Back to Resources
GSMA Open Gateway at 80%: The Commercial Playbook for Operators
Kashika Mishra
October 29, 2025

GSMA Open Gateway now spans 86 operator groups representing 80% of global mobile connections — the threshold at which a carrier API framework transitions from an industry initiative to a commercial infrastructure that enterprises must integrate with. The July 2026 US carrier launch of number verification and silent authentication APIs across 300 million connections demonstrated what that transition looks like in practice: enterprise identity platforms integrated, per-verification billing activated, and network-based authentication revenue flowing from day one. For operators that have not yet activated their CAMARA API products, the 80% milestone is not a reason to wait and watch — it is the signal that the commercial window is open and that the operators who move first capture the enterprise relationships that define the next decade of identity revenue.

Definition — GSMA Open Gateway: A framework of standardised network APIs — built on the CAMARA specification — that exposes mobile operator network capabilities (authentication, number verification, SIM status, device connectivity) to enterprise developers through a common, interoperable interface. 86 operator groups, 80% of global mobile connections. Operators monetise participation through per-API-call revenue against their subscriber base.

This blog is the commercial playbook: what Open Gateway is, which APIs generate the most operator revenue in 2026, what the per-call economics look like against A2P SMS, which enterprise verticals are buying and why, what operators need to activate, and how the network-based authentication product suite sits at the centre of the highest-revenue API category in the Open Gateway portfolio. The complete network-based authentication operator guide covers the full product architecture; this blog covers the commercial strategy for operators ready to monetise it at Open Gateway scale.

What GSMA Open Gateway Is — and What It Is Not

GSMA Open Gateway is a framework agreement and API standardisation initiative that enables mobile operators to expose their network capabilities to enterprise customers through CAMARA-compliant REST APIs. The CAMARA Project — hosted under the Linux Foundation — defines the technical API specifications; GSMA Open Gateway defines the commercial and governance framework that makes those APIs interoperable across operator networks. An enterprise that integrates against one Open Gateway-compliant operator endpoint can, in principle, route verification requests to any other participating operator's subscriber base through the same integration.

What Open Gateway is not: it is not a wholesale SMS or voice routing agreement, it is not a content delivery network, and it is not a managed service. It is a standardised API layer over network capabilities that operators already have — the HSS, the SIM authentication infrastructure, the subscriber database — packaged so enterprises can consume them without understanding or caring about the underlying network architecture.

The 86 operator groups in the Open Gateway framework represent networks across every major region. The 80% figure — 80% of global mobile connections — means that an enterprise integrating against the Open Gateway API portfolio has meaningful coverage in almost every market they operate in. This coverage is what converts the framework from an experiment into a procurement decision: enterprise identity platforms need global coverage to replace SMS OTP end-to-end, and Open Gateway now offers it. For operators, the coverage concentration also means that not participating has a cost — enterprise customers routing to Open Gateway-enabled operators for network-based authentication are routing away from operators that are not.

The Open Gateway API Portfolio: What Is Live and Sellable in 2026

Open Gateway covers multiple API categories, but they are not equally commercial in 2026. The categories are driven by two things: technical maturity (has the CAMARA specification reached Stable status?) and enterprise demand (is there a budget and a procurement motion behind it?). The table below maps the current state across the categories most relevant to operator revenue.

Number Verification (NV2) Stable — Fall25 NIST/RBI/CBUAE/MAS/BNM OTP mandates — forced migration from SMS OTP Highest
Silent Authentication (TS.43) Stable — Fall25 Phishing-resistant AAL2 login — regulated banking, fintech, SaaS Highest
SIM Swap Detection Stable — Spring24 Account takeover fraud prevention — banking, e-commerce, crypto High
Device Status / Roaming Stable — Spring24 Fraud risk signals — insurance, logistics, financial services Medium
Quality on Demand (QoD) Stable — Spring24 Guaranteed bandwidth for enterprise apps — gaming, video, IoT Medium
Edge Cloud In development Low-latency compute at the network edge — autonomous, AR/VR Emerging

The clear commercial priority in 2026 is network-based authentication — Number Verification and Silent Authentication together — for a specific reason: they are not discretionary purchases. Regulatory mandates across six markets (US, India, UAE, Singapore, Malaysia, and the FCC) have created compliance deadlines that enterprise customers in regulated sectors cannot ignore. The enterprise is not evaluating network-based authentication against other options as a feature comparison; they are evaluating it as the only available option that satisfies the phishing-resistance requirement without hardware tokens or app dependencies. This changes the sales cycle materially — operator API products that would normally require months of enterprise education and evaluation are closing in weeks because the compliance deadline is imminent.

