01
Multiple authentication options or one focused method?
An Okta sign-in policy is assembled. A password here, a push there, a code, a security key, and conditions deciding which combination applies to whom. The expressiveness is the value on offer, and it exists only because every method remains on the shelf, available to be selected.
SenseCrypt does not assemble. There is one ceremony, and the methods behind it are transports for the same proof rather than alternatives of differing strength. Taking the password out is the point, and keeping one as a fallback would quietly put the weakest path back into the policy.
The 2023 attack on MGM Resorts shows why the fallback decides the outcome. Attackers phoned the IT helpdesk, impersonated an employee, and entered through the recovery path rather than the front door, with a reported impact of around 100 million dollars. A front door is worth what its softest reset path allows.
Three ways to check the person
A scanned QR code with the face scan completed in the companion app; a real FIDO2/WebAuthn passkey (ES256) presented by that same app acting as a roaming authenticator; and, for enterprise customers on a trusted network, a webcam variant arranged through sales@seventhsense.ai. This licensed on-premises method processes captures inside the customer deployment and does not add an enrolled-phone possession factor.
Face verification runs on the enrolled phone
For the two mobile-app methods, liveness and matching run on the user's own phone rather than on a server. The device being signed in to, whether a browser, a kiosk or a shared desktop, is never enrolled.
The recovery path carries no password
There is nothing for a caller to talk a helpdesk agent into resetting. Pairing a replacement handset uses a single-use PIN that arrives by email, plus SMS where the record holds a mobile number, and it plays no part in any routine sign-in. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.
Origin binding on the passkey path
FIDO2/WebAuthn ties the credential to your real origin, so a relay in front of a lookalike domain captures nothing it can replay. That is the phishing-resistance claim, stated at the path where it applies.
02
What the server retains after enrollment
Ask any biometric vendor for the list rather than the reassurance. Ours: IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.
The retained face token is quantum-safe, sealed, biometric-free and disposable. No face images or templates are retained in the documented phone flow. Tokens are tenant-bound and stored alongside the required account records. ISO/IEC 24745:2022 is the standard that frames those properties for a protected biometric reference; ISO/IEC 30136:2018 is the one that frames how the protection is measured.
The consequence is what an incident can cost. There is no face gallery to exfiltrate, biometric-free face tokens and account records to assess in a data request, and sealed, biometric-free, disposable face tokens and account records to assess if you later change vendors. That is the work the term biometric-blind is doing in our material.
Quantum-safe, revocable and renewable face token
The construction uses NIST 140-3 approved symmetric and hash primitives exclusively: AES-256-GCM, HKDF-SHA256, SHA-256. No proprietary or non-approved cryptographic primitives are used anywhere. Nothing in it rests on a public-key assumption that a future quantum computer would undo.
Hybrid post-quantum TLS on the wire
Sessions negotiate hybrid post-quantum TLS (X25519MLKEM768), the transport answer to harvest-now-decrypt-later, alongside the NIST FIPS 203/204/205 series and the timetable US NSM-10 set.
Independent tests and evaluators
Liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. Face recognition is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021.
Patent-pending face tokenization and Face PKI
Face tokenization and Face PKI are patent-pending. The published recognition report card is at https://pages.nist.gov/frvt/reportcards/11/seventhsense_005.html.
03
Broad platform or focused sign-in?
Okta brings a directory, lifecycle management, policy, device signals, and an integration catalog assembled over more than a decade. It also brings a hiring pool: administrators who have run the console somewhere else and need no training on it here. When an estate is heterogeneous and the requirements are broad, that whole surface is the product being bought, and giving it up is not a small decision.
SenseCrypt brings one method with a hard floor under it. Narrowing the surface is what raised that floor; the two are a single fact seen from opposite sides.
Protocol coverage will not separate them. Both issue standard tokens and assertions, so the switching cost sits in rollout, support and enrollment rather than in application code.
Compare integration breadth and sign-in design
Okta's value compounds with the number of systems it touches. SenseCrypt's value compounds with how much you can delete from the sign-in path. Neither of those is a feature row.
Include ecosystem costs in your assessment
Okta has training, staffing and a decade of published answers behind it. Any newer vendor, ours included, asks your team to learn something nobody has already learned on their behalf.
Plan the enrollment rollout
Every user installs the companion app and binds a phone. Plan it as a change management project with a helpdesk script, not as a configuration change made on a Thursday.
04
SenseCrypt as an external identity provider in Okta
Replacing Okta is rarely proportionate to a change in sign-in method, and it is not the recommendation here. External identity providers are a standing Okta concept, registered over OIDC or SAML 2.0, and SenseCrypt registers as one of them.
Everything your team administers stays administered in Okta: the directory, the group assignments, the policy, the audit history. Applications keep pointing at the same place. Only the proof step relocates. A redirect sends the user to SenseCrypt, the face ceremony completes on the enrolled phone, a token or assertion comes back, and Okta mints the session on exactly the terms it always did.
Both sides are configured rather than installed: endpoints and metadata, a client registration, a claim mapping, and a routing rule that decides who takes the new path.
