Home
Providers
Descope
Descope
Descope is a customer and agentic identity access management (CIAM) platform founded in 2022 by veterans of Sentrigo and Demisto (acquired by Palo Alto Networks). Its signature is drag-and-drop Descope Flows — a visual authentication-flow builder — paired with passwordless methods (passkeys, magic link, OTP, social, biometric), risk-based MFA, SSO/SAML/SCIM, fine-grained authorization, and a growing Agentic Identity Hub that issues scoped OAuth tokens to AI agents and MCP servers. Descope ships SDKs for every mainstream language and framework, a CLI, Terraform/Pulumi providers, self-hostable hosted-auth app, and prebuilt migration tools from Auth0, Cognito, Firebase, and Keycloak. Free tier covers 7,500 MAUs forever; paid tiers start at $249/month.
Descope publishes 16 APIs on the APIs.io network, including Apps API, Auth API, Custom Attributes API, and 13 more. Tagged areas include Authentication, Identity, CIAM, Passwordless, and Passkeys.
Descope’s developer surface includes authentication, developer portal, documentation, getting-started guide, API reference, developer console, signup flow, and 53 more developer resources.
16 APIs
23 Features
8 Use Cases
Authentication Identity CIAM Passwordless Passkeys MFA SSO OAuth OIDC SAML SCIM Authorization FGA Agentic Identity MCP
On this page
Kin Score
APIs 16
Open Collections 1
Features 23
Security Posture 3
Agentic Access 1
Use Cases 8
Integrations 10
Solutions 4
Resources 60
apis.yml
21 Operational Transparency
Composite quality — 47.1/100 · developing
Contract Quality
13.0 / 25
Developer Ergonomics
16.1 / 20
Commercial Clarity
7.9 / 20
Operational Transparency
2.7 / 13
Agent readiness — 28/100 · agent aware
Machine-Readable Contract
18 / 18
Agentic Access Contract
10 / 10
MCP Server
0 / 12
Machine-Readable Auth
10 / 10
Idempotency
0 / 9
Stable Error Semantics
0 / 8
Request/Response Examples
0 / 7
Rate-Limit Signaling
0 / 7
Typed Event Surface
0 / 6
Agent Skills
0 / 5
Well-Known Catalog
0 / 4
Consent & Bot Identity
0 / 3
A2A Agent Card
0 / 8
Dry-Run / Simulate Mode
0 / 4
Individual APIs this provider publishes, each with its own machine-readable definition.
Scroll for all 16
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Notable capabilities this provider offers.
Drag-and-drop Descope Flows for designing authentication, signup, MFA, step-up, and account-recovery journeys with no code
Passwordless authentication — magic links, enchanted links, passkeys/WebAuthn, OTP (email/SMS/voice/IM), nOTP push, TOTP authenticator apps, and Google One Tap
Social login and OIDC federation with 30+ providers
SAML 2.0 inbound and outbound SSO with self-service IdP configuration for B2B customers
WS-Federation IdP support for Microsoft enterprise tenants
SCIM 2.0 user and group provisioning
Fine-grained authorization (FGA / ReBAC) modeled after Google Zanzibar with schema, relation, and policy APIs
Role-based access control with company/project/tag-scoped management keys
Multi-tenant architecture with delegated admin widgets for B2B customer self-service
Risk-based / adaptive MFA via flow conditional logic and connectors (reCAPTCHA, Fingerprint, ipQualityScore)
Step-up authentication for sensitive transactions
50+ outbound connectors (HTTP, audit, AWS, Segment, Salesforce, HubSpot, Twilio, SendGrid, Slack, etc.)
Inbound third-party app OAuth — Descope as an OIDC/OAuth 2.1 authorization server
Agentic Identity Hub with MCP server registration, per-agent OAuth scopes, and token vaulting for AI agents (Claude, ChatGPT, Cursor, etc.)
OAuth 2.1, PKCE, JAR (RFC 9101), DPoP, CIBA, and device authorization flows
Anonymous-to-known user merging
Account takeover prevention with disposable-email/burner detection (go-free-email-providers)
Custom domains for hosted authentication pages
Hosted Flow app (React) with full source available for self-hosting
Terraform and Pulumi providers for declarative project management
CLI (`descopecli`) for project snapshot, import, export, and CI/CD pipelines
Audit log API and analytics API
Free 7,500 MAU forever tier
Scroll for all 23
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Recommended x-agentic-access execution contracts for AI agents.
What developers build with this provider.
Scroll for all 8
Pre-built integrations with other platforms and tools.
Scroll for all 10
Packaged solutions this provider offers.
