# CIAM Compass > Vendor-neutral knowledge portal for Customer Identity & Access Management. Vendor-neutral knowledge portal for Customer Identity & Access Management. Every entry (vendor profile, comparison, guide, glossary term) is hand-curated by Deepak Gupta (founded LoginRadius in 2014, left 2023; founded Start with Identity in 2026, an independent open IAM and security community at startwithidentity.com) and dated. No affiliate links, no vendor sponsorships. ## About the author - [Deepak Gupta](https://guptadeepak.com/about/): Founded LoginRadius (2014, 1B+ users; left 2023); founded [Start with Identity](https://startwithidentity.com) in 2026, an independent, open community for security and IAM professionals; patents in identity; long-form essays at guptadeepak.com. ## Start here - [CIAM Compass home](https://guptadeepak.com/ciam-compass/): What CIAM is, and the 2026 ranking by job. Last verified 19 August 2026. - [Best CIAM vendors 2026](https://guptadeepak.com/ciam-compass/guides/best-ciam-vendors-2026/): Shortlist by job. No aggregate score. - [Capability matrix](https://guptadeepak.com/ciam-compass/matrix/): Dated dataset, CSV and JSON, citation text. - [Methodology](https://guptadeepak.com/ciam-compass/methodology/): How vendors are scored and what "vendor-neutral" means in practice here. - [Contributors](https://guptadeepak.com/ciam-compass/contributors/): Who reviews changes and how to suggest one. ## Pillar guides - [Account Recovery Design: The Most-Attacked Flow in CIAM](https://guptadeepak.com/ciam-compass/guides/account-recovery-design/): The recovery flow is the security floor of the entire auth system. Email magic link on a passkey-secured account is, structurally, an email-secured account. Design recovery deliberately. - [Account Takeover Defense: A Layered Approach for 2026](https://guptadeepak.com/ciam-compass/guides/account-takeover-defense/): ATO is the single largest CIAM threat in 2026. The defense stack is layered, credential stuffing protection, MFA, session management, and recovery design, each addressing a different attack class. - [Adaptive Risk-Based Authentication: Decisioning at Login](https://guptadeepak.com/ciam-compass/guides/adaptive-risk-based-authentication/): Adaptive auth scores each login against risk signals, device, geo, velocity, behavior, and challenges only when the score warrants. Patterns and where vendors diverge. - [AI Agent Identity and MCP: Authenticating Non-Human Identities](https://guptadeepak.com/ciam-compass/guides/ai-agent-identity-mcp/): How CIAM evolves for AI agents in 2026: MCP, OAuth 2.1 Dynamic Client Registration, scoped agent tokens, and patterns separating agent from human identity. - [API Authorization Patterns: A 2026 Practitioner's Guide](https://guptadeepak.com/ciam-compass/guides/api-authorization-patterns/): How to authorize API requests in modern CIAM. Bearer tokens, scopes, OAuth 2.1 client patterns, machine-to-machine, and where the architectural lines fall. - [Auth.js vs CIAM: When a Next.js Library Is Enough](https://guptadeepak.com/ciam-compass/guides/auth-js-vs-ciam/): Auth.js (NextAuth) is a library, not a CIAM platform. When the library is enough, when Better Auth is the 2026 pick, and when you should buy Auth0, Clerk, or SuperTokens instead. - [Authentication for AI Agents: OAuth Patterns for Non-Human Identity](https://guptadeepak.com/ciam-compass/guides/authentication-for-ai-agents/): How AI agents authenticate in 2026. The on-behalf-of pattern, delegated agent identity, OAuth 2.1 Dynamic Client Registration, and where the patterns are still being invented. - [B2B SaaS Identity: Organizations, SSO, SCIM, and the Enterprise Sales Checklist](https://guptadeepak.com/ciam-compass/guides/b2b-saas-identity/): How to design B2B SaaS identity: Organizations, Enterprise SSO with SAML and OIDC, SCIM provisioning, audit logs, and the IT-admin features that close enterprise deals. - [Best CIAM Vendors in 2026, Ranked by Job to Be Done](https://guptadeepak.com/ciam-compass/guides/best-ciam-vendors-2026/): A dated, vendor-neutral 2026 shortlist: MojoAuth for native passkeys, SSOJet for enterprise SSO pricing, Descope for orchestration, Clerk for Next.js and Node. No aggregate score. - [Biometric Authentication: A Practitioner's Guide to Fingerprint, Face, and Beyond](https://guptadeepak.com/ciam-compass/guides/biometric-authentication-guide/): How modern biometric authentication actually works — device-local templates, signed assertions, liveness detection, and where the privacy story is real vs marketing. - [Bot Defense and Fraud Detection for Authentication Endpoints](https://guptadeepak.com/ciam-compass/guides/bot-defense/): Credential-stuffing bots, account-creation bots, scrapers, MFA-fatigue bots — the modern auth endpoint faces continuous automated attack. The defenses that hold and the ones that don't. - [Build vs Buy CIAM: A 2026 Framework for the Decision](https://guptadeepak.com/ciam-compass/guides/build-vs-buy-ciam/): When building CIAM in-house makes sense in 2026, when it doesn't, and the realistic cost comparison most teams underestimate. - [CCPA and CIAM: California Privacy Compliance for Consumer Apps](https://guptadeepak.com/ciam-compass/guides/ccpa-and-ciam/): How CCPA / CPRA intersects with CIAM, opt-out, sale-of-data, consumer rights, and the architectural choices that satisfy California compliance. - [Choosing a CIAM Vendor: The Key Concepts Developers and Security Teams Check](https://guptadeepak.com/ciam-compass/guides/choosing-a-ciam-vendor-key-concepts/): The rubric behind a CIAM decision: standards, tokens, authentication, authorization, tenancy, extensibility, security posture, residency, cost, lock-in, and agentic identity, plus where to check each. - [CIAM at High Scale: The Platforms Built for It](https://guptadeepak.com/ciam-compass/guides/ciam-at-high-scale/): What high scale demands from CIAM (MAU ceiling, throughput, multi-region, the cost curve past 1M MAU) and the families that deliver it: hyperscaler-native, enterprise, modern B2C, self-hosted. - [How to Migrate Between CIAM Platforms: A Vendor-Agnostic Framework](https://guptadeepak.com/ciam-compass/guides/ciam-migration-framework/): A vendor-neutral framework for CIAM migration: what actually migrates and what does not, the five-phase playbook, how to choose a destination by what you are escaping, and how security teams evaluate the move. - [CIAM Pricing at 100k and 1M MAU in 2026](https://guptadeepak.com/ciam-compass/guides/ciam-pricing-at-scale-2026/): Editorial TCO bands for major CIAM vendors at 100k and 1M MAU, using Compass standard assumptions. Quote-only vendors called out. Dated 19 August 2026, no vendor money. - [CIAM Pricing Models: MAU, MTU, and the Cost Traps That Bite at Renewal](https://guptadeepak.com/ciam-compass/guides/ciam-pricing-models/): Per-MAU pricing looks cheap until you scale. MTU pricing looks predictable until the definition shifts. Each CIAM pricing model hides a different cost trap — modeled honestly for buyers. - [CIAM Reference Architectures: Four Patterns and the Vendors That Fit](https://guptadeepak.com/ciam-compass/guides/ciam-reference-architectures/): Four production CIAM patterns: B2C mobile-first, B2B multi-tenant with SSO and SCIM, hybrid B2B2C, and regulated or