PasskeyBridge

Intel · 2026-04-16

Carrier Monetization of Identity Signals: The $4B Opportunity Reshaping Telecom Revenue

By J. W. Bouckaert

Carrier Monetization of Identity Signals: The $4B Opportunity Reshaping Telecom Revenue

The structural economics of telecommunications are shifting. For two decades, carriers extracted identity revenue passively—collecting per-message fees on A2P SMS used for OTP delivery, authentication codes, and transaction verification. That model is in terminal decline.

What's replacing it is more interesting, more profitable, and more consequential for the identity verification industry: carriers are now actively monetizing the raw identity signals embedded in their network infrastructure. SIM status events, device binding confirmations, number portability records, and subscriber attribute verifications are being repackaged as standardized API products—and the revenue trajectory is steep.

This isn't speculative. As of April 2026, 86 operator groups representing more than 300 networks and 80% of global mobile connections are commercially aligned around a shared API framework under the GSMA Open Gateway initiative. More than 300 instances of 20 different CAMARA APIs have been commercially launched across 65 markets worldwide.

The question is no longer whether carriers will monetize identity signals. It's how fast the revenue scales—and who captures the margin.

The decline that forced the pivot

Global A2P SMS revenue peaked around 2022. Since then, the trajectory has been decisively downward, driven by three converging forces:

OTP displacement. Passkeys (WebAuthn/FIDO2), push-based authentication, and TOTP apps have eliminated SMS OTP for security-conscious enterprises. Apple and Google's platform-level passkey support accelerated this faster than any industry analyst predicted.

Grey-route compression. Unauthorized SMS routing through grey routes has eroded carrier margins on legitimate A2P traffic. Despite GSMA and carrier efforts to close these routes, the economics of SMS fraud arbitrage remain favorable for bad actors.

Regulatory price caps. Multiple jurisdictions—including the EU under the European Electronic Communications Code—have imposed or proposed caps on A2P SMS termination rates, further compressing carrier revenue per message.

The result: carriers needed a new identity-adjacent revenue stream that used their existing network infrastructure without depending on message delivery economics.

GSMA Open Gateway: The standardization catalyst

The GSMA Open Gateway initiative, launched at MWC23 Barcelona, provided the commercial framework carriers needed. Built on CAMARA—a Linux Foundation project defining standardized telecom API specifications—Open Gateway solved the two problems that had historically prevented carrier API monetization at scale:

Fragmentation. Before CAMARA, every carrier exposed identity signals through proprietary APIs with different schemas, authentication mechanisms, and response formats. An integrator building against Vodafone's SIM Swap API had to rebuild entirely for Orange. CAMARA standardized the interface: a SIM Swap check against Telefónica in Spain uses the same API contract as one against T-Mobile in the United States.

Distribution. Carriers historically lacked developer-facing go-to-market channels. Open Gateway solved this by onboarding 60+ channel partners—including hyperscalers (Google Cloud, AWS, Microsoft Azure), CPaaS providers (Vonage, Twilio), and aggregators—who embed network APIs into their existing developer platforms.

The CAMARA identity API portfolio

Three CAMARA APIs form the core of carrier identity monetization:

APICAMARA VersionFunctionCommercial Status
Number Verifyv1.0 (GSMA Certified)Silent device-based phone number confirmation—no SMS sentLive in 65+ markets
SIM Swapv1.0 (GSMA Certified)Detects recent SIM card changes on a given MSISDNLive in 65+ markets
KYC Matchv0.3 (Pre-release)Verifies subscriber attributes against operator recordsPilot deployments
Device Swapv0.2 (Draft)Detects when a phone number moves to a new device (IMEI change)Limited trials

Number Verify and SIM Swap have achieved "GSMA Certified API" status—meaning they've passed interoperability testing across multiple operators and markets. KYC Match is the next major commercial opportunity, with Juniper Research identifying it as key to pushing network API revenue growth beyond initial fraud-prevention use cases into regulated verticals like eCommerce, gambling, and financial services.

