Passwordless sign-in for web, mobile and kiosks
Replace passwords with a live face check on the user's enrolled phone. Your application receives a standard OIDC token or SAML assertion.
Explore practical uses for SenseCrypt. Each page explains the problem, the implementation and the limits of the solution.
Explore the library7 of 7 entries
Replace passwords with a live face check on the user's enrolled phone. Your application receives a standard OIDC token or SAML assertion.
SenseCrypt removes the shared sign-in secret. Its passkey method uses FIDO2/WebAuthn origin binding to prevent your site’s sign-in proof from working on a lookalike origin. Phone sign-in also combines a live face check with a key bound to the enrolled device.
A face match says nothing about whether a living person is at the camera. SenseCrypt separates the two problems, has liveness tested by an accredited lab, and stops the injection case with device checks that run before capture begins.
Conventional MFA was built to protect a password, not to retire one. SenseCrypt withdraws both and leaves a single device-bound face ceremony, with step-up handled by a signed request in place of a prompt to tap.
SenseCrypt has no password waiting to be reset; what a person can mislay is the handset carrying their key material. Getting back in means binding a replacement device, gated on contact points the account already held, and issuing nothing that works twice.
Provision accounts from photos you already hold or allow controlled self-signup. Users bind their phone, then sign in with a live face check instead of a password.
Machines that belong to nobody and are used by everybody, during shifts that will not pause for a login screen. SenseCrypt treats the terminal as untrusted: it shows a code and waits, and the face check runs on the phone of whoever walked up to it.