30921: Campaign rejected: Website requires authentication and cannot be reviewed
Your A2P 10DLC campaign registration was rejected because the website URL you submitted requires a login or other authentication to review. Reviewers must be able to access and verify your business website and consent flow without credentials. If your opt-in mechanism or other required details are not publicly accessible at the website URL you provide, submit a publicly accessible URL that hosts screenshots of the relevant pages.
- The website URL points to a page that requires a username, password, single sign-on, or another authentication step before reviewers can view the content.
- The URL points to an internal tool, staging site, admin portal, or development environment that is not publicly accessible. Twilio requires a verifiable, publicly accessible opt-in method for campaign review.
- The website does not expose the business details, opt-in flow, or required disclosures in a way reviewers can verify.
- Submit a publicly accessible website URL that reviewers can open without signing in.
- If your opt-in flow or required information is behind a login or not yet live, provide a publicly accessible URL with hosted screenshots of the relevant pages in your
message_flowor Call to Action details. - If you use a development website that is not live, provide a publicly accessible video or other publicly accessible proof that shows the opt-in process.
- Make sure the submission clearly shows how end users consent to receive messages and includes any required public links, such as your privacy policy and terms of service when the website is used for opt-in.
- If your primary product experience is gated, create a public page that explains your business and messaging program so reviewers can verify the campaign. If the actual opt-in flow remains gated, add publicly accessible screenshots of that flow.
Run through this list before submitting or resubmitting your campaign:
message_flownames every opt-in method used for this campaign (website, keyword, paper form, verbal, QR code, or other mechanism).message_flowincludes a link to your privacy policy and a link to your terms and conditions.- Your privacy policy states that mobile numbers are not shared with third parties, includes message frequency, and includes a "message and data rates may apply" disclosure.
- If opt-in happens on a website, the URL is publicly accessible. If it is not public, you have provided a URL with hosted screenshots of the full consent flow.
- If end users opt in by texting a keyword,
opt_in_keywordsandopt_in_messageare populated. Theopt_in_messageincludes the brand name, confirmation of enrollment, message frequency, and opt-out instructions. - If the campaign uses multiple opt-in paths, all paths are described in the same
message_flowfield. - Sample messages match the declared use case, identify the brand by name, and include opt-out language.
- The website URL loads without a login, password, single sign-on, or other authentication requirement.
- If the opt-in flow is behind a login, you have provided a publicly accessible URL with hosted screenshots of the relevant pages.
Warning
The following submission would be rejected:
A URL that redirects to a login page before reviewers can view the business or consent content.
Reviewers cannot verify your business or opt-in flow without publicly accessible content.
Info
The following submission would pass review:
Provide a public landing page at www.acmesandwich.com that explains the business and messaging program. If the opt-in flow itself is behind a login, host screenshots of the consent screen at www.acmesandwich.com/sms-consent-evidence and include that URL in message_flow.
Passes because reviewers can verify both the business identity and the consent flow from publicly accessible URLs.