CAPIF (Common API Framework)

Also known as: Common API Framework

CAPIF is the 3GPP framework (TS 23.222 / TS 33.122) that standardises how 3GPP northbound APIs are published, discovered, authenticated and authorised. It defines the roles of API provider, API invoker and CAPIF core function, and mandates OAuth2 or TLS-based authentication of external API consumers. NEF and SEAL exposures typically sit behind CAPIF.

Categories: Core NetworkSignalingSecurity Controls

CAPIF in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

To place CAPIF in the wider telecom-security picture, review Hardening, 5G SBA, Core Network Security Assessment, Network Exposure Function (NEF), ACL and Authorization: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • 5G NEF Security Network Exposure Function security in the 5G core.
  • SEPP Security N32-c/N32-f, PRINS, JWE and OAuth 2.0 at the 5G roaming edge.
  • SS7 Security SS7/MAP/CAP/SCCP attacks and defenses across 2G/3G interconnect.
  • Diameter Security 4G/LTE Diameter threats across IPX/roaming and DEA defenses.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.