How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

GSMA Device Location Verification

GSMA Device Location Verification from GSMA — 1 path(s) described in OpenAPI.

GSMA Device Location Verification is one of 18 APIs that GSMA publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 1 operation across 1 path, and defines 9 schemas. It is described by OpenAPI 3.0.3, at version wip.

Requests are made against a single base URL, {apiRoot}/location-verification/vwip.

1 operations 1 paths 9 schemas 1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.3
API Version
wip
Base URL
https://sandbox.mobilemoneyapi.io/simulator/v1.2/passthrough/mm
Authentication
OpenID Connect
License
Resource Areas
1

Authentication & Security 1

GSMA Device Location Verification declares 1 security scheme for authenticating requests. It supports OpenID Connect (openId) discovered at https://example.org/.well-known/openid-configuration.

  • openId — OpenID Connect authentication

Paths & Operations 1

Across 1 path, the API surfaces 1 operation — 1 POST. Each is listed below with its method, path, parameters, and response codes.

Location Verification 1

Verification of the location of a device

POST
/verify
Verify the location of a device
verifyLocation 1 param body → 200400401403404422

Schemas 9

The contract defines 9 schemas that model the data the API accepts and returns. The most detailed are VerifyLocationResponse (4 properties), VerifyLocationRequest (3 properties), Area (1 property). Each schema is shown below with its type and property counts.

Area
object
Base schema for all areas
1 property 1 required
AreaType
string
Type of this area. CIRCLE - The area is defined as a circle.
Circle
Circular area
VerifyLocationRequest
object
Request to verify the location of a device. Device is not required when using a 3-legged access token, following the rules in the description.
3 properties 1 required
VerifyLocationResponse
object
Response to a location verification request
4 properties 2 required
MaxAge
integer
The maximum age (in seconds) for the location known by the implementation, which is accepted for the verification. Absence of maxAge means "any age" and maxAge…
VerificationResult
string
Result of a verification request: - TRUE: when the network locates the device within the requested area, - FALSE: when the requested area does not match the ar…
MatchRate
integer
Estimation of the match rate between the area in the request (R), and area where the network locates the device (N), calculated as the percent value of the int…
LastLocationTime
string
Timestamp of the last location information. It must follow [RFC 3339](https://datatracker.ietf.org/doc/html/rfc3339section-5.6) and must have time zone.

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

gsma-open-gateway-device-location-verification-openapi.yml Raw ↑

Other APIs GSMA publishes across the network.

GSMA Mobile Money API
GSMA Call Forwarding Signal
GSMA Carrier Billing
GSMA Carrier Billing Refund
GSMA CAMARA Mobile Device Identifier
GSMA Device Location Retrieval
GSMA Device Reachability Status
GSMA Device Roaming Status
GSMA Device Swap
GSMA Home Devices QoD
GSMA Know Your Customer Match
GSMA Number Verification
Where this information came from

This is an independent, third-party profile of GSMA Device Location Verification, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.