Messages from every account's own carrier sub-account are accepted

Signature verification resolves whichever carrier account actually signed the request, instead of only trusting the platform's own.

What it is

A widened but still strict verification path. The account id present on every provider webhook is used to find the credentials that should have signed it; the signature must then verify against those. This covers texts and calls on per-builder sub-accounts, browser-originated calls, and callbacks that carry no phone numbers at all.

Also called: texts stopped arriving · 11200 error · webhook rejected · recordings never showed up

See it
Messages from every account's own carrier sub-account are accepted
Prepared for
Marlin Hoover
1140 Ridge Line Rd · Fair Play
Shell package$33,325
Concrete & site$9,675
Doors & windows$6,450
Trim & finish$4,300
Total
$53,750
Signature
Diagram: webhook → try platform token → try number's account → match AccountSid to a binding → verify or 403. Sample data — no customer information appears here.
How it works
  1. 1The platform's own token is tried first, then the token of the account that owns the called number
  2. 2Failing that, the account id in the request body is matched against stored provider bindings and that account's token is tried
  3. 3For browser calls the client identity carries the account, so that account's credentials are used
  4. 4This widens WHICH token may verify a request, never whether a request must be verified at all
Why we built it

Each account has its own carrier sub-account, and only the platform's own was trusted to sign incoming requests — which broke three things silently at once. Every inbound text to a builder's number was rejected and never reached the thread, while the person who sent it saw it send fine; every call recording was refused, so recording was switched on and not one call had a recording; and every browser call failed, with the caller hearing "an application error has occurred". Signature verification now resolves whichever carrier account actually signed the request.

The problem
  • Inbound traffic on per-account carrier sub-accounts silently rejected
  • Callbacks without phone numbers unverifiable
  • Browser calls rejected by the platform's own security check
Sound familiar?
What you get
Every account's messages and calls reach the platform
Security stays mandatory — only the set of valid signers widened

See it on your own jobs

Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.

or keep browsing features →