Descope website screenshot

Descope

Descope is a customer and agentic identity access management (CIAM) platform founded in 2022 by veterans of Sentrigo and Demisto (acquired by Palo Alto Networks). Its signature is drag-and-drop Descope Flows — a visual authentication-flow builder — paired with passwordless methods (passkeys, magic link, OTP, social, biometric), risk-based MFA, SSO/SAML/SCIM, fine-grained authorization, and a growing Agentic Identity Hub that issues scoped OAuth tokens to AI agents and MCP servers. Descope ships SDKs for every mainstream language and framework, a CLI, Terraform/Pulumi providers, self-hostable hosted-auth app, and prebuilt migration tools from Auth0, Cognito, Firebase, and Keycloak. Free tier covers 7,500 MAUs forever; paid tiers start at $249/month.

Descope publishes 16 APIs on the APIs.io network, including Apps API, Auth API, Custom Attributes API, and 13 more. Tagged areas include Authentication, Identity, CIAM, Passwordless, and Passkeys.

Descope’s developer surface includes authentication, developer portal, documentation, getting-started guide, API reference, developer console, signup flow, and 53 more developer resources.

47.1/100 developing ▬ flat Agent 28/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessSelf serve
16 APIs 23 Features 8 Use Cases
AuthenticationIdentityCIAMPasswordlessPasskeysMFASSOOAuthOIDCSAMLSCIMAuthorizationFGAAgentic IdentityMCP

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 47.1/100 · developing
Contract Quality 13.0 / 25
Developer Ergonomics 16.1 / 20
Commercial Clarity 7.9 / 20
Operational Transparency 2.7 / 13
Governance 0.0 / 12
Discoverability 7.4 / 10
Agent readiness — 28/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/descope: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 16

Individual APIs this provider publishes, each with its own machine-readable definition.

Descope Apps API

The Apps API from Descope — 4 operation(s) for apps.

Descope Auth API

The Auth API from Descope — 52 operation(s) for auth.

Descope Custom Attributes API

The Custom Attributes API from Descope — 3 operation(s) for custom attributes.

Descope Default API

The Default API from Descope — 10 operation(s) for default.

Descope Email API

The Email API from Descope — 10 operation(s) for email.

Descope Embedded Link API

The Embedded Link API from Descope — 1 operation(s) for embedded link.

Descope Fedcm API

The Fedcm API from Descope — 2 operation(s) for fedcm.

Descope Instant Message (IM) API

The Instant Message (IM) API from Descope — 5 operation(s) for instant message (im).

Descope Keys API

The Keys API from Descope — 2 operation(s) for keys.

Descope Mgmt API

The Mgmt API from Descope — 276 operation(s) for mgmt.

Descope Oauth2 API

The Oauth2 API from Descope — 30 operation(s) for oauth2.

Descope Scim API

The Scim API from Descope — 6 operation(s) for scim.

Descope Text Message (SMS) API

The Text Message (SMS) API from Descope — 9 operation(s) for text message (sms).

Descope Verification API

The Verification API from Descope — 1 operation(s) for verification.

Descope Voice Message (Phone) API

The Voice Message (Phone) API from Descope — 5 operation(s) for voice message (phone).

Descope .well Known API

The .well Known API from Descope — 6 operation(s) for .well known.

Scroll for all 16

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Descope API

OPEN COLLECTION

Features 23

Notable capabilities this provider offers.

