The question this article actually answers
Every operator deck since 2023 has the same slide: the network becomes a platform, developers call APIs, new revenue appears. The supply side of that story is now real and measurable — the specs exist, the catalog is published, the operators have signed. The demand side is the open question, and it is the one most coverage dodges.
This is the evidence-and-economics pillar for that question. If you want the conceptual primer — what NEF is, what CAMARA is, how an operator would expose a capability — read the companion explainer first: CAMARA and 5G Network APIs. This piece assumes you have that and goes two directions the explainer does not: down into the exact 3GPP specs and clause versions under the API, and up into the forecast numbers, where they disagree, and what is actually selling in 2026. The short version of the verdict, which the rest of the article earns: the plumbing is solid, the footprint is growing fast, the audited revenue is zero, and Ericsson's own word for current revenue is "tiny."
A scope note before the numbers. The adjacent business-model layer — NaaS packaging, slicing-as-a-service, the operator go-to-market wins — is its own topic, covered in Network-as-a-Service monetization. This pillar owns the API stack and the revenue evidence; it links there rather than restating it.
Three layers, three failure modes fixed
The network-API stack is three layers deep, and each layer exists because the one below it was not sellable. That framing is the cleanest way to read it, so the plumbing section follows it bottom-up.
Sitting alongside NEF is CAPIF — the Common API Framework — TS 23.222, introduced in Release 15, current at v19.9.0. CAPIF is the framework that makes northbound APIs discoverable, authenticated, authorized, logged and charged. Three entities carry it: the API invoker (the consumer), the CAPIF Core Function (authentication, authorization, discovery, publishing, logging/charging), and the API Exposing Function. Reference points CAPIF-1/-1e and CAPIF-2/-2e separate the inside-the-PLMN trust domain from outside it. The stage-3 protocol is TS 29.222; security is TS 33.122.
The actual REST/OpenAPI contract between NEF and an AF — for example AsSessionWithQoS, the operation behind a QoS request — is TS 29.522, "Network Exposure Function Northbound APIs; Stage 3," current at v19.6.0. If you cite the ETSI-published mirror, use ETSI TS 129 522 V19.6.0 (2026-04) — the older V18.10.0 (July 2025) has been superseded.
The reason this layer never became a product is in that paragraph: nobody outside a core team reads TS 29.522. It solved machine-to-machine exposure inside the operator's trust domain and stopped there.
One Release-18 addition matters specifically for monetization, because it makes consumer-facing APIs legally usable: RNAA (Resource owner-aware Northbound API Access), added to CAPIF via SA6's SNAAPP work. RNAA puts OAuth-style authorization in front of the API so the subscriber — the resource owner — consents when an invoker acts on their behalf. A game server requesting a QoS boost, or an app reading device location, now has a consent path. Before Rel-18 the end user had no visibility or control over such invocations at all. That is the side rail in Figure 1, and it is the difference between "technically exposable" and "shippable to consumers under privacy law."
Layer 1 — CAMARA, the developer-intent contract. CAMARA (a Linux Foundation project, launched February 2022 with 22 partners) does the one thing layer 0 could not: it defines developer-facing intent APIs — OpenAPI/YAML definitions on GitHub — that hide 5QI, S-NSSAI and the NEF contract behind a shape a developer can use without a 3GPP background. Operators implement these on top of their exposure layer, in collaboration with GSMA and TM Forum. The Fall25 meta-release (7 October 2025) totals 60 released APIs — 10 stable/implementation-ready, 27 updated, 23 new initial — from 1,300+ contributors across 476 organizations. Stable APIs include SIM Swap, Number Verification, Location Verification, Quality-on-Demand with QoS Profiles, One-Time-Password SMS, Device Roaming Status, Device Reachability Status and Simple Edge Discovery. KYC Match — comparing customer-supplied identity attributes against the MNO's verified records for AML/fraud — is an incubating CAMARA API already offered commercially, e.g. on Telefónica Open Gateway.The conceptual point about CAMARA — intent over mechanism — is the explainer's territory; this is the load-bearing fact for the economics: the catalog is large, stable and standardized, so "the developer contract does not exist" is no longer a valid reason for the revenue not to appear.
