Voice Fraud & Compliance Wiki

    Call Authentication

    PASSporTPersonal Assertion Token

    The signed JSON Web Token inside the Identity header that asserts the calling number, called number, attestation level, and origination identifier.

    A PASSporT carries a header (algorithm, token type, certificate URL) and a payload with the origination and destination numbers, an issued-at timestamp, the attestation level, and an origid that uniquely identifies the originating customer.

    Timestamps matter: most verification services reject a PASSporT older than 60 seconds, which is why clock drift on a signing server can silently break authentication network-wide.

    Extended PASSporT types carry additional data — 'rcd' for Rich Call Data such as a display name and logo, and 'div' for calls that were diverted or forwarded.

    Why it matters to carriers

    The origid inside the PASSporT is what lets a traceback investigation identify which of your customers originated a specific illegal call, so it must map to real, verified customer records.

    Handling passport on your own switch

    SipShield scores live SIP traffic with patented AI so the controls behind this term run automatically — and leave the audit trail regulators expect.