FAQ

Beyond the QR Code: Every eSIM Activation Method Explained

TravelGo 2026-06-24
Beyond the QR Code: Every eSIM Activation Method Explained

The QR Code: Simple but Not Universal

When most people think of eSIM activation, they picture a QR code. This method, formally defined in the GSMA SGP.22 specification, remains the most widely recognized activation path. The process is straightforward: your carrier generates a QR code containing an SM-DP+ server address and a matching ID, you scan it with your phone's camera, and the device downloads the profile. However, the QR code method has critical limitations. It requires a functioning internet connection on the device before activation can begin — a frustrating catch-22 when you are trying to get connected in the first place. QR codes are also static by nature; once printed on a card or displayed in an email, they cannot be dynamically updated. Worse, if the QR code is shared or leaked, anyone who scans it before you can consume your prepaid profile. The industry is gradually moving toward more secure and convenient alternatives, but QR codes persist because of their simplicity and universal compatibility across virtually every eSIM-capable device released since 2018.

SM-DP+ Auto-Discovery: The Apple Way

Apple redefined eSIM onboarding with the introduction of SM-DP+ automatic discovery, often marketed as eSIM Carrier Activation or eSIM Quick Transfer. Instead of scanning a QR code, the device proactively queries a discovery server maintained by GSMA — the SM-DS (Subscription Manager Discovery Server). When a carrier provisions a profile for your device, it registers a pending notification with the SM-DS using your device's EID (eUICC Identifier). Your device periodically polls the SM-DS, detects the waiting profile, and initiates download automatically. This method eliminates the need for a prior internet connection since the polling can occur once any connectivity — including temporary Wi-Fi — becomes available. The user experience is dramatically smoother: during iPhone setup, the system simply asks if a cellular plan is ready for your device. Behind the scenes, this method relies on a chain of trust between the carrier's SM-DP+ server, the global SM-DS infrastructure, and the device's eUICC. The trade-off is that carriers must invest in integrating with the SM-DS ecosystem, which smaller MVNOs sometimes find cost-prohibitive. Samsung has since adopted a similar mechanism for Galaxy devices, and Google Pixel supports it through its carrier services framework, making this the de facto premium activation method.

In-App Activation: When Carriers Take Control

A growing number of carriers and travel eSIM providers favor application-based activation, where the carrier's own app orchestrates the entire profile download. In this model, the app — having been granted eUICC access permissions by the operating system — communicates directly with the carrier's backend, retrieves the activation token, and passes it to the device's LPA (Local Profile Assistant). The user never sees a QR code or interacts with system settings. This approach offers several advantages for carriers. First, it enables dynamic pricing and real-time plan selection within a branded experience. Second, it allows carriers to implement additional authentication layers — biometrics, two-factor verification, or existing account credentials — before releasing the profile. Third, it creates a closed loop for customer support; if activation fails, the app can surface contextual error messages and guide the user through troubleshooting. For travel eSIM providers like Airalo and Holafly, in-app activation has become the dominant model because it bundles profile delivery with top-up flows, usage monitoring, and support chat — all without requiring the user to understand what an eSIM actually is. The downside is that users must install yet another app and grant it sensitive permissions, raising valid privacy and trust questions.

M2M Push: The Industrial-Grade Method

The fourth activation method, defined in GSMA's SGP.02 specification for machine-to-machine (M2M) and IoT deployments, operates on an entirely different paradigm: push rather than pull. In consumer eSIM architectures, the device pulls the profile from the carrier's server. In M2M eSIM, the carrier pushes the profile to the device's eUICC through a dedicated SM-SR (Subscription Manager Secure Routing) entity. This push model is essential for devices that lack a user interface — think smart meters, vehicle telematics units, asset trackers, and agricultural sensors deployed across thousands of square kilometers. The SM-SR maintains a secure tunnel to each eUICC and can remotely provision, enable, disable, or delete profiles without any local intervention. The profile switching logic can be triggered by network conditions, geolocation, or time-based rules defined by the enterprise. While M2M eSIM rarely concerns the average smartphone user today, the underlying push architecture is gradually influencing consumer eSIM standards. GSMA's SGP.32 specification for IoT eSIM bridges the gap between M2M push and consumer pull models, and some industry observers predict that future smartphone eSIM implementations will adopt hybrid push-pull capabilities — enabling carriers to proactively provision profiles in the background, perhaps even before the user realizes they need one.