Identity and Access
Customer Identity and Access Management (CIAM): from Homegrown Login Pages to AI agents
Customer identity and access management (CIAM) is the software that signs up, signs in and protects a company's customers at scale: login, social sign-in, consent, profiles, recovery and bot defence. It is being rebuilt for a new kind of customer, the AI agent that signs in, shops and pays on a person's behalf under delegated, revocable authority.
Autonomy level
2.0 of 5 · Copilot
launch score
Projected 3.3 by 2031
- Tasks automated
- 2.0
- Approval load
- 1.5
- Production maturity
- 2.5
Overall is the mean of the three sub-scores. How scores work
Key numbers
51%
Automated traffic made up 51% of all web traffic in 2024, the first time in a decade it passed human activity, and account takeover attacks rose 40% (vendor-reported, Imperva 2025 Bad Bot Report).
2025 Imperva Bad Bot Report: How AI is Supercharging the Bot Threat47%
47% of consumers say they are likely to abandon a purchase or sign-in when they cannot remember their password, in an April 2026 survey of 11,000 consumers in ten countries commissioned by the FIDO Alliance.
FIDO Alliance: State of Passkeys 2026 on World Passkey Day75%
75% of consumers in the same FIDO Alliance survey had enabled a passkey on at least one account, but only 49% used passkeys regularly when available.
FIDO Alliance: State of Passkeys 2026 on World Passkey Day0.1%
23andMe told the SEC that attackers accessed about 0.1% of user accounts using passwords reused from other breached sites, then used them to reach shared ancestry profiles of other users.
23andMe Holding Co. Form 8-K/A (SEC)$180M to $400M
Coinbase's SEC filing estimated $180 million to $400 million in remediation and customer reimbursement costs after it said overseas support contractors or employees were paid to pull customer data from internal systems.
Coinbase Global, Inc. Form 8-K, May 2025 (SEC)$6.5B
Okta completed its acquisition of Auth0, the developer-first CIAM platform founded in 2013, in a deal valued at about $6.5 billion.
Okta Completes Acquisition of Auth0 (Business Wire)1 May 2025
Microsoft stopped selling Azure AD B2C to new customers on 1 May 2025, pointing them to Entra External ID, and commits to support existing tenants until at least May 2030.
Frequently asked questions for Azure Active Directory B2C (Microsoft Learn)
The same job, five eras
Drag across the eras to see who did the work, with what, and what broke.
What job does customer identity and access management software do?
CIAM answers one question millions of times a day: is this really my customer, and what have they agreed to? It covers sign-up, sign-in, social login, passwordless, profile data, consent and preferences, account recovery, B2B organisations and tenants, and the fraud and bot defence that sits in front of all of it.
It is not workforce IAM with a bigger user count. The buyer is usually product, engineering or digital, not IT. The success metrics are conversion, completed sign-ups, uptime at peak traffic and privacy compliance, not access reviews. I lay out the full split in IAM vs CIAM. I founded and built LoginRadius, a CIAM platform I scaled to over a billion users, so this is the category I know from the inside.
The job is changing because the customer is changing. A growing share of the sessions that hit a login page are software: good bots, bad bots, and now AI agents acting for a real person who wants them there.
Era 1 · Before SaaS · 1995-2008
How did customer identity and access management work before SaaS?
Every web team built its own login. A users table, an email column, a password column, a reset link sent by email, and later a hash function someone hoped was strong enough. The sign-up form often asked for everything at once because marketing wanted the data.
Federation for consumers arrived as an experiment. OpenID 2.0 was declared final in December 2007, letting a person prove control of an identifier without the site holding a password. Facebook Connect opened to every website in December 2008 and turned the social network into a login button.
What broke was everything around the password. People reused the same one across dozens of sites, so one breach unlocked many. Reset flows were the softest path into an account, and nobody measured how many customers abandoned a form they could not finish.
Era 2 · The Cloud Move · 2009-2020
What changed when customer identity and access management moved to the cloud?
Customer identity became a product you bought. Janrain, Gigya, LoginRadius, Auth0, ForgeRock and Ping sold hosted login, social sign-in, user profiles and APIs, priced per monthly active user. Cloud platforms followed with developer services: Amazon Cognito launched in July 2014, and Microsoft offered Azure AD B2C until it stopped selling it to new customers in 2025.
