Customer identity and access management, often called CIAM, concerns how customers sign in and what they can access. For a startup, the practical first step is to separate account sign-in from the permissions required by its particular product.
Gammal Tech covers a focused part of that experience: hosted account sign-in, session checks, sign-out, and saved app data. Assess those features against your requirements instead of assuming that every identity product offers the same controls.
Start with the customer experience you need
A learning service may need returning lesson progress. An agency portal may need to show a client only their own project information. A team product may need administrators, members, and billing permissions. These experiences share a need for sign-in, but their access rules differ.
Write down the account journey and the permission decisions separately. This makes it easier to choose services without buying capabilities you do not need or assuming that a basic sign-in feature supplies every business control.
What Gammal Tech provides
| Feature | What to expect |
|---|---|
| Hosted sign-in | Customers complete sign-in through a Gammal Tech popup using their existing verified account. They do not create another Gammal Tech account for each website. |
| App password storage | Your application does not collect or store a separate account password for this flow. |
| Session checks and sign-out | The application can check the current session and sign the user out, clearing the local session. |
| Account privacy | The underlying account’s name, email, phone number, national ID number, and identity documents are not disclosed to developers through login or an API lookup. |
| Saved experiences | Your project retrieves only customer data it previously stored for the same account. That data persists across visits and devices, up to 1 MB per user. |
These features are useful for preferences, progress, and compact personal app state. They do not by themselves establish a complete team-management, enterprise directory, or organization-role system.
Customer portals and multiple domains
Each project can have up to four registered HTTPS domains. A business may use those slots for its main site and selected application or portal subdomains. The bare domain and its www version count separately. Browser API requests for account features use these registered domains as the project’s whitelist. The project ID is public configuration, and no secret developer API key is required.
Registered subdomains can share the project’s users and payments. That does not mean automatic sign-in across every tab or device: sessions are kept per browser tab, and a fresh tab or reopened browser requires another sign-in. A session token remains a sensitive credential and must be protected even though the project ID is public.
Before choosing a project structure, list all the website addresses you plan to use. A clear domain plan avoids promising more sites under one project than the documented four-domain limit allows.
Guest payment links are a separate public, shareable flow. They can be opened from anywhere without a secret API key or a domain whitelist. Sharing the same link does not change the receiving owner.
Privacy and customer information
Gammal Tech does not disclose the customer’s underlying account name, email address, phone number, national ID number, or identity documents to your project, through login or a separate API lookup. When your project retrieves saved customer data, it receives only what that project previously stored for the same authenticated account. This supports returning preferences without exposing the underlying account profile.
If a client portal requires a billing contact, delivery address, or business profile, it can ask the customer directly for that information. This is a separate collection through your own forms, not a request to Gammal Tech for the underlying account details. Your forms and saved documents can therefore still contain personal data.
Setup and pricing for customer sign-in
Currency guide: Listed EGP prices are the billing amounts. USD figures are approximate, using USD 1 = EGP 51.78, the calculated midpoint of Banque Misr’s USD buying and selling rates on 24 September 2026. Your payment provider’s exchange rate and fees may differ.
Each person has one Gammal Tech account, and every account requires national ID verification. Existing account holders reuse that account on participating websites. The national ID number and verification documents remain private from developers. The owner creates a project in the Developer Console and registers the required HTTPS domains before integration. No secret developer API key is needed.
| Feature | What to expect |
|---|---|
| Login, logout and session checks | Free, with unlimited use. |
| Saved user data | Free; a maximum of 1 MB per user applies. |
| Login codes (OTP) | 200 codes per month per project are included. Additional codes cost 0.40 EGP (approx. US$0.0077) each. |
The code allowance includes codes sent during login and checkout identity verification, and resets monthly. Paid usage comes from the project balance: add funds to your personal wallet, then transfer them into the project. The first project is free; additional projects have a one-time fee shown in the Console.
Common questions
Does every customer need a verified Gammal Tech account?
Yes. Each person has one account, and every account requires national ID verification. Customers reuse that account on participating websites; the national ID number and verification documents remain private from developers.
Can a client portal use Gammal Tech sign-in?
Yes. It can use hosted sign-in and session checks. Access to private client records still requires appropriate product permissions.
Can my application request the customer’s underlying identity details?
No. Gammal Tech does not provide the underlying account’s name, email address, phone number, national ID number, or identity documents to your project through login or another API lookup. Customer-data retrieval is limited to data your own project previously stored for that account.
Does this automatically migrate existing customer accounts?
No automatic account migration is documented. Plan how existing records and permissions will relate to the new sign-in experience.
Reference
- Gammal Tech API and SDK reference — account features, project domains, session behavior, storage limits, and pricing.