
On July 8, 2026, the three largest mobile operators in the United States launched network-based authentication as a commercial API product — making CAMARA-compliant SIM verification available across more than 300 million US connections. This is not a pilot. It is not a limited beta. It is a commercial product, with enterprise pricing and developer documentation, available today.
For mobile network operators everywhere, this is the market signal that removes any remaining doubt about the direction of authentication: network-based authentication is not a future standard. It is a current commercial product that the world's largest carriers are actively selling to enterprises, banks, and developers.
This blog is written for operators. What happened. What the commercial model looks like. What the underlying technical standard requires. What the regulatory tailwinds are driving enterprise demand. And what your network needs to do to get in market with its own network-based authentication API — before the enterprise revenue opportunity migrates entirely to carriers that are already there.
KEY STAT
300M+
US connections now covered by commercial network-based authentication. AT&T, T-Mobile and Verizon, July 2026.
1. What Happened: The US Network Authentication Launch Explained
The three major US carriers launched CAMARA-compliant Number Verification — the standardised network-based authentication API — across their combined subscriber base in July 2026. The launch makes a single, standardised API for SIM-based identity verification available to enterprises and developers across AT&T, T-Mobile, and Verizon networks through a carrier-backed GSMA Open Gateway deployment.
Number Verification is the CAMARA name for what operators have long called silent authentication, SIM-based authentication, or network-based authentication. In all cases, it refers to the same core capability: verifying that the SIM in a user's device matches a registered subscriber record in the carrier's Home Subscriber Server — cryptographically, invisibly, in under 300 milliseconds, without the user doing anything.
The commercial significance of the US launch is threefold.
First, scale. 300 million connections covered from day one is the largest single-market deployment of network-based authentication in history. There is no ambiguity about whether the US market has arrived. It has.
Second, standardisation. The CAMARA API means enterprises integrate once and reach all three carriers through the same interface. This is the outcome GSMA Open Gateway was designed to create — and it is now commercially live in the world's most important enterprise software market.
Third, commercial validation. Three of the world's most financially sophisticated mobile operators have put a per-verification enterprise pricing model on this capability. The business case is no longer theoretical. The revenue model is proven.
2. What Is Network-Based Authentication?
Network-based authentication is a method of verifying a user's identity using the mobile carrier network itself — without sending an OTP code, requiring app interaction, or asking the user to do anything. The carrier's network validates the cryptographic credentials in the user's SIM card against its subscriber database and returns a confirmed identity match in under 300 milliseconds.
The mechanism is EAP-AKA (Extensible Authentication Protocol – Authentication and Key Agreement), the cryptographic protocol built into every SIM manufactured since the late 1990s. EAP-AKA performs a challenge-response exchange using keys burned into the SIM at manufacture — keys that cannot be extracted, copied, or intercepted. The SIM key never leaves the SIM. The carrier's HSS (Home Subscriber Server) holds a matching key. The challenge-response proves that the device holds the legitimate SIM without revealing anything that could be stolen or replayed.
The GSMA TS.43 standard (Service Entitlement Configuration, Release 11) defines how a carrier's entitlement server orchestrates this EAP-AKA exchange over a data channel — and how it falls back to USSD signalling for 2G and 3G devices where the data path may not be available. Learn more about TS.43 in our entitlement server guide for MNOs.
Network-Based Authentication vs SMS OTP
The contrast with SMS OTP is fundamental, not incremental. SMS OTP is architecturally interceptable: it sends a human-readable code that passes through the user's hands, which means an attacker can phish it in real time. Network-based authentication has no code. The proof of identity is a cryptographic exchange that happens entirely at network infrastructure level, invisible to the user and inaccessible to any attacker without physical possession of the SIM itself.
For operators, the comparison also matters from a revenue quality perspective. SMS OTP generates A2P SMS traffic that is permanently exposed to AIT (Artificially Inflated Traffic) fraud — costing operators over $1.2 billion annually across the industry. Network-based authentication generates per-verification API calls against your own subscriber database, with zero AIT exposure and materially higher per-event margins.
3. The Commercial Model: How US Carriers Are Selling Auth as an API
The commercial model for network-based authentication is straightforward: enterprises pay a per-verification fee for each API call against the carrier's subscriber database. The carrier receives a per-call revenue share. There is no setup fee to the enterprise for basic integration, and the pricing is usage-based — enterprises pay more as their verification volumes grow, which is naturally correlated with their own customer growth.
