How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

GSMA Open Gateway Location verification API

Verification of the location of a device

GSMA Open Gateway Location verification API is one of 34 APIs that GSMA Open Gateway publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Location Verification. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 1 operation across 1 path, and defines 18 schemas. It is described by OpenAPI 3.2.0, at version 3.0.0.

Requests are made against a single base URL, {apiRoot}/location-verification/v3.

1 operations 1 paths 18 schemas 1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
3.0.0
Server
{apiRoot}/location-verification/v3
Authentication
OpenID Connect
License
Resource Areas
1

Authentication & Security 1

GSMA Open Gateway Location verification API declares 1 security scheme for authenticating requests. It supports OpenID Connect (openId) discovered at https://example.org/.well-known/openid-configuration.

  • openId — OpenID Connect authentication

Paths & Operations 1

Across 1 path, the API surfaces 1 operation — 1 POST. Each is listed below with its method, path, parameters, and response codes.

Location verification 1

Verification of the location of a device

POST
/verify
Verify the location of a device
verifyLocation 1 param body → 200400401403404422

Schemas 18

The contract defines 18 schemas that model the data the API accepts and returns. The most detailed are Device (4 properties), VerifyLocationResponse (4 properties), ErrorInfo (3 properties), DeviceIpv4Addr (3 properties). Each schema is shown below with its type and property counts.

VerifyLocationRequest
object
Request to verify the location of a device. Device is not required when using a 3-legged access token, following the rules in the description.
3 properties 1 required
MatchRate
integer
Estimation of the match rate between the area in the request (R), and area where the network locates the device (N), calculated as the percent value of the int…
AreaType
string
Type of this area. CIRCLE - The area is defined as a circle.
XCorrelator
string
MaxAge
integer
The maximum age (in seconds) for the location known by the implementation, which is accepted for the verification. Absence of maxAge means "any age" and maxAge…
NetworkAccessIdentifier
string
A public identifier addressing a subscription in a mobile network. In 3GPP terminology, it corresponds to the GPSI formatted with the External Identifier ({Loc…
LastLocationTime
string
Timestamp of the last location information. It must follow [RFC 3339](https://datatracker.ietf.org/doc/html/rfc3339section-5.6) and must have time zone.
VerifyLocationResponse
object
Response to a location verification request
4 properties 2 required
DeviceIpv4Addr
object
The device should be identified by either the public (observed) IP address and port as seen by the application server, or the private (local) and any public (o…
3 properties
ErrorInfo
object
Common schema for errors
3 properties 3 required
DeviceIpv6Address
string
The device should be identified by the observed IPv6 address, or by any single IPv6 address from within the subnet allocated to the device (e.g. adding ::0 to…
Area
object
Base schema for all areas
1 property 1 required
VerificationResult
string
Result of a verification request: - TRUE: when the network locates the device within the requested area, - FALSE: when the requested area does not match the ar…
SingleIpv4Addr
string
A single IPv4 address with no subnet mask
PhoneNumber
string
A public identifier addressing a telephone subscription. In mobile networks it corresponds to the MSISDN (Mobile Station International Subscriber Directory Num…
Port
integer
TCP or UDP port number
DeviceResponse
An identifier for the end-user equipment able to connect to the network that the response refers to. This parameter is only returned when the API consumer incl…
Device
object
End-user device able to connect to a mobile network. Examples of devices include smartphones or IoT sensors/actuators. The developer can choose to provide the…
4 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

open-gateway-location-verification-api-openapi.yml Raw ↑

Other APIs GSMA Open Gateway publishes across the network.

GSMA Open Gateway Age Verification API
GSMA Open Gateway API Product API
GSMA Open Gateway API Product Order API
GSMA Open Gateway Application API
GSMA Open Gateway Application Owner API
GSMA Open Gateway Call Forwarding information retrieval API
GSMA Open Gateway Check Device Swap API
GSMA Open Gateway Check SIM swap API
GSMA Open Gateway Check Subscriber Tenure API
GSMA Open Gateway Connected Network Type API
GSMA Open Gateway Device reachability status API
GSMA Open Gateway Device reachability status subscription API
Where this information came from

This is an independent, third-party profile of GSMA Open Gateway Location verification API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.