self-hosted, with the capabilities and failure modes that define each. - [CIAM vs IAM vs IDaaS: Definitions and Where the Lines Blur](https://guptadeepak.com/ciam-compass/guides/ciam-vs-iam-vs-idaas/): What separates Customer Identity from Workforce Identity from Identity-as-a-Service. The terminology that actually matters in 2026 and why the categories overlap more every year. - [Consent Management Platforms (CMPs) and CIAM: Where the Lines Fall](https://guptadeepak.com/ciam-compass/guides/consent-management-cmps/): How CMPs (OneTrust, TrustArc, Cookiebot) compose with CIAM. The architectural seam, when each handles what, and the integration patterns that work. - [Customer Onboarding and Progressive Profiling: The Conversion-Aware CIAM Pattern](https://guptadeepak.com/ciam-compass/guides/customer-onboarding-progressive-profiling/): Every field at signup costs conversion. Progressive profiling defers data collection to the moment of contextual need — better UX, better data quality, better GDPR posture, all at once. - [Data Residency and Sovereignty in CIAM: Where Your Auth Data Lives](https://guptadeepak.com/ciam-compass/guides/data-residency-and-sovereignty/): How data residency requirements shape CIAM choice, EU sovereignty, regional data laws, government-cloud constraints, and the vendors that handle each. - [DDoS and Rate-Limiting for Authentication Endpoints](https://guptadeepak.com/ciam-compass/guides/ddos-rate-limiting-auth/): Login endpoints are the highest-leverage target for volumetric attacks — small request size, large server cost, identity-system disruption. The composite defense pattern that scales. - [Decentralized Identity and Verifiable Credentials: What CIAM Teams Should Know](https://guptadeepak.com/ciam-compass/guides/decentralized-identity-for-ciam/): EUDI Wallet rolls out in 2026. US mDL adoption is uneven but real. DID and VC are no longer research projects. The CIAM-side impact, and when to start integrating. - [Enterprise SSO: SAML vs OIDC, and How to Pick](https://guptadeepak.com/ciam-compass/guides/enterprise-sso-saml-vs-oidc/): SAML and OIDC are the two protocols that dominate enterprise SSO. A practical comparison, when each is the right answer, and the IdP-side considerations that determine the choice. - [FIDO2 Explained: CTAP2, WebAuthn, and Where Security Keys Still Win](https://guptadeepak.com/ciam-compass/guides/fido2-explained/): FIDO2 is the umbrella for WebAuthn (browser API) plus CTAP2 (the authenticator protocol). How the pieces fit, when to require security keys, and how passkeys changed the deployment model. - [Fine-Grained Authorization (FGA): A 2026 Implementation Guide](https://guptadeepak.com/ciam-compass/guides/fine-grained-authorization-fga/): FGA is the umbrella for per-resource permissions at scale. The Zanzibar model, the production implementations (OpenFGA, SpiceDB, Permify, Keto), and how to choose. - [GDPR and CIAM: A Practical Compliance Guide](https://guptadeepak.com/ciam-compass/guides/gdpr-and-ciam/): How CIAM platforms intersect with GDPR, lawful basis, consent, data minimization, subject rights, and the architectural choices that make compliance maintainable. - [HIPAA and CIAM: The Healthcare Identity Compliance Checklist for 2026](https://guptadeepak.com/ciam-compass/guides/hipaa-and-ciam/): HIPAA's Security Rule constrains how CIAM handles healthcare identity. The technical safeguards, the auditor's checklist, and vendor-selection implications for 2026. - [Identity Verification and Proofing (IDV/KYC): A CIAM Guide for 2026](https://guptadeepak.com/ciam-compass/guides/identity-verification-kyc/): How to prove a real person matches a claimed identity at signup — document capture, liveness, authoritative-data checks. The 2026 stack, the deepfake escalation, and where CIAM ends. - [Inbound vs Outbound SSO: How Federation Actually Works](https://guptadeepak.com/ciam-compass/guides/inbound-vs-outbound-sso/): The direction that trips teams up: inbound SSO (your app accepts a customer's IdP) vs outbound SSO (your app is the IdP). The flows, per-tenant setup, and security checks that matter. - [ITDR: Identity Threat Detection and Response in CIAM](https://guptadeepak.com/ciam-compass/guides/itdr-identity-threat-detection-response/): What ITDR means in 2026, how it differs from traditional auth analytics, and where CIAM platforms and dedicated ITDR tools fit in the security stack. - [JWT Explained: JSON Web Tokens, JWT Authentication, and the Pitfalls](https://guptadeepak.com/ciam-compass/guides/jwt-explained/): JWT (JSON Web Token) is the dominant signed-token format for authentication and API authorization. How JWT tokens are structured, how JWT authentication works in OAuth 2.0 / OIDC, which algorithms to pin, and the recurring vulnerability classes that keep biting implementers. - [Magic Links vs OTP: Picking the Passwordless Fallback](https://guptadeepak.com/ciam-compass/guides/magic-links-vs-otp/): Magic links and OTP (email, SMS) are the two common passwordless fallbacks. A practical comparison: deliverability, security, UX, and when each is the right choice. - [Migrating Off Auth0: A Practitioner's Guide for 2026](https://guptadeepak.com/ciam-compass/guides/migrating-from-auth0/): Why teams migrate off Auth0, where they go, and the 60–90 day playbook for executing the migration without locking out users or breaking integrations. - [Migrating from AWS Cognito: A 2026 Practitioner's Guide](https://guptadeepak.com/ciam-compass/guides/migrating-from-cognito/): Why teams migrate off AWS Cognito in 2026, the realistic paths to Auth0, Stytch, MojoAuth, Clerk, or self-hosted, and the migration mechanics that matter. - [mTLS Explained: Mutual TLS for Service Identity and API Authentication](https://guptadeepak.com/ciam-compass/guides/mtls-explained/): Mutual TLS authenticates both sides of the connection. How it works for service-to-service, where SPIFFE/SPIRE fits, and the cert-management pitfalls that bite. - [Multi-Factor Authentication (MFA): A 2026 Practitioner's Guide](https://guptadeepak.com/ciam-compass/guides/multi-factor-authentication-mfa/): How to roll out MFA in CIAM in 2026: factor selection, adoption, recovery design, anti-patterns, and where SMS OTP no longer meets the standard. - [Multi-Region CIAM: Data Residency, Latency, and Availability](https://guptadeepak.com/ciam-compass/guides/multi-region-ciam/): Why multi-region CIAM matters (residency law, latency, availability), the architecture patterns (active-active, regional isolation, data pinning), and what to verify in a vendor before you commit. - [Multi-Tenant Architecture for CIAM: Patterns and Trade-offs](https://guptadeepak.com/ciam-compass/guides/multi-tenant-architecture/): How to design CIAM for multi-tenant B2B SaaS in 2026. Tenant isolation models, data partitioning, per-tenant configuration, and the architectural choices that determine scale ceilings. - [OAuth 2.1 Explained: What Changed and Why It Matters](https://guptadeepak.com/ciam-compass/guides/oauth-2-1-explained/): OAuth 2.1 consolidates fifteen years of OAuth 2.0 practice into a single coherent specification. What it deprecates, what it requires, and how to migrate existing OAuth 2.0 code. - [OpenID Connect (OIDC) Explained: The Modern Identity Layer on OAuth 