.png)
NumberVerify2 (NV2) is the CAMARA Number Verification API v2.0 — a GSMA Open Gateway standard that allows a mobile network operator to verify whether a phone number matches the SIM card in a device, without sending an OTP, without any user action, and with a network-side latency of under 300 milliseconds. NV2 is the commercial implementation of network-based authentication for number verification — your subscriber database answers the enterprise's identity question directly, and the result is billable at per-verification rates that exceed the A2P SMS termination fee for the same transaction. The July 2026 launch of number verification APIs across three major US carriers — covering over 300 million connections — marks the moment NV2 moved from GSMA specification to live network revenue.
Definition — NumberVerify2 (NV2): The CAMARA Number Verification API v2.0 (CAMARA Fall25 Stable). NV2 verifies whether a phone number matches the SIM card in the requesting device via a network-side lookup — no OTP, no user step, sub-500ms. NV2 adds CIBA + TS.43 temporary token to extend verification to Wi-Fi sessions, eliminating the primary coverage gap of NV1.
For operators, NV2 is a product that wraps a capability the network already performs — subscriber identity verification — and makes it sellable to enterprise customers who need it urgently. The commercial pull is now structural: NIST SP 800-63B-4 restricts SMS OTP for regulated US workloads, and equivalent mandates are in force across India, the UAE, Singapore, and Malaysia. Enterprise customers in banking, fintech, and cloud platforms need an OTP replacement that satisfies the phishing-resistance requirement. NV2 is the operator's answer — deployed through GSMA Open Gateway and monetised at scale through U2opia's NumberVerify2 platform across 104+ operators in 60+ countries.
What is NumberVerify2 (NV2)? The CAMARA v2.0 Upgrade Explained
The CAMARA Number Verification API defines how enterprise applications query an operator's subscriber database to answer one question: does this phone number match the SIM currently installed in the device making this request? The answer is a boolean — match or mismatch — returned in under 500 milliseconds, with no message delivered to the user and no code entered.
NV2 is the v2.0 iteration of this API, formalised under the CAMARA Project Fall25 Stable release. It is the successor to NV1 (v1.0, CAMARA Spring24 Stable), which shipped in the first wave of GSMA Open Gateway API launches. The two versions are technically compatible at the API surface — an enterprise integration built for NV1 can migrate to NV2 without a full rebuild — but NV2 adds a critical capability that NV1 lacked: verification on Wi-Fi sessions.
Understanding why the Wi-Fi gap existed in NV1 requires understanding how the verification itself works. When a device is on a cellular data session (4G or 5G), the operator's network can inspect the SIM identity directly as part of the data session — it knows which MSISDN is attached to which IP session. When the device moves to Wi-Fi, that direct network visibility disappears. NV1 had no mechanism for bridging this gap: if the device was on Wi-Fi when the verification request arrived, the call failed or returned an error. NV2 resolves this with a CIBA + TS.43 token architecture that pre-fetches a verification token while the device is on cellular, binding it to the SIM identity cryptographically so it can be used to complete verification on a subsequent Wi-Fi session.
The full EAP-AKA mechanics that underpin both SilentAuth+ and NV2 are detailed in How Network-Based Authentication Works: EAP-AKA and TS.43 Explained for Operators. The token flow specifically — from EAP-AKA challenge to the access token presented to the enterprise API — is covered in From EAP-AKA to Access Token: How Device Authentication Works in a TS.43.
The Wi-Fi Gap: Why NV1 Left Revenue on the Table
Mobile users in 2026 spend a substantial portion of their connected time on Wi-Fi — whether at home, in the office, or in any environment with an available Wi-Fi network. For enterprise applications performing number verification — account creation, login confirmation, transaction authorisation — this means a significant proportion of verification events occur when the user's device has handed off from cellular to Wi-Fi.
Under NV1, those sessions were silent failures. The operator could not see the SIM identity on the Wi-Fi session, so the verification returned no result — and the enterprise application fell back to SMS OTP. This produced a structural paradox: the operator had deployed a premium network-based authentication product precisely to replace SMS OTP, but a large share of the user base was still receiving OTPs — on the sessions the operator could not verify — while the operator still bore the cost of running the CAMARA API infrastructure. The uncaptured revenue went to the SMS delivery chain instead.
