On this page
What SenseCrypt adds
Both vendors put a face in front of the sign-in, so that checkbox tells you nothing. The useful question is the shape of the system around the face: where the comparison runs, what the server still holds after enrollment, and whether the biometric is the front door or a layer bolted onto one.
SenseCrypt is the identity provider itself. Your applications get tokens from it over the same protocols they would use with any other IdP, and the face ceremony is how a user proves they are there.
The match runs on the user's phone
Capture and comparison both stay on the device. The server holds no face image and no face template, so there is no gallery for an attacker to take and none for you to defend in an audit.
Every sign-in spends a face token
The token is single-use, so recorded traffic replays into a rejection. The tokenization is patent-pending.
The user has nothing to type
No password, no code read off a screen or out of a text message. A convincing fake login page has nothing to collect, and that is what makes the flow phishing-resistant rather than merely quick.
Standards ship with it, not beside it
OIDC and OAuth 2.0 with PKCE and PAR, SAML 2.0, SCIM 2.0, and CIBA come from the same product that runs the face ceremony. You do not keep a biometric service and an IdP in step with each other.
Where each fits
authID has been selling into this market longer than we have, and it reaches across more of the identity lifecycle: proving who a new user is at onboarding, then authenticating that user later. If your hard problem is establishing identity from scratch on day one, that breadth is worth paying for.
SenseCrypt does not do identity proofing. It takes the sign-in moment and does it one way, for everybody, with nothing softer behind it.
authID reaches further up the lifecycle
Verification and authentication under one vendor relationship saves real work during onboarding. Ask which modules your quote actually covers, because packaging differs by plan.
SenseCrypt is narrow on purpose
One method, hardened, with no password path left behind it to undo the result. That is a strength when phishing is your live risk and a constraint when it is not.
Federate instead of migrating
SenseCrypt connects to your current identity provider as an external IdP over OIDC or SAML. Your directory, your policy, and your application integrations stay where they are.
Roles are emitted, your app enforces them
SenseCrypt puts roles and permissions in the token and your application decides what they allow. SenseCrypt itself enforces a default-closed group gate at sign-in and capability checks on the admin console routes.
The questions that separate them
You will learn more from four questions than from any feature grid, ours included. Send the same list to both vendors and hold out for specific answers instead of category words.
Here are ours, written the way we would say them on a call.
Where does the face match run
On the device, or in the vendor cloud. That one answer sets the blast radius of a breach. SenseCrypt matches on the device, so no face image travels anywhere to be compared.
What is left on the server after enrollment
Ask for a list, not a reassurance. SenseCrypt keeps no face image and no face template. A sealed face token is persisted, and we would rather name that than round it down to nothing.
What does a captured session buy an attacker
The SenseCrypt face token is single-use, so a replay arrives dead. Put the same question to any vendor whose flow carries a credential that can be used twice.
How does a user get back in
A strong front door counts for little if the recovery path is softer. SenseCrypt has no password to reset. A one-time PIN appears once in the lifecycle, when a user binds a new device, sent by email and also by SMS when a mobile number is on file. It is never part of a normal sign-in.
Standards, controls, and pricing in SenseCrypt
List price is one dollar per user per month on a 20-seat minimum. Treat that as the starting line and not the bill: signing-key custody in KMS costs twenty dollars per key per month, and each tenant or custom domain past the first three adds ten dollars per month. Customer identity deployments bill on monthly active users, not on every account ever registered.
The trial runs 30 days and asks for no card. What follows is what the product carries inside it.
- Protocols: OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 for provisioning, and CIBA
- CIBA: the backchannel push starts a device-bound face ceremony, not a tap to approve
- Controls: roles and permissions in the token, multi-tenant isolation, and audit logs
- Liveness: iBeta ISO 30107-3 certified at Level 1 and Level 2, which covers presentation attacks at the camera; app attestation and device authenticity checks block virtual-camera and SDK injection
- Face recognition: entered the NIST evaluation in 2021 (then FRVT, later split into FRTE and FATE), maintained through our latest submissions
SenseCrypt and authID across common identity dimensions.
| Dimension | SenseCrypt | authID |
|---|---|---|
| Primary sign-in method | Passwordless face login | Varies by plan |
| Biometric data on server | None; face matching on-device | Varies by plan |
| Open standards | OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, CIBA | Supported |
| Phishing-resistant by design | Yes; no password or shared code to enter | Varies by plan |
| Pricing model | One dollar per user per month (20-seat minimum) | Varies by plan |
Frequently asked questions
How does SenseCrypt compare to authID?
Both products use face biometrics. authID is an established provider of biometric and passwordless authentication. SenseCrypt is a full identity provider that adds passwordless face login and the OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, and CIBA standards.
Where does SenseCrypt store the face data?
SenseCrypt matches the face on the device. The server stores no face image and no face template. It uses a single-use face token with patent-pending tokenization.
Is SenseCrypt phishing-resistant?
Yes. The sign-in asks for no password and no shared code to enter. It binds the sign-in to the device.
What does SenseCrypt cost?
SenseCrypt costs one dollar per user per month, with a 20-seat minimum. It offers a 30-day free trial with no card.
Related