Standardised, Developer-Friendly APIs for Accessing Telecom Network Capabilities

CAMARA

Last Update: 10/2026

What is CAMARA?  

CAMARA is an open-source project hosted within the Linux Foundation that defines, develops, documents and tests APIs that expose telecommunications-network capabilities to application developers and enterprises. 

Mobile operators have access to information and capabilities that ordinary internet applications cannot obtain directly. Examples include determining whether the SIM associated with a mobile number has recently changed, verifying the phone number associated with a device, checking whether a device is roaming, obtaining network-derived location information, requesting a particular level of network quality, or validating selected customer information already verified by an operator. 

Historically, these capabilities were often exposed through operator-specific interfaces. An application developer wishing to use the same capability across several operators could therefore need different integrations, authentication procedures, data formats and commercial arrangements for every network. 

CAMARA addresses this fragmentation by defining common, developer-friendly Network APIs that abstract the underlying complexity of telecom networks. The objective is to allow developers to integrate a capability using a consistent API model and make applications more portable across participating operators, countries and API providers. 

CAMARA describes its role as simplifying telecom-network complexity through APIs and making those capabilities accessible across networks and countries. It works closely with the GSMA Operator Platform Group to align API requirements and publish common API definitions. CAMARA specifications and reference implementations are made available under the Apache 2.0 licence. 

CAMARA therefore sits between the underlying telecom network and the applications that want to use telecom intelligence. 

A simplified model is: 

Mobile Network Capability → Operator Exposure Platform → CAMARA Network API → Enterprise Application 

 

Examples include: 

 

  • SIM information → SIM Swap API
  • Mobile-number association → Number Verification API
  • Operator KYC records → KYC Match API
  • Network location → Location Verification or Location Retrieval API
  • Roaming information → Device Roaming Status API
  • Network performance → Quality on Demand API
  • Operator charging → Carrier Billing API

CAMARA itself is not a mobile network, an API marketplace, a telecom operator or a commercial API aggregator. It is primarily the open technical standardisation and development environment for the Network APIs. 

 

How does CAMARA work? 

 

CAMARA transforms telecom-network capabilities into standardised northbound Service APIs. 

A mobile operator may have highly specialised internal systems such as subscriber databases, policy-control functions, network exposure functions, charging platforms, location systems, authentication infrastructure and fraud-management systems. 

Application developers generally should not need to understand or integrate directly with those systems. 

Instead, the operator or API provider exposes the relevant capability through a CAMARA-compliant API. 

For example, an application that wants to know whether a SIM associated with a mobile number recently changed does not need to understand IMSI provisioning, subscriber-management infrastructure or the operator's internal SIM lifecycle. 

It can call the CAMARA SIM Swap API and receive a standardised response. 

Likewise, a banking application that wants to confirm whether a phone number belongs to the mobile subscription currently being used can call Number Verification rather than implementing a proprietary authentication integration with each operator. 

This abstraction is one of CAMARA's core purposes: making telecom capabilities consumable by developers who do not need deep telecom expertise. 

 

CAMARA Service APIs 

CAMARA's scope includes customer-facing northbound APIs. 

 

The project distinguishes several API types, including: 

 

  • Service APIs — APIs consumed by applications to invoke a telecom capability.

  • Service Management APIs — APIs used to determine availability or other operational information about Service APIs.

  • Operate APIs — operational interfaces used between telecom providers and channel partners; this area is coordinated with organisations such as TM Forum rather than being the primary CAMARA Service API scope. 

The CAMARA API portfolio includes capabilities across several categories. 

 

Authentication and Fraud Prevention examples include: 

 

  • Number Verification

  • SIM Swap

  • SIM Swap Subscriptions

  • Device Swap

  • Know Your Customer Match

  • Know Your Customer Fill In

  • Know Your Customer Age Verification

  • Number Recycling

  • Call Forwarding Signal

  • One Time Password SMS

Other categories include:

 

  • Location Services

  • Communication Services

  • Communication Quality

  • Device Information

  • Computing Services

  • Payments and Charging

  • Service Management 


The exact set continues to evolve as new telecom capabilities are proposed and standardised.

 

Common API Design 

CAMARA is not simply a collection of unrelated HTTP endpoints. 

The project also develops common API-design conventions so APIs behave consistently. 

