One App, Two Worlds of Identity
On August 25, 2026, Japan's Digital Agency retired the split between Mynaportal — the app for filing government paperwork — and the standalone Digital Authentication App, folding both into a single "Myna App" (マイナアプリ). Existing Mynaportal users got the merge as a background update; anyone still on the old Digital Authentication App is now redirected into the unified app whenever they try to sign in or sign a document (Digital Agency, July 28, 2026).
The practical change is bigger than a UI cleanup. The same My Number Card credential — read via NFC into a smartphone and unlocked with a PIN or the phone's own biometric lock — now authenticates a citizen renewing a driver's license and a customer opening a brokerage account or completing an online retail purchase (ID Tech; News On Japan). Japan has offered this bridge into private-sector verification since 2016, when the Act on Public Personal Authentication was amended to let approved businesses tap the same certificate infrastructure — but it lived in a separate app most people never opened. Merging it into the portal citizens already use for tax filings and vaccination records is a deliberate default-adoption push, backed by a card base that had reached 81.2% of the population by the end of January 2026 (BCN+R).
The Case For It
The strongest argument for pushing everyone toward one chip-based, PIN-protected credential is that Japan's current private-sector identity-verification landscape is demonstrably leaky. The Personal Information Protection Commission's FY2024 annual report — covering the year to March 2025 — logged 19,056 data-leak reports from private businesses, a 57% jump and the highest since reporting began in 2017, plus 1,951 reports from public bodies, up 68%, mostly clerical errors like misdirected mail (PPC annual report). Of the 2,052 incidents specifically involving My Number data, 1,726 traced to a single vendor, MKSystem — a reminder that fragmenting identity verification across many private eKYC providers multiplies the number of places a leak can originate, not just the number of options consumers have. A single, cryptographically signed, tamper-resistant chip credential — verified in person at a municipal counter when the card is issued — is a plausible upgrade over the photo-ID-plus-selfie method that dominates online onboarding today and is comparatively easy to spoof with synthetic images. Consolidating two apps into one also removes a genuine UX failure: forcing citizens to discover, download, and configure a second app for private-sector use suppressed adoption of the more secure option in favor of whatever a bank's own scan-and-selfie flow offered.
The Risk Worth Naming
But collapsing public and private identity verification into one rail concentrates risk in ways a pro-innovation, security-conscious reader should not wave away. First, a competition concern: Japan hosts a real market of private eKYC vendors competing on onboarding speed, fraud-detection tooling, and price. As the Digital Agency's certificate service becomes the low-friction default embedded in an app most citizens already have, businesses have less reason to invest in differentiated verification products — narrowing a market to a single government-run utility is rarely how the best fraud-detection technology gets built. Second, a systemic-risk concern: previously, a Digital Authentication App outage or credential compromise was contained to whichever private services relied on it; a Mynaportal problem stayed within government services. One merged app means one outage or one compromised credential now touches both simultaneously — a single point of failure across two domains that used to fail independently. Norway offers a live illustration of what that looks like at scale: a DDoS attack that began August 24, 2026 against Digdir's IT partner Vivicta knocked out ID-porten, the login gateway behind more than 4.5 million Norwegians' access to banking, health records, and e-prescriptions, for over 30 hours — the third such incident since June (The Record). Japan is not Norway, and Myna App's local-device biometric lock adds a layer ID-porten's browser-based flow lacks — but the architectural lesson is the same: when one login gateway spans government and commerce, its downtime or breach radius grows with it.
The Proportionate Path
None of this argues against the merger — a harder-to-spoof, chip-based credential replacing selfie uploads is a genuine security upgrade, and giving citizens one app instead of two is basic product sense. But the Digital Agency should treat this as infrastructure that now carries systemic weight: publish uptime and incident-response commitments comparable to critical infrastructure, keep the underlying Digital Certificate Service API open so private eKYC vendors can build fraud-detection layers on top of the credential rather than being displaced by it, and resist any future move — mirroring the phase-out debate already underway around lower-security "photo ID plus selfie" onboarding methods under the Act on Prevention of Transfer of Criminal Proceeds — toward making the government credential the only legally acceptable path. A single strong option beats a single mandatory one.