🚀 AI Launch Week Day 1: Your dedicated identity provider for AI agents
Introducing @descopeinc Agentic Identity Hub 2.0 - a one-stop solution to help developers and security teams add auth, access control, credential management, and policies to their AI systems.
🧵👇
Session management is important, friends
If you're planning to use JSON Web Tokens (JWTs) to maintain auth state between calls, it's helpful to keep some best practices in mind 👇
Good luck to all teams participating in @ycombinator Demo Day!
Product-market fit for your company is in your hands, but we're happy to play a small part in helping you achieve founder-energy fit. Go crush it!
Excited to share a new customer case study with b.well Connected Health. b.well is the connective layer between patients and the health data scattered across systems that hold it. The company works with partners including Samsung and Walgreens, and its platform sits behind consumer health experiences announced with OpenAI, Google, and Perplexity.
Case study - https://t.co/vOc3OzsxXx
AI agents are moving into production. Identity models built for humans and static service accounts aren't ready for them.
We're taking that conversation to 6 cities:
Dublin OH · NYC · Costa Mesa · Seattle · Chicago · Atlanta
Fireside chats + lunches with Guidepoint, Trace3, RedLegg, and SDG.
Links below 👇
Here’s what’s most exciting about moving agents from pilots to production: there are no playbooks written yet. Which means conversations are ripe for first-principles and philosophy.
Had a room full of CIOs, CISOs, and security leaders from @zscaler@Box@salesforce last week deliberating on:
- What should an agent’s identity represent? The code, its current task, the person delegating authority, or some combination of all three?
- Can “intent” ever be reliably inferred when the same action and data can support either a legitimate or malicious outcome?
Excited to keep digging deeper and having lots more of these across the country.
If you're a security leader with similar questions and would like to join the next one, DM me.
We're grateful to work with customers like @DWPgovuk to help modernize citizen identity without overburdening engineering teams.
Read our announcement
https://t.co/IHiPVW2gDV
Descope has been named a supplier on Government Commercial Agency's (GCA) G-Cloud 15 framework
Eligible UK public sector buyers can procure Descope through pre-agreed commercial terms rather than running a full procurement from scratch.
🧵👇
AI agents have made destructive decisions on company codebases before, and (without proper guardrails) they will do it again.
Simply prompting agents not to take harmful actions isn’t enough. You need infrastructure-level controls and mitigations.
🧵👇
This is a big one. And it’s taken a village to get here.
Launching what will be one of the most sought-after agent infrastructure products of the new world:
🕵️♀️ SSO for agents.
Building autonomous workflows or exposing MCP servers, multi-agent systems, or external APIs to your users has so far carried the risk of:
- rogue AI agents running wild with unmonitored API keys
- hardcoding sensitive secrets to repositories to let agents interact with third-party data sources
- and an under-looked one: the user friction caused by endless consent and auth prompts
With Descope's XAA we're bringing SSO to the agentic world. Not just with token validation. We’re one of the first ones going a step further and solving for both:
1. ID-JAG token validation: which enables SSO-like login for any AI agent accessing your MCP server.
2. ID-JAG token issuance, which enables SSO-like login for your AI agents accessing any MCP server.
Special S/Os to a few of many that have made it possible:
- @denniscode and the @AnthropicAI team
- @PrathmeshPatel_ and the rest of the @mcpjams team
To everyone in the interoperability channels:
- Nick Steele from @OpenAI@zirotrust from @CrowdStrike@aaronpk from @okta
And as always - s/o to this entire Descope team to have pulled this off!
We have a new @freebean_co distribution partner: @join_ef
Since March 2nd of this year, our accelerator & incubator distribution channel has been rocking…but only in NYC with Antler, Techstars, and Fractal Tech. It was time to make our way to Silicon Valley with EF
With a recently expanded cohort (that loves caffeine), we're excited to bring @descopeinc coffee to the incredible EF founders and early teams
☑️ Enterprise-ready MCP servers: SSO-like login for your customers' AI agents accessing your MCP servers
☑️ Managing internal AI agents: SSO-like login for your AI agents accessing any MCP server
https://t.co/XlfsTTVcJl
🤖 SSO for your agents
We're delighted to announce Cross-App Access (XAA) support in the @descopeinc Agentic Identity Hub!
Descope becomes one of the first identity providers to support both issuance and validation of ID-JAG tokens.
🧵👇
In this month's Auth Thoughts, we cover:
🏆 Self-service agent SSO for your MCP server
🤖 Descope MCP server on Claude and ChatGPT
📚 Guides on adding building secure agents with Claude Agent SDK and LlamaIndex
Read on for your customer and agentic identity roundup 🧵👇
Another Daytona AI Builders in San Francisco is behind us! 🚀
Huge thanks to our event partners, @descopeinc & @tensorwave, our amazing speakers @MrunankPawar, @evisdrenova, @zhuolunfranklin, @LinghuaJ, @muhashmii, and everyone who joined us and made the night special.
We’ll be back on September 29 for another monthly AI Builders Demo Night in SF. More details coming soon.
See you there!
Had a great time sharing @descopeinc's learnings on agentic identity at the @daytonaio AI Builders meetup!
AI moves fast, but we need to slow down to build sustainable, standards-based identity controls for AI agents and MCP servers.