How people prove who they are online, and how products get that right at scale. Passkeys, MFA, account recovery, CIAM architecture and the standards underneath them.
Chrome shipped DBSC to stable. It binds the session cookie to a key in the TPM, which makes a stolen cookie inert off the originating device. Here is the protocol, the honest limits, and the buyer checklist.
Vendor log retention ends months before the average breach is discovered. The funnel, security, and silent-failure metrics every CIAM deployment should have, and the seven-panel dashboard to start with.
Meta's settlement with 51 attorneys general commits at least $12.1 billion, but the money is the survivable part. Every teen safety term in the deal depends on knowing who is under 18, and nobody has solved that yet.
GrackerAI switched enterprise SSO from WorkOS to SSOJet, cut the annual bill by roughly $5,000, and gained the custom authentication flexibility an AI platform needs.
A decision framework for enterprise passkeys: when device-bound hardware keys beat synced passkeys, mapped to user risk, device context, compliance, and total cost. Includes the three failure patterns that surface only after rollout.
WebAuthn Level 3 was proposed for W3C Recommendation in July 2026. Encryption key derivation, cross-domain credentials, and automatic list syncing are now first-class. Here is what changed.
Everyone argues about auth pricing. Almost nobody accounts for what identity actually costs per closed deal, or notices the invoice founders obsess over is the smallest of four identity costs.
In a monolith you check who someone is once. In microservices, every hop has to ask again. Here is how I design authentication and authorization across services: edge auth, per-service verification, workload identity with SPIFFE, and centralized policy.
IAM decides who gets in the door. PAM controls the keys that can rewire the building. Here is the real difference, where they converge in 2026, and why your AI agents need both.
AI made it cheap to fake a face, a voice, and a video. Here is my working map of the three problems authentication now has to solve, and the tools that actually hold up in 2026: verifying people, verifying agents, and verifying content.
Your identity stack was architected for humans with browsers and thumbs. Agent traffic breaks consent, delegation, sessions, bot defence and audit at once.
Passkeys, post-quantum crypto, silent network authentication, AI behavioral biometrics, and decentralized identity are fusing into one login stack. Here is what it looks like by 2030, and the two moves in 2026 that decide whether you are ready.
Every CTO re-litigates build vs buy for authentication every 18 months, and the framing is broken. The real question isn't build or buy. It's which parts of identity are commodity and which parts are your actual product.
Identity vendors rarely die of bankruptcy. They die of acquisition, then neglect, then a shutdown email. A complete history of every dead CIAM vendor, the pattern behind the deaths, and the questions that protect you from the next one.
Whether Auth0 is too expensive depends entirely on who's asking. A framework for telling the regulated enterprise buyer (pay and negotiate) apart from the high-volume, cost-sensitive platform (migrate), with 2026 pricing and breach-cost data.
Scaling a CIAM platform past a billion users taught me that customer identity is a trust problem: progressive profiling, risk-based auth, and passwordless done right.
Okta and Microsoft no longer define the CIAM market alone. Five developer-first, passwordless-native, and AI-ready platforms are growing fast by solving the specific problems the incumbents leave unaddressed. Here is where each one fits in 2026.
JWT versus opaque tokens for API authentication: statelessness versus revocation, latency at global scale, blast radius, and the hybrid pattern most large deployments use.
"Is eSIM safer than a physical SIM?" has a more interesting answer than most articles give. Each SIM type, physical, eSIM, and iSIM, has a different architecture and a different attack surface. Here is how they actually work and which is genuinely more secure.
Auth0 (Okta) versus ForgeRock (Ping Identity), compared on developer experience, CIAM versus workforce IAM, deployment models, extensibility, standards, and pricing.
Most CIAM selection decisions get made on features at evaluation time. Six-figure migration projects 18 months later are the result. Here's the stage-fit framework that prevents it.
An annual research piece based on 12 months of monitoring 200+ CIAM vendor changelogs. The 14 trends shaping customer identity in 2026 and the vendors leading each shift.
Most "use bcrypt" posts are from 2014. Argon2 won the Password Hashing Competition in 2015 and nobody updated. Here is the actual 2026 decision framework for picking a password hashing algorithm.
The five CIAM contenders in 2026 don't compete head-on. Each wins for a different stage and buyer. Here's the framework I use, with the honest tradeoffs each carries.
A founder's guide to the difference between authentication and authorization in 2026, with passkeys, agent auth, JWT pitfalls, and the mistakes I see at scale.
We cancelled Auth0 over a year ago. Not because it stopped working, but because scaling to 350,000 monthly active users made the pricing model untenable.