Glossary

What is single sign-on (SSO)?

Single sign-on (SSO) is a method that lets a user sign in one time to reach many applications. The user signs in with one identity provider (IdP). The IdP then grants access to each connected application.

On this page
  1. What does single sign-on do?
  2. How does single sign-on work?
  3. What are the benefits of single sign-on?
  4. How does SenseCrypt provide single sign-on?
  5. Frequently asked questions

What does single sign-on do?

Single sign-on (SSO) lets a user sign in one time and reach many applications. One identity provider holds the session, and each connected application trusts it instead of running a login of its own.

The benefit users notice is obvious, and it is not the main one. Identity teams push for SSO because of control: one place to grant access, one place to remove it, and one log that shows both.

One sign-in, many applications

The user authenticates once and moves between connected applications without repeating it. Fewer sign-ins also means fewer chances to type a credential into the wrong place.

One account to grant and revoke

Access is managed at the identity provider, so a change reaches every application at once rather than application by application.

One place to strengthen

Any improvement to the sign-in method, such as moving to a phishing-resistant factor, applies everywhere on the day you turn it on.

How does single sign-on work?

The first application redirects the user to the identity provider and gets a signed answer back. The identity provider also keeps a session of its own, and that session is what makes the second sign-in invisible.

The second application still runs a full protocol exchange. The user simply never sees a login screen, because the identity provider already knows who they are and answers at once.

  • A user signs in at the identity provider through the first application.
  • The identity provider creates its own session for that user.
  • The user opens a second application and is redirected.
  • The identity provider recognizes the existing session and answers without prompting.
  • The second application verifies the signed answer and starts its own session.

What are the benefits of single sign-on?

SSO pays for itself in the parts of identity work that are hard to see: the leaver who kept access, the shadow account nobody knew about, the audit that took three weeks. It also removes the daily friction that drives password reuse in the first place.

Be clear about what it does not do. SSO does not make your sign-in stronger. It makes whatever sign-in you have apply everywhere.

Fewer credentials in circulation

Users stop inventing and reusing a password for every tool, which removes the credential-stuffing exposure that arrives from somebody else's breach.

Offboarding actually completes

One deactivation ends access to every connected application. With SCIM the accounts themselves are removed rather than left dormant.

The audit trail is in one place

Sign-in events across all applications land in the same log, so an access question is answered from one source instead of reconciled from several.

How does SenseCrypt provide single sign-on?

SenseCrypt is a passwordless identity provider that provides SSO across customer identity, workforce access, and B2B SaaS from one directory. A user signs in by face on an enrolled device, and the match runs there.

Because SSO applies the sign-in method everywhere, the method is the decision. A phishing-resistant one protects every connected application at once, and a phishable one exposes every connected application at once.

No password and no shared code

There is nothing to type at sign-in, so a fake login page has nothing to collect. The sign-in binds to the enrolled device.

OIDC and SAML side by side

Modern applications federate over OIDC and OAuth 2.0 with PKCE and PAR. Enterprise applications take a standard SAML 2.0 assertion. One directory serves both.

Provisioning and roles included

SCIM 2.0 keeps accounts in step, and SenseCrypt emits roles and permissions in the token for your applications to enforce. Audit logs cover the sign-in events.

One deployment, isolated tenants

Multi-tenant isolation keeps separate customers or business units apart while they share one platform.

Frequently asked questions

What is single sign-on (SSO)?

Single sign-on (SSO) is a method that lets a user sign in one time to reach many applications. One identity provider grants access to each connected application.

What is the difference between SSO and an identity provider?

An identity provider verifies the user. Single sign-on is the feature that the IdP enables. With SSO, one sign in works across many applications.

Is single sign-on secure?

Single sign-on is as secure as its identity provider. A phishing-resistant IdP protects every connected application. SenseCrypt uses a face login that binds to the device.

Does SenseCrypt support single sign-on?

Yes. SenseCrypt gives passwordless single sign-on by face. It supports OIDC, OAuth 2.0, and SAML 2.0 for customer and workforce access.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.