EntryIDP is a drop-in OIDC passwordless identity provider using 3D facial biometrics and liveness detection. Easy integration, zero passwords, zero trust.
Digital security has reached a critical turning point. While the industry has rushed toward biometric authentication most implementations offer only the illusion of improved protection. By relying on client-side hardware and loaning trust to arbitrary smartphones operating systems and local authenticators they create a dangerous vulnerability. When a remote device is compromised the data it transmits back to your servers cannot be trusted.
Entry fundamentally changes this paradigm. Built on an uncompromising Zero Trust architecture Entry removes trust from endpoint hardware entirely. Instead of asking a phone if an identity is valid Entry captures the live session directly and conducts advanced 3D liveness detection and facial matching inside its secure cloud environment. The result is pure verifiable human authenticity with no stored passwords no transferable credentials and zero exposure to synthetic replays or deepfake bypasses.
Built by Synapser founded in 2019 and an AWS partner with a completed Well-Architected Review Entry runs on multi-AZ AWS infrastructure across all AWS regions targeting 99.9 percent standard SaaS availability with higher contractual uptime commitments 99.95 percent or 99.99 percent available through enterprise agreements. The platform has processed approximately 35000 authentications and continues to scale.
Verified Biometric Performance
Presentation Attack Detection: Tested under ISO IEC 30107-3 metrics. In independent NIST NVLAP-accredited third-party testing by iBeta Quality Assurance Lab Code 200962 the underlying liveness engine achieved 0 percent APCER meaning zero successful presentation attacks across all tested species including high-resolution 2D prints digital screen replays and realistic 3D silicone and latex masks. Conforms to iBeta PAD Level 1 and Level 2.
Facial Matching: Tunable match confidence thresholds. At the recommended 99 percent confidence threshold FAR is less than 0.1 percent and TAR is greater than 99 percent. Raising the threshold to 99.9 percent drops FAR to less than 0.01 percent.
Cryptographic Security: RS256 token signing with AWS KMS backed by HSMs certified to FIPS 140-3 Security Level 3 by NIST CMVP providing physical tamper resistance and zeroization mechanisms. Biometric templates are encrypted with AES-256-GCM and never touch relying party servers.
Key Differentiators
Zero Trust in the Device: The connecting camera or device is treated strictly as an untrusted input lens. Liveness verification and biometric evaluation occur entirely server-side eliminating client-side tampering.
One Lifetime Registration with Non-Federated Consent: Users register their biometric profile once for life. To access a new application they simply provide explicit consent. One physical face permanently maps to one verified subject identifier preventing duplicate personas and enabling true cross-system fraud prevention.
Credential-Free and Replay-Proof: Entry eliminates usernames passwords and static seed keys. With nothing static transmitted across the wire intercepted network data cannot be weaponized or replayed.
Standard OIDC Drop-In Integration: Entry functions as a standard OpenID Connect Identity Provider using Authorization Code flow with mandatory PKCE S256. Developers integrate in 15 to 30 minutes using 10 to 30 lines of configuration code with standard libraries including oidc-client-ts next-auth openid-client AppAuth iOS Android and flutter_appauth. No proprietary SDK required.
Enterprise Privacy and HSM Token Signing: Biometric templates never leave the isolated vault. Identity tokens are cryptographically signed using AWS KMS hardware security modules certified to FIPS 140-3 Security Level 3.
Getting Started
Visit the Developer Portal at https://www.synapser.com/developers/ to provision a free self-service sandbox tenant and client_id. Point your standard OIDC client configuration to the Entry discovery endpoint at https://idp.entryidp.com/.well-known/openid-configuration. Configure exact-match redirect URIs no wildcards and enable PKCE with S256. Explore live interactive demos including NorthVault Digital Bank a Developer Sample with decoded biometric claims and attendance checkpoint applications. Review full documentation at https://idp.entryidp.com/docs/.
Prerequisites: An OIDC-compatible relying party a provisioned client_id self-service via sandbox or production tenant exact-match redirect URIs and mandatory PKCE S256. No custom DNS or proprietary SDK required.
Real-World Use Cases
Financial Services Step-Up: Seamless usernameless customer sign-in on web and mobile with instant biometric step-up authentication when high-risk transactions exceed defined thresholds.
Highlights
Zero Trust Server-Side Facial Biometrics with Proven Accuracy: All 3D liveness detection and matching run inside a secure cloud environment - never on untrusted client devices. Liveness engine holds iBeta PAD Level 1 and Level 2 conformance under ISO/IEC 30107-3, achieving 0% APCER across all tested attack species. Facial matching at the 99% confidence threshold delivers FAR below 0.1% and TAR above 99%. Cryptographic signing anchored in AWS KMS HSMs certified to FIPS 140-3 Security Level 3.