Drag-and-drop Descope Flows for designing authentication, signup, MFA, step-up, and account-recovery journeys with no code
Passwordless authentication — magic links, enchanted links, passkeys/WebAuthn, OTP (email/SMS/voice/IM), nOTP push, TOTP authenticator apps, and Google One Tap
Social login and OIDC federation with 30+ providers
SAML 2.0 inbound and outbound SSO with self-service IdP configuration for B2B customers
WS-Federation IdP support for Microsoft enterprise tenants
SCIM 2.0 user and group provisioning
Fine-grained authorization (FGA / ReBAC) modeled after Google Zanzibar with schema, relation, and policy APIs
Role-based access control with company/project/tag-scoped management keys
Multi-tenant architecture with delegated admin widgets for B2B customer self-service
Risk-based / adaptive MFA via flow conditional logic and connectors (reCAPTCHA, Fingerprint, ipQualityScore)
Step-up authentication for sensitive transactions
50+ outbound connectors (HTTP, audit, AWS, Segment, Salesforce, HubSpot, Twilio, SendGrid, Slack, etc.)
Inbound third-party app OAuth — Descope as an OIDC/OAuth 2.1 authorization server
Agentic Identity Hub with MCP server registration, per-agent OAuth scopes, and token vaulting for AI agents (Claude, ChatGPT, Cursor, etc.)
OAuth 2.1, PKCE, JAR (RFC 9101), DPoP, CIBA, and device authorization flows
Anonymous-to-known user merging
Account takeover prevention with disposable-email/burner detection (go-free-email-providers)
Custom domains for hosted authentication pages
Hosted Flow app (React) with full source available for self-hosting
Terraform and Pulumi providers for declarative project management
CLI (`descopecli`) for project snapshot, import, export, and CI/CD pipelines
Audit log API and analytics API
Free 7,500 MAU forever tier

Scroll for all 23

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Descope Authentication

http · 1 scheme

SECURITY

Descope Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Descope Trust Center

SOC 2, ISO 27001

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Descope Agentic Access

459 operations · 375 acting · 8 human-in-the-loop

459 operations · 375 acting

AGENTIC

Use Cases 8

What developers build with this provider.

B2C Customer Authentication

Add passwordless sign-up/sign-in (passkeys, magic link, social) to consumer apps with adaptive MFA and account-takeover protection.

B2B Enterprise SSO

Let business customers self-serve SAML/OIDC SSO and SCIM provisioning without per-tenant engineering work, using delegated admin widgets.

Auth Migration

Migrate users from Auth0, Cognito, Firebase, Keycloak, and other IdPs with prebuilt Python-based migration tools that preserve password hashes where possible.

Agentic Identity for AI Agents

Issue scoped OAuth tokens to AI agents and MCP servers using progressive scoping, token vaulting, and per-agent audit trails via the Agentic Identity Hub.

Multi-Tenant SaaS

Model tenant hierarchies, delegated admin, per-tenant SSO, and tenant-scoped RBAC/FGA from a single Descope project.

Fine-Grained Authorization

Replace homegrown permission systems with a Zanzibar-style schema, relations, and policies via the FGA Management API.

Mobile Authentication

Native passkey, biometric, and social login in iOS, Android, React Native, and Flutter apps using Descope's mobile SDKs.

Compliance-Driven Auth

Use audit logs, custom message templates, MFA enforcement, and SOC 2 / GDPR controls to satisfy regulated-industry requirements.

Scroll for all 8

Integrations 10

Pre-built integrations with other platforms and tools.

AWS

SaaS Builder Toolkit integration, Cognito migration, and IAM role assumption from GCP via OIDC GitHub Action.

Cloudflare

Workers-based redirect worker for tenant-level SSO migration.

Terraform

Official `terraform-provider-descope` for managing projects, flows, tenants, and SSO declaratively.

Pulumi

Official `pulumi-descope` provider.

WordPress

Descope auth plugin replacing native WordPress login.

Django

`django-descope` plugin for first-class Django auth integration.

Passport.js

`passport-descope` strategy for Node.js apps using Passport.

Next.js / React / Vue / Angular / SvelteKit

Client SDKs and Flow web components shipped under `descope-js`.

Salesforce / HubSpot / Segment / Twilio / SendGrid / Slack / S3 / Snowflake

50+ outbound connectors invoked from inside Flows to enrich users, send messages, and stream events.

Anthropic Claude / OpenAI / Cursor / MCP Clients

Agentic Identity Hub issues short-lived, scoped tokens to AI agents via MCP server registration and per-agent OAuth.

