Voice Fraud & Compliance Wiki

    Call Authentication

    SIP Identity Header

    The SIP header that carries the signed PASSporT token proving a call's caller ID was authenticated by the originating provider.

    The Identity header is added to the SIP INVITE by the authentication service. It contains a base64-encoded JWT (the PASSporT) plus parameters pointing to the public certificate used to sign it, the algorithm, and the origination identifier.

    A terminating provider fetches that certificate, validates the signature, checks the certificate chains back to an approved STI-CA, and confirms the signed calling number matches the number actually presented.

    If the header is missing, malformed, expired, or the numbers do not match, verification fails and the call is typically treated as unauthenticated.

    Why it matters to carriers

    Header stripping by intermediate carriers is a common cause of verification failures that look like your fault. Logging Identity headers on both sides of your network is the fastest way to prove where a signature was lost.

    Handling sip identity header on your own switch

    SipShield scores live SIP traffic with patented AI so the controls behind this term run automatically — and leave the audit trail regulators expect.