CSA STAR Level 1
PublishedRead NamoID’s completed CAIQ v4.1 security and privacy answers in the public CSA registry.
Public self-assessment — not an independent audit
Open the public recordProduct
Customer IdentityHosted customer authenticationMCP AuthorizationDeveloper preview · Scoped AI-client accessAgent AccessAvailable now · External provider accessWorkforce IdentityDesign partner · Employee lifecycle and SSODevelopers
OverviewHosted Auth, OAuth/OIDC, and MCPDocumentationGuides & integrationAPI referenceEndpoints & schemasTrust
DPDP readinessChecklist & readiness reviewSecurityHow we protect your dataPrivacyHow we handle your dataLaunch hosted sign-in for your product. Give each AI client a separate, expiring grant for only the resources and actions a user approves.
$ npx @namoidhq/cli init
Detecting your application and installed agents…
✓ NamoID setup ready
Test environment
Trust credentials and supported identity capabilities
Configure sign-in methods and branding, keep Test and Live separate, revoke sessions, manage users, answer privacy requests, and inspect audit events from one console.
A user session proves who is present. An AI client still needs its own boundary: one client, one resource, approved actions, a short lifetime, and an independent revocation path.
Session for your application
Audience-bound grant for exact actions
Authentication methods are the beginning. Recovery, environments, sessions, user lifecycle, privacy requests, notifications, and audit are what keep identity working after launch.
Customer users, workforce users, AI clients, and provider connections can share administration and audit infrastructure without sharing identities, credentials, sessions, or lifecycle state.
Trust record
Open the evidence, check what the product supports, and see which audits and certifications NamoID does not hold yet. No hidden qualifiers.
Available to review
Read NamoID’s completed CAIQ v4.1 security and privacy answers in the public CSA registry.
Public self-assessment — not an independent audit
Open the public recordOperate notice, consent records, privacy requests, audit history, and incident evidence from the identity layer.
Supports your implementation — it does not make your business compliant
See the DPDP controlsPrivacy and security workflows account for data-subject requests and controller–processor responsibilities.
No certification claimed — applicability depends on your processing
Read our privacy approachNo certificate yet
Built to the ISO 27001 control set.
Documentation on request
Review our security postureControls map to the Security, Availability and Confidentiality criteria.
Documentation on request
Review our security postureWe test code, APIs, OAuth flows, dependencies, containers and configuration in-house.
Assessment summary on request
Review our security postureIndia ecosystem
Build consent-led DigiLocker document flows through the official partner ecosystem. Each production use case still follows DigiLocker approval and configuration.
Partner status does not mean DigiLocker certifies NamoID’s security
Also recognised: DPIIT and iStart Rajasthan recognise the company as a startup. They do not certify the product or its security.
Read the full security record →Status reviewed 30 Aug 2026 · evidence and availability may change
Security you can inspect
NamoID separates user sessions, AI grants, and provider credentials so each can be limited and revoked on its own path. Review the protocols, assessment, infrastructure region, and current certification status behind the claims.
MCP grant · live lifetime
15:00then the client asks again
01
Signs a human into your application. Ending it does not silently rewrite an agent’s authority.
subject → application
02
Names one client, one resource, and approved actions. It expires and can be revoked on its own.
client × resource × actions
03
Remains sealed inside NamoID. It is used only after policy allows an action and never becomes the agent token.
stored authority ≠ issued grant
Customer Identity is available now. MCP Authorization and Agent Access are available now. Workforce Identity is still a design-partner direction, not a generally available feature.
No. Customer Identity uses OAuth, OpenID Connect, PKCE, WebAuthn, JWT, and JWKS. India is where the product has additional depth: DPDP-focused workflows, local operating context, and India deployment requirements. SAML belongs to the Workforce Identity direction, which is not generally available yet.
No product can make an organization compliant on its own. NamoID provides identity controls and evidence for consent, audit, privacy operations, minimization, and retention. Your organization remains responsible for its notices, purposes, policies, and legal obligations.
Not yet. We build to both control sets, and our CSA STAR Level 1 assessment is published in the public CSA registry. Control documentation is available on request.
Usually, but the work is broader than changing an issuer. Callback and token-validation configuration can often move cleanly through OAuth and OpenID Connect; users, password hashes, linked identities, claims, and existing sessions need an explicit migration plan before production cutover.
Hosted Auth through redirect or popup is the supported Customer Identity path. SDKs handle the OAuth and OpenID Connect mechanics, while NamoID hosts credential collection, passkeys, social sign-in, and MFA. A general native authentication API is not currently offered for production use.
They point in opposite directions. MCP Authorization protects a server you own when someone else's AI client asks to use it. Agent Access is the other way round: your agent reaching into an account your user owns — their Gmail, their Slack — with a key that expires, instead of their password.
The first milestone is deliberately small: connect one application, register one exact callback, and complete one Hosted Auth flow in Test. The time depends on your framework and existing authentication setup; the setup assistant and direct engineering support are available if you get stuck.
You can talk directly with the engineers building NamoID. Use the setup assistant for configuration, join the Slack community for implementation questions, or book an engineering call for architecture and migration decisions.
Start in Test
Connect one application, register one exact callback, and complete Hosted Auth. If your product exposes an MCP server, add a separate grant for the resource, actions, audience, consent, and expiry.
No payment card to start Customer Identity · available now MCP Authorization · available now