> For a complete page index, fetch https://docs.synthflow.ai/llms.txt. For full documentation content, fetch https://docs.synthflow.ai/llms-full.txt.

# Connect over SIP

> Point a SIP trunk from your carrier or PBX at Synthflow, configure transport, codecs, DTMF, and registration, import your numbers, and encrypt calls with TLS and SRTP.

A SIP trunk connects your carrier or PBX to Synthflow, so agents handle calls on numbers you already own. This guide covers any SIP-capable system. If your provider has its own guide in the [telephony integrations overview](/telephony-integrations), follow that one instead.

## Prerequisites

* An Enterprise plan.
* A public IP or SBC hostname for signaling and media.
* SIP credentials, or an IP allow list on your trunk.
* Your workspace's region, under **Admin** → **Workspace Settings** → **Preferences** → **Customer Region**.
* Firewall rules for your region's [signaling and media addresses](/ip-allow-lists#region-addresses).

## SIP addresses

Send inbound calls to the SIP address for your workspace's region. Use the hostname, not the IPs, so failover and maintenance work automatically.

| Region | SIP address           | UDP and TCP port | TLS port |
| ------ | --------------------- | ---------------- | -------- |
| Global | `sip.synthflow.ai`    | `32681`          | `32682`  |
| US     | `sip.us.synthflow.ai` | `32681`          | `32682`  |
| EU     | `sip.eu.synthflow.ai` | `32681`          | `32682`  |

Address each call to the number in E.164 format, for example `sip:+12065551234@sip.us.synthflow.ai:32681`. The number must be imported into Synthflow and assigned to an inbound agent.

## Trunk settings

| Setting      | Supported values                                               |
| ------------ | -------------------------------------------------------------- |
| Transport    | UDP, TCP, or TLS                                               |
| Codecs       | G.711 μ-law, G.711 A-law, Opus                                 |
| DTMF         | RFC 2833 (RTP events), SIP INFO                                |
| Registration | Static (IP-based) or SIP `REGISTER` with digest authentication |
| NAT          | Symmetric NAT, with media pinholes and `rport`                 |

We recommend starting with G.711, which every system supports.

To keep the trunk stable:

* Set SIP timers and keep-alives short enough to hold your NAT bindings open.
* Provide several destination IPs, or a DNS SRV record, for failover.
* Space out retries so a failure does not flood the trunk with requests.

## Number import

Import each number as a custom number, so Synthflow knows how to route calls to and from it. In Synthflow, select **Phone Numbers** → **New Phone Number** → **Import a Custom Number**. [Add a custom number](/phone-numbers#adding-custom-numbers) explains each field, including the outbound proxy and outbound registration.

The import form shows the **Origination URI**: the Synthflow SIP address your carrier or PBX sends calls to, filled in from your workspace region. Then assign the number to an agent.

## Encryption

Synthflow can encrypt both the signaling and the audio of a call.

* **Secure signaling** uses TLS to protect SIP messages, including any custom headers you send.
* **Secure media** uses SRTP to encrypt call audio between your carrier or PBX and Synthflow. It requires secure signaling.

Your carrier or PBX needs:

* A certificate signed by a trusted authority, and TLS 1.2 or later, for secure signaling.
* SRTP-DTLS or SRTP-SDES, and OSRTP ([RFC 8643](https://www.rfc-editor.org/rfc/rfc8643)), for secure media.

To turn it on:

* **Inbound calls:** point your trunk at the TLS port, for example `sip:sip.us.synthflow.ai:32682;transport=tls`.
* **Outbound calls:** set the **Outbound Proxy** on the [custom number](/phone-numbers#adding-custom-numbers) to the TLS address of your carrier or PBX. Secure outbound calls are only available on custom numbers.

On a TLS call, we always try to negotiate SRTP. If your carrier or PBX does not accept it, audio falls back to unencrypted RTP while signaling stays encrypted.

> **Warning**
>
> Media encryption is best-effort. To guarantee it, configure your carrier or PBX to require SRTP and reject unencrypted RTP.

## Integration matrix

Supported settings on common platforms. Some features depend on your platform version and configuration.

| Platform              | Transport | DTMF               | Registration     | NAT traversal | Codecs      |
| --------------------- | --------- | ------------------ | ---------------- | ------------- | ----------- |
| **Asterisk**          | UDP, TCP  | RFC 2833, SIP INFO | Static, REGISTER | Yes           | G.711, Opus |
| **Cisco (CUCM/CUBE)** | UDP, TCP  | RFC 2833           | Static, REGISTER | Yes           | G.711, Opus |
| **Avaya**             | UDP, TCP  | RFC 2833           | Static           | Yes           | G.711       |
| **Genesys**           | UDP, TCP  | RFC 2833           | Static           | Yes           | G.711, Opus |
| **Generic SIP trunk** | UDP, TCP  | RFC 2833, SIP INFO | Static, REGISTER | Yes           | G.711, Opus |