Face login: proof of person, proof of device
Phone sign-in combines a live face check with a key bound to the enrolled device. The passkey method adds FIDO2/WebAuthn origin binding, live face proof for phishing resistance.
SenseCrypt is a complete identity provider whose sign-in ceremony happens to be a live face check, and every capability here is reached through a published standard. The pages below describe what each one does, where its limits sit, and which parts of the job stay with your own application.
Explore the library7 of 7 entries
Phone sign-in combines a live face check with a key bound to the enrolled device. The passkey method adds FIDO2/WebAuthn origin binding, live face proof for phishing resistance.
Your application speaks ordinary OpenID Connect, and what sits between the redirect and the callback is a live face check rather than a password form.
Applications that speak SAML 2.0 can federate to SenseCrypt without being changed, because the AuthnRequest and the signed Response are ordinary.
A SCIM 2.0 endpoint sits on every tenant, with SenseCrypt in the service provider role, so the directory you already operate remains the answer to who exists.
FAPI-CIBA / CIBA: a backchannel push starts a face check on the enrolled phone.
SenseCrypt answers two different authorization questions: who may sign in at all, and what the signed-in person may do inside your own API.
Every customer gets a tenant with its own signing keys; nothing is shared across the boundary.