2.0](https://guptadeepak.com/ciam-compass/guides/oidc-explained/): OIDC adds authentication and identity claims to OAuth 2.0. How discovery, ID tokens, and the standard scopes work, plus the pitfalls that bite implementers in production. - [Okta CIAM vs Auth0 vs Workforce: Which Product You Actually Need](https://guptadeepak.com/ciam-compass/guides/okta-ciam/): Okta is two products. Workforce Identity Cloud is employee IAM. Auth0 is Okta Customer Identity Cloud. Searching 'Okta CIAM' without that split wastes a quarter. - [Organizations and Tenants in B2B CIAM: Modeling Customer Boundaries](https://guptadeepak.com/ciam-compass/guides/organizations-and-tenants/): How modern B2B CIAM model the customer-Organization boundary, why per-Org config matters, and the pitfalls of treating tenants as a database concern alone. - [Passkey Orchestration Ranking 2026: Who Actually Gets Adoption](https://guptadeepak.com/ciam-compass/guides/passkey-orchestration-vendors-2026/): WebAuthn support is table stakes. Orchestration is not. A 2026 ranking of which CIAM vendors get passkey adoption above a 5–10% stall. - [Passkey Overlays vs CIAM: Corbado, Hanko, Passage, OwnID](https://guptadeepak.com/ciam-compass/guides/passkey-overlays-vs-ciam/): When a passkey overlay (Corbado, Hanko, Passage by 1Password, OwnID, Authsignal) is the right 2026 move, and when you should change CIAM instead. Dated, vendor-neutral. - [Passkeys Explained: How Synced Credentials Replace Passwords](https://guptadeepak.com/ciam-compass/guides/passkeys-explained/): Passkeys are the user-facing brand for synced WebAuthn credentials. A practical explanation of how they work, sync, recovery, and the deployment patterns that make adoption real. - [Password Security and Storage: Hashing, Salting, and What Actually Works in 2026](https://guptadeepak.com/ciam-compass/guides/password-security-and-storage/): Passwords still exist, and storing them correctly still matters. The 2026 production-grade answer: Argon2id with per-user salt, optional pepper, no fast hashes, no reversible encryption. - [Passwordless Authentication: A 2026 Practitioner's Guide](https://guptadeepak.com/ciam-compass/guides/passwordless-authentication/): How passkeys, magic links, and biometrics replace passwords in CIAM, with implementation patterns, adoption data, and vendor support. - [PCI DSS 4.0 and CIAM: Identity Requirements for Payment Workloads](https://guptadeepak.com/ciam-compass/guides/pci-dss-and-ciam/): PCI DSS 4.0's Requirements 7, 8, and 10 directly constrain CIAM design for any system handling cardholder data. MFA, audit logs, role separation, and the gotchas that fail QSA audits. - [Post-Quantum Cryptography for Authentication: What CIAM Teams Should Do in 2026](https://guptadeepak.com/ciam-compass/guides/post-quantum-cryptography-for-auth/): When post-quantum cryptography matters for authentication, what NIST has standardized, and the realistic CIAM migration path through 2030. - [RBAC vs ABAC vs ReBAC: Choosing an Authorization Model](https://guptadeepak.com/ciam-compass/guides/rbac-vs-abac-vs-rebac/): Three authorization models, Role-Based, Attribute-Based, and Relationship-Based Access Control, with concrete examples, scaling characteristics, and when each is the right answer. - [The ROI of Passwordless Authentication: A CFO-Ready Business Case](https://guptadeepak.com/ciam-compass/guides/roi-of-passwordless/): Passwordless authentication pays back through three measurable lines: help-desk ticket reduction, breach-probability reduction, and conversion lift. The numbers are unflattering to passwords. - [SAML 2.0 Explained: The Enterprise SSO Standard, 20 Years In](https://guptadeepak.com/ciam-compass/guides/saml-2-0-explained/): SAML 2.0 still dominates enterprise SSO install base in 2026. How the protocol actually works, the bindings, profiles, the metadata exchange, and the security pitfalls that keep biting implementers. - [SCIM Provisioning: A B2B SaaS Practitioner's Guide](https://guptadeepak.com/ciam-compass/guides/scim-provisioning/): SCIM 2.0 is the standard protocol for automated user provisioning between IdPs and SaaS apps. How it works, why it matters at 1000-seat scale, and what production deployments need. - [Session Management: JWTs vs Opaque Tokens, and How to Pick](https://guptadeepak.com/ciam-compass/guides/session-management-jwts-vs-opaque-tokens/): JWT-based and opaque-token sessions trade off scale against revocability, the 2026 default is hybrid. Patterns, revocation, and where each is the right answer. - [Deprecating SMS OTP in 2026: Why, When, and How](https://guptadeepak.com/ciam-compass/guides/sms-otp-deprecation-2026/): NIST SP 800-63-4 places SMS OTP outside AAL2. The 2026 question is how to migrate the install base off SMS, what to replace it with, in what order, and the patterns that work. - [SOC 2 and CIAM: What Auditors Actually Look at in the Identity Section](https://guptadeepak.com/ciam-compass/guides/soc2-and-ciam/): SOC 2 doesn't prescribe CIAM features, but Type II auditors expect specific controls — MFA, access reviews, audit logs, deprovisioning evidence. The checklist that closes the audit cleanly. - [Social Login: Implementation, Trade-offs, and the Privacy Cost](https://guptadeepak.com/ciam-compass/guides/social-login/): Sign in with Google, Apple, Microsoft, Facebook, GitHub — conversion lift is real, lock-in is real, privacy cost is real. The 2026 decision is not whether but which providers to support. - [Start Here: How to Choose a CIAM Platform (A Guided Path)](https://guptadeepak.com/ciam-compass/guides/start-here-choosing-ciam/): A first-principles path for choosing CIAM: figure out your identity shape, settle build vs buy, fix your hard constraints, weigh cost at scale, then narrow to a shortlist. - [The True Cost of a CIAM Breach: Downside Modeling for Identity Incidents](https://guptadeepak.com/ciam-compass/guides/true-cost-of-ciam-breach/): A CIAM breach is rarely 'just' a breach. Direct response, regulatory exposure, customer churn, and brand damage compound for years — modeled honestly for finance and security leaders. - [WebAuthn Explained: How Passkeys Work Under the Hood](https://guptadeepak.com/ciam-compass/guides/webauthn-explained/): WebAuthn is the W3C browser API that powers passkeys. A practical explanation of registration, assertion, RP-IDs, attestation, and the architecture choices that determine adoption. - [What Is CIAM? The Complete Guide to Customer Identity and Access Management](https://guptadeepak.com/ciam-compass/guides/what-is-ciam/): CIAM is the production system that handles registration, login, MFA, profile, consent, and provisioning for the customers of your application — distinct from workforce IAM, which handles employees. - [WorkOS vs Auth0 vs Clerk in 2026: Which CIAM for B2B SaaS](https://guptadeepak.com/ciam-compass/guides/workos-vs-auth0-vs-clerk/): A vendor-neutral three-way for the 2026 B2B SaaS auth decision. WorkOS for SSO and SCIM, Clerk for Next.js speed, Auth0 when you need the whole surface. Dated 19 August 2026. - [Google Zanzibar Explained: The Authorization Model Behind Modern FGA](https://guptadeepak.com/ciam-compass/guides/zanzibar-explained/): How Google Zanzibar's relationship-based authorization model works, why it scaled to billions of objects, and