The revenue math

The numbers tell a clear story of exponential growth from a low base:

Metric20252028 (est.)2030 (est.)Source
Global network API operator revenue$284M~$4B$8B+Juniper Research (Aug 2025)
Mobile identity API revenue$2.4B~$12BJuniper Research (Mar 2025)
Mobile identity API share of total identity revenue~50%>60%Juniper Research
CAMARA APIs commercially deployed~150 instances500+ (proj.)GSMA
Markets with live identity APIs40+65+80+ (proj.)GSMA Open Gateway

The $284 million to $8 billion trajectory represents a 28x increase over five years. Even accounting for analyst optimism, the directional signal is unambiguous: carriers are building a multi-billion-dollar business line from assets they already own.

Margin

The economics of carrier identity APIs differ fundamentally from SMS:

SMS OTP was a volume game with thin margins. Carriers earned fractions of a cent per message, with revenue split across originating carriers, terminating carriers, and aggregators. Grey-route fraud further compressed realized revenue.

Identity APIs are a value game with thick margins. A Number Verify call costs the carrier near-zero marginal compute (it's a network-layer lookup against existing HLR/HSS infrastructure). Pricing ranges from $0.01–0.05 per API call for Number Verify to $0.03–0.10 for SIM Swap checks, depending on volume tier and market. At scale, gross margins exceed 80%—comparable to SaaS rather than telecommunications.

The unit economics explain why carriers are investing aggressively. A carrier with 100 million subscribers generating even 10 identity API calls per subscriber per year at $0.03 per call produces $30 million in near-pure-margin revenue—from infrastructure that's already deployed and amortized.

Carrier by carrier

Telefónica

The most aggressive mover in carrier identity APIs globally. Telefónica's Open Gateway portal offers both SIM Swap (v1.0) and Number Verification (v1.0) as GSMA Certified APIs, with sandbox environments for developer testing. At MWC26 Barcelona, Telefónica announced accelerated global rollout with new agreements across multiple technology firms and markets. Their CAMARA API deployments span Spain, Germany, the UK, Brazil, and expanding Latin American markets.

Deutsche Telekom

Deutsche Telekom's T-Wholesale division partnered with Google to deliver second-generation Phone Number Verification (PNV) that operates over WiFi and in Airplane Mode—a significant technical advancement that removes the cellular-connectivity requirement that limited first-generation Number Verify. This was presented at MWC26 Barcelona and signals Google's strategic investment in carrier-sourced identity signals as an alternative to SMS-based verification in Android.

U.S. carriers (AT&T, T-Mobile, Verizon)

In a first for the three companies, AT&T, T-Mobile, and Verizon announced a joint initiative through Aduna on 27 February 2025 to bring standardized 5G Network APIs—including Number Verification and SIM Swap—to the U.S. market. The significance: U.S. carriers have historically resisted shared API platforms, preferring proprietary approaches. Their alignment around CAMARA standards signals that the commercial opportunity has overcome competitive reluctance.

Orange

Orange Developer offers a comprehensive digital identity and fraud prevention suite built on CAMARA APIs, spanning France and multiple African markets. Their deployment highlights the global applicability of carrier identity APIs—the same standardized interface serves both European regulatory environments and emerging markets where mobile identity is often the primary form of digital identity.

Consequences for identity aggregators

The carrier identity monetization wave creates a structural bifurcation in the aggregator market:

Aggregators at risk

Pure-play SMS aggregators that repositioned as "identity verification" providers by wrapping carrier SIM Swap and Number Verify APIs face existential pressure. As carriers sell directly through hyperscaler partnerships and their own developer portals, the aggregation margin compresses toward zero. If your value proposition is "we integrated the Vonage Number Insight API and the Twilio Lookup API so you don't have to," the value of that integration decreases as CAMARA standardization makes the underlying APIs interchangeable.

Aggregators with defensible position

Platforms operating above the signal layer—those that correlate, fuse, and attest identity signals rather than merely proxying them—retain structural advantage. The differentiation:

Multi-signal fusion. No single carrier API provides a complete identity picture. A SIM Swap check confirms the SIM hasn't changed; it says nothing about whether the device is physically present, whether the user's biometric binding is intact, or whether a Verifiable Credential corroborates the claimed identity. Platforms that fuse carrier signals with passkey attestation data, VC verification, and behavioral signals create composite trust scores that no single carrier can replicate.