Scroll for all 10

Solutions 4

Packaged solutions this provider offers.

Customer Identity (CIAM)

Drop-in B2C authentication with Flows, passwordless methods, and progressive profiling.

Workforce-Adjacent B2B Identity

SAML SSO, SCIM, delegated admin, and tenant management for SaaS vendors selling to enterprises.

Agentic Identity

OAuth issuance, MCP server registration, and credential vaulting for AI agents and autonomous workflows.

Migration & Modernization

Tooling to lift users off legacy IdPs (Auth0, Cognito, Firebase, Keycloak) onto a modern, passwordless-first platform.

Resources

Get Started 5

Portal, sign-up, and the first successful call

Documentation 4

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Build 34

SDKs, sample code, and the tooling you integrate with

Scroll for all 34

Access & Security 3

Authentication, authorization, and security posture

Learn 2

Tutorials, courses, talks, and written guidance

Operate 3

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: descope
url: https://raw.githubusercontent.com/api-evangelist/descope/refs/heads/main/apis.yml
apis:
- aid: descope:descope-apps-api
  name: Descope Apps API
  description: The Apps API from Descope — 4 operation(s) for apps.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Apps
  properties:
  - type: OpenAPI
    url: openapi/descope-apps-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-auth-api
  name: Descope Auth API
  description: The Auth API from Descope — 52 operation(s) for auth.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Auth
  properties:
  - type: OpenAPI
    url: openapi/descope-auth-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-custom-attributes-api
  name: Descope Custom Attributes API
  description: The Custom Attributes API from Descope — 3 operation(s) for custom attributes.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Custom Attributes
  properties:
  - type: OpenAPI
    url: openapi/descope-custom-attributes-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-default-api
  name: Descope Default API
  description: The Default API from Descope — 10 operation(s) for default.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Default
  properties:
  - type: OpenAPI
    url: openapi/descope-default-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-email-api
  name: Descope Email API
  description: The Email API from Descope — 10 operation(s) for email.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Email
  properties:
  - type: OpenAPI
    url: openapi/descope-email-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-embedded-link-api
  name: Descope Embedded Link API
  description: The Embedded Link API from Descope — 1 operation(s) for embedded link.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Embedded Link
  properties:
  - type: OpenAPI
    url: openapi/descope-embedded-link-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-fedcm-api
  name: Descope Fedcm API
  description: The Fedcm API from Descope — 2 operation(s) for fedcm.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Fedcm
  properties:
  - type: OpenAPI
    url: openapi/descope-fedcm-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-instant-message-im-api
  name: Descope Instant Message (IM) API
  description: The Instant Message (IM) API from Descope — 5 operation(s) for instant message (im).
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Instant Message (IM)
  properties:
  - type: OpenAPI
    url: openapi/descope-instant-message-im-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-keys-api
  name: Descope Keys API
  description: The Keys API from Descope — 2 operation(s) for keys.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Keys
  properties:
  - type: OpenAPI
    url: openapi/descope-keys-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-mgmt-api
  name: Descope Mgmt API
  description: The Mgmt API from Descope — 276 operation(s) for mgmt.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Mgmt
  properties:
  - type: OpenAPI
    url: openapi/descope-mgmt-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-oauth2-api
  name: Descope Oauth2 API
