Call Authentication
The SIP header that carries the signed PASSporT token proving a call's caller ID was authenticated by the originating provider.
The Identity header is added to the SIP INVITE by the authentication service. It contains a base64-encoded JWT (the PASSporT) plus parameters pointing to the public certificate used to sign it, the algorithm, and the origination identifier.
A terminating provider fetches that certificate, validates the signature, checks the certificate chains back to an approved STI-CA, and confirms the signed calling number matches the number actually presented.
If the header is missing, malformed, expired, or the numbers do not match, verification fails and the call is typically treated as unauthenticated.
Header stripping by intermediate carriers is a common cause of verification failures that look like your fault. Logging Identity headers on both sides of your network is the fastest way to prove where a signature was lost.
The FCC-mandated framework that cryptographically signs calling numbers so terminating carriers can verify the caller ID was not spoofed.
The signed JSON Web Token inside the Identity header that asserts the calling number, called number, attestation level, and origination identifier.
The signaling protocol used to set up, modify, and tear down voice and video calls over IP networks.
The terminating-side service that validates a call's signature and returns a verification status used for call display and analytics.
SipShield scores live SIP traffic with patented AI so the controls behind this term run automatically — and leave the audit trail regulators expect.