Layer 2 — GSMA Open Gateway and the aggregators (one contract, many operators). Even a clean per-operator API leaves a developer facing fragmentation: 300 networks, 300 contracts. GSMA Open Gateway is the commercial layer that mutualizes that, and the aggregators are the businesses built to sell it. That is the next section.From 21 operators to 80% of connections — the footprint, honestly labelled
GSMA Open Gateway launched 27 February 2023 at MWC Barcelona with 21 operator groups (the launch PR says "21 mobile network operators") and 8 universal APIs: SIM Swap, Quality on Demand, Device Status, Number Verification, Edge Site Selection and Routing, Number Verification (SMS 2FA), Carrier Billing, and Device Location. AWS and Microsoft Azure were channel partners at launch.
The growth curve, with each datapoint dated:
- 26 February 2024: 47 operator groups / 239 networks / 65% of global mobile connections; 94 commercially available API instances across 21 markets.
- 4 March 2026: 86 operator groups, 300+ networks, 80% of global mobile connections signed; 300+ commercial instances of 20 different CAMARA APIs across 65 markets; 60+ channel partners. Rakuten Mobile signed the MoU on 5 March 2026 — names are still being added in 2026.
Read those numbers with the right label on them. These are GSMA self-reported, supply-side footprint metrics. "86 operator groups signed" is MoU signatures, not commercial launches. "80% of global connections" describes reachable footprint, not usage. "300+ commercial instances of 20 APIs" counts operator-API pairs that exist, not API calls served or dollars earned. Every one of these is a real and impressive supply-side fact, and not one of them is revenue.
The aggregators are the layer that turns footprint into a single sellable contract:
- Aduna — announced 11 September 2024, transaction completed July 2025 as a 50:50 JV: Ericsson on one side; twelve CSPs on the other (AT&T, Bharti Airtel, Deutsche Telekom, KDDI, Orange, Reliance Jio, Singtel, Telefónica, Telstra, T-Mobile, Verizon, Vodafone). By February 2026 Aduna reported agreements covering all three major US carriers, giving developers CAMARA-compliant access to 300M+ US connections through one platform — the first single-aggregator full-US coverage. At MWC 2026 it reported services live in the US, Germany, Spain, Canada, France and the Netherlands, ~40 operators in footprint, 15 ecosystem partners. (The US-coverage and operator-count figures are Aduna company PR — treat as vendor-reported.)
- Nokia Network as Code — 75+ partners as of MWC26 (3 March 2026), including Deutsche Telekom, Orange, Rakuten, Telefónica, TELUS and Vodafone, plus a Google Cloud tie-up exposing network APIs to AI agents via MCP using Google's ADK and Gemini models. Hold that agentic-AI thread; it is the wildcard in the verdict.
- Vonage — Ericsson's earlier, costlier route to the same goal, and the cautionary tale below.
There is a $4B-shaped lesson in how Ericsson got to Aduna. It closed the Vonage acquisition for $6.2B in July 2022, then took impairments against it: a charge of roughly SEK 32B (~$2.9–3.0B), announced October 2023, followed by a further SEK 11.4B (~$1.1B) non-cash impairment "mainly relating to Vonage" in July 2024. (Ericsson's PRs state the SEK figures; the USD conversions are press estimates.) The strategy then pivoted: rather than own a CPaaS business and chase its margins, mutualize the aggregation risk into a JV. Per reporting, Aduna is structured to cover its costs rather than to generate profit — which tells you how the people closest to the asset price the near-term opportunity. (That characterization is attributed reporting from search-level access to a source that returned HTTP 403; treat it as reporting, not a direct quote.)
