cleanup eliminates version-control artifacts from the distributed package, ensuring a cleaner file structure for users.

pkg · high confidence

Behavioural changes

Library restructured with new configuration and autoload system

The library has been refactored to replace the legacy monolithic entry point with a modular structure. Users now configure the client via a dedicated \Twilio.configure\ block that sets a \Configuration\ object, supporting global settings like \account\_sid\, \auth\_token\, \region\, and \edge\. The main entry file (\lib/twilio-ruby.rb\) uses \autoload\ for major components (JWT, TwiML, HTTP, REST) to improve load performance, and conditionally loads Rack webhook authentication only when the Rack gem is present.

lib · high confidence

Library version bump to 7.11.2 and deprecation of utility methods

The twilio-ruby library has been updated to version 7.11.2. This release introduces deprecation warnings for the \Twilio::Util::url\_encode\ and \Twilio::Util::get\_string\ methods, alerting users that these utilities are no longer recommended for use. The change also includes structural updates to the library's autoload mechanism for HTTP and REST components.

lib/twilio-ruby · high confidence

New ClientBase class with regional/edge URI handling and automatic Content-Type headers

The library introduces a new \ClientBase\ class in \lib/twilio-ruby/base\ that centralizes API request logic. This change adds support for regional and edge processing by automatically modifying request URIs based on configured region and edge settings, ensuring requests are routed to the correct Twilio endpoints. Additionally, the client now automatically sets the \Content-Type\ header to \application/x-www-form-urlencoded\ for POST and PUT requests when not explicitly provided, and includes a new method to validate SSL certificates against Twilio's test endpoint.

lib/twilio-ruby/base · high confidence

New HTTP client implementation with Faraday and token managers

The HTTP layer has been replaced with a new implementation using the Faraday library. The new \Twilio::HTTP::Client\ supports proxy configuration (protocol, address, port, and credentials), global timeout settings, and allows users to inject custom connection configurations via a \configure\_connection\ method. It also introduces \ClientTokenManager\ and \OrgTokenManager\ classes to handle OAuth 2.0 token fetching for public and private OAuth flows, respectively.

lib/twilio-ruby/http · high confidence

New JWT token generation classes for Access Tokens, Client Capabilities, and Task Router

The library introduces a new JWT generation architecture in the \lib/twilio-ruby/jwt\ directory, featuring \AccessToken\, \ClientCapability\, and \TaskRouterCapability\ classes that inherit from a common \BaseJWT\ base class. \AccessToken\ supports granular grants for Chat, Voice, Sync, Video, and TaskRouter services, including specific features like the \region\ header and \incoming\_allow\ for Voice. \ClientCapability\ handles client scopes (incoming, outgoing, and event streams), while \TaskRouterCapability\ manages workspace policies and web socket policies. This refactoring centralizes JWT logic and expands supported Twilio product integrations.

lib/twilio-ruby/jwt · high confidence

New REST framework with token pagination and metadata support

The \lib/twilio-ruby/framework/rest\ directory now contains a complete, new REST client implementation. This introduces token-based pagination via the new \TokenPage\ class, allowing users to navigate large result sets using page tokens. It also adds a \PageMetadata\ class to expose raw response metadata alongside records. The framework now supports the HTTP PATCH method for partial updates, in addition to existing GET, POST, PUT, and DELETE operations. Error handling has been redesigned with specific \RestError\ and \RestErrorV10\ classes to provide detailed error messages, codes, and status information. Additionally, the \Version\ class now provides \stream\ and \stream\_with\_metadata\ methods for iterating through records, and the \Domain\ class handles URL construction and request dispatching.

lib/twilio-ruby/framework/rest · high confidence

New framework components for request handling, serialization, and value management

This change introduces four new core framework files that underpin the library's API interaction capabilities. The \Request\ class now encapsulates HTTP request details and provides a \to\_s\ method to generate cURL-compatible command strings for debugging. The \Response\ class handles HTTP responses, automatically parsing JSON bodies and normalizing empty responses. A new \Serialize\ module adds utilities for converting dates and datetimes to ISO 8601 formats, flattening nested hashes for query parameters, and serializing complex objects. Finally, the \Values\ module introduces an \:unset\ sentinel value mechanism, allowing the library to distinguish between explicitly passed \nil\ values and omitted parameters during request construction.

lib/twilio-ruby/framework · high confidence

Pre-commit hook now runs tests

A new pre-commit hook has been added to the repository. It automatically executes the test suite (via \make test\) before every commit, ensuring that tests pass before code is committed.

