Personal Phone System

PBX

Sign in to your Twilio line. Calls, texts, and voicemail live here โ€” not in a carrier console.

First sign-in uses APP_PASSWORD from .env (not your Twilio password). After that, use your username or Pocket ID SSO if an admin enabled it.

Sign in with Pocket ID
PBX
Offline

Your number

โ€”

Enter a number

Allow microphone access so the browser can ring.

Recent

Recorded calls and live transcriptions land here. Voicemail is on its own tab.

Contacts

Messages

Pick a conversation or start a new text.

SMS to regular phones is not end-to-end encrypted. Twilio and the carrier can read it. PBX encrypts data stored on this server.

Voicemail

Settings

Your account and phone behavior live here. Twilio secrets, users, OIDC, and Cloudflare are on the Admin page.

Account

Leave the password blank to keep the current one. SSO accounts can set a password to also sign in locally.

Appearance

Pick a look for this phone. Most themes are dark; Daylight is the light option.

Quiet hours

Admin

Texts and calls to regular phones cannot be end-to-end encrypted โ€” Twilio and the carrier see them in plaintext. PBX encrypts data at rest on this server, hashes passwords, and keeps API secrets off the browser.

Twilio line

From Twilio Console โ†’ Account โ†’ API keys & tokens paste Account SID (starts with AC) and Auth token. Copy the number from Phone Numbers โ†’ Manage โ†’ Active numbers (or buy one). Save and provision creates the API key (SKโ€ฆ) and TwiML App (APโ€ฆ) used for browser calling โ€” you do not paste those.

Cloudflare Tunnel

Create a token at Cloudflare โ†’ My Profile โ†’ API Tokens with Account Cloudflare Tunnel Edit, Zone Read, and Zone DNS Edit. Account ID is on the right of any account Overview. Type the full hostname Cloudflare should serve โ€” any FQDN, for example phone.example.com. Leave it blank for a quick tunnel. Without a token, Start tunnel still builds a Cloudflare quick tunnel. Named tunnels also appear under Zero Trust โ†’ Networks โ†’ Tunnels.

Enter any FQDN Cloudflare should route here.

Pocket ID / OIDC

Use your self-hosted Pocket ID (or any OpenID Connect provider). In Pocket ID open Settings โ†’ OIDC Clients, create a confidential client (OIDC client docs), paste the redirect URI below exactly, and copy the issuer (Pocket ID APP_URL, no trailing slash), client ID, and client secret here. Confirm the issuer at https://your-pocket-id/.well-known/openid-configuration.

If Pocket ID sends this group name in the groups claim, that user becomes a PBX admin. Existing admins are never demoted.

Favicon

Shown in the browser tab and Home Screen icon. PNG, SVG, ICO, JPEG, WebP, or GIF, under 512 KB.

Users

Call

Unknown

Connecting