NamoID public betaBuilding customer authentication? Get setup help and share feedback with other builders.Join the Slack community
NamoID
From the team

The NamoID blog

Practical identity engineering for customer login, scoped agent access, security, and India’s DPDP framework — with product boundaries called out plainly.

Why Consent Screens Fail for AI-Agent Authorization — NamoID
Deep dive5 min read

Why Consent Screens Fail for AI-Agent Authorization

Agent actions are too frequent and context-dependent for repeated consent prompts. The safer model is policy first, approval by exception, and resumable authorization.

The NamoID TeamDeep dive
Read article
ID-JAG and Cross App Access: Enterprise Delegation Explained — NamoID
Deep dive5 min read

ID-JAG and Cross App Access: Enterprise Delegation Explained

How ID-JAG lets an application obtain an API token through a shared enterprise identity provider—and why it is not an AI-agent identity standard.

The NamoID TeamDeep dive
How MCP Authorization Converged on OAuth in 18 Months — NamoID
Deep dive5 min read

How MCP Authorization Converged on OAuth in 18 Months

Trace MCP authorization from no protocol support to protected-resource metadata, audience-bound tokens, CIMD, issuer checks, and extensible OAuth.

The NamoID TeamDeep dive
OAuth Solved Agent Access. It Hasn't Solved Agent Authority — NamoID
Deep dive10 min read

OAuth Solved Agent Access. It Hasn't Solved Agent Authority

OAuth can get an AI agent to an API. It cannot yet express task scope, offline attenuation, delegation provenance, or the intent behind an action.

The NamoID TeamDeep dive
Prompt Injection Proves Identity and Scopes Are Not Enough — NamoID
Deep dive6 min read

Prompt Injection Proves Identity and Scopes Are Not Enough

A correctly authenticated and authorized AI agent can still leak data. Prompt injection exposes the boundary between identity, authority, and information flow.

The NamoID TeamDeep dive
Exact Redirect URI Matching: Why One Character Matters — NamoID
Security8 min read

Exact Redirect URI Matching: Why One Character Matters

How weak OAuth redirect URI matching leaks authorization codes, why RFC 9700 requires exact strings, and how to validate web, mobile, and loopback callbacks safely.

The NamoID TeamSecurity
Custom Authentication Domains: Security, Cookies, and Trust — NamoID
Security8 min read

Custom Authentication Domains: Security, Cookies, and Trust

How to design custom domains for hosted authentication: DNS ownership, TLS, host routing, cookie boundaries, redirect validation, monitoring, and safe decommissioning.

The NamoID TeamSecurity
Authentication Data Retention for Indian Startups — NamoID
Compliance9 min read

Authentication Data Retention for Indian Startups

Build a defensible authentication-data retention policy under India's DPDP framework, with a practical matrix for users, sessions, OTPs, logs, audit events, waitlists, and backups.

The NamoID TeamCompliance
How to Turn Waitlist Applicants into Early-Access Users — NamoID
Product7 min read

How to Turn Waitlist Applicants into Early-Access Users

A practical early-access lifecycle for startups: verify applicants, approve the right cohort, activate access reliably, measure adoption, and learn without spamming users.

The NamoID TeamProduct
Phone OTP for India: DLT, Cost, and Fallback Planning — NamoID
Compliance7 min read

Phone OTP for India: DLT, Cost, and Fallback Planning

A production guide to SMS OTP in India: TRAI DLT registration, AWS local routes, real cost modelling, delivery controls, abuse prevention, and secure fallbacks.

The NamoID TeamCompliance