This is the era I built in. I founded and created LoginRadius, a CIAM platform I scaled to over a billion users. The lessons are in building customer identity at scale: conversion, uptime at peak, consent, and data residency decide a customer login far more than they decide an employee one.
Regulation turned identity data into a liability as well as an asset. GDPR applied from May 2018 and CCPA took effect in January 2020, so consent records, preference centres and data export became core CIAM features. The big platforms consolidated: SAP agreed to buy Gigya in 2017 and Akamai acquired Janrain in January 2019.
- LoginRadius launches social login for websitessource
- Auth0 founded by Eugenio Pace and Matias Woloskisource
- Amazon Cognito launchessource
- SAP agrees to acquire Gigyasource
- GDPR starts to apply across the EUsource
- Akamai acquires Janrain for $123.6 million in cashsource
- California Consumer Privacy Act takes effectsource
Era 3 · The Copilot Years · 2020-2024
What did AI copilots change in customer identity and access management?
Machine learning moved into the login path as a risk score. Adaptive authentication weighed device, network, location and velocity, and stepped a sign-in up to a second factor only when something looked wrong. Bot management sat in front of sign-up and login to filter credential stuffing and fake account creation.
The credential problem stayed. In 2023, 23andMe disclosed that attackers had logged into about 0.1% of accounts using passwords reused from other breaches, then reached far more profiles through a relatives feature. A login let reused passwords in, and a sharing model multiplied the damage.
Passkeys gave consumers a phishing-resistant way out when Apple, Google and Microsoft committed to them in May 2022. The market consolidated again: Okta closed its $6.5 billion purchase of Auth0 in 2021, and Thoma Bravo folded ForgeRock into Ping Identity in 2023. I track who survived and who did not in the CIAM graveyard.
Era 4 · The Agentic Shift · 2024-2026
The Agentic Shift: What do AI agents do in customer identity and access management today?
The new customer at the login page is an AI agent. A person asks an assistant to find, compare and buy, and the agent needs to sign in to the store, read the cart and pay. The first agents did this by driving a browser with the customer's own password or session, which looks exactly like the account takeover CIAM was built to stop. I cover where this is heading in agentic commerce.
The payment networks moved first. Visa announced Intelligent Commerce and Mastercard announced Agent Pay with agentic tokens in April 2025. In September 2025 Google published the Agent Payments Protocol, which records user authorization as signed mandates, and Stripe and OpenAI released the Agentic Commerce Protocol with Instant Checkout in ChatGPT. All of them answer the same question: did a real customer authorise this specific purchase?
CIAM vendors are adding the identity half. Auth0 for AI Agents went GA in November 2025 with a Token Vault for third-party tokens and asynchronous approval, so a customer confirms a consequential action on their phone. Stytch, Descope and WorkOS ship OAuth 2.1 authorization for MCP servers so a customer's agent gets its own scoped token. Ping's Identity for AI includes detection that separates personal AI agents from other bots.
The other agent in the room works for the company. Support bots and agents now sit in the account recovery path, which is where social engineering already wins. In May 2025 Coinbase disclosed that bribed overseas support staff had copied customer data used to impersonate the company. My view, set out in account recovery design, is that recovery sets the real security ceiling, and an agent with recovery powers raises the stakes.
- Visa announces Intelligent Commerce for AI agentssource
- Mastercard announces Agent Pay and agentic tokenssource
- Azure AD B2C closed to new customers; Entra External ID is the successorsource
- Coinbase discloses bribed support staff copied customer datasource
- Stripe and OpenAI release the Agentic Commerce Protocolsource
- Auth0 for AI Agents reaches general availabilitysource
- Stytch confirms Twilio's acquisition is finalsource
- Ping Identity for AI generally available, with personal AI agent detectionsource
Era 5 · The Next Five Years · 2026-2031
What will customer identity and access management look like by 2031?
My bet is that by 2031 the most important customer on many storefronts will not be a person typing into a form. It will be that person's agent, holding its own short-lived token, scoped to a budget and a merchant, with a signed record of what the customer approved. I expect a store that cannot authenticate agents to lose that sale.
