Greater Boston Area, MA

Shachindra Tiwari

Senior Principal Engineer & IAM Architect

Specializing in Native Protocol Engineering (OAuth 2.1, OIDC, SAML), Agent-to-Agent (A2A) Auth, Non-Human Identities (NHI), FIDO Passkeys, and MCP Integrations.

About

Core IAM systems. Native protocols. Trusted AI agents.

With 16+ years of engineering leadership, I build high-scale core native software stacks for enterprise SSO/MFA and pioneer next-generation authentication—OAuth 2.1, Agent-to-Agent (A2A) authorization, Non-Human Identities (NHI), Passkeys, and W3C Verifiable Credentials. I also design secure Model Context Protocol (MCP) infrastructure so AI agents can act with least-privilege, auditable access. My focus is protocol-correct identity systems that scale under real enterprise load.

Experience

16+ Years Experience

Domain

Core IAM & Security Protocol Architect

Leadership

Full-Stack & AI Systems Leader

Experience

Career timeline across core IAM, SaaS, and systems engineering.

From healthcare and enterprise platforms to native OAuth/OIDC/SAML, A2A/NHI, Passkeys, VCs, and MCP.

RS

RSA Security

Senior Principal Software Engineer & Team Lead / Scrum Master

Jan 2023 — Present

Greater Boston Area, MA

Leading core IAM systems architecture across native OAuth 2.1, A2A/NHI governance, MCP security for LLM agents, and passwordless credentials.

SI

Socure Inc.

Staff Software Engineer

May 2022 — Jan 2023

Remote

Designed authentication stack and high-throughput microservices for Identity Verification workloads.

RS

RSA Security

Principal Software Engineer

2014 — May 2022

Greater Boston Area, MA

Core protocol developer for native cloud SAML/OIDC MFA services, MyPage SaaS, and Rhapsody SSO.

H

Hewlett-Packard

System Software Engineer

2010 — 2013

On-site

Engineered system software components and platform services supporting enterprise product lines.

GH

GE Healthcare

Design Engineer

2008 — 2010

On-site

Contributed design and engineering work for healthcare technology systems with a focus on quality and compliance.

Projects

Architectures in native IAM, A2A/NHI, and agent security.

Selected systems spanning OAuth 2.1, FIDO/Passkeys, Agent-to-Agent auth, Non-Human Identities, MCP gateways, and Verifiable Credentials.

Native OAuth 2.1 & FIDO Engine

Native passwordless identity provider with OAuth 2.1, PKCE, refresh token rotation, and FIDO2/Passkeys support.

  • Native OAuth 2.1 authorization server
  • PKCE + refresh token rotation
  • Passkeys / WebAuthn enrollment & assertion
OAuth 2.1FIDO2OIDCJavaSpring Boot

Agent-to-Agent (A2A) & NHI IAM Framework

Authorization protocol for autonomous AI agent delegation and Non-Human Identity (machine identity) governance.

  • A2A authorization & delegation flows
  • Non-Human Identity (NHI) lifecycle controls
  • Least-privilege agent policy surfaces
A2ANHIOAuthTypeScriptPolicy

Model Context Protocol (MCP) Identity Gateway

Secure MCP server enabling LLM agents to perform authorized enterprise tasks with auditable identity context.

  • MCP tool/server integration for LLM agents
  • Scoped, auditable enterprise actions
  • Identity-aware agent tool gateway
MCPNode.jsTypeScriptOAuthLLM APIs

W3C Verifiable Credentials Issuer/Verifier

Decentralized digital credential verification engine for issuing, presenting, and verifying W3C VCs.

  • VC issuance & presentation flows
  • Verifier trust and revocation hooks
  • Interop-focused credential formats
W3C VCsOIDCCryptographyNode.js

Tech Stack

Native IAM protocols, next-gen AI security, and full-stack delivery.

From OAuth/OIDC/SAML and FIDO to A2A, NHI, MCP, and cloud-native platforms.

Core IAM Protocols

  • OAuth 2.1 / 2.0
  • OIDC Core Provider
  • SAML 2.0 IdP/SP
  • FIDO2 / WebAuthn
  • Passkeys
  • W3C Verifiable Credentials

Contact

Let's talk native IAM, A2A/NHI, and MCP security.

Open to principal conversations, architecture reviews, and collaborations on core identity protocols and AI agent authorization.