When you evaluate a user authentication API, start with the experience it will give your customers. They need to sign in, return to useful saved information, and sign out when they finish. Your business needs to understand the account model, limits, and costs before integration begins.

Gammal Tech provides those account features through its authentication service and Web SDK. This guide explains the product capabilities without implementation code.

The account features available to your website

Authentication features and their customer purpose.
FeatureWhat to expect
Hosted login popupCustomers sign in through Gammal Tech using their existing verified account, which they reuse on participating websites.
Session verificationYour app can confirm whether the current session is valid.
Sign-outThe customer can sign out and clear the local session.
Saved user dataYour project can save preferences and progress, then retrieve only the customer data it previously stored for that same signed-in account.
Account privacyThe underlying account’s name, email, phone number, national ID number, and identity documents are not disclosed to developers through login or an API lookup.

Passwordless here means no application-specific password to collect or store. The app still receives a sensitive session credential that must be protected. The service should not be described as eliminating every credential or every security responsibility.

Registered domains instead of developer API keys

Each person has one Gammal Tech account, and every account requires national ID verification. Existing account holders reuse that account on participating websites. The national ID number and verification documents remain private from developers. The owner creates a project in the Developer Console and registers the website’s HTTPS domains. The integration does not require a secret developer API key; its project ID is public configuration.

A project supports up to four domains. The bare domain and its www version count separately, as do additional subdomains. Browser API requests for account features must come from this whitelist of registered HTTPS domains. List the site addresses your product needs before choosing how to organize its projects.

Guest payment links are a separate public, shareable flow. They can be opened from anywhere without a secret API key or a domain whitelist. Sharing the same link does not change the receiving owner.

This is a configuration feature of Gammal Tech. When comparing services, evaluate each provider’s own setup requirements, supported account flows, limits, and pricing rather than assuming they all follow one model.

What to expect across tabs and devices

Sessions are kept per browser tab. Opening a fresh tab or reopening the browser requires another sign-in. Sign-out clears the local session; the documented behavior should not be presented as a guarantee that every device is signed out at once.

Persistent user data is separate. After the customer signs in on another device, your project can retrieve only the data it previously stored for that same account. This lets an app restore preferences or progress without treating a temporary session as a permanent customer identifier.

Saved experiences and privacy limits

The user-data service supports up to 1 MB per user. Suitable uses include language preferences, bookmarks, learning progress, compact settings, and small drafts. It is not a promise of unlimited file storage or a complete shared business database.

Gammal Tech does not disclose the customer’s underlying account name, email address, phone number, national ID number, or identity documents to your project, through login or a separate API lookup. If your app needs an email for another purpose or asks someone to complete a profile, it can request that information directly from the customer. This is a separate collection by your app, not disclosure of Gammal Tech account details. Free-text documents and support forms can therefore still contain personal information.

Authentication and storage costs

Currency guide: Listed EGP prices are the billing amounts. USD figures are approximate, using USD 1 = EGP 51.78, the calculated midpoint of Banque Misr’s USD buying and selling rates on 24 September 2026. Your payment provider’s exchange rate and fees may differ.

Authentication and saved user data pricing.
FeatureWhat to expect
Login, logout and session checksFree, with unlimited use.
Saved user dataFree; a maximum of 1 MB per user applies.
Login codes (OTP)200 codes per month per project are included. Additional codes cost 0.40 EGP (approx. US$0.0077) each.

The code allowance includes codes sent during login and checkout identity verification, and resets monthly. Paid usage comes from the project balance: add funds to your personal wallet, then transfer them into the project. The first project is free; additional projects have a one-time fee shown in the Console.

For example, if a project sends 300 qualifying login or checkout verification codes in a month, 200 are included and the additional 100 cost 40 EGP (approx. US$0.77). This example covers code usage only; other paid services have their own charges.

Decide whether the service fits your product

  • Match the account model. Customers sign in with a Gammal Tech account rather than a password created only for your website.
  • Define the saved experience. Choose compact preferences and progress within the per-user limit.
  • Plan business permissions. Paid access, private records, and administrative actions need appropriate controls beyond a valid sign-in.
  • Account for existing customers. Plan any relationship to current records; automatic migration is not documented.

Common questions

Does each website need a different Gammal Tech account?

No. Each person has one Gammal Tech account, and every account requires national ID verification. Existing account holders reuse the same account on participating websites. Developers cannot retrieve the account’s national ID number or verification documents.

Does the service require a developer API key?

No secret developer API key is required. The project ID is public, and browser API requests for account features must come from the project’s registered HTTPS domains. A project supports up to four domains. Session tokens remain sensitive credentials.

Is every login free?

Login, logout, and session verification are free. Login codes have a separate allowance of 200 per month per project; additional codes cost 0.40 EGP (approx. US$0.0077) each.

Can I request the customer’s underlying account email or identity details?

No. Gammal Tech does not provide the underlying account’s name, email, phone number, national ID number, or identity documents through login or another API lookup. Your project retrieves only customer data it previously stored for the same account. Information requested directly from the customer is a separate collection.

Review the features for your next project

Choose the customer experience, registered domains, and saved information you need, then open the Console to begin setup.

Reference