Seventh Sense
SenseCrypt IdP

Passwordless sign-in with a live face check.

Application accessLaunched

SenseCrypt IdP combines FIDO2/WebAuthn passkeys (ES256) with a separate live face check. Provision users from existing photos, enroll their phones and let them sign in by face.

Security scope
  • Simple QR is not origin-bound. Passkey sign-in combines a WebAuthn assertion with a separate live face proof.
  • The licensed on-premises webcam method processes captures inside the customer deployment and does not add an enrolled-phone possession factor.
  • Replacement-device enrollment requires email verification and a new device key; the enrolled face is still required at sign-in.
  • IdP retains quantum-safe, sealed, biometric free, disposable face tokens and their verifier challenges. Standard OIDC/SAML account records, device public keys, sessions, logs and encrypted tenant signing keys, are held as well. It does not retain any face images or templates in the documented phone flow.
  • IdP retains encrypted tenant signing keys and uses classical ES256 for OIDC federation. SAML uses separate RSA signing keys. SenseCrypt IdP supports FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA for financial-grade flows. PKI’s post-quantum algorithms and transient private keys are separate from IdP federation.

Transparent pricing: $1/user per month (20-seat minimum). No credit card required for trial.

Application access
The principalLive
person.
Face verification + device proof
The identity layerSenseCrypt
IdP
OIDCSAML 2.0SCIM 2.0
WorkforceCustomer appsB2B SaaS
Your applications keep their standards. Authentication verifies the live person.
01 / Authentication

Three login methods. One identity layer.

A deliberate choice of ceremony for each environment.

Method 1

Simple QR

Scan an on-screen code and complete the face match on your own device. The enrolled phone acts as the trust anchor via its device key and app attestation. Simple QR is not origin-bound.

Method 2

Passkeys

Real FIDO2/WebAuthn passkeys with a separate live face proof. This path provides phishing resistance via WebAuthn origin binding; the passkey provider depends on the device.

Method 3

Simple Webcam

An enterprise-only option running from a webcam on a trusted network, avoiding the need for a secondary device during authorization. The licensed on-premises service processes the capture within the customer deployment. (Contact sales@seventhsense.ai).

Evaluated and tested

Evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, and liveness detection tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2.

02 / Enterprise standards

Plugs into your existing stack.

IdP retains encrypted tenant signing keys and uses classical ES256 for OIDC federation. SenseCrypt IdP supports FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA for financial-grade flows. Applications use the supported identity protocols and enforce their own access decisions.

  • Multi-tenant isolation
  • Role-based access control
  • Active Directory provisioning via SCIM
01 / Protocol

OpenID Connect

OpenID Connect and OAuth 2.0 (RFC 6749), with PKCE (RFC 7636) and pushed authorization requests (RFC 9126). FAPI 2.0 and FAPI 2.0 Message Signing support financial-grade flows.

02 / Protocol

SAML 2.0

Identity Provider support for legacy federation. Single Logout and HTTP Artifact binding are not implemented.

03 / Provisioning

SCIM 2.0

Automated user provisioning and de-provisioning workflows.

04 / Protocol

CIBA and FAPI-CIBA

FAPI-CIBA / CIBA: a backchannel push starts a face check on the enrolled phone. Token delivery follows the configured profile.

05 / Access

M2M / Client Credentials

Machine-to-Machine authentication for background services and automated workflows.