- The iOS and Android beta uses carrier-backed SIM or eSIM credentials instead of SMS one-time passwords for supported authentication flows
- Glide says unsupported flows can fall back to passkeys or email links, leaving fallback and recovery performance to be tested beyond beta
The fact
Glide.id has launched a public beta of MagicalAuth on iOS and Android across AT&T, T-Mobile and Verizon in the United States. The service is designed as an alternative to SMS one-time passwords, using a cryptographic check tied to a carrier-issued SIM or eSIM. Glide says MagicalAuth sends a challenge that is answered using the credential held by the SIM, allowing the mobile network to verify possession of the subscription without sending a code to the user.
Support is now live across the three operators. Glide says the service can work over mobile data or Wi-Fi and can be integrated through software development kits or application programming interfaces. If SIM-based authentication is unavailable, MagicalAuth can fall back to alternatives including passkeys or email links. Neither Glide’s product page nor reporting on the launch provides production-scale fraud results, authentication completion rates or fallback frequency.
The assessment
MagicalAuth changes how an application verifies that a user controls a mobile subscription. With SMS, the application sends a code to a phone number and relies on the user returning it. MagicalAuth instead uses the carrier and the SIM or eSIM credential to confirm possession of the subscription. This removes the code-delivery step and brings the mobile network directly into the authentication process.
Fallback matters when that SIM-based check cannot be completed. Glide says MagicalAuth can switch to passkeys or email links, giving users another way to sign in. The strength of the overall process therefore also depends on how those alternatives and account-recovery routes are configured. The public beta has not yet shown how often they will be needed or whether performance differs by carrier, device or network conditions.
For BTW readers, support across AT&T, T-Mobile and Verizon gives developers a SIM-based authentication method that can be tested across the three major US mobile networks. If production deployments can keep most eligible users on that route, businesses could reduce their reliance on SMS one-time passwords. The beta has not yet demonstrated that outcome.
What towatch
Production deployments will show whether MagicalAuth works consistently beyond the beta. Completion rates, latency and fallback use across AT&T, T-Mobile and Verizon will be important, along with how the service handles SIM changes, number porting and device replacement. Independent security testing, recovery data and fraud comparisons with SMS would provide stronger evidence of whether SIM-based authentication improves the login process in practice.