I expect passkeys to become the default human credential, with passwords as the fallback and then the exception. Recovery gets redesigned around strong proofs instead of support calls, because both attackers and helpful agents will push on it. I made the longer case in the future of CIAM, where delegated access matters more than the login screen.
Verifiable credentials and wallets change what sign-up means. The W3C published Verifiable Credentials 2.0 as a Recommendation in May 2025, and the EU requires every member state to offer a digital identity wallet by the end of 2026. I expect sign-up to shift from typing data in to presenting a verified claim, such as age or residency, without handing over the whole profile.
What has to be true: merchants, payment networks and CIAM vendors must agree on how an agent proves delegated authority, bot defence must learn to admit good agents, and consumer protection rules must say who pays when an agent buys the wrong thing.
My prediction · by 2031 · medium confidence
By 2031, most large consumer and B2B platforms will let customers authorise AI agents through their CIAM with their own scoped, revocable tokens and signed purchase limits, and agents that sign in with a customer's password will be blocked as account takeover.
What has to be true
- Merchants, card networks and CIAM vendors converge on a shared way for an agent to prove delegated authority
- Bot defence vendors reliably separate authenticated agents from hostile automation
- Consumer protection rules settle who bears the loss when an authorised agent buys the wrong thing
- Passkeys become the default customer credential so agents never need a password
Projected autonomy 3.3 of 5
Then vs now: who does each step?
The job broken into its steps, and who or what does each one in each era.
| Job step | On-prem | SaaS and cloud | AI-assisted | Agentic | Next 5 years |
|---|---|---|---|---|---|
| Sign the customer up | Long form posts to a homegrown users table | Hosted sign-up with social login and progressive profiling | Bot checks and risk scoring filter fake sign-ups | A customer's agent can register through OAuth with its own scoped client | Expected: the customer presents a verified credential instead of typing data |
| Prove who is signing in | A password, often reused from other sites | Password or social login, plus SMS codes | Adaptive MFA and passkeys for people | Passkeys for people; delegated, short-lived tokens for their agents | Expected: passkeys by default; agents carry signed proof of delegation |
| Capture consent and preferences | A pre-ticked box, rarely stored | Consent records and preference centres for GDPR and CCPA | Consent synced to marketing and data platforms | Consent screens for agent access with scopes and step-up approval | Expected: narrow, time-boxed grants per task, revocable from one place |
| Recover a locked account | Email reset link or a support call | Self-service reset with SMS or security questions | Risk checks on recovery; passkey sync reduces lockouts | Support bots and agents handle recovery requests; humans approve risky resets | Expected: recovery by strong proof, never by persuading a support agent |
| Stop bots and account takeover | CAPTCHAs and IP blocklists | Rate limits and breached-password checks | ML bot management and behavioural risk scores | Detection tries to separate personal AI agents from hostile bots | Expected: authenticated agents admitted by policy, unknown automation challenged |
| Complete a purchase | Customer types card details into every checkout | Stored cards and one-click checkout on a signed-in account | Risk-based payment authentication | Agent pays with a scoped token; customer confirms consequential buys | Expected: agent buys within a signed mandate and spend limit, no per-item approval |
How does the customer identity and access management team change?
CIAM teams were built to make one screen work: the login page, plus the reset flow behind it. Hosted CIAM shrank that work, passkeys shrank lockouts, and agents shrink it further, because a customer's agent does not need a beautiful form.
The work that grows is trust design. Someone has to decide which agents a customer may authorise, what a grant allows, when the customer must confirm, and how support handles recovery without becoming the attack path. That job sits between product, fraud, privacy and payments, and it needs one owner.
Roles that shrink
- Login and sign-up form builders
- Support staff resetting passwords by phone and email
- Manual fraud review of suspicious sign-ups
- CAPTCHA tuning and blocklist upkeep
Roles that appear
- Delegation and consent designer for customer agents
- Agent trust and bot policy lead
- Account recovery security owner
- Agentic commerce integration engineer
Skills to learn
- OAuth 2.1, PKCE and token exchange for agent clients
- Designing step-up approval for consequential actions
- Passkey rollout and recovery design
- Telling wanted automation from attacks in bot telemetry
- Privacy law for consent and delegated data access
What gets easier for the humans?
