Seventh Sense
Compare

SenseCrypt
Technical library

Identity platforms

SenseCrypt vs Okta

Okta is an established workforce and customer identity platform with a large application integration catalog. SenseCrypt is an identity provider with a single sign-in ceremony, a face scan completed in a companion app on the user's enrolled phone. This page is about which of those two shapes fits the problem you have.

7 sectionsSeventh Sense / SenseCrypt
On this page

01

Multiple authentication options or one focused method?

An Okta sign-in policy is assembled. A password here, a push there, a code, a security key, and conditions deciding which combination applies to whom. The expressiveness is the value on offer, and it exists only because every method remains on the shelf, available to be selected.

SenseCrypt does not assemble. There is one ceremony, and the methods behind it are transports for the same proof rather than alternatives of differing strength. Taking the password out is the point, and keeping one as a fallback would quietly put the weakest path back into the policy.

The 2023 attack on MGM Resorts shows why the fallback decides the outcome. Attackers phoned the IT helpdesk, impersonated an employee, and entered through the recovery path rather than the front door, with a reported impact of around 100 million dollars. A front door is worth what its softest reset path allows.

Three ways to check the person

A scanned QR code with the face scan completed in the companion app; a real FIDO2/WebAuthn passkey (ES256) presented by that same app acting as a roaming authenticator; and, for enterprise customers on a trusted network, a webcam variant arranged through sales@seventhsense.ai. This licensed on-premises method processes captures inside the customer deployment and does not add an enrolled-phone possession factor.

Face verification runs on the enrolled phone

For the two mobile-app methods, liveness and matching run on the user's own phone rather than on a server. The device being signed in to, whether a browser, a kiosk or a shared desktop, is never enrolled.

The recovery path carries no password

There is nothing for a caller to talk a helpdesk agent into resetting. Pairing a replacement handset uses a single-use PIN that arrives by email, plus SMS where the record holds a mobile number, and it plays no part in any routine sign-in. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.

Origin binding on the passkey path

FIDO2/WebAuthn ties the credential to your real origin, so a relay in front of a lookalike domain captures nothing it can replay. That is the phishing-resistance claim, stated at the path where it applies.

02

What the server retains after enrollment

Ask any biometric vendor for the list rather than the reassurance. Ours: IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment.

The retained face token is quantum-safe, sealed, biometric-free and disposable. No face images or templates are retained in the documented phone flow. Tokens are tenant-bound and stored alongside the required account records. ISO/IEC 24745:2022 is the standard that frames those properties for a protected biometric reference; ISO/IEC 30136:2018 is the one that frames how the protection is measured.

The consequence is what an incident can cost. There is no face gallery to exfiltrate, biometric-free face tokens and account records to assess in a data request, and sealed, biometric-free, disposable face tokens and account records to assess if you later change vendors. That is the work the term biometric-blind is doing in our material.

Quantum-safe, revocable and renewable face token

The construction uses NIST 140-3 approved symmetric and hash primitives exclusively: AES-256-GCM, HKDF-SHA256, SHA-256. No proprietary or non-approved cryptographic primitives are used anywhere. Nothing in it rests on a public-key assumption that a future quantum computer would undo.

Hybrid post-quantum TLS on the wire

Sessions negotiate hybrid post-quantum TLS (X25519MLKEM768), the transport answer to harvest-now-decrypt-later, alongside the NIST FIPS 203/204/205 series and the timetable US NSM-10 set.

Independent tests and evaluators

Liveness detection is tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2. Face recognition is evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, participation since 2021.

Patent-pending face tokenization and Face PKI

Face tokenization and Face PKI are patent-pending. The published recognition report card is at https://pages.nist.gov/frvt/reportcards/11/seventhsense_005.html.

03

Broad platform or focused sign-in?

Okta brings a directory, lifecycle management, policy, device signals, and an integration catalog assembled over more than a decade. It also brings a hiring pool: administrators who have run the console somewhere else and need no training on it here. When an estate is heterogeneous and the requirements are broad, that whole surface is the product being bought, and giving it up is not a small decision.

SenseCrypt brings one method with a hard floor under it. Narrowing the surface is what raised that floor; the two are a single fact seen from opposite sides.

Protocol coverage will not separate them. Both issue standard tokens and assertions, so the switching cost sits in rollout, support and enrollment rather than in application code.

Compare integration breadth and sign-in design

Okta's value compounds with the number of systems it touches. SenseCrypt's value compounds with how much you can delete from the sign-in path. Neither of those is a feature row.

Include ecosystem costs in your assessment

Okta has training, staffing and a decade of published answers behind it. Any newer vendor, ours included, asks your team to learn something nobody has already learned on their behalf.

Plan the enrollment rollout

Every user installs the companion app and binds a phone. Plan it as a change management project with a helpdesk script, not as a configuration change made on a Thursday.

04

SenseCrypt as an external identity provider in Okta

Replacing Okta is rarely proportionate to a change in sign-in method, and it is not the recommendation here. External identity providers are a standing Okta concept, registered over OIDC or SAML 2.0, and SenseCrypt registers as one of them.

Everything your team administers stays administered in Okta: the directory, the group assignments, the policy, the audit history. Applications keep pointing at the same place. Only the proof step relocates. A redirect sends the user to SenseCrypt, the face ceremony completes on the enrolled phone, a token or assertion comes back, and Okta mints the session on exactly the terms it always did.

Both sides are configured rather than installed: endpoints and metadata, a client registration, a claim mapping, and a routing rule that decides who takes the new path.

