Skip to contentSkip to navigationSkip to topbar
Page toolsOn this pageProducts used
Looking for more inspiration?Visit the
Error
Application error

30921: Campaign rejected: Website requires authentication and cannot be reviewed

Twilio Messaging DocumentationMessaging
Twilio Phone Numbers DocumentationPhone Numbers

Description

description page anchor

Your A2P 10DLC campaign registration was rejected because the website URL you submitted requires a login or other authentication to review. Reviewers must be able to access and verify your business website and consent flow without credentials. If your opt-in mechanism or other required details are not publicly accessible at the website URL you provide, submit a publicly accessible URL that hosts screenshots of the relevant pages.

Possible causes

possible-causes page anchor
  • The website URL points to a page that requires a username, password, single sign-on, or another authentication step before reviewers can view the content.
  • The URL points to an internal tool, staging site, admin portal, or development environment that is not publicly accessible. Twilio requires a verifiable, publicly accessible opt-in method for campaign review.
  • The website does not expose the business details, opt-in flow, or required disclosures in a way reviewers can verify.
  • Submit a publicly accessible website URL that reviewers can open without signing in.
  • If your opt-in flow or required information is behind a login or not yet live, provide a publicly accessible URL with hosted screenshots of the relevant pages in your message_flow or Call to Action details.
  • If you use a development website that is not live, provide a publicly accessible video or other publicly accessible proof that shows the opt-in process.
  • Make sure the submission clearly shows how end users consent to receive messages and includes any required public links, such as your privacy policy and terms of service when the website is used for opt-in.
  • If your primary product experience is gated, create a public page that explains your business and messaging program so reviewers can verify the campaign. If the actual opt-in flow remains gated, add publicly accessible screenshots of that flow.

Pre-submission checklist

pre-submission-checklist page anchor

Run through this list before submitting or resubmitting your campaign:

  • message_flow names every opt-in method used for this campaign (website, keyword, paper form, verbal, QR code, or other mechanism).
  • message_flow includes a link to your privacy policy and a link to your terms and conditions.
  • Your privacy policy states that mobile numbers are not shared with third parties, includes message frequency, and includes a "message and data rates may apply" disclosure.
  • If opt-in happens on a website, the URL is publicly accessible. If it is not public, you have provided a URL with hosted screenshots of the full consent flow.
  • If end users opt in by texting a keyword, opt_in_keywords and opt_in_message are populated. The opt_in_message includes the brand name, confirmation of enrollment, message frequency, and opt-out instructions.
  • If the campaign uses multiple opt-in paths, all paths are described in the same message_flow field.
  • Sample messages match the declared use case, identify the brand by name, and include opt-out language.
  • The website URL loads without a login, password, single sign-on, or other authentication requirement.
  • If the opt-in flow is behind a login, you have provided a publicly accessible URL with hosted screenshots of the relevant pages.

Website requires authentication

website-requires-authentication page anchor
(warning)

Warning

The following submission would be rejected:

A URL that redirects to a login page before reviewers can view the business or consent content.

Reviewers cannot verify your business or opt-in flow without publicly accessible content.

(information)

Info

The following submission would pass review:

Provide a public landing page at www.acmesandwich.com that explains the business and messaging program. If the opt-in flow itself is behind a login, host screenshots of the consent screen at www.acmesandwich.com/sms-consent-evidence and include that URL in message_flow.

Passes because reviewers can verify both the business identity and the consent flow from publicly accessible URLs.