By Javier Beceiro and Juan Andrés Antoniuk · Presented at Antel Summit 2026
When a transaction is instant and irreversible, there’s no room for error. There’s no dispute process, no reconciliation cycle that buys time to review it. Either the transaction is verified as good before it executes, or the fraud has already happened.
That’s the reality reshaping digital payments — and also the context that makes Open Gateway worth talking about.
Mobile networks know things no app can know on its own. They know if you swapped your SIM this morning. They know if your device is roaming in another country. They know if someone ported your number to another line five minutes ago. That information exists, it’s in the network, in real time.
The problem is that, for years, each carrier exposed it its own way — when it exposed it at all. Anyone wanting to integrate those capabilities into an app had to negotiate separately with each operator, build custom integrations, and repeat the work in every market. The result was predictable: fragmented rollouts, expensive integrations, and capabilities that ended up out of reach for most players.
Open Gateway sets out to fix that with a simple decision: a common access point, a single standard for mobile networks to expose their capabilities to the market.
Behind Open Gateway there are three players worth distinguishing. The GSMA is the international association that promotes and aligns the initiative. CAMARA is the open-source project, governed by the Linux Foundation, that defines each API’s technical specifications: how it should behave, what it returns, how it’s documented. Operators implement those specifications and offer the services — either directly or through aggregators like AWS, Google Cloud, or Microsoft Azure.
The scale is already significant: 86 operator groups, representing close to 80% of the world’s mobile connections, with more than 300 live commercial API instances across 65 markets. CAMARA’s latest meta-release closed with 60 APIs at various stages of development, 10 of them in stable status — with 1.0 versions and guaranteed backward compatibility — and around 20 commercially available to contract. The gap between what’s specified and what’s actually contractable is real, and that’s where much of the action is.
The most relevant APIs today cover three broad areas: authentication and fraud prevention, device information, and quality of service. The three that come up most in financial services are:
Number Verification confirms that the phone number provided matches the one associated with the mobile connection the operation is being carried out from — no SMS, no code to type. The check happens directly on the network, in milliseconds, transparently to the user. Useful for fintech onboarding, password recovery, or any flow that currently relies on an SMS OTP.
SIM Swap detects whether the number was recently moved to a new SIM. A direct signal for one of the most common fraud mechanisms: the attacker calls the carrier posing as the victim, convinces an agent to issue a new SIM, and redirects all messages to their own device.
Call Forwarding Signal detects whether call forwarding is active on the number. This covers a subtler fraud vector: the attacker doesn’t need to swap the SIM, they just need the victim — talked into it over the phone — to unknowingly enable call forwarding.
Device Swap detects whether the service is being accessed from a different device than usual. It can indicate a legitimate phone upgrade or a fraud pattern. The business decides how to weigh that signal.
Device Roaming Status reports whether the number is roaming and in which country. Useful for geographic fraud detection, territorial licensing restrictions, and experience segmentation.
Device Reachability Status indicates whether a number can be reached via SMS, data, or both. It allows choosing the right communication channel before attempting to send — relevant for emergency services, customer support, and IoT fleet management.
Still in development, but already in use: KYC Match and KYC Age Verification, which allow verifying user data against the operator’s records without the operator disclosing any data — it only confirms a match or whether the person is of legal age. And Quality of Service Booking, which allows reserving network conditions for a specific time and location: live broadcasts, remote surgery, competitive gaming.
Juan Andrés Antoniuk — a telecommunications engineer with more than a decade in the payments industry — put into perspective why fraud prevention is today Open Gateway’s most compelling use case.
The global shift toward account-to-account (A2A) payments — Pix in Brazil, Toke in Uruguay — is changing two fundamental things. First: payments are instant and irreversible. There’s no room for after-the-fact corrections. Second: the identity key is no longer the card, it’s the phone number.