The US Carrier Launch: What It Proved About Open Gateway Commercial Viability

The July 2026 launch of number verification and silent authentication APIs across three major US carriers — covering over 300 million connections — was the largest single commercial activation of Open Gateway APIs in the framework's history. It was also the first deployment at a scale large enough to answer definitively whether enterprise customers would integrate and pay for CAMARA APIs in production.

The answer is yes. Enterprise identity platforms — across banking, fintech, cloud platforms, and SaaS — integrated against the US carrier number verification APIs within weeks of the launch, driven by the NIST SP 800-63B-4 compliance deadline that classified SMS OTP as a Restricted Authenticator in July 2025. The procurement motion was already built: enterprise security teams had been planning OTP migration for months, the US carrier launch gave them the network-side capability they needed,and the CAMARA API integration was fast enough (days to weeks, not months) that it cleared the procurement timeline.

For operators outside the US, the launch resolves the most common objection to Open Gateway API investment: 'We don't know if enterprises will actually pay for this.' The US market has now demonstrated per-verification billing at volume, integration timelines measured in weeks, and enterprise demand that is structurally driven by regulation rather than discretionary innovation budget. The commercial model works. The question for every operator in the Open Gateway framework is whether they activate their portion of it before or after their enterprise customers route to a competitor that has. The full US context is in US Carriers Launch Network-Based Authentication: What It Means for Global Operators.

Per-Call Revenue Economics: Open Gateway vs A2P SMS

The commercial case for activating Open Gateway network-based authentication APIs starts with the per-call economics — comparing what operators currently earn per SMS OTP termination against what they earn per CAMARA API verification call.

Gross per-event fee USD 0.02–0.05 (termination rate, market-dependent) USD 0.03–0.10 (per-verification, enterprise contract)
AIT fraud exposure 5–20× fraud multiplier on OTP routes; operator bears clean-up cost Zero — no message delivery step, no AIT attack surface
Delivery cost SMSC routing, SS7 fees, failed delivery overhead Near-zero — HSS lookup, Diameter interface call
Fraud liability Operator exposed on fraudulent route revenue reversals None — network-level verification, no delivery fraud
Revenue trajectory Declining — regulatory mandates forcing enterprise OTP migration Growing — 13.39% CAGR through 2031 (Mordor Intelligence)
Enterprise relationship Commodity route — easily replaced by any SMS aggregator Strategic API contract — operator is the identity infrastructure layer

The net per-event economics favour CAMARA auth APIs at every volume level once AIT exposure is factored in. More significantly, the enterprise relationship is categorically different. An A2P SMS OTP contract is a commodity routing arrangement — the enterprise can switch operators with 30 days' notice and no integration change. A CAMARA network-based authentication API contract is an integration dependency: the enterprise's identity platform calls the operator's API, and switching requires a re-integration project. Operators that establish the CAMARA API relationship now are establishing a multi-year revenue dependency, not a month-to-month routing contract. For the full revenue model analysis — including ARPU uplift modelling and the four operator monetisation frameworks — see How Operators Monetize Authentication APIs: The Global MNO Revenue Playbook.

Enterprise Demand by Vertical: Who Is Buying Open Gateway Auth APIs and Why

Enterprise demand for Open Gateway network-based authentication APIs is concentrated in regulated sectors — financial services, healthcare, government — where compliance mandates are creating forced migration events, and in high-fraud sectors — e-commerce, gaming, cloud platforms — where the economics of SMS OTP have become unsustainable due to AIT fraud and delivery costs.

Banking & BFSI Number Verification + Silent Auth for login, onboarding, transactions SMS OTP fails AAL2; SIM swap fraud on account recovery increasing NIST, RBI, CBUAE, MAS, BNM
Fintech & Payments Number Verification at checkout; SIM Swap before high-value transfer OTP drop-off reduces conversion; AIT fraud on payment OTPs PSD2, RBI, MAS
Cloud & Hyperscaler Number Verification for account recovery; Silent Auth for 2FA replacement FedRAMP and SOC2 compliance requires phishing-resistant auth at AAL2 NIST 800-63B-4 (US)
E-Commerce & Marketplace Number Verification at account creation; Silent Auth at login AIT fraud on registration OTPs; checkout friction reducing conversion Market-driven
Gaming & OTT Silent Auth for seamless login; Number Verification for account linking OTP latency breaks real-time session flows; SMS cost per MAU unsustainable Platform-driven
Enterprise SaaS Silent Auth for privileged access; Number Verification for MFA replacement Corporate security policies now require phishing-resistant MFA beyond TOTP NIST 800-63B-4