which open-source and managed implementations carry the design forward. ## All guides - [Authentication vs Authorization: The Difference, Explained Properly](https://guptadeepak.com/ciam-compass/guides/authentication-vs-authorization/): Authentication answers 'who are you'; authorization answers 'what may you do'. The split is structural, the confusion is endless, and the integration bugs hide in the gap. - [Authorization Patterns for Agentic Workflows: Delegation, Constraints, and Just-in-Time Permissions](https://guptadeepak.com/ciam-compass/guides/authorization-patterns-for-agentic-workflows/): AI agents need authorization models that handle delegated permissions, multi-step workflows, and least-privilege at machine speed. The patterns that work and the ones being invented. - [MCP Server Identity Model: Authentication, Authorization, and Trust for the Model Context Protocol](https://guptadeepak.com/ciam-compass/guides/mcp-server-identity-model/): Model Context Protocol is OAuth 2.1 with discovery. How MCP servers register, authenticate clients, scope access, and where the protocol leaves identity questions to the implementer. - [MFA vs 2FA: Are They the Same Thing?](https://guptadeepak.com/ciam-compass/guides/mfa-vs-2fa/): 2FA is two factors. MFA is two or more. The terms are often used interchangeably, and that's mostly fine — but the security-meaningful difference is in the factor quality, not the count. - [PASETO Explained: The JWT Alternative That Removes the Footguns](https://guptadeepak.com/ciam-compass/guides/paseto-explained/): PASETO is a signed-token format designed to be safe by default. How it differs from JWT, what it gives up, and when its smaller surface area justifies switching. - [Passkeys in Next.js: A CIAM Recipe for App Router](https://guptadeepak.com/ciam-compass/guides/passkeys-in-nextjs/): A copy-paste path for passkeys on Next.js App Router: WebAuthn via a CIAM vendor, conditional UI, RP-ID, and recovery. Not a from-scratch crypto tutorial. - [Passkeys vs Passwords: The 2026 Migration Decision](https://guptadeepak.com/ciam-compass/guides/passkeys-vs-passwords/): Passwords are the inherited primitive; passkeys are the modern replacement. The decision isn't whether to switch, it's how to stage the migration without breaking the long tail of existing users. - [Password Manager vs Passwordless: Two Genuinely Different Paths Past the Password](https://guptadeepak.com/ciam-compass/guides/password-manager-vs-passwordless/): Password managers keep passwords; they just keep them well. Passwordless eliminates the password as a primitive. Both improve over typed passwords; the migration paths diverge. - [SAML SSO for Multi-Tenant SaaS: A CIAM Recipe](https://guptadeepak.com/ciam-compass/guides/saml-sso-multi-tenant-saas/): How to add per-customer SAML SSO to a multi-tenant SaaS without turning every enterprise deal into a custom IdP project. SP vs IdP, tenant mapping, and when to buy WorkOS. - [SCIM vs SAML: Provisioning vs Authentication, and Why You Need Both](https://guptadeepak.com/ciam-compass/guides/scim-vs-saml/): SAML authenticates users at login. SCIM provisions and deprovisions them in the background. They solve different problems, and enterprise B2B SaaS needs both — the confusion costs deals. - [SSO vs Federation: One Login Across Apps, or One Identity Across Domains](https://guptadeepak.com/ciam-compass/guides/sso-vs-federation/): SSO is a user experience — one login unlocks many apps. Federation is the protocol mechanism that trusts another organization's identity assertions. SSO uses federation; they aren't the same. - [Symmetric vs Asymmetric Encryption: When to Use Each, and Why Production Systems Use Both](https://guptadeepak.com/ciam-compass/guides/symmetric-vs-asymmetric-encryption/): Symmetric encryption uses one shared secret; asymmetric uses a key pair. Symmetric is 1000× faster; asymmetric solves key distribution. Modern systems hybridize — and that's where bugs live. - [Token Lifetime Best Practices: Access, Refresh, ID, and Session Tokens in 2026](https://guptadeepak.com/ciam-compass/guides/token-lifetime-best-practices/): How to set access, refresh, ID, and session token lifetimes for CIAM in 2026, the trade-offs, the defaults that work, and the patterns that fail in production. - [Token Management for AI Agents: Lifetimes, Rotation, and Revocation at Machine Speed](https://guptadeepak.com/ciam-compass/guides/token-management-for-ai-agents/): Agent tokens are stolen faster and used harder than human tokens. How to set lifetimes, rotate refresh tokens, scope per-tool, and detect anomalies in production agent deployments. - [TOTP vs SMS OTP: And Why One Is Being Deprecated](https://guptadeepak.com/ciam-compass/guides/totp-vs-sms-otp/): TOTP and SMS OTP look identical to the user — a six-digit code — but the security models differ sharply. NIST removed SMS from AAL2 in 2024; TOTP remains acceptable. Migration matters. - [WebAuthn Level 3: What CIAM Teams Should Ship](https://guptadeepak.com/ciam-compass/guides/webauthn-level-3/): WebAuthn Level 3 was proposed as a W3C Recommendation on 20 July 2026. PRF, related origins, Signal API, and conditional create change the CIAM passkey checklist. ## Vendors 48 vendor profiles, dated with `last_verified`. Status is one of active / acquired / deprecated / open-source. - [Akamai Identity Cloud (deprecated)](https://guptadeepak.com/ciam-compass/vendors/akamai-identity-cloud/) - [Auth0 (active)](https://guptadeepak.com/ciam-compass/vendors/auth0/) - [Authelia (open-source)](https://guptadeepak.com/ciam-compass/vendors/authelia/) - [Authentik (open-source)](https://guptadeepak.com/ciam-compass/vendors/authentik/) - [Authress (active)](https://guptadeepak.com/ciam-compass/vendors/authress/) - [Authsignal (active)](https://guptadeepak.com/ciam-compass/vendors/authsignal/) - [BetterAuth (open-source)](https://guptadeepak.com/ciam-compass/vendors/betterauth/) - [Beyond Identity (active)](https://guptadeepak.com/ciam-compass/vendors/beyond-identity/) - [Casdoor (open-source)](https://guptadeepak.com/ciam-compass/vendors/casdoor/) - [Clerk (active)](https://guptadeepak.com/ciam-compass/vendors/clerk/) - [Amazon Cognito (active)](https://guptadeepak.com/ciam-compass/vendors/cognito/) - [Corbado (active)](https://guptadeepak.com/ciam-compass/vendors/corbado/) - [Curity (active)](https://guptadeepak.com/ciam-compass/vendors/curity/) - [CyberArk Identity (active)](https://guptadeepak.com/ciam-compass/vendors/cyberark-customer-identity/) - [Descope (active)](https://guptadeepak.com/ciam-compass/vendors/descope/) - [Microsoft Entra External ID (active)](https://guptadeepak.com/ciam-compass/vendors/entra-external-id/) - [Firebase Authentication (active)](https://guptadeepak.com/ciam-compass/vendors/firebase-auth/) - [ForgeRock (acquired)](https://guptadeepak.com/ciam-compass/vendors/forgerock/) - [Frontegg (active)](https://guptadeepak.com/ciam-compass/vendors/frontegg/) - [FusionAuth (active)](https://guptadeepak.com/ciam-compass/vendors/fusionauth/) - [Hanko (active)](https://guptadeepak.com/ciam-compass/vendors/hanko/) - [IBM Verify (active)](https://guptadeepak.com/ciam-compass/vendors/ibm-security-verify/) - [Keycloak (open-source)](https://guptadeepak.com/ciam-compass/vendors/keycloak/) - [Kinde (active)](https://guptadeepak.com/ciam-compass/vendors/kinde/) - [LoginRadius (active)](https://guptadeepak.com/ciam-compass/vendors/loginradius/) - [Logto (active)](https://guptadeepak.com/ciam-compass/vendors/logto/) - [miniOrange (active)](https://guptadeepak.com/ciam-compass/vendors/miniorange/) - [MojoAuth (active)](https://guptadeepak.com/ciam-compass/vendors/mojoauth/) - [Oracle IAM Identity Domains (active)](https://guptadeepak.com/ciam-compass/vendors/oracle-idcs/) - [Ory (active)](https://guptadeepak.com/ciam-compass/vendors/ory/) - [Ping Identity (active)](https://guptadeepak.com/ciam-compass/vendors/ping-identity/) - [PropelAuth (active)](https://guptadeepak.com/ciam-compass/vendors/propelauth/) - [Rownd (active)](https://guptadeepak.com/ciam-compass/vendors/rownd/) - [SAP Customer Data Cloud (active)](https://guptadeepak.com/ciam-compass/vendors/sap-customer-data-cloud/) - [Scalekit (active)](https://guptadeepak.com/ciam-compass/vendors/scalekit/) - [SlashID (active)](https://guptadeepak.com/ciam-compass/vendors/slashid/) - [SSOJet (active)](https://guptadeepak.com/ciam-compass/vendors/ssojet/) - [Stack Auth (active)](https://guptadeepak.com/ciam-compass/vendors/stack-auth/) - [Strivacity (active)](https://guptadeepak.com/ciam-compass/vendors/strivacity/) - [Stytch (acquired)](https://guptadeepak.com/ciam-compass/vendors/stytch/) - [Supabase Auth (active)](https://guptadeepak.com/ciam-compass/vendors/supabase-auth/) - [SuperTokens (active)](https://guptadeepak.com/ciam-compass/vendors/supertokens/) - [Tesseral (active)](https://guptadeepak.com/ciam-compass/vendors/tesseral/) - [Transmit Security (active)](https://guptadeepak.com/ciam-compass/vendors/transmit-security/) - [WorkOS (active)](https://guptadeepak.com/ciam-compass/vendors/workos/) - [Wristband (active)](https://guptadeepak.com/ciam-compass/vendors/wristband/) - [WSO2 Identity Server (active)](https://guptadeepak.com/ciam-compass/vendors/wso2-is/) - [Zitadel (active)](https://guptadeepak.com/ciam-compass/vendors/zitadel/) ## Vendor comparisons - [Auth0 vs Akamai Identity Cloud](https://guptadeepak.com/ciam-compass/compare/auth0-vs-akamai-identity-cloud/) - [Auth0 vs Authentik](https://guptadeepak.com/ciam-compass/compare/auth0-vs-authentik/) - [Auth0 vs Authress](https://guptadeepak.com/ciam-compass/compare/auth0-vs-authress/) - [Auth0 vs BetterAuth](https://guptadeepak.com/ciam-compass/compare/auth0-vs-betterauth/) - [Auth0 vs Beyond Identity](https://guptadeepak.com/ciam-compass/compare/auth0-vs-beyond-identity/) - [Auth0 vs Clerk](https://guptadeepak.com/ciam-compass/compare/auth0-vs-clerk/) - [Auth0 vs Amazon Cognito](https://guptadeepak.com/ciam-compass/compare/auth0-vs-cognito/) - [Auth0 vs Curity](https://guptadeepak.com/ciam-compass/compare/auth0-vs-curity/) - [Auth0 vs CyberArk Identity](https://guptadeepak.com/ciam-compass/compare/auth0-vs-cyberark-customer-identity/) - [Auth0 vs Descope](https://guptadeepak.com/ciam-compass/compare/auth0-vs-descope/) - [Auth0 vs Microsoft Entra External ID](https://guptadeepak.com/ciam-compass/compare/auth0-vs-entra-external-id/) - [Auth0 vs Firebase Authentication](https://guptadeepak.com/ciam-compass/compare/auth0-vs-firebase-auth/) - [Auth0 vs ForgeRock](https://guptadeepak.com/ciam-compass/compare/auth0-vs-forgerock/) - [Auth0 vs Frontegg](https://guptadeepak.com/ciam-compass/compare/auth0-vs-frontegg/) - [Auth0 vs FusionAuth](https://guptadeepak.com/ciam-compass/compare/auth0-vs-fusionauth/) - [Auth0 vs Keycloak](https://guptadeepak.com/ciam-compass/compare/auth0-vs-keycloak/) - [Auth0 vs Kinde](https://guptadeepak.com/ciam-compass/compare/auth0-vs-kinde/) - [Auth0 vs Logto](https://guptadeepak.com/ciam-compass/compare/auth0-vs-logto/) - [Auth0 vs miniOrange](https://guptadeepak.com/ciam-compass/compare/auth0-vs-miniorange/) - [Auth0 vs Oracle IAM Identity Domains](https://guptadeepak.com/ciam-compass/compare/auth0-vs-oracle-idcs/) - [Auth0 vs Ory](https://guptadeepak.com/ciam-compass/compare/auth0-vs-ory/) - [Auth0 vs Ping Identity](https://guptadeepak.com/ciam-compass/compare/auth0-vs-ping-identity/) - [Auth0 vs PropelAuth](https://guptadeepak.com/ciam-compass/compare/auth0-vs-propelauth/) - [Auth0 vs Rownd](https://guptadeepak.com/ciam-compass/compare/auth0-vs-rownd/) - [Auth0 vs SAP Customer Data Cloud](https://guptadeepak.com/ciam-compass/compare/auth0-vs-sap-customer-data-cloud/) - [Auth0 vs SlashID](https://guptadeepak.com/ciam-compass/compare/auth0-vs-slashid/) - [Auth0 vs SSOJet](https://guptadeepak.com/ciam-compass/compare/auth0-vs-ssojet/) - [Auth0 vs Strivacity](https://guptadeepak.com/ciam-compass/compare/auth0-vs-strivacity/) - [Auth0 vs Stytch](https://guptadeepak.com/ciam-compass/compare/auth0-vs-stytch/) - [Auth0 vs Supabase Auth](https://guptadeepak.com/ciam-compass/compare/auth0-vs-supabase-auth/) - [Auth0 vs SuperTokens](https://guptadeepak.com/ciam-compass/compare/auth0-vs-supertokens/) - [Auth0 vs Transmit Security](https://guptadeepak.com/ciam-compass/compare/auth0-vs-transmit-security/) - [Auth0 vs WorkOS](https://guptadeepak.com/ciam-compass/compare/auth0-vs-workos/) - [Auth0 vs Zitadel](https://guptadeepak.com/ciam-compass/compare/auth0-vs-zitadel/) - [Authentik vs Zitadel](https://guptadeepak.com/ciam-compass/compare/authentik-vs-zitadel/) - [Authress vs Casdoor](https://guptadeepak.com/ciam-compass/compare/authress-vs-casdoor/) - [Authress vs WorkOS](https://guptadeepak.com/ciam-compass/compare/authress-vs-workos/) - [Authsignal vs Corbado](https://guptadeepak.com/ciam-compass/compare/authsignal-vs-corbado/) - [BetterAuth vs SuperTokens](https://guptadeepak.com/ciam-compass/compare/betterauth-vs-supertokens/) - [Beyond Identity vs CyberArk Identity](https://guptadeepak.com/ciam-compass/compare/beyond-identity-vs-cyberark-customer-identity/) - [Beyond Identity vs Stytch](https://guptadeepak.com/ciam-compass/compare/beyond-identity-vs-stytch/) - [Casdoor vs FusionAuth](https://guptadeepak.com/ciam-compass/compare/casdoor-vs-fusionauth/) - [Clerk vs Frontegg](https://guptadeepak.com/ciam-compass/compare/clerk-vs-frontegg/) - [Clerk vs Kinde](https://guptadeepak.com/ciam-compass/compare/clerk-vs-kinde/) - [Clerk vs PropelAuth](https://guptadeepak.com/ciam-compass/compare/clerk-vs-propelauth/) - [Clerk vs Rownd](https://guptadeepak.com/ciam-compass/compare/clerk-vs-rownd/) - [Clerk vs Stack Auth](https://guptadeepak.com/ciam-compass/compare/clerk-vs-stack-auth/) - [Clerk vs Stytch](https://guptadeepak.com/ciam-compass/compare/clerk-vs-stytch/) - [Clerk vs WorkOS](https://guptadeepak.com/ciam-compass/compare/clerk-vs-workos/) - [Amazon Cognito vs Microsoft Entra External ID](https://guptadeepak.com/ciam-compass/compare/cognito-vs-entra-external-id/) - [Amazon Cognito vs Firebase Authentication](https://guptadeepak.com/ciam-compass/compare/cognito-vs-firebase-auth/) - [Amazon Cognito vs FusionAuth](https://guptadeepak.com/ciam-compass/compare/cognito-vs-fusionauth/) - [Amazon Cognito vs Oracle IAM Identity Domains](https://guptadeepak.com/ciam-compass/compare/cognito-vs-oracle-idcs/) - [Amazon Cognito vs Supabase Auth](https://guptadeepak.com/ciam-compass/compare/cognito-vs-supabase-auth/) - [Curity vs ForgeRock](https://guptadeepak.com/ciam-compass/compare/curity-vs-forgerock/) - [Descope vs