Get Started 5
Portal, sign-up, and the first successful call
Documentation 4
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Build 34
SDKs, sample code, and the tooling you integrate with
Scroll for all 34
Access & Security 3
Authentication, authorization, and security posture
Learn 2
Tutorials, courses, talks, and written guidance
Operate 3
Status, limits, changes, and where to get help
Commercial 4
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 1
Properties that don't map to a standard resource type
Source (apis.yml)
aid: descope
url: https://raw.githubusercontent.com/api-evangelist/descope/refs/heads/main/apis.yml
apis:
- aid: descope:descope-apps-api
name: Descope Apps API
description: The Apps API from Descope — 4 operation(s) for apps.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Apps
properties:
- type: OpenAPI
url: openapi/descope-apps-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-auth-api
name: Descope Auth API
description: The Auth API from Descope — 52 operation(s) for auth.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Auth
properties:
- type: OpenAPI
url: openapi/descope-auth-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-custom-attributes-api
name: Descope Custom Attributes API
description: The Custom Attributes API from Descope — 3 operation(s) for custom attributes.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Custom Attributes
properties:
- type: OpenAPI
url: openapi/descope-custom-attributes-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-default-api
name: Descope Default API
description: The Default API from Descope — 10 operation(s) for default.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Default
properties:
- type: OpenAPI
url: openapi/descope-default-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-email-api
name: Descope Email API
description: The Email API from Descope — 10 operation(s) for email.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Email
properties:
- type: OpenAPI
url: openapi/descope-email-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-embedded-link-api
name: Descope Embedded Link API
description: The Embedded Link API from Descope — 1 operation(s) for embedded link.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Embedded Link
properties:
- type: OpenAPI
url: openapi/descope-embedded-link-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-fedcm-api
name: Descope Fedcm API
description: The Fedcm API from Descope — 2 operation(s) for fedcm.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Fedcm
properties:
- type: OpenAPI
url: openapi/descope-fedcm-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-instant-message-im-api
name: Descope Instant Message (IM) API
description: The Instant Message (IM) API from Descope — 5 operation(s) for instant message (im).
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Instant Message (IM)
properties:
- type: OpenAPI
url: openapi/descope-instant-message-im-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-keys-api
name: Descope Keys API
description: The Keys API from Descope — 2 operation(s) for keys.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Keys
properties:
- type: OpenAPI
url: openapi/descope-keys-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-mgmt-api
name: Descope Mgmt API
description: The Mgmt API from Descope — 276 operation(s) for mgmt.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Mgmt
properties:
- type: OpenAPI
url: openapi/descope-mgmt-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-oauth2-api
name: Descope Oauth2 API
description: The Oauth2 API from Descope — 30 operation(s) for oauth2.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Oauth2
properties:
- type: OpenAPI
url: openapi/descope-oauth2-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-scim-api
name: Descope Scim API
description: The Scim API from Descope — 6 operation(s) for scim.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Scim
properties:
- type: OpenAPI
url: openapi/descope-scim-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-text-message-sms-api
name: Descope Text Message (SMS) API
description: The Text Message (SMS) API from Descope — 9 operation(s) for text message (sms).
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Text Message (SMS)
properties:
- type: OpenAPI
url: openapi/descope-text-message-sms-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-verification-api
name: Descope Verification API
description: The Verification API from Descope — 1 operation(s) for verification.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Verification
properties:
- type: OpenAPI
url: openapi/descope-verification-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-voice-message-phone-api
name: Descope Voice Message (Phone) API
description: The Voice Message (Phone) API from Descope — 5 operation(s) for voice message (phone).
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- Voice Message (Phone)
properties:
- type: OpenAPI
url: openapi/descope-voice-message-phone-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
- aid: descope:descope-well-known-api
name: Descope .well Known API
description: The .well Known API from Descope — 6 operation(s) for .well known.
