America.gov launched on September 29, 2026 as a single AI front door to federal services, drawing on 29,000 government websites. What it does today, how to use it well, where it falls short, and what other countries should take from it.
Your account is only as secure as its weakest reachable path, and that path is usually recovery. A ranked guide to recovery methods, the NIST-backed design rules, and the help desk vector behind MGM, TfL and M&S.
A decision framework for enterprise passkeys: when device-bound hardware keys beat synced passkeys, mapped to user risk, device context, compliance, and total cost. Includes the three failure patterns that surface only after rollout.
WebAuthn Level 3 was proposed for W3C Recommendation in July 2026. Encryption key derivation, cross-domain credentials, and automatic list syncing are now first-class. Here is what changed.
Passkeys, post-quantum crypto, silent network authentication, AI behavioral biometrics, and decentralized identity are fusing into one login stack. Here is what it looks like by 2030, and the two moves in 2026 that decide whether you are ready.
We cancelled Auth0 over a year ago. Not because it stopped working, but because scaling to 350,000 monthly active users made the pricing model untenable.
Production authentication patterns for OAuth 2.0, OIDC, JWT, SAML, and WebAuthn, including the build-versus-buy maths and the storage and session decisions that are expensive to reverse later.
Ten passwordless CIAM platforms compared on verified September 2026 pricing and real passkey depth, plus three vendors to drop from an older shortlist.
Passkeys use public-key cryptography, so there is no shared secret for a breach to leak or a phishing page to capture. Passwords are still everywhere. Here is where each one belongs in 2026.
Synced passkeys for most users, device-bound FIDO2 keys for admins, push as a bridge. The full comparison on security, cost, assurance level and rollout.