Bring Your Own Token (BYOT) lets you use your own STIR/SHAKEN certificate to sign outbound calls placed through Convoso. This gives your business more direct control over call authentication, token lifecycle, and carrier trust. If no BYOT token is selected for an outbound trunk, Convoso uses its default STIR/SHAKEN token.
BYOT applies to outbound trunks. It is not used for inbound-only trunks.
In the current phase of BYOT, customers provide the token materials and public certificate URL, and Convoso makes the token available in the platform for assignment.
Before you begin
Make sure you have the following:
Your STIR/SHAKEN certificate package from your Certificate Authority (CA)
The certificate’s public key and private key
A customer-hosted public URL for the certificate, such as an AWS S3 link
The outbound trunk in Convoso that should use the token
The public certificate URL must be hosted and maintained by your team. Convoso uses that URL as part of the signing process.
How BYOT works in Convoso
Once your token has been made available in Convoso, you can assign it to an outbound trunk. Convoso then uses that selected token to sign outbound calls for that trunk.
If no token is selected, Convoso uses its default STIR/SHAKEN token.
If an active token is selected and not expired, outbound calls are signed with your token.
If a token is marked inactive, it is treated as revoked.
If a token has passed its expiration date, you should provide a refreshed token.
Overview
In the STIR/SHAKEN framework, call attestation determines whether a call is delivered to a consumer's handset as "Verified," which can have bearing on analytics such as being labeled as "Spam Likely," or blocked entirely. Telemarketing and outbound contact centers often face attestation downgrades (B or C attestation) when relying solely on default intermediate carrier signing.
To overcome this, enterprises and telemarketing firms can leverage Bring Your Own Token (BYOT) / Delegate Certificate models. This brief details the multi-step regulatory and technical workflow: how telemarketing firms partner with regulated carriers to acquire an SPC (Service Provider Code) token, and how Convoso utilizes that token to issue digital certificates and sign outbound calls directly on their behalf.
how getting a token works
Navigating the Carrier-Token Relationship
How Convoso Executes Call Signing
- Token Ingestion & ACME Certificate Generation
- Dynamic PASSporT Construction & SIP Signing
- Maintenance & Automated Lifecycle Management
- Key Business Benefits for Telemarketing Clients
Guidance for Convoso Customers: Navigating the Carrier-Token Request Process
- A: Internal Preparation (Vetting Readiness)
- B: Pitching the Carrier
- C: Formalizing the Delegation Agreement
- D: Onboarding the Token into Convoso
Navigating the Carrier-Token Relationship
The Regulatory Barrier
Under Federal Communications Commission (FCC) rules and Secure Telephone Identity Governance Authority (STI-GA) guidelines, an enterprise/telemarketing company cannot directly apply for an SPC token or STIR/SHAKEN certificate on its own.
To be eligible for an SPC token from the Secure Telephone Identity Policy Administrator (STI-PA), a company must meet three (3) strict criteria:
- Be a registered FCC Form 499-A filer.
- Possess an assigned Operating Company Number (OCN).
- Maintain direct access to telephone numbers via NANPA or operate as an approved Voice Service Provider (VSP).
The Carrier Approach Strategy
Because Outbound Call Centers typically do not meet 499-A/OCN requirements, the company must approach a Partner Carrier (Service Provider) through a Sponsoring Carrier/Delegate Relationship:
-
KYC & Vetting Compliance:
The telemarketing company submits to rigorous Know Your Customer (KYC) and Know Your Upstream Provider (KYUP) vetting with a Partner Carrier.- They must demonstrate Legal Caller ID ownership, Brand Authorization, and Explicit Consent mechanisms for their Lead Lists.
-
Requesting the Token Delegation:
Once vetted, the Carrier requests an SPC Token (or an authorized Delegate/Authority Token) from the STI-PA tied to the numbers/traffic assigned to the client. -
Token Hand-off:
The Carrier provides the signed, cryptographic SPC JSON Token to the client (or directly provisions access) to establish authorized delegation.
How Convoso Executes Call Signing
Once the client secures the Token from their Partner Carrier, Convoso serves as the Signing Engine / Dialing Platform to complete end-to-end Call Authentication.
┌────────────────────────┐ 1. Partner Vetting ┌─────────────────────────┐
│ Telemarketing Company │─────────────────────────────>│ Sponsoring Voice Carrier│
└───────────┬────────────┘ └────────────┬────────────┘
│ │
│ 2. Issues SPC Token / Authority │ 3. Requests Token
▼ ▼
┌────────────────────────┐ ┌─────────────────────────┐
│ Convoso Dialing │ │ STI-PA / STI-CA Engine │
│ Platform │◄─────────────────────────────┴─────────────────────────┘
└───────────┬────────────┘ 4. Generates Certificate via ACME Protocol
│
│ 5. Places Outbound Call with PASSporT / SIP Identity Header
▼
┌────────────────────────┐
│ Terminating Carriers │ ───> Full "A" Attestation Delivered to Consumer
└────────────────────────┘
Token Ingestion & ACME Certificate Generation
- The customer inputs their Carrier-provided SPC Token into Convoso's compliance framework.
- Convoso connects to an approved Secure Telephone Identity Certificate Authority (STI-CA) via the ACME protocol.
- Convoso presents the customer's SPC token alongside a generated Certificate Signing Request (CSR).