humanURL: https://docs.descope.com/api
baseURL: https://api.descope.com
tags:
- .well Known
properties:
- type: OpenAPI
url: openapi/descope-well-known-api-openapi.yml
- type: Documentation
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/auth-methods
- type: APIReference
url: https://docs.descope.com/api/openapi-spec
- type: Documentation
url: https://docs.descope.com/manage
- type: APIReference
url: https://docs.descope.com/api
- type: Documentation
url: https://docs.descope.com/inbound-apps
- type: Documentation
url: https://docs.descope.com/scim
- type: Documentation
url: https://docs.descope.com/jwks
name: Descope
tags:
- Authentication
- Identity
- CIAM
- Passwordless
- Passkeys
- MFA
- SSO
- OAuth
- OIDC
- SAML
- SCIM
- Authorization
- FGA
- Agentic Identity
- MCP
kind: contract
accessModel:
pricing: unknown
onboarding: self-serve
trial: false
try_now: false
public: false
label: Self-serve signup
confidence: medium
source:
- authentication
generated: '2026-07-22'
method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/descope.png
access: 3rd-Party
common:
- type: AgenticAccess
url: agentic-access/descope-agentic-access.yml
- type: TrustCenter
url: security/descope-trust-center.yml
- type: DomainSecurity
url: security/descope-domain-security.yml
- type: Authentication
url: authentication/descope-authentication.yml
- url: https://www.descope.com
type: Portal
- url: https://docs.descope.com
type: Documentation
- url: https://docs.descope.com/getting-started
type: GettingStarted
- url: https://docs.descope.com/api/openapi-spec
type: APIReference
- url: https://app.descope.com
type: Console
- url: https://www.descope.com/sign-up
type: Signup
- url: https://www.descope.com/pricing
data:
- id: free
name: Free Forever
entries:
- geo: Global
unit: 7500
label: Monthly Active Users
limit: 7500
price: 0
metric: mau
timeFrame: month
description: No-cost tier with 7,500 MAUs. No overages allowed — upgrade required to exceed limits.
elements:
- name: All authentication methods (OTP, magic link, passkeys, social, SSO, MFA)
- name: Drag-and-drop Descope Flows
- name: Role-based access control
- name: Multi-factor authentication
- name: Community support
description: Free tier for development, prototypes, and small applications.
- id: pro
name: Pro
entries:
- geo: Global
unit: 1
label: Starting Price
price: 249
metric: month
timeFrame: month
description: Annual billing. Includes 10,000 MAUs; usage-based overages apply.
- geo: Global
unit: 10000
label: Included MAUs
limit: 10000
metric: mau
timeFrame: month
description: Monthly active users included in the Pro tier.
elements:
- name: Everything in Free
- name: Custom domain
- name: Google One Tap
- name: CI/CD integration
- name: Web and Slack support
description: Production-ready tier for growing applications.
- id: growth
name: Growth
entries:
- geo: Global
unit: 1
label: Starting Price
price: 799
metric: month
timeFrame: month
description: Annual billing. Includes 25,000 MAUs; usage-based overages apply.
- geo: Global
unit: 25000
label: Included MAUs
limit: 25000
metric: mau
timeFrame: month
description: Monthly active users included in the Growth tier.
elements:
- name: Everything in Pro
- name: Bot protection
- name: 1M included anonymous users
- name: SCIM provisioning
- name: Fine-grained authorization (FGA)
description: For scaling B2B and B2C applications needing enterprise auth features.
- id: enterprise
name: Enterprise
entries:
- geo: Global
unit: 1
label: Custom
price: Call
metric: contract
timeFrame: year
description: Custom MAU limits and tiered volume discounts.
elements:
- name: Everything in Growth
- name: Tiered volume discounts
- name: Dedicated customer success engineer
- name: Custom deployments (single-tenant, private cloud, on-prem)
- name: Unlimited test users
- name: Unlimited anonymous users
- name: Premium support
description: For large enterprises with custom deployment and compliance requirements.
name: Plans
type: Plans
- url: https://www.descope.com/pricing
name: Pricing
type: Pricing
- url: https://www.descope.com/terms
type: TermsOfService
- url: https://www.descope.com/privacy
type: PrivacyPolicy
- url: https://descopestatus.com
type: StatusPage
- url: https://www.descope.com/blog
type: Blog
- url: https://www.descope.com/contact
type: Support
- url: https://www.descope.com/customers
type: CaseStudies
- url: https://www.descope.com/learn
type: Training
name: Learning Center
- url: https://www.descope.com/learn/post/agentic-identity-hub
type: Documentation
name: Agentic Identity Hub
- url: https://github.com/descope
type: GitHubOrganization
- url: https://github.com/descope/node-sdk
name: Node.js SDK
type: SDKs
- url: https://github.com/descope/python-sdk
name: Python SDK
type: SDKs
- url: https://github.com/descope/go-sdk
name: Go SDK
type: SDKs
- url: https://github.com/descope/descope-java
name: Java SDK
type: SDKs
- url: https://github.com/descope/descope-dotnet
name: .NET SDK
type: SDKs
- url: https://github.com/descope/descope-php
name: PHP SDK
