Hosted step-up identity evidence
Add live identity evidence before high-risk actions go through.
Account recovery, support-driven changes, and high-value payouts often need more than an OTP. Sonavera runs a guided browser session and assembles configured biometric, liveness, media-authenticity, browser, and network evidence into a structured result your backend validates. Your team sets the policy and makes the final decision.
- No app install
- OIDC or API redirect
- Tenant-scoped comparison
- No raw media or biometric embeddings in the tenant result
The riskiest moments often rely on the weakest checks
An OTP can show access to a phone or inbox. It does not, by itself, show who is present. Manual review can add judgment, but it also adds delay, cost, and inconsistent outcomes.
A Sonavera digital handshake is a guided, browser-based session that gathers the configured evidence before returning the user to your application. It runs on supported modern browsers with a camera and microphone, with no app install.

Built for high-risk moments
Add a live evidence step only where impersonation or account takeover creates meaningful business risk.
Account recovery
Compare fresh observations with an active, tenant-scoped enrollment before your policy restores access.
Sensitive support actions
Collect fresh evidence before changing an email address, MFA method, role, or recovery setting.
Protected account changes
Step up when a new device, unusual location, or other risk signal makes credentials insufficient.
High-value payouts
Bind a live ceremony to the payout, beneficiary, or payment-detail change under review.
How it works
Step 1
Your application starts the ceremony
A backend or BFF can start OIDC or API redirect. A public-client SPA can initiate OIDC with the protected action bound to backend-owned transaction state.
Step 2
Sonavera runs the guided session
Sonavera validates the governing consent context. When fresh consent is required, the user reviews it before checking their camera and microphone and completing the configured interaction.
Step 3
Your application validates the result
Your backend receives authoritative ceremony state and configured evidence. Your policy determines what happens next.
Evidence, not a black-box verdict
See the evidence behind the result
A completed ceremony does not mean every requested measurement was complete or strong. Lifecycle, sensor-data sufficiency, operation delivery, and evidence remain separate.
The result preserves complete, partial, and absent measurements, their bounded reasons, fixed allocations, and earned contributions. The Evidence Index is not a probability or an action recommendation.
measurements_partial- Identity evidence
- 30.50 / 40 points
- Face continuity
- 12.41 / 15 points
- Challenge integrity
- 20.50 / 25 points
- Media integrity
- 16.40 / 20 points
Illustrative only. Values come from the repository-generated verify/partial fixture.
OIDC step-up
Authorization Code with PKCE and signed ID tokens containing namespaced ceremony claims.
API redirect
Start from your backend, redirect into Sonavera, then retrieve the authoritative result.
Signed webhooks
HMAC-verified terminal notifications for asynchronous downstream workflows.
TypeScript SDK
Helpers for protocol construction, result validation, webhook verification, and deletion workflows.
Fits beside your existing identity stack
Choose the supported integration pattern that fits how you already handle authentication, support, and sensitive account events.
Security you can trace
Consent gates processing. Biometric comparison stays within tenant-specific data boundaries. Stored biometric templates are protected, customer results are minimized, and artifact deletion follows the disclosed boundary.
We run the ceremony. You make the decision.
Guided ceremony. Structured evidence. Customer-owned policy.