Passwordless web authentication is useful when you want returning customer accounts without operating a separate password system for your website. The distinction between an account, a session, and saved user data helps explain what customers can expect.
An account belongs to the user. A session allows access during a signed-in visit. Saved app data preserves preferences and progress after that visit ends. Each has a different purpose.
What passwordless authentication means here
For a website using Gammal Tech, passwordless describes the absence of an application-specific password. Your website opens the hosted sign-in popup instead of collecting a separate password for the customer.
After successful sign-in, the application receives a session credential and can check whether the session is valid. That credential still needs protection. The benefit is that your application does not have to collect or store the user’s account password for this flow.
How sessions behave
The documented session is kept per browser tab. A user who opens a fresh tab or reopens the browser signs in again. A returning user can then retrieve the data already saved for their account and your project.
| Feature | What to expect |
|---|---|
| Sign in | A hosted popup lets the customer complete their Gammal Tech account sign-in. |
| Session check | The application can confirm whether the current signed-in session is valid. |
| Fresh browser tab | The user signs in again; saved app data is separate from the session. |
| Sign out | The user is signed out and the local session is cleared. |
Do not describe local sign-out as a promise to end every session on every device. If your product needs organization-wide or cross-device session controls, confirm those requirements separately before promising them to customers.
Why saved data survives sign-out
Gammal Tech provides persistent user data for each account in your project, with a maximum size of 1 MB per user. This can hold preferences, bookmarks, progress, and other compact app information.
For example, a user may choose a language and complete several lessons on a laptop. After signing in on another device, the app can retrieve that saved state. The session has changed, but the saved experience remains.
This does not mean the service is a shared company database or a file archive. Choose the information that fits the individual customer experience and the documented size limit.
Account privacy and business permissions
Login verification confirms that a user is signed in without returning their Gammal Tech email, phone number, or identity documents to your application. If your product asks for contact or profile information separately, that is an additional collection by your business.
Sign-in also does not decide whether a person should see a company invoice, manage a team, or receive a paid feature. Those product permissions need their own reliable controls. A remembered preference should not be treated as proof of payment or administrative authority.
What to plan before launch
- Customer expectations. Explain when sign-in is needed and give users a clear way to sign out.
- Returning visits. Check that preferences reappear after a new sign-in and on another device.
- Project setup. Use a verified owner account and register up to four HTTPS domains. Bare and www domains count separately.
- Existing accounts. Plan how current customer records relate to the new sign-in flow; account migration is not automatic.
Authentication pricing
Currency guide: Listed EGP prices are the billing amounts. USD figures are approximate, using USD 1 = EGP 51.78, the calculated midpoint of Banque Misr’s USD buying and selling rates on 24 September 2026. Your payment provider’s exchange rate and fees may differ.
| Feature | What to expect |
|---|---|
| Login, logout and session checks | Free, with unlimited use. |
| Saved user data | Free; a maximum of 1 MB per user applies. |
| Login codes (OTP) | 200 codes per month per project are included. Additional codes cost 0.40 EGP (approx. US$0.0077) each. |
The code allowance includes codes sent during login and checkout identity verification, and resets monthly. Paid usage comes from the project balance: add funds to your personal wallet, then transfer them into the project. The first project is free; additional projects have a one-time fee shown in the Console.
Common questions
Is passwordless sign-in the same as anonymous browsing?
No. This flow signs the user into their Gammal Tech account. Your app can then restore saved user data without receiving their account contact details.
Does signing out delete saved preferences?
No. Sign-out clears the local session. Saved user data persists and can be retrieved after the user signs in again.
Does removing app passwords remove every account risk?
No. Session credentials and product permissions still require protection. The documented benefit is removing your application’s password storage for this sign-in flow.
Reference
- Gammal Tech API and SDK reference — account features, project domains, session behavior, storage limits, and pricing.