NV2 eliminates this. The CIBA (Client-Initiated Backchannel Authentication) flow allows the enterprise application to request a verification token before the user's session moves to Wi-Fi. The Entitlement Server — which intermediates between the CAMARA API and the operator's Home Subscriber Server — issues a temporary token bound to the SIM's EAP-AKA credentials. When the verification event is triggered on the Wi-Fi session, the enterprise presents the token, and the Entitlement Server verifies its authenticity against the SIM record without needing live cellular visibility. For operators who have not yet deployed an Entitlement Server, What is an Entitlement Server & Why It Matters and the Entitlement Server TS.43 Implementation Guide cover the architecture and deployment path.
NV2 vs NV1: The Complete Feature Comparison
The table below reflects the CAMARA Fall25 Stable (NV2) versus CAMARA Spring24 Stable (NV1) specifications as implemented in U2opia's NumberVerify2 platform. All existing NV1 integrations are recommended to migrate to NV2 for new deployments — NV1 remains supported for legacy operators.
The integrated SIM Swap signal is a noteworthy addition in NV2. When the operator's network detects that a SIM swap occurred within the last 72 hours for the requesting MSISDN, NV2 surfaces this as a risk flag within the same API response — allowing the enterprise application to trigger additional verification or block the session without a separate SIM Swap Detection API call. For operators, this increases the per-API-call value and creates a natural upsell path from number verification into the full network-based authentication product suite.
The July 2026 US Carrier Launch: What It Means for the NV2 Market
On July 8, 2026, three major US carriers activated network-based authentication APIs across their combined subscriber base of over 300 million connections — the largest single-market deployment of CAMARA Number Verification in the standard's history. This was not a pilot or a limited rollout: it was a production launch of both silent authentication and number verification capabilities, available to enterprise identity platforms and aggregators with immediate effect.
The context for why the US launch happened in July 2026 is regulatory. The NIST SP 800-63B-4 publication in July 2025 formally classified SMS OTP as a 'Restricted Authenticator' — meaning any US federal agency or regulated entity using SMS OTP for AAL2 must now plan for migration to a phishing-resistant alternative. The FCC's subsequent November 2025 security guidance reinforced the direction for the carrier ecosystem specifically. Enterprise demand for a compliant replacement preceded the US carrier launch by months; the launch gave the US market an operator-native answer. For the full regulatory timeline and compliance mapping, see NIST 800-63B-4 & Carrier APIs: The US Operator's Authentication Mandate Playbook.
For operators outside the US, the US launch is significant for a second reason: it has validated the GSMA Open Gateway commercial model at scale. The GSMA Open Gateway initiative now spans 86 operator groups representing 80% of global mobile connections — but for many regional operators, the question of whether enterprises would actually integrate and pay for CAMARA APIs remained open until the US launch demonstrated live enterprise demand and per-verification billing at volume. The US launch resolves that question. Operators in South Asia, Southeast Asia, the Middle East, and Africa now have a proven commercial reference for the NV2 revenue model in their own markets. The full US launch context is in US Carriers Launch Network-Based Authentication: What It Means for Global Operators.
Operator Revenue Model: How NV2 Monetises Number Verification
Every number verification request is a billable event against the operator's subscriber database — a capability the network already runs at near-zero marginal cost for its own authentication purposes. NumberVerify2 converts this existing network function into a per-call API product.
The commercial structure is straightforward. Enterprises pay per verification request — typically in the range of USD 0.02–0.10 depending on market, volume commitment, and use case tier — through the GSMA Open Gateway commercial framework. U2opia routes enterprise verification requests to the appropriate operator network, handles API gateway operations, enterprise billing, and settlement, and passes a revenue share to the operator on each call against their subscriber base. The operator's incremental cost per verification event is effectively zero: it is a database lookup on the HSS, not a message delivery or a network action.
