Is CAMARA a Threat or an Opportunity for Indian CPaaS Providers?
- TechTo Networks
- Aug 15
- 11 min read
A grounded look at GSMA Open Gateway and CAMARA Network APIs, what's already live in India, and what it actually means for businesses built on Bulk SMS, WhatsApp Business API, and RCS.
Introduction
Every few years, a new piece of telecom infrastructure shows up promising to make an entire layer of the messaging business obsolete. Sometimes that fear is justified. Often it isn't, or it's justified only for a narrow slice of the business. CAMARA — the open-source project standardizing what's known as GSMA Open Gateway Network APIs — is the latest infrastructure shift worth taking seriously, and it deserves an honest answer rather than either dismissal or alarm.
The short version: CAMARA is real, it's already live in India with all three major operators, and it does target one specific piece of the CPaaS business model — OTP delivery over SMS. But the full picture is more nuanced, and more interesting, than a simple "this will disrupt SMS providers" narrative suggests. This post breaks down what CAMARA actually is, what's genuinely live in India today, where the real risk sits, and — just as importantly — where it opens up a legitimate new opportunity for CPaaS and BSP providers who position themselves correctly.

What Is CAMARA, in Plain Terms?
CAMARA is an open-source project hosted by the Linux Foundation, developed in close collaboration with the GSMA Operator Platform Group, that defines standardized Network APIs — a way for telecom operators to expose capabilities that have always existed deep inside their network infrastructure, but were never accessible to ordinary application developers in a simple, uniform way.
Historically, if a bank wanted to verify that a phone number genuinely belonged to the device requesting a login, or wanted to check whether a SIM card had recently been swapped (a common precursor to fraud), there was no standard way to ask the network that question directly. CAMARA changes that by defining a common set of REST APIs — the same API, working the same way, whether the underlying operator is Jio, Airtel, an operator in Spain, or one in Brazil — so a developer builds against the standard once and gets access across every participating network.
This is the technical foundation behind what's branded commercially as GSMA Open Gateway. As of early 2026, the numbers behind this initiative are substantial: more than 80 operator groups, representing over 300 networks and roughly 80% of the world's mobile connections, are aligned to the initiative, with more than 300 instances of over 20 different CAMARA APIs already commercially launched across 65 markets globally.
The APIs most relevant to messaging and authentication businesses include:
Number Verification — silently confirms a phone number belongs to the device making a request, without sending an OTP at all
SIM Swap — detects whether a SIM was recently swapped, a key fraud signal for account-takeover prevention
KYC Match / KYC Age Verification — network-level identity and age verification
One Time Password SMS — a standardized way to trigger OTP delivery through the network layer
Device Reachability / Roaming Status — signals useful for smarter message routing
Several of these map directly onto things CPaaS and BSP providers already do — which is exactly why the "threat or opportunity" question matters.
What's Already Live in India
This isn't a distant, theoretical initiative for the Indian market — it's already operational, with all three major operators involved.
SIM Swap API is already launched. Bharti Airtel, Reliance Jio, and Vodafone Idea have jointly launched the SIM Swap API, specifically aimed at helping banks and online retailers prevent account-takeover attacks, where fraudsters use social engineering or stolen personal data to gain control of a victim's SIM card and intercept OTPs.
Number Verification was planned for late 2025 rollout, with GSMA explicitly describing this API as a more secure replacement for SMS one-time passwords — a direct statement of intent about what this technology is meant to eventually reduce reliance on.
All three operators are engaged with the broader Open Gateway ecosystem, and India was a specific focus area at India Mobile Congress, where the operators partnered with GSMA and Nokia on an Open Gateway hackathon aimed at building API-driven use cases for the Indian market.
Worth noting: this wasn't always a given. Reliance Jio — India's largest operator — was notably slow to formally commit to Open Gateway, with GSMA's own APAC leadership publicly stating as late as 2024 that they were still in discussions with Jio and hoped India would play a more dynamic role in the initiative. By late 2025, that had resolved into active participation, with all three major Indian operators collaborating on the SIM Swap launch. That trajectory — early hesitation, followed by full three-operator commitment within about a year — tells you this is a genuine, accelerating trend in India, not a slow-moving global standard that will take a decade to reach the Indian market.
The Threat Case: Where CAMARA Genuinely Puts Pressure on CPaaS Providers
Let's be direct about where the real exposure sits, rather than either overstating or dismissing it.
OTP-over-SMS is the specific target
GSMA's own language is unambiguous: Number Verification is explicitly positioned as a replacement for SMS OTPs, not a complementary tool. The pitch to banks and fintechs is straightforward — instead of sending an SMS with a one-time code that a user has to read and type back in (a flow vulnerable to SIM-swap fraud, SMS interception, and user error), the network itself silently confirms the phone number matches the requesting device, with no message sent at all.
For any CPaaS or BSP business with meaningful revenue tied to transactional OTP SMS volume — and for most bulk SMS providers in India, OTP traffic is a significant, often primary, revenue category — this is worth taking seriously as a long-term trend, not a rumor.