When the phone number is the payment credential, compromising that number means compromising a person’s financial access. And traditional fraud-detection engines — based on probabilistic inference, user history, behavior — have a blind spot: they can’t see what’s happening on the network. A device’s GPS can easily be spoofed. But which cell tower a phone is connected to at the moment of a transaction — an app can’t know that. Only the network knows.
And fraud has gotten more sophisticated: according to Sumsub, 42.5% of fraud attempts in the financial sector are now AI-generated — cloned voices, real-time video (2). In the extreme case, the victim themselves authorizes the transfer, convinced by a phone call, and the risk engine doesn’t flag anything unusual because everything looks legitimate.
That’s Open Gateway’s contribution: it doesn’t replace existing fraud engines, it adds a layer of determinism. Voice can be faked. The status of the line can’t. The network doesn’t infer: it knows, with a timestamp. When the SIM was swapped, whether forwarding is active, which line you’re connecting from. These are facts, not estimates. With a clear limit: around 12% of queries can come back as «unknown» — if the device is connected via Wi-Fi rather than the cellular network. Determinism doesn’t mean full coverage, but it adds a certainty that simply didn’t exist before.
Juan Andrés used an analogy worth keeping. Apple Pay and Google Pay arrived in Uruguay at the end of 2024. But the technology behind them — the tokenization that makes paying with your phone possible — had been in the works since 2019. Adoption was fast. The rails took years.
The market is starting to confirm the direction: consumption of network APIs grew 91% during 2026, led by the financial sector.
Open Gateway is at the rail-laying stage. Mass adoption will come once the standards are widely enough deployed and the use cases are proven. And the use cases are already proven.
Itaú Unibanco (Brazil, 2023): started with SIM Swap and later added other APIs, including Number Verification, to eliminate OTPs for trusted customers’ transactions. The logic is simple: if a transaction comes from the same phone it always has, asking the user to type in a code adds no security, only friction. It now handles 36 million queries and is the highest-volume Open Gateway deployment in the world (3,4)
Anonymous bank (United Kingdom, March 2024): implemented SIM Swap via the aggregator Sekura.id. In one month, out of 3 million queries: 87% of users hadn’t changed SIMs and went through with no added friction; 12% came back unknown and were processed through traditional mechanisms; 1% had recently swapped SIMs and were routed to manual review. If even 1% of those flagged cases were real fraud, the bank would have avoided up to £930,000 in losses in that single month. The operational takeaway is clear: friction gets concentrated on those who warrant it.
Vodafone UK (April 2024): launched Scam Signal, its own product aligned with CAMARA’s guidelines, to target impersonation fraud. The signal it uses — active call forwarding — is the one CAMARA later standardized as Call Forwarding Signal. The attacker calls the victim posing as the bank, talks them into dialing certain codes, which activates call forwarding that redirects their calls to the scammer. When the bank tries to verify the transaction, the attacker is the one who picks up. Scam Signal detects active forwarding before the call comes through. In three months, detection improved by 30% with a low false-positive rate.
On June 23, 2026, ANTEL and Claro announced the launch of SIM Swap and Number Verification in Uruguay, with an explicit focus on fraud prevention. The announcement has been made; commercial availability of the APIs is close. The payments ecosystem is moving too: Toke is advancing as an account-to-account payments platform built on the national ACH.
Both ends already exist. What doesn’t exist yet is the use case: the integration between the fintech world, banking, and network APIs. That’s the opportunity — and also the work that remains.
The talk closed with an idea that sums up the moment well: Open Gateway isn’t a future promise. It’s infrastructure being laid right now, with real use cases and documented numbers. As happened with mobile payments, the rails tend to be invisible until adoption arrives — and then it feels like it was always this way.
Want to explore how these APIs could apply to your organization? Let’s talk.
Sources:
With a 360° potential, our solutions matrix accompanies the lifecycle of any project, with skills and experience in Development, Design, Q&A, Devops, Operation & Deploy, and Architecture
We are here to help you!
You can leave us your query or recommendation through this form.
I accept the terms & conditions and I understand that my data will be hold securely in accordance with the privacy policy.