The banking and fintech verticals deserve particular attention because of the mandate concentration. NIST SP 800-63B-4 (US), the RBI Digital Payments Security mandate (India, April 2026), the CBUAE Authentication Directive (UAE, March 2026), MAS Digital Token Guidelines (Singapore, July 2024), and BNM Risk Management Framework (Malaysia, September 2024) are all in force simultaneously. A multinational bank operating across these markets needs a network-based authentication solution that covers all of them — which is precisely the commercial proposition that Open Gateway's global interoperability delivers. One API integration, coverage across 86 operator groups, compliance in every regulated market. The full regulatory mapping is in NIST 800-63B-4 & Carrier APIs: The US Operator's Authentication Mandate Playbook.

The Open Gateway Auth API Stack: Silent Auth, Number Verification, SIM Swap

For operators positioning Open Gateway network-based authentication to enterprise customers, there are three complementary APIs in the authentication category — each exposing a different network capability, each targeting a distinct enterprise use case, and each generating separate per-call revenue.

Silent Authentication EAP-AKA SIM cryptography via TS.43 Entitlement Server Seamless login — verifies the user holds the registered SIM with zero user steps. Phishing-resistant AAL2. SilentAuth+
Number Verification (NV2) HSS subscriber database lookup via CAMARA Number Verification API v2.0 Phone number confirmation at onboarding or account recovery. Sub-500ms, Wi-Fi supported via CIBA+TS.43. NumberVerify2
SIM Swap Detection HLR/HSS SIM event history lookup Fraud risk signal — detects recent SIM swap before high-value transaction. Returns risk flag in <300ms. SIM Swap Detection

The commercial packaging of these three products matters as much as the technical specification. Enterprises buying SilentAuth+ for login authentication will almost always need NumberVerify2 for the account creation or phone number confirmation step — they are natural co-sells. SIM Swap Detection is the logical third product for any enterprise customer operating in a fraud-sensitive vertical: it adds a risk signal to every high-value transaction with the same subscriber lookup the operator already runs. Bundling all three — Silent Auth for login, Number Verification for onboarding, SIM Swap for transaction risk — allows operators to replace the entire enterprise SMS OTP spend with Open Gateway API revenue and position themselves as the authentication infrastructure layer rather than a termination route. For how the infrastructure connects these at the network layer, see How Entitlement Server Enables Silent Network Authentication and TS.43 Silent Authentication Explained.

Regional Deployment: Where Operators Stand in the Open Gateway Network

U2opia's Open Gateway-aligned network-based authentication platform covers 104+ operators across 60+ countries — a deployment footprint built over a decade of operator partnerships before the Open Gateway framework formalised the commercial infrastructure around it. The regional breakdown reflects both the maturity of authentication API deployments and the intensity of enterprise demand in each market.

South Asia (India+) 22+ MNOs Live RBI mandate (April 2026) — financial sector OTP replacement
Southeast Asia 18+ MNOs Live MAS (Singapore), BNM (Malaysia) — banking OTP mandates
Europe 21+ MNOs Live PSD2 SCA requirements; corporate MFA compliance
Americas 12+ MNOs Live — incl. July 2026 US launch NIST 800-63B-4 (US); FCC security framework; enterprise SaaS
Middle East 14+ MNOs Expanding CBUAE (UAE, March 2026); banking sector OTP phase-out
Africa 10+ MNOs Expanding Market-driven — delivery reliability; emerging fintech sector

The 'Expanding' markets in the Middle East and Africa are not passive — they are active deployments at earlier stages. For operators in these regions, the commercial urgency is different from the US or India: instead of a hard regulatory deadline, the driver is competitive positioning. Enterprise customers in the UAE, Saudi Arabia, and across East Africa are evaluating OTP alternatives now, ahead of their own markets' regulatory timelines. Operators that deploy network-based authentication before the mandate lands are in the strongest commercial position — they have a reference customer base and proven integration when their competitors are still in pilot. For the USSD fallback architecture that extends coverage to 2G and 3G subscribers in these markets, see Why Silent Authentication Fails in TS.43 Production Networks.