Common areas include:

 

  • API naming and resource conventions
  • Request and response formats 
  • Error handling 
  • Authentication
  • Authorisation
  • OAuth 2.0 and OpenID Connect usage
  • Access-token handling
  • User identification
  • Consent handling
  • Privacy requirements
  • Event subscriptions
  • API versioning
  • Conformance and testing 

 

This is important because true interoperability requires more than giving APIs similar names. Developers need consistent behaviour across different operators and API providers. 

 

CAMARA's Identity and Consent Management work, for example, provides a Security and Interoperability Profile describing how API consumers obtain access tokens and how user-specific authorisation and consent can be handled. 

 

Authentication, Authorisation and Consent 

Many Network APIs process subscriber-specific information. 

As a result, an API provider must consider whether the application is authorised to access the information, whether the end user needs to provide consent, and which legal basis applies. 

CAMARA's Identity and Consent Management framework is designed to provide common patterns for these processes. 

Depending on the API and use case, an implementation may use: 

 

  • two-legged access tokens, where the API consumer is authorised for a capability without an interactive end-user authorisation flow; or three-legged access tokens representing a specific end user and authorisation context. 

For APIs that process personal information where users exercise rights through mechanisms such as opt-in or opt-out, CAMARA specifications require three-legged access tokens in the applicable situations. The exact legal and authorisation requirements still depend on the API, operator, declared purpose and jurisdiction. 

 

Why is CAMARA important for Mobile Operators & Enterprises? 

Without common Network APIs, an enterprise attempting to integrate directly with ten operators could face ten separate technical implementations.

 

Differences might include:

 

  • authentication methods;
  • API paths;
  • request formats;
  • response formats;
  • error codes;
  • consent flows;
  • commercial onboarding;
  • terminology; and
  • capability behaviour.
  • digital identity;
  • fraud prevention;
  • onboarding;
  • authentication;
  • location services;
  • connectivity management;
  • application performance;
  • payments; and
  • customer experience.

That fragmentation makes global deployment expensive and slow.

 

CAMARA's objective is to allow operators and API providers to expose the same capability through a common API definition.

 

This supports the concept of building an application once and making it easier to deploy across multiple compatible networks and markets.

 

GSMA describes application portability as one of the core benefits of common northbound Network APIs, while CAMARA specifically identifies harmonisation, simplified developer access and cross-network availability as key objectives.

 

For mobile operators, CAMARA provides a standard mechanism for packaging network intelligence and capabilities into programmable services.

 

For enterprises, it provides access to telecom-derived signals that may improve:

 

  • digital identity;

  • fraud prevention;

  • onboarding;

  • authentication;

  • location services;

  • connectivity management;

  • application performance;

  • payments; and

  • customer experience.


Key Benefits / Features of CAMARA

 

  • Standardised Network API definitions

  • Developer-friendly REST/OpenAPI interfaces

  • Reduced operator-specific integration

  • Greater application portability

  • Cross-network interoperability

  • Common authentication and authorisation patterns

  • Privacy and consent considerations

  • Standardised errors and API behaviour

  • Open-source collaboration

  • Public API specifications

  • Apache 2.0 licensing

  • Reference implementations and test definitions

  • Alignment with GSMA Open Gateway

  • Support for operator, aggregator and channel-partner deployments

  • Access to telecom capabilities without requiring applications to understand underlying network architecture

 

Examples of CAMARA API Use Cases 

Fraud prevention

A bank can combine SIM Swap, Device Swap, Number Verification and KYC Match to obtain several independent network-derived signals before authorising a sensitive transaction.

 

SIM Swap can identify a recent SIM change.

 

Number Verification can establish whether the expected mobile number corresponds to the authenticated subscription.

 

KYC Match can compare customer-supplied identity information with operator-held information.

 

The bank remains responsible for combining those signals with its broader fraud and authentication strategy.

 

Passwordless authentication

 

An application may use Number Verification to confirm the number associated with the user's mobile subscription without requiring an SMS OTP.

 

This can reduce onboarding and login friction while retaining an operator-confirmed possession signal.

 

Device and subscription intelligence

 

Applications can query capabilities such as roaming status, device identifiers, reachability, SIM changes or device changes.

 

This information can be used by fraud engines, mobility services, enterprise applications or digital-service platforms.

