SHAKEN/STIR Parameters

Telnyx customers can now get more granular information on call attestation and verification results with new… See Telnyx guidance and requirements.

How to interpret SHAKEN/STIR verstat parameters and ensure secure call identity verification

As part of our ongoing efforts to improve the SHAKEN/STIR framework, Telnyx has introduced additional values to the verstat parameter in our SIP headers.

This update provides Telnyx customers with more granular information regarding originating Caller ID attestation and verification results.

The verstat parameter is included in the P-Asserted-Identity SIP header and includes information about the caller identity validation and attestation level.

Previously, the possible values were TN-Validation-Passed, TN-Validation-Failed, or No-TN-Validation depending on verification results of the PASSPorT and attestation level.

This verification is done for inbound calls from the PSTN as well as on-net calls from Telnyx customers to other Telnyx customers.

Introducing two additional verstat values:

  • TN-Validation-Passed-B: Indicates that identity header verification is successful, and the call has a B attestation.
  • TN-Validation-Passed-C: Indicates that identity header verification is successful, and the call has a C attestation.

With these new values, Telnyx customers will have more detailed information about the origin of incoming calls and the level of attestation.

This can be especially useful for customers who need to verify the identity of incoming calls to prevent fraud or for regulatory compliance.

It's important to note that these new verstat values will be included in the SIP headers passed along to Telnyx customers. This means that customers can access this information directly through their own systems and tools.

Note: When using SHAKEN/STIR, the shaken_stir_param controls whether the identity header is present in the B leg, it requires that the following conditions both be true to successfully pass the identity header.

  • shaken_stir_enabled is true (from CPB connection settings — the B-leg)

  • cpb_transport_protocol is "TCP" or "TLS"

Identity headers are not sent over UDP to prevent fragmentation issues.

Verstat Values Summary

Verstat valueDescription
TN-Validation-PassedIdentity header verification is successful, and the caller has an A attestation
TN-Validation-FailedIdentity header verification failed as the certificate Telnyx received was deemed invalid.
No-TN-ValidationNo verification took place because the Identity header was not provided
TN-Validation-Passed-BIdentity header verification is successful, and the caller has a B attestation
TN-Validation-Passed-CIdentity header verification is successful, and the caller has a C attestation

Below you can find a P-Asserted-Identity example:

P-Asserted-Identity:"John Doe"<sip:+18889809750@sip.telnyx.com;verstat=TN-Validation-Passed>

For more information on the SHAKEN/STIR framework and how it works, please visit our resource center.

Related articles

Email Notification: International Spend LimitIn this article we will explain why you may have received this email. See Telnyx guidance and requirements.Calls per second (CPS) surchargeUnderstanding CPS surcharges, their impact, and how Telnyx manages high CPS rates. See Telnyx guidance and requirements.SIP - Record Route HeadersUnderstanding the Importance of Route Headers. See Telnyx guidance and requirements Learn more about SIP - Record Route Headers with Telnyx.TLS and SRTPLearn how TLS and SRTP secure SIP calls, configure encryption, inspect certificates, and troubleshoot secure media negotiation.