THE LINUX FOUNDATION PROJECTS

Device Swap

API Description
Use Cases
  • Account Takeover Protection and risk-based Authentication: Banks, fintechs and digital services can call the Device Swap API before sensitive actions such as login, password reset, account recovery or high-value transactions. If a recent device swap is detected, the application can trigger step-up authentication, alert the user, request manual review or block the action.
  • Fraud Detection in mobile Insurance Claims: Insurance providers can use Device Swap as a contextual risk signal before approving claims related to mobile devices. A recent device swap may indicate that additional verification is required before a payout is processed. See the GSMA Use Case Library: Fraud Detection in Mobile Insurance Claims.
  • Secure User Access and Identity Verification: Online services can use Device Swap information to validate whether the user’s mobile line is still associated with the expected device context. If a recent change is detected, the service can require re-authentication before granting access to sensitive account functions.
  • Corporate mobile Line and Policy Compliance: Enterprises managing corporate mobile plans can detect whether a company SIM is being used in a different device. This helps security and IT teams enforce device policies, reduce misuse of corporate lines and protect access to enterprise services.
  • Device Transition and Customer Experience: When a device change is legitimate, service providers can use the signal to adapt security flows, refresh trusted-device status or support a smoother transition to the new device.

See also at GSMA:

Benefits
  • Enhanced Security and Fraud Prevention: Helps detect suspicious use of a mobile line in a different physical device before sensitive actions are completed.
  • Risk-based Authentication: Enables applications to apply additional verification only when a recent device swap increases the risk level.
  • Account Protection: Supports protection against account takeover, unauthorized access, suspicious password resets and high-value transaction fraud.
  • Developer-friendly Integration: Provides a standardized CAMARA interface that can be integrated into existing fraud, authentication and risk-scoring workflows.
  • Operational Efficiency: Helps API consumers automate risk decisions and reduce manual investigation or remediation costs.

API Portfolio: Authentication and Fraud Prevention

Sub Project Wiki: Number Insights
(incl. how to meet the team)

API Wiki: Device Swap

API Repository: Device Swap

API Repository Status: Incubating

API Status: Stable

API Version(s) and Release Date(s):

  • v0.1.0 (12.12.2024)
  • v0.2.0 (13.03.2025), Spring25 meta-release
  • v1.0.0 (10.09.2025), Fall25 meta-release

API availability: Information which APIs are available in which country and network, and how to get access can be found on the GSMA public launch status page.

Be part of a collaborative community driving the future of global Telco APIs.

Join Today