What Operators Need to Activate Open Gateway Auth APIs

Activating Open Gateway network-based authentication APIs requires two things: the network infrastructure to expose the authentication capability (the TS.43 Entitlement Server), and the commercial infrastructure to bill enterprises and settle revenue (the CAMARA API gateway and revenue management layer). Most operators have the first component — the HSS, the SIM infrastructure, the Diameter interfaces — and need the second.

The TS.43 Entitlement Server is the network function that intermediates between the CAMARA API layer and the operator's Home Subscriber Server. It issues EAP-AKA challenges, validates responses, and translates the result into the CAMARA API response format the enterprise integration expects. Operators that have not yet deployed an Entitlement Server can use U2opia's SilentAuth+ as a hosted gateway — U2opia operates the Entitlement Server, CAMARA compliance, enterprise billing, and revenue settlement, while the operator contributes HSS access and subscriber coverage. The deployment checklist is in TS.43 Entitlement Server Deployment Checklist, and the infrastructure architecture is covered in What is an Entitlement Server & Why It Matters and Architecting a Scalable Entitlement System.

Operators already running U2opia's SilentAuth+ gateway can activate NumberVerify2 as an additive product on the same infrastructure — the CIBA+TS.43 Wi-Fi extension and the SIM Swap signal integration are the only NV2-specific additions. The full NV2 deployment context is in NumberVerify2 (NV2): The CAMARA API Behind the US Carrier Network Auth Launch.

The commercial onboarding timeline for operators joining U2opia's Open Gateway-aligned network is 4–6 weeks to production readiness — live verification against the operator's subscriber base with enterprise billing active. This is fast enough to capture demand from enterprises whose compliance deadlines are already in force. The revenue share begins from the first verification call against the operator's subscribers; there is no upfront capex on the hosted deployment model. See the network-based authentication operator guide for the full architecture, or contact the U2opia operator team for a readiness assessment.

The Open Gateway Flywheel: Why Early Activation Compounds

Open Gateway creates a network effect that makes early activation disproportionately valuable. Enterprise identity platforms that integrate against Open Gateway-enabled operators build their routing logic around the available network. When additional operators activate their CAMARA APIs, they are added to the enterprise's routing configuration — but the primary integration has already been built against whoever was first in market.

This means the first operator in a given market to activate network-based authentication APIs captures the initial enterprise integration. The second operator in that market is added to the enterprise's routing as a supplementary or fallback network — a lower-value commercial position. In markets where only one operator has CAMARA auth APIs live, that operator has effective exclusivity on enterprise network-based authentication API revenue for the duration of the enterprise's integration cycle (typically 12–24 months before re-evaluation).

The compounding effect extends to data and product quality. Operators with higher verification volumes have more signal for identifying anomalous patterns — which feeds into fraud detection capabilities, SIM Swap signal quality, and ultimately the premium pricing those operators can command for higher-quality API responses. For the full business case for early Entitlement Server investment, see Business Benefits of TS.43 Entitlement Servers for Telecom Operators. For the security architecture that protects the operator's core network from API exposure risk, see Security in Entitlement Servers.

The commercial parallel to the GSMA Open Gateway flywheel is TS.43 vs OAuth: Why Telecom Authentication Is Different from Enterprise IAM. OAuth and IAM frameworks operate at the application layer — above the network. Open Gateway network-based authentication operates below OAuth: it is the network-layer identity signal that enterprise OAuth and IAM platforms consume as a trusted input. Operators that establish themselves as the network authentication layer become infrastructure to enterprise identity stacks — a position that is very difficult for OTT identity providers to displace once it is established.

Frequently Asked Questions: GSMA Open Gateway

What is GSMA Open Gateway?

GSMA Open Gateway is a framework of standardised network APIs — built on the CAMARA specification — that allows mobile network operators to expose core network capabilities (authentication, number verification, SIM status, device connectivity) to enterprise developers through a common, interoperable interface. It spans 86 operator groups representing 80% of global mobile connections, enabling enterprises to integrate once and reach subscribers across all participating networks. Operators monetise participation through per-API-call revenue against their subscriber base. The authentication APIs — network-based authentication (Number Verification and Silent Authentication) — are the highest-revenue category in the portfolio in 2026.

How do operators make money from GSMA Open Gateway?

