How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Standards Research

CAMARA — The Standard You Can Download and Cannot Call

The mobile industry built itself a real, open API standard with no mandate behind it. Then it published the specifications and kept the endpoints.

On the standard: CAMARA · Updated July 2026 · Evidence as of July 2026

This is my standing research position on CAMARA — updated as I re-score the sector, and written to be argued with. It is the working layer underneath The State of Telecom APIs, kept here because CAMARA is a standard I intend to keep investing in rather than score once and file.

Why this standard matters more than its adoption suggests

CAMARA is the only sector-wide API standard I have scored that was built by an industry, published openly, and governed neutrally, with no regulatory mandate forcing any of it. Banking got open APIs because legislators demanded them. Healthcare got FHIR because compliance required it. Telecom decided on its own.

The governance shape is genuinely well designed. CAMARA holds the specifications under the Linux Foundation. TM Forum holds the operational and fulfilment layer. The GSMA holds interoperability and commercial evangelism through Open Gateway. Distributed, with just enough of a centre. And the consent model was deliberately built to record consent when it happens so it can be interrogated afterward rather than only at the moment of the click — which is the most thoughtful piece of policy engineering I have found in any sector.

The form was right. This research is about what happened next.

The finding

You can download three hundred and fifty-one API contracts in this sector and call none of them.

Six organizations that sell nothing publish 351 freely downloadable, provider-authored specifications — 3GPP 116, MEF 94, ETSI 87, CAMARA 24, GSMA 18, TM Forum 12. Every CAMARA server declaration in the entire stack is the template variable {apiRoot}, and every openIdConnectUrl is the CAMARA placeholder pointing at example.com. Across nineteen standards and exposure repositories there is exactly one absolute base URL.

In telecom the specification is the most public thing in the sector and the endpoint is the most private.

Twenty-six of thirty-six operators show evidence of Open Gateway membership. Exactly one publishes a CAMARA contract a developer can download, price and call self-serve — KPN, which is not an Aduna shareholder, runs SIM Swap on a real production host, and publishes euro pricing with a free sandbox. The second-best CAMARA artifact in the world’s telecom industry is a zip file linked off a Brazilian marketing page.

Four structural reads

The standard is sold through the intermediary it was built to bypass. Operators treat CAMARA as a product for a channel. The channel is exactly the aggregator layer the standard was meant to route around.

The aggregators out-publish the carriers by nineteen points — and not because they resell CAMARA. The CPaaS, UCaaS and IoT layer averages 56.6 against the carriers’ 37.6 and ships 6,943 published operations. Exactly one of its twenty-eight companies exposes a /camara/ path. The rest sell CAMARA’s identity verbs under contracts they wrote first and shipped years earlier. CAMARA’s actual network half — quality on demand, carrier billing, edge discovery — appears in zero of those 6,943 operations.

The authorization flow the standard depends on is largely undocumented. CIBA — Client-Initiated Backchannel Authentication, the flow CAMARA specifies for network-based authorization because the party being asked is a subscriber rather than a session — appears in three of nineteen standards repositories, and is absent from the specifications of the one platform with a genuinely callable endpoint.

Consent sits at 13.3% in the one industry whose product is subscriber identity. The best-designed consent model in any sector I have scored is present in the specification and largely absent from the published surface.

The longer echo

In February 2011 I surveyed the carrier API programmes of the day. Verizon offered location and messaging. Sprint offered geofence, location, messaging and presence. AT&T offered SMS, MMS, WAP Push, terminal location and device capabilities. Location, messaging, device capability.

Fifteen years later CAMARA’s flagship set is device location, number verification, SIM swap and quality on demand. The primitives barely moved. What the industry has been trying to sell has been stable for over a decade; what has never stabilised is the ability to actually buy it.

The motive has not changed either. I wrote in 2011 that carriers offer location APIs because they do not want to be dumb pipes — they want to be an integrated player in their own customers’ handset usage. That is the up-the-stack impulse behind Open Gateway, stated plainly fourteen years earlier. On this evidence it is still losing.

What I am building against this

The gap here is not the standard and not the specifications. Both are excellent and free. The gap is everything between a downloadable contract and a callable endpoint — and nobody is investing in that layer.

  • A public, runnable conformance suite. The industry holds 237 certified assets behind a 403 and certified a Quality on Demand implementation against sixty-three technical tests it never published. A certification programme whose results a machine cannot read is a press release. A public, runnable conformance suite would do more for CAMARA’s adoption than another operator signing the pledge.
  • A Spectral ruleset for governing an Open Gateway deployment — catching unresolved server templates, placeholder OIDC discovery URLs, security requirements naming schemes that are never defined, and network-auth APIs that never document CIBA. Every one of those rules is derived from a real defect in the live corpus.
  • Agent skills for the CAMARA verbs. Number Verification, SIM Swap and Device Location return deterministic answers; a skill that drops into a consumer’s own repository is the right artifact for that shape, and an agent deciding whether a number is on a device is the wrong one. Nobody has published these.
  • Overlays that resolve {apiRoot} into a real host, turning the published standard into something callable per operator.
  • An AsyncAPI for the telecom event surface — a sector whose webhooks are universal and whose event contracts are nonexistent.

Two of these I promised publicly in December 2024, after the Calvert conversation, and did not deliver. Eighteen months later nobody else has built them either. That is the opportunity and the indictment at the same time.

What I am watching

  1. Whether any tier-one operator publishes a CAMARA specification with an absolute base URL in it. That single act would tell you the industry has decided to be reachable rather than resold. Today one carrier clears that bar, with one API.
  2. Whether Aduna ever publishes a specification. The carriers’ own joint venture being the least machine-readable body in the sector is not a stable position.
  3. Whether the aggregators begin exposing CAMARA’s network half. The day a major CPaaS ships a quality-on-demand product is the day the carriers have lost the last piece of the stack they still exclusively hold.

Corrections welcome, and taken seriously. If you work on CAMARA or ship against it and I have read your surface wrong, the fastest way to change this page is to point me at the artifact.

Primary sources — API Evangelist Conversations

Recorded conversations with the people building this standard. These are on the record and quotable.

API Evangelist Conversation with Henry Calvert, Global Head of Future Networks @ GSMA

Henry Calvert, GSMA · 5 December 2024

The primary source for why CAMARA exists. Calvert names OneAPI a spectacular failure, and identifies the change that mattered — the industry stopped writing specifications as documentation and started writing them as code.

Published research

The State of Telecom APIs

Eighty-three telecom organizations scored on the same rubric as Stripe, read from machine-readable evidence — the CAMARA gap category by category, the two exposure platforms, and the investable thesis.

Referenced on the API Evangelist blog