  description: The Oauth2 API from Descope — 30 operation(s) for oauth2.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Oauth2
  properties:
  - type: OpenAPI
    url: openapi/descope-oauth2-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-scim-api
  name: Descope Scim API
  description: The Scim API from Descope — 6 operation(s) for scim.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Scim
  properties:
  - type: OpenAPI
    url: openapi/descope-scim-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-text-message-sms-api
  name: Descope Text Message (SMS) API
  description: The Text Message (SMS) API from Descope — 9 operation(s) for text message (sms).
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Text Message (SMS)
  properties:
  - type: OpenAPI
    url: openapi/descope-text-message-sms-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-verification-api
  name: Descope Verification API
  description: The Verification API from Descope — 1 operation(s) for verification.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Verification
  properties:
  - type: OpenAPI
    url: openapi/descope-verification-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-voice-message-phone-api
  name: Descope Voice Message (Phone) API
  description: The Voice Message (Phone) API from Descope — 5 operation(s) for voice message (phone).
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - Voice Message (Phone)
  properties:
  - type: OpenAPI
    url: openapi/descope-voice-message-phone-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
- aid: descope:descope-well-known-api
  name: Descope .well Known API
  description: The .well Known API from Descope — 6 operation(s) for .well known.
  humanURL: https://docs.descope.com/api
  baseURL: https://api.descope.com
  tags:
  - .well Known
  properties:
  - type: OpenAPI
    url: openapi/descope-well-known-api-openapi.yml
  - type: Documentation
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/auth-methods
  - type: APIReference
    url: https://docs.descope.com/api/openapi-spec
  - type: Documentation
    url: https://docs.descope.com/manage
  - type: APIReference
    url: https://docs.descope.com/api
  - type: Documentation
    url: https://docs.descope.com/inbound-apps
  - type: Documentation
    url: https://docs.descope.com/scim
  - type: Documentation
    url: https://docs.descope.com/jwks
name: Descope
tags:
- Authentication
- Identity
- CIAM
- Passwordless
- Passkeys
- MFA
- SSO
- OAuth
- OIDC
- SAML
- SCIM
- Authorization
- FGA
- Agentic Identity
- MCP
kind: contract
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/descope.png
access: 3rd-Party
common:
- type: AgenticAccess
  url: agentic-access/descope-agentic-access.yml
- type: TrustCenter
  url: security/descope-trust-center.yml
- type: DomainSecurity
  url: security/descope-domain-security.yml
- type: Authentication
  url: authentication/descope-authentication.yml
- url: https://www.descope.com
  type: Portal
- url: https://docs.descope.com
  type: Documentation
- url: https://docs.descope.com/getting-started
  type: GettingStarted
- url: https://docs.descope.com/api/openapi-spec
  type: APIReference
- url: https://app.descope.com
  type: Console
- url: https://www.descope.com/sign-up
  type: Signup
- url: https://www.descope.com/pricing
  data:
  - id: free
    name: Free Forever
    entries:
    - geo: Global
      unit: 7500
      label: Monthly Active Users
      limit: 7500
      price: 0
      metric: mau
      timeFrame: month
      description: No-cost tier with 7,500 MAUs. No overages allowed — upgrade required to exceed limits.
    elements:
    - name: All authentication methods (OTP, magic link, passkeys, social, SSO, MFA)
    - name: Drag-and-drop Descope Flows
    - name: Role-based access control
    - name: Multi-factor authentication
    - name: Community support
    description: Free tier for development, prototypes, and small applications.
  - id: pro
    name: Pro
    entries:
    - geo: Global
      unit: 1
      label: Starting Price
      price: 249
      metric: month
      timeFrame: month
      description: Annual billing. Includes 10,000 MAUs; usage-based overages apply.