- The STI-CA validates the token and issues a STIR/SHAKEN Digital Certificate specifically authorized to sign calls for those numbers.
Dynamic PASSporT Construction & SIP Signing
When an agent or automated dialer places an outbound call through Convoso:
-
Identity Header Creation:
Convoso’s SIP engine intercepts the outbound call initiation and builds a STIR/SHAKEN PASSporT (JSON Web Token). -
Cryptographic Signature:
Convoso uses the private key corresponding to the generated STIR/SHAKEN certificate to digitally sign the call’s SIP header in real time. -
Attestation Elevation:
Because the call is signed directly with a validated certificate mapped to verified numbers, the call achieves Full "A" Attestation.
Maintenance & Automated Lifecycle Management
STIR/SHAKEN certificates are designed with short life cycles (often 24 hours to 7 days) to limit security exposure. Convoso’s automated management handling ensures:
- Automated ACME token validation and silent certificate renewals.
- Zero disruption to live dialing campaigns.
Key Business Benefits for Telemarketing Clients
-
Maximizing Connect Rates:
Eliminates Spam Likely or Unverified flags on call-recipient screens by delivering cryptographic proof of Caller ID legitimacy. -
Brand Protection:
Prevents bad actors from spoofing the telemarketing company's dedicated phone numbers. -
Regulatory Alignment:
Keeps outbound dialing fully compliant with FCC STIR/SHAKEN mandates while allowing high-volume dialing through Convoso.
Navigating the Carrier-Token Request Process
As a Convoso customer preparing to implement Bring Your Own Token (BYOT) / Delegate Certificate signing, your first major milestone is securing an SPC (Service Provider Code) token from a partner carrier. Because telemarketing entities and non-499 filers cannot request tokens directly from the STI-PA, you must establish a sponsoring carrier relationship.
Use the following step-by-step recommendation to approach your carrier and successfully secure a token.
A: Internal Preparation (Vetting Readiness)
Before reaching out to your carrier, assemble a Trust & Compliance Dossier. Carriers will only grant token delegation if you pass their Know Your Customer (KYC) and Know Your Upstream Provider (KYUP) audits.
What to prepare:
-
Proof of DID Ownership/Right to Use:
Documentation proving you own or lease the specific outbound telephone numbers (DIDs) you intend to sign. -
Lead Generation & Consent Proof:
Samples of your opt-in workflows, landing pages, and proof of consent (e.g., Jornaya or TrustedForm tokens) demonstrating TCPA compliance. -
FCN & Business Registration:
Corporate registration details, EIN, and primary operating address. -
FCC Robocall Mitigation Database (RMD) Status:
If applicable, proof of your organization’s standing or compliance filings.
B: Pitching the Carrier
Contact your Account Executive, Compliance Manager, or Network Operations Lead at your origination/underlying voice carrier.
Frame Your Request
Carriers want to ensure their delegated tokens are not used to sign illegal traffic. Frame your request around traffic transparency, brand protection, and compliance execution:
"We are implementing a BYOT / Delegate Certificate workflow with Convoso to handle end-to-end STIR/SHAKEN signing for our outbound campaigns. To support this, we need [Carrier Name] to issue/delegate an SPC authority token for the DID blocks assigned to our account."
Key Points to Emphasize with the Carrier
-
Scope of Numbers:
Emphasize that the token delegation will be strictly bound to the specific DIDs provisioned by that Carrier. -
Convoso’s Compliance Architecture:
Inform them that Convoso acts as the signing engine via secure ACME protocol connections to an authorized STI-CA. -
Traceability & Auditing:
Clarify that all signed calls retain full traceback visibility back to your business, protecting the Carrier’s network reputation.
C: Formalizing the Delegation Agreement
Carriers will typically require a formal Delegate Certificate Agreement or Third-Party Signing Addendum. Review the following provisions during contract execution:
-
Token Scope & Expiration:
Ensure the Carrier provisions an active SPC Token (or Authorization Delegate Token) with clear guidelines on renewal intervals. -
Service Level Agreements (SLAs):
Ensure the Carrier agrees to assist in maintaining token validity so your certificate generation within Convoso remains uninterrupted. -
Revocation Terms:
Understand the conditions under which the Carrier reserves the right to revoke token access (e.g., elevated spam complaints or traceback requests).
D: Onboarding the Token into Convoso
Once the carrier approves your request and generates your signed JSON token file:
-
Secure Hand-off:
Securely transfer the JSON token payload provided by your Carrier. -
Convoso Integration:
Submit the token into your Convoso administrative dashboard. -
Automated ACME Handshake:
Convoso will automatically initiate an ACME challenge against a STIR/SHAKEN Certificate Authority (STI-CA) using your Carrier Token, generate your company-specific certificate, and begin signing outbound calls with Full "A" Attestation.
CRITICAL REGULATORY & TECHNICAL REQUIREMENT
DID Provisioning & Attestation Responsibility: The carrier providing the token must also be the voice provider issuing and hosting those specific DIDs.
Under STIR/SHAKEN framework rules, attestation levels (A vs. B) are determined directly by the token-issuing carrier’s relationship to the telephone numbers. The carrier issuing the token holds joint regulatory and legal responsibility (alongside your enterprise) for the attestation tier assigned to those signed calls and any downstream traceback requests.