Frontegg](https://guptadeepak.com/ciam-compass/compare/descope-vs-frontegg/) - [Microsoft Entra External ID vs Descope](https://guptadeepak.com/ciam-compass/compare/entra-external-id-vs-descope/) - [Microsoft Entra External ID vs Firebase Authentication](https://guptadeepak.com/ciam-compass/compare/entra-external-id-vs-firebase-auth/) - [Firebase Authentication vs Clerk](https://guptadeepak.com/ciam-compass/compare/firebase-auth-vs-clerk/) - [Firebase Authentication vs MojoAuth](https://guptadeepak.com/ciam-compass/compare/firebase-auth-vs-mojoauth/) - [Firebase Authentication vs Stytch](https://guptadeepak.com/ciam-compass/compare/firebase-auth-vs-stytch/) - [Firebase Authentication vs Supabase Auth](https://guptadeepak.com/ciam-compass/compare/firebase-auth-vs-supabase-auth/) - [ForgeRock vs IBM Verify](https://guptadeepak.com/ciam-compass/compare/forgerock-vs-ibm-security-verify/) - [Frontegg vs PropelAuth](https://guptadeepak.com/ciam-compass/compare/frontegg-vs-propelauth/) - [Frontegg vs SSOJet](https://guptadeepak.com/ciam-compass/compare/frontegg-vs-ssojet/) - [FusionAuth vs Authentik](https://guptadeepak.com/ciam-compass/compare/fusionauth-vs-authentik/) - [Hanko vs Corbado](https://guptadeepak.com/ciam-compass/compare/hanko-vs-corbado/) - [Hanko vs SlashID](https://guptadeepak.com/ciam-compass/compare/hanko-vs-slashid/) - [Hanko vs Stack Auth](https://guptadeepak.com/ciam-compass/compare/hanko-vs-stack-auth/) - [Keycloak vs Authelia](https://guptadeepak.com/ciam-compass/compare/keycloak-vs-authelia/) - [Keycloak vs Authentik](https://guptadeepak.com/ciam-compass/compare/keycloak-vs-authentik/) - [Keycloak vs Casdoor](https://guptadeepak.com/ciam-compass/compare/keycloak-vs-casdoor/) - [Keycloak vs FusionAuth](https://guptadeepak.com/ciam-compass/compare/keycloak-vs-fusionauth/) - [Keycloak vs miniOrange](https://guptadeepak.com/ciam-compass/compare/keycloak-vs-miniorange/) - [Keycloak vs Ory](https://guptadeepak.com/ciam-compass/compare/keycloak-vs-ory/) - [Keycloak vs WSO2 Identity Server](https://guptadeepak.com/ciam-compass/compare/keycloak-vs-wso2-is/) - [Keycloak vs Zitadel](https://guptadeepak.com/ciam-compass/compare/keycloak-vs-zitadel/) - [Kinde vs WorkOS](https://guptadeepak.com/ciam-compass/compare/kinde-vs-workos/) - [Logto vs FusionAuth](https://guptadeepak.com/ciam-compass/compare/logto-vs-fusionauth/) - [Logto vs Zitadel](https://guptadeepak.com/ciam-compass/compare/logto-vs-zitadel/) - [MojoAuth vs Auth0](https://guptadeepak.com/ciam-compass/compare/mojoauth-vs-auth0/) - [MojoAuth vs SSOJet](https://guptadeepak.com/ciam-compass/compare/mojoauth-vs-ssojet/) - [MojoAuth vs Stytch](https://guptadeepak.com/ciam-compass/compare/mojoauth-vs-stytch/) - [Ory vs FusionAuth](https://guptadeepak.com/ciam-compass/compare/ory-vs-fusionauth/) - [Ping Identity vs Curity](https://guptadeepak.com/ciam-compass/compare/ping-identity-vs-curity/) - [Ping Identity vs CyberArk Identity](https://guptadeepak.com/ciam-compass/compare/ping-identity-vs-cyberark-customer-identity/) - [Ping Identity vs Microsoft Entra External ID](https://guptadeepak.com/ciam-compass/compare/ping-identity-vs-entra-external-id/) - [Ping Identity vs ForgeRock](https://guptadeepak.com/ciam-compass/compare/ping-identity-vs-forgerock/) - [Ping Identity vs IBM Verify](https://guptadeepak.com/ciam-compass/compare/ping-identity-vs-ibm-security-verify/) - [Ping Identity vs Strivacity](https://guptadeepak.com/ciam-compass/compare/ping-identity-vs-strivacity/) - [Ping Identity vs Transmit Security](https://guptadeepak.com/ciam-compass/compare/ping-identity-vs-transmit-security/) - [Scalekit vs SSOJet](https://guptadeepak.com/ciam-compass/compare/scalekit-vs-ssojet/) - [Scalekit vs WorkOS](https://guptadeepak.com/ciam-compass/compare/scalekit-vs-workos/) - [SSOJet vs Frontegg](https://guptadeepak.com/ciam-compass/compare/ssojet-vs-frontegg/) - [SSOJet vs WorkOS](https://guptadeepak.com/ciam-compass/compare/ssojet-vs-workos/) - [Stack Auth vs BetterAuth](https://guptadeepak.com/ciam-compass/compare/stack-auth-vs-betterauth/) - [Strivacity vs Descope](https://guptadeepak.com/ciam-compass/compare/strivacity-vs-descope/) - [Stytch vs Corbado](https://guptadeepak.com/ciam-compass/compare/stytch-vs-corbado/) - [Stytch vs Descope](https://guptadeepak.com/ciam-compass/compare/stytch-vs-descope/) - [Stytch vs Hanko](https://guptadeepak.com/ciam-compass/compare/stytch-vs-hanko/) - [Stytch vs Rownd](https://guptadeepak.com/ciam-compass/compare/stytch-vs-rownd/) - [Stytch vs SlashID](https://guptadeepak.com/ciam-compass/compare/stytch-vs-slashid/) - [Supabase Auth vs Clerk](https://guptadeepak.com/ciam-compass/compare/supabase-auth-vs-clerk/) - [SuperTokens vs FusionAuth](https://guptadeepak.com/ciam-compass/compare/supertokens-vs-fusionauth/) - [SuperTokens vs Keycloak](https://guptadeepak.com/ciam-compass/compare/supertokens-vs-keycloak/) - [Tesseral vs SSOJet](https://guptadeepak.com/ciam-compass/compare/tesseral-vs-ssojet/) - [Tesseral vs WorkOS](https://guptadeepak.com/ciam-compass/compare/tesseral-vs-workos/) - [Tesseral vs Zitadel](https://guptadeepak.com/ciam-compass/compare/tesseral-vs-zitadel/) - [WorkOS vs Frontegg](https://guptadeepak.com/ciam-compass/compare/workos-vs-frontegg/) - [WorkOS vs SSOJet](https://guptadeepak.com/ciam-compass/compare/workos-vs-ssojet/) - [Wristband vs Frontegg](https://guptadeepak.com/ciam-compass/compare/wristband-vs-frontegg/) - [Wristband vs SSOJet](https://guptadeepak.com/ciam-compass/compare/wristband-vs-ssojet/) - [Wristband vs WorkOS](https://guptadeepak.com/ciam-compass/compare/wristband-vs-workos/) - [WSO2 Identity Server vs Auth0](https://guptadeepak.com/ciam-compass/compare/wso2-is-vs-auth0/) - [WSO2 Identity Server vs Ping Identity](https://guptadeepak.com/ciam-compass/compare/wso2-is-vs-ping-identity/) - [Zitadel vs FusionAuth](https://guptadeepak.com/ciam-compass/compare/zitadel-vs-fusionauth/) - [Zitadel vs Ory](https://guptadeepak.com/ciam-compass/compare/zitadel-vs-ory/) ## Best practices - [Account recovery: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/account-recovery/) - [Anti-pattern: home-grown cryptography](https://guptadeepak.com/ciam-compass/best-practices/anti-pattern-homegrown-crypto/) - [Anti-pattern: long-lived static API keys](https://guptadeepak.com/ciam-compass/best-practices/anti-pattern-long-lived-api-keys/) - [Anti-pattern: SMS OTP as the only second factor](https://guptadeepak.com/ciam-compass/best-practices/anti-pattern-sms-otp-only/) - [API key rotation: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/api-key-rotation/) - [Audit logging: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/audit-logging/) - [B2B customer onboarding: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/b2b-customer-onboarding/) - [Bot defense and rate limiting: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/bot-defense-rate-limiting/) - [Consent capture: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/consent-capture/) - [Custom domains for CIAM: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/custom-domains/) - [JWT validation: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/jwt-validation/) - [Magic link and OTP email deliverability: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/magic-link-deliverability/) - [MFA