Building ConSentra — execution-scoped authorization and governance for enterprise AI agents. ConSentra — authorization for enterprise AI agents. See the architecture →

Your Phone Number Should Be a Signal, Not a Password

·

For years, consumer authentication has relied on a strange little ritual.

A company sends a temporary secret over the mobile network. The customer waits for it, copies it from a text message, returns to the application, and types it back in.

We have all grown used to it. That does not make it especially elegant or secure.

SMS one-time passcodes became popular because they were easy to understand and available to almost anyone with a phone. They also created an authentication method vulnerable to phishing, SIM-swapping, message interception, delivery failures, and determined social engineering.

A new U.S. rollout could begin changing that experience.

In July, Aduna announced that it was working with AT&T, T-Mobile, and Verizon to introduce network-based Number Verification across the United States. The service allows an application to check, through the carrier network, whether a mobile number is associated with the SIM and device being used.

The verification happens in the background. The customer does not need to wait for a text message, memorize a code, or switch between applications.

That sounds like a clear improvement. In many customer journeys, it probably will be.

It also raises an important question for identity architects:

What has actually been verified?

SMS Codes Have Been Carrying Too Much Responsibility

An SMS code is generally used as proof that someone can receive a message sent to a particular phone number.

Over time, that modest piece of evidence has been asked to carry an enormous amount of trust.

Organizations use SMS codes during registration, login, account recovery, payment approval, device enrollment, profile changes, and other sensitive transactions. In some environments, possession of a code can be enough to reset a password or take control of an account.

Attackers understand that.

A convincing phishing page can capture an OTP while it is still valid. A successful SIM swap can redirect messages to a device controlled by the attacker. Social engineering can persuade a customer or support agent to reveal or bypass the code entirely.

SMS also creates ordinary customer friction. Messages arrive late. Customers leave the application to retrieve them. Codes expire. Autofill fails. Some messages never appear at all.

Every extra step creates another opportunity for confusion, abandonment, or fraud.

Carrier-based Number Verification removes the temporary secret from the journey. Rather than asking the customer to prove possession by reading and returning a code, the application asks the carrier network whether the mobile number matches the SIM and device making the request.

The GSMA’s Number Verification standard describes this as silent authentication. It can run during registration, login, or a transaction without requiring the customer to interact with an OTP prompt.

That is a much cleaner experience.

It also removes the reusable human from the middle of the process. There is no code for the customer to mistype, misunderstand, or hand to an attacker.

A Verified Number Is Useful Evidence

Aduna says its U.S. implementation addresses technical limitations that affected earlier network-verification approaches, including customers using Wi-Fi or different device and operating-system combinations.

AT&T has also described Number Verification and SIM Swap APIs as part of a wider effort to expose carrier intelligence through standardized interfaces. Rather than negotiating separate integrations with each major carrier, developers can work through a common layer covering AT&T, T-Mobile, and Verizon.

This matters for CIAM.

A customer identity platform makes better decisions when it has access to reliable signals beyond usernames, passwords, and static profile data. The carrier network can contribute context that an application would otherwise struggle to obtain.

A successful Number Verification check can provide strong evidence that the phone number, SIM, and device involved in the journey are currently associated through the mobile network.

That evidence can be valuable during registration, low-risk authentication, phone-number validation, and transaction approval.

It should still be treated as evidence rather than a complete identity decision.

The carrier can help establish possession of the mobile number. It cannot automatically establish the identity of the person holding the phone. It cannot determine whether the customer intended the transaction. It cannot decide whether the account should be allowed to perform a sensitive action.

A stolen unlocked phone may still pass a possession check. A compromised carrier account may require additional investigation. A recent SIM or device change may completely alter the risk of an otherwise successful verification.

The phone number belongs in the risk decision. It should not become the risk decision.

Better Authentication Comes From Combining Signals

The most useful future for carrier verification is not a universal replacement for every authentication factor.

Its value comes from orchestration.

