STIR/SHAKEN PASSporT Decoder

Paste a SIP Identity header or a bare PASSporT token. This decodes every claim, checks it against the SHAKEN profile, flags the things that actually break attestation in production, and tells you what a terminating carrier would stamp as verstat.

What this does and does not do. Everything runs in your browser, so nothing you paste is uploaded anywhere. What it checks is the structure and claims of the token. What it does not check is the signature, because verifying that means fetching the certificate from the x5u URL and walking the chain back to a trusted STI-CA, which is a verification service’s job (STI-VS). The practical consequence is worth stating plainly: a token can come back clean on this page and still fail verification on a real network. Use it to rule out the structural faults, not to certify a token.

Identity header or PASSporT token
Decode & check
Load sample
Clear

Attestation levels, and what they actually mean

Level Name The originating provider asserts Typical use
A Full attestation It knows the customer and confirmed their right to use the calling number. Retail subscribers on numbers you issued and authenticated.
B Partial attestation It knows the customer, but cannot confirm the calling number is theirs. Wholesale or transit where origin is known but the number is not verifiable.
C Gateway attestation It only knows where it received the call from, and nothing about the caller. International gateway or untrusted peering ingress.

The thing to hold onto: attestation is asserted at origination, and nobody re-judges it at termination. It is not a quality score. An A-level call still fails verification if the signature or certificate is bad, and a C-level call passes if the signature is sound. Those two facts surprise people more than anything else here.

What verstat means on the terminating side

Value Meaning Do not confuse it with
TN-Validation-Passed An Identity header was present and the signature and certificate validated. A verdict on the caller. A C-level call passes too, if its signature is sound.
TN-Validation-Failed A token was present but did not validate: bad signature, untrusted or expired certificate, or a stale iat. Not the same as no-validation. Something was wrong.
No-TN-Validation There was nothing to check, because the call arrived unsigned. Treating this as “failed” flags enormous volumes of legitimate traffic.

Need per-call attestation control?

Most deployments need to sign different traffic differently, and a static per-trunk setting cannot do that. ProSBC treats attestation as a routing decision instead, so one SBC signs your retail traffic A, wholesale B and gateway C, with your choice of signing provider and failover if it goes down. See how it works.

By submitting this form, your information will be processed in accordance with our Privacy Policy.