rollout: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/mfa-rollout-checklist/) - [Multi-tenant isolation: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/multi-tenant-isolation/) - [OAuth and OIDC client configuration: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/oauth-oidc-client-config/) - [Passkey adoption: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/passkey-adoption/) - [Password storage: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/password-storage/) - [Session management: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/session-management/) - [SSO troubleshooting: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/sso-troubleshooting/) - [Token revocation: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/token-revocation/) - [User data export: do's and don'ts](https://guptadeepak.com/ciam-compass/best-practices/user-data-export/) ## Playbooks - [B2B Enterprise SSO Onboarding: A 60-Day Playbook](https://guptadeepak.com/ciam-compass/playbooks/b2b-enterprise-sso-onboarding/) - [B2B SaaS Identity From Scratch: A 60-Day Playbook](https://guptadeepak.com/ciam-compass/playbooks/b2b-saas-from-scratch/) - [CIAM Decommission: Retiring an Old Identity Platform Safely](https://guptadeepak.com/ciam-compass/playbooks/ciam-decommission/) - [CIAM Launch Checklist: 30-Day Pre-Production Playbook](https://guptadeepak.com/ciam-compass/playbooks/ciam-launch-checklist/) - [CIAM Compliance Audit Prep: A 45-Day Playbook for SOC 2, ISO 27001, GDPR Readiness](https://guptadeepak.com/ciam-compass/playbooks/compliance-audit-prep/) - [MFA Rollout: A 90-Day Playbook for Mid-Market SaaS](https://guptadeepak.com/ciam-compass/playbooks/mfa-rollout-90-day/) - [Migrating from Auth0 to FusionAuth: A 60-Day Runbook](https://guptadeepak.com/ciam-compass/playbooks/migrate-auth0-to-fusionauth/) - [Migrating Auth0 to MojoAuth: A 60-Day Passwordless Runbook](https://guptadeepak.com/ciam-compass/playbooks/migrate-auth0-to-mojoauth/) - [Migrating Auth0 Enterprise SSO to SSOJet: A 45-Day Runbook](https://guptadeepak.com/ciam-compass/playbooks/migrate-auth0-to-ssojet/) - [Migrating Auth0 B2B to WorkOS: A 60-Day Runbook](https://guptadeepak.com/ciam-compass/playbooks/migrate-auth0-to-workos/) - [Migrating Azure AD B2C P1 to Entra External ID: A 90-Day Runbook](https://guptadeepak.com/ciam-compass/playbooks/migrate-azure-ad-b2c-to-entra-external-id/) - [Migrate from AWS Cognito to Stytch: A 60-Day Playbook](https://guptadeepak.com/ciam-compass/playbooks/migrate-cognito-to-stytch/) - [Migrating from Auth0 to a Self-Hosted CIAM: A 90-Day Playbook](https://guptadeepak.com/ciam-compass/playbooks/migrate-from-auth0-to-self-hosted/) - [Migrate from Keycloak to a Managed CIAM: A 90-Day Playbook](https://guptadeepak.com/ciam-compass/playbooks/migrate-keycloak-to-managed/) - [Passkey Rollout: A 90-Day Playbook for Consumer SaaS](https://guptadeepak.com/ciam-compass/playbooks/passkey-rollout/) ## Verticals - [Financial services & banking](https://guptadeepak.com/ciam-compass/verticals/financial-services/) - [Travel & hospitality](https://guptadeepak.com/ciam-compass/verticals/travel-hospitality/) - [Government & cities](https://guptadeepak.com/ciam-compass/verticals/government-cities/) - [Retail & e-commerce](https://guptadeepak.com/ciam-compass/verticals/retail-ecommerce/) - [B2B SaaS](https://guptadeepak.com/ciam-compass/verticals/b2b-saas/) - [Direct-to-consumer (D2C) brands](https://guptadeepak.com/ciam-compass/verticals/direct-to-consumer/) - [Consumer apps & marketplaces](https://guptadeepak.com/ciam-compass/verticals/consumer-apps/) - [Gaming & interactive entertainment](https://guptadeepak.com/ciam-compass/verticals/gaming/) - [iGaming, online gambling & sports betting](https://guptadeepak.com/ciam-compass/verticals/igaming-gambling/) - [Healthcare & life sciences](https://guptadeepak.com/ciam-compass/verticals/healthcare/) - [Education & EdTech](https://guptadeepak.com/ciam-compass/verticals/education/) - [Media & streaming](https://guptadeepak.com/ciam-compass/verticals/media-streaming/) - [Automotive & connected vehicle](https://guptadeepak.com/ciam-compass/verticals/automotive-mobility/) - [Energy & utilities](https://guptadeepak.com/ciam-compass/verticals/energy-utilities/) - [Insurance](https://guptadeepak.com/ciam-compass/verticals/insurance/) - [Real estate & proptech](https://guptadeepak.com/ciam-compass/verticals/real-estate-proptech/) - [Crypto & Web3](https://guptadeepak.com/ciam-compass/verticals/crypto-web3/) - [Non-profit & civic](https://guptadeepak.com/ciam-compass/verticals/nonprofit-civic/) ## Glossary 119 terms. Each entry has a canonical definition, related vendors, and citations. - [Two-Factor Authentication](https://guptadeepak.com/ciam-compass/glossary/2fa/) - [AAGUID](https://guptadeepak.com/ciam-compass/glossary/aaguid/) - [AAL1](https://guptadeepak.com/ciam-compass/glossary/aal1/) - [AAL2](https://guptadeepak.com/ciam-compass/glossary/aal2/) - [AAL3](https://guptadeepak.com/ciam-compass/glossary/aal3/) - [ABAC](https://guptadeepak.com/ciam-compass/glossary/abac/) - [Access Token](https://guptadeepak.com/ciam-compass/glossary/access-token/) - [Account Linking](https://guptadeepak.com/ciam-compass/glossary/account-linking/) - [Account Recovery](https://guptadeepak.com/ciam-compass/glossary/account-recovery/) - [Adaptive Risk-Based Authentication](https://guptadeepak.com/ciam-compass/glossary/adaptive-risk-based-authentication/) - [Agentic Identity](https://guptadeepak.com/ciam-compass/glossary/agentic-identity/) - [ATO](https://guptadeepak.com/ciam-compass/glossary/ato/) - [Attestation](https://guptadeepak.com/ciam-compass/glossary/attestation/) - [Authentication](https://guptadeepak.com/ciam-compass/glossary/authentication/) - [Authenticator](https://guptadeepak.com/ciam-compass/glossary/authenticator/) - [Authorization Code Flow](https://guptadeepak.com/ciam-compass/glossary/authorization-code-flow/) - [Authorization](https://guptadeepak.com/ciam-compass/glossary/authorization/) - [Bearer Token](https://guptadeepak.com/ciam-compass/glossary/bearer-token/) - [Biometric Authentication](https://guptadeepak.com/ciam-compass/glossary/biometric-authentication/) - [Bot Detection](https://guptadeepak.com/ciam-compass/glossary/bot-detection/) - [Brute Force Attack](https://guptadeepak.com/ciam-compass/glossary/brute-force-attack/) - [CAPTCHA](https://guptadeepak.com/ciam-compass/glossary/captcha/) - [CIBA](https://guptadeepak.com/ciam-compass/glossary/ciba/) - [Claims](https://guptadeepak.com/ciam-compass/glossary/claims/) - [Client Credentials Flow](https://guptadeepak.com/ciam-compass/glossary/client-credentials-flow/) - [Conditional UI](https://guptadeepak.com/ciam-compass/glossary/conditional-ui/) - [Consent Management](https://guptadeepak.com/ciam-compass/glossary/consent-management/) - [Continuous Authentication](https://guptadeepak.com/ciam-compass/glossary/continuous-authentication/) - [Credential Monitoring](https://guptadeepak.com/ciam-compass/glossary/credential-monitoring/) - [Credential Stuffing](https://guptadeepak.com/ciam-compass/glossary/credential-stuffing/) - [Credential](https://guptadeepak.com/ciam-compass/glossary/credential/) - [CTAP2](https://guptadeepak.com/ciam-compass/glossary/ctap2/) - [Data