The revenue comparison against A2P SMS is instructive. An A2P SMS OTP for the same enterprise customer generates termination revenue in the range of USD 0.02–0.05 in most markets — and the operator bears delivery cost, delivery failure rate, and AIT fraud liability. A number verification event with NV2 generates a per-call fee in the same range or higher, with near-zero delivery cost, zero fraud liability, and a completion rate that does not depend on SS7 routing, SMSC availability, or the user's SMS inbox state. The economics favour NV2 at every volume level.
For the full four-model monetisation framework — including ARPU uplift modelling, revenue share structures, and API product bundling strategy — see How Operators Monetize Authentication APIs: The Global MNO Revenue Playbook. For the infrastructure-level business case that underpins NV2 deployment, see Business Benefits of TS.43 Entitlement Servers for Telecom Operators.
Enterprise Demand by Vertical: Who Is Buying NV2 and Why
Enterprise demand for NV2 is driven by three converging pressures: regulatory mandates that restrict SMS OTP, fraud losses that make OTP delivery economically unsustainable, and user experience data showing that verification friction directly reduces conversion. Each enterprise vertical has a specific version of this problem.
The Emerging Markets row reflects a meaningful differentiator in U2opia's NumberVerify2 platform relative to implementations built for 4G-only markets. Across Africa, South Asia, and Southeast Asia, a proportion of subscribers are on 2G or 3G connections at any given verification event. Standard NV2 implementations fail silently on these sessions and fall back to SMS OTP — undermining the operator's monetisation and the enterprise's fraud protection. U2opia's implementation adds a USSD fallback path, maintaining network-based authentication verification coverage across 2G through 5G on the same API contract. For context on how the fallback architecture works, see Why Silent Authentication Fails in TS.43 Production Networks.
NV2 vs SMS OTP: The Verification Economics
The business case for migrating enterprise customers from SMS OTP to NV2 is not primarily a security argument — though the security improvement is significant. It is an economics argument, and operators are positioned to make it from both sides.
SMS OTP is expensive for enterprises in ways that extend well beyond the per-message termination fee. Artificial Inflation of Traffic (AIT) fraud — in which fraudsters trigger OTP sends to numbers they control to generate termination revenue — costs the enterprise ecosystem over USD 1.2 billion annually. OTP delivery failures (SMSC overload, SS7 routing errors, SMS blocking) produce false negatives that enterprise platforms handle by sending a second or third OTP, multiplying cost without improving outcome. In markets with high SMS fraud rates, enterprises have reported AIT multipliers of 5–20× on their actual authentication traffic. These costs land on the enterprise — but the operator's reputation for delivery quality absorbs the damage.
NV2 eliminates all of these cost vectors. There is no message to deliver — and therefore no delivery failure, no AIT surface, no SMSC cost, and no SS7 exposure. The per-verification fee is comparable to the per-OTP termination fee, but the operator retains a higher share of it (no delivery chain intermediary) and bears none of the fraud liability. For enterprises, the total cost of ownership comparison strongly favours NV2 when AIT, fallback OTP sends, and customer support costs for failed authentication are included. For the full cost model, see The True Cost of SMS OTP: What Operators Are Losing Globally. For the head-to-head technical and commercial comparison, see Network-Based Authentication vs SMS OTP: The Operator Comparison.
How NV2 Fits Within the Network-Based Authentication Product Suite
NV2 is one of three products in U2opia's network-based authentication product suite, each addressing a distinct enterprise verification pattern. Understanding where NV2 sits relative to SilentAuth+ and SIM Swap Detection allows operators to position the full suite — and maximise per-enterprise revenue by matching the right product to the right use case.
In practice, NV2 and SilentAuth+ are often bundled for enterprise customers: SilentAuth+ handles the login authentication, and NV2 handles the account creation or phone number confirmation step. This is the pattern that most enterprise identity platforms are moving toward following the US carrier launch — a network-based layer for every identity event, rather than a point solution for a single step. The combined package allows operators to replace the entire A2P SMS OTP revenue stream with network-based authentication API revenue at higher per-event rates. The TS.43 Silent Authentication Explained deep-dive covers how SilentAuth+ works in the context of a full TS.43 Entitlement Server deployment.
