Descope

Descope

Provides developer-focused user authentication platform

Overview

Descope provides a platform that helps app developers implement and manage user authentication and customer identity. Its product lets developers build authentication infrastructure without deep in-house engineering, aiming to reduce friction for end users while improving security and user experience. The company differentiates itself by offering an integrated service for authentication infrastructure, along with a learning center and community resources that educate on authentication concepts and foster engagement. It emphasizes data privacy and GDPR compliance, storing personal data securely and guiding clients on responsible data use. Descope’s goal is to make it easier for developers to deploy secure, user-friendly authentication in applications, while positioning itself as a trusted provider in the identity space through education and community support.

About Descope

Simplify's Rating
Why Descope is rated
C+
Rated C on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Data & Analytics

Enterprise Software

Cybersecurity

Education

Company Size

51-200

Company Stage

Seed

Total Funding

$88M

Headquarters

Los Altos, California

Founded

2022

Get referred to Descope

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • September 2026 XAA launch targets a hot enterprise pain point around AI-agent access.
  • Descope says its platform serves hundreds of MCP servers and millions of monthly transactions.
  • September 2025 funding reached $88 million, extending runway for hiring and product expansion.

What critics are saying

  • Auth0's September 2, 2026 Cross App Access narrows Descope's standards-driven differentiation quickly.
  • Okta and Ping already control enterprise IdPs, giving them a distribution advantage in 2027.
  • If MCP agent adoption stalls, Descope's agentic identity bet becomes a costly niche.

What makes Descope unique

  • Descope pairs no-code CIAM with agentic identity, spanning humans, customers, and AI agents.
  • September 1, 2026 XAA lets tenant admins govern MCP access through existing IdPs.
  • Descope supports OAuth 2.1, DCR, CIMD, and ID-JAG without custom auth rewrites.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$88M

Above

Industry Average

Funded Over

2 Rounds

Notable Investors:
Seed funding is usually the first official round after pre-seed, when a startup has a prototype or concept. It’s typically used to develop the product, test the market, and start building the team. Investors here are often angel investors or early-stage venture capitalists.
Seed Funding Comparison
Above Average

Industry standards

$3.3M
$2M
Netflix
$2.3M
Instacart
$3M
Robinhood
$35M
Descope

Growth & Insights and Company News

Headcount

6 month growth

-2%

1 year growth

-5%

2 year growth

-1%
VMblog
Sep 1st, 2026
Descope unveils Cross-App Access (XAA) support, letting enterprises manage AI agent access with their existing identity providers.

