Skip to content
Boston Identity

Customer identity

Customer IAM

Registration, login and account security for the people who buy from you, designed for the traffic, fraud and privacy rules of a consumer service.

How it works

OpenID Connect sign-in with PKCE

OpenID Connect sign-in with PKCEThe browser is redirected to the authorization server with a code challenge. The user signs in and consents, and a one-time code returns to the client through the browser. The client redeems the code with its code verifier over the back channel and receives an ID token and an access token.BrowserClientappAuthorizationservertrust boundary1. GET /loginuser starts sign-in2. Authorization requestredirect, code_challenge3. Login + consentuser authenticates4. Authorization codevia the redirect URI5. Token requestcode + code_verifier6. ID + access tokensID token: a signed JWT
OpenID Connect authorization code flow with PKCE (RFC 7636). The code is worthless without the verifier, which only the client holds.

The problem

  • Login is the front door to revenue, and every failed or abandoned sign-in is a lost sale.
  • Account takeover and credential stuffing grow with the size of the customer base.
  • Customer data carries privacy obligations that workforce systems do not.

What we do

Customer identity uses the same protocols as workforce identity and almost none of the same constraints. The population is counted in millions rather than thousands, nobody can be trained, and a slow login shows up in the sales figures.

The engagements below include a customer identity system serving more than 300 million active users and an e-commerce identity rollout carried out alongside a move to cloud services.

What you get

  • A customer identity architecture sized for peak traffic rather than average traffic.
  • Registration, login, recovery and consent flows on OAuth 2.0 and OpenID Connect.
  • Account protection, from MFA to step-up checks, placed where the risk is.
  • Existing customer accounts migrated without forcing everyone to reset a password.

How it is usually shaped

Usually a platform program, run alongside the product team that owns the customer journey.

Platforms

  • Ping Identity
  • ForgeRock
  • Okta

Engagements

  • A home improvement retailer

    Develop and support a Customer online IAM system with more than 300 million active users.

  • A national department store retailer

    Implementing e-commerce Customer IAM solutions and migration to cloud services.

  • A global banking group

    Maintain and upgrade commercial and consumer faced IAM system for global areas.

Talk to us

Tell us where your Customer IAM work stands, and we will reply within one business day.

Talk to us about Customer IAM