Passwordless authentication
Passwordless authentication verifies a user’s identity without asking for a password.
Understand the terms behind identity and authentication. Each entry explains the definition, implementation differences and how SenseCrypt applies it.
Explore the library13 of 13 entries
Passwordless authentication verifies a user’s identity without asking for a password.
Phishing-resistant multi-factor authentication (MFA) resists attempts to authenticate through an attacker-controlled page.
A passkey is a key-pair sign-in credential created for one website and unlocked locally by an authenticator.
Liveness detection checks whether the camera sees a live person or an artifact such as a photo, replay or mask.
Presentation attack detection (PAD) identifies fake biometric samples presented to a sensor.
Face tokenization creates a quantum-safe, protected, revocable, renewable token for face verification, and neither the face image nor the template is retained.
OpenID Connect (OIDC) adds identity to OAuth 2.0/2.1 so applications can authenticate users through a trusted provider.
SAML 2.0 enables federation: an identity provider signs an XML assertion about the user, and a service provider validates it to establish a session.
SCIM is an open standard for creating and managing user accounts and groups across systems.
CIBA is an OpenID Connect flow: the application starts authentication, and the user approves on a separate device they already hold.
An identity provider (IdP) authenticates users and sends signed identity information to connected applications.
Single sign-on (SSO) lets users authenticate once with a trusted identity provider to access multiple applications.
Customer identity and access management (CIAM) manages registration, sign-in and access for external customers.