Skip to main contentArrow Right
Descope Named in the 2026 Gartner® Hype Cycle™ for Digital Identity Thumbnail

Table of Contents

Summarize with AI

Don't have the time to read the entire post? Our human writers will be sad, but we understand. Summarize the post with your preferred LLM here instead.

On July 6, 2026, Gartner published its Hype Cycle for Digital Identity, 2026, tracking the innovations shaping how organizations establish, secure, and manage digital identities. We’re proud to share that Descope is listed as a Sample Vendor in two categories: CIAM for AI Agents and Journey-Time Orchestration. 

Gartner Hype Cycles map innovations across five phases of maturity, helping cybersecurity leaders gauge where a technology sits on its journey to mainstream adoption. In our view, the two categories where Descope appears as a Sample Vendor tell a story about both ends of that journey:

  • CIAM for AI Agents is one of six new entrants on this year’s Hype Cycle. It sits on the first maturity phase, the Innovation Trigger

  • Journey-Time Orchestration is climbing the fourth, the Slope of Enlightenment, as an early mainstream discipline. Both categories are given a High benefit rating in the report.

This inclusion follows Descope’s Honorable Mention in the 2025 Gartner Magic Quadrant for Access Management, continuing a year in which we have closely tracked Gartner’s guidance on agentic identity. Our own reflections on the IAM Adapts to Secure and Enable AI Agents report demonstrate how Descope’s methodology maps cleanly to Gartner recommendations.

This blog will share our reflections on the two categories in which Descope is named, what the report says about each, and how Descope continues to align with the direction charted by Gartner.

How digital identity and AI have intertwined

The report opens with a framing that we feel captures the current moment. Gartner says:

“The digital identity landscape is being transformed by AI agents, identity visibility and identity threats. Cybersecurity leaders should use this Hype Cycle to foster innovation and investment to securely enable an adaptable digital business.”

Of the six new entrants on this year’s Hype Cycle, most are directly linked to AI agents and other workloads, including innovations like workload access management, AI agent identity, and intent-based access control. 

The report also states:

“The hype surrounding AI agents is contributing to many innovations specifically for workload IAM. Gartner’s 2025 Machine Identity survey revealed that 94% of organizations are dealing with increased machine identities, largely driven by AI and AI agent deployments.”

In our view, this mirrors what we see across the Descope customer base: identity is no longer a human-only concern, and the organizations moving fastest are the ones treating agentic identity as a present requirement rather than a future investment. 

The Gartner® Report: IAM Adapts to Secure and Enable AI Agents from January 2026 states:

“Through 2029, over 50% of successful cybersecurity attacks against AI agents will exploit access control issues, using direct or indirect prompt injection as an attack vector.”

Our reading is that pursuing dedicated solutions for agentic identity now will prevent security gaps and costly rebuilds later.

Nowhere is this better explained than the OWASP Top 10 for Agentic Applications: each threat description cites at least one identity-related mitigation. Read our full analysis of the OWASP recommendations and see how Descope addresses every threat to agentic applications.

An infographic titled Auth and Access Control Critical for AI Agent Security on a dark blue gradient background. Subtext states that every threat in the OWASP Top 10 for Agentic Applications cites identity-related mitigations. The image presents a two-column list of threats and their corresponding mitigations. Threats include Agent Goal Hijack, Tool Misuse Exploitation, Identity and Privilege Abuse, Agentic Supply Chain Vuln, Unexpected Code Execution, Memory Context Poisoning, Insecure Inter-Agent Comms, Cascading Failures, Human-Agent Trust Exploit, and Rogue Agents. Mitigations emphasize strategies such as least privilege, ephemeral access, short-lived tokens, mutual authentication via mTLS, and human approval for high-impact actions. The descope logo is in the top right corner.
Fig: OWASP Agentic Top 10

CIAM for AI Agents and the customer agentic era

CIAM for AI Agents is a new entrant in this year’s Hype Cycle, debuting on the Innovation Trigger with a High benefit rating. The category name is Gartner’s, and our read is that it describes a shift we’ve been building toward for some time: extending customer identity and access management (CIAM) beyond human users to the AI agents acting on their behalf. This means authenticating agents as distinct actors, letting customers delegate narrowly scoped access to their agents, verifying and binding the customer behind each agent, managing consent, and preventing account takeover in interactions where no human is directly at the keyboard.

The report states:

“Customer IAM solutions are engineered to manage diverse, large-scale customer identities and ensure a frictionless digital experience. Cybersecurity leaders must adopt IAM capabilities to securely manage AI agent identities in customer-facing contexts given the emergence of use cases where customers send AI agents to interact with organizations.”

We believe this is one of the most consequential shifts in customer identity since the move to passwordless. Businesses already deploy AI agents to engage customers, and customers are beginning to send their own agents to make purchases and manage accounts. 

