Simple QR
Scan an on-screen code and complete the face match on your own device. The enrolled phone acts as the trust anchor via its device key and app attestation. Simple QR is not origin-bound.
SenseCrypt IdP combines FIDO2/WebAuthn passkeys (ES256) with a separate live face check. Provision users from existing photos, enroll their phones and let them sign in by face.
Transparent pricing: $1/user per month (20-seat minimum). No credit card required for trial.
A deliberate choice of ceremony for each environment.
Scan an on-screen code and complete the face match on your own device. The enrolled phone acts as the trust anchor via its device key and app attestation. Simple QR is not origin-bound.
Real FIDO2/WebAuthn passkeys with a separate live face proof. This path provides phishing resistance via WebAuthn origin binding; the passkey provider depends on the device.
An enterprise-only option running from a webcam on a trusted network, avoiding the need for a secondary device during authorization. The licensed on-premises service processes the capture within the customer deployment. (Contact sales@seventhsense.ai).
Evaluated in the NIST Face Recognition Technology Evaluation under Seventh Sense's own name, and liveness detection tested by iBeta to ISO/IEC 30107-3 Levels 1 and 2.
IdP retains encrypted tenant signing keys and uses classical ES256 for OIDC federation. SenseCrypt IdP supports FAPI 2.0, FAPI 2.0 Message Signing and FAPI-CIBA for financial-grade flows. Applications use the supported identity protocols and enforce their own access decisions.
OpenID Connect and OAuth 2.0 (RFC 6749), with PKCE (RFC 7636) and pushed authorization requests (RFC 9126). FAPI 2.0 and FAPI 2.0 Message Signing support financial-grade flows.
Identity Provider support for legacy federation. Single Logout and HTTP Artifact binding are not implemented.
Automated user provisioning and de-provisioning workflows.
FAPI-CIBA / CIBA: a backchannel push starts a face check on the enrolled phone. Token delivery follows the configured profile.
Machine-to-Machine authentication for background services and automated workflows.