Skip to content
Back to skills

Esim

ASecurity

Implement and troubleshoot eSIM across consumer activation, carrier integration, and RSP development.

  • 14 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 7, 2026
developmentgotestingapisecurity

Works with

  • api

Security analysis

A100/100

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill esim --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Esim?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Esim
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-esim/badge)](https://www.skillsdirectory.com/skills/modbender-esim)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: eSIM
description: Implement and troubleshoot eSIM across consumer activation, carrier integration, and RSP development.
metadata: {"clawdbot":{"emoji":"πŸ“±","os":["linux","darwin","win32"]}}
---

## Critical Distinction
- Consumer RSP (SGP.22) and M2M RSP (SGP.02) are completely different architectures β€” not interchangeable, verify which applies before starting

## Platform API Restrictions
- Apple eSIM APIs require carrier entitlements β€” third-party apps cannot access without carrier partnership agreement
- Android carrier privilege APIs require signing certificate match β€” must be signed with carrier's certificate
- No public API exists for arbitrary eSIM provisioning β€” apps suggesting otherwise will fail App Store/Play Store review

## Activation Code Traps
- Format is `LPA:1$SMDP+address$MatchingId` β€” parse carefully, some codes omit optional parts
- `$1` suffix means confirmation code required β€” flow differs, timeout is shorter
- Codes are often one-time use β€” SM-DP+ rejects reused MatchingId, must generate new code
- QR code is just encoding β€” the activation code content is what matters

## Certification Requirements
- GSMA SAS (Security Accreditation Scheme) mandatory for production SM-DP+ β€” cannot go live without it
- Use test eUICCs during development β€” production EIDs must not touch test environments
- GSMA TS.48 defines RSP test cases β€” certification testing follows this spec
- Entitlement server is separate from RSP β€” iOS carrier features require additional integration beyond profile provisioning

## Consumer-Facing Pitfalls
- QR codes expire β€” typically 24-72 hours, carrier-dependent, users panic when "invalid"
- Deleting profile is permanent on device β€” must request new activation code from carrier, no local recovery
- Device lock status matters β€” locked devices reject profiles from non-native carriers
- Regional variants of same phone model may lack eSIM hardware β€” verify before promising compatibility
- Profile transfer between devices almost never works β€” expect new activation per device

## Carrier Integration Reality
- MVNOs rarely operate own SM-DP+ β€” use MNO's infrastructure or aggregators (G+D, IDEMIA, Thales)
- Business agreements required before technical integration β€” ES2+ access isn't self-service
- Number porting complicates eSIM activation β€” may require physical SIM first depending on carrier process

## Troubleshooting Specifics
- "Profile already exists" error β€” delete existing profile before retry, or request new MatchingId from SM-DP+
- Download fails mid-process β€” ES9+ requires stable HTTPS, retry on better connection, not a code issue
- Profile installed but no service β€” verify profile is enabled AND set as active line, restart radio

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…