The NamoID blog
Practical identity engineering for customer login, scoped agent access, security, and India’s DPDP framework — with product boundaries called out plainly.
Why Consent Screens Fail for AI-Agent Authorization
Agent actions are too frequent and context-dependent for repeated consent prompts. The safer model is policy first, approval by exception, and resumable authorization.
Read articleID-JAG and Cross App Access: Enterprise Delegation Explained
How ID-JAG lets an application obtain an API token through a shared enterprise identity provider—and why it is not an AI-agent identity standard.
How MCP Authorization Converged on OAuth in 18 Months
Trace MCP authorization from no protocol support to protected-resource metadata, audience-bound tokens, CIMD, issuer checks, and extensible OAuth.
OAuth Solved Agent Access. It Hasn't Solved Agent Authority
OAuth can get an AI agent to an API. It cannot yet express task scope, offline attenuation, delegation provenance, or the intent behind an action.
Prompt Injection Proves Identity and Scopes Are Not Enough
A correctly authenticated and authorized AI agent can still leak data. Prompt injection exposes the boundary between identity, authority, and information flow.
Exact Redirect URI Matching: Why One Character Matters
How weak OAuth redirect URI matching leaks authorization codes, why RFC 9700 requires exact strings, and how to validate web, mobile, and loopback callbacks safely.
Custom Authentication Domains: Security, Cookies, and Trust
How to design custom domains for hosted authentication: DNS ownership, TLS, host routing, cookie boundaries, redirect validation, monitoring, and safe decommissioning.
Authentication Data Retention for Indian Startups
Build a defensible authentication-data retention policy under India's DPDP framework, with a practical matrix for users, sessions, OTPs, logs, audit events, waitlists, and backups.
How to Turn Waitlist Applicants into Early-Access Users
A practical early-access lifecycle for startups: verify applicants, approve the right cohort, activate access reliably, measure adoption, and learn without spamming users.
Phone OTP for India: DLT, Cost, and Fallback Planning
A production guide to SMS OTP in India: TRAI DLT registration, AWS local routes, real cost modelling, delivery controls, abuse prevention, and secure fallbacks.