Compare

SenseCrypt vs Keyless

Keyless is a biometric authentication provider, now part of Ping Identity after an acquisition that closed in January 2026. SenseCrypt is a full identity provider with passwordless face login as the primary sign-in method.

On this page
  1. What SenseCrypt adds
  2. Where each fits
  3. What the Ping acquisition changes for your shortlist
  4. Standards, controls, and pricing in SenseCrypt
  5. Frequently asked questions

What SenseCrypt adds

Both products put a face at the front of the sign-in, so that fact on its own settles nothing. What separates them is the shape of the system around the face: where the comparison runs, what stays on a server after enrollment, and whether the biometric is the whole front door or one method among several.

SenseCrypt is the identity provider itself. Your applications collect tokens from it over the protocols they already speak, and the face ceremony is how a user proves they are present.

The match runs on the user's phone

Capture and comparison both stay on the device. The server holds no face image and no face template, so there is no gallery for an attacker to take and none for you to account for in an audit.

Every sign-in spends a face token

The token is single-use. Record the traffic, replay it, and it fails. The tokenization is patent-pending.

The user has nothing to type

No password, and no code read off a screen or out of a text message. A convincing fake login page has nothing to collect from the user. That is the entire basis of the phishing-resistance claim, and it is why we are willing to make it.

One product, not a biometric wired to an IdP

OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0, and CIBA come from the same service that runs the face ceremony. There is no second vendor to keep in step.

Where each fits

Keyless built its name as an independent vendor of privacy-preserving biometric authentication. Since January 2026 it is part of Ping Identity, so what you are evaluating is a biometric line inside a large enterprise identity platform rather than a company you contract with on its own. That is not a criticism of either party. It does change who answers your questions.

SenseCrypt is smaller and deliberately narrower. One sign-in method, run end to end, with the identity protocols in the same box.

Keyless is now Ping's biometric line

The acquisition closed in January 2026. If face biometrics is why you are in the conversation, ask which Ping plan carries it and how it is packaged, because that answer now comes from Ping.

SenseCrypt is narrow on purpose

One method, hardened, with no password path left behind it to undo the result. That is a strength when phishing is your live risk and a constraint when it is not.

Federate instead of migrating

SenseCrypt connects to your current identity provider as an external IdP over OIDC or SAML. Your directory, your policy, and your application integrations stay exactly where they are.

Roles are emitted, your app enforces them

SenseCrypt writes roles and permissions into the token and your application decides what they allow. SenseCrypt itself runs a default-closed group gate at sign-in and capability checks on the admin console routes.

What the Ping acquisition changes for your shortlist

If your evaluation of Keyless started before January 2026, part of it is out of date. We will not guess at Ping's roadmap or packaging, and you should distrust any vendor page that does. Put the questions to Ping directly and hold out for specific answers.

These are the four we would take into that call. Our own answers are underneath each one, so you can hold us to the same standard.

Which plan carries the biometric line

Packaging inside a large platform is rarely the packaging the standalone product had. Get the module, the tier, and the price in writing before you build a business case on it.

Where does the face match run

On the device, or in a vendor cloud. That one answer sets the blast radius of a breach. SenseCrypt matches on the device, so no face image travels anywhere to be compared.

What is left on the server after enrollment

Ask for a list, not a reassurance. SenseCrypt keeps no face image and no face template. A sealed face token is persisted, and we would rather name that than round it down to nothing.

How does a user get back in

A strong front door counts for little if the recovery path is softer. SenseCrypt has no password to reset. A one-time PIN appears once in the lifecycle, when a user binds a new device, sent by email and also by SMS when a mobile number is on file. It is never part of a normal sign-in.

Standards, controls, and pricing in SenseCrypt

List price is one dollar per user per month on a 20-seat minimum. Read that as the starting line and not the bill: signing-key custody in KMS costs twenty dollars per key per month, and each tenant or custom domain past the first three adds ten dollars per month. Customer identity deployments bill on monthly active users, not on every account ever registered.

The trial runs 30 days and asks for no card. What follows is what the product carries inside it.

  • Protocols: OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, SCIM 2.0 for provisioning, and CIBA
  • CIBA: the backchannel push starts a device-bound face ceremony on the phone, not a tap to approve
  • Controls: roles and permissions in the token, multi-tenant isolation, and audit logs
  • Liveness: iBeta ISO 30107-3 certified at Level 1 and Level 2, which covers presentation attacks at the camera; app attestation and device authenticity checks block virtual-camera and SDK injection
  • Face recognition: entered the NIST evaluation in 2021 (then FRVT, later split into FRTE and FATE), maintained through our latest submissions

SenseCrypt and Keyless across common identity dimensions.

DimensionSenseCryptKeyless
Primary sign-in methodPasswordless face loginVaries by plan
Biometric data on serverNone; face matching on-deviceVaries by plan
Open standardsOIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, CIBASupported
Phishing-resistant by designYes; no password or shared code to enterVaries by plan
Pricing modelOne dollar per user per month (20-seat minimum)Varies by plan

Frequently asked questions

How is SenseCrypt different from Keyless?

Both use face biometrics. Keyless is now Ping Identity's biometric line, after the acquisition closed in January 2026. SenseCrypt is a full identity provider. It adds OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, and CIBA, plus RBAC, multi-tenant isolation, and audit logs.

Where does SenseCrypt store my biometric data?

SenseCrypt stores no face image and no face template. It matches the face on the device and uses a single-use face token.

How much does SenseCrypt cost?

SenseCrypt costs one dollar per user per month, with a 20-seat minimum. There is a 30-day free trial, and you do not need a card.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.