Descope unveils Cross-App Access (XAA) support, letting enterprises manage AI agent access with their existing identity providers. Descope announced Cross-App Access (XAA) support in its Agentic Identity Hub, giving organizations a way to let every enterprise customer govern AI agent access through the identity provider (IdP) they already trust. Descope is among the first identity providers to support both: * ID-JAG token validation, enabling SSO-like login for any AI agent accessing Descope customers' MCP servers * ID-JAG token issuance, enabling SSO-like login for Descope customers' AI agents accessing any MCP server AI agents are becoming the primary consumers of enterprise APIs, and B2B companies are building MCP servers so those agents can reach intended services and data. However, many MCP servers use identity anti-patterns that were not designed for autonomous agents. * Static API keys sit in configuration files and environment variables with no expiration and no tool-level scoping. * Agents borrow the signed-in user's session and inherit every permission that user holds, which greatly increases the blast radius of a single compromised agent. * Authorization is applied at the application level rather than per user, per tenant, per agent, or per tool, leaving agents over-permissioned by default. 2026 research from Gravitee found that only 22% of teams treat agents as independent identities, with most relying on shared API keys. Cross-App Access is an open protocol built to standardize how AI agents receive access to another application's APIs or MCP server. Built on the Identity Assertion JWT Authorization Grant and adopted as the Enterprise-Managed Authorization extension to the Model Context Protocol, it replaces static API keys and repeated consent screens with short-lived assertions minted by the identity provider both applications already trust. An agent signed in to one application reaches another application's API or MCP server with no second login. "Every B2B company shipping an MCP server is about to hear the same question from its enterprise customers: can we govern agent access to this MCP server with our own identity provider?" said Rishi Bhargava, Co-Founder of Descope. "Descope's Cross-App Access support helps customers deploy enterprise-ready MCP servers that can validate assertions coming in from their customers' identity providers and even let tenant admins configure XAA support entirely on their own. This is a huge unlock for any business that has high hopes for their Claude connector or ChatGPT plugin." New Cross-App Access capabilities in the Agentic Identity Hub include: * ID-JAG validation, which helps B2B companies let their enterprise customers govern agent access through the identity provider they already trust. Organizations can register a trusted issuer for each tenant, accept assertions from Okta, Ping, and other standards-compliant providers, and validate a standard access token at the MCP server without implementing the protocol themselves. * ID-JAG issuance, which makes Descope the identity provider for the AI agents an organization runs internally. Security teams can grant those agents scoped, short-lived access to any MCP server / API, with policies evaluated on every request instead of being baked into a long-lived credential. * Self-service XAA setup, which adds Cross-App Access to Descope's SSO Setup Suite alongside SSO, SCIM, and JIT provisioning. Tenant admins can choose their identity provider, establish trusted issuers, register their AI agents, and map user attributes through a guided flow without any support ticket or manual back-and-forth. * Per-organization scope policies, which let companies grant different levels of agent access to different enterprise customers on the same MCP server. Policies can be created based on user roles, tenant membership, and claims carried over from the customer's identity provider. * Standards-based token exchange, which builds on the OAuth 2.1, DCR, CIMD, and consent management support already in the Agentic Identity Hub. Cross-App Access follows the Enterprise-Managed Authorization extension to MCP, using OAuth 2.0 Token Exchange to mint assertions and the JWT Bearer grant to redeem them. Cross-App Access support builds on the Descope Agentic Identity Hub, which handles authentication and access control for hundreds of MCP servers and millions of monthly agentic transactions. Descope, a member of the Agentic AI Foundation (AAIF), was named a Leader in the 2025 Frost Radar for Non-Human Identity Solutions, where Frost & Sullivan analyst Dolores Aleman described Descope as "one of the first vendors to treat AI agents as a first-class identity type." David Marshall is the founder of VMblog.com, one of the industry's longest-running independent publications covering modern data center technologies. What began as a focus on virtualization and cloud computing has expanded to cover the full spectrum of enterprise IT, including AI, security, and DevOps, making VMblog a trusted destination for vendor news, technology analysis, and industry commentary.Beyond publishing, David has spent his career at the intersection of technology and business, inventing, marketing, and launching a number of successful software companies and products, and building a reputation as a skilled marketing executive in the enterprise IT space.David is also a published author, having written two well-regarded books on virtualization and served as technical editor for two "For Dummies" titles covering virtualization and cloud computing. He co-founded CloudCow.com, a publication focused on cloud computing, and has been named a VMware vExpert every year since 2009, one of the longest continuous honoree streaks in the program's history.Connect with David on LinkedIn: https://www.linkedin.com/in/davidmarshall/

Descope
Nov 19th, 2025
Descope Gets Honorable Mention in 2025 Gartner(R) Magic Quadrant(TM) for Access Management

