Service · Software development

Custom CIAM platform development.

A Customer Identity & Access Management platform that fits your customer journeys, your brand and your integrations. For B2C brands, B2B SaaS, banks and insurers who want more than what Auth0 or Microsoft Entra External ID offers out of the box.

CIAMKeycloakNL Wallet & EUDIiDIN & DigiDOpenID Connect

CIAM is not IAM.

IAM (Identity & Access Management) manages identities within your organisation: employees, Active Directory, SSO to Microsoft 365 and Salesforce. CIAM manages identities outside it: customers, citizens, partners. The numbers are many times larger, the UX requirements are much stricter, the regulation works differently, and the brand plays a part. A customer who forgets their password is a lost conversion, not an internal helpdesk ticket. A 401 error during checkout costs you revenue; a 401 on the employee VPN only costs you a Slack message.

The term Customer Identity today covers very different worlds: a loyalty account for a retailer, a customer portal for an insurer with BSN integration, a SaaS product that lets enterprise customers federate via SAML, a media service with a paywall and subscriptions, a fintech app with strong customer authentication. What they have in common: identity is not an internal department, it is a product feature with a direct impact on conversion, retention and compliance.

We have been building custom CIAM platforms since 2015 for organisations where off-the-shelf SaaS CIAM (Auth0, ForgeRock, Microsoft Entra External ID, Amazon Cognito, FusionAuth, Ping Identity) does not go far enough. Often based on Keycloak with a custom UX layer, sometimes fully built from scratch. Always integrated into your existing architecture and, where relevant, connected to Dutch identity schemes such as iDIN, DigiD, eHerkenning or the NL Wallet.

Three types of CIAM project.

The scope of a CIAM project depends on the type of identity, the number of connected systems and the regulatory framework. We work within three patterns; in an initial conversation we determine which pattern suits your situation.

Compact project · Keycloak base with custom UX

B2C CIAM for brands and retailers

A customer account for your brand: registration, login (password, social login, magic link, passkey/WebAuthn), self-service profile and order history. Integrated with your CDP, e-commerce platform and marketing tools. Your customers see your brand, not a generic Auth0 pop-up. Progressive profiling spreads data collection across several visits so you are not asking for everything at registration, which is better for conversion and for compliance.

Social loginPasskey/WebAuthnProgressive profilingLoyalty integration
Mid-sized project · multi-tenant architecture

B2B SaaS CIAM with federated identity

Organisation accounts with multiple users, roles and permissions. Customers bring their own identity provider (Azure AD, Okta, Google Workspace) via SAML or OIDC. Self-service onboarding for new tenants, automatic provisioning via SCIM, and an admin console where your customer success team can resolve tenant issues without developer involvement. Suited to SaaS vendors growing towards enterprise customers, similar to our vendor portal builds, but for your end customers.

Multi-tenantSAML/OIDC federationSCIM provisioningRBAC + ABAC
Larger project · regulated industries

CIAM for banks, insurers and healthcare

High-assurance identity for customer portals in regulated sectors. iDIN, DigiD and eHerkenning for strong verification, BSN integration where legally permitted, KYC integration, audit logging in line with DNB/AFM and NEN 7510. Prepared for the EUDI Wallet and eIDAS 2.0, with OpenID for Verifiable Presentations (OpenID4VP) and SD-JWT credentials. Step-up authentication for high-risk transactions: a customer logs in lightly to view information, but must identify again via iDIN to make a change.

iDIN & DigiDEUDI WalletKYC/AMLRisk-based auth

The features that make up a CIAM platform.

A complete CIAM platform combines authentication, authorisation, account management, consent and risk detection. We do not implement all of them by default; for each project we choose which are needed now and which can come later.

Authentication

Login methods

Password, social login (Google, Apple, Facebook, LinkedIn, Microsoft), email magic link, SMS OTP, passkey/WebAuthn, hardware keys (YubiKey, FIDO2), iDIN, DigiD, eHerkenning. For each user segment we select which methods are offered.

MFA

Multi-factor authentication

TOTP via authenticator apps, SMS OTP, push notifications, biometrics via mobile SDK, hardware keys. Risk-based: MFA is enforced when suspicious signals appear, not on every login, since the latter hurts conversion without adding security.

Account management

Self-service for the customer

Edit profile, password reset, MFA settings, linked devices, revoke sessions, delete account (GDPR right), export data (data portability). All in your house style, without your customer service team having to handle every request manually.

Authorisation

RBAC, ABAC and relationships

Role-based access control for simple role models. Attribute-based for situations where context decides (location, time, transaction amount). Relationship-based for B2B tenants where permissions follow organisation membership. Built on Open Policy Agent or your own policy engine.