For operators whose enterprise customers are still assessing the full migration path, the Entitlement Server Use Cases blog provides a practical use-case catalogue across verticals, and How Entitlement Server Enables Silent Network Authentication shows how the infrastructure links SilentAuth+ and NV2 at the network layer.
Regulatory Mandates: The Enterprise Migration Timetable
Enterprise demand for NV2 is not discretionary. Six regulatory frameworks across four continents have either restricted SMS OTP, mandated phishing-resistant authentication, or both. Each mandate creates a compliance deadline — and a procurement window — for the enterprise customers in your market.
All six mandates are in force. Enterprises that have not yet begun migration are already behind their compliance schedules. For operators in regulated markets, this translates directly to qualified enterprise demand for network-based authentication APIs — the only authentication mechanism that simultaneously satisfies phishing-resistance requirements, requires no hardware token distribution, and requires no user app installation. The full regulatory analysis is in NIST 800-63B-4 & Carrier APIs: The US Operator's Authentication Mandate Playbook.
Deploying NV2: The Operator Path to API Revenue
Operators joining U2opia's NumberVerify2 platform gain immediate access to the enterprise customer base without building CAMARA API infrastructure from scratch. The deployment model is designed for production readiness in weeks, not quarters.
The technical foundation for NV2 is the same TS.43 Entitlement Server that powers SilentAuth+ — the network function that intermediates between the CAMARA API layer and the operator's HSS/HLR. If your network has already deployed an Entitlement Server (or is running U2opia's SilentAuth+ gateway), NV2 is an additive API product on the same infrastructure: it uses the same EAP-AKA challenge/response flow, the same Diameter S6a interface to the HSS, and the same subscriber database. The additional NV2-specific work is the CIBA token pre-fetch flow for Wi-Fi extension and the SIM Swap signal integration.
For operators deploying an Entitlement Server for the first time, the TS.43 Entitlement Server Deployment Checklist provides the carrier-side readiness framework, and Architecting a Scalable Entitlement System covers high-availability design patterns for production deployment. The security architecture for Entitlement Servers blog is essential reading before any HSS-facing deployment — it covers the trust model between the CAMARA API gateway and the operator's core network.
U2opia's hosted deployment path eliminates the need for operators to build and operate the gateway layer: U2opia runs the Entitlement Server, CAMARA API compliance, enterprise billing, and settlement infrastructure, while the operator contributes HSS access and subscriber coverage. Revenue share is per verification call against the operator's subscriber base. Operators can be production-ready — live NV2 verification against their subscriber database — within 4–6 weeks of integration start. See the NumberVerify2 product page for the operator onboarding pathway and API access details.
For the broader operator revenue architecture — including how NV2 fits into a full GSMA Open Gateway API portfolio and the ARPU impact of moving a mature A2P SMS enterprise customer to network-based authentication APIs — see How Operators Monetize Authentication APIs: The Global MNO Revenue Playbook. For operators targeting the reduction in enterprise onboarding friction as a commercial lever, the entitlement-server-side analysis shows how faster enterprise API integration timelines increase the speed of per-verification revenue ramp.
Frequently Asked Questions: NumberVerify2 (NV2)
What is NumberVerify2 (NV2)?
NumberVerify2 is the CAMARA Number Verification API v2.0 — a GSMA Open Gateway standard that allows operators to verify whether a phone number matches the SIM card in a device without sending an OTP. The enterprise application asks 'does this phone number belong to this device?' and the operator's network answers with a boolean in under 500 milliseconds, with zero user steps. NV2 extends this capability to Wi-Fi sessions using a CIBA + TS.43 token, removing the primary limitation of NV1. Operators monetise NV2 by charging enterprises a per-verification fee against their subscriber database — a capability the network already runs at near-zero marginal cost.
How is NV2 different from NV1?
