Integration

Federate SenseCrypt with Ping Identity

SenseCrypt federates with Ping Identity through open standards. It uses OpenID Connect and SAML 2.0, not a proprietary connector. Ping Identity supports both protocols as a federation hub. Users then sign in with face login.

On this page
  1. What this integration does
  2. What Ping Identity needs from SenseCrypt
  3. Setup steps
  4. What you get
  5. Frequently asked questions

What this integration does

Ping Identity acts as the federation hub and SenseCrypt sits upstream of it as an external identity provider. Ping still issues the session your applications consume and still holds the directory, the policies and the audit history.

What SenseCrypt takes over is the moment of proof. The user looks at the camera on a device bound to them, and a signed token or assertion comes back to Ping. Nothing proprietary is involved: Ping has accepted upstream federation over OIDC and SAML 2.0 for a long time, and this is that.

Ping stays the hub

Applications keep pointing at Ping and Ping keeps issuing their sessions. SenseCrypt never becomes something your app inventory depends on.

SenseCrypt is the upstream provider

Ping redirects to SenseCrypt, the face ceremony runs on the enrolled device, and Ping maps the returned claims onto its own user record.

One protocol, your choice

OIDC or SAML 2.0. Pick whichever your Ping estate already runs, because the ceremony on the device does not change with the wire format.

Add it to one connection first

Upstream federation is configured per connection, so you can route a single application or a pilot group and leave the rest of the estate alone.

What Ping Identity needs from SenseCrypt

Ping needs two things to trust SenseCrypt: an endpoint to send users to, and a key to verify what comes back. Both are published, so there is no secret to exchange out of band.

After that the work is claim mapping, and it deserves care. Ping builds its own session from whatever you map, so an identifier that shifts when a user changes email will show up as account drift months later.

OIDC: the discovery document

One URL gives Ping the authorization and token endpoints and the signing keys, and it keeps working across key rotation without an admin touching anything.

SAML 2.0: the metadata file

Import the SenseCrypt IdP metadata into Ping and hand Ping's service provider metadata back. Every assertion SenseCrypt issues is signed.

Claims to map

Standard OIDC claims or SAML attributes, plus the roles and permissions SenseCrypt computes. Ping maps them onto its users, and your applications enforce what they allow.

What never crosses

No face image and no face template leaves the device. A single-use face token is what moves, and it is worthless the moment it is spent.

Setup steps

All of this happens in the Ping administration console and the SenseCrypt console. Nothing is deployed, so your risk here is configuration rather than infrastructure.

Do the first sign in with a test identity and a real phone, then look at what Ping actually recorded about that user. Mapping mistakes surface there and nowhere earlier.

  • Decide on OIDC or SAML 2.0 for the link.
  • Register Ping Identity as a relying party in the SenseCrypt console.
  • Add SenseCrypt as an external provider in Ping Identity.
  • Paste the SenseCrypt discovery URL for OIDC, or import the metadata file for SAML 2.0.
  • Map the SenseCrypt claims onto your Ping directory attributes.
  • Enroll a test user and run one face login end to end.

What you get

Your Ping policies, applications and reporting all survive, and the front of the flow becomes a face check with no secret in it. That is the point of putting SenseCrypt upstream instead of replacing anything.

It is also the cheapest way to find out whether face login suits your users, because undoing it means removing a connection.

Phishing has nothing to take

Sign in uses no password and no shared code. A one-time PIN is used once in the lifecycle, to bind a new device, sent by email and also by SMS when a mobile number is on file.

Liveness is certified, recognition is evaluated

Liveness holds iBeta ISO 30107-3 certification at Level 1 and Level 2, which covers presentation attacks at the camera such as a printed photo or a mask. Face recognition entered the NIST evaluation in 2021, then FRVT and later split into FRTE and FATE, and we maintain it through our latest submissions.

Reversible by design

Federation is a connection. If face login does not fit a group, remove the routing and they are back on the previous method with nothing to migrate.

What it costs

One dollar per user per month with a 20-seat minimum. Signing-key custody in KMS adds twenty dollars per key per month, and each tenant or custom domain past the first three is ten dollars per month. The 30-day trial takes no card.

Frequently asked questions

Does this integration use a proprietary Ping connector?

No. SenseCrypt federates through standard OIDC or SAML 2.0. Ping Identity reads a discovery URL or metadata file. This is standards-based federation.

Is SenseCrypt a partner of Ping Identity?

This page describes standards-based federation only. SenseCrypt connects to Ping Identity through open standards. It claims no partnership or certification with Ping Identity.

Where does the face match run?

The face match runs on-device. SenseCrypt keeps no face image and no face template on the server. It uses patent-pending face tokenization.

Which protocols can I use for the link?

You can use OpenID Connect or SAML 2.0. SenseCrypt also supports OAuth 2.0, SCIM 2.0, and CIBA.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.