The money question: four forecasts that do not agree
Here is where rigor matters most, because the headline numbers in circulation span a factor of roughly forty, and they are routinely quoted as if they measure the same thing. They do not. Lined up with their dates, scopes and who produced them:
- Analysys Mason (13 June 2025): CAMARA-based network-API spend was ~$550M worldwide in 2024, growing to ~$7.6B by 2030 — just 0.6% of mobile service revenue — with potential 8× further growth by 2035. Their headline finding: 94% of 2024 revenue (~$521M) came from China, mainly authentication/number-verification at scale, projected to fall to 37% by 2030.
- Juniper Research (4 August 2025): ~$284M in 2025 rising to >$8B by 2030 (~28×), led by SIM Swap, Number Verification and KYC. Note carefully: Juniper's baseline ($284M in 2025) does not reconcile with Analysys Mason's ($550M in 2024). The likely cause is a scope difference — China inclusion, CPaaS resale, what counts as a "network API" — but it was not confirmed. Never quote these two baselines side by side without that caveat, and never average them.
- STL Partners (15 August 2025): $31.5B by 2030 — an ~8.5% downgrade from its 2024 forecast, made after mapping actual GSMA per-market rollout data. Identity/anti-fraud APIs grow from just under $3B (2025) to $12B (2030); STL still forecasts network-performance APIs at $5.3B by 2030.
- McKinsey (article first published 21 February 2024): network APIs could unlock a large band of connectivity- and edge-related revenue over 5–7 years, plus $10–30B from the APIs themselves. Two things must be said about this number. First, the headline figure has a history: the article as originally published said $300–500B, and was silently revised to ~$100–300B between March and June 2024 — so cite the revised band, and know the original existed. Second, the $100–300B is mostly enabled/adjacent revenue, not API fees, and the McKinsey primary page is unreachable, so the figure rests on corroborating secondaries. It is best labelled a reported, scenario-style number — and it should be called "research by McKinsey, announced by GSMA," not "GSMA-commissioned," because the article carries no commissioning note.
So what are people pointing at when they say "the network API market"? Often McKinsey's $100–300B band — which is mostly adjacent revenue under a five-to-seven-year scenario — set against Analysys Mason's hard $7.6B-by-2030, which is API spend at 0.6% of mobile service revenue. Both can be defensible and they are not the same quantity. A forecast is only as useful as the scope printed next to it.
Fraud pays the bills; QoD makes the demos
Strip the forecasts down to which APIs carry the revenue and an awkward pattern appears, and every analyst house agrees on it: identity and anti-fraud APIs are nearly all near-term revenue, and Quality-on-Demand — the most 5G-native API in the catalog — is parked for after 2030.
The revenue today is identity. SIM Swap (has this number's SIM changed recently?), Number Verification (silent possession-of-line check, the friction-free successor to SMS OTP), and KYC Match are what banks and fintechs actually buy, because they map directly onto a fraud-loss line item the buyer already understands. These are subscriber-identity-security primitives at heart — the same problem space as the SIM-binding and identity-concealment mechanisms in SUPI vs SUCI and the attacker model in can IMSI catchers attack 5G. The first at-scale commercialization proves it: in Brazil, Claro, TIM and Vivo announced three anti-fraud APIs — Number Verification, SIM Swap and Device Location — on 28 November 2023, individually available by end-2023, aimed at banks and fintechs and designed for LGPD compliance. GSMA calls Brazil the Open Gateway pioneer market; in 2026 Aduna signed Vivo, Claro and TIM Brasil to push it further. In the US, the same identity APIs are what the tri-carrier Aduna footprint exposes.
Quality on Demand is the irony at the center of the whole story. QoD is the API that actually exercises 5G's QoS machinery — it is the developer-facing front end to the 5QI and QoS-flow plumbing that the network was rebuilt around. It is also the one not selling. Analysys Mason positions the QoD/quality wave as a phenomenon for after 2030 (this "post-2030" framing is Analysys Mason's, not STL's). STL is less bearish — its $5.3B network-performance forecast by 2030 is non-trivial — but no analyst puts quality APIs anywhere near identity APIs in the near term. The most 5G-est API is the one the market is not yet buying; the boring fraud check is what pays.A second, larger irony sits underneath the whole dataset. 94% of 2024 network-API revenue was China (Analysys Mason). The "global API economy" is, today, largely a China number-verification story — and China Mobile's headline use of number verification is not even fraud prevention but lifting ad-conversion rates (GSMA, March 2026). Strip China out and the rest-of-world number for 2024 is small. The geographic concentration is as important to read honestly as the forecast dispersion.
