A website authentication system is more than a login button. Visitors need to understand when they are signed in, what information belongs to their account, and how to leave safely on a shared device.
Gammal Tech brings sign-in and personal project storage together. This suits products where visitors return to preferences, saved items, or progress. The service provides account features; your product still decides what the signed-in experience should do.
Four jobs of website authentication
- Offer a clear way to sign in. A visitor chooses the sign-in control and completes the hosted Gammal Tech account flow in a popup.
- Confirm the active session. The website checks that the session is valid before loading account-specific views.
- Restore useful information. Your project can load only the preferences or progress it previously saved for the same account, across visits and devices.
- Provide sign-out. Signing out clears the local session, and the website should return to a clear signed-out view.
These features work together, but they have different lifetimes. A new browser tab requires another sign-in. Saved project information remains available when the account is used again.
Understand the account and privacy boundaries
Gammal Tech does not disclose the signed-in user’s underlying account name, email address, phone number, national ID number, or identity documents to your application. There is no API lookup for those details. Your project can retrieve only the customer data it previously saved for the same account.
Every Gammal Tech account requires national ID verification, and each person can have only one account. Customers reuse that account across participating websites; developers do not receive the identity verification details.
If your product needs a display name or a preference, the visitor can provide it in your own form. That information is collected by your business, not obtained from Gammal Tech’s underlying identity records.
Being signed in also differs from having permission to perform a privileged action. Administrative access and paid benefits need appropriate trusted checks. A preference a visitor can change must not be treated as proof of an entitlement.
What the Gammal Tech account service includes
| Feature | Scope |
|---|---|
| Passwordless website login | Hosted popup sign-in without a customer password table in your application. |
| Session handling | Session confirmation and local sign-out, with the active session kept per browser tab. |
| Personal project data | Free storage of up to 1 MB per user. Your project can retrieve only the data it previously saved for that account, across visits and devices after sign-in. |
| Registered website domains | Browser API access uses a public project identifier and domain whitelisting for up to four HTTPS domains per project, with no secret API key. |
The storage feature can support saved settings, a reading list, or learning progress. It does not automatically supply a shared customer database, an administrator dashboard, or a connection to historical records from an older login system.
Set up the project and plan the rollout
The owner uses their existing Gammal Tech account verified with national ID, or completes national ID verification when creating their first account. The owner then creates a project in the Developer Console and registers the website’s HTTPS domains for browser API access.
Register the main domain and its www version separately when both are used. Give your developer a defined visitor journey: sign in, confirm the session, load saved information, and sign out.
For an existing product, plan how customers using their existing Gammal Tech accounts will connect to your previous records before replacing its login. Gammal Tech does not supply underlying identity details for matching, and migration is not automatic. Test sign-in cancellation, a fresh browser tab, returning visits, and sign-out before offering the feature to customers. Keep the site secure and protect active sessions throughout the journey.
How much does website authentication cost?
Currency guide: Listed EGP prices are the billing amounts. USD figures are approximate, using USD 1 = EGP 51.78, the calculated midpoint of Banque Misr’s USD buying and selling rates on 24 September 2026. Your payment provider’s exchange rate and fees may differ.
Login, logout, and session verification are free. User data storage is also free within the 1 MB per-user limit. The first project is free; additional projects have a one-time fee shown through the account.
OTP codes for login and checkout identity verification share an allowance of 200 per project per month. Each additional code costs 0.40 EGP (approx. US$0.0077). Fund the personal account wallet and then transfer money into the project balance to cover paid usage. Paid OTP operations stop if the project balance is exhausted.
Common questions
Does national ID verification reveal the customer’s identity to my website?
No. Verification supports the one-account-per-person rule without disclosing underlying identity details to developers. Your project can retrieve only customer information that it previously stored for that account.
Does passwordless mean no credentials are stored anywhere?
No. Your application does not store customer passwords for this flow, but the integration manages a sensitive session token per browser tab. That token still needs protection even though there is no secret API key.
Can users recover saved preferences on another device?
Yes. Once the same customer signs in on another device, your project can retrieve the data it previously saved for that account.
Does sign-in automatically grant administrator access?
No. Authentication confirms a session. Your application must separately enforce permissions for privileged actions.
References
- Gammal Tech API reference — account setup, hosted login, project funding, pricing, and user storage limits.