descope.com
Descope is an identity and access management platform for adding authentication, access control, and identity management to customer applications, partner applications, AI agents, and MCP servers. It provides CIAM features such as passwordless login, SSO, MFA, user management, and agent-oriented authorization.
Descope exposes a documented REST API with an OpenAPI spec, a hosted remote MCP server at `https://mcp.descope.com`, and two CLIs (`descope` and `create-descope-app`).
- Descope MCP Serverdetected
- Descope REST APIdiscovered
- descope CLIdiscovered
- create-descope-app CLIdiscovered
Open Project Settings in the Descope Console and copy your Project ID. Descope's API docs state that sign-up/sign-in endpoints use Authorization: Bearer <ProjectID>.
In the Descope Console, go to Company Settings → Management Keys and generate a management key for your project. The REST docs say management endpoints use a management key, and the CLI docs require setting it in DESCOPE_MANAGEMENT_KEY.
Create an access key in the Descope Console from the Access Keys page, or via the descope access-key create command documented in descope CLI. Descope's API docs say management endpoints may use an access key.
Obtain a user's refresh JWT by completing a Descope authentication flow such as the OTP flow described in One-Time-Password APIs. For user-scoped endpoints, Descope documents the header format as Authorization: Bearer <ProjectID>:<RefreshJWT>, so this credential is the combination of your project identifier and the user's refresh token.
Point your MCP client at the server URL and approve access in the browser. The server accepts a Client ID Metadata Document (CIMD), so the client authenticates with its own hosted URL as the client_id — nothing to register.
conventions · 1/7 published
- integrations.json——
- llms.txt✓https://descope.com/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing