
Helene Vigue outlines how new network capabilities will strengthen online security
Online authentication has reached a watershed. As fraudsters increasingly try to access users’ online accounts and payments channels, service providers need to further strengthen their defences. Building on the success of one-time passcodes (OTPs) delivered by SMS, the mobile industry is now rolling out a new and even more robust mechanism to authenticate people logging into apps and web sites.
Having addressed the limitations of its predecessor, version 2 of the CAMARA Number Verification API provides a swift and reliable way for an app or a web site to verify in real-time that an incoming user’s handset is currently associated with the phone number of the user. Although the API queries the user’s mobile operator, it works over all kinds of connections, including Wi-Fi. That means consumers can still easily authenticate themselves in places where there is no mobile signal, such as deep inside a building.
For mobile network operators and their customers, this approach to authentication provides a secure, dependable, and frictionless solution that will help reduce fraud and errors. In short, there is now a clear technology path that both mobile operators and device suppliers can get behind. The Number Verification API is one of a portfolio of standardised APIs, which have widespread support from the industry.
Today, 86 operator groups, representing more than 300 networks and 80% of global mobile connections, are aligned with the Open Gateway API framework.
New API triggers renewed momentum
Let’s take a closer look at how the second iteration of the Number Verification API works. To validate the user’s phone number, the API employs a temporary token provided by the mobile network operator’s entitlement server 1, delivered via the handset’s operating system (OS). The integration with the OS makes it easy for the user to give their consent and there is no need for the operator to use the header enrichment mechanism, which can be insecure and suffer from compatibility issues.

At MWC26 Barcelona, there were clear signs that the upgraded Number Verification API is gaining traction. For example, Aduna, an API aggregator, said it is now testing the new API with its operator partners in the US, Germany, Spain, France and the UK, and soon Brazil.
Meanwhile, in Malaysia, CelcomDigi Berhad is working with Telenor Linx to make API-based phone number verification capabilities available via Google’s Firebase platform.
The operator says the “one tap” solution reduces friction, while lowering the risk of scams, phishing and OTP interception. DITO Telecommunity, a mobile operator in the Philippines, has launched a similar proposition, in partnership with Shush and Twilio.
During the Mobile Identity Summit at MWC, TikTok outlined its progress from trialling the Number Verification API in several markets in 2025 to productising the API in 2026. At MWC26, Meta said that the first version of the Number Verification API achieved a conversion rate of between 80% and 95%, compared with 60% to 75% for SMS OTP in the best markets, and less than 50% in “high cost/risk markets.” As well as using the standardised API to authenticate its own users, Meta has a broader ambition to integrate it with Meta services for enterprise customers.
Multiple Factors Driving Uptake
This renewed momentum is being fuelled by several factors. Most significantly, the growing scale and sophistication of online fraud and other cyber threats demand stronger and more convenient authentication solutions. Although OTPs via SMS offer near universal reach and are well understood by users, they are vulnerable to interception. There are growing concerns about artificially inflated traffic (AIT) fraud, as well as a cumbersome user interface and pricing structures in some markets. Still, SMS will continue to have a role as a fallback channel, particularly in emerging markets or for users without smartphones.
As well as major digital service providers, such as Google, Meta and TikTok, the financial services sector is keen to use network APIs for authentication. Banks really see the value of basing trust on two entirely separate roots of trust – biometrics and the device/SIM – as a fraudster can’t easily attack and defeat both of them.

For example, mobile financial services platform Lydia Solutions is leveraging the Number Verification API to automatically authenticate tens of thousands of users daily. Lydia says the API-based solution has reduced latency by up to 50% compared to previous authentication mechanisms, while social engineering attacks based on OTP sharing have been virtually eliminated.
Meanwhile, some regulators are calling for a move away from OTPs. The Central Bank of the United Arab Emirates, for example, issued a comprehensive directive requiring all financial institutions to completely discontinue the use of OTPs sent via SMS and email by 31 March 2026.
A New GSMA Task Force
Although the direction of travel seems clear, there are still some obstacles on the road to widespread commercial availability of SIM-based authentication. One issue is that some operators don’t have entitlement servers that support this feature, while not all devices’ OS support the new API. The GSMA Identity and Data Community has formed a task force to help address these issues and accelerate adoption during 2026.
Another challenge is the need to ensure that this authentication solution enables participants in the value chain to monetise their contribution. That can be done. Telin, the international arm of Telkom Indonesia, has supplemented authentication via OTPs with an API-based mechanism, increasing the successful number verification rate by over 20%, while strengthening their position in the enterprise market.
To ensure success, mobile operators may need to offer enterprises a choice of innovative charging models, beyond the current SMS OTP model of simply pricing API usage on a per call basis. Customised propositions are key in the enterprise sector. Over time, mobile operators could supplement the Number Verification API with other APIs, which can alert an enterprise to a recent SIM swap, verify the user’s age and perform other functions, to further strengthen the authentication process.
If you would like to engage further with the ongoing advances in mobile authentication, you can join the GSMA Identity and Community.
If you’d like to get involved and join our community, please fill in the short form below.
- The GSMA’s TS.43 specification standardises the APIs used by mobile operators’ entitlement servers, which notifies connected devices which operator services they are entitled to use. ↩︎
