What SenseCrypt adds
Ping is not short of authentication methods, and since the Keyless acquisition closed in January 2026 that list includes a face biometric line of its own. So whether a vendor does face is no longer the question worth asking. Ask instead where the match runs, what the server keeps after enrollment, and what a captured artifact is worth to an attacker.
SenseCrypt answers those three the same way every time, because it only has one sign-in method and nothing sits behind it as a fallback. A user enrolls from a photo already on file, then signs in by looking at the camera.
The match runs on the device
Capture and comparison happen on the user's own phone. The server keeps no face image and no face template, so there is no gallery to breach today or to hand over later.
A token that dies on use
Each sign-in spends a single-use face token, and the token is worthless the moment it is spent. Replaying an intercepted copy gets an attacker nowhere. The tokenization is patent-pending.
Nothing to type, nothing to read out
Sign-in uses no password and no shared code, which is precisely why a convincing fake login page collects nothing usable. A one-time PIN appears once in the lifecycle, when a user binds a new device: emailed, and sent by SMS as well when a mobile number is on file.
Read the biometric certificates closely
Our liveness holds iBeta ISO 30107-3 certification at Level 1 and Level 2. That covers presentation attacks at the camera, such as a printed photo or a mask, and it does not cover virtual-camera or SDK injection. Injection is blocked separately: sign-in runs only inside the SenseCrypt app on an enrolled phone, and app attestation and device authenticity checks verify both at every sign-in. Our face recognition entered the NIST evaluation in 2021, then FRVT and later split into FRTE and FATE, and we maintain it through our latest submissions.
Where each fits
Both products are full identity providers, so a feature count will not settle anything. Ping has the deeper enterprise footprint, with years in workforce and customer identity and a long-established position on the open standards. SenseCrypt is younger, and narrower by choice.
One practical note if face biometrics is the reason you are in the room with Ping: that line joined the portfolio in January 2026, so ask where it lands in the plan you are buying and on what timeline.
Ping is the enterprise platform
It is an established identity platform for workforce and customer identity, and it speaks the open standards you already integrate against. When your requirements sprawl across many systems and a long procurement, that reach is worth paying for.
SenseCrypt is narrow on purpose
One sign-in method, hardened, with no password path left behind it to undo the result. That is a strength when phishing is your real risk and a constraint when it is not.
The protocol layer is common ground
SenseCrypt speaks OIDC and OAuth 2.0 with PKCE and pushed authorization requests, SAML 2.0, and SCIM 2.0 for provisioning. CIBA is there too, where the backchannel push starts a device-bound face ceremony instead of a tap to approve.
Roles are emitted, not enforced for you
SenseCrypt puts roles and permissions into the token, and your application decides what they allow. SenseCrypt itself runs a default-closed group gate at sign-in and capability checks on the admin console routes, over multi-tenant isolation and audit logs.
Priced per user, with the add-ons named
One dollar per user per month with a 20-seat minimum. That is the list price and not the whole bill: signing-key custody in KMS adds twenty dollars per key per month, and each tenant or custom domain past the first three costs ten dollars per month. Customer identities bill as monthly active users. The 30-day trial takes no card.
Use them together
Pulling out Ping Identity is rarely on the table, and it does not need to be. Ping accepts an external identity provider over standard federation, and SenseCrypt is one.
Face login then arrives as a connection you configure rather than a migration you schedule. Ping stays the front door. What changes is the moment of proof.
Ping keeps the directory and the policy
Your applications keep pointing at Ping. User records, group membership, policy and audit history all stay where they are, and none of your existing application integration has to be rewritten.
SenseCrypt becomes the proof step
Ping hands the user to SenseCrypt over OIDC or SAML. The face ceremony runs on the device, SenseCrypt returns a standard token or assertion, and Ping issues the session exactly as it did before.
Start with one group
Federation is set up as a connection, so you can route a pilot group or a single application through face login and leave everyone else on their current method. Widen it when the helpdesk queue tells you it holds.
SenseCrypt and Ping Identity at a glance
| Dimension | SenseCrypt | Ping Identity |
|---|---|---|
| Primary sign-in | Passwordless face login | Varies by plan |
| Face matching location | On-device | Varies by plan |
| Biometric data on server | None (single-use face token) | Varies by plan |
| Open standards (OIDC, SAML, SCIM) | OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, CIBA | Supported |
| Phishing-resistant by design | Yes; no password or shared code to enter | Varies by plan |
| Federation as an external IdP | Yes; federate into another IdP | Supported |
Frequently asked questions
Is SenseCrypt a Ping Identity alternative?
Yes. SenseCrypt is a passwordless identity provider with face login. You can use it as an alternative or a complement.
Can I federate SenseCrypt into Ping Identity?
Yes. SenseCrypt speaks open standards. You can federate it into Ping Identity as an external identity provider.
Where does SenseCrypt match a face?
SenseCrypt matches a face on-device. SenseCrypt stores no face image and no face template. It uses a single-use face token.
Related