Operators earn revenue through a per-API-call model: enterprises pay each time they query a participating operator's network through a CAMARA-compliant API — for authentication verification, number confirmation, SIM swap detection, or other capabilities. The operator receives a revenue share on each call against their subscriber base. Because these calls expose existing network functions (HSS lookups, SIM identity checks) at near-zero marginal cost, the per-call margin significantly exceeds the equivalent A2P SMS termination revenue for the same enterprise customer. The revenue model is detailed in How Operators Monetize Authentication APIs: The Global MNO Revenue Playbook.

Which GSMA Open Gateway APIs generate the most operator revenue?

Network-based authentication APIs — specifically NumberVerify2 (CAMARA Number Verification v2.0) and SilentAuth+ (TS.43 Silent Authentication) — are generating the highest per-call revenue in 2026, driven by regulatory mandates forcing enterprise customers to replace SMS OTP. The US carrier launch in July 2026 across 300 million connections has validated these as the highest-commercial-priority APIs in the Open Gateway portfolio. SIM Swap Detection is the natural third product in the authentication bundle, generating additional per-query revenue on the same subscriber infrastructure.

What is the difference between Open Gateway membership and having live API products?

Open Gateway membership — signing the framework agreement and joining the operator group — is a governance and commercial commitment. Having live API products means the operator's network is actually returning responses to CAMARA API calls from enterprise customers. Many operators are Open Gateway members but have not yet activated specific API products. Revenue only flows when API products are live and enterprises are calling against them. For authentication APIs specifically, 'live' means having a TS.43 Entitlement Server deployed, integrated with the HSS, and connected to an enterprise-accessible CAMARA API endpoint.

How long does it take for an operator to activate Open Gateway auth APIs?

Using U2opia's hosted deployment model — where U2opia operates the Entitlement Server, CAMARA API compliance, enterprise billing, and settlement infrastructure — operators can reach production readiness in 4–6 weeks from integration start. This requires HSS/HLR access for EAP-AKA challenge routing and subscriber coverage for the operator's network. Operators building their own Entitlement Server infrastructure should budget 3–6 months depending on internal development capacity; the TS.43 Entitlement Server Implementation Guide and Deployment Checklist cover the build path.

Does GSMA Open Gateway work for 2G and 3G subscribers?

Standard CAMARA Number Verification and Silent Authentication implementations require 4G or 5G connectivity for the TS.43 EAP-AKA primary flow. For operators with 2G or 3G subscriber populations — common across Africa, South Asia, and parts of Southeast Asia — a USSD fallback path is required to maintain coverage continuity. U2opia's SilentAuth+ and NumberVerify2 both include USSD fallback, delivering verification coverage across 2G through 5G on the same API contract. Without fallback, 2G/3G sessions produce silent failures and fall through to SMS OTP — undermining the operator's monetisation and the enterprise's fraud protection. See Why Silent Authentication Fails in TS.43 Production Networks for the failure mode analysis.

The 80% Milestone Is the Commercial Starting Gun

GSMA Open Gateway reaching 80% of global mobile connections is not a technical milestone — it is a commercial one. It is the point at which the framework's coverage is broad enough that enterprises have no reason not to integrate, regulatory mandates are creating the procurement urgency to integrate now, and the US carrier launch has demonstrated that per-verification billing at volume works in practice.

For operators inside the Open Gateway framework who have not yet activated network-based authentication API products: the window in which being early in your market creates a competitive advantage is open, but it is not indefinitely open. Enterprise identity platforms are making integration decisions now, and the operators whose APIs are live when those decisions are made establish the relationships that define the next decade of identity revenue.

For operators outside the Open Gateway framework: the 80% threshold means that the standard interoperability benefits — enterprises integrating once to reach most of the world's subscribers — are now materially real. The cost of not being in the network is no longer theoretical; it is measured in the enterprise OTP contracts that are being re-routed to Open Gateway-enabled operators in your market.

U2opia's network-based authentication platform — covering SilentAuth+, NumberVerify2, and SIM Swap Detection — provides the fastest path from Open Gateway membership to live API revenue. The hosted deployment model eliminates the build timeline as a constraint. The revenue share model means the operator earns from the first verification call. Contact the U2opia operator team to scope your network's activation timeline, or explore the complete network-based authentication operator guide for the full architecture and commercial model.

Related articles
Browse all
GET STARTED
Ready To Reach Every Mobile User?
Start with SilentAuth+ and add customer experience and payments as you grow. One platform, carrier-grade, global.