Greater Boston Area, MA
Shachindra Tiwari
Senior Principal Engineer & IAM Architect
Specializing in Native Protocol Engineering (OAuth 2.1, OIDC, SAML), Agent-to-Agent (A2A) Auth, Non-Human Identities (NHI), FIDO Passkeys, and MCP Integrations.
About
Core IAM systems. Native protocols. Trusted AI agents.
With 16+ years of engineering leadership, I build high-scale core native software stacks for enterprise SSO/MFA and pioneer next-generation authentication—OAuth 2.1, Agent-to-Agent (A2A) authorization, Non-Human Identities (NHI), Passkeys, and W3C Verifiable Credentials. I also design secure Model Context Protocol (MCP) infrastructure so AI agents can act with least-privilege, auditable access. My focus is protocol-correct identity systems that scale under real enterprise load.
Experience
16+ Years Experience
Domain
Core IAM & Security Protocol Architect
Leadership
Full-Stack & AI Systems Leader
Experience
Career timeline across core IAM, SaaS, and systems engineering.
From healthcare and enterprise platforms to native OAuth/OIDC/SAML, A2A/NHI, Passkeys, VCs, and MCP.
RSA Security
Senior Principal Software Engineer & Team Lead / Scrum Master
Jan 2023 — Present
Greater Boston Area, MA
Leading core IAM systems architecture across native OAuth 2.1, A2A/NHI governance, MCP security for LLM agents, and passwordless credentials.
Socure Inc.
Staff Software Engineer
May 2022 — Jan 2023
Remote
Designed authentication stack and high-throughput microservices for Identity Verification workloads.
RSA Security
Principal Software Engineer
2014 — May 2022
Greater Boston Area, MA
Core protocol developer for native cloud SAML/OIDC MFA services, MyPage SaaS, and Rhapsody SSO.
Hewlett-Packard
System Software Engineer
2010 — 2013
On-site
Engineered system software components and platform services supporting enterprise product lines.
GE Healthcare
Design Engineer
2008 — 2010
On-site
Contributed design and engineering work for healthcare technology systems with a focus on quality and compliance.
Projects
Architectures in native IAM, A2A/NHI, and agent security.
Selected systems spanning OAuth 2.1, FIDO/Passkeys, Agent-to-Agent auth, Non-Human Identities, MCP gateways, and Verifiable Credentials.
Native OAuth 2.1 & FIDO Engine
Native passwordless identity provider with OAuth 2.1, PKCE, refresh token rotation, and FIDO2/Passkeys support.
- Native OAuth 2.1 authorization server
- PKCE + refresh token rotation
- Passkeys / WebAuthn enrollment & assertion
Agent-to-Agent (A2A) & NHI IAM Framework
Authorization protocol for autonomous AI agent delegation and Non-Human Identity (machine identity) governance.
- A2A authorization & delegation flows
- Non-Human Identity (NHI) lifecycle controls
- Least-privilege agent policy surfaces
Model Context Protocol (MCP) Identity Gateway
Secure MCP server enabling LLM agents to perform authorized enterprise tasks with auditable identity context.
- MCP tool/server integration for LLM agents
- Scoped, auditable enterprise actions
- Identity-aware agent tool gateway
W3C Verifiable Credentials Issuer/Verifier
Decentralized digital credential verification engine for issuing, presenting, and verifying W3C VCs.
- VC issuance & presentation flows
- Verifier trust and revocation hooks
- Interop-focused credential formats
Tech Stack
Native IAM protocols, next-gen AI security, and full-stack delivery.
From OAuth/OIDC/SAML and FIDO to A2A, NHI, MCP, and cloud-native platforms.
Core IAM Protocols
- OAuth 2.1 / 2.0
- OIDC Core Provider
- SAML 2.0 IdP/SP
- FIDO2 / WebAuthn
- Passkeys
- W3C Verifiable Credentials
Contact
Let's talk native IAM, A2A/NHI, and MCP security.
Open to principal conversations, architecture reviews, and collaborations on core identity protocols and AI agent authorization.