Carriers Are Quietly Replacing SMS Passcodes With the SIM Itself

Glide.id's MagicalAuth, launched in public beta with AT&T, T-Mobile US, and Verizon, replaces SMS one-time passcodes with hardware-rooted authentication anchored in the SIM or eSIM itself, verified through open network APIs. TeckNexus examines how this differs structurally from SMS OTP, why the three-carrier coverage threshold matters, and why the underlying infrastructure is likely to become directly relevant to enterprise IoT and OT device identity verification, even though today's launch is consumer-facing.
SIM-Based Authentication: Why Carriers Are Replacing SMS OTPs

SMS one-time passcodes have been a known, tolerated weak point in digital authentication for years, vulnerable to SIM-swap fraud, interception, and phishing, but retained because they’re universally available and don’t require the user to install anything extra. A public beta launched this August by Glide.id, in partnership with AT&T, T-Mobile US, and Verizon, is a concrete step toward replacing that weak point with something structurally stronger: authentication rooted directly in the hardware of the SIM or eSIM itself, rather than in a message sent to the device.

How SIM-Based Authentication Differs From SMS OTP

Glide.id’s MagicalAuth service uses open network APIs — standardised interfaces that let a service provider query carrier-held information about a device or subscriber in real time — combined with hardware-rooted cryptography embedded in the SIM or eSIM itself. The practical difference from SMS one-time passcodes is where the trust anchor sits: an SMS OTP relies on the assumption that only the legitimate device holder can receive a text message sent to that number, an assumption that SIM-swap fraud directly defeats by fraudulently porting the number to an attacker-controlled device. Hardware-rooted SIM authentication instead verifies a cryptographic credential embedded in the physical SIM or eSIM hardware, which is a fundamentally harder thing to fraudulently transfer or spoof than a phone number, since it requires compromising the physical or virtual credential itself rather than merely redirecting where a text message is delivered.

The three-carrier launch matters as much as the technology. Authentication infrastructure is only as useful as its coverage — a SIM-based authentication service that only worked on one carrier’s network would be a niche capability, not a viable SMS OTP replacement. AT&T, T-Mobile US, and Verizon together cover the substantial majority of the US mobile subscriber base, which means a service or enterprise integrating MagicalAuth in beta today can realistically reach most of its US mobile user base without needing carrier-specific integration work for each one, a meaningful threshold for authentication infrastructure to clear before it’s genuinely viable as a default replacement rather than a supplementary option offered alongside SMS as a fallback.

Why This Matters Beyond Consumer App Login

The immediate framing of this launch is consumer-facing, replacing SMS OTPs for app and account login. But the underlying capability, hardware-rooted device identity verified through open network APIs, is directly relevant to a problem industrial and enterprise buyers face independently of consumer authentication: verifying the identity of IoT and OT devices connecting to a private network or enterprise system, where SMS-based verification was never a realistic option in the first place, and where device identity spoofing is a genuine security concern as more industrial devices carry cellular connectivity, increasingly via eSIM, rather than being confined to a physically isolated network.

A hardware-rooted SIM or eSIM credential, verified through open network APIs, is architecturally the same kind of capability the UK NCSC has been recommending for private network security more broadly — identity-based access control anchored in something harder to spoof than a network location or a shared credential. As eSIM adoption grows across industrial IoT and connected equipment, the infrastructure being built and proven out through consumer authentication services like MagicalAuth is likely to become directly applicable to enterprise device identity and access management, even though that’s not how it’s being marketed today. The consumer authentication market, with its scale and regulatory scrutiny around fraud, is arguably a faster path to maturing this infrastructure than a purpose-built enterprise product would achieve on its own, simply because of the volume of real-world usage and edge cases it will encounter.


What to Watch as This Moves Past Beta

For enterprise and industrial buyers, the near-term relevance of this specific launch is limited — it’s a US consumer authentication beta, not an enterprise IoT identity product. But it’s worth tracking as the infrastructure and standards underpinning it, open network APIs, hardware-rooted SIM cryptography, multi-carrier interoperability, mature, since that same infrastructure is the more likely long-term foundation for cellular-connected device identity verification in industrial and OT contexts than a purpose-built enterprise product developed independently. Buyers evaluating eSIM-based device identity strategies for their own private network or IoT deployments should treat consumer-facing launches like this one as an early proof point for the underlying technology’s maturity and carrier support, not as a directly applicable enterprise product yet, and should watch specifically for whether Glide.id or a comparable provider extends the same open-network-API and hardware-rooted-credential model into an explicitly enterprise-facing IoT identity product over the next one to two years.

Why Open Network APIs Are the Component Worth Watching Most Closely

Of the three technical components underpinning MagicalAuth, the open network APIs are arguably the most consequential for enterprise buyers to track independently of the specific authentication use case. Open network APIs are a broader carrier initiative, standardised interfaces exposing carrier-held network and subscriber information to third-party developers and services, and authentication is only one of several applications being built on top of them, alongside use cases like fraud detection, number verification, and location-based services. An enterprise already integrating with carrier open network APIs for one purpose, fraud prevention on customer-facing transactions, for instance, is well positioned to extend that same integration toward device identity verification for its own IoT estate with comparatively little additional engineering effort, since the underlying API relationship and carrier integration work is already in place. That’s a meaningful reason for enterprise IT and security teams to track open network API adoption and standardisation progress as infrastructure in its own right, independent of any single application like MagicalAuth built on top of it.

The fraud-reduction motivation behind this shift is also worth naming directly, since it’s the commercial driver that makes carrier investment in hardware-rooted authentication durable rather than a short-lived pilot. SIM-swap fraud and SMS interception have been a persistent, costly problem for carriers and the services relying on SMS OTPs for years, with the cost typically falling on whichever party, bank, platform, or carrier, ends up absorbing the fraud loss or the customer trust damage that follows a compromised account. A hardware-rooted alternative that measurably reduces that fraud rate has a clear return on investment case for carriers independent of any single partner’s enthusiasm for the technology, which is a more durable foundation for continued investment and expansion than a feature built purely on forward-looking technical merit without an immediate cost justification behind it.

Explore the full TeckNexus Intelligence Platform — independent, buyer-neutral tools for private network and industrial AI decisions. https://tecknexus.com/intelligence/

Tech News & Insight
Tech News & Insight

Partner Hubs

Download content, access intelligence tools, and hear from executives.

Partner Events

  • M360 ASEAN
  • FutureNet Asia 2026
  • Network X Vienna 2026
Scroll to Top