# Transactional SMS updates

Optional Twilio Messaging Service for consented individual updates and service reminders, opt-out suppression, local quiet hours and verified delivery state.

## Install

Use the verified installer in the website container. It installs dependencies, checks checksums, and refuses to replace customer changes:

```sh
python /opt/runalio/catalog_install.py sms-notifications
python /opt/runalio/catalog_install.py --status
```

Review the preview and click Publish to promote backend code and pages. Production data remains separate.

To undo the last installation before publishing: `python /opt/runalio/catalog_install.py --rollback`.

## Settings

The customer enters these in Runalio, Settings → Website modules → this module (never in files or chat):

| Name | Required | Secret | Purpose |
|---|---|---|---|
| `TWILIO_ACCOUNT_SID` | yes | no | Twilio Account SID beginning AC. |
| `TWILIO_API_KEY` | yes | yes | Server API Key SID beginning SK. Use a restricted messaging key when available. |
| `TWILIO_API_SECRET` | yes | yes | The API key secret; never the account auth token. |
| `TWILIO_MESSAGING_SERVICE_SID` | yes | no | Registered Messaging Service SID beginning MG. Configure advanced opt-out in Twilio. |
| `SMS_ENABLED` | yes | no | yes to enable transactional SMS; no to pause. Preview never sends SMS. |
| `BUSINESS_TIMEZONE` | no | no | IANA time zone for local schedules and messaging, such as America/Chicago. |

## What the customer needs to do

- Use a Twilio account, API key and registered Messaging Service with advanced opt-out enabled.
- Record each recipient’s actual transactional consent and local time zone in Business admin.
- Review sender/registration requirements in Twilio before enabling. Customer-provider charges are separate; messages run only from production.
- Only individual transactional updates are included. Provider timeouts become unknown, requiring reconciliation before any resend.

## Administration and data

Business admin opens from the portal Settings. Managed websites use portal team membership and same-origin mutation checks. Customer data stays in the website SQLite database and participates in consistent backups. Agent changes to source and page snippets remain drafts until Publish. No customer credentials are embedded in pages or chat.
