Accuracy
The human at the moment of risk
A live biometric check re-proves the person where MFA only proves a credential is present and a device is enrolled.
3 years in a row named a Leader
A Leader in the 2026 Gartner® Magic Quadrant™ for Identity Verification
Download the report
Introducing GovFaceMatch
The first identity solution to match biometrics against DMV records
Read more
How we protect data
Privacy is the architecture
Explore the Privacy Hub
Incode adds a fast biometric step-up at the exact high-risk moments where credentials aren't enough, re-proving the real, live human behind the account.
The challenge
Account takeover (ATO) starts with a stolen or phished credential, a SIM-swapped one-time code, a socially engineered password reset, or a hijacked session. Because the account and its credentials are real, the activity looks legitimate.
Passwords and MFA (multi-factor authentication) protect the credential and the device rather than the human, and generative AI has made it worse: deepfaked voice and video now defeat the manual checks that call centers and recovery flows fall back on.
in US account-takeover losses in 2025, the costliest single fraud type
Javelin Strategy & Research
US account-takeover victims in 2025, up 18% year over year
Javelin, 2026
password attacks per second, with credential attacks up 74% year over year
Microsoft
stolen in a single deepfake CFO video-call transfer
CFO Dive
How it works
Account takeover protection layers on your existing auth stack: Incode proves a real human is present, while your CIAM or IAM (Auth0, Okta, Microsoft Entra, Ping) manages the credential and session.
Why Incode
Incode layers on your auth stack and re-proves the live person behind the account, closing the SIM-swap, phishing, and social-engineering gaps that MFA leaves open.
Accuracy
A live biometric check re-proves the person where MFA only proves a credential is present and a device is enrolled.
Security
Multi-modal liveness and Deepsight catch the exact vectors that defeat one-time codes, knowledge-based answers, and manual video recovery.
Recovery
Biometric re-proof closes the social-engineering path through the help desk and reset flow, with no knowledge-based questions to guess. The step-up runs only when risk warrants: a browser-based selfie, with no app, hardware key, or SDK for the user to install.
Scalability
The same identity proven at KYC re-authenticates and recovers the account across its lifecycle, backed by more than 7.1 billion trust checks run on the Incode platform.
Use cases
Account takeover wins at the event rather than the login. The same step-up covers every moment where value moves.
Challenge a risky login with a selfie match before the session proceeds.
Replace one-time codes and security questions with a biometric re-proof at every reset.
Re-prove the account holder with a selfie, or a full government ID plus selfie, when a credential is fully lost.
Step up at wires, payee or beneficiary changes, loyalty redemptions, and other irreversible actions.
Re-prove the real account holder at a SIM change, port-out, eSIM re-provision, or number transfer.
Methods
Every challenge runs on the same core identity stack.
We made privacy a founding conviction long before regulation or the market asked for it. Incode's AI-first identity verification reduces fraud while remaining private and compliant.
See it in actionConfirmed integrations
In Auth0, Incode installs as a post-login Action from the Auth0 Marketplace: new users get full identity verification, returning users skip within the reverification window, and high-risk sessions get a no-document face authentication step-up against the enrolled biometric, with the verified result stamped into the Auth0 token.
Incode IDV as step-up verification inside Auth0 consumer authentication flows.
Step-up biometric verification and account recovery in Okta consumer sign-in flows.
Biometric step-up at consumer sign-in, MFA recovery, and account recovery in Entra External ID.
Incode IDV in PingOne DaVinci orchestration for workforce and consumer identity use cases.
Incode verification as a step-up journey inside Transmit's orchestration.
Biometric step-up on high-risk Cognito sessions, with the verified result returned to the user pool.
No-code auth platform with Incode verification built in for customer-facing applications.
Step-up biometric verification and account recovery in Okta workflows.
Biometric verification to provide additional protection at provisioning, MFA recovery, and privileged access.
Incode in ServiceNow IT workflows, protecting password resets, MFA recovery, and high-risk actions from impersonation.
Identity verification inside Zendesk support workflows, so a reset or recovery ticket cannot be socially engineered.
Verified proof
Top financial institutions run risk-based step-up and help-desk pre-verification in production for their workforces, the same re-prove-the-human mechanic this page applies to customer accounts.
7.1B+
trust checks run on the Incode platform
8 of 10
top U.S. banks choose Incode
190+
countries and territories covered
NIST 800-63-B
authentication-assurance guidelines the step-up maps to
Account takeover (ATO) is when a fraudster seizes control of a legitimate user's existing account, getting in with stolen or phished credentials, a SIM-swapped one-time code, a socially engineered password reset, or a hijacked session. Because the account and its credentials are real, the activity looks legitimate.
MFA (multi-factor authentication) proves a device rather than the person: SMS codes get SIM-swapped, phishing kits steal live sessions, and push prompts get fatigue-bombed. Incode re-proves the real human at the risky moment, closing the gaps MFA leaves open.
No. It's risk-based: it steps up only at high-risk events (a new-device login, a password or MFA reset, an account recovery, a large transfer, or a payee or beneficiary change), so normal traffic stays frictionless.
It replaces knowledge-based questions with a biometric re-proof: a selfie, or a full ID plus selfie for high-assurance recovery, so there's nothing for an attacker to guess or socially engineer.
Yes. Pre-built CIAM and IAM connectors (Auth0, Okta, Microsoft Entra, Ping), OIDC, a REST API, and SDKs. Your platform keeps the session; Incode proves a real human is present.
Because the check is biometric rather than an SMS code, a SIM swap doesn't help the attacker, and Incode can re-prove the account holder at a SIM change, port-out, or number transfer.
No. Passive liveness plus Deepsight block the deepfakes and injected feeds that defeat naive face checks.
Incode challenges only high-risk actions, and the check is a sub-second selfie, browser-based, with no app: far less friction than a locked account or a failed one-time code.
Anywhere accounts hold money or value: banking, wealth, fintech, crypto, marketplaces, telco, travel and loyalty, and gaming.
What's next
See how a biometric step-up closes the gaps MFA leaves open.
Answers come from across incode.com. For the full explainer, ask anything.