STIR/SHAKEN PASSporT Decoder
Paste a SIP Identity header or a bare PASSporT token. This decodes every claim, checks it against the SHAKEN profile, flags the things that actually break attestation in production, and tells you what a terminating carrier would stamp as verstat.
What this does and does not do. Everything runs in your browser, so nothing you paste is uploaded anywhere. What it checks is the structure and claims of the token. What it does not check is the signature, because verifying that means fetching the certificate from the x5u URL and walking the chain back to a trusted STI-CA, which is a verification service’s job (STI-VS). The practical consequence is worth stating plainly: a token can come back clean on this page and still fail verification on a real network. Use it to rule out the structural faults, not to certify a token.
Attestation levels, and what they actually mean
| Level | Name | The originating provider asserts | Typical use |
|---|---|---|---|
| A | Full attestation | It knows the customer and confirmed their right to use the calling number. | Retail subscribers on numbers you issued and authenticated. |
| B | Partial attestation | It knows the customer, but cannot confirm the calling number is theirs. | Wholesale or transit where origin is known but the number is not verifiable. |
| C | Gateway attestation | It only knows where it received the call from, and nothing about the caller. | International gateway or untrusted peering ingress. |
The thing to hold onto: attestation is asserted at origination, and nobody re-judges it at termination. It is not a quality score. An A-level call still fails verification if the signature or certificate is bad, and a C-level call passes if the signature is sound. Those two facts surprise people more than anything else here.
What verstat means on the terminating side
| Value | Meaning | Do not confuse it with |
|---|---|---|
TN-Validation-Passed |
An Identity header was present and the signature and certificate validated. | A verdict on the caller. A C-level call passes too, if its signature is sound. |
TN-Validation-Failed |
A token was present but did not validate: bad signature, untrusted or expired certificate, or a stale iat. |
Not the same as no-validation. Something was wrong. |
No-TN-Validation |
There was nothing to check, because the call arrived unsigned. | Treating this as “failed” flags enormous volumes of legitimate traffic. |
Need per-call attestation control?
Most deployments need to sign different traffic differently, and a static per-trunk setting cannot do that. ProSBC treats attestation as a routing decision instead, so one SBC signs your retail traffic A, wholesale B and gateway C, with your choice of signing provider and failover if it goes down. See how it works.
By submitting this form, your information will be processed in accordance with our Privacy Policy.
Prefer to get hands-on first? Build a free ProSBC lab and test it yourself.