Customer identity and access management, often called CIAM, concerns how customers sign in and what they can access. For a startup, the practical first step is to separate account sign-in from the permissions required by its particular product.

Gammal Tech covers a focused part of that experience: hosted account sign-in, session checks, sign-out, and saved app data. Assess those features against your requirements instead of assuming that every identity product offers the same controls.

Start with the customer experience you need

A learning service may need returning lesson progress. An agency portal may need to show a client only their own project information. A team product may need administrators, members, and billing permissions. These experiences share a need for sign-in, but their access rules differ.

Write down the account journey and the permission decisions separately. This makes it easier to choose services without buying capabilities you do not need or assuming that a basic sign-in feature supplies every business control.

What Gammal Tech provides

Documented customer account features.
FeatureWhat to expect
Hosted sign-inCustomers complete sign-in through a Gammal Tech popup using their existing verified account. They do not create another Gammal Tech account for each website.
App password storageYour application does not collect or store a separate account password for this flow.
Session checks and sign-outThe application can check the current session and sign the user out, clearing the local session.
Account privacyThe underlying account’s name, email, phone number, national ID number, and identity documents are not disclosed to developers through login or an API lookup.
Saved experiencesYour project retrieves only customer data it previously stored for the same account. That data persists across visits and devices, up to 1 MB per user.

These features are useful for preferences, progress, and compact personal app state. They do not by themselves establish a complete team-management, enterprise directory, or organization-role system.

Customer portals and multiple domains

Each project can have up to four registered HTTPS domains. A business may use those slots for its main site and selected application or portal subdomains. The bare domain and its www version count separately. Browser API requests for account features use these registered domains as the project’s whitelist. The project ID is public configuration, and no secret developer API key is required.

Registered subdomains can share the project’s users and payments. That does not mean automatic sign-in across every tab or device: sessions are kept per browser tab, and a fresh tab or reopened browser requires another sign-in. A session token remains a sensitive credential and must be protected even though the project ID is public.

Before choosing a project structure, list all the website addresses you plan to use. A clear domain plan avoids promising more sites under one project than the documented four-domain limit allows.

Guest payment links are a separate public, shareable flow. They can be opened from anywhere without a secret API key or a domain whitelist. Sharing the same link does not change the receiving owner.

Privacy and customer information

Gammal Tech does not disclose the customer’s underlying account name, email address, phone number, national ID number, or identity documents to your project, through login or a separate API lookup. When your project retrieves saved customer data, it receives only what that project previously stored for the same authenticated account. This supports returning preferences without exposing the underlying account profile.

If a client portal requires a billing contact, delivery address, or business profile, it can ask the customer directly for that information. This is a separate collection through your own forms, not a request to Gammal Tech for the underlying account details. Your forms and saved documents can therefore still contain personal data.

Who can see what remains a product decision

A valid session establishes that the user is signed in. It does not alone establish which company records they own or whether they should have administrative privileges. Your business must arrange appropriate controls for those decisions.

When evaluating a provider, ask about the specific features you need: organization membership, account migration, support processes, session controls, and any required reporting. Confirm requirements that go beyond the published sign-in and user-data features before committing to a customer promise.

Setup and pricing for customer sign-in

Currency guide: Listed EGP prices are the billing amounts. USD figures are approximate, using USD 1 = EGP 51.78, the calculated midpoint of Banque Misr’s USD buying and selling rates on 24 September 2026. Your payment provider’s exchange rate and fees may differ.

Each person has one Gammal Tech account, and every account requires national ID verification. Existing account holders reuse that account on participating websites. The national ID number and verification documents remain private from developers. The owner creates a project in the Developer Console and registers the required HTTPS domains before integration. No secret developer API key is needed.

Authentication and saved user data pricing.
FeatureWhat to expect
Login, logout and session checksFree, with unlimited use.
Saved user dataFree; a maximum of 1 MB per user applies.
Login codes (OTP)200 codes per month per project are included. Additional codes cost 0.40 EGP (approx. US$0.0077) each.

The code allowance includes codes sent during login and checkout identity verification, and resets monthly. Paid usage comes from the project balance: add funds to your personal wallet, then transfer them into the project. The first project is free; additional projects have a one-time fee shown in the Console.

Common questions

Does every customer need a verified Gammal Tech account?

Yes. Each person has one account, and every account requires national ID verification. Customers reuse that account on participating websites; the national ID number and verification documents remain private from developers.

Can a client portal use Gammal Tech sign-in?

Yes. It can use hosted sign-in and session checks. Access to private client records still requires appropriate product permissions.

Can my application request the customer’s underlying identity details?

No. Gammal Tech does not provide the underlying account’s name, email address, phone number, national ID number, or identity documents to your project through login or another API lookup. Customer-data retrieval is limited to data your own project previously stored for that account.

Does this automatically migrate existing customer accounts?

No automatic account migration is documented. Plan how existing records and permissions will relate to the new sign-in experience.

Plan customer access around your product

List the sign-in journey, saved preferences, and business permissions your customers need, then configure the project that supports them.

Reference