Skip to main content Skip to footer

Could network APIs spell the end for SMS OTP?

Otp

The one-time password has long been the default bridge between mobile networks and digital identity. But as SMS authentication becomes increasingly vulnerable to fraud, operators are beginning to offer network-based verification as an alternative. Can they turn that capability into a scalable commercial service?

One of the most familiar points of interaction between digital services and mobile networks is the humble one-time password (OTP).

You create an online account or log into an existing one, provide your mobile number, and the digital service provider sends a code to your phone to verify that you are you.

Now, in a rare show of unity, the United States’ big three mobile operators – AT&T, T-Mobile and Verizon – are working with Aduna to roll out network-based Number Verification as an alternative to SMS OTP.

Instead of sending a code, an application can ask the mobile network whether the phone number being presented matches the number associated with the authenticated device, often with little or no input from the user.

That is the conceptual leap behind Number Verification. Instead of merely transporting an authentication secret, the operator can provide an assertion derived from information it already possesses inside the network.

SMS OTP is increasingly exploited through phishing, social engineering and SIM-swap attacks, while automation makes such fraud easier to scale.

Number Verification is one example of a broader opportunity – also visible in services such as Branded Calling – to expose network-derived trust signals through APIs and package them as commercial services for other businesses.

“I am not a number…”: the mobile network as a trust platform

Phone numbers were never intended to be digital identities. A mobile number is essentially a routing address used by a telecommunications network to reach a subscriber.

But over the past two decades, the phone number has become something much more important.

Banks ask for it. Social networks use it for account recovery. OTT messaging applications such as WhatsApp use it to identify users. To many businesses, possession of a mobile number has become important evidence that you are who you say you are.

The number itself, however, is not the most interesting part of this; a mobile subscription is backed by cryptographic credentials stored on a SIM or eSIM and verified by the operator’s authentication infrastructure. Every time a device attaches to a mobile network, the operator authenticates the subscription using those credentials.

That gives mobile operators something unusual in the internet economy: persistent, cryptographically authenticated relationships with billions of mobile subscriptions.

The SIM was never intended to become a universal internet identity token, but mobile networks have many of the ingredients needed to provide valuable identity and authentication signals.

OTP is a strange workaround

With SMS OTP, the network may already know that a particular subscription has successfully authenticated, but historically businesses have had no simple, standardised way to make use of that fact.

Instead, a service provider generates a random code and sends it through the network to a phone number. The user receives the code and then submits it to confirm their identity.

In other words, rather than exposing useful evidence from the network directly, the network transports another piece of information intended to prove possession.

A random code can be an excellent secret, but it does not establish who possesses it. If an attacker compromises the delivery process or deceives the user, an impeccably random OTP can still be delivered to the wrong person or surrendered through phishing.

SMS OTP effectively asks the user to return the secret sent to their number.

Instead, Number Verification asks: does the network see the subscription associated with this number on the device making the request?

Identity is about binding

Authentication depends on reliably binding an account to the right person, device, mobile number and subscription. Network authentication can establish some of those relationships directly – but a SIM is not a person.

Successful SIM or eSIM authentication proves possession of network credentials. It does not inherently prove the identity of whoever is holding the device. Numbers can also be ported, reassigned or recycled, while attackers can persuade operators to swap a victim’s number to another SIM.

That is the basis of SIM-swap fraud. If an attacker convinces an operator to transfer a victim’s number, downstream services can mistakenly interpret control of that mobile identity as evidence that they are dealing with the original person.

The consequences can be severe: T-Mobile paid a $33 million arbitration award over a SIM-swap attack that led to the theft of more than 1,500 Bitcoin.

This is why other network signals matter too.

An operator may, for example, be able to say whether the SIM associated with a number has recently changed. A SIM Swap API can expose that information to banks and other businesses assessing the risk of a transaction.

Over time, enterprises could therefore consume a portfolio of network-derived signals rather than relying on a single identifier.

Standardising network capabilities

For that model to work globally, developers cannot realistically integrate separately with hundreds of operators, each exposing different APIs and commercial models.

This is the problem that CAMARA, GSMA Open Gateway and aggregators such as Aduna are designed to address.