Route one group first
One routing rule is enough to put a single application, or one pilot department, behind face login while the rest of the estate carries on unchanged. A quiet support queue is the signal to widen the rule.
Map claims between providers
SenseCrypt emits roles and permissions in its token. Okta maps them into its own model, and your applications keep enforcing exactly what they enforced before.
Keep session management in Okta
SenseCrypt keeps no operator-side single sign-on session for end users, so the session your applications depend on is still the one Okta issues and Okta expires.
05
Supported standards and pricing
SenseCrypt is a standards-based provider first and a biometric second. An application integrates with it the way it integrates with any OIDC or SAML provider, and the face ceremony is how presence is proven inside that flow rather than a second system to keep in step.
Two limits, stated rather than implied. End-user authentication has no operator-side single sign-on session; each application sign-in is its own ceremony, and the browser session that does exist belongs to the admin console. The hash-chained tamper-evident log covers administrative actions in that console, while end-user sign-ins go to a separate read-only activity stream that is not part of the chain and has no customer-facing verification interface.
A seat costs a dollar a month and twenty is the smallest order we take. Non-exportable signing keys in a managed key service are twenty dollars per key per month, and the key cannot be copied out by anyone, including us. Tenants and custom domains beyond the three included in every account are ten dollars per month each. Customer identity deployments meter monthly active users rather than registered accounts, and a thirty-day trial runs without a card.
- OpenID Connect and OAuth 2.0 (RFC 6749), with PKCE (RFC 7636) and pushed authorization requests (RFC 9126)
- SAML 2.0 identity provider for the applications that federate that way
- SCIM 2.0 (RFC 7644) provisioning for users and groups
- FAPI-CIBA / CIBA for backchannel initiation, where the push opens a face ceremony on the enrolled phone
- Roles and permissions in the token, a default-closed group gate at sign-in, capability checks on console routes
- Tenant isolation, with three tenants or custom domains per account included.
06
Compare the details
| Dimension | SenseCrypt | Okta |
|---|---|---|
| Primary sign-in | Face scan in the companion app on an enrolled phone | Policy assembled from several factors, varies by plan |
| Password in the system | None, and no password fallback by design | Varies by plan and policy |
| Where face verification runs | On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows. | See vendor documentation |
| Stored on the server after enrollment | Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. | See vendor documentation |
| Phishing resistance | On the passkey path, via FIDO2/WebAuthn origin binding | Varies by plan and configuration |
| Federation protocols | OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA | Documented as supported |
| Use as an external IdP | Yes, SenseCrypt federates into Okta over OIDC or SAML 2.0 | Accepts external identity providers |
| List price | One dollar per user per month, twenty-seat minimum | Varies by plan |
Primary sign-in
- SenseCrypt
- Face scan in the companion app on an enrolled phone
- Okta
- Policy assembled from several factors, varies by plan
Password in the system
- SenseCrypt
- None, and no password fallback by design
- Okta
- Varies by plan and policy
Where face verification runs
- SenseCrypt
- On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.
- Okta
- See vendor documentation
Stored on the server after enrollment
- SenseCrypt
- Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.
- Okta
- See vendor documentation
Phishing resistance
- SenseCrypt
- On the passkey path, via FIDO2/WebAuthn origin binding
- Okta
- Varies by plan and configuration
Federation protocols
- SenseCrypt
- OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA
- Okta
- Documented as supported
Use as an external IdP
- SenseCrypt
- Yes, SenseCrypt federates into Okta over OIDC or SAML 2.0
- Okta
- Accepts external identity providers
List price
- SenseCrypt
- One dollar per user per month, twenty-seat minimum
- Okta
- Varies by plan
07
Frequently asked questions
Can SenseCrypt replace Okta, or does it sit behind it?
Either. SenseCrypt is a full identity provider, so applications can federate to it directly over OIDC or SAML 2.0. The lower-risk pattern in an established Okta estate is to register SenseCrypt as an external identity provider and route one application or one group through it, which leaves the directory, the policies and the application catalog untouched.
How is this different from adding a passkey factor in Okta?
A passkey factor is one option inside a policy, and the policy usually retains a weaker path for enrollment, recovery or exception cases. SenseCrypt has no password path to retain; device replacement uses email verification and a new device key, and still requires the enrolled face at sign-in. The gain is less the factor itself than the absence of everything behind it.
What biometric data does SenseCrypt store?
IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment. The token is persisted and we name it rather than claiming nothing is kept.
Does a helpdesk still need a reset procedure?
It needs a device-binding procedure rather than a reset procedure. Someone who has lost a handset pairs a replacement using a single-use PIN we email, with an SMS copy where a mobile number sits on the record. No password exists to be reset and no security question exists to be answered, which takes away the script that helpdesk impersonation attacks are built around. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.
How do shared workstations and kiosks work?
The target device is never enrolled, so a shared desktop or kiosk behaves like any other browser: it displays the QR code, and the user completes the face scan on their own enrolled phone. Nothing is installed on the shared machine.
What does it take to run a pilot?
A tenant, one application or group routed to SenseCrypt as an external identity provider in Okta, and the companion app installed by the pilot users. The thirty-day trial takes no card, and the twenty-seat minimum applies at purchase rather than during the trial.