Begin with the person.
Your live biometric generates PKI private keys for face sign or face decapsulate. Private keys exist only during that operation.
A private key for this operation.
Your live biometric generates the PKI key-pair in memory. Its public key is stored; its private key is generated for face sign or face decapsulate and is never retrieved from storage. Public keys, signatures and decapsulated shared secrets go directly to relying party endpoints, without the IdP seeing them.
Sign or decapsulate with your live biometric.
The transient key signs the payload. The resulting signature can be verified using the relevant public material.
Public keys stay. Private keys do not.
The PKI private key is discarded after face sign or face decapsulate. Public keys, signatures and decapsulated shared secrets are sent directly to relying party end-points, without the IdP seeing them. IdP tenant keys have a separate retained, encrypted lifecycle.