The Sonavera digital handshake
Proof of person, not paperwork.
Sonavera adds a short camera-and-mic check to your riskiest moments. It runs in the browser, takes a couple of minutes, and hands your backend signed evidence that a real, present person completed it. No app to install. No documents to photograph. What happens next stays your call.
- Runs in the browser — no app
- Takes a couple of minutes
- No raw video or audio in your results
- You own the decision
The riskiest moments get the weakest checks.
A six-digit code proves someone has the phone. It doesn’t prove who’s holding it. Manual review adds judgment, but it’s slow, expensive, and different every time. Asking for a passport photo works — and your users hate you for it.
A Sonavera handshake takes a different path: a short, guided session in the browser that gathers positive evidence a real person is present — face, voice, liveness, and media signals — then sends the user straight back to your app.

Friction where it counts
Built for the moments that matter.
Don’t make everyone do it. Trigger a handshake only when the stakes rise — when your risk engine flags something, or the action itself is too big to wave through.
Account recovery
They lost the password and the phone. Before you hand the account back, compare the person asking with the person who enrolled.
Sensitive support actions
Email changes, MFA resets, recovery settings — the moves attackers make right before they cash out. Add a live check before support clicks approve.
Privileged and agent actions
When an admin — or an AI agent running on someone’s credentials — reaches for a dangerous switch, have a person show up first.
High-value payouts
Tie the check to the payout or the new beneficiary, so the money moves only after a person does.
How it works
Step 1
You send them to us
Your app starts a handshake over OIDC or a simple API redirect, tied to the exact action you’re protecting.
Step 2
We run the check
The user reviews what’s being asked and consents, then completes a short guided session with their camera and microphone.
Step 3
You get the evidence
Your backend fetches a signed result and applies your own rules. Strong evidence or weak, the decision is yours.
Evidence, not verdicts
See exactly why the number is what it is.
Every check returns an Evidence Index from 0 to 100 — not a pass/fail, not a probability. It’s composed from fixed, published allocations: each signal earns points toward its share, and anything we couldn’t measure earns zero, in plain sight.
No hidden reweighting. No black box. You see every measurement, what it contributed, and why — so your policy can be as strict or as forgiving as your product needs.
Evidence Index
measurements_partial- Identity match
- 30.50 / 40 pts
- Face continuity
- 12.41 / 15 pts
- Challenge integrity
- 20.50 / 25 pts
- Media integrity
- 16.40 / 20 pts
Real structure, example numbers — rendered from the same generated fixture our tests use.
OIDC step-up
The pattern your identity stack already speaks: Authorization Code with PKCE and a signed ID token carrying the evidence.
API redirect
The simplest path. One call to start, a redirect, one call to fetch the result. Good for a pilot afternoon.
Signed webhooks
Get told when a check finishes instead of polling. Every delivery is HMAC-signed so your backend can verify it.
TypeScript SDK
Helpers for starting checks, validating results and tokens, verifying webhooks, and handling deletion requests.
Fits beside the identity stack you already have.
Sonavera isn’t your identity provider and doesn’t want to be. Keep your login, your user database, and your rules — and call us for the moments that need a real person.
Privacy isn’t a feature. It’s the shape.
Consent comes first — no consent, no check. Biometric data stays locked inside your tenant, never compared across customers. Your results carry evidence, not recordings. And everything expires: deletion is on the calendar from the moment the check starts.
We run the check. You make the call.
Try it right now — it takes two minutes and there’s nothing to install.