Imagine a returning customer signing in from a familiar device and location. The carrier silently confirms the expected number, the device has a clean history, and the customer is accessing a low-risk service.

That journey may require almost no visible authentication friction.

Now imagine the same phone number appearing on a new device shortly after a SIM change. The customer is attempting an account recovery, changing the payment destination, or moving a large amount of money.

A successful Number Verification result should not erase those other signals.

The journey may need a passkey, stronger identity verification, a trusted-device confirmation, a waiting period, or review through a separate channel.

This is where CIAM architecture becomes more interesting than simply choosing an authentication method.

The system has to understand the action being requested, the assurance provided by each available signal, and the consequences of making the wrong decision.

Number Verification may be enough for one transaction and insufficient for another. The correct response depends on the customer, device, account history, requested action, and surrounding fraud context.

Good orchestration lets an organization apply that judgment without forcing every customer through the most difficult possible journey.

Passkeys and Carrier Signals Solve Different Problems

The arrival of network-based verification comes as passkeys are becoming mainstream.

The FIDO Alliance reported in May that approximately five billion passkeys were already in active use worldwide. Its research found that 90 percent of surveyed consumers were familiar with passkeys and 75 percent had enabled them on at least some accounts.

Passkeys provide phishing-resistant authentication tied to a credential held on the customer’s device. Carrier verification provides evidence about the relationship among the phone number, SIM, device, and mobile network.

Those signals complement one another.

A passkey can provide strong authentication for a known customer. Carrier intelligence can add context during registration, recovery, device replacement, or a high-risk transaction.

The combination becomes especially valuable when the organization needs to distinguish a normal customer journey from an account-takeover attempt.

A customer using a valid passkey from a familiar device with a stable phone-number history presents a very different risk profile from someone attempting recovery after a recent SIM swap.

CIAM platforms should be able to recognize that difference and respond accordingly.

The Fallback Path Still Matters

New authentication methods often fail at the edges rather than the center.

The happy path looks excellent. The phone is supported, the network responds, the device is available, and the customer moves through the journey without seeing a code.

Then someone changes carriers. They travel internationally. They lose their phone. Their device cannot complete the silent verification. The network API is temporarily unavailable. A legitimate customer needs access through a channel that does not depend on the original device.

Organizations still need fallback journeys.

Those fallbacks cannot quietly reintroduce every weakness the new method was supposed to remove.

Replacing SMS verification during normal login provides limited value if account recovery still allows a support agent to send a reset link to a newly supplied email address. A sophisticated primary journey can still be undermined by weak factor replacement, device enrollment, or customer-service overrides.

The broader identity lifecycle has to be designed as one system.

Registration, authentication, recovery, profile changes, device replacement, fraud review, and customer support all need controls appropriate to the authority they hold.

Where Navar Helps

Network-based verification gives organizations another valuable source of customer context. Turning that signal into better security and a better customer experience requires more than connecting an API.

Navar helps organizations design CIAM journeys that bring authentication, fraud signals, device context, recovery, and step-up controls into a consistent architecture.

That work includes determining where carrier verification adds meaningful assurance, how it should interact with passkeys and MFA, when recent SIM or device changes should increase risk, and which transactions require stronger verification.

It also means designing reliable fallbacks, testing the journeys customers actually use, and giving support and fraud teams enough visibility to understand why an authentication decision was made.

The goal is not to collect as many signals as possible.

The goal is to use the right signals at the right moment, with enough context to make a sound decision.

Carrier verification could remove one of the clumsiest steps in consumer authentication. It could also give CIAM and fraud systems better insight into the mobile device behind the journey.

That makes the phone number more useful than it was as a destination for six-digit codes.

It still should not be treated as a password.

Navar helps organizations turn mobile-network context into secure, low-friction customer journeys that hold up beyond the happy path.

Share LinkedIn X
Jacob Ehmer Avatar

Let’s deploy

Have an IAM deployment stuck between strategy and production?

Navar can help assess the environment, define the plan, integrate the systems, and support the rollout.

Keep reading

More articles & posts