PSMO Operations
Create profile lifecycle operations, execute against eIM Core, and monitor job status.
New operation
Assign ICC to EID
Link a Released profile from inventory to the target EID (Released(assigned) until install completes).
Advanced options
Operation queue
| id | type | EID | ICCID | esipa_suffix | status | error | created_at | executed_at | Actions |
|---|
Batch Campaigns
Stage PSMO operations across your fleet, or queue a Remote IPAe applet update for a list of EIDs (or every eUICC not yet on the desired IPAe version).
Fleet operations at scale
Paste EIDs (one per line) or import a .txt file. PSMO campaigns can pick a Released profile by MNO / product / PLMN. IPAe update campaigns clone an SCP11c script per EID and optionally skip cards already on the target version.
New campaign
IPAe update
Upload a CAP (or reuse an existing Remote IPAe job). After a successful queue, each EID is stamped with the target version so the next fleet run skips cards already on it.
Default ICC selection (inventory)
Used when a target line has EID only. Picks oldest Released ICC matching all filled fields.
Lines: EID · EID,ICCID · EID,version (IPAe) · EID,MCC,MNC,MNO,product. Comments start with #.
Campaign history
| Name | Operation | Status | Total | OK | Failed | Progress | Created |
|---|---|---|---|---|---|---|---|
| Sign in and open this view to load campaigns. | |||||||
—
—
| EID | ICCID / job | Status | Error | Operation ID |
|---|
Remote IPAe management
Campaign Manager: upload a Java Card CAP, build a GlobalPlatform SCP11c (variant C) script that deletes the IPAe instance and load file, then loads and installs the new applet. Push the script over the OTA HTTP interface.
Build SCP11c script
OTA HTTP execute
SCP11c handshake is interactive (card ephemeral key). eIM queues the plaintext GP script plus CERT.OCE.ECKA; the OTA HTTP client wraps APDUs (CLA 0x84) after MUTUAL AUTHENTICATE.
Build a script to preview APDUs.
| Job | CAP | SD AID | Instance | Status | |
|---|---|---|---|---|---|
| No jobs yet. | |||||
Network QoS
Ingest device QoS by PLMN, compare networks, and apply recommend-mode profile selection (assign + stage download — no auto-switch yet).
Ingest report (lab / device app)
Recommend profile
| EID | Serving PLMN | Signal | Surveyed PLMNs | Location | Source | Score | Observed |
|---|
QoS map
No reports with GPS coordinates in this window.
● score ≥70 ● 40–69 ● <40
Analytics & Reports
PSMO volume, success rates, and inventory snapshot — filter by date range and operation type.
—
Operations by status
Operations by type
Volume over time
ICC inventory by status
User Management
Provision tenant users and roles. Admin-only actions are hidden from standard users.
Create user
Email is required for welcome and password-reset messages. Optional policy: force password change on first sign-in, and rotate password after N days.
Directory
| username | role | kind |
|---|
Inventory Management
ICCIDs with activation material, EUICC registry, and lifecycle status aligned with your ops workflow.
ICC inventory
Import ICCIDs with activation codes: legacy icc_id,activation_code or extended
icc_id,activation_code,imsi,mcc,mnc,network_operator,product_type (MCC/MNC or IMSI recommended for QoS).
JSON entries supports the same fields. Register EIDs separately (right panel).
Lifecycle: Released → Released(assigned) (assign) → Installed (automatic) → Deleted.
| icc_id | activation_code | PLMN | MNO / product | status | eid / assign | updated_at |
|---|
eUICCs (EIDs)
Register 32-digit EIDs. Optional second column sets the last-known IPAe version: EID,1.2.0. Duplicates without a version are skipped.
| eid | IPAe version | eim_config | updated_at |
|---|
eIM Configuration
Configure eIM on the eUICC remotely over HTTPS (IPAd polls GetEimPackage and delivers a signed package). No manual APDUs required when IPAd is connected.
Push to eUICC (HTTPS / ESipa)
Package counter resync admin
SGP.32 signed EuiccPackageRequest uses a monotonic counterValue. IPAd error euiccPackageErrorCode=4 is replayError — the eUICC already saw that counter. After a failed op, the platform auto-syncs stored to the replay counter — usually just re-stage (no align). Align only if stored is behind the latest replay value from IPAd. Use the replay counter from the error (e.g. replay on 13 → enter 13, next sign is 14). Do not enter the next counter you want to send.
—
Inventory JSON (optional)
Stores tenant inventory only — does not send anything to the eUICC.
Tip: use Load for edit from the EUICC table in Inventory Management.
Debug & event log
Look up audit entries and ESipa / IPA protocol traces (transport + BER hex preview) by EID or ICCID. For raw TCP captures use Wireshark on the host. Export saves audit events as text.
| Time (UTC) | Severity | Type | Message | EID | ICCID | Operation | Actor | Request | Detail |
|---|
Protocol traces (ESipa / IPAe)
| Time | Layer | Dir | Function | Path | Status | Remote | Len | Payload hex |
|---|
Documentation
Operator guide and Admin HTTP API reference (Markdown). Served as static files from this site.
White-label
This screen is shown only when your deployment sets EIM_VENDOR_WHITELABEL_KEY and you unlock this browser (once) with ?eim_wl=….
Customer builds ship with an empty key — they never see this menu. Rebrand data is still localStorage + optional URL params for OEM theming without exposing the editor.
Identity
Theme colors
Primary drives accents and grid highlights; secondary supports gradients and glows.
Advanced surfaces
Persist & share