SIP Credentials — How Extension Authentication Works
Every extension owns one set of SIP credentials — a username, a generated password, and a server domain — used by every device that registers as that extension. Auto-provisioned desk phones receive them invisibly; you only handle them directly when configuring a third-party softphone, and you can reset them in one click.
The three values
Field | Format | Example |
|---|---|---|
SIP username | extension + account identifier |
|
SIP password | 16-character generated secret | shown in the portal |
Domain / server | your account's registrar address |
|
Find them on the extension's Softphone tab. Transport should be TLS where the client supports it.
When you need them
- Configuring a generic SIP client (a softphone Signal doesn't auto-provision).
- Integrating a SIP-capable appliance (door intercom, paging amplifier) — give each appliance its own extension rather than sharing a person's.
You never need them for supported desk phones or Signal's own apps.
Treat them like passwords — because they are
SIP credentials authorize placing calls that bill to your account. Handle accordingly:
- Share them through a password manager, not email or chat.
- One extension per device-owner; never one credential across a team.
- Reset immediately when a device is lost or a technician with access leaves: extension settings → reset SIP password. Every registered device disconnects until it re-authenticates — auto-provisioned phones recover on their next configuration reload; manual softphones need the new password entered.
- Keep international dialing off for extensions whose credentials live in third-party devices; it caps toll-fraud exposure.
Related articles
Last reviewed August 6, 2026. Still stuck? Contact Signal Support from your portal — include what you expected, what happened instead, and one example phone number or extension.