OBIDUA Authentication Code
One identity, every BIDUA service — passwordless, phishing-resistant, built on Indian rails.
OBIDUA is BIDUA's proprietary authentication and identity layer — a passwordless, phishing-resistant, India-aware authentication code system designed to be the front door to every BIDUA product (Naploo, FinWault, BIDUA Beauty, BIDUA Hosting, Virtual RDP) and, eventually, to licensed third parties.
The system combines open standards (FIDO2, WebAuthn, OAuth 2.1) with India-native primitives — Aadhaar e-KYC, DigiLocker-backed credentials, UPI handle as identity, mobile-number-as-identifier — and a proprietary device-binding code (the OBIDUA code) that anchors a verified identity to a hardware key or trusted device.
The status is idea. R&D begins in 2027 and the first internal rollout is targeted for 2028 across BIDUA's own properties. Third-party licensing follows once the system is battle-tested at scale.
Every breach in 2025 traces back to a password, an OTP that was phished, or a session token that lived too long. The fix is not better passwords. The fix is no passwords.
The opportunity, on its own terms.
Passwords are economically obsolete.
Credential-stuffing, phishing and OTP-interception now cost Indian banks and fintechs thousands of crores per year. The cost of "better passwords" exceeds the cost of replacing them.
FIDO2 and passkeys hit consumer adoption.
Apple, Google and Microsoft all ship passkey support natively. The platform burden is gone.
India Stack provides ground truth.
Aadhaar e-KYC, DigiLocker and the upcoming Bharat e-Sign Stack make identity proof a solved problem.
BIDUA needs its own front door.
Across Naploo, FinWault and Virtual RDP we already operate multiple auth stacks — consolidating them is operationally inevitable.
Sized in three rings.
- Auth0 / Okta charge ~$2-5 per active user per month — Indian SMBs price-cap at ₹50-100.
- RBI and SEBI have flagged credential-based fraud as a top-3 systemic risk for Indian financial services.
- DPDP Act compliance has made consent-based identity a regulatory requirement, not a feature.
- BIDUA's own auth volume across divisions is projected at 100M+ logins/year by 2028 — already a meaningful captive scale.
How it works, end to end.
OBIDUA code
A device-bound cryptographic credential anchored to a hardware key (TPM, Secure Enclave, mobile keystore). Replaces passwords and OTPs across all BIDUA properties.
Aadhaar + India Stack
Initial identity proofing via Aadhaar e-KYC and DigiLocker. UPI handle and mobile number as recoverable identifiers. DPDP Act-aligned consent framework.
SSO across BIDUA
Single sign-on for all BIDUA divisions — log in once, access Naploo, FinWault, Virtual RDP, BIDUA Beauty without re-authenticating.
Developer SDK
Drop-in SDKs for web, iOS, Android. Open standards (OIDC, SAML, WebAuthn) so third-party integration takes hours, not weeks.
Third-party CIAM
Once proven internally, OBIDUA is licensed to external Indian fintechs, healthtechs and SMBs as a managed CIAM service — priced for the Indian market.
Three compounding phases.
Internal rollout
- Cost-avoidance across BIDUA divisions (replacing Auth0/Cognito)
- Reduced fraud losses
- Internal SLAs and chargeback to divisions
Third-party launch
- Per-MAU CIAM pricing
- Enterprise SSO contracts
- Compliance & audit packs (DPDP, RBI)
- Premium fraud-signal feed
Platform
- Government and BFSI tier contracts
- Identity verification API (KYC-as-a-service)
- Risk scoring & adaptive auth
- International expansion (Southeast Asia, GCC)
Patient cadence, deliberate steps.
-
Q3 2027Architecture and threat model finalised. External security audit of design.
-
Q1 2028Internal alpha on FinWault — the highest-stakes BIDUA division.
-
Q3 2028Rollout across Naploo, BIDUA Beauty, Virtual RDP. Full SSO live.
-
Q2 2029Developer SDK and third-party CIAM pilots with 5 Indian fintech partners.
-
2030GA for third parties. Compliance packs for DPDP and RBI ready out of the box.
-
2031BFSI and government tier launches. International expansion scoped.
Who else is here — and why we're different.
- Passwordless by default — no OTP, no SMS, no password reset flow.
- India-native — Aadhaar, DigiLocker, UPI as first-class identifiers.
- Battle-tested inside BIDUA before external sale — proven at meaningful scale.
- Built on open standards (FIDO2, OIDC) — no vendor lock-in for licensees.
What can go wrong — and how we plan for it.
Cryptographic implementation bugs
Mitigation: External pen-test before every release. Bug-bounty programme. Open-spec design reviewed by independent auditors.
Aadhaar regulation changes
Mitigation: Aadhaar as one of several identity sources, not the only one. Mobile and DigiLocker provide redundancy.
Device-loss recovery UX
Mitigation: Multi-device passkey sync. Aadhaar / DigiLocker re-bootstrap path. Account recovery with cooling-off period.
Slow third-party adoption
Mitigation: Aggressive India-pricing. Free tier up to 10K MAU. Migration tooling from Auth0/Cognito.
Hyperscaler bundling pressure
Mitigation: Compete on India-context, regulatory specificity and price. Bundle with BIDUA Hosting for stickier accounts.
Connected BIDUA divisions.
Every BIDUA bet feeds something else in the group. This one connects to:
FinWault
Highest-stakes internal customer — payments and credit need strongest auth.
finwault.comBIDUA Hosting
Bundled identity-aware access layer for BIDUA Hosting and Virtual RDP.
biduahosting.comPersistIP
Network-layer integration for zero-trust access — OBIDUA on the auth side, PersistIP on the network side.
ip.bidua.inQuestions partners and investors actually ask.
Is OBIDUA just an SSO?
It is SSO, plus passwordless auth, plus identity verification, plus a fraud-signal layer. SSO is the surface; the substance is the entire identity stack.
How does it compare to Auth0?
Comparable feature set on the core, deeper integration with Indian identity rails, priced for the Indian market, no vendor lock-in.
What if I lose my phone?
Multi-device sync via passkeys. If all devices are lost, Aadhaar + DigiLocker re-bootstrap kicks in with a mandatory cooling-off period for security.
Is Aadhaar required?
Required for high-assurance flows (banking, government). Optional for general consumer login — UPI handle or verified mobile is sufficient.
Will I be locked into BIDUA?
No. OBIDUA is built on open standards (OIDC, SAML, FIDO2). Exporting users to another provider is supported by design.
How much does it cost for a third party?
Free up to 10K MAU. Tiered pricing above — significantly below Auth0/Okta Indian list prices.
Is it RBI compliant?
Designed to meet RBI's digital authentication guidelines, DPDP Act and the upcoming CERT-In auth norms. We publish a compliance pack with every release.
Replace passwords across your stack.
We are looking for 5 Indian fintech and healthtech partners to pilot OBIDUA in 2029. Free for the first 12 months, with co-design input into the product roadmap.