When a fraudster moves a victim's phone number to a new SIM, they start receiving the victim's one-time passwords and can reset accounts or approve payments. Ooredoo's network APIs let you check the line before you trust it.
Before a login from a new device, a password reset, a payment or a payout, call SIM Swap check with the phone number and a time window (maxAge, in hours).
2
If the SIM changed recently
Pause the action and ask for stronger proof: in-app confirmation, a document check or a call. Use retrieve-date if you want the date of the last swap to apply your own rule.
3
If it did not
Continue as normal. For a smoother check, confirm the number silently with Number Verification instead of sending an SMS code.
You decide. The check operation takes maxAge, a window in hours, and answers whether the SIM was swapped within it. retrieve-date returns when the SIM was last swapped, so you can apply your own rule.
Does the user have to do anything?
No. SIM Swap is a server-to-server call on the phone number. The user sees nothing unless you decide to ask for more proof.
Which standard does it follow?
SIM Swap, Number Verification and OTP follow CAMARA, part of the GSMA Open Gateway initiative.