What this integration does
SenseCrypt acts as an external identity provider (IdP) for Ping Identity. Ping Identity supports OIDC and SAML federation. It can trust SenseCrypt as an upstream provider. SenseCrypt then handles the sign in with face login. Ping Identity issues its own session to your applications.
- SenseCrypt is the upstream identity provider (IdP).
- Ping Identity is the federation hub.
- The link uses OIDC or SAML 2.0, not a proprietary connector.
- Users sign in with face login.
How the standards flow works
You add SenseCrypt as an external provider in Ping Identity. For OIDC, Ping Identity reads the SenseCrypt discovery URL. For SAML, Ping Identity imports the SenseCrypt metadata file. Ping Identity redirects users to SenseCrypt to sign in. SenseCrypt returns a signed token or assertion.
- SenseCrypt publishes an OIDC discovery URL.
- SenseCrypt publishes a SAML 2.0 metadata file.
- Ping Identity trusts the SenseCrypt signing key.
- Ping Identity maps the SenseCrypt claims to its users.
Setup steps
You choose OIDC or SAML for the link. You add SenseCrypt as an external identity provider (IdP). You paste the discovery URL or import the metadata file. The face match runs on-device during sign in. SenseCrypt stores no biometric data on the server.
- Pick OIDC or SAML 2.0 for the link.
- Add SenseCrypt as an external provider in Ping Identity.
- Paste the SenseCrypt discovery URL for OIDC.
- Import the SenseCrypt metadata file for SAML.
- Map the SenseCrypt claims to your directory.
- Test the sign in flow.
What you get
Your Ping Identity users get passwordless sign in. Face login uses no password and no shared code at sign in. Each sign in binds to the device. This binding makes the flow phishing-resistant. You keep your Ping Identity policies and applications. You add face login at the front of the flow.
- Passwordless sign in through Ping Identity.
- Phishing-resistant authentication with no password or shared code to enter at sign in.
- On-device face match keeps biometric data off the server.
- Standards-based federation with OIDC or SAML 2.0.
Frequently asked questions
Does this integration use a proprietary Ping connector?
No. SenseCrypt federates through standard OIDC or SAML 2.0. Ping Identity reads a discovery URL or metadata file. This is standards-based federation.
Is SenseCrypt a partner of Ping Identity?
This page describes standards-based federation only. SenseCrypt connects to Ping Identity through open standards. It claims no partnership or certification with Ping Identity.
Where does the face match run?
The face match runs on-device. SenseCrypt stores no biometric data on the server. It uses patent-pending face tokenization.
Which protocols can I use for the link?
You can use OpenID Connect or SAML 2.0. SenseCrypt also supports OAuth 2.0, SCIM 2.0, and CIBA.
Related