What this integration does
SenseCrypt works as an external identity provider (IdP) for Salesforce. Salesforce stays the platform for your teams and customers. SenseCrypt handles the sign in by face login.
This is standards-based federation. SenseCrypt has no proprietary connector for Salesforce. SenseCrypt has no app-store listing. Salesforce trusts SenseCrypt through open standards only.
- Salesforce sends each sign in to SenseCrypt.
- The user does face login on the device.
- SenseCrypt returns a signed token or assertion to Salesforce.
- Salesforce completes the single sign-on (SSO).
How the standards flow works
SenseCrypt supports SAML 2.0 and OpenID Connect (OIDC). Salesforce acts as the service provider or the relying party. You pick one standard for the trust.
SenseCrypt publishes a metadata file for SAML 2.0. SenseCrypt also publishes an OIDC discovery URL. Salesforce reads the metadata file or the discovery URL. Salesforce then trusts SenseCrypt.
- SAML 2.0 federation uses a signed metadata file.
- OIDC federation uses a discovery URL, PKCE, and PAR.
- SenseCrypt signs each assertion or token.
- Face matching runs on-device.
- SenseCrypt stores no biometric data on the server.
How you set it up
You connect Salesforce to SenseCrypt in a few steps. You use the standard setup screens in both products. You install no custom package.
- Register Salesforce as a relying party in SenseCrypt.
- Copy the SenseCrypt discovery URL or the metadata file for SAML 2.0.
- Add SenseCrypt in the single sign-on settings.
- Map the claims to user fields in Salesforce.
- Set SenseCrypt as the sign in option for your users.
- Enable SCIM 2.0 to provision users if you need it.
- Test one face login from end to end.
What you get
The integration gives your users passwordless single sign-on. The sign in is phishing-resistant by design. The sign in binds to the device.
- Users sign in to Salesforce by face login.
- Salesforce keeps your existing profiles and permissions.
- SenseCrypt liveness holds iBeta ISO 30107-3 certification (L1 and L2).
- SenseCrypt supports customer identity (CIAM) and workforce single sign-on (SSO).
- You pay one dollar per user per month, flat.
- You can start with a 30-day free trial, no card.
Frequently asked questions
Does SenseCrypt have a Salesforce AppExchange connector?
No. SenseCrypt connects to Salesforce through open standards only. You use SAML 2.0 or OIDC with metadata and a discovery URL.
Where does SenseCrypt store biometric data?
SenseCrypt stores no biometric data on the server. Face matching runs on-device. SenseCrypt uses patent-pending face tokenization. A face becomes a single-use face token.
Does SenseCrypt do KYC or identity proofing?
No. SenseCrypt authenticates the enrolled person. It signs in the user who enrolled from a photo on file.
Can SenseCrypt provision Salesforce users?
Yes. SenseCrypt supports SCIM 2.0. You can sync users and groups with Salesforce.
Related