NV1 (CAMARA Spring24) only verifies phone numbers when the device is on a cellular data session. When the device is on Wi-Fi, NV1 cannot see the SIM identity and the verification fails, forcing a fallback to SMS OTP. NV2 (CAMARA Fall25) adds a CIBA + TS.43 token architecture: while the device is on cellular, the Entitlement Server pre-fetches a temporary token cryptographically bound to the SIM identity. When the verification request arrives on a Wi-Fi session, the enterprise presents the token, and the Entitlement Server verifies it without needing live cellular visibility. NV2 also integrates a SIM Swap risk flag into the standard verification response, replacing a separate API call required under NV1.
How does NV2 verify phone numbers over Wi-Fi?
NV2 uses the CIBA (Client-Initiated Backchannel Authentication) flow in combination with TS.43 EAP-AKA. When the device is on a 4G or 5G cellular session, the Entitlement Server issues an EAP-AKA challenge to the device's USIM application. The USIM responds using the Ki key stored on the SIM — a cryptographic proof only the physical SIM can produce. The Entitlement Server issues a temporary verification token tied to this proof. When the device moves to Wi-Fi and a verification event is triggered, the enterprise presents this token. The Entitlement Server validates it against the SIM record in the HSS, confirming the phone number match without requiring cellular visibility at the time of verification. The token has a short validity window — typically 30–120 seconds — limiting replay risk.
Which markets have NV2 deployed?
U2opia's NumberVerify2 platform covers 104+ operators across 60+ countries. NV2-ready coverage is live across South Asia (22+ MNOs), Southeast Asia (18+ MNOs), Europe (21+ MNOs), and the Americas (12+ MNOs, including three major US carriers following the July 2026 launch). Middle East, Africa, and remaining APAC markets are in active expansion. Operators not yet in the network can enquire about onboarding via the NumberVerify2 operator partnership page.
How do operators monetise NumberVerify2?
Operators monetise NV2 through a per-verification revenue share. Each time an enterprise calls the CAMARA Number Verification API against a subscriber on the operator's network, the operator receives a fraction of the per-call fee charged to the enterprise. U2opia handles API gateway operations, enterprise billing, and settlement; the operator contributes HSS access and subscriber coverage. The per-call fee is comparable to or higher than the A2P SMS termination fee for the equivalent OTP transaction — but with near-zero operator delivery cost and no AIT fraud liability. The revenue model scales directly with enterprise verification volume against the operator's subscriber base.
Does NV2 require the user to take any action?
No. NumberVerify2 is entirely passive. The verification event is triggered by the enterprise application and resolved by the operator's network — the user never sees a code, a prompt, or a waiting state. The network-based authentication mechanism is invisible to the user, which is why enterprise customers report significantly higher conversion rates relative to SMS OTP flows. The only exception is the USSD fallback path for 2G/3G devices, which requires a brief USSD session — still transparent to the user in U2opia's implementation, with no code entry required.
The Verification API Your Network Already Supports — Now Sellable
NV2 is not new infrastructure. It is a commercial wrapper around verification your network performs on every device authentication — the HSS lookup, the SIM identity check, the subscriber database query that your network runs millions of times per day as an internal operation. NumberVerify2 makes that operation billable, CAMARA-compliant, and enterprise-accessible at scale.
The US carrier launch in July 2026 has set the reference point: 300 million connections, live NV2 capability, enterprise integrations active, revenue flowing. The GSMA Open Gateway framework has given every participating operator the commercial structure to replicate that model in their own market. The regulatory mandates across six jurisdictions have given enterprise customers a compliance deadline that makes the migration non-discretionary.
The question for operators who have not yet launched NV2 is not whether enterprise customers will migrate from OTP to network-based authentication APIs. They will. The question is whether they migrate to your network's verification capability — or to an aggregator who has already built the integration layer on your infrastructure and is billing enterprises for the access. Operators who deploy NumberVerify2 now capture both the short-term migration revenue from OTP displacement and the long-term enterprise relationship that comes from being the verification layer for your customers' identity infrastructure.
See the full NumberVerify2 product and operator onboarding guide to understand what deployment looks like for your network, or explore the complete network-based authentication operator guide for the broader product suite and commercial architecture. When you are ready to scope your network's NV2 readiness, contact the U2opia operator team for a single-session technical and commercial assessment.
.png)
