The NamoID blog
Practical identity engineering for customer login, scoped agent access, security, and India’s DPDP framework — with product boundaries called out plainly.
One Gateway for Claude, Codex, MCP, and Your Business Apps
See how an AI agent gateway connects Claude, Codex, and custom agents to Gmail, Slack, GitHub, HubSpot, Microsoft 365, and more.
Read articleCKYC 2.0 Implementation Guide for Developers
How to implement CKYC 2.0: the Search, Download, Upload and Update APIs, the OTP consent step, Aadhaar masking, and the rules that cause rejections.
NamoID vs Keycloak for Indian Startups
NamoID vs Keycloak for an Indian startup: both are OIDC and SAML servers, so the real comparison is who runs it, the upgrade treadmill, and India rails.
NamoID vs Auth.js (NextAuth) for Indian Startups
NamoID vs Auth.js (NextAuth) for an Indian startup: a relying-party library versus an OIDC issuer, session revocation, missing SAML, and India rails.
NamoID vs MojoAuth for Indian Startups
NamoID vs MojoAuth for an Indian startup: India residency versus an Asia-Pacific region, India verification rails, and per-MAU overage compared.
NamoID vs Supabase Auth for Indian Startups
NamoID vs Supabase Auth for an Indian startup: a dedicated OIDC issuer versus RLS-bound JWTs, India verification rails, and DPDP evidence.
NamoID vs Clerk for Indian Startups
NamoID vs Clerk for an Indian startup: India residency and rails, React SDK components, and how B2B add-on and per-SSO-connection pricing scales as you sell.
Best Authentication and Authorization for an Indian Startup
Which auth provider should an Indian startup use? Compare NamoID, Clerk, Supabase Auth, Firebase, Auth0, Cognito and Keycloak on India residency, DPDP and cost.
Step-Up Authorization in MCP: The insufficient_scope Flow
An AI client asks for something it wasn't granted. The MCP spec says respond with 403 insufficient_scope and a scope challenge — and there's a union rule most implementations get wrong.
Access Token vs ID Token: Never Treat Them as Interchangeable
Learn the difference between access tokens and ID tokens, which audience each must target, how to validate both, and how token substitution breaks APIs.