Consent & privacy

Consent management under GDPR

Granular consent per processing purpose, version control of privacy statements (who accepted what and when), cookie consent integration, channel preferences. APIs for access, correction and erasure requests so that your DPO doesn't have to search for them manually in databases.

Risk detection

Fraud signals and suspicious login detection

Impossible-travel detection, device fingerprinting, velocity checks, IP reputation, behaviour analysis. Connectable to your existing fraud engine or vendors such as Sift, Castle or Auth0 Adaptive MFA. Signals lead to step-up or blocking, not automatically to lockout.

What you get at the end.

A production-ready CIAM platform that connects to your applications, plus the operational foundation to run it yourself or have us manage it for you.

  • The CIAM platform itselfProduction and staging environments, running in your cloud (GCP, AWS or Azure) or with us. Containerised with Docker, monitored and auto-scaling where needed.
  • Branded login and account UXLogin, registration, MFA setup, account management and password reset in your own brand identity, with no generic vendor pop-ups.
  • SDKs and integration librariesClient libraries for your web, mobile and backend applications. OAuth2/OIDC compatible so external tools can connect easily.
  • Admin console and documentationFor your IT team: manage roles, export user data (GDPR requests), review the audit log, configure federation.
  • Penetration test report and security baselineExternal penetration test in the final sprint, plus a baseline configuration for rate limiting, bot protection and suspicious login detection.
  • Managed service contract (optional)Monitoring, security patches, ongoing development. Fixed monthly fee, with four response time levels matched to the criticality of your login flow.
Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

When custom CIAM makes sense.

We actively recommend standard CIAM platforms (Auth0, Microsoft Entra External ID, Amazon Cognito, FusionAuth, Ping Identity) ourselves where they fit. Custom makes sense in these patterns.

Dutch identity

iDIN, DigiD, eHerkenning, NL Wallet

You need strong customer verification with Dutch identity sources. Standard SaaS CIAM often doesn't support these, or only superficially. Custom lets you integrate iDIN or DigiD onboarding deeply into your flow.

EUDI and eIDAS 2.0

Ready for the EU Digital Identity Wallet

With eIDAS 2.0 (mandatory for member states from 2026), the EUDI Wallet is on its way. Verifiable credentials, OpenID4VP and SD-JWT are standards that most off-the-shelf CIAM platforms are not yet ready for.

Sector-specific flows

Banking, insurance, healthcare

Risk-based authentication connected to your fraud engine, BSN (citizen service number) processing under a legal basis, AFM/DNB audit requirements, NEN 7510 for healthcare. Standard CIAM covers 80%, and the last 20% costs more than a custom solution. Often combined with KYC and AML compliance software in the same stack.

Deep integration with core systems

Core banking, EHR, ERP, CDP

The identity layer needs to communicate bi-directionally with your core systems: profile changes, consent updates, segmentation. With standard CIAM you pay per API call and remain vulnerable to rate limits.

White-label CIAM

Identity-as-a-service for your partners

You provide a platform yourself and your partners want to bring their customers onto it. Multi-tenant, white-label, with each tenant having its own branding, federation configuration and consent regime. Related to our work on an employee portal and the broader vendor portal work, but focused on customer identities.

Scale or vendor lock-in

Costs rise, control diminishes

You grow into millions of identities and the vendor pricing scales with them, often faster than your revenue. Or you want to stop depending on a single supplier for such a critical component. Keycloak custom or from-scratch gives that control back to you.

How a CIAM project runs.

A CIAM build isn't a feature you slot in alongside existing work; it touches every application that talks to customers. We work in five phases: first understand, then scope, then build, then migrate, then operate.

1

Introduction and architecture scan

A conversation to map your current identity situation: which applications need to connect, which identity providers are in use, where customer data lives today, and which compliance requirements apply. No sales pitch, just sharp questions.

2

Scope and threat model

A workshop with your team plus interviews with security and compliance. We deliver a threat model, a data flow diagram and a concrete scope: which flows go into the MVP, which come later, and which a standard CIAM product could handle better. We often cut things here that don't need to be built.

3

Building in sprints

A working build on staging every two weeks. We usually start with the most painful flow (registration, login and MFA), so you can test real usage quickly. An external penetration test runs in parallel during the final sprints, not as an afterthought.

4

Migration and rollout

The existing user base is migrated with zero disruption: password hashes are carried over, password rotation happens at the next login rather than through a bulk reset, and the rollout is phased by segment or brand.

5

Operations and ongoing development

Ongoing management after go-live: security patches, monitoring, dependency updates and audit log reviews. Plus continued development: adding new identity sources (the NL Wallet is on its way), expanding MFA methods and onboarding B2B tenants.

Frequently asked questions.

