Integration

Add SenseCrypt face login to Okta

SenseCrypt adds face login to Okta through open standards. Okta stays your identity platform. SenseCrypt becomes the external identity provider (IdP) behind each sign in. Users sign in by face login on the device. This is standards-based federation. It is not a proprietary connector.

What this integration does

SenseCrypt works as an external identity provider (IdP) for Okta. Okta stays the identity platform for your apps. SenseCrypt handles the sign in by face login.

This is standards-based federation. SenseCrypt has no proprietary connector for Okta. SenseCrypt has no app-store listing. Okta trusts SenseCrypt through open standards only.

  • Okta sends each sign in to SenseCrypt.
  • The user does face login on the device.
  • SenseCrypt returns a signed token or assertion to Okta.
  • Okta completes the sign in for your apps.

How the standards flow works

SenseCrypt supports OpenID Connect (OIDC) and SAML 2.0. Okta acts as the relying party or the service provider. You pick one standard for the trust.

SenseCrypt publishes an OIDC discovery URL. SenseCrypt also publishes a metadata file for SAML 2.0. Okta reads the discovery URL or the metadata file. Okta then trusts SenseCrypt.

  • OIDC federation uses a discovery URL, PKCE, and PAR.
  • SAML 2.0 federation uses a signed metadata file.
  • SenseCrypt signs each token or assertion.
  • Face matching runs on-device.
  • SenseCrypt stores no biometric data on the server.

How you set it up

You connect Okta to SenseCrypt in a few steps. You use standard configuration screens in both products. You install no custom software.

  • Register Okta as a relying party in SenseCrypt.
  • Copy the SenseCrypt discovery URL or the metadata file for SAML 2.0.
  • Add SenseCrypt in Okta as an external identity provider (IdP).
  • Map the claims to user fields in Okta.
  • Set an Okta routing rule to send users to SenseCrypt.
  • Enable SCIM 2.0 to provision users if you need it.
  • Test one face login from end to end.

What you get

The integration gives your users passwordless sign in. The sign in is phishing-resistant by design. The sign in binds to the device.

  • Users sign in by face login.
  • Okta keeps your existing apps and policies.
  • SenseCrypt liveness holds iBeta ISO 30107-3 certification (L1 and L2).
  • SenseCrypt adds RBAC, multi-tenant isolation, and audit logs.
  • You pay one dollar per user per month, flat.
  • You can start with a 30-day free trial, no card.

Frequently asked questions

Does SenseCrypt have a prebuilt Okta connector?

No. SenseCrypt connects to Okta through open standards only. You use OIDC or SAML 2.0 with metadata and a discovery URL.

Where does SenseCrypt store biometric data?

SenseCrypt stores no biometric data on the server. Face matching runs on-device. SenseCrypt uses patent-pending face tokenization. A face becomes a single-use face token.

Does SenseCrypt replace Okta?

No. Okta stays your identity platform. SenseCrypt works as the external identity provider (IdP) for face login.

Can SenseCrypt provision users with Okta?

Yes. SenseCrypt supports SCIM 2.0. You can sync users and groups with Okta.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.