Connect over SIP
A SIP trunk connects your carrier or PBX to Synthflow, so agents handle calls on numbers you already own. This guide covers any SIP-capable system. If your provider has its own guide in the telephony integrations overview, follow that one instead.
Prerequisites
- An Enterprise plan.
- A public IP or SBC hostname for signaling and media.
- SIP credentials, or an IP allow list on your trunk.
- Your workspace’s region, under Admin → Workspace Settings → Preferences → Customer Region.
- Firewall rules for your region’s signaling and media addresses.
SIP addresses
Send inbound calls to the SIP address for your workspace’s region. Use the hostname, not the IPs, so failover and maintenance work automatically.
Address each call to the number in E.164 format, for example sip:+12065551234@sip.us.synthflow.ai:32681. The number must be imported into Synthflow and assigned to an inbound agent.
Trunk settings
We recommend starting with G.711, which every system supports.
To keep the trunk stable:
- Set SIP timers and keep-alives short enough to hold your NAT bindings open.
- Provide several destination IPs, or a DNS SRV record, for failover.
- Space out retries so a failure does not flood the trunk with requests.
Number import
Import each number as a custom number, so Synthflow knows how to route calls to and from it. In Synthflow, select Phone Numbers → New Phone Number → Import a Custom Number. Add a custom number explains each field, including the outbound proxy and outbound registration.
The import form shows the Origination URI: the Synthflow SIP address your carrier or PBX sends calls to, filled in from your workspace region. Then assign the number to an agent.
Encryption
Synthflow can encrypt both the signaling and the audio of a call.
- Secure signaling uses TLS to protect SIP messages, including any custom headers you send.
- Secure media uses SRTP to encrypt call audio between your carrier or PBX and Synthflow. It requires secure signaling.
Your carrier or PBX needs:
- A certificate signed by a trusted authority, and TLS 1.2 or later, for secure signaling.
- SRTP-DTLS or SRTP-SDES, and OSRTP (RFC 8643), for secure media.
To turn it on:
- Inbound calls: point your trunk at the TLS port, for example
sip:sip.us.synthflow.ai:32682;transport=tls. - Outbound calls: set the Outbound Proxy on the custom number to the TLS address of your carrier or PBX. Secure outbound calls are only available on custom numbers.
On a TLS call, we always try to negotiate SRTP. If your carrier or PBX does not accept it, audio falls back to unencrypted RTP while signaling stays encrypted.
Media encryption is best-effort. To guarantee it, configure your carrier or PBX to require SRTP and reject unencrypted RTP.
Integration matrix
Supported settings on common platforms. Some features depend on your platform version and configuration.