| Before | After |
|---|---|
| Customers abandoned purchases when they could not remember a password | Passkeys sign them in with a fingerprint or face, with nothing to forget |
| Customers filled the same long form on every new site | A verified credential or an agent completes sign-up with only what is needed |
| Giving an assistant access meant handing over your password | Your agent gets its own scoped token and you can revoke it in one place |
| Support staff spent shifts on lockouts and reset calls | Routine recovery is self-service; staff handle the hard, high-risk cases |
| Real customers solved CAPTCHAs to prove they were human | Risk signals let good customers through and challenge only suspicious traffic |
Decisions that stay human
- Approving a consequential purchase, transfer or account change an agent proposes
- Deciding which agents a customer may authorise and with what limits
- Approving account recovery when the signals disagree
- Setting consent, privacy and data retention policy for customer identity data
- Deciding what to tell customers after an identity breach
Where should agents not act alone?
Risks and failure modes, through a security and identity lens.
- 01
Agents running on the customer's password
Browser-driving agents that log in with a person's own credentials or copied session look exactly like account takeover, and they hold the full account. Give customer agents their own OAuth client and scoped, short-lived tokens, so a stolen token buys an attacker one task, not the account.
- 02
Account recovery as the attack path
Recovery is the softest way into a protected account, and support teams are the softest part of recovery. In May 2025 Coinbase disclosed that bribed overseas support staff copied customer data used to impersonate the company, and its SEC filing estimated $180 million to $400 million in costs. An AI support agent with reset powers can be talked into the same mistake at scale. Recovery must require strong proof that no human or agent can waive.
- 03
Credential stuffing that multiplies through sharing
23andMe disclosed that attackers entered about 0.1% of accounts with reused passwords, then reached many more profiles through a relatives feature. Breached-password checks, passkeys and rate limits stop the first step; data-sharing features need their own access model so one account cannot expose thousands.
- 04
Blocking good agents with bad bots
Imperva reports that automated traffic was 51% of web traffic in 2024 (vendor-reported). A bot wall tuned to stop scrapers will also stop the shopping agent a customer sent, and the sale goes elsewhere. Treat agent detection as an authentication problem: admit agents that prove delegated authority, challenge the rest.
- 05
Consent that no longer means consent
A customer clicks allow once and an agent uses that grant hundreds of times. Broad, standing grants fail privacy law and customer trust alike. Prefer narrow, time-boxed scopes, spend limits, and asynchronous confirmation for consequential actions.
- 06
Platform churn under your login
CIAM vendors are bought and retired often: Gigya went to SAP, Janrain to Akamai, ForgeRock into Ping, Stytch to Twilio, and Azure AD B2C closed to new customers in May 2025. Migrating millions of customer credentials is slow and risky. Write data export, password hash export and migration support into the contract.
How should you evaluate an agentic customer identity and access management vendor?
Questions to put to any vendor before you let its agents act.
- Can a customer's AI agent get its own OAuth client and scoped, short-lived token, or does it have to use the customer's password or session? Show me the flow.
- Which agent actions trigger a confirmation on the customer's device, and who sets that line: your default, my policy, or the agent?
- How does your bot defence tell a customer's authorised agent from a scraper or credential stuffing bot, and what does it do with each?
- What can your account recovery flow, and any AI support agent you provide, do without strong proof from the customer?
- How are consent and delegated grants recorded, and can a customer see and revoke every agent grant from one place?
- Can I export all customer identities, including password hashes and passkey registrations, if I leave or you are acquired?
- What is your pricing model when agents, not people, drive most sign-ins?
Who is building agentic customer identity and access management?
Incumbents adding agents vs agent-native entrants. Capability lines are checked against each vendor's own site.
Incumbents
Auth0 for AI Agents, GA since November 2025: user authentication for agents, Token Vault for third-party tokens, asynchronous authorization (push via Guardian, email and SMS announced as coming), and FGA for RAG. Auth for MCP was in early access at GA.
Checked Oct 10, 2026Compare
Threat protection detects bots, credential stuffing and account takeover, and asks "bad bot or good AI agent?" so human and agentic users can be allowed, stepped up or denied; Agent Detection in PingOne Protect, GA by 31 March 2026, identifies personal and external AI agents.