One Lifetime Registration with True Non-Repudiation: Binds each user to a single verified biometric profile for life with explicit cross-app consent, eliminating duplicate personas and credential replay attacks. Platform targets 99.9% service availability across identity discovery, authorization, liveness sessions, and token issuance, backed by multi-AZ AWS infrastructure. Higher contractual uptime commitments of 99.95% or 99.99% are available through enterprise agreements.
Drop-In OIDC Integration in Under 30 Minutes: Uses strict standard OpenID Connect (Authorization Code plus PKCE S256) with no proprietary SDK. Typical integration requires 10 to 30 lines of configuration code and works with oidc-client-ts, next-auth, AppAuth, flutter_appauth, and more. Free self-service developer sandbox provides a client_id in minutes so teams can validate the flow before production deployment.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Grants one active user entitlement for biometric identity verification and authentication across the contracted duration. Additional usage beyond the contracted quantity is billed per unit.
This contract gives you one pricing dimension: the User License. Each unit grants one active user entitlement for biometric identity verification and authentication. You commit to a set quantity of user licenses for the contract duration. Pricing scales with the number of active users you authenticate, not with how often each user verifies. If your usage goes past the contracted quantity, the extra usage is billed per unit at the same rate. This keeps the structure simple: you plan your spend around expected user counts and pay for any overage as it occurs.
Top-of-mind questions for buyers
What counts as one active user for a User License unit?
One user license covers one enrolled person whose face is registered for biometric verification. That person can authenticate as often as needed within the contract period. The count tracks unique active users you verify, not the number of verification events, logins, or transactions each user performs.
Does the number of verifications per user affect what I pay?
No. Cost tracks the number of active users you authenticate, not how often each verifies. A single license allows unlimited logins, step-up checks, and re-verifications for that user during the contract. Your spend stays tied to user counts, not verification volume.
What happens if I authenticate more users than my contracted quantity?
Usage beyond the contracted quantity is billed per unit at the same rate. You do not need to renegotiate the contract for extra users. The overage is charged as it occurs, so you can plan your base spend around expected users and pay for growth incrementally.
www.synapser.com
Helpful?
Vendor refund policy
We consider refund requests on a case-by-case basis. Subscriptions canceled due to technical issues that our support team cannot resolve may be eligible for a prorated refund for any unused contracted term. Usage-based overage fees are non-refundable once consumed. To request a refund, please contact our support team at support@synapser.com with your AWS Account ID, product subscription details, and reason for the request.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Standard Support: Available during business hours (8am - 5pm UTC+2) via email. Initial response target is within 24 hours. Covers troubleshooting, account configuration, integration inquiries, and general technical questions.
Premium Support: Available at additional cost and includes phone and live chat channels with a 2-hour response time SLA. Contact entryidp@synapser.com for details on premium support options.
Enterprise Agreements: Customers with large-scale deployments may qualify for custom rate structures and dedicated SLA commitments. Reach out to the support team for more information.
Support Coverage
Integration and Architecture Guidance: Direct assistance for developer teams implementing standard OpenID Connect (OIDC) client libraries, configuring authorization flows (Authorization Code Flow with PKCE S256), and setting up prompt parameters across web and mobile platforms including React, Vue, Next.js, iOS, Android, Flutter, and .NET MAUI. Typical integration takes 15-30 minutes using 10-30 lines of configuration code.
Service Availability and Reliability: Multi-AZ AWS infrastructure with a 99.9% standard SaaS availability target. Continuous cloud-side monitoring of hosted liveness and authentication engines, backed by security patching, HSM key management, and ongoing platform health updates. System errors are auto-ticketed and monitored for escalation and resolution.
Self-Service Resources: Full access to interactive API documentation, integration code snippets for supported frameworks and libraries (oidc-client-ts, next-auth, openid-client, AppAuth, flutter_appauth), and developer FAQs.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
IBM Verify is an IAM SaaS platform that secures workforce and customer access to AWS and hybrid applications. It delivers SSO, multi-factor and passwordless authentication, and risk-based access controls, complementing AWS IAM and Amazon Cognito with advanced workforce IAM and CIAM capabilities for large-scale enterprise environments.
ANDIP is service based platform created to support Government or organizational bodies to manage and govern their user identities and data with standard principle of securities that been proven by serving in governmental digital identity system.
Elevate organizational security with strong and adaptive authentication, preventing unauthorized access to your most critical systems, applications and sensitive data.
A unified IAM platform offering advanced security solutions like multi-factor authentication, single sign-on, and Identity-Bound Biometrics for exceptional security and usability across browsers and workstations. Phoneless. Tokenless. Passwordless.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.