The chip inside: what an eUICC is
Inside every eSIM-capable phone sits an eUICC (embedded Universal Integrated Circuit Card): a tiny, rewritable secure chip soldered to the board. Secure has a specific meaning here: like the chip on a bank card, it keeps its secrets in a vault that the rest of the phone cannot read directly. Rewritable is the real difference. A plastic SIM leaves the factory with one carrier's data burned in for life; an eUICC leaves the factory empty, ready to have carrier profiles written to it, swapped and deleted for years. Our what-is-an-eSIM explainer covers the basics; this article is the layer underneath.
Where profiles come from: SM-DP+ servers
Every eSIM profile is prepared and delivered by an SM-DP+ (Subscription Manager Data Preparation Plus), a secure server run by or for the carrier. When a carrier issues you an eSIM, the SM-DP+ packages your credentials into an encrypted profile and holds it until your phone comes to collect. The download travels over a mutually authenticated, encrypted connection: the server proves to the chip that it is genuine, and the chip proves to the server that it is a real eUICC. This is why installing an eSIM needs an internet connection, and why nothing sensitive travels in the email itself.
What a profile actually contains
A profile is the digital version of everything a plastic SIM would hold. The main pieces: your subscriber identity (the IMSI, the number the network knows you by), a secret authentication key that lets your phone prove that identity, the profile's serial number (the ICCID), and the carrier's settings, such as network names and roaming preferences. On a physical SIM these are written into the card at the factory. In an eSIM they arrive as a download and are stored in the eUICC's secure vault, which is designed so that apps and everyday software cannot simply read them out.
The LPA: the eSIM manager in your phone
The LPA (Local Profile Assistant) is the built-in software that manages eSIMs on your phone. It is the screen you already know: Settings, then Mobile or Cellular, then Add eSIM. The LPA scans the QR code, contacts the SM-DP+ server it names, checks the certificates, downloads the profile and hands it to the eUICC. Afterwards it is your control panel: enable or disable a profile, rename it ("Bali trip"), choose which line handles data, and delete profiles you no longer need. You never install a separate app for any of this; it ships with the operating system.
Why a QR code works only once
The QR code is not the eSIM itself: it is an address plus a one-time activation code. Decoded, it tells the LPA which SM-DP+ server to contact and which pending profile to ask for. Once a phone completes the download, the server marks that activation code as consumed, so a second scan gets nothing. That is deliberate: one set of credentials should end up on exactly one chip, never two. It is also why an unused QR code deserves the same care as a password until you have redeemed it.
Many profiles, one standard
An eUICC can hold several profiles at once, and it all works across brands because everyone follows the same GSMA standard. How many profiles fit depends on the phone's storage: many recent models hold five to ten, though usually only one or two can be active at a time. The GSMA (the mobile industry's standards body) publishes the Remote SIM Provisioning specification that defines the eUICC, the SM-DP+ and the LPA, so any compliant carrier's eSIM installs on any compliant phone: iPhone, Pixel or Galaxy alike. It is the reason a travel eSIM from a provider like Goodbars works the moment you scan it.