Gartner says:

“Use of AI agents in customer-facing scenarios presents a range of cybersecurity challenges that will need to be addressed using CIAM for AI agents. These include managing authentication and authorization mechanisms, delegating access from customers to AI agents, and verifying the identity of customers behind AI agents and being able to bind the two securely.”

In our reading, the last statement gets to the heart of the agentic identity challenge: delegation without binding is a liability. If an organization cannot reliably, securely tie an agent’s actions back to the customer who authorized them, it cannot scope, audit, or revoke that access, and account takeover prevention becomes guesswork. 

This is the exact problem we built the Descope Agentic Identity Hub to solve. Customers authorize agents through OAuth 2.1-based consent flows, agents receive their own short-lived, scoped credentials linked back to the authorizing user, and the credential vault (Descope Connections) ensures agents never handle raw user credentials directly. 

The Descope Agentic Identity Hub showing AI agent connection templates for credential management and storage.
Fig: AI agent connection templates for credential management and storage

Our reading is that the report’s user recommendations also address the build vs. buy question. Gartner says:

“Look to vendor-provided capabilities rather than attempt to build CIAM tooling in-house in order to manage costs and demands on resources. In the first instance, evaluate whether your existing CIAM vendors can meet requirements to support agent interactions. If your incumbent CIAM vendor is incapable, look for a dedicated vendor that can manage the agent interactions and integrate with your incumbent platform.”

In our view, this statement echoes a pattern we’ve observed across hundreds of customer conversations: organizations that build identity in-house end up committing to being identity companies on top of their actual business. We believe the agentic era raises those takes even further.

Alongside familiar CIAM requirements, security teams now face niche infrastructure like Dynamic Client Registration (DCR), Client ID Metadata Documents (CIMD), consent management, per-agent and per-tool scopes, and Model Context Protocol (MCP) authorization flows. Prior to the AI boom, these were rare even within the auth vertical, and they continue to present relatively novel identity challenges for teams who are hearing about them for the first time. 

Read more: AI Agent Credential Management Best Practices

The Agentic Identity Hub offloads that burden with dedicated agentic identities, policy-driven access control, and scope-aware step-up authentication for sensitive operations. 

Agentic Identity Management with the Descope Agentic Identity Hub
Fig: Agentic identity management with the Descope Agentic Identity Hub

Production-ready agentic identity

While Gartner places the CIAM for AI Agents category early in its journey, Descope’s Agentic Identity Hub is already production infrastructure. It powers hundreds of MCP servers and millions of agentic transactions.

A few of the customers running Descope agentic identity in production today:

  • You.com: Protects their MCP server with OAuth 2.1, secure client registration, and token management without rewriting their backend APIs. Read the case study.

  • WisdomAI: Took MCP auth from concept to production in roughly a day and a half, freeing their dev team to focus on core AI capabilities rather than auth. Read the case study.

  • Token Security: Extended the same roles and tenants that govern human access to control what AI clients can do on their MCP server. Read the case study.

You.com Login
Fig: The You.com login screen, powered by Descope

How Journey-Time Orchestration unifies customer identity

Journey-Time Orchestration (JTO) appears on the Slope of Enlightenment with a High benefit rating and early mainstream maturity. In our view, this reflects a discipline that has proven its value and is heading toward broader adoption. This is familiar territory for Descope, as we’ve been named a Representative Vendor for our JTO capabilities in three previous Gartner Hype Cycle reports: the 2025 Hype Cycle for Digital Identity, the 2025 Hype Cycle for Banking Customer Experience, and the 2025 Hype Cycle for Fraud and Financial Crime Prevention.

Journey-time orchestration is Gartner’s term for a capability we consider foundational to modern customer identity. Most identity stacks accumulate separate tools for identity verification, authentication, account takeover prevention, and registration. By default, none of these talk to each other. Risk is assessed at isolated checkpoints instead of as a continuous stream across the session, with one blunt policy threshold applied to every user.

JTO is the layer connecting these disconnected elements, evaluating risk signals throughout an active journey, and adapting the experience to what it finds. 

Read more: What Is Journey-Time Orchestration (JTO)?

The report states:

“Journey-time orchestration (JTO) solutions improve risk management along digital user journeys and deliver optimized user experience (UX). Most organizations manage multiple identity verification, authentication and account takeover (ATO) prevention tools, and adjacent capabilities such as user registration. A JTO solution manages the integration of these tools, simplifies assessment of risk at each event in the journey, and facilitates tailored and risk-appropriate UX delivery.”

Descope Flows, our visual workflow builder, is Journey-Time Orchestration natively plugged into a CIAM platform. In our view, this is one of the main drivers for our inclusion as a Sample Vendor.

Creating a New/Existing User condition on the flow canvas
Fig: Adding a condition in Descope Flows, the drag-and-drop identity journey editor

Gartner says:

“Security teams and app developers are both seeking more tailored, risk-appropriate UX, which is easier to achieve with a JTO solution due to the fine-grained user journey control intrinsic to such solutions. The JTO solution optimally acts as the connective thread between the analytics solutions and the UI layer to reduce fraud risk while enabling a great UX.”

