Alerts by text and email
Owner alerts — Twilio SMS + email, dependency-free & fail-safe
For when the answer to “Text or email me when something breaks” is yes.
Text or email yourself when something matters (an export failed, the shared API key is out of credit) with no npm dependency and no risk to the request path — it never throws, throttles so failures can't spam you, and no-ops when…
Skip the rebuild
You do not write this one. It arrives in your project as ordinary source you can read, change and keep, with its audit record and its caveats beside it.
- Download the Playground. It is free and runs on your own machine.
- Start a new app and tick “Text or email me when something breaks”.
- This block is written in, along with anything else you ticked.
The mistake it removes
The naive version calls Twilio from the wrong place or lets a paging failure crash the very request it was trying to report. And a Twilio auth token in client code is a full-account credential leak.
What is already handled
Each of these was checked by running the code, not by reading it.
- 32 node assertions (counted here: test/notify-kit.test.mjs), all passing, with fetch injected as a mock
- the Twilio REST call is built correctly: Basic auth = base64(sid:token), urlencoded From/To/Body, /2010-04-01/Accounts/<sid>/Messages.json
- sms/email no-op with {skipped} when their channel isn't configured — never a half-built call
- reads TWILIO_*/RESEND_* from env when config isn't passed explicitly
- NEVER throws into the caller: a rejected fetch or a non-2xx returns {ok:false,...} and logs; owner() uses Promise.allSettled so one dead channel can't sink the other
- owner() throttles a second page inside the window (verified with an injected clock) and pages again after it elapses
- owner() is loud-but-harmless when no channel is configured (logs the fix, returns {unconfigured:true})
What the audit found
Named rather than summarized. The reasoning behind each one ships inside the block, so it travels with the code instead of living on a page you have to trust.
- Correctly server-only, but that depends on the installer respecting it minor · Secrets beyond source
- Throttle is per-instance, so serverless can page a little more than once/hr minor · API cost & abuse safety
What you still have to do
A copied file cannot own your secrets, your host or your legal obligations. This is the part the block deliberately does not claim.
- Keep this on the server and out of every client bundle. A Twilio auth token is a full-account credential; there is deliberately no vanilla build, but nothing stops a host importing the module into browser code.
- A shared-store throttle, or spend caps set in the Twilio and Resend dashboards. The throttle here is in-memory per warm serverless instance, so a cold start may send one extra page and a fleet sends one per instance.
- TWILIO_AUTH_TOKEN and RESEND_API_KEY must come from your host's environment or secret manager. The block reads them from env; it does not store, rotate or scope them.
- Twilio and Resend are paid/rate-limited services; a page still costs a fraction of a cent and counts against their limits. The throttle bounds it, honeypot/abuse paths shouldn't call owner() per request.
- isCreditError is an Anthropic-specific example predicate — swap it for whatever condition should page you.
What lands in your project
node
- node/notify.js
createNotifier(config?) -> { sms, email, owner, smsConfigured, emailConfigured }. Also exports isCreditError(status, msg). Reads TWILIO_*/RESEND_* from env by default, or pass explicit config. Dependency-free (raw REST + fetch).
What you supply
- TWILIO_ACCOUNT_SID / TWILIO_AUTH_TOKEN / TWILIO_FROM — your Twilio creds + sending number (+15551234567)
- ALERT_SMS_TO — the phone that gets the text
- RESEND_API_KEY / EMAIL_FROM / ALERT_EMAIL_TO — optional email channel (Resend)
- throttleMs — min gap between owner() pages (default 1 hour)
Licensed MIT. It is a starting point, not a finished product.
Get it
Download the Playground See the other blocks
Nothing here is locked. The files are yours, in your folder, under a permissive license.
Questions
- Is Alerts by text and email audited?
- Yes. A full due-diligence audit was run on 2026-07-18 and the verdict was a pass.
- What do I still have to do myself?
- Keep this on the server and out of every client bundle. A Twilio auth token is a full-account credential; there is deliberately no vanilla build, but nothing stops a host importing the module into browser code.
- How do I get this code?
- Download the Playground, start a new app, and tick “Text or email me when something breaks”. The block is written into your project as ordinary source you can read and edit.
All pre-built code blocks · Learn to build from zero · The coding guide