    - geo: Global
      unit: 10000
      label: Included MAUs
      limit: 10000
      metric: mau
      timeFrame: month
      description: Monthly active users included in the Pro tier.
    elements:
    - name: Everything in Free
    - name: Custom domain
    - name: Google One Tap
    - name: CI/CD integration
    - name: Web and Slack support
    description: Production-ready tier for growing applications.
  - id: growth
    name: Growth
    entries:
    - geo: Global
      unit: 1
      label: Starting Price
      price: 799
      metric: month
      timeFrame: month
      description: Annual billing. Includes 25,000 MAUs; usage-based overages apply.
    - geo: Global
      unit: 25000
      label: Included MAUs
      limit: 25000
      metric: mau
      timeFrame: month
      description: Monthly active users included in the Growth tier.
    elements:
    - name: Everything in Pro
    - name: Bot protection
    - name: 1M included anonymous users
    - name: SCIM provisioning
    - name: Fine-grained authorization (FGA)
    description: For scaling B2B and B2C applications needing enterprise auth features.
  - id: enterprise
    name: Enterprise
    entries:
    - geo: Global
      unit: 1
      label: Custom
      price: Call
      metric: contract
      timeFrame: year
      description: Custom MAU limits and tiered volume discounts.
    elements:
    - name: Everything in Growth
    - name: Tiered volume discounts
    - name: Dedicated customer success engineer
    - name: Custom deployments (single-tenant, private cloud, on-prem)
    - name: Unlimited test users
    - name: Unlimited anonymous users
    - name: Premium support
    description: For large enterprises with custom deployment and compliance requirements.
  name: Plans
  type: Plans
- url: https://www.descope.com/pricing
  name: Pricing
  type: Pricing
- url: https://www.descope.com/terms
  type: TermsOfService
- url: https://www.descope.com/privacy
  type: PrivacyPolicy
- url: https://descopestatus.com
  type: StatusPage
- url: https://www.descope.com/blog
  type: Blog
- url: https://www.descope.com/contact
  type: Support
- url: https://www.descope.com/customers
  type: CaseStudies
- url: https://www.descope.com/learn
  type: Training
  name: Learning Center
- url: https://www.descope.com/learn/post/agentic-identity-hub
  type: Documentation
  name: Agentic Identity Hub
- url: https://github.com/descope
  type: GitHubOrganization
- url: https://github.com/descope/node-sdk
  name: Node.js SDK
  type: SDKs
- url: https://github.com/descope/python-sdk
  name: Python SDK
  type: SDKs
- url: https://github.com/descope/go-sdk
  name: Go SDK
  type: SDKs
- url: https://github.com/descope/descope-java
  name: Java SDK
  type: SDKs
- url: https://github.com/descope/descope-dotnet
  name: .NET SDK
  type: SDKs
- url: https://github.com/descope/descope-php
  name: PHP SDK
  type: SDKs
- url: https://github.com/descope/descope-ruby-sdk
  name: Ruby SDK
  type: SDKs
- url: https://github.com/descope/descope-swift
  name: Swift (iOS) SDK
  type: SDKs
- url: https://github.com/descope/descope-kotlin
  name: Kotlin (Android) SDK
  type: SDKs
- url: https://github.com/descope/descope-react-native
  name: React Native SDK
  type: SDKs
- url: https://github.com/descope/descope-flutter
  name: Flutter SDK
  type: SDKs
- url: https://github.com/descope/descope-js
  name: JavaScript / React / Next.js / Vue / Angular / Web Components
  type: SDKs
- url: https://github.com/descope/django-descope
  name: Django Plugin
  type: SDKs
- url: https://github.com/descope/passport-descope
  name: Passport.js Strategy
  type: SDKs
- url: https://github.com/descope/descope-wordpress
  name: WordPress Plugin
  type: Plugins
- url: https://github.com/descope/descopecli
  name: descopecli
  type: CLI
- url: https://github.com/descope/terraform-provider-descope
  name: Terraform Provider
  type: Tools
- url: https://github.com/descope/pulumi-descope
  name: Pulumi Provider
  type: Tools
- url: https://github.com/descope/auth-hosting
  name: Auth Hosting (self-hostable Flows UI)
  type: Tools
- url: https://github.com/descope/virtualwebauthn
