Number Verification Without SMS OTP: How Network APIs Enable Silent Authentication
By PAiCore Technology ● 4 min read
Can a mobile number be verified without sending an SMS OTP?
Yes. And Network APIs are making it possible.
Traditionally, digital services verify a mobile number by sending an SMS one-time password (OTP). While widely used, this approach introduces additional user interaction and can create opportunities for phishing and social-engineering attacks.
Network APIs and SIM-based authentication are enabling a different approach—using trusted signals from the mobile network to verify a user’s mobile number.
The GSMA Open Gateway Number Verification API, developed within the CAMARA ecosystem, enables applications to verify or retrieve the mobile phone number associated with a device.
It can support silent authentication, allowing verification to take place without requiring the user to manually enter an SMS OTP.
How Does Number Verification Work?
The application interacts with a standardised API, while the underlying authentication process can use network-based or SIM-based mechanisms.
At a high level, the architecture can be represented as:
Application → Network API → Gateway → Telecom Network / Authentication Infrastructure
From the application’s perspective, the process can remain simple.
Behind the API, however, multiple network and authentication components may work together to establish and verify the subscriber’s identity.
This is where a Network API Gateway becomes an important architectural component.
The Role of the Network API Gateway
The PAiCore Network API Gateway provides an interworking layer between modern API applications and telecom signalling environments, including SS7/MAP and Diameter.
This allows network capabilities to be exposed through modern APIs without requiring application developers to implement telecom-specific signalling protocols.
The gateway effectively bridges two different worlds:
Modern API Applications
↓
HTTP / REST
↓
Network API Gateway
↓
SS7 / MAP / Diameter
↓
Telecom Network
This abstraction allows developers to consume network capabilities through familiar API interfaces while operators can continue leveraging their existing telecom infrastructure.
Explore the PAiCore Network API Gateway
The PAiCore Network API Gateway supports multi-protocol interworking between REST/HTTP, SS7/MAP, and Diameter, along with CAMARA-aligned Network API use cases such as Number Verification.
Explore the PAiCore Network API Gateway →
SIM-Based Authentication and the Entitlement Layer
Number Verification can also involve SIM-based authentication mechanisms.
Depending on the implementation and network architecture, the authentication ecosystem can include an Entitlement Server based on GSMA TS.43, which defines a framework for service entitlement configuration.
GSMA ASAC specifications further extend the authentication model for scenarios including Wi-Fi connectivity.
This introduces another important architectural layer:
Application → Network API → Network API Gateway → Authentication / Entitlement Infrastructure → Mobile Network
For operators implementing these capabilities, the ability to integrate the API layer with the underlying entitlement and authentication infrastructure becomes essential.
PAiCore ECSaaS
PAiCore ECSaaS provides an entitlement capability that can be integrated with Network API architectures to support standardised authentication and Number Verification experiences.
Combined with the PAiCore Network API Gateway, this architecture can help connect modern application interfaces with the underlying telecom and authentication infrastructure required to deliver network-based verification.
The result is a more seamless authentication experience while allowing operators to make better use of capabilities already available within their networks.
Why Silent Authentication Matters
Moving beyond SMS OTP can provide several advantages for digital services and users.
Reduced User Friction
Users don’t necessarily need to wait for an SMS, retrieve a code, and manually enter it into an application.
Stronger Network-Based Trust
Verification can leverage information and authentication mechanisms associated with the mobile network and SIM.
Improved User Experience
A more seamless verification flow can reduce interruptions during account registration, login, or other authentication journeys.
New Network API Use Cases
Number Verification is part of a broader movement toward using trusted mobile-network capabilities for identity, security, fraud prevention, and other digital services.
The Mobile Network as an Identity Platform
For decades, mobile networks have primarily been viewed as connectivity infrastructure.
Network APIs are changing that perspective.
Capabilities traditionally embedded within telecom infrastructure can increasingly be exposed through standardised APIs and consumed by applications, enterprises, and digital platforms.
Number Verification is one example of this shift.
The mobile network is becoming an identity platform—not just a connectivity platform.
As GSMA Open Gateway and CAMARA continue to standardise Network API capabilities, the opportunity for operators is to transform existing network intelligence into services that developers can consume through modern APIs.
Explore and Test the Open-Source Project
The evolution of Network APIs depends not only on standards, but also on open technologies that developers and telecom engineers can explore, test, and build upon.
The PAiCore Network API Gateway is available as an open-source project, providing developers, system integrators, and telecom engineers with an opportunity to explore the technology behind modern telecom signalling and Network API architectures.
Explore the Project on GitHub
Explore & Test the PAiCore Network API Gateway on GitHub →
We welcome developers, telecom engineers, system integrators, and the wider open-source community to explore the project, test the implementation, share feedback, and contribute to its continued development.
Standards & Industry References
The development of Number Verification and SIM-based authentication is supported by several industry standards and initiatives:
- GSMA Open Gateway Number Verification API →
API reference for the Open Gateway Number Verification capability. - GSMA TS.43 – Service Entitlement Configuration →
Specification covering service entitlement configuration and related mechanisms. - GSMA ASAC.01 →
Specification related to authentication and service access capabilities. - GSMA Open Gateway API Descriptions →
Overview of the standardised Network API portfolio.
The Future of Mobile Identity
SMS OTP has played an important role in digital authentication, but the evolution of Network APIs is opening new possibilities.
By combining standardised APIs, network-based authentication, SIM capabilities, and telecom infrastructure, operators can provide applications with trusted network intelligence through simpler interfaces.
The architecture may be complex underneath.
But the experience for the user doesn’t have to be.
The future of mobile identity could be silent, network-based, and API-driven.
Explore the Network API Gateway. Test the open-source project. And help shape the next generation of programmable telecom networks.