Cross-carrier correlation. In multi-SIM markets (common across Africa, Southeast Asia, and parts of Europe), a user's identity is distributed across multiple carriers. An aggregator querying SIM Swap status from Carrier A and Number Verify from Carrier B—and cryptographically binding the results—provides a verification layer that neither carrier can offer independently.

Attestation and provenance. Raw carrier API responses are unsigned JSON payloads. An aggregator that wraps carrier signals in PQC-signed attestations, records them in an immutable audit trail, and issues Verifiable Credentials based on the fused result creates a trust artifact with legal and cryptographic standing that a bare API call lacks.

Latency and resilience. Direct carrier API integration requires managing per-carrier rate limits, authentication mechanisms, and failure modes. Enterprise customers increasingly prefer a single integration point with built-in circuit breakers, fallback signal weighting, and in-request response—capabilities that require orchestration infrastructure carriers don't provide.

The agentic multiplier

The next acceleration vector is machine-to-machine identity verification. As agentic AI systems proliferate in commerce, customer service, and financial operations, every autonomous agent action that touches a phone-number-linked identity will generate a carrier API call. The volume implications are significant:

A single human user might trigger 2–5 identity verification events per day (login, transaction, step-up). An AI agent managing a portfolio of accounts might trigger hundreds per hour. If agentic commerce reaches the $1.5 trillion in transaction volume by 2030 that Juniper Research projects, the demand for real-time carrier identity signals will scale proportionally.

The GSMA has recognized this. At MWC26, Telefónica and Nokia demonstrated Agent-to-Agent (A2A) protocols using Model Context Protocol (MCP) to orchestrate carrier API calls autonomously—automatic API discovery, intelligent capability selection, and multi-API chaining without human intervention. This is the infrastructure that makes carrier identity signal consumption programmable at machine scale.

The structural risks

Carrier identity monetization isn't without headwinds:

Privacy regulation. SIM Swap and Number Verify APIs, while privacy-preserving in design (they return boolean or timestamp responses, not subscriber PII), still involve the carrier processing a phone number to generate the response. Under GDPR, this constitutes personal data processing. Schrems III regulatory developments could further complicate cross-border carrier lookups, particularly for global enterprises that need to verify identities across jurisdictional boundaries.

Carrier reliability. Carrier APIs inherit the operational characteristics of telecom infrastructure—planned maintenance windows, network partitions, and variable latency. Identity verification systems that depend on synchronous carrier API responses need circuit-breaker patterns and cached-proof fallback mechanisms to maintain availability during carrier outages.

Single-provider risk. Relying on a single carrier's SIM Swap API for fraud detection is a single-provider failure scenario. If the carrier's HLR data is stale, the API returns an incorrect "no swap detected" result, and the fraud succeeds. Multi-carrier signal fusion and independent signal correlation are essential for production identity systems.

Interoperability gaps. Despite CAMARA standardization, real-world implementations still vary. Response latency ranges from 50ms to 800ms depending on carrier, market, and API. Error handling semantics differ. Some carriers support real-time SIM Swap detection; others report daily batch updates. Aggregators must normalize these variations to provide consistent service levels.

Strategic implications

For enterprises consuming identity signals: diversify your carrier sources, demand PQC-signed attestations on every signal response, and build your verification stack for the agentic scale that's coming—not the human-only scale you're operating at today.

For carriers: the window for building direct enterprise relationships is open now. Once aggregator platforms embed your APIs into their orchestration layers and add attestation, fusion, and audit capabilities on top, the enterprise relationship belongs to the aggregator—not the carrier.

For identity platforms: the game has shifted from "who can integrate the most carrier APIs" to "who can build the most trustworthy attestation layer on top of carrier signals." Raw signal access is commoditizing. Trust infrastructure is not.

---

PasskeyBridge operates as an identity attestation and signal orchestration layer that fuses carrier signals (via Vonage and Twilio APIs) with passkey attestations and Verifiable Credentials into PQC-signed composite trust scores. Learn more about our carrier signal fusion architecture or explore our API documentation.

Start free · Test the API