The enterprise buyer pool is large and growing. Any business that currently sends SMS OTP to verify customer identity is a potential buyer of network-based authentication. This includes every bank, every fintech, every e-commerce platform, every ride-hailing and super-app operator, and every enterprise running customer-facing authentication flows. In regulated sectors — financial services, healthcare, government services — the regulatory pressure to move away from SMS OTP is now explicit and in force in multiple markets.
For operators, the per-verification margin is materially better than A2P SMS on two dimensions. First, there is no AIT fraud surface: the verification is a direct API call against your own subscriber record, not a message delivery that can be artificially inflated. Read more about what AIT fraud costs operators in our true cost of SMS OTP analysis. Second, the capability being sold — SIM cryptographic verification — is native to your network infrastructure and has zero marginal cost per verification once the entitlement server is deployed.
The US carriers are accessing this enterprise demand through a GSMA Open Gateway deployment — a standardised API gateway that allows enterprise developers to integrate once and reach all participating operators through a single interface. This is not the only route to market: operators can also sell directly to enterprises via their own API portals, or route through a specialised aggregator like U2opia that connects operator capability to enterprise demand and handles billing settlement.
COMMERCIAL NOTE FOR OPERATORS
The US carrier launch establishes the commercial precedent: per-verification API pricing, enterprise channel via GSMA Open Gateway, no per-message AIT exposure. Operators globally now have a reference model to take to their own commercial and regulatory teams. See our revenue playbook: How Operators Monetize Authentication APIs.
4. The Technical Standard Behind the Launch: CAMARA, TS.43, and GSMA Open Gateway
The US carrier launch is built on three interlocking standards that together define the technical architecture of network-based authentication. Operators planning to deploy their own capability need to understand all three.
CAMARA — The API Standard
CAMARA is an open-source project within the Linux Foundation and GSMA that defines standardised API interfaces for telco network capabilities. The Number Verification API is a CAMARA-defined interface — it specifies how enterprises call the carrier's network to verify a phone number match, what the request and response format looks like, and how authentication and consent are handled. CAMARA means an enterprise developer who integrates with AT&T's Number Verification in the US can use the same integration pattern to reach a CAMARA-compliant operator in India, Southeast Asia, or MENA. Learn more at the CAMARA Project.
TS.43 — The SIM Authentication Mechanism
The CAMARA Number Verification API is the enterprise-facing interface. Underneath it, the authentication mechanism is TS.43 EAP-AKA. When an enterprise calls the CAMARA Number Verification API, the carrier's entitlement server issues an EAP-AKA challenge to the SIM using the TS.43 framework. The SIM responds with a cryptographic proof. The carrier's HSS verifies the response. The CAMARA API then returns a confirmed match or no-match. For operators, TS.43 entitlement server deployment is the critical infrastructure step that makes the CAMARA API possible. Our entitlement server deployment guide for MNOs covers this in detail.
GSMA Open Gateway — The Distribution Channel
GSMA Open Gateway is the operator alliance that aggregates participating carriers behind a common CAMARA API layer — making their combined subscriber base reachable through a single integration point. As of 2026, GSMA Open Gateway represents 86 operator groups covering approximately 80% of the world's mobile connections. The US carrier launch brought the largest English-language mobile market into this network. The commercial implication: an enterprise that integrates with GSMA Open Gateway now reaches US, European, Asian, and MENA subscribers through a single API. For operators that are already GSMA Open Gateway members, the US launch expands the enterprise value proposition of the channel they are already participating in.
Operators that are not yet CAMARA-compliant or not yet connected to GSMA Open Gateway are effectively outside the distribution channel that US, European, and major Asian enterprise developers are now standardising on. The NumberVerify2 (NV2) page covers the latest CAMARA Number Verification spec in detail.
5. Why the US Launch Matters for Operators Everywhere
The immediate impact of the US launch is confined to the US market — enterprises deploying Number Verification via AT&T, T-Mobile, and Verizon can now reach 300 million US connections. But the downstream implications extend to every operator globally, for three reasons.
