{"id":51718162,"url":"https://github.com/abhirupr123/signalbind","last_synced_at":"2026-07-17T06:05:13.962Z","repository":{"id":331338924,"uuid":"1126237459","full_name":"abhirupr123/signalbind","owner":"abhirupr123","description":"SignalBind is a trust layer for digital onboarding that ties user consent to verified SIM ownership preventing fraud from recycled numbers strengthening consent capture for regulatory compliance.","archived":false,"fork":false,"pushed_at":"2026-01-01T13:47:34.000Z","size":136,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"master","last_synced_at":"2026-01-06T15:16:40.540Z","etag":null,"topics":["android","fintech-security","fraud-prevention","jetpack-compose","network-as-code","number-verification","sim-swap-detection","telco-api","typescript"],"latest_commit_sha":null,"homepage":"","language":"Kotlin","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/abhirupr123.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-01-01T13:11:31.000Z","updated_at":"2026-01-01T13:50:29.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/abhirupr123/signalbind","commit_stats":null,"previous_names":["abhirupr123/signalbind"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/abhirupr123/signalbind","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/abhirupr123%2Fsignalbind","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/abhirupr123%2Fsignalbind/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/abhirupr123%2Fsignalbind/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/abhirupr123%2Fsignalbind/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/abhirupr123","download_url":"https://codeload.github.com/abhirupr123/signalbind/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/abhirupr123%2Fsignalbind/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35569672,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-17T02:00:06.162Z","response_time":116,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["android","fintech-security","fraud-prevention","jetpack-compose","network-as-code","number-verification","sim-swap-detection","telco-api","typescript"],"created_at":"2026-07-17T06:05:13.250Z","updated_at":"2026-07-17T06:05:13.955Z","avatar_url":"https://github.com/abhirupr123.png","language":"Kotlin","funding_links":[],"categories":[],"sub_categories":[],"readme":"# 📱 SignalBind - Telco-Verified Consent Receipt\n\n## 🚀 Overview\nDigital platforms like UPI apps, wallets, and microloan services rely heavily on mobile numbers and OTPs for user verification. However, mobile numbers are frequently recycled or reassigned, especially in prepaid-heavy markets. This creates a blind spot where fraudsters can hijack dormant accounts or impersonate users.\n\nSignalBind implements a **Telco-Verified Consent Receipt** system using **GSMA Open Gateway APIs via Nokia Network-as-Code**. It ensures that user consent is tied to the rightful SIM holder, reducing fraud and improving trust in digital financial services.\n\n---\n\n## 🌍 What SignalBind Actually Is\nSignalBind is a **trust layer for digital onboarding**. Instead of relying only on OTPs or basic KYC checks, it introduces a **telco-verified consent receipt**—a digital proof that the person giving consent is the rightful owner of the SIM and phone number at that moment.\n\nThink of it as a **network-signed certificate of identity**: when someone signs up for a loan, wallet, or UPI app, the telecom operator confirms that the number is valid, hasn’t been recycled recently, and belongs to the current SIM holder. That confirmation is then bound into a receipt that can be audited later.\n\n---\n\n## 🎯 Why We Are Using It\n- **Close a Blind Spot in Identity Verification**  \n  OTP-based verification assumes that whoever receives the OTP owns the number. But in prepaid-heavy markets, numbers are recycled frequently. Fraudsters exploit this gap by hijacking dormant accounts or impersonating users.\n\n- **Strengthen Consent Capture**  \n  Regulators (like RBI in India) require platforms to maintain consent logs. By tying consent to a telco-verified identity, platforms can prove that the user was genuine at the time of onboarding.\n\n- **Reduce Fraud in Financial Inclusion**  \n  Microfinance, rural banking, and UPI apps often deal with vulnerable populations. A telco-backed verification layer reduces fraud risk without adding friction for genuine users.\n\n---\n\n## 🌟 Impact It Might Have\n- **For Users**: Safer onboarding, fewer cases of account hijack, and more trust in digital financial services.  \n- **For Platforms**: Stronger compliance with regulatory mandates, reduced fraud losses, and a competitive edge by offering “network-verified” trust.  \n- **For Regulators**: A reproducible audit trail that shows consent was captured with telecom-level verification, aligning with emerging data protection and cybersecurity rules.  \n- **For the Ecosystem**: Builds a foundation for telco-backed digital identity, which can extend beyond finance into education, healthcare, and e-commerce.\n\n---\n\n## 🏗️ Architecture\n\n### Frontend\n- **Android App (Jetpack Compose)**\n  - Captures mobile number from device\n  - Displays consent receipt and audit status\n\n### Backend\n- **Node.js + TypeScript Service**\n  - Routes: `/verify`, `/sim-swap`, `/number-verification`\n  - Integrates with Nokia Network-as-Code APIs\n  - Generates signed consent receipts (JWT)\n  - Stores evidence bundle with API response IDs and timestamps\n\n### APIs Used\n- **Number Verification API** → Confirms SIM holder owns the number\n- **Number Recycling API** → Checks if the number was reassigned recently\n- **SIM Swap Detection API (optional)** → Flags recent SIM changes\n\n---\n\n## 🔑 Authentication Flow\n1. **Get Client Credentials** → Retrieve `client_id` and `client_secret`\n2. **Get Endpoints** → Authorization + Token endpoints from metadata\n3. **Get Authorization Code** → Redirect via RequestCatcher to capture `code`\n4. **Exchange Code for Access Token** → OAuth2 token endpoint\n5. **Verify Number** → Call Number Verification API with `Bearer \u003cACCESS_TOKEN\u003e`\n\n---\n\n## 📂 Project Structure\n```\n/src\n  /routes\n    verify.ts\n  /services\n    numberVerification.ts\n    telcoApi.ts\n  /utils\n    receiptGenerator.ts\n  index.ts\n```\n\n---\n\n## ⚙️ Technical Stack\n- **Frontend**: Android (Jetpack Compose, Kotlin)\n- **Backend**: Node.js, TypeScript, Express.js\n- **Database (optional)**: MongoDB / PostgreSQL for audit logs\n- **APIs**: Nokia Network-as-Code (GSMA Open Gateway)\n- **Security**: OAuth2, JWT, TLS\n\n---\n\n## 🧑‍💻 Running Locally\n1. Clone the repo:\n\n```bash\ngit clone https://github.com/signalbind.git\ncd telco-consent-receipt\n```\n\n2. Install dependencies:\n\n```bash\nnpm install\n```\n\n3. Set environment variables in `.env`:\n\n```bash\nRAPIDAPI_KEY=\u003cyour-key\u003e\nREDIRECT_URI=https://\u003cyour-url\u003e.requestcatcher.com/\n```\n\n4. Start the backend:\n\n```bash\nnpm run dev\n```\n\n5. Test with curl:\n\n```bash\ncurl -X POST http://localhost:3000/verify \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"phoneNumber\": \"+99999991001\"}'\n```\n\n---\n\n## 📊 Demo Strategy\n- Live demo on Android device with real SIM context\n- UI shows real-time decision flow and audit metadata\n\n---\n\n## 🔮 Future Scope\n- Extend to UPI onboarding, wallet login, microloan disbursal\n- Align with RBI consent log mandates \u0026 India’s DPDPA\n- Scalable across fintech, edtech, and e-commerce platforms\n- Telco-backed trust infrastructure for digital identity\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fabhirupr123%2Fsignalbind","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fabhirupr123%2Fsignalbind","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fabhirupr123%2Fsignalbind/lists"}