Ideas · Technology & Software · Concept ·8 min read

OBIDUA Authentication Code

One identity, every BIDUA service — passwordless, phishing-resistant, built on Indian rails.

OBIDUA Authentication Code
0 passwords
Passwordless by design
FIDO2
Open standards backbone
<200 ms
Auth handshake latency
Aadhaar + WebAuthn
Identity primitives

Overview

OBIDUA is BIDUA's proprietary authentication and identity layer — a passwordless, phishing-resistant, India-aware authentication code system designed to be the front door to every BIDUA product (Naploo, FinWault, BIDUA Beauty, BIDUA Hosting, Virtual RDP) and, eventually, to licensed third parties.

The system combines open standards (FIDO2, WebAuthn, OAuth 2.1) with India-native primitives — Aadhaar e-KYC, DigiLocker-backed credentials, UPI handle as identity, mobile-number-as-identifier — and a proprietary device-binding code (the OBIDUA code) that anchors a verified identity to a hardware key or trusted device.

The status is idea. R&D begins in 2027 and the first internal rollout is targeted for 2028 across BIDUA's own properties. Third-party licensing follows once the system is battle-tested at scale.

Every breach in 2025 traces back to a password, an OTP that was phished, or a session token that lived too long. The fix is not better passwords. The fix is no passwords.


Why now

The opportunity, on its own terms.

01

Passwords are economically obsolete.

Credential-stuffing, phishing and OTP-interception now cost Indian banks and fintechs thousands of crores per year. The cost of "better passwords" exceeds the cost of replacing them.

02

FIDO2 and passkeys hit consumer adoption.

Apple, Google and Microsoft all ship passkey support natively. The platform burden is gone.

03

India Stack provides ground truth.

Aadhaar e-KYC, DigiLocker and the upcoming Bharat e-Sign Stack make identity proof a solved problem.

04

BIDUA needs its own front door.

Across Naploo, FinWault and Virtual RDP we already operate multiple auth stacks — consolidating them is operationally inevitable.


Market opportunity

Sized in three rings.

Total addressable
USD 25B by 2030
Global IAM / CIAM market
CAGR ~14%
Serviceable
~₹4,200 cr potential by 2030
Indian CIAM + auth infrastructure
If validated — driven by fintech, healthcare, govt
BIDUA share aim
Internal across BIDUA + 50 third-party tenants
OBIDUA 2030 target
₹40-60 cr ARR potential
  • Auth0 / Okta charge ~$2-5 per active user per month — Indian SMBs price-cap at ₹50-100.
  • RBI and SEBI have flagged credential-based fraud as a top-3 systemic risk for Indian financial services.
  • DPDP Act compliance has made consent-based identity a regulatory requirement, not a feature.
  • BIDUA's own auth volume across divisions is projected at 100M+ logins/year by 2028 — already a meaningful captive scale.

Business model

How it works, end to end.

01

OBIDUA code

A device-bound cryptographic credential anchored to a hardware key (TPM, Secure Enclave, mobile keystore). Replaces passwords and OTPs across all BIDUA properties.

02

Aadhaar + India Stack

Initial identity proofing via Aadhaar e-KYC and DigiLocker. UPI handle and mobile number as recoverable identifiers. DPDP Act-aligned consent framework.

03

SSO across BIDUA

Single sign-on for all BIDUA divisions — log in once, access Naploo, FinWault, Virtual RDP, BIDUA Beauty without re-authenticating.

04

Developer SDK

Drop-in SDKs for web, iOS, Android. Open standards (OIDC, SAML, WebAuthn) so third-party integration takes hours, not weeks.

05

Third-party CIAM

Once proven internally, OBIDUA is licensed to external Indian fintechs, healthtechs and SMBs as a managed CIAM service — priced for the Indian market.


Revenue streams

Three compounding phases.