  name: VirtualWebAuthn (WebAuthn test tool)
  type: Tools
- url: https://github.com/descope/mcp-express
  name: MCP Express
  type: Tools
- url: https://github.com/descope/mcp-go
  name: MCP Go
  type: Tools
- url: https://github.com/descope/descope-mcp
  name: Descope MCP SDKs
  type: Tools
- url: https://github.com/descope/skills
  name: Descope Authentication Skills for AI Agents
  type: Tools
- url: https://github.com/descope/ai
  name: Descope Official AI Repository
  type: Tools
- url: https://github.com/descope/descope-migration
  name: Generic Migration Tool
  type: Tools
- url: https://github.com/descope/descope-auth0-migration
  name: Auth0 Migration Tool
  type: Tools
- url: https://github.com/descope/descope-cognito-migration
  name: Amazon Cognito Migration Tool
  type: Tools
- url: https://github.com/descope/descope-firebase-migration
  name: Firebase Migration Tool
  type: Tools
- url: https://github.com/descope/descope-keycloak-migration
  name: Keycloak Migration Tool
  type: Tools
- url: https://github.com/descope/project-cicd-template
  name: Project CI/CD Template (GitHub Actions)
  type: Tools
- url: https://github.com/descope/project-gitlab-cicd-pipeline
  name: Project CI/CD Template (GitLab)
  type: Tools
- url: https://github.com/descope/sbt-aws-descope
  name: AWS SaaS Builder Toolkit Integration
  type: Tools
- url: https://www.linkedin.com/company/descope
  type: LinkedIn
- url: https://twitter.com/descopeinc
  type: Twitter
- url: https://www.youtube.com/@descopeinc
  type: YouTube
- url: https://authtown.unstructured.chat
  type: Forums
  name: AuthTown Community
- type: Features
  data:
  - Drag-and-drop Descope Flows for designing authentication, signup, MFA, step-up, and account-recovery journeys with no
    code
  - Passwordless authentication — magic links, enchanted links, passkeys/WebAuthn, OTP (email/SMS/voice/IM), nOTP push, TOTP
    authenticator apps, and Google One Tap
  - Social login and OIDC federation with 30+ providers
  - SAML 2.0 inbound and outbound SSO with self-service IdP configuration for B2B customers
  - WS-Federation IdP support for Microsoft enterprise tenants
  - SCIM 2.0 user and group provisioning
  - Fine-grained authorization (FGA / ReBAC) modeled after Google Zanzibar with schema, relation, and policy APIs
  - Role-based access control with company/project/tag-scoped management keys
  - Multi-tenant architecture with delegated admin widgets for B2B customer self-service
  - Risk-based / adaptive MFA via flow conditional logic and connectors (reCAPTCHA, Fingerprint, ipQualityScore)
  - Step-up authentication for sensitive transactions
  - 50+ outbound connectors (HTTP, audit, AWS, Segment, Salesforce, HubSpot, Twilio, SendGrid, Slack, etc.)
  - Inbound third-party app OAuth — Descope as an OIDC/OAuth 2.1 authorization server
  - Agentic Identity Hub with MCP server registration, per-agent OAuth scopes, and token vaulting for AI agents (Claude, ChatGPT,
    Cursor, etc.)
  - OAuth 2.1, PKCE, JAR (RFC 9101), DPoP, CIBA, and device authorization flows
  - Anonymous-to-known user merging
  - Account takeover prevention with disposable-email/burner detection (go-free-email-providers)
  - Custom domains for hosted authentication pages
  - Hosted Flow app (React) with full source available for self-hosting
  - Terraform and Pulumi providers for declarative project management
  - CLI (`descopecli`) for project snapshot, import, export, and CI/CD pipelines
  - Audit log API and analytics API
  - Free 7,500 MAU forever tier
  sources:
  - https://www.descope.com
  - https://docs.descope.com
  - https://docs.descope.com/api/openapi-spec
  - https://www.descope.com/pricing
  - https://github.com/descope
  updated: '2026-05-25'
- type: UseCases
  data:
  - name: B2C Customer Authentication
    description: Add passwordless sign-up/sign-in (passkeys, magic link, social) to consumer apps with adaptive MFA and account-takeover
      protection.
  - name: B2B Enterprise SSO
    description: Let business customers self-serve SAML/OIDC SSO and SCIM provisioning without per-tenant engineering work,
      using delegated admin widgets.
  - name: Auth Migration
