GSMA Open Gateway · Authentication Profile

Open Gateway Authentication

Authentication

GSMA Open Gateway secures its APIs with http and openIdConnect across 2 declared security schemes, as derived from its OpenAPI definitions.

TelecommunicationsUnited KingdomNetwork APIsCAMARAOpen GatewayStandardsMobile Network OperatorIdentity VerificationSIM SwapQuality on Demand5GCertificationTrade AssociationTM Forum
Methods: http, openIdConnect Schemes: 2 OAuth flows: API key in:

Security Schemes

openId openIdConnect
notificationsBearerAuth http
scheme: bearer

Source

Authentication Profile

Raw ↑
generated: '2026-07-25'
method: searched
source: openapi/camara-call-forwarding-signal-openapi.yml, openapi/camara-carrier-billing-openapi.yml,
  openapi/camara-connected-network-type-openapi.yml, openapi/camara-device-identifier-openapi.yml, openapi/camara-device-reachability-status-openapi.yml,
  openapi/camara-device-reachability-status-subscriptions-openapi.yml, openapi/camara-device-roaming-status-openapi.yml,
  openapi/camara-device-swap-openapi.yml, openapi/camara-home-devices-qod-openapi.yml, openapi/camara-kyc-age-verification-openapi.yml,
  openapi/camara-kyc-match-openapi.yml, openapi/camara-kyc-tenure-openapi.yml ...
summary:
  types:
  - http
  - openIdConnect
schemes:
- name: openId
  type: openIdConnect
  openIdConnectUrl: https://example.com/.well-known/openid-configuration
  description: to support Consent Management
  sources:
  - openapi/camara-call-forwarding-signal-openapi.yml
  - openapi/camara-carrier-billing-openapi.yml
  - openapi/camara-connected-network-type-openapi.yml
  - openapi/camara-device-identifier-openapi.yml
  - openapi/camara-device-reachability-status-openapi.yml
  - openapi/camara-device-reachability-status-subscriptions-openapi.yml
  - openapi/camara-device-roaming-status-openapi.yml
  - openapi/camara-device-swap-openapi.yml
  - openapi/camara-home-devices-qod-openapi.yml
  - openapi/camara-kyc-age-verification-openapi.yml
  - openapi/camara-kyc-match-openapi.yml
  - openapi/camara-kyc-tenure-openapi.yml
  - openapi/camara-location-retrieval-openapi.yml
  - openapi/camara-location-verification-openapi.yml
  - openapi/camara-number-verification-openapi.yml
  - openapi/camara-one-time-password-sms-openapi.yml
  - openapi/camara-population-density-data-openapi.yml
  - openapi/camara-qos-profiles-openapi.yml
  - openapi/camara-quality-on-demand-openapi.yml
  - openapi/camara-sim-swap-openapi.yml
  - openapi/camara-simple-edge-discovery-openapi.yml
- name: notificationsBearerAuth
  type: http
  scheme: bearer
  bearerFormat: '{$request.body#/sinkCredential.credentialType}'
  sources:
  - openapi/camara-carrier-billing-openapi.yml
  - openapi/camara-device-reachability-status-subscriptions-openapi.yml
  - openapi/camara-population-density-data-openapi.yml
  - openapi/camara-quality-on-demand-openapi.yml
docs: https://github.com/camaraproject/IdentityAndConsentManagement
design_guide: https://github.com/camaraproject/Commonalities/blob/main/documentation/CAMARA-API-Design-Guide.md
note: 'CAMARA authentication is OpenID Connect plus CIBA, profiled by the CAMARA Identity and Consent
  Management working group. Every certified Open Gateway API declares one openIdConnect scheme named openId;
  the openIdConnectUrl carried in the published specs is the placeholder https://example.com/.well-known/openid-configuration
  because the real discovery document belongs to each certified operator, aggregator or channel partner.
  Access tokens come in two legs: three-legged tokens carry the end user identity and their consent (device
  is implied by the token and MUST NOT be repeated in the request body), and two-legged client-credentials
  tokens are used only where no personal data is involved. notificationsBearerAuth is a separate http
  bearer scheme used to authenticate the operator when it POSTs CloudEvents to a consumer-supplied sink;
  its bearerFormat is a runtime expression resolving to sinkCredential.credentialType. GSMA itself issues
  no credentials.'
token_legs:
- leg: three-legged
  grants:
  - authorization_code (OIDC)
  - CIBA
  carries: end-user identity and consent
- leg: two-legged
  grants:
  - client_credentials
  carries: API client identity only; no personal data operations
scopes_artifact: scopes/open-gateway-scopes.yml
conventions_artifact: conventions/open-gateway-conventions.yml

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/open-gateway-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.