D

descope.com

Descope is an identity and access management platform for adding authentication, access control, and identity management to customer applications, partner applications, AI agents, and MCP servers. It provides CIAM features such as passwordless login, SSO, MFA, user management, and agent-oriented authorization.

4 integrations · MCP · REST · CLI

Descope exposes a documented REST API with an OpenAPI spec, a hosted remote MCP server at `https://mcp.descope.com`, and two CLIs (`descope` and `create-descope-app`).

discovered 2mo ago
MCP servers1
REST · OpenAPI1
CLI2
Credentials
Descope Project ID used as bearer token for public auth endpointsbearerGet token ↗

Open Project Settings in the Descope Console and copy your Project ID. Descope's API docs state that sign-up/sign-in endpoints use Authorization: Bearer <ProjectID>.

Descope Management KeybearerGet token ↗

In the Descope Console, go to Company Settings → Management Keys and generate a management key for your project. The REST docs say management endpoints use a management key, and the CLI docs require setting it in DESCOPE_MANAGEMENT_KEY.

Descope Access KeybearerGet token ↗

Create an access key in the Descope Console from the Access Keys page, or via the descope access-key create command documented in descope CLI. Descope's API docs say management endpoints may use an access key.

Project ID plus Refresh JWT for user-scoped API callscompound

Obtain a user's refresh JWT by completing a Descope authentication flow such as the OTP flow described in One-Time-Password APIs. For user-scoped endpoints, Descope documents the header format as Authorization: Bearer <ProjectID>:<RefreshJWT>, so this credential is the combination of your project identifier and the user's refresh token.

OAuth 2.0oauth2
OAuth 2.0 — self-onboarding

Point your MCP client at the server URL and approve access in the browser. The server accepts a Client ID Metadata Document (CIMD), so the client authenticates with its own hosted URL as the client_id — nothing to register.

conventions · 1/7 published

Publish these signals → /publishing