Descope gets Honorable Mention in 2025 gartner(r) Magic quadrant(tm) for Access Management. Company Updates November 19, 2025 On 11 November 2025, Gartner published its annual Magic Quadrant for Access Management. Descope Inc. is proud to share that Descope received an Honorable Mention in this report, a mere two years after launching from stealth. In its view, being mentioned alongside products that have been in the market for decades highlights that its approach to CIAM has been validated by industry analysts. This is further testament to the fact that Descope is an enterprise-grade solution that can meet organizational requirements around scale, compliance, and flexibility. This blog will share its reflections on recommendations made in the report and how they align with learnings from hundreds of Descope customers. Gartner clients can access the full research note through this link. CIAM driving access management growth. "This year, CIAM is the primary contributor to the growth of the AM market. Gartner is seeing a significant increase in demand from client organizations moving from existing home grown CIAM platforms to a commercial/modern solution." In its opinion, this aligns with several customer conversations and deployments Descope Inc. has observed over the past year as well. Changing user needs, digital-first spaces, and overburdened developers mean that organizations with in-house CIAM deployments face an uphill battle to keep maintaining these systems. Ultimately, organizations need to commit to being "identity companies" in addition to the space they operate in if they are to continue down the "build" path when it comes to CIAM. Several organizations like GoFundMe, BBSI, OpenWeb, and HiBob have chosen Descope to replace their homegrown CIAM systems - improving user experience, enhancing account security, and saving developer time in the process. Let's take a step back, though. Once organizations do decide to go down the "buy" path, there are broadly three options available: * A dedicated CIAM solution * A workforce-oriented solution that has CIAM product lines * An open-source solution While all three are viable options on the surface, organizations adopting workforce-oriented solutions or open-source platforms end up with their own struggles. Square pegs, round holes. Earlier this year, Descope commissioned a survey of 416 individuals with technical and / or budgetary responsibility for CIAM and the findings revealed "user's remorse" among those that used workforce-oriented and open-source IAM solutions for their CIAM initiatives. While 51% of respondents used workforce-oriented solutions for CIAM, only 8% said they would go down the same path if given the opportunity to start over from scratch. This gap between current and desired states point to users feeling trapped by decisions made years ago. With user needs constantly changing, workforce-oriented IAM solutions lack the flexibility, self-service administration, and focus on user experience to help organizations stay agile in 2025 and beyond. The story with open-source CIAM is different but equally telling, with organizations eventually finding themselves running on a hamster wheel of maintenance and custom work to implement their desired user journeys. Consider the following two statistics: * When asked if organizations lost revenue after implementing stricter access control, 50% of open-source CIAM buyers agreed, almost double the average across respondents. * When asked if organizations had suffered security incidents after implementing low-friction access control, 51% of open-source CIAM buyers agreed compared to 39% on average across respondents. Achieving a balance between security and customer experience is tricky at the best of times - and using open-source solutions evidently feels like doing this on hard mode. How Descope aligns with access management trends. Gartner changes the focus of its Magic Quadrant for Access Management based on prevailing market conditions every year. Here are the major trends listed in the report mapped to how Descope Inc. feel Descope aligns with these trends: | Access management trend | How Descope aligns | | Passwordless authentication | - Broad support for passwordless methods (magic links, OTP, passkeys, social login, authenticator apps, Whatsapp) - Support for using any method as the first or second factor | | Adaptive and risk-based access controls | - Adaptive MFA based on workflow-based journey logic - Native risk factors: impossible traveler, trusted device, etc. - Third-party risk connectors: Forter, Fingerprint, reCAPTCHA etc. - Augment existing user stores with adaptive MFA | | Seamless omnichannel experience | - Native mobile flows to deliver frictionlessUX across web and mobile - Platform integrations and plugins with WordPress, Framer, Shopify, WooCommerce, Salesforce CC, and any OIDC-compatible service - Identity Federation Broker to unify auth across apps and IdPs | | Identity orchestration and automation | - Journey-Time Orchestration engine (Descope Flows) - Harmonize actions across frontend and backend - Choose from 100+ templates with best practice flows - Work in lockstep with your SDLC using CI / CD integrations - Weave in data from 50+ third-party connectors | | API-first and developer-centric approaches | - SDK support for all popular web, mobile, backend frameworks - Comprehensive REST API - Modify user journeys without touching your codebase - Visually A/B test user journeys for phased enhancements - Flexibility to support just-in-time and bulk migration - Variety of tools to enable zero-downtime migration of sessions, SSO connections, passwords, and API keys | | Machine IAM | - Secure M2M authentication via OAuth tokens or API keys - Secure MCP servers with OAuth, DCR, and scope-based access control - Enable AI agents to call APIs on users' behalf while offloading token mgmt. and storage - Restrict AI agent access to corporate tools based on user roles and JWT claims | | FIDO2 | - Native FIDO2 / passkey support including device-bound and cross-device passkeys with autofill - Add passkeys as primary or secondary factor - Promote passkeys as optional MFA during the user journey or within in-app user profiles - Add backup auth methods when user devices are not WebAuthn-compatible | Descope Inc. feel the Gartner Magic Quadrant for Access Management is a comprehensive resource to guide requirement-gathering and decision-making around access management initiatives. As migrations from homegrown CIAM deployments gather pace, Descope Inc. anticipate more organizations engaging in "from scratch" thinking and choosing an approach that delivers quick time to value while also enabling their developers to easily make modifications and enhancements with time. User needs and market forces will change every day in 2026, and Descope will ensure its customers' auth stacks are ready to respond to those changes. If you're interested in trying out Descope, sign up for a free account. Have an active IAM project for your customers, partners, or agentic AI / MCP systems? Book a demo with its auth experts to learn more. Gartner, Magic Quadrant for Access Management, By Brian Guthrie, Nathan Harris, Yemi Davies, Steve Wessels, 11 November 2025. GARTNER and MAGIC QUADRANT are trademarks of Gartner, Inc. and its affiliates. Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner's business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

Descope
Oct 3rd, 2025
Descope Extends and Closes Seed Round With $88M Total Funding, Announces Advisory Board

$35M in new funding from existing investors enables Descope to continue simplifying and securing customer, partner, and agentic identities for organizations of all sizes.

CyberMaterial
Oct 2nd, 2025
Descope Raises 35M In Seed Extension

Descope, a company specializing in identity and access management (IAM), recently secured an additional $35 million in a seed funding extension.

Team IT Security
Oct 1st, 2025
Descope Secures $35M for Expansion

Descope has raised $35 million in a seed round extension. The identity and access management provider plans to invest in agentic identity research and development, expand to new regions, and hire new talent.

Recently Posted Jobs

Sign up to get curated job recommendations

There are no jobs for Descope right now.

Find jobs on Simplify and start your career today

We update Descope's jobs every few hours, so check again soon! Browse all jobs →