type: SDKs
- url: https://github.com/descope/descope-ruby-sdk
name: Ruby SDK
type: SDKs
- url: https://github.com/descope/descope-swift
name: Swift (iOS) SDK
type: SDKs
- url: https://github.com/descope/descope-kotlin
name: Kotlin (Android) SDK
type: SDKs
- url: https://github.com/descope/descope-react-native
name: React Native SDK
type: SDKs
- url: https://github.com/descope/descope-flutter
name: Flutter SDK
type: SDKs
- url: https://github.com/descope/descope-js
name: JavaScript / React / Next.js / Vue / Angular / Web Components
type: SDKs
- url: https://github.com/descope/django-descope
name: Django Plugin
type: SDKs
- url: https://github.com/descope/passport-descope
name: Passport.js Strategy
type: SDKs
- url: https://github.com/descope/descope-wordpress
name: WordPress Plugin
type: Plugins
- url: https://github.com/descope/descopecli
name: descopecli
type: CLI
- url: https://github.com/descope/terraform-provider-descope
name: Terraform Provider
type: Tools
- url: https://github.com/descope/pulumi-descope
name: Pulumi Provider
type: Tools
- url: https://github.com/descope/auth-hosting
name: Auth Hosting (self-hostable Flows UI)
type: Tools
- url: https://github.com/descope/virtualwebauthn
name: VirtualWebAuthn (WebAuthn test tool)
type: Tools
- url: https://github.com/descope/mcp-express
name: MCP Express
type: Tools
- url: https://github.com/descope/mcp-go
name: MCP Go
type: Tools
- url: https://github.com/descope/descope-mcp
name: Descope MCP SDKs
type: Tools
- url: https://github.com/descope/skills
name: Descope Authentication Skills for AI Agents
type: Tools
- url: https://github.com/descope/ai
name: Descope Official AI Repository
type: Tools
- url: https://github.com/descope/descope-migration
name: Generic Migration Tool
type: Tools
- url: https://github.com/descope/descope-auth0-migration
name: Auth0 Migration Tool
type: Tools
- url: https://github.com/descope/descope-cognito-migration
name: Amazon Cognito Migration Tool
type: Tools
- url: https://github.com/descope/descope-firebase-migration
name: Firebase Migration Tool
type: Tools
- url: https://github.com/descope/descope-keycloak-migration
name: Keycloak Migration Tool
type: Tools
- url: https://github.com/descope/project-cicd-template
name: Project CI/CD Template (GitHub Actions)
type: Tools
- url: https://github.com/descope/project-gitlab-cicd-pipeline
name: Project CI/CD Template (GitLab)
type: Tools
- url: https://github.com/descope/sbt-aws-descope
name: AWS SaaS Builder Toolkit Integration
type: Tools
- url: https://www.linkedin.com/company/descope
type: LinkedIn
- url: https://twitter.com/descopeinc
type: Twitter
- url: https://www.youtube.com/@descopeinc
type: YouTube
- url: https://authtown.unstructured.chat
type: Forums
name: AuthTown Community
- type: Features
data:
- Drag-and-drop Descope Flows for designing authentication, signup, MFA, step-up, and account-recovery journeys with no
code
- Passwordless authentication — magic links, enchanted links, passkeys/WebAuthn, OTP (email/SMS/voice/IM), nOTP push, TOTP
authenticator apps, and Google One Tap
- Social login and OIDC federation with 30+ providers
- SAML 2.0 inbound and outbound SSO with self-service IdP configuration for B2B customers
- WS-Federation IdP support for Microsoft enterprise tenants
- SCIM 2.0 user and group provisioning
- Fine-grained authorization (FGA / ReBAC) modeled after Google Zanzibar with schema, relation, and policy APIs
- Role-based access control with company/project/tag-scoped management keys
- Multi-tenant architecture with delegated admin widgets for B2B customer self-service
- Risk-based / adaptive MFA via flow conditional logic and connectors (reCAPTCHA, Fingerprint, ipQualityScore)
- Step-up authentication for sensitive transactions
- 50+ outbound connectors (HTTP, audit, AWS, Segment, Salesforce, HubSpot, Twilio, SendGrid, Slack, etc.)
- Inbound third-party app OAuth — Descope as an OIDC/OAuth 2.1 authorization server
- Agentic Identity Hub with MCP server registration, per-agent OAuth scopes, and token vaulting for AI agents (Claude, ChatGPT,
Cursor, etc.)
- OAuth 2.1, PKCE, JAR (RFC 9101), DPoP, CIBA, and device authorization flows
- Anonymous-to-known user merging
- Account takeover prevention with disposable-email/burner detection (go-free-email-providers)
- Custom domains for hosted authentication pages
- Hosted Flow app (React) with full source available for self-hosting
- Terraform and Pulumi providers for declarative project management
- CLI (`descopecli`) for project snapshot, import, export, and CI/CD pipelines
- Audit log API and analytics API
- Free 7,500 MAU forever tier
sources:
- https://www.descope.com
- https://docs.descope.com
- https://docs.descope.com/api/openapi-spec
- https://www.descope.com/pricing
- https://github.com/descope
updated: '2026-05-25'
- type: UseCases
data:
- name: B2C Customer Authentication
description: Add passwordless sign-up/sign-in (passkeys, magic link, social) to consumer apps with adaptive MFA and account-takeover
protection.