What clients usually want to know before we start.

What is the difference between CIAM and IAM?
IAM (Identity & Access Management) is about employees within your organisation, such as Active Directory, Okta Workforce, Microsoft Entra ID, and single sign-on to internal SaaS tools. CIAM (Customer Identity & Access Management) is about identities outside your organisation: customers, citizens and partners. The volumes are larger, the UX requirements stricter, the brand plays a role, and regulation (GDPR, sector-specific rules) works differently. Tools that excel at IAM (Okta Workforce, Microsoft Entra ID) aren't automatically suited to CIAM, and vice versa.
Do you replace Auth0, Okta or Microsoft Entra External ID?
For standard B2C or B2B flows we often actually recommend those platforms. Auth0, ForgeRock, Microsoft Entra External ID, Amazon Cognito, Ping Identity, FusionAuth and SuperTokens are mature products. We come in once you hit their limits: sector-specific flows (banking, healthcare with BSN), Dutch identities (iDIN, DigiD), the EUDI Wallet, white-label CIAM for partners, or deep integration with core systems that standard CIAM rate limits can't handle.
Do you work with Keycloak?
Yes, often. Keycloak is open source, OpenID Connect-compatible, scalable, and gives you full control over the data layer. We usually build a custom UX layer on top of Keycloak instead of using the bundled theme, which rarely meets modern CIAM requirements. For B2B multi-tenant we configure Keycloak realms strategically; for B2C we often build a dedicated account front end that talks to Keycloak via OIDC. We only build fully from scratch if Keycloak really doesn't fit.
How do you handle the NL Wallet, iDIN and EUDI?
We integrate iDIN via the Currence integration, with the right step-up flow so you don't force a bank login on every sign-in. DigiD and eHerkenning require a Logius connection via a routing provider. We handle the technical part; your organisation must apply for the legal connection itself. For EUDI and the NL Wallet we build on OpenID for Verifiable Presentations (OpenID4VP) and SD-JWT credentials. The ecosystem moves quickly; we build architecture that moves with it.
How about GDPR, consent and data sovereignty?
A CIAM platform carries significant GDPR obligations: you process personal data, receive access, correction and erasure requests, and must maintain a consent administration. We build consent management in as standard, including version control of privacy statements, granular consent per purpose, and APIs for data portability. Data residency within the EU/NL is handled through your choice of cloud provider (GCP europe-west, AWS eu-central, Azure West Europe or a Dutch hosting provider). A DPIA is included in the scoping phase.
What determines the cost?
The biggest cost factors are: the number and type of identity providers (social login is light, iDIN or DigiD requires more work), the number of connected applications (each SDK integration takes time), the regulatory framework (banking and healthcare require audit trails and penetration tests that other sectors do not), migration of an existing user base, and requirements for branding and UX. After the architecture review, we provide a substantiated range rather than a round figure over the phone.
Can you connect to our existing architecture?
Almost always. A CIAM platform communicates through standards: OIDC, OAuth2, SAML, SCIM, webhooks. We have experience connecting to core banking systems, EHRs, ERPs (SAP, Microsoft Dynamics), CDPs (Segment, Tealium, mParticle), e-commerce platforms (Magento, Shopify Plus, commercetools) and customer service tooling. For specific integration questions we often work together with our smart API integrations page.
What if we want to switch later?
Standards are your safety net. We build on OIDC, OAuth2 and SCIM so that applications connected to your CIAM can move to another platform without being rebuilt. You can export your user data at any time via the admin console. For Keycloak builds, you receive the configuration as infrastructure as code. Avoiding lock-in to our code is an explicit design goal.
How do you handle migrating an existing user base?
We carry over password hashes in their original algorithm (bcrypt, argon2, scrypt, even outdated variants) and upgrade them lazily: at the next successful login, the hash is automatically recalculated using the newer algorithm. This avoids the painful "everyone must reset their password" email, which typically puts 20–40% of your user base into dormant mode. For social identities, we create account-linking records so customers can keep logging in with their existing method.
Do you work only on B2C or also on B2B CIAM?
Both. B2C CIAM (customer accounts, social login, paywalls) and B2B CIAM (organisation tenants, federated identity via SAML, SCIM provisioning) share overlapping foundations but also distinct challenges. We often build platforms that must support both: a retailer with a loyalty brand and a business B2B arm; an insurer with private customers and mandated brokers; a media service with consumer subscribers and licensing clients. We handle the multi-tenant architecture in the foundation.

Talk to us about your CIAM platform.

A no-obligation introductory conversation of half an hour. We listen to your customer flow and the identity sources you are tied to, and give concrete direction, including if the outcome is that a standard CIAM platform is a better fit for you.

Edit content