Verdict 2026: tiny but ramping, and one real wildcard
Put the evidence together. The 3GPP plumbing is mature and current (Figure 1). The footprint has gone from 21 operator groups to 80% of global connections in three years (Figure 3). The catalog is 60 APIs, 10 stable. The aggregator problem — one contract, many operators — is solved in at least one large market. That is a genuinely strong supply side.
And the demand side, stated without varnish: no operator and no aggregator has published audited network-API revenue in financial reporting. The most honest public datapoint is Ericsson leadership describing the revenue, in February 2026, as real and starting to "ramp" but "tiny." (That characterization reached us through search-level access to a source that returned HTTP 403 — attributed reporting, not a verbatim quote.) Every credible forecast that touches 2024/2025 actuals agrees the base is small ($284M–$550M depending on scope), heavily concentrated in China, and dominated by fraud APIs.
Two readings of that are defensible, and an honest engineer should hold both:
The OneAPI-déjà-vu reading. The industry has tried to sell network capabilities to developers before, and earlier GSMA API initiatives failed to scale. (We did not re-verify the history of those earlier programs in this pass; keep the comparison general.) On this reading, the supply-side metrics are vanity numbers — MoUs and operator-API pairs that have repeatedly failed to convert into developer spend, and "80% of connections signed" is exactly the kind of footprint figure that looked good last time too. The slow-compounding-curve reading. Identity/anti-fraud is a genuine, growing, fraud-loss-funded business with real buyers (banks, fintechs) and a clean near-term ROI; it grows from ~$3B (2025) to $12B (2030) on STL's numbers. On this reading the early revenue is small but real and compounding, with QoD as upside once latency-sensitive demand and devices catch up post-2030.The wildcard that did not exist the last time is agentic AI. Nokia's Network as Code now exposes network APIs to AI agents over MCP (Google Cloud, Gemini), and the bull thesis is that autonomous agents — not human developers wiring up SDKs — become the high-volume API consumers that earlier programs never found. It is a thesis, not a datapoint, and worth flagging as exactly that.
The defensible 2026 conclusion: the network-API stack is engineered and deployed; the revenue is early, small, China-weighted and fraud-led; and whether it becomes a material line on operator P&Ls is still genuinely unsettled. Treat any vendor slide quoting a billion-dollar API market as a scope question first — ask which forecast, what year, what counts as a "network API," and whether the number is API fees or "enabled" revenue. The honest answer in mid-2026 is that the plumbing is done and the money has not arrived yet.
Want to touch the actual contract instead of reading about it? Start a free 7-day trial — no card — and work through the stack hands-on. If you operate or sell into enterprise, the demand-side context lives in private 5G for enterprise and the packaging models in NaaS monetization.
Confidence grading used in this article
- High (primary-sourced): all 3GPP/ETSI spec versions and clauses; CAMARA Fall25 release counts; GSMA launch and growth metrics (as self-reported); Aduna JV ownership and the 12 CSPs; Vonage acquisition price and impairments; Analysys Mason, STL and Juniper figures; the Brazil launch.
- Medium / vendor-reported: Aduna coverage and operator-count claims (company PR); the McKinsey band (primary unreachable, secondaries only).
- Reported, not verbatim: Ericsson's "tiny but ramping" and Aduna-as-cost-recovery (search-level access; source returned HTTP 403).
- Explicitly not claimed: any audited operator API revenue (none exists); a reconciliation of the Analysys Mason and Juniper baselines (scopes differ, unconfirmed); the history of pre-2023 GSMA API programs (not re-verified this pass).