PPact
Voice MCP

Authentication

How Voice MCP authenticates callers — a DTMF PIN for unknown callers, and a texted one-time code before a recognized caller can send, merge, or launch.

Voice MCP authenticates callers so that a phone call can act on your CRM. Two controls are live: a PIN for callers the system doesn't recognize, and a texted one-time code before a recognized caller can do something that can't be taken back.

PIN for unknown callers

When an unrecognized caller reaches the line and your workspace has the "require PIN for unknown callers" control enabled, the agent prompts for a PIN. The caller enters it on the dial pad (DTMF), Pact verifies it, and — on success — marks the caller authenticated for the session.

This is the live caller-auth control

The DTMF PIN prompt for unknown callers is enforced on the live call path. Turn it on from your voice admin settings, and set per-user PINs there as well.

One-time code for consequential actions

A recognized caller is identified by caller ID, and caller ID can be spoofed. So when your workspace's voice_otp_required setting is on (the default), Pact texts a six-digit code to the phone number on the caller's profile before it will, by voice:

  • send an email, a text message, or a calendar invitation to someone outside your workspace;
  • book a meeting, because the invitation goes to the attendee;
  • launch a campaign;
  • merge duplicate records.

The caller reads the code back (dial-pad entry works only on the keypad-menu line for now). A correct code verifies them for the rest of the call and the action carries on; three wrong codes for one text lock verification for that call, and nothing is done. Saying "one second" while the text arrives is treated as waiting, not as a wrong code. Looking things up, Slack posts, and ordinary edits never ask for a code, and a caller who entered their PIN is already verified.

A few older voice paths that can reach someone outside your workspace are not behind the code yet; Admin → Voice security names them.

Fail-closed by design

A missing configuration row, a NULL value, or a lookup error all resolve to "code required," and there is no environment-variable override. If a code can't be sent — no phone on the caller's profile, no SMS sender connected, the per-number limit reached — the action is refused with the reason, never silently allowed. Admins can turn the setting off for demo or test workspaces; see Admin → Voice security.

What's next