Enterprise buyer expectations are now set globally. An enterprise CTO who has integrated CAMARA Number Verification for their US user base now knows exactly what network-based authentication costs, what the API looks like, and what conversion improvement they can expect. When they expand to India, Southeast Asia, or MENA, they will look for the same CAMARA-compliant API. Operators in those markets who are not CAMARA-ready will lose that API revenue to operators who are. See our guide to silent network authentication for operators for the global picture.
GSMA Open Gateway now has a US commercial anchor. The GSMA Open Gateway initiative covers 80% of global mobile connections — but until July 2026, it lacked a major US commercial deployment. The US launch changes the enterprise sales narrative from 'global coverage except the US' to 'truly global.' This accelerates enterprise adoption of the CAMARA API standard, which benefits every operator in the GSMA Open Gateway network.
The per-verification revenue model is commercially validated at scale. Operators that have been evaluating network-based authentication as a revenue product now have the largest mobile market in the world as a reference case. The commercial model — per-verification API fee, enterprise channel via GSMA Open Gateway, no AIT exposure — is no longer hypothetical. See our upcoming MNO authentication API monetization guide for the full operator revenue playbook.
For operators that are already deployed — particularly those in U2opia's SilentAuth+ network — the US launch expands the enterprise market they can sell into. US enterprises now primed on CAMARA will seek CAMARA-compliant verification for their global user bases. Operators in 60+ countries that are already CAMARA-ready through SilentAuth+ for operators are the natural beneficiaries.
6. The Regulatory Tailwinds Driving Enterprise Adoption
The US carrier launch is accelerating a demand shift that regulatory mandates were already creating. Across four major markets, SMS OTP has been formally restricted or replaced by regulation — in force now, not upcoming. In the US, NIST guidance published in July 2025 reclassified SMS OTP as a restricted authenticator that fails AAL2. The result is a global enterprise buyer base that is simultaneously being pushed off SMS OTP by regulators and pulled toward CAMARA-compliant network authentication by a now-proven commercial product.
For operators, the regulatory picture translates directly into a qualified buyer pool. Every enterprise operating in these markets now has a compliance obligation to replace SMS OTP. Network-based authentication is the only solution that is simultaneously phishing-resistant, zero-friction, and reachable across the operator's full subscriber base — including 2G and 3G devices. The NIST 800-63B-4 carrier API playbook covers the US regulatory angle in depth.
For a complete global regulatory tracker, see our SMS OTP Ban Tracker — updated quarterly with status across 15+ markets.
7. What Operators Need to Do Now
The US launch has set a competitive benchmark. Operators that want to participate in the enterprise authentication API revenue market need to be able to offer a CAMARA-compliant number verification product to their enterprise customers. Here is what that requires.
Operators that try to build all of this from scratch face an 18–24 month deployment timeline and significant capex. Operators that partner with U2opia through SilentAuth+ for operators can reach commercial deployment on a compressed timeline, with U2opia handling entitlement server deployment, CAMARA compliance, enterprise routing, and revenue settlement.
8. SilentAuth+ and U2opia: 104+ Operators Already in Market
While the US market launched in July 2026, network-based authentication has been commercially deployed across 104+ operators in 60+ countries through U2opia's SilentAuth+ platform. SilentAuth+ is U2opia's TS.43 EAP-AKA implementation — with a USSD fallback layer that extends silent authentication to 2G and 3G networks, the only implementation that does so at commercial scale.
For operators in the SilentAuth+ network, the US launch is directly additive: US enterprises now seeking to extend CAMARA Number Verification to their global user bases will look for CAMARA-compliant operators in India, Southeast Asia, MENA, and Africa. SilentAuth+ operators in those markets are the natural fulfilment layer for that demand.
For operators not yet deployed, SilentAuth+ offers the fastest path to market. The commercial model is revenue-share from day one — no upfront capex, no enterprise sales infrastructure, no billing infrastructure to build. U2opia handles entitlement server deployment and management, CAMARA compliance through NumberVerify2 (NV2), enterprise demand routing, and per-verification settlement. The operator provides network access and earns per-call revenue.
SilentAuth+ is CAMARA-compliant via the NumberVerify2 (NV2) API — the CAMARA Fall 2025 stable release of the Number Verification specification. This means SilentAuth+ operators are compatible with the same CAMARA interface that US enterprises are now standardising on. For a complete view of the authentication products available to operators, including SIM swap detection and phone number verification, see the U2opia authentication hub.