 

Location services

 

A business can use standardised location APIs to retrieve or verify the network-derived location of a device, subject to permission and regulatory requirements.

 

Possible applications include logistics, fraud prevention, mobility, asset management and public-safety systems.

 

Network quality

 

Quality on Demand and related APIs allow applications to interact with network-performance capabilities rather than treating connectivity as an entirely passive service.

 

Potential applications include gaming, live video, industrial systems, remote operation and other latency- or bandwidth-sensitive services.

 

Payments and charging

 

Carrier Billing APIs allow application developers to incorporate operator-supported charging capabilities into digital services where the capability is commercially available.

 

CAMARA vs. GSMA Open Gateway

CAMARA and GSMA Open Gateway are closely connected, but they are not the same thing. Here are the main differences between CAMARA and GSMA Open Gateway:

CAMARA develops and maintains the technical API definitions. 

GSMA Open Gateway provides the broader industry framework through which mobile operators expose common Network APIs commercially and at global scale. 

The GSMA explicitly states that Open Gateway northbound Service APIs are defined within the CAMARA project. 

A useful simplified distinction is: 

CAMARA = technical API definitions and developer standardisation 

GSMA Open Gateway = operator ecosystem, commercial exposure framework and global API availability 

An operator's Open Gateway platform can therefore expose a CAMARA-defined API such as SIM Swap or Number Verification. 

 

CAMARA vs. 3GPP 

CAMARA should also not be confused with 3GPP network interfaces. 

3GPP specifies many of the lower-level capabilities and network functions used inside mobile networks. 

CAMARA focuses on customer-facing northbound Service APIs that abstract those underlying technologies into interfaces designed for enterprise developers. 

CAMARA's own scope documentation recognises 3GPP, O-RAN, IETF, Broadband Forum and other standards organisations as technology-domain sources whose underlying network functions may ultimately be exposed through CAMARA APIs.

 

Common questions about CAMARA

  1. Is CAMARA a telecom operator?  No. CAMARA does not operate a mobile network. It defines and develops Network API specifications.  

  2. Is CAMARA an API provider? Not normally in the commercial sense. The API itself is implemented and exposed by mobile operators, operator platforms, aggregators or other authorised API providers.
  3. Can I call CAMARA directly to get subscriber information? No. CAMARA publishes specifications. Access to a live capability must come from an operator or participating API provider that has deployed the API.
  4. Are CAMARA APIs free? The API definitions and reference materials are open source under Apache 2.0. Access to a live commercial Network API may be subject to operator or API-provider pricing and commercial terms.
  5. Are all CAMARA APIs available on every operator? No. Availability varies by API, network, operator, country and provider. GSMA maintains Open Gateway deployment and launch information to show where capabilities are commercially available.
  6. Does CAMARA replace operator infrastructure? No. CAMARA standardises the interface presented to API consumers. Operators still require the network, subscriber-management, security, policy and exposure infrastructure that delivers the underlying capability.
  7. Does CAMARA only apply to 5G? No. Some capabilities can be implemented using existing 4G infrastructure, while 5G enables additional and more advanced network capabilities. CAMARA focuses on how those capabilities are exposed through APIs.
  8. Does CAMARA manage end-user consent? CAMARA defines common Identity and Consent Management approaches, but the actual consent implementation and legal basis belong to the API provider and relevant parties in the commercial deployment.
  9. Is CAMARA the same as Network as a Service? Not exactly. Network as a Service is the broader concept of making network functions consumable programmatically. CAMARA provides standardised APIs that help enable that model. 
 
Related Terms

Network APIs; GSMA Open Gateway; Operator Platform; Mobile Network Operator; Network Exposure; Network as a Service; OpenAPI; REST API; OAuth 2.0; OpenID Connect; Identity and Consent Management; Three-Legged Access Token; Two-Legged Access Token; SIM Swap; Number Verification; KYC Match; Device Swap; Quality on Demand; Device Location; Carrier Billing; 4G; 5G; API Aggregator; Channel Partner; TM Forum; 3GPP. 

 

Sources 

CAMARA Project Home

CAMARA API Overview

CAMARA Scope

CAMARA GitHub Organization

CAMARA Identity and Consent Management

GSMA Open Gateway API Descriptions


Last Updated: October 2026