Route one group first

One routing rule is enough to put a single application, or one pilot department, behind face login while the rest of the estate carries on unchanged. A quiet support queue is the signal to widen the rule.

Map claims between providers

SenseCrypt emits roles and permissions in its token. Okta maps them into its own model, and your applications keep enforcing exactly what they enforced before.

Keep session management in Okta

SenseCrypt keeps no operator-side single sign-on session for end users, so the session your applications depend on is still the one Okta issues and Okta expires.

05

Supported standards and pricing

SenseCrypt is a standards-based provider first and a biometric second. An application integrates with it the way it integrates with any OIDC or SAML provider, and the face ceremony is how presence is proven inside that flow rather than a second system to keep in step.

Two limits, stated rather than implied. End-user authentication has no operator-side single sign-on session; each application sign-in is its own ceremony, and the browser session that does exist belongs to the admin console. The hash-chained tamper-evident log covers administrative actions in that console, while end-user sign-ins go to a separate read-only activity stream that is not part of the chain and has no customer-facing verification interface.

A seat costs a dollar a month and twenty is the smallest order we take. Non-exportable signing keys in a managed key service are twenty dollars per key per month, and the key cannot be copied out by anyone, including us. Tenants and custom domains beyond the three included in every account are ten dollars per month each. Customer identity deployments meter monthly active users rather than registered accounts, and a thirty-day trial runs without a card.

  • OpenID Connect and OAuth 2.0 (RFC 6749), with PKCE (RFC 7636) and pushed authorization requests (RFC 9126)
  • SAML 2.0 identity provider for the applications that federate that way
  • SCIM 2.0 (RFC 7644) provisioning for users and groups
  • FAPI-CIBA / CIBA for backchannel initiation, where the push opens a face ceremony on the enrolled phone
  • Roles and permissions in the token, a default-closed group gate at sign-in, capability checks on console routes
  • Tenant isolation, with three tenants or custom domains per account included.

06

Compare the details

SenseCrypt and Okta, dimension by dimension
DimensionSenseCryptOkta
Primary sign-inFace scan in the companion app on an enrolled phonePolicy assembled from several factors, varies by plan
Password in the systemNone, and no password fallback by designVaries by plan and policy
Where face verification runsOn the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.See vendor documentation
Stored on the server after enrollmentQuantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.See vendor documentation
Phishing resistanceOn the passkey path, via FIDO2/WebAuthn origin bindingVaries by plan and configuration
Federation protocolsOIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBADocumented as supported
Use as an external IdPYes, SenseCrypt federates into Okta over OIDC or SAML 2.0Accepts external identity providers
List priceOne dollar per user per month, twenty-seat minimumVaries by plan

Primary sign-in

SenseCrypt
Face scan in the companion app on an enrolled phone
Okta
Policy assembled from several factors, varies by plan

Password in the system

SenseCrypt
None, and no password fallback by design
Okta
Varies by plan and policy

Where face verification runs

SenseCrypt
On the user's phone for both mobile-app methods; within the customer deployment for licensed on-premises Webcam flows.
Okta
See vendor documentation

Stored on the server after enrollment

SenseCrypt
Quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist.
Okta
See vendor documentation

Phishing resistance

SenseCrypt
On the passkey path, via FIDO2/WebAuthn origin binding
Okta
Varies by plan and configuration

Federation protocols

SenseCrypt
OIDC, OAuth 2.0, SAML 2.0, SCIM 2.0, PAR, CIBA; FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA
Okta
Documented as supported

Use as an external IdP

SenseCrypt
Yes, SenseCrypt federates into Okta over OIDC or SAML 2.0
Okta
Accepts external identity providers

List price

SenseCrypt
One dollar per user per month, twenty-seat minimum
Okta
Varies by plan

07

Frequently asked questions

Can SenseCrypt replace Okta, or does it sit behind it?

Either. SenseCrypt is a full identity provider, so applications can federate to it directly over OIDC or SAML 2.0. The lower-risk pattern in an established Okta estate is to register SenseCrypt as an external identity provider and route one application or one group through it, which leaves the directory, the policies and the application catalog untouched.

How is this different from adding a passkey factor in Okta?

A passkey factor is one option inside a policy, and the policy usually retains a weaker path for enrollment, recovery or exception cases. SenseCrypt has no password path to retain; device replacement uses email verification and a new device key, and still requires the enrolled face at sign-in. The gain is less the factor itself than the absence of everything behind it.

What biometric data does SenseCrypt store?

IdP retains quantum-safe, sealed, biometric-free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys also persist. No face images or templates are retained in the documented phone flow. Licensed on-premises Webcam processes captures inside the customer deployment. The token is persisted and we name it rather than claiming nothing is kept.

Does a helpdesk still need a reset procedure?

It needs a device-binding procedure rather than a reset procedure. Someone who has lost a handset pairs a replacement using a single-use PIN we email, with an SMS copy where a mobile number sits on the record. No password exists to be reset and no security question exists to be answered, which takes away the script that helpdesk impersonation attacks are built around. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.

How do shared workstations and kiosks work?

The target device is never enrolled, so a shared desktop or kiosk behaves like any other browser: it displays the QR code, and the user completes the face scan on their own enrolled phone. Nothing is installed on the shared machine.

What does it take to run a pilot?

A tenant, one application or group routed to SenseCrypt as an external identity provider in Okta, and the companion app installed by the pilot users. The thirty-day trial takes no card, and the twenty-seat minimum applies at purchase rather than during the trial.

Next step

The next level of detail depends on your stack, so the fastest route is a conversation.