Checked Oct 10, 2026Compare
Agentic IAM manages agent identities separately from users and apps with scoped OAuth 2.1 credentials, rotation and revocation; MCP authorization with RFC 8693 token exchange, step-up for high-risk scopes and real-time token revocation.
Checked Oct 10, 2026
Remote MCP authorization with OAuth 2.1, dynamic client registration and Client ID Metadata Documents, scoped delegated access for agents acting for users, org-wide agent allowlists, and human approval through device authorization flows.
Checked Oct 10, 2026Compare
Agentic Identity Hub: OAuth 2.1 and tool-level scopes for MCP servers, agents managed as first-class identities; version 2.5, announced 9 June 2026, adds token exchange for delegated access, CIBA step-up for sensitive agent actions and support for headless agents.
Checked Oct 10, 2026
AuthKit acts as an OAuth 2.1 authorization server for MCP, with PKCE, scopes and tool permissions for AI agents; a standalone mode adds MCP OAuth flows in front of an existing user system.
Checked Oct 10, 2026Compare
Open source
Open-source login with social sign-in and an end-user account console for profile, password, 2FA and sessions; documents full support for MCP specification 2025-03-26 as an authorization server, with later versions including 2026-07-28 experimental.
Checked Oct 10, 2026
Ory Kratos (Apache 2.0) provides self-service registration, login and account recovery, used by Fandom for hundreds of millions of users; open-source Ory Hydra serves as an OAuth 2.1 authorization server for MCP servers with PKCE and scoped tokens for agents.
Checked Oct 10, 2026
Side-by-side comparisons: Top 10 Customer Identity and Access Management (CIAM) Solutions for 2026, Top 10 Passwordless Customer Identity and Access Management (CIAM) Solutions for 2026, Top 5 Developer-First CIAM Platforms: Frontegg, SSOJet, Stytch, Clerk, and WorkOS Compared.
Questions people ask
What is CIAM?
Customer identity and access management is the software that handles a company's customers: sign-up, sign-in, social login, passwordless, profiles, consent, account recovery and bot defence. It is built for millions of users, where conversion, uptime and privacy compliance matter as much as security.
What is the difference between IAM and CIAM?
Workforce IAM manages employees and contractors, and IT buys it for control and compliance. CIAM manages customers, and product or engineering buys it for conversion, scale and consent. They share protocols like OIDC and OAuth, but the users, vendors and success metrics are different.
How is AI changing customer identity?
In two ways. AI runs inside CIAM as risk scoring and bot detection that challenge only suspicious logins. And AI agents have become customers themselves, signing in, comparing and buying for a person, so CIAM now has to authenticate agents and record what the customer delegated.
How can an AI agent log in and buy on my behalf safely?
The agent should get its own OAuth token, scoped to the task and the merchant and short-lived, never your password. Consequential actions such as a payment should trigger a confirmation on your device. Card networks add their own tokens: Visa Intelligent Commerce and Mastercard Agent Pay were both announced in April 2025.
What is agentic commerce?
Agentic commerce is shopping done by an AI agent for a person: finding, comparing and buying. It needs identity for the agent, proof the customer authorised the purchase, and payment tokens scoped to the deal. Google's AP2 and the Stripe and OpenAI Agentic Commerce Protocol both launched in September 2025.
Are passkeys replacing passwords for customers?
In a 2026 consumer survey commissioned by the FIDO Alliance, 75% of people had enabled a passkey on at least one account, but only 49% used them regularly when offered. Passwords remain as fallback, which is why recovery design still matters.
Why is account recovery the weakest point in customer identity?
Because recovery exists to let someone in without their usual credential. Attackers target reset flows and support staff instead of the login itself. Coinbase disclosed in 2025 that bribed support staff copied customer data used to impersonate the company.
Should AI support agents be allowed to reset customer accounts?
Only for low-risk, well-proven cases. An AI agent can gather evidence and run checks, but a reset that bypasses a passkey or changes the email on a high-value account should require strong proof or human approval. An agent that can be persuaded is a new social engineering target.
What happened to Azure AD B2C?
Microsoft stopped selling Azure AD B2C to new customers on 1 May 2025 and points them to Microsoft Entra External ID. Existing customers can keep using it, and Microsoft says it will support Azure AD B2C until at least May 2030.
Do verifiable credentials and digital wallets replace CIAM?
