Building YonoSIM API in the open — Vol. 2
I built an API for travel apps. The partner actually sending me buyers runs an eSIM marketplace — and I didn't count them until this week.
Summary
I built the API for travel apps, and I’m still waiting on that door — it’s only been open sixteen days, which on my own SEO clock is far too early to read. Meanwhile a partner I’d half-dismissed was quietly sending me real buyers — an eSIM marketplace, not the app developer I’d pictured. On the consumer side it was our best fortnight yet: 36 different people bought in fourteen days, and strangers in fifteen countries started searching our name. Vol. 2 is about not recognising your own first customer.
In Vol. 1 I wrote that I’d had zero live-mode integrations and promised to go find three real conversations before Vol. 2. Here’s the part that took me all week to see clearly: I had three conversations. I just didn’t count them, because none of them were with the customer I had in my head.
The customer in my head was a travel app. A trip-booking flow, an itinerary product, a hotel checkout — someone who’d embed connectivity where their user already was. Every page I wrote on /business, the whole hero on /developers, and most of Vol. 1 speaks to that person. That person hasn’t arrived yet, and I’ll get to why I think it’s too early to read anything into that.
The people who showed up run eSIM marketplaces. Price comparison sites. The places a traveler goes when they’ve decided to buy an eSIM and want to know which one. I had them filed under “affiliate stuff” rather than “partners,” and that filing error cost me a volume of this log.
The partner I didn’t write about
eSIMDB has been live with us since before Vol. 1 shipped, and I never mentioned them once. Pulled from Postgres and GA4 this morning:
- 7 referred sessions in July → 59 in August (42 distinct people).
- 5 orders, 5 different buyers, first on 2 August, most recent on 21 August.
- They landed on
/destinations/*and/plan/*pages, not just the homepage — the feed is deep-linking people straight to the thing they wanted. - That made eSIMDB our second-largest attributed order source in August, behind ChatGPT and ahead of every other channel we can name.
Five orders is a small number. I’m not going to dress it up. But it is five more than the segment I built the API for has produced in six weeks, and it arrived through a mechanism I wasn’t paying attention to. And this week a second marketplace got their key: their team bought a plan and tested it on the ground in Seoul before writing a line of integration code, which is a better vendor-diligence process than most companies run. They’re mid-integration as I publish this.
The whole partner ledger, including the embarrassing parts
Nine partners are registered in our codebase. Here is what that number actually means, which is less than it sounds:
- 1 live and producing orders. eSIMDB, above.
- 1 integrating right now. Key issued this week.
- 1 replied, then went quiet. My read is that marketplaces are being approached by every eSIM provider at once and the listing slots are contested. I don’t think we did anything wrong; I think we were one of forty emails.
- 1 asked for a setup fee, and I said no. I’ll pay commission on a traveler who actually buys, forever. I won’t pay to be listed next to people who did. That’s a real cost — it’s a placement we don’t have — and I’d make the same call again.
- 5 were never switched on at all. They exist in our partner registry, they have a docs page, and the feed returns a hard error for every one of them because I never issued a credential. Not rejected. Not evaluated. Never given a key. I found this while writing this post.
That last line is the one worth sitting with. For weeks I’ve been describing YonoSIM as having nine listing partners. Five of them couldn’t have called our feed if they’d tried. The distribution wasn’t rejected by the market — it was half-built and I’d stopped looking at it.
The other half is sixteen days old
Vol. 1’s headline fix was tearing down the “request early access” gate on /developers so anyone could self-serve a sandbox key — no NDA, no card, no sales call. Here is the scoreboard, and then the reason I’m not reading much into it yet:
- 0 sandbox keys issued to anyone outside the company. Every key in the database is one I created myself, with names like “Local smoke.”
- About 7 strangers have ever visited
api.yonosim.com, and the interactive playground has had one session in the last four weeks. Zero of that traffic came from search, referral, or an AI assistant. Nobody links to it. Nothing cites it. - 0 commits to the API repo since Vol. 1 — against 44 commits to the consumer site in the same nine days. My hands went where the results were, and I didn’t decide that on purpose.
Now the part I’d have got wrong a week ago: none of that is a verdict yet. The API has been live for sixteen days. I have a very good reference clock for how long this takes, because I already ran the experiment on the consumer side:
- Month 1 of consumer SEO: single-digit clicks. It looked like nothing was happening, because nothing was.
- Month 2: first meaningful traffic — a jump of more than 10×, still almost no revenue.
- Month 3–4: the orders finally arrived, and they compounded.
Sixteen days in, the API is somewhere around week two of that curve — the stretch where the consumer site was also producing nothing and I had no way to tell a slow start from a dead end. If I’d judged the blog at this point in its life I’d have deleted it. So I’m not concluding that developers don’t want this. I’m saying the sample is too small to conclude anything, and I’m going to keep publishing the number every volume until it either moves or doesn’t.
What I will say is that the API isn’t broken. It has run without an outage, and the same code path that answers POST /v1/orders fulfilled every consumer order we shipped this month. And one working hypothesis I’ll be testing: price was probably never the friction. Weeks of engineering work against an unproven one-person company is. Making the key free doesn’t touch that — a named, working integration might.
