Collectors, the parent company of PSA, PCGS, SGC, and Beckett, needed to unify identity across three distinct login scenarios (consumer brand auth, a co-managed partner product, and internal admin access) under a single platform. Their incumbent solution couldn't provide the federation flexibility, JWT customization, or integration depth they required. Learn how Descope gave Collectors' identity team the control and extensibility they needed to consolidate authentication for millions of users across brands and partners.
About Collectors
Collectors is the global leader in third-party grading and certification for collectibles. Its portfolio includes PSA (trading cards, memorabilia, and video games), PCGS (coins and currency), SGC (vintage and pre-war cards), Beckett (grading, price guides, and publications), and CardLadder (analytics).
With over a quarter million monthly active users, 30,000 daily active users, and nearly 8 million machine-to-machine credential exchanges across 5.7 million user records, Collectors operates identity infrastructure at a scale where fragmentation can quickly create UX friction.
Three login experiences, one identity challenge
Collectors' identity requirements were somewhat atypical: the company had three different authentication use cases with different trust models, user populations, and technical constraints.
Internal admin access required corporate SSO for employees accessing administrative tools. On its own, this was straightforward SAML-based SSO. But running it alongside two other login patterns on a platform that treated each as a separate configuration environment created operational fragmentation for a lean identity team.
Consumer brand login served the primary user base across PSA, PCGS, and other Collectors properties. Sub-brands needed to federate to a central, self-hosted authentication page with Collectors' own branding, privacy policies, and footer. The incumbent platform made this federation rigid, and routing users across brands while maintaining consistent session behavior required workarounds that added overhead without adding flexibility.
A co-managed partner product introduced a different trust model. Partner users needed to authenticate through the partner's own identity provider via OAuth, with Collectors acting as an intermediary. The incumbent platform had no clean abstraction for this kind of multi-party federation.
The core challenge was architectural: Collectors needed an authentication provider that could handle all three use cases within a unified identity model.
Dan Van Tran, CTO at Collectors, said:
"Our consumer federation, partner federation, and admin SSO grew up separately, so each one was its own world to maintain. We wanted one unified place to run them without giving up our work on claims and scopes. Descope fit all three experiences into the same auth model, letting us keep the control we’d built.”
The Descope experience
Collectors needed a solution that could replicate the JWT claim patterns and scope controls they'd built previously while extending into areas where their former provider had set limitations. They evaluated alternatives against federation flexibility, JWT template depth, connector-based integration architecture, M2M scope control, and engineering responsiveness. Descope addressed all of these requirements.
Collectors rolled out Descope across each of their three use cases: admin SSO, consumer brand authentication, and partner federation. Each use case exercised different parts of Descope's solution, but all three ran through the same flow-based orchestration layer:
The SAML-based admin SSO flow authenticates employees through Collectors' corporate identity provider, applies specific audience info and custom admin scope claim, and completes. Once the redirect model and frontend integration were set up, the team moved quickly to production.
User records were imported from the incumbent alongside Collectors' internal database. During the transition, a just-in-time (JIT) password sync captured credentials as users logged in through the incumbent and wrote them to Descope. These accounts were then ready at cutover without a forced password reset. MFA enrollment data was also preserved from the legacy provider, and Collectors implemented a new MFA pattern: users select their method (SMS OTP or voice call OTP) at registration, stored as a custom attribute and enforced at sign-in through the flow.
Partner users authenticate through the partner's custom identity provider, with Descope acting as the intermediary. The flow initiates an OAuth exchange with the partner's identity provider, then a proxy connector call to Collectors' backend API creates or validates the user, maps custom attributes across both systems, and handles edge cases like suspended user redirects and error audit events.
Descope's connector system ties the identity layer into Collectors' broader infrastructure: Twilio for SMS and voice OTP delivery, Mimecast (via SMTP connector) for transactional email, AWS S3 for audit log streaming, webhook-driven event handling for MFA verification, and the proxy API that powers user creation in the partner federation flow.
Authentication flows across all three use cases support English, French Canadian, and Japanese. Account lockout emails, OTP messages, and user-facing screens are localized per user locale, extended by Descope's Google Cloud Translation connector.
The migration also surfaced requirements that drove new platform capabilities, feature requests pushed to production before the migration completed rather than as a future roadmap. Descope shipped PKCE support for custom OAuth providers, public/private key JWT authentication for external identity provider integration, .NET SDK enhancements, JIT session migration support for Okta CIS, and localization changes.
Smit Gujarathi, VP of Marketplace Engineering at Collectors, said:
"Partner federation could have been a service we owned and maintained forever. With Descope Flows, it’s a simple matter of configuration. In case we did run into an unexpected requirement, the Descope team built the feature while we were still in the middle of the project. That’s not your typical auth vendor."
Simplifying the identity surface for six million users
Leveraging Descope’s flexible orchestration and federation capabilities, Collectors replaced a fragmented identity stack with a single orchestration layer that handles consumer federation, partner authentication, admin SSO, and millions of monthly M2M exchanges. As they continue enriching their identity experiences with Descope, they plan to add more integrations, introduce native mobile applications, and enhance token management.
Dan Van Tran, CTO at Collectors, said:
"Identity used to be three separate engineering efforts for us, and now it's one. What matters most looking ahead is agility: we can add integrations, test different flows, and refine token management without rebuilding the foundations every time we want to try something new."
For organizations managing identity across multiple brands, partners, and user populations, Descope provides the flow-based architecture and robust integrations to consolidate without compromising, and without spending months and countless dev cycles to end up with never-ending maintenance.
Descope is a flexible customer and agentic platform that helps organizations easily add authentication, authorization, and identity management to their apps, AI agents, and MCP servers. Customers use us for initiatives such as passwordless authentication, SSO, identity federation, strong MFA, fraud prevention, and agentic identity.
To get started with Descope, sign up for a Free Forever account. If you have questions about our platform, book time with our auth experts.