The initial targets are exactly the highest-value clients
The use cases operators are leading with — bank login authentication, e-commerce account security, fraud prevention — are concentrated in precisely the client segment that generates the highest OTP volumes and the most stable, high-margin transactional messaging revenue: large banks, fintechs, and major e-commerce platforms. These aren't marginal accounts. If even a handful of large enterprise clients shift core authentication flows from OTP SMS to Number Verification over the next few years, that's a concentrated, meaningful revenue impact for providers whose books are weighted toward large financial-sector clients.
Operators are engaging enterprise developers directly, at least initially
The current go-to-market motion described in India Mobile Congress announcements is operators providing direct federated access to enterprise developers at banks and online retailers — not routing this exclusively through CPaaS/BSP intermediaries. That's a meaningfully different distribution model from how SMS and WhatsApp API access typically works in India, where BSPs are the mandatory middle layer. If operators continue building direct enterprise relationships for Network APIs, it represents a genuine bypass of the reseller layer for this specific category of service — at least for the largest, most technically capable clients who can integrate directly.
The Opportunity Case: Why This Isn't a Simple Disruption Story
Here's where the picture gets more interesting, and considerably more favorable for established CPaaS providers than the threat framing alone suggests.
The ecosystem itself says it needs channel partners
At the GSMA Open Gateway Channel Partner Roundtable held during MWC Barcelona 2026 — bringing together channel partners, CPaaS providers, hyperscalers, and system integrators — the industry's own assessment was candid: the primary barriers to scaling Open Gateway adoption are no longer technical. Instead, participants identified commercial readiness, developer awareness, and operational execution as the real constraints.
More specifically, the roundtable concluded that channel partners, system integrators, and solution providers are central to commercial success, and that enterprise adoption depends on partner-led go-to-market models — solutions packaged around business outcomes, not raw technical API access. Regulatory alignment and the complexity of managing CAMARA API versioning across markets were also flagged as areas where specialized partners add real, ongoing value that operators are not well-positioned to provide directly at scale.
This is a significant signal. It means the organizations building this technology have already concluded, from direct experience trying to scale it, that they cannot succeed by selling Network APIs directly to every bank, fintech, and retailer themselves. They need exactly the kind of onboarding, integration support, developer relationships, and go-to-market infrastructure that CPaaS and BSP providers already operate.
This mirrors a pattern the messaging industry already knows well
If this dynamic sounds familiar, it should. It's structurally identical to how Meta's WhatsApp Business API works today: Meta owns the core infrastructure and could theoretically sell directly to every business, but instead relies almost entirely on Business Solution Providers to handle onboarding, technical integration, compliance support, and ongoing account management — because that layer of work doesn't scale well as a direct-to-enterprise motion for a platform serving millions of businesses of wildly varying size and technical sophistication.
Network APIs are following the same logic. Large telecom operators are excellent at building and operating network infrastructure. They are historically much weaker at enterprise sales, developer support, multi-vertical use-case packaging, and the unglamorous operational work of onboarding thousands of businesses of different sizes. That gap is exactly what CPaaS and BSP providers are built to fill — and the GSMA's own roundtable conclusions suggest the industry already recognizes this.
Fraud prevention pairs naturally with messaging, rather than replacing it
It's also worth separating Number Verification (which is genuinely positioned to reduce OTP SMS volume) from SIM Swap and KYC APIs, which function differently. SIM Swap detection doesn't replace an OTP message — it's a fraud-risk signal that sits alongside an authentication flow, helping a business decide whether to trust an OTP-based login or add extra verification friction. That's naturally something a messaging and authentication platform can bundle as an additional service, not something that displaces messaging revenue.
In other words: for every part of CAMARA that competes with OTP SMS, there's another part that complements it — and the businesses best positioned to sell that combination are the ones who already have deep, trusted relationships with exactly the banks, fintechs, and e-commerce platforms these fraud-prevention APIs are built for.
Adoption is still genuinely early
Even with three major Indian operators involved and real product launches underway, the GSMA's own market assessment from Q1 2026 describes an ecosystem still working through commercial and operational scaling challenges, not one that has already achieved mass enterprise adoption. Fraud prevention is described as the most appealing use case for developers globally, followed by mobile payments — meaning the highest-priority use cases are still concentrated in specific verticals, and broad displacement of general-purpose OTP SMS across all business types is not an imminent, near-term reality.
What This Actually Means: A Balanced Read
Putting the threat and opportunity cases together, here's the honest assessment:
CAMARA is not a threat to Bulk SMS, WhatsApp Business API, or RCS as a whole. Promotional messaging, order and delivery notifications, customer support conversations, marketing campaigns, and the vast majority of transactional messaging use cases are entirely untouched by Network APIs, which are narrowly focused on authentication and fraud prevention.