We feel “connective thread” is exactly the right image to conjure. Identity journeys touch verification, authentication, risk signals, registration, and UI in a single user session, and stitching those together in code is where most in-house or rigid vendor implementations stall. 

Gartner also says:

“The need to facilitate A/B testing in DevOps is pushing the adoption of JTO. Optimization of a risk management strategy is facilitated by a strong JTO platform in the form of A/B testing. For example, traffic could be split across two different identity verification vendors to assess which delivers better conversion rates.”

Descope Flows unifies actions across frontend and backend with 100+ best practice templates, weaves in data from 50+ third-party connectors (including risk signals from Forter, Fingerprint, and reCAPTCHA), and lets teams visually A / B test user journeys to optimize both conversion and risk posture. 

Fig: A/B testing flow
Fig: An A/B testing flow in Descope Flows, the drag-and-drop identity journey editor

Gartner also says:

“Enabling robust integrations with access management and other identity and access management (IAM) tools introduces additional efficiencies to cybersecurity organizations. Many customer identity and access management (CIAM) vendors have developed or acquired JTO capabilities. This lowers one barrier for adoption by implementing companies.”

In our opinion, orchestration works best when it is native rather than bolted on. Because Flows is a cornerstone of the Descope platform rather than an acquired add-on, journey logic, risk assessment, and auth methods share one control plane. Teams can modify user journeys without touching their codebase, all while staying in sync through CI/CD integrations (GitHub, GitLab, Terraform, Pulumi) for software development life cycle (SDLC) alignment.

Orchestration at scale

Descope Flows is proven well beyond analyst recognition; thousands of organizations run Descope in production, managing hundreds of millions of identities. The vast majority of them use Flows to orchestrate their user journeys.

A few examples:

  • GoFundMe: Moved from a homegrown CIAM system to workflow-based user journeys, improving UX while saving developer time. Read the case study.

  • Linktree: Migrated tens of millions of users while keeping their authentication UX identical, replacing custom auth logic with Flows so teams can iterate without touching app code. Read the case study.

  • Databricks: Unified authentication across multiple user portals and identity providers using dynamic federation in workflows, with zero engineering life. Read the case study

GoFundMe Login Screen
Fig: The GoFundMe login screen, powered by Descope Flows

How Descope aligns with the 2026 Gartner Hype Cycle for Digital Identity

The table below maps themes from the two categories where Descope is listed to the platform capabilities that, in our view, address them.

Hype Cycle Theme

How Descope Aligns

Delegating access from customers to AI agents and binding the two securely

• OAuth-based consent and delegation

• Agents receive short-lived, scoped credentials tied to the authorizing user, with raw tokens kept in Descope Connections

Managing authentication and authorization mechanisms for agents

• AI agents managed as first-class identities with their own attributes: associated user, tenant, and granted scopes

• Flexible agent registration (pre-registration, DCR, CIMD) and grant support (authorization code, client credentials, JWT bearer)

• Per-agent and per-tool scopes

• Policy engine with user, tenant, and JWT claim context

Account takeover prevention across agentic and human contexts

• Adaptive MFA based on journey logic

• Native risk factors like impossible traveler and trusted device

• Third-party risk connectors (Forter, Fingerprint, reCAPTCHA)

Reducing the complexity of multiple vendor integrations along the user journey

• Native Journey-Time Orchestration implementation (Descope Flows) unifying actions across frontend and backend

• 100+ journey templates

• 50+ third-party connectors

A / B testing to optimize risk strategy and conversion

• Visual A / B testing of user journeys with phased rollouts

• Journey-time analytics dashboard to show step-by-step conversions and dropoffs

• CI / CD integrations for SDLC alignment

What the Hype Cycle for Digital Identity means for Descope

We feel the Hype Cycle for Digital Identity is a valuable resource for cybersecurity leaders deciding where to invest as AI agents reshape the identity landscape. Being listed as a Sample Vendor in both an emerging category and a maturing one is, in our view, a confirmation that Descope’s market approach is a wise one: build for the customer agentic era that is still arriving, on orchestration foundations that are already proven today.

User needs and market forces will keep organizations on their toes throughout 2026, and Descope will ensure that our customers’ auth deployments are ready to meet tomorrow’s challenges. If you’re interested in trying out Descope, sign up for a Free Forever account. Have an active CIAM project for your customers, partners, or agentic AI / MCP systems? Book a demo with our auth experts to learn more. 

FAQs about the 2026 Gartner Hype Cycle for Digital Identity


Gartner, Hype Cycle for Digital Identity, 2026, By Zachary Smith, Nayara Sangiorgio, 6 July 2026.

GARTNER is a registered trademark and service mark of Gartner, Inc., and/or its affiliates in the U.S. and internationally, and HYPE CYCLE is a registered trademark of Gartner, Inc. and/or its affiliates, and are used herein with permission. All rights reserved.

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.