OPERATOR PARTNERSHIP
104+ operators. 60+ countries. Revenue from day one. If your network is not yet in market with network-based authentication, talk to U2opia's operator partnerships team about SilentAuth+ deployment.
9. Key Takeaways for Operators
The US carrier launch is a commercial landmark — but it is not the finish line. It is the moment at which network-based authentication shifted from an emerging technology to an expected API product. Enterprises in the US now know what it costs, what it does, and how to integrate it. They will expect the same from operators in every market they operate in.
For operators globally, the window to get ahead of this demand is narrowing. The U2opia authentication platform is deployed across 104+ operators today. The commercial model — per-verification revenue share, no capex, CAMARA-compliant from day one — is designed to get operators to market quickly on the right side of an enterprise buyer shift that is already in motion.
Three actions for operators reading this:
First: Assess where you stand on TS.43 entitlement server deployment. If you don't have one, that is the critical path item.
Second: Map your enterprise customer base for authentication API demand. Banks, fintechs, and e-commerce platforms operating in regulated markets are already looking for a network auth solution from their preferred carrier.
Third: Contact U2opia. SilentAuth+ for operators is the fastest path from assessment to commercial revenue — without building anything from scratch.
Frequently Asked Questions
What did AT&T, T-Mobile and Verizon launch in July 2026?
AT&T, T-Mobile, and Verizon launched network-based authentication — specifically the CAMARA Number Verification API — as a commercial product across their combined US subscriber base in July 2026. Number Verification uses SIM cryptographic credentials (EAP-AKA via TS.43) to verify that the SIM in a user's device matches the phone number they claim, without sending an OTP code or requiring any user action. The three carriers deployed this through a carrier-backed GSMA Open Gateway consortium, making a single CAMARA-compliant API available to enterprises and developers across 300 million US connections.
What is network-based authentication and how is it different from SMS OTP?
Network-based authentication verifies user identity through the carrier network itself — using EAP-AKA cryptography built into every SIM — rather than sending a one-time code. SMS OTP creates a phishable code that passes through the user's hands; network-based authentication has no code and therefore no phishable surface. Network-based authentication completes in under 300ms versus 10–30 seconds for OTP delivery, requires zero user action, satisfies NIST SP 800-63B-4 AAL2 phishing-resistance requirements (SMS OTP fails AAL2), and eliminates the AIT fraud surface that costs operators over $1.2 billion annually on SMS routes.
How do operators make money from network-based authentication?
Operators earn per-verification API revenue on every authentication call against their subscriber database. When an enterprise customer calls the network-based authentication API to verify a subscriber's identity, the operator earns a per-call revenue share. This is a new revenue line built on existing network infrastructure — the carrier already performs SIM authentication for every call, data session, and roaming event. Network-based authentication monetises that existing capability as an enterprise API product, at higher per-event margins than A2P SMS, with zero AIT fraud exposure. See our operator authentication monetization guide for the full revenue model.
What technical standards do operators need to deploy network-based authentication?
Three standards are required. CAMARA defines the enterprise-facing API interface (Number Verification). TS.43 (GSMA Release 11) defines the entitlement server mechanism that enables EAP-AKA SIM authentication. GSMA Open Gateway provides the distribution channel that aggregates operator capability behind a single CAMARA API layer. At the infrastructure level, operators need a TS.43 entitlement server connected to their HLR/HSS, CAMARA compliance for the enterprise API, and either a GSMA Open Gateway connection or a specialist aggregator to route enterprise demand. U2opia deploys all of this for operators through SilentAuth+ for operators.
What is U2opia SilentAuth+ and how does it relate to the US carrier launch?
SilentAuth+ is U2opia's network-based authentication platform — TS.43 EAP-AKA with a USSD fallback channel, deployed across 104+ operators in 60+ countries. SilentAuth+ is CAMARA-compliant via NumberVerify2 (NV2) — the same CAMARA Number Verification standard that the US carriers launched with. This means SilentAuth+ operators in India, Southeast Asia, MENA, and Africa use the same API interface that US enterprises are now standardising on. US enterprises that have integrated CAMARA Number Verification for their US user base can extend to SilentAuth+ markets with the same integration code. Contact U2opia to discuss operator deployment.
.png)

