Skip to content

STIR/SHAKEN

STIR/SHAKEN is a pair of IETF specifications for cryptographically signing and verifying the calling number on SIP calls - STIR (Secure Telephony Identity Revisited) and SHAKEN (Signature-based Handling of Asserted information using toKENs), defined in RFC 8224 and RFC 8588. Together they let a terminating carrier confirm that the calling number in a call was authorized by the originating provider, which is the basis for caller-ID “verified” indicators and for combating illegal spoofing and robocalls.

This page configures the system-wide behavior. You must also enable STIR/SHAKEN on each trunk where you want to verify or sign calls (see Trunks → STIR/SHAKEN).

How it works

  • Outbound (signing/authentication). When enabled on a trunk, the system adds a SIP Identity header to outbound INVITEs. The header is a token signed with your private key and carries an attestation level and a pointer to your public key URL, where the far end downloads the certificate to verify the signature.
  • Inbound (verification). When enabled on a trunk, the system reads the Identity header on incoming calls, downloads the originator’s public key, and validates the signature. The verification result (verstat) can then be surfaced to agents and used in routing.

Attestation levels

The signer asserts one of three levels, which the terminating side can display or act on:

  • A - Full attestation. The provider authenticates the caller and confirms they are authorized to use the calling number (for example your own DID on your own trunk).
  • B - Partial attestation. The provider authenticates the caller but cannot confirm they own the calling number (for example calls from a downstream PBX).
  • C - Gateway attestation. The provider originated the call onto the network but cannot authenticate its source (for example an international or wholesale gateway).

System-wide settings

Enable STIR/SHAKEN support. Master switch for STIR/SHAKEN on this system. This must be on for any per-trunk signing or verification to take effect.

Identity Header Expiration (sec). How long a generated Identity header remains valid. After this time the token is considered expired by the receiving side, so keep it long enough to cover normal call setup but short enough to limit replay.

Public Key Download Timeout (sec). Maximum time the system waits when downloading a remote public key during inbound verification. If the key cannot be fetched within this window, verification fails.

Enable Public Key Caching. When enabled, downloaded public keys are cached so repeated calls from the same originator do not require a fresh download each time, reducing latency and load.

Public Key Expiration (sec). How long a cached public key is kept before it is refreshed (shown when caching is enabled).

Per-trunk configuration

On each trunk’s STIR/SHAKEN tab:

  • Check Identity of Inbound Calls - verify the Identity header on calls arriving on this trunk. Paste the carrier-provided validation key into Key for validating Identity Header.
  • Create Identity for Outbound Calls - sign calls leaving on this trunk. Set the Attestation Level (A/B/C), the Public Key URL where your certificate is published, and paste your Private Key used to sign the header.

Certificates and keys are issued by an authorized certification authority under the STIR/SHAKEN governance framework (in the US, via the STI-PA / STI-CA process). Your carrier will tell you whether they expect signed calls, which attestation to use, and how to publish your public key.