Customer identity and access management in depth: architecture, build-versus-buy, vendor selection, and the login, onboarding, and security tradeoffs behind it.
The identity market consolidated in 2026, from Palo Alto Networks closing CyberArk to four NHI startups changing hands in ten weeks. The Identity Map sorts 255 vendors into 14 branches so buyers pick the right category before they pick a vendor.
Your account is only as secure as its weakest reachable path, and that path is usually recovery. A ranked guide to recovery methods, the NIST-backed design rules, and the help desk vector behind MGM, TfL and M&S.
Vendor log retention ends months before the average breach is discovered. The funnel, security, and silent-failure metrics every CIAM deployment should have, and the seven-panel dashboard to start with.
WebAuthn Level 3 was proposed for W3C Recommendation in July 2026. Encryption key derivation, cross-domain credentials, and automatic list syncing are now first-class. Here is what changed.
Everyone argues about auth pricing. Almost nobody accounts for what identity actually costs per closed deal, or notices the invoice founders obsess over is the smallest of four identity costs.
Your identity stack was architected for humans with browsers and thumbs. Agent traffic breaks consent, delegation, sessions, bot defence and audit at once.
Every CTO re-litigates build vs buy for authentication every 18 months, and the framing is broken. The real question isn't build or buy. It's which parts of identity are commodity and which parts are your actual product.
Identity vendors rarely die of bankruptcy. They die of acquisition, then neglect, then a shutdown email. A complete history of every dead CIAM vendor, the pattern behind the deaths, and the questions that protect you from the next one.
Whether Auth0 is too expensive depends entirely on who's asking. A framework for telling the regulated enterprise buyer (pay and negotiate) apart from the high-volume, cost-sensitive platform (migrate), with 2026 pricing and breach-cost data.
Scaling a CIAM platform past a billion users taught me that customer identity is a trust problem: progressive profiling, risk-based auth, and passwordless done right.
Okta and Microsoft no longer define the CIAM market alone. Five developer-first, passwordless-native, and AI-ready platforms are growing fast by solving the specific problems the incumbents leave unaddressed. Here is where each one fits in 2026.
Auth0 (Okta) versus ForgeRock (Ping Identity), compared on developer experience, CIAM versus workforce IAM, deployment models, extensibility, standards, and pricing.
Most CIAM selection decisions get made on features at evaluation time. Six-figure migration projects 18 months later are the result. Here's the stage-fit framework that prevents it.
An annual research piece based on 12 months of monitoring 200+ CIAM vendor changelogs. The 14 trends shaping customer identity in 2026 and the vendors leading each shift.
The five CIAM contenders in 2026 don't compete head-on. Each wins for a different stage and buyer. Here's the framework I use, with the honest tradeoffs each carries.
A founder's guide to the difference between authentication and authorization in 2026, with passkeys, agent auth, JWT pitfalls, and the mistakes I see at scale.
Security buyers research vendors in AI tools before a sales rep ever hears from them. The way a CISO interrogates ChatGPT looks nothing like how a marketer does. Here is what GEO actually looks like for cybersecurity.
We cancelled Auth0 over a year ago. Not because it stopped working, but because scaling to 350,000 monthly active users made the pricing model untenable.
AT&T's $177M settlement covers 73M customers, but the real story is how breach data from 2019 just resurfaced in 2026 with fully decrypted SSNs. Here's why.
Production authentication patterns for OAuth 2.0, OIDC, JWT, SAML, and WebAuthn, including the build-versus-buy maths and the storage and session decisions that are expensive to reverse later.
Firebase Auth has no real B2B Organizations and prices enterprise SAML free only to 50 MAU. Eight alternatives compared on verified September 2026 pricing.
Cognito's free tier shrank and its hosted UI still fights you. Eight alternatives compared on verified September 2026 pricing, plus the SRP migration trap.
Fourteen Auth0 alternatives compared on verified September 2026 pricing: Clerk, WorkOS, SSOJet, Stytch, Descope, Keycloak, FusionAuth, Cognito and more.
Ten passwordless CIAM platforms compared on verified September 2026 pricing and real passkey depth, plus three vendors to drop from an older shortlist.
Which IAM platform fits your organization? 21 workforce platforms compared with verified 2026 pricing, the year's acquisitions, and newer entrants to watch.
The complete CIAM provider directory, not a ranking: 34 identity platforms across six categories, with current ownership, published free tiers, and fit.
Passkeys use public-key cryptography, so there is no shared secret for a breach to leak or a phishing page to capture. Passwords are still everywhere. Here is where each one belongs in 2026.
Discover a comprehensive guide to implementing CIAM across five critical components: core configuration, security, privacy, API security, and monitoring.
Businesses face mounting cyber threats and data breaches from third-party vendors. Open-source CIAM solutions offer a secure, transparent alternative for
With the e-commerce market experiencing a surge in demand over the past couple of years, specific security threats that require adequate attention have
Authentication, identity verification, and identification answer three different security questions. Confusing them is how products end up with weak controls.
Businesses have to be extra vigilant in safeguarding customer data. Minor mistakes can cause a massive data breach, violating data privacy regulations and
What does it mean if everyone’s an identity driven company? Before answering that question, let’s define what it means to be an identity-driven company.
Identity Governance and Administration is the policy and audit layer on top of IAM. Why every mid-sized organization now needs it and what to evaluate.
Login is a big deal that decides the entire UX your website is going to deliver. Businesses should try to put as little resistance as possible into their
IAM is the discipline of giving the right people the right access and proving it after the fact. Concepts, controls, and how to design a modern program.
Security problems are an alternative way to recognise your customers when they have forgotten their password, entered too many times the wrong passwords,
In the previous article (Guide to Digital Identity-Part 1 [https://medium.com/@dip_ak/guide-to-digital-identity-part-1-4b7c8fe45ee1]), we talked about the
Social login still has a place, but it is no longer the front door. A practitioner's view on when to use it, how to harden it, and what is replacing it.