Year 1–2

Internal rollout

  • Cost-avoidance across BIDUA divisions (replacing Auth0/Cognito)
  • Reduced fraud losses
  • Internal SLAs and chargeback to divisions
Year 3–4

Third-party launch

  • Per-MAU CIAM pricing
  • Enterprise SSO contracts
  • Compliance & audit packs (DPDP, RBI)
  • Premium fraud-signal feed
Year 5+

Platform

  • Government and BFSI tier contracts
  • Identity verification API (KYC-as-a-service)
  • Risk scoring & adaptive auth
  • International expansion (Southeast Asia, GCC)

Timeline

Patient cadence, deliberate steps.

  1. Q3 2027
    Architecture and threat model finalised. External security audit of design.
  2. Q1 2028
    Internal alpha on FinWault — the highest-stakes BIDUA division.
  3. Q3 2028
    Rollout across Naploo, BIDUA Beauty, Virtual RDP. Full SSO live.
  4. Q2 2029
    Developer SDK and third-party CIAM pilots with 5 Indian fintech partners.
  5. 2030
    GA for third parties. Compliance packs for DPDP and RBI ready out of the box.
  6. 2031
    BFSI and government tier launches. International expansion scoped.

Competitive landscape

Who else is here — and why we're different.

01 Auth0 / Okta Global CIAM leaders: Best-in-class. Expensive. Not India-rails native.
02 AWS Cognito / Firebase Auth Hyperscaler auth: Cheap baseline. Weak on Indian compliance and identity primitives.
03 Indian auth providers (MSG91, Karix, Truecaller SDK) Local SMS/auth players: Strong on OTP delivery. Weak on passwordless, FIDO2 and modern identity.
What BIDUA does differently
  • Passwordless by default — no OTP, no SMS, no password reset flow.
  • India-native — Aadhaar, DigiLocker, UPI as first-class identifiers.
  • Battle-tested inside BIDUA before external sale — proven at meaningful scale.
  • Built on open standards (FIDO2, OIDC) — no vendor lock-in for licensees.

Risks & mitigation

What can go wrong — and how we plan for it.

Risk 1

Cryptographic implementation bugs

Mitigation: External pen-test before every release. Bug-bounty programme. Open-spec design reviewed by independent auditors.

Risk 2

Aadhaar regulation changes

Mitigation: Aadhaar as one of several identity sources, not the only one. Mobile and DigiLocker provide redundancy.

Risk 3

Device-loss recovery UX

Mitigation: Multi-device passkey sync. Aadhaar / DigiLocker re-bootstrap path. Account recovery with cooling-off period.

Risk 4

Slow third-party adoption

Mitigation: Aggressive India-pricing. Free tier up to 10K MAU. Migration tooling from Auth0/Cognito.

Risk 5

Hyperscaler bundling pressure

Mitigation: Compete on India-context, regulatory specificity and price. Bundle with BIDUA Hosting for stickier accounts.



Common questions

Questions partners and investors actually ask.

Is OBIDUA just an SSO?

It is SSO, plus passwordless auth, plus identity verification, plus a fraud-signal layer. SSO is the surface; the substance is the entire identity stack.

How does it compare to Auth0?

Comparable feature set on the core, deeper integration with Indian identity rails, priced for the Indian market, no vendor lock-in.

What if I lose my phone?

Multi-device sync via passkeys. If all devices are lost, Aadhaar + DigiLocker re-bootstrap kicks in with a mandatory cooling-off period for security.

Is Aadhaar required?

Required for high-assurance flows (banking, government). Optional for general consumer login — UPI handle or verified mobile is sufficient.

Will I be locked into BIDUA?

No. OBIDUA is built on open standards (OIDC, SAML, FIDO2). Exporting users to another provider is supported by design.

How much does it cost for a third party?

Free up to 10K MAU. Tiered pricing above — significantly below Auth0/Okta Indian list prices.

Is it RBI compliant?

Designed to meet RBI's digital authentication guidelines, DPDP Act and the upcoming CERT-In auth norms. We publish a compliance pack with every release.

Get involved

Replace passwords across your stack.

We are looking for 5 Indian fintech and healthtech partners to pilot OBIDUA in 2029. Free for the first 12 months, with co-design input into the product roadmap.