githooks · high confidence

Request validation now supports URLs with and without explicit ports

The RequestValidator now validates Twilio request signatures against both the URL with the standard port included and the URL with the port removed. This ensures signature verification succeeds regardless of whether the incoming request URL includes an explicit port number, addressing inconsistencies in how backends generate signatures.

lib/twilio-ruby/security · high confidence

TwiML generation rewritten to use Nokogiri and support block-based DSL

The TwiML library has been completely rewritten to replace the previous libxml dependency with Nokogiri for XML generation. This change introduces a new, block-based DSL for building TwiML responses (VoiceResponse, MessagingResponse, FaxResponse), allowing developers to nest elements and configure options using Ruby blocks. The new implementation also adds support for adding comments and text nodes to responses, allows generic child tags, and ensures that non-snake\_case parameters are correctly handled during XML serialization.

lib/twilio-ruby/twiml · high confidence

Test coverage

Added Holodeck and Hologram test helper classes; Added RSpec test suite and test configuration; Added integration tests for Twilio API capabilities; Added test coverage for HTTP client behavior; Added test coverage for JWT token generation and capability scopes; Added test coverage for REST framework error handling, pagination, and token-based paging; Added test coverage for TwiML Messaging and Voice Response generators; Added test coverage for framework request handling, serialization, and versioned API actions; Added tests for REST client configuration, SSL validation, logging, and regional/edge URL handling; Added tests for Rack webhook authentication middleware; Added tests for RequestValidator configuration and signature validation; Added tests for configuration attributes and date URL encoding; Removed legacy SVN metadata and test files.

Dependencies

Update runtime and development dependencies for twilio-ruby 7.11.2

The twilio-ruby gem (version 7.11.2) updates its core runtime dependencies to faraday (\>= 2.0, \< 3.0), jwt (\>= 1.5, \< 4.0), and nokogiri (\>= 1.6, \< 2.0). Development dependencies have also been refreshed, including the addition of rubocop (1.71.2) for linting and the pinning of rspec (\~\> 3.0), while maintaining support for Ruby versions \>= 2.0.0.

(dependencies) · high confidence

Housekeeping

Removed Subversion metadata from lib directory

The .svn control directories and their contents (such as all-wcprops, entries, format, and text-base files) have been deleted from the lib directory. This cleanup removes version-control metadata artifacts, leaving only the source code files (e.g., twilio.rb) without the associated Subversion working-copy data.

lib/.svn · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 62.

Lenses

  • Code Health 99
  • Architecture 95
  • Maturity 54
  • Readiness 58
  • Security 68

Changes since last survey

  • 300 commits — 276 feature/other, 24 fixes

By area

  • (root) — 135 commits
  • lib/twilio-ruby — 135 commits
  • .github/workflows — 17 commits
  • spec/integration — 4 commits
  • (repo) — 1 commit
  • .github/ISSUE_TEMPLATE — 1 commit
  • cluster/cluster_oauth_spec.rb — 1 commit
  • conf/cacert.pem — 1 commit
  • lib/rack — 1 commit
  • lib/twilio-ruby.rb — 1 commit
  • spec/rest — 1 commit
  • spec/security — 1 commit
  • spec/twiml — 1 commit

Notable commits

  • fix: Fix local jump error due to lack of block passing for recording list (#665)
  • fix: added bug report issue template (#740)
  • fix: chore: bug fix (#726)
  • fix: chore: bug fix (#727)
  • fix: chore: fix documentation link (#725)
  • fix: chore: fix test failures (#763)
  • fix: fix: Make RequestValidator#validate fail if URL has no query params
  • fix: fix: Only require twilio_webhook_authentication if Rack version > 2 (#606)
  • fix: fix: Regional API domain processing (#765)
  • fix: fix: Retrieval of OS Info with Ruby Config for User Agent string (#607)
  • fix: fix: Reverse edge processing (#779)
  • fix: fix: avoid JSON::ParserError for all server errors (#582)
  • fix: fix: bug fix (#770)
  • fix: fix: correct the docker tag syntax for RCs
  • fix: fix: fix the headers issue (#671)
  • fix: fix: fixed query param not going for delete (#693)
  • fix: fix: match only against the end of a file path. (#654)
  • fix: fix: remove ruby version (#673)
  • fix: fix: revert setting ruby version (#672)
  • fix: fix: update gem
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

twilio/twilio-ruby was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c87a7b40a4445c70528f8135ac78bcb7db647008 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.