CAMARA is a legitimate long-term watch item specifically for OTP SMS revenue concentrated in large banking, fintech, and e-commerce clients. This is where Number Verification is explicitly positioned to compete, and where operators currently appear willing to build direct enterprise relationships rather than routing exclusively through resellers.
CAMARA is also a genuine expansion opportunity, because the ecosystem's own leadership has concluded it cannot scale without channel partners, and because fraud-prevention APIs like SIM Swap and KYC pair naturally with — rather than replace — existing messaging and authentication infrastructure.
The businesses most exposed to real disruption here are ones that treat OTP SMS to large financial-sector clients as a static, permanent revenue line and do nothing else. The businesses best positioned to benefit are ones that get ahead of the trend by understanding these APIs now, building relationships with operators as a channel partner, and packaging fraud-prevention capabilities alongside their existing SMS/WhatsApp/RCS offerings before competitors do.
What Indian CPaaS Providers Should Actually Do
A few concrete, practical steps worth considering:
Track OTP concentration by client, not just in aggregate. Understand which of your largest clients — particularly banks, fintechs, and major e-commerce accounts — represent concentrated OTP SMS volume, since these are the accounts most likely to explore Network API alternatives first.
Explore becoming a CAMARA/Open Gateway channel partner directly. Given the GSMA's own stated need for partner-led go-to-market, there's a real first-mover advantage available to CPaaS providers who engage with operators as Network API resellers now, rather than waiting to react once enterprise clients start asking about it.
Position fraud-prevention APIs as a bundled upsell, not a defensive move. SIM Swap detection paired with your existing OTP SMS service is a genuinely stronger security offering for banking and fintech clients than either capability alone — frame it that way in client conversations rather than waiting for clients to raise it first.
Watch India-specific rollout pace closely. Given how quickly the picture shifted from "Jio hasn't joined Open Gateway" in 2024 to "all three major operators jointly launching SIM Swap" by late 2025, this space is moving faster in India than typical multi-year telecom infrastructure rollouts — it's worth revisiting this assessment every few months rather than treating it as settled.
Don't over-invest in defense against a threat that's still narrow. For most CPaaS providers, the bulk of revenue sits in promotional, transactional, and support messaging across SMS, WhatsApp, and RCS — none of which CAMARA currently touches. The right level of response is informed vigilance and selective opportunity-seeking, not a wholesale strategic pivot.
Where This Is Headed
The trajectory here seems fairly clear, even if the exact timeline isn't. Network APIs will very likely continue expanding across Indian operators, and Number Verification will likely see real adoption among the largest banks and fintechs over the next few years, precisely because the fraud-prevention case is strong and the operators involved are serious, well-resourced players. What's much less certain is how quickly this reaches beyond the largest enterprise accounts into the broader base of mid-market and small business clients that make up most of the CPaaS customer base — and the industry's own commentary suggests that broader reach specifically depends on channel partners doing the work of translating this technology into accessible, packaged offerings.
That's the opening. Whether Indian CPaaS and BSP providers capture it, or watch operators and hyperscalers build that channel-partner layer themselves through different players, is very much still an open question — and one worth positioning for now rather than after the fact.
Frequently Asked Questions
What is CAMARA?
CAMARA is an open-source project hosted by the Linux Foundation that defines standardized Network APIs, letting developers access telecom network capabilities — like number verification and SIM swap detection — through a common set of REST APIs across participating operators worldwide. It's the technical foundation behind the GSMA Open Gateway initiative.
Is CAMARA/Open Gateway live in India?
Yes. Bharti Airtel, Reliance Jio, and Vodafone Idea have jointly launched the SIM Swap API for fraud prevention, and a Number Verification API was planned for late 2025 rollout, targeted initially at banks and online retailers.
Will Network APIs replace OTP SMS entirely?
Not entirely, and not quickly. Number Verification is explicitly positioned by GSMA as a more secure alternative to OTP SMS for authentication use cases, and adoption is expected to concentrate first among large banks and fintechs with the strongest fraud-prevention motivation. Broader SMS use cases — marketing, transactional alerts, order updates — are unaffected.
Should CPaaS and BSP providers in India be worried about CAMARA?
Selectively, not broadly. The exposure is concentrated in OTP SMS revenue from large financial-sector clients specifically. For the broader messaging business — WhatsApp, RCS, promotional and transactional SMS — CAMARA has no direct impact, and the ecosystem's own leadership has stated it needs channel partners to scale, which creates a genuine opportunity for established providers.
Can a CPaaS provider become a CAMARA channel partner?
Yes — GSMA's Open Gateway ecosystem explicitly includes channel partners and CPaaS providers as recognized categories, and industry discussion at MWC 2026 emphasized that partner-led go-to-market is central to scaling adoption, suggesting real opportunity for providers who engage early.
TechtoNetworks tracks emerging telecom infrastructure trends like GSMA Open Gateway and CAMARA as part of how we plan our platform roadmap. If you're a bank, fintech, or e-commerce business thinking through fraud prevention alongside your OTP and messaging strategy, get in touch with our team.



Comments