Breach](https://guptadeepak.com/ciam-compass/glossary/data-breach/) - [Data Minimization](https://guptadeepak.com/ciam-compass/glossary/data-minimization/) - [Deepfake Attack](https://guptadeepak.com/ciam-compass/glossary/deepfake-attack/) - [Device Code Flow](https://guptadeepak.com/ciam-compass/glossary/device-code-flow/) - [Device Fingerprinting](https://guptadeepak.com/ciam-compass/glossary/device-fingerprinting/) - [Decentralized Identifier](https://guptadeepak.com/ciam-compass/glossary/did/) - [Digital Identity Wallet](https://guptadeepak.com/ciam-compass/glossary/digital-identity-wallet/) - [Digital Identity](https://guptadeepak.com/ciam-compass/glossary/digital-identity/) - [Discovery Document](https://guptadeepak.com/ciam-compass/glossary/discovery-document/) - [DPoP](https://guptadeepak.com/ciam-compass/glossary/dpop/) - [Encryption](https://guptadeepak.com/ciam-compass/glossary/encryption/) - [EUDI Wallet](https://guptadeepak.com/ciam-compass/glossary/eudi-wallet/) - [Federation Assurance Level](https://guptadeepak.com/ciam-compass/glossary/fal/) - [FAPI](https://guptadeepak.com/ciam-compass/glossary/fapi/) - [Federation](https://guptadeepak.com/ciam-compass/glossary/federation/) - [FGA](https://guptadeepak.com/ciam-compass/glossary/fga/) - [FIDO2](https://guptadeepak.com/ciam-compass/glossary/fido2/) - [Identity Assurance Level](https://guptadeepak.com/ciam-compass/glossary/ial/) - [ID Token](https://guptadeepak.com/ciam-compass/glossary/id-token/) - [IdP](https://guptadeepak.com/ciam-compass/glossary/idp/) - [Identity Verification](https://guptadeepak.com/ciam-compass/glossary/idv/) - [Injection Attack](https://guptadeepak.com/ciam-compass/glossary/injection-attack/) - [ITDR](https://guptadeepak.com/ciam-compass/glossary/itdr/) - [JIT Provisioning](https://guptadeepak.com/ciam-compass/glossary/jit-provisioning/) - [JWE](https://guptadeepak.com/ciam-compass/glossary/jwe/) - [JWKS](https://guptadeepak.com/ciam-compass/glossary/jwks/) - [JWS](https://guptadeepak.com/ciam-compass/glossary/jws/) - [JWT](https://guptadeepak.com/ciam-compass/glossary/jwt/) - [Knowledge-Based Authentication](https://guptadeepak.com/ciam-compass/glossary/kba/) - [Key Derivation Function](https://guptadeepak.com/ciam-compass/glossary/kdf/) - [KYC](https://guptadeepak.com/ciam-compass/glossary/kyc/) - [Liveness Detection](https://guptadeepak.com/ciam-compass/glossary/liveness-detection/) - [Magic Link](https://guptadeepak.com/ciam-compass/glossary/magic-link/) - [MAU](https://guptadeepak.com/ciam-compass/glossary/mau/) - [Mobile Driver's License](https://guptadeepak.com/ciam-compass/glossary/mdl/) - [MFA](https://guptadeepak.com/ciam-compass/glossary/mfa/) - [mTLS](https://guptadeepak.com/ciam-compass/glossary/mtls/) - [NHI](https://guptadeepak.com/ciam-compass/glossary/nhi/) - [Nonce](https://guptadeepak.com/ciam-compass/glossary/nonce/) - [OAuth 2.1](https://guptadeepak.com/ciam-compass/glossary/oauth-2-1/) - [OAuth Scope](https://guptadeepak.com/ciam-compass/glossary/oauth-scope/) - [OIDC](https://guptadeepak.com/ciam-compass/glossary/oidc/) - [One-Time Password](https://guptadeepak.com/ciam-compass/glossary/otp/) - [PAR](https://guptadeepak.com/ciam-compass/glossary/par/) - [Passkey](https://guptadeepak.com/ciam-compass/glossary/passkey/) - [Password Hashing](https://guptadeepak.com/ciam-compass/glossary/password-hashing/) - [Passwordless Authentication](https://guptadeepak.com/ciam-compass/glossary/passwordless-authentication/) - [Pepper](https://guptadeepak.com/ciam-compass/glossary/pepper/) - [Phishing-Resistant Authentication](https://guptadeepak.com/ciam-compass/glossary/phishing-resistant-authentication/) - [Phishing](https://guptadeepak.com/ciam-compass/glossary/phishing/) - [PII](https://guptadeepak.com/ciam-compass/glossary/pii/) - [PKCE](https://guptadeepak.com/ciam-compass/glossary/pkce/) - [Progressive Profiling](https://guptadeepak.com/ciam-compass/glossary/progressive-profiling/) - [Public-Key Cryptography](https://guptadeepak.com/ciam-compass/glossary/public-key-cryptography/) - [Push Authentication](https://guptadeepak.com/ciam-compass/glossary/push-authentication/) - [Rainbow Table](https://guptadeepak.com/ciam-compass/glossary/rainbow-table/) - [Rate Limiting](https://guptadeepak.com/ciam-compass/glossary/rate-limiting/) - [RBAC](https://guptadeepak.com/ciam-compass/glossary/rbac/) - [ReBAC](https://guptadeepak.com/ciam-compass/glossary/rebac/) - [Refresh Token Rotation](https://guptadeepak.com/ciam-compass/glossary/refresh-token-rotation/) - [Refresh Token](https://guptadeepak.com/ciam-compass/glossary/refresh-token/) - [Relying Party](https://guptadeepak.com/ciam-compass/glossary/relying-party/) - [RP-ID](https://guptadeepak.com/ciam-compass/glossary/rp-id/) - [Salt](https://guptadeepak.com/ciam-compass/glossary/salt/) - [SAML Metadata](https://guptadeepak.com/ciam-compass/glossary/saml-metadata/) - [SAML](https://guptadeepak.com/ciam-compass/glossary/saml/) - [SCIM](https://guptadeepak.com/ciam-compass/glossary/scim/) - [Selective Disclosure](https://guptadeepak.com/ciam-compass/glossary/selective-disclosure/) - [Sender-Constrained Token](https://guptadeepak.com/ciam-compass/glossary/sender-constrained-token/) - [Service Provider](https://guptadeepak.com/ciam-compass/glossary/service-provider/) - [Session](https://guptadeepak.com/ciam-compass/glossary/session/) - [Single Logout](https://guptadeepak.com/ciam-compass/glossary/slo/) - [Social Login](https://guptadeepak.com/ciam-compass/glossary/social-login/) - [Self-Sovereign Identity](https://guptadeepak.com/ciam-compass/glossary/ssi/) - [SSO](https://guptadeepak.com/ciam-compass/glossary/sso/) - [Step-up Authentication](https://guptadeepak.com/ciam-compass/glossary/step-up-authentication/) - [Synthetic Identity Fraud](https://guptadeepak.com/ciam-compass/glossary/synthetic-identity-fraud/) - [Token Binding](https://guptadeepak.com/ciam-compass/glossary/token-binding/) - [TOTP](https://guptadeepak.com/ciam-compass/glossary/totp/) - [Universal Login](https://guptadeepak.com/ciam-compass/glossary/universal-login/) - [User Directory](https://guptadeepak.com/ciam-compass/glossary/user-directory/) - [Userinfo Endpoint](https://guptadeepak.com/ciam-compass/glossary/userinfo-endpoint/) - [Verifiable Credential](https://guptadeepak.com/ciam-compass/glossary/vc/) - [Verifier Impersonation Resistance](https://guptadeepak.com/ciam-compass/glossary/verifier-impersonation-resistance/) - [WebAuthn](https://guptadeepak.com/ciam-compass/glossary/webauthn/) - [Zanzibar](https://guptadeepak.com/ciam-compass/glossary/zanzibar/) - [Zero Trust](https://guptadeepak.com/ciam-compass/glossary/zero-trust/) ## Site indices - [Sitemap](https://guptadeepak.com/ciam-compass/sitemap.xml) - [Full corpus (llms-full.txt)](https://guptadeepak.com/ciam-compass/llms-full.txt): Single-document dump of vendor bodies, guides, and comparisons for retrieval crawlers. - [Vendor matrix JSON](https://guptadeepak.com/ciam-compass/data/vendors.json): Machine-readable capability matrix and TCO bands. - [Comparisons JSON](https://guptadeepak.com/ciam-compass/data/comparisons.json) - [Changelog](https://guptadeepak.com/ciam-compass/changelog/): Editorial change log for the portal. - [Changelog RSS](https://guptadeepak.com/ciam-compass/changelog/feed.xml): Freshness feed for industry events.