CAMARA is developing common API definitions for network capabilities, while GSMA Open Gateway provides an industry framework through which operators can expose them. Aduna, meanwhile, provides a common layer through which developers and enterprises can consume capabilities across multiple operators.

Standardisation makes APIs consistent. Aggregation makes them easier to consume at scale.

Together, they could turn functionality once buried inside individual telecommunications networks into globally consumable digital products.

Operators are already making money from authentication

This transition is particularly interesting because SMS OTP is not simply an obsolete technology operators are helping to eliminate.

Authentication is part of the enormous application-to-person (A2P) business messaging market.

Juniper Research estimates that total global operator revenue from business messaging was $51.7 billion in 2025 and forecasts that it will reach $54.6 billion in 2030. Operators do not disclose OTP revenue separately, but authentication represents a substantial part of the market: Future Market Insights projects authentication applications to account for about 30% of A2P messaging volume in 2026.

For operators, moving away from OTP therefore involves a degree of deliberate cannibalisation. But operators do not control whether SMS OTP survives.

Passkeys, authenticator applications, push authentication and other methods are already competing with it, while enterprises are increasingly conscious of both its security weaknesses and user friction.

Number Verification will not replace every OTP use case, but it gives operators a way to retain value as enterprises shift suitable mobile journeys away from SMS.

Operators therefore need to decide how quickly to shift their emphasis from transporting authentication messages to providing network-derived information that helps an enterprise decide whether a transaction should be trusted.

With OTP, the operator monetises transport.

With network APIs, it can increasingly monetise what the network knows.

Combining network signals for stronger assurance

Network authentication could become particularly valuable because mandatory SIM card registration is widespread across much of the world, requiring subscribers in many markets to provide identity information before a SIM can be activated.

The effectiveness and quality of those registration systems vary considerably, so Number Verification should not be treated as proof of someone's real-world identity.

Instead, different signals establish different things.

Number Verification can provide evidence that the mobile number entered by a user matches the number associated with the authenticated device. Information from the SIM Swap API can indicate whether the SIM associated with that number has recently changed. Separately, an operator may hold customer identity information established through local registration or KYC processes.

None of these signals individually proves that someone is who they claim to be.

Combined, however, they may become considerably more useful to banks, governments and digital services making decisions about authentication, fraud and identity.

That potentially gives telcos something unusually valuable: infrastructure combining cryptographic network authentication, persistent communications identities and, in many markets, some form of subscriber identity verification.

From connectivity provider to trust provider

The industry is therefore moving beyond treating possession of a phone number as a proxy for identity and towards treating the relationships between subscriptions, credentials, devices and networks as useful trust signals.

But turning network trust into a product is not just an API management problem. It is also a governance problem: operators must manage subscriber consent, minimise the information disclosed and comply with local privacy and identity rules.

Once capabilities such as Number Verification and SIM Swap are exposed commercially, operators need to define them as products, control who can consume them, measure usage, apply prices and discounts, bill customers and settle revenue with partners.

The person being authenticated is not necessarily the customer being charged. A bank might consume millions of verification requests concerning subscribers across several networks, potentially buying them through an aggregator.

API activity therefore starts to look like another form of telecom usage. Operators might charge per API call, per successful verification, through volume tiers or bundles, or as part of a broader fraud-prevention service.

Partner management becomes equally important. If a transaction involves an enterprise, identity provider, aggregator and mobile operator, somebody needs to manage contracts, entitlements, revenue shares and settlement between them.

For decades, BSS has focused on monetising what passes through the network. Network APIs increasingly require it to monetise what the network knows and can verify.

Network APIs may not spell the immediate end of SMS OTP, but they do change the operator’s role in authentication. The opportunity is to move from carrying the message to providing the trust behind it.

Cerillion's pre-integrated BSS/OSS Suite provides the building blocks for this new commercial model, from defining network API products and tariffs in Enterprise Product Catalogue, through usage processing, charging and billing, to partner management and settlement – helping CSPs turn network capabilities into scalable, monetisable digital services.

About the author

Adam Hughes

Content Specialist, Cerillion

Keep up with the latest company news and industry analysis