Identity provider for your MCP servers
Build secure MCP servers and AI agents with standards-based identity infrastructure. Add auth, consent management, access control, credential management, and policy controls to your MCP servers with the Descope MCP authentication provider.
Trusted by innovative AI companies like yours
Introducing Agentic Identity Hub
Manage agentic identities, connect MCP servers to AI agents, manage purpose-built AI agent credentials for downstream connections, and enforce granular policies to govern AI agent access.
Built for MCP server authentication and more
MCP server auth
Securely expose your external and internal-facing MCP servers to AI agents with OAuth, client registration, user consent, and more.
MCP gateway
Support MCP gateway implementation patterns with Descope acting as the IdP: issuing tokens, managing consent, and storing and refreshing credentials.
Bring Your Own Auth
Add Descope as your MCP auth provider without changing your existing homegrown or third-party user authentication stack.
Agentic Identity Hub capabilities
User authentication
Authenticate users in your AI apps
Add frictionless, secure user auth to any business or consumer-facing AI app.
Prompt users to reauthenticate during sensitive actions.
Issue sessions that identify users across AI conversations, agents, and background tasks.
Delegate admin with self-service SSO / SCIM setup, user / role / access key mgmt. and more.
Save developer time using no / low code user journeys.

Agentic Identity Management
Get a unified view of agentic identities
Get dedicated identities for each AI agent alongside several attributes such as associated users, tenants, tool-level scopes, etc.
Filter, group, and tag agents based on business needs and logic.
Bring in existing workforce / customer IDs to make authorization decisions.
Monitor every AI agent action, identify potential misconfigurations, revoke access for potentially rogue agents.

MCP Auth
Secure MCP servers with auth and access control
Securely expose MCP servers to MCP clients with OAuth 2.1 and PKCE.
Validate access to MCP servers with user auth and consent management.
Support context-aware MCP client registration through DCR and CIMD with agent risk assessment flows.
Assign granular per-agent and per-tool scopes to MCP clients.
Bring Your Own Auth: Federate with existing homegrown or third-party user auth stacks.

Connections
Manage credentials for your AI agents
Issue portable, revocable tokens designed specifically for agents, independent of platform or downstream authentication requirements.
Manage, store, and refresh credentials for AI agents to access third-party or internal services.
Choose from 50+ prebuilt templates or vanilla OAuth and API key implementations.
Leverage presets to connect AI agents to third-party MCP servers.
Request scopes at the user and tenant level for B2C and B2B coverage.

Policies
Govern AI agent access to MCP servers, tools & resources
Define authorization controls for per-agent and per-tool access to MCP servers or enterprise resources.
Create policies that take context from the user, tenant, MCP server, agent, JWT claim, and downstream service into account.
Bring in existing workforce / customer IDs for authorization decisions.
Ensure least privilege access and have AI agents progressively request elevated scopes if needed.

Auditing and Reporting
Get visibility into the entire AI agent identity lifecycle
Log every AI agent’s identity, the delegating user, and the tools / scopes / MCP servers they have access to.
Identify access misconfigurations and instantly revoke access for potentially rogue or shadow agents.
View detailed audit logs in the Descope dashboard or stream them to your SIEM.

Ecosystem
Identity for your AI systems–wherever you build them

Popular MCP auth and identity resources
Frequently asked questions
Ready for liftoff?
If you’ve seen all you need to see, sign up and get started with Descope. If you'd like a demo, meet with our auth experts.





