Create the trunk
- Dashboard: Phone Numbers → SIP Endpoints → Create SIP Endpoint, choose Username and password, name it and pick the agent that answers. Only workspace owners and admins can create one.
- API: POST /sip-endpoints with
"auth_mode": "credentials", using a key withsip_endpoints:manage.
403 SIP_TRUNKS_NOT_ENABLED: ask Yappr
support to switch them on.
GET /sip-endpoints/status tells you whether
you can create one right now.
The password is shown once, right after you create the trunk. Copy it into your
phone system, or a password manager, before you close the panel: neither the
dashboard nor the API can show it again. If it is lost,
issue a new one.
Each trunk answers with one agent. To send calls to different agents, create a
trunk for each.
Each trunk takes 2 calls at once unless you change its limit
(max_concurrent_calls, 1 to 8). One call more is refused with 486 Busy Here, so
your phone system can try its next route.
If your workspace’s inbound calling hours are
switched on (inbound_enabled), they apply to trunk calls too: outside them, every
call to the trunk is refused with 603 Decline, including after-hours calls your
phone system sends to the agent. If the trunk takes after-hours calls, widen those
hours or switch inbound calling hours off.
What to enter in your phone system
The server, backups, transports and registration are also in every trunk’s
sip_connection in the API.
Register, or send keep-alives
When the agent ends a call, Yappr’s hang-up has to travel back to your phone system: over TLS or TCP on the connection your system opened, over UDP through your router or firewall. The server keeps a quiet connection open, but some phone systems close their own after about 30 seconds without traffic, and routers and firewalls forget a quiet UDP path, some within a minute. Once that path has closed, the hang-up never arrives, and the caller stays on a silent line until they hang up themselves. To keep the path open:- Over TLS or TCP: register the trunk with its username and password, or send keep-alives every 30 seconds or less. Either keeps the connection open.
- Over UDP behind NAT or a firewall: send keep-alives every 30 seconds or less, even if your system registers. A registration is refreshed only every few minutes, too seldom to keep a UDP path open.
OPTIONS requests, often called qualify or heartbeat (in
Asterisk, qualify_frequency; in FreePBX, Qualify Frequency; in FreeSWITCH,
ping). If a firewall in front of your system only lets known traffic in, also
allow SIP from the server’s addresses (see firewalls).
Then check it once: make a test call of at least two minutes, let the agent end it,
and make sure your system hangs up too. A shorter call can end correctly even with
no keep-alives at all.
When the same system also uses another Telnyx trunk
If the same phone system or IP address also sends calls to another Telnyx trunk, or you send from a cloud platform whose addresses other customers share, add the headerX-Telnyx-Username: <your username> to this trunk’s calls, so that each call
is matched to this trunk. If your system can’t add headers, put the username in the
user part of its Contact header instead.
Plivo, Sinch and Infobip send calls from addresses other customers share, and
document no way to do either. If another Telnyx customer’s trunk is tied to one of
those addresses, a call can land on that trunk instead of reaching your agent. Yappr
hasn’t tested this yet, so ask Yappr support to test your route with you before you
send real calls over it.
TLS certificates
Most phone systems trust the server’s certificate out of the box. If yours only trusts root certificates you upload (3CX does, for example), upload both:- DigiCert Global Root G2, which signs the
sip.telnyx.comandsip.telnyx.eucertificates today; - ISRG Root X1 (Let’s Encrypt), which signs
sip.telnyx.me, and will signsip.telnyx.euandsip.telnyx.comtoo once Telnyx moves them on 12 and 13 November 2026.
Firewalls
If a firewall in front of your phone system only lets known traffic through, allow:- SIP to and from the server you send to (on its side, TLS 5061, TCP or UDP
5060): the agent’s hang-up comes from it.
sip.telnyx.comis 192.76.120.10 and 64.16.250.10,sip.telnyx.euis 185.246.41.140 and 185.246.41.141, andsip.telnyx.meis 185.246.42.128 and 185.246.42.129. - Media (RTP) to and from Telnyx’s media networks below, which use UDP ports 16384 to 32768 on their side. The media can come from a different address than the SIP server.
https://sip.telnyx.com/voice.json.
What your phone system hears back
Answered calls use your workspace’s credit, like other calls to your agents. A
call refused before it is answered costs nothing.
Before you switch a trunk off or delete it, re-route its calls in your phone system.
A switched-off trunk still looks available to your system (it can still register),
but every call to it is refused with
603 Decline, and not every system tries its
next route after that.
Transfers
Transfers to a person aren’t available yet on calls that arrive over a SIP trunk. If the agent tries one, nothing is dialled: the caller stays with the agent, which is told that this call can’t be transferred, and the call’s events record atransfer_failed with error_code UNAVAILABLE_ON_SIP_TRUNK.
If some callers must be able to reach a person, handle it in your phone system:
send the trunk only calls the agent can finish, or forward the calls that may need a
person to one of your workspace’s
Yappr phone numbers over the phone network
instead, where transfers work.
Change the password
Issue a new password in the dashboard (the trunk’s Change password, owners and admins) or with the API. The old one stops working within seconds, and calls already in progress are not dropped. If your phone system registers, enter the new password before its next registration refresh, or that refresh fails. To switch with no gap at all, create a second trunk on the same agent, move your phone system to it, then delete the old trunk.Platforms
These platforms document that they answer a username-and-password challenge on the calls they send, so they can use a trunk. The rows namesip.telnyx.com; from
Israel or Europe, enter sip.telnyx.eu instead, as the server and as the realm.
Whatever the platform, keep the path open where it offers a setting for it, as
described above: over UDP behind NAT or a firewall,
that means keep-alives every 30 seconds or less. Then check with a test call of at
least two minutes that the agent ends.
These can’t answer that challenge on the calls they send:
- Twilio Elastic SIP Trunking (origination). Use Twilio Programmable Voice
instead: point the number at TwiML with the
<Dial><Sip>above. - Vonage, Bandwidth, Five9, Amazon Connect, RingCentral, Zendesk Talk.
- Calls routed by your own Telnyx account (Call Control, TeXML or call forwarding): Telnyx doesn’t sign in to a trunk with its username and password when it routes a call there. Send those numbers to a SIP address endpoint instead.
- Microsoft Teams Direct Routing and Zoom Phone, except through your own SBC (AudioCodes, Ribbon, Oracle or Cisco CUBE above), which then sends the calls to the trunk.
- add the trunk on your own PBX and route the calls through it;
- or forward the calls to a Yappr phone number;
- or, if it can send calls to a plain SIP address, use a SIP address endpoint
(
auth_mode: "uri"), whose address is its only secret.
Security
- A call needs the trunk’s username and password. A wrong one is refused before the call reaches Yappr.
- The password is shown only when you create the trunk or issue a new one. Yappr does not keep a copy.
- Calls sent to a trunk reach its agent and no one else, and a trunk can’t be used to place calls. Emergency numbers never reach the agent: keep them off the trunk (see the warning above).
- Even with a leaked password, a trunk takes no more calls at once than its
max_concurrent_calls. - Only workspace owners and admins can create, change or delete a trunk, or issue a
new password, in the dashboard. API keys need
sip_endpoints:manage. A key withsip_endpoints:readalone lists endpoints without passwords, without trunk usernames (sip_usernameisnull) and without SIP addresses (slugandsip_uriarenull). - Your phone system sets the caller’s number, so Yappr does not use it to recognize returning callers (lead memory) on these calls.
- If the password may have leaked, issue a new one. To stop the trunk for a while,
turn it off (
is_active: false); to stop it for good, delete it. Either way, re-route its calls in your phone system first.