No, they change its inputs. A wallet lets a customer present a verified claim, such as age or residency, instead of typing data. The CIAM platform still runs the account, session, consent and recovery. EU member states must offer a digital identity wallet by the end of 2026.
Sources
- OpenID Authentication 2.0 - Final, accessed Oct 10, 2026
- Facebook Expands its Social Platform across the Web Through General Availability of Facebook Connect, accessed Oct 10, 2026
- Logging in goes social with LoginRadius (YourStory), accessed Oct 10, 2026
- Bessemer Venture Partners: Auth0 investment memo, accessed Oct 10, 2026
- Introducing Amazon Cognito, accessed Oct 10, 2026
- SAP confirms acquisition of Israel-founded Gigya (Times of Israel), accessed Oct 10, 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation), accessed Oct 10, 2026
- California Consumer Privacy Act (CCPA), California Attorney General, accessed Oct 10, 2026
- Okta Completes Acquisition of Auth0 (Business Wire), accessed Oct 10, 2026
- Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard, accessed Oct 10, 2026
- Thoma Bravo Completes Acquisition of ForgeRock; Combines ForgeRock into Ping Identity, accessed Oct 10, 2026
- 23andMe Holding Co. Form 8-K/A (SEC), accessed Oct 10, 2026
- 2025 Imperva Bad Bot Report: How AI is Supercharging the Bot Threat, accessed Oct 10, 2026
- FIDO Alliance: State of Passkeys 2026 on World Passkey Day, accessed Oct 10, 2026
- Find and Buy with AI: Visa Unveils New Era of Commerce, accessed Oct 10, 2026
- Mastercard unveils Agent Pay, pioneering agentic payments technology to power commerce in the age of AI, accessed Oct 10, 2026
- Frequently asked questions for Azure Active Directory B2C (Microsoft Learn), accessed Oct 10, 2026
- Coinbase extorted for $20M. Support staff bribed. Customers scammed (The Register), accessed Oct 10, 2026
- Stripe powers Instant Checkout in ChatGPT and releases Agentic Commerce Protocol codeveloped with OpenAI, accessed Oct 10, 2026
- Announcing Agent Payments Protocol (AP2) (Google Cloud blog), accessed Oct 10, 2026
- Auth0 for AI Agents is now generally available, accessed Oct 10, 2026
- Stytch changelog (14 November 2025: Twilio acquisition final), accessed Oct 10, 2026
- Stytch Connected Apps, accessed Oct 10, 2026
- Descope Agentic Identity Hub 2.5 press release, accessed Oct 10, 2026
- WorkOS: MCP authorization with AuthKit, accessed Oct 10, 2026
- Ping Identity Defines the Runtime Identity Standard for Autonomous AI, accessed Oct 10, 2026
- LoginRadius AI capabilities, accessed Oct 10, 2026
- Keycloak: Integrating with Model Context Protocol (MCP), accessed Oct 10, 2026
- Ory: agentic AI security, accessed Oct 10, 2026
- Securing AI agents with Ory Hydra and MCP: A complete integration guide, accessed Oct 10, 2026
- Verifiable Credentials Data Model v2.0 (W3C Recommendation), accessed Oct 10, 2026
- EUR-Lex summary: European Digital Identity Framework and EU Digital Identity Wallets, accessed Oct 10, 2026
- Akamai Technologies Form 10-K for 2019 (SEC), accessed Oct 10, 2026
- Coinbase Global, Inc. Form 8-K, May 2025 (SEC), accessed Oct 10, 2026
- Ping Identity: threat protection, accessed Oct 10, 2026
- Keycloak, accessed Oct 10, 2026
- Ory Kratos, accessed Oct 10, 2026
Published Oct 9, 2026. Last verified Oct 10, 2026. Eras 4 and 5, vendors, and scores are re-checked every six to eight weeks; see the changelog and methodology.
Keep reading
Essays and analysis
- IAM vs CIAM vs IDaaS: What's the Difference and Which Do You Need?
- Building Customer Identity at Scale: Lessons from 1 Billion Users
- Agentic Commerce: How AI Agents Will Find, Compare, and Buy for You
- Account Recovery Design: The Flow That Determines Your Real Security Ceiling
- The Future of CIAM: Why Legacy Identity Systems Are Dead (And What Replaces Them)