The best two weeks we’ve had
I want to be careful here, because founders quoting growth multiples off a tiny base is its own genre and I don’t want to write in it. So here is the plainest version I can give you, in people rather than percentages.
- 36 different people bought an eSIM from us in the last fourteen days. In the fourteen days before that it was 15. Not one customer buying repeatedly — 36 separate human beings who’d never bought from us before.
- The best single day was 11 orders from 11 people. Our normal day, a week earlier, was one or two.
- Organic search and AI assistants are 43% of our sessions but 57% of our orders. Direct traffic is the mirror image — plenty of it, and it barely buys.
And the honest asterisk, because the shape matters as much as the total: it was spiky, not a step change. Nine orders one day, seven the next, then a day with zero, then eleven. I can’t yet tell you what caused the peak — Google’s reporting runs a few days behind, so the search data for our biggest day hasn’t even arrived. Ask me in Vol. 3 whether it was a new floor or a good fortnight.
The number that actually got me, though, wasn’t an order count. It was branded search. People typing yonosim into Google went from zero in June, to two in July, to forty-seven in August — scattered one and two at a time across fifteen countries. That isn’t friends telling friends; a friend group clusters in one place. It’s people who met the brand somewhere and then Googled the name to check we were real before handing over a card.
Which means that for the first time since I started this, strangers on four continents went looking for us on purpose. Forty-seven is a small number and I know it. But it’s a different kind of number than traffic is. Traffic is people who bumped into you. This is people who remembered your name well enough to type it.
Türkiye is the clean worked example. A single country guide ranks, sends traffic, and converts — and Türkiye is simultaneously our number-one source of branded search. Same country, both halves of the funnel, same fortnight. Brand search isn’t a separate channel. It’s the receipt for content that ranked six weeks earlier.
There’s a humbling ratio underneath all of it. We’ve published several hundred posts across four months to get to a few hundred clicks a month, and a small handful of those posts are doing nearly all of the work. The lesson I’m taking isn’t “write more.”
Four vendors knocked. One is being wired in.
The genuinely good news this fortnight came from the supply side rather than the demand side: four different upstream eSIM vendors approached us, and one of them is being onboarded now.
In Vol. 1 I claimed the stack was multi-supplier by design — that every order runs through one provider-agnostic aggregator on our side, so adding an upstream is one adapter rather than a rewrite. This is the first time that claim has had to survive contact with reality, and so far it has: the new upstream is an adapter, and nothing above it had to change.
What it buys, in order of how much I care: no single vendor’s outage can take us down, wider country coverage, more plan shapes to offer, and better economics. I’m not naming the vendor or publishing the margin math while the commercial terms are still being negotiated — that’s a number you can never take back, and it would price every conversation I have after it.
What I’m changing
- Issue the five missing credentials. Or delete those partners from the registry. Claiming nine and shipping four is the kind of thing that happens when you write the code and skip the last mile, and it’s embarrassing precisely because it’s so cheap to fix.
- Write to marketplaces, not just to app developers. The /partners surface has one working case study on it now and it should say so. The /developers pitch stays, but it stops being the only door I describe.
- Stop treating “free and instant” as the answer. The sandbox key is still free and still instant. But nobody integrates infrastructure because it was easy to sign up for — they integrate it because somebody they trust already did. One named, working integration is worth more than removing another form field.
Vol. 3’s number
Vol. 1 said the metric was live-mode integrations. That’s still true, but it was pointed at the wrong segment, so it just printed a zero and told me nothing. The number I’m committing to for Vol. 3 is live marketplace integrations shipping real orders.
Today that number is 1. One is not a channel. Three would be. If it’s still 1 when Vol. 3 goes up, the honest reading isn’t that partners don’t work — it’s that I went back to writing blog posts because blog posts were working, and I should say that out loud rather than dress it up as strategy.
The bigger lesson I’m carrying out of this volume is smaller than it sounds and took me six weeks to learn: you don’t get to choose who your first customers are. You get to notice them.
— Roc · #YouOnlyNeedOneSIM
Common questions
QWho is YonoSIM API actually for?
AHonestly: as of Vol. 2, the segment with evidence is eSIM marketplaces and comparison sites. They consume a price feed, deep-link into our catalog, and earn commission on what converts. The travel-app and hotel-checkout use case the API was designed for is still a hypothesis with zero live integrations behind it. Both doors are open; only one has people walking through it.
QHow does the marketplace partner feed work?
AA registered partner gets a key and calls GET /api/partners/plans and /api/partners/destination-links. Every outbound link is tagged with their slug, so attribution runs on our side without a third-party network. They earn commission on converted orders, and get a per-sale email plus a monthly CSV. No setup fee, ever — see /partners.
QDo you charge a listing or setup fee?
ANo. We were asked for one this month by a marketplace we'd have liked to be on, and we said no. Commission on real conversions or nothing — a fee that gets paid whether or not a single traveler buys is the wrong incentive for both sides.
QHow do I get a sandbox key for the provisioning API?
Ayonosim.com/developers — an sk_test_* key is emailed on signup, no NDA, no card, no call. Fair warning, reported in this volume: nobody outside the company has taken one yet. The endpoints are real and the same code path fulfills our consumer orders, but you would be the first.