- name: B2B Enterprise SSO
description: Let business customers self-serve SAML/OIDC SSO and SCIM provisioning without per-tenant engineering work,
using delegated admin widgets.
- name: Auth Migration
description: Migrate users from Auth0, Cognito, Firebase, Keycloak, and other IdPs with prebuilt Python-based migration
tools that preserve password hashes where possible.
- name: Agentic Identity for AI Agents
description: Issue scoped OAuth tokens to AI agents and MCP servers using progressive scoping, token vaulting, and per-agent
audit trails via the Agentic Identity Hub.
- name: Multi-Tenant SaaS
description: Model tenant hierarchies, delegated admin, per-tenant SSO, and tenant-scoped RBAC/FGA from a single Descope
project.
- name: Fine-Grained Authorization
description: Replace homegrown permission systems with a Zanzibar-style schema, relations, and policies via the FGA Management
API.
- name: Mobile Authentication
description: Native passkey, biometric, and social login in iOS, Android, React Native, and Flutter apps using Descope's
mobile SDKs.
- name: Compliance-Driven Auth
description: Use audit logs, custom message templates, MFA enforcement, and SOC 2 / GDPR controls to satisfy regulated-industry
requirements.
- type: Integrations
data:
- name: AWS
description: SaaS Builder Toolkit integration, Cognito migration, and IAM role assumption from GCP via OIDC GitHub Action.
- name: Cloudflare
description: Workers-based redirect worker for tenant-level SSO migration.
- name: Terraform
description: Official `terraform-provider-descope` for managing projects, flows, tenants, and SSO declaratively.
- name: Pulumi
description: Official `pulumi-descope` provider.
- name: WordPress
description: Descope auth plugin replacing native WordPress login.
- name: Django
description: '`django-descope` plugin for first-class Django auth integration.'
- name: Passport.js
description: '`passport-descope` strategy for Node.js apps using Passport.'
- name: Next.js / React / Vue / Angular / SvelteKit
description: Client SDKs and Flow web components shipped under `descope-js`.
- name: Salesforce / HubSpot / Segment / Twilio / SendGrid / Slack / S3 / Snowflake
description: 50+ outbound connectors invoked from inside Flows to enrich users, send messages, and stream events.
- name: Anthropic Claude / OpenAI / Cursor / MCP Clients
description: Agentic Identity Hub issues short-lived, scoped tokens to AI agents via MCP server registration and per-agent
OAuth.
- type: Solutions
data:
- name: Customer Identity (CIAM)
description: Drop-in B2C authentication with Flows, passwordless methods, and progressive profiling.
- name: Workforce-Adjacent B2B Identity
description: SAML SSO, SCIM, delegated admin, and tenant management for SaaS vendors selling to enterprises.
- name: Agentic Identity
description: OAuth issuance, MCP server registration, and credential vaulting for AI agents and autonomous workflows.
- name: Migration & Modernization
description: Tooling to lift users off legacy IdPs (Auth0, Cognito, Firebase, Keycloak) onto a modern, passwordless-first
platform.
- type: Portal
url: https://www.descope.com
- type: Documentation
url: https://docs.descope.com
created: '2026-05-25T00:00:00.000Z'
modified: '2026-05-25'
position: Consuming
description: Descope is a customer and agentic identity access management (CIAM) platform founded in 2022 by veterans of Sentrigo
and Demisto (acquired by Palo Alto Networks). Its signature is drag-and-drop Descope Flows — a visual authentication-flow
builder — paired with passwordless methods (passkeys, magic link, OTP, social, biometric), risk-based MFA, SSO/SAML/SCIM,
fine-grained authorization, and a growing Agentic Identity Hub that issues scoped OAuth tokens to AI agents and MCP servers.
Descope ships SDKs for every mainstream language and framework, a CLI, Terraform/Pulumi providers, self-hostable hosted-auth
app, and prebuilt migration tools from Auth0, Cognito, Firebase, and Keycloak. Free tier covers 7,500 MAUs forever; paid
tiers start at $249/month.
maintainers:
- FN: Kin Lane
email: info@apievangelist.com
X: apievangelist
url: https://apievangelist.com
specificationVersion: '0.16'