    description: Migrate users from Auth0, Cognito, Firebase, Keycloak, and other IdPs with prebuilt Python-based migration
      tools that preserve password hashes where possible.
  - name: Agentic Identity for AI Agents
    description: Issue scoped OAuth tokens to AI agents and MCP servers using progressive scoping, token vaulting, and per-agent
      audit trails via the Agentic Identity Hub.
  - name: Multi-Tenant SaaS
    description: Model tenant hierarchies, delegated admin, per-tenant SSO, and tenant-scoped RBAC/FGA from a single Descope
      project.
  - name: Fine-Grained Authorization
    description: Replace homegrown permission systems with a Zanzibar-style schema, relations, and policies via the FGA Management
      API.
  - name: Mobile Authentication
    description: Native passkey, biometric, and social login in iOS, Android, React Native, and Flutter apps using Descope's
      mobile SDKs.
  - name: Compliance-Driven Auth
    description: Use audit logs, custom message templates, MFA enforcement, and SOC 2 / GDPR controls to satisfy regulated-industry
      requirements.
- type: Integrations
  data:
  - name: AWS
    description: SaaS Builder Toolkit integration, Cognito migration, and IAM role assumption from GCP via OIDC GitHub Action.
  - name: Cloudflare
    description: Workers-based redirect worker for tenant-level SSO migration.
  - name: Terraform
    description: Official `terraform-provider-descope` for managing projects, flows, tenants, and SSO declaratively.
  - name: Pulumi
    description: Official `pulumi-descope` provider.
  - name: WordPress
    description: Descope auth plugin replacing native WordPress login.
  - name: Django
    description: '`django-descope` plugin for first-class Django auth integration.'
  - name: Passport.js
    description: '`passport-descope` strategy for Node.js apps using Passport.'
  - name: Next.js / React / Vue / Angular / SvelteKit
    description: Client SDKs and Flow web components shipped under `descope-js`.
  - name: Salesforce / HubSpot / Segment / Twilio / SendGrid / Slack / S3 / Snowflake
    description: 50+ outbound connectors invoked from inside Flows to enrich users, send messages, and stream events.
  - name: Anthropic Claude / OpenAI / Cursor / MCP Clients
    description: Agentic Identity Hub issues short-lived, scoped tokens to AI agents via MCP server registration and per-agent
      OAuth.
- type: Solutions
  data:
  - name: Customer Identity (CIAM)
    description: Drop-in B2C authentication with Flows, passwordless methods, and progressive profiling.
  - name: Workforce-Adjacent B2B Identity
    description: SAML SSO, SCIM, delegated admin, and tenant management for SaaS vendors selling to enterprises.
  - name: Agentic Identity
    description: OAuth issuance, MCP server registration, and credential vaulting for AI agents and autonomous workflows.
  - name: Migration & Modernization
    description: Tooling to lift users off legacy IdPs (Auth0, Cognito, Firebase, Keycloak) onto a modern, passwordless-first
      platform.
- type: Portal
  url: https://www.descope.com
- type: Documentation
  url: https://docs.descope.com
created: '2026-05-25T00:00:00.000Z'
modified: '2026-05-25'
position: Consuming
description: Descope is a customer and agentic identity access management (CIAM) platform founded in 2022 by veterans of Sentrigo
  and Demisto (acquired by Palo Alto Networks). Its signature is drag-and-drop Descope Flows — a visual authentication-flow
  builder — paired with passwordless methods (passkeys, magic link, OTP, social, biometric), risk-based MFA, SSO/SAML/SCIM,
  fine-grained authorization, and a growing Agentic Identity Hub that issues scoped OAuth tokens to AI agents and MCP servers.
  Descope ships SDKs for every mainstream language and framework, a CLI, Terraform/Pulumi providers, self-hostable hosted-auth
  app, and prebuilt migration tools from Auth0, Cognito, Firebase, and Keycloak. Free tier covers 7,500 MAUs forever; paid
  tiers start at $249/month.
maintainers:
- FN: Kin Lane
  email: info@apievangelist.com
  X: apievangelist
  url: https://apievangelist.com
specificationVersion: '0.16'