Features

Features

The capabilities behind passwordless face login. SenseCrypt is a full identity provider, so each feature works through an open standard.

Face Login: passwordless biometric sign-in

Face login is passwordless biometric sign-in from SenseCrypt. A user signs in by face. Face matching runs on-device. On the passkey path it is phishing-resistant (FIDO2/WebAuthn).

Read the page

OpenID Connect (OIDC) identity provider

SenseCrypt is an OpenID Connect (OIDC) identity provider. Users sign in by face. It supports OAuth 2.0 with PKCE and PAR. Sign-in is phishing-resistant on the passkey path (FIDO2/WebAuthn).

Read the page

SAML 2.0 identity provider

SenseCrypt is a SAML 2.0 identity provider. Users sign in by face, then your app gets a signed SAML assertion. Sign-in is passwordless, and phishing-resistant on the passkey path (FIDO2/WebAuthn).

Read the page

SCIM 2.0 user provisioning

SenseCrypt supports SCIM 2.0 user provisioning. Your directory creates, updates, and deactivates users automatically in the passwordless IdP.

Read the page

CIBA decoupled backchannel authentication

SenseCrypt supports CIBA for decoupled backchannel authentication. A backend service starts the request. The user then approves it by face login.

Read the page

Role-based access control (RBAC)

SenseCrypt gives role-based access control (RBAC). You assign roles to users. Each role grants a set of permissions. SenseCrypt puts them in the sign-in token, and your app enforces them.

Read the page

Multi-tenant identity for B2B SaaS

SenseCrypt gives multi-tenant authentication for B2B SaaS. Each tenant stays isolated with its own users, roles, and audit logs. Users sign in by face login.

Read the page

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.