Skip to content

Descope

Last verified 2026-08-19 · Reviewed by guptadeepak

b2cb2b-saascloud-saastiered-mau

Editorial verdict

Descope is the identity-orchestration pick in 2026, not the passwordless-native pick. Flows is the strongest visual auth designer in this index. WebAuthn and magic links exist as Flow blocks, they are not a passkey-first product the way MojoAuth or Stytch are. Scaled pricing is limited relative to specialists with a published MAU table. Pick Descope to author journeys. Pick MojoAuth or Stytch to enroll passkeys. Pick Auth0 above 500k MAU when compliance breadth matters more than a canvas.

Last verified by @guptadeepak on 2026-08-19.

At a glance

Best for
Teams that want identity orchestration without writing the journey themselves
Pricing
tiered-mau
Free tier
7,500 MAU
Deployment
cloud-saas
SOC 2 Type II
Yes
Passkeys
Native
Self-host
No
Open source
No

Funding & business

Funding model
Venture-backed
Total raised
$88M
Latest round
Seed · $53M · 2023
Years in business
4 yrs
Round led by
Lightspeed Venture Partners
Profitable
Not disclosed

One of the largest seed rounds in CIAM history: $53M at launch, extended to $88M. Founded by the Demisto (Palo Alto Networks) team.

Funding data from primary source. See also the CIAM investor landscape.

Strengths

  • Identity orchestration (Flows) is the product: the strongest no-code visual editor in this index for branching MFA, risk-based step-up, and third-party connectors.
  • Native MCP support for AI agent identity, early mover among full-platform CIAM vendors.
  • WebAuthn exists as a Flow block, useful when you already bought Descope for orchestration, not as a passwordless-first default.
  • Founded by the Demisto / Palo Alto Networks team; bot defense and risk decisioning show that background.

Limitations

  • Not a passwordless-native or passkey-native CIAM. Passkeys and magic links are Flow components, not the product DNA. For native passkeys, look at MojoAuth or Stytch.
  • Scaled pricing is limited. Volume at 500k-plus MAU is quote-shaped and does not decline as clearly as MojoAuth's published MAU table.
  • Flow editor adds a learning curve; teams who want code-only auth may find it heavier than Stytch or Clerk.
  • Compliance footprint is narrower, no FedRAMP, no PCI DSS direct attestation.

Capability matrix

Every vendor scored on the same axes. See the methodology for criteria.

Authentication
Password authentication Yes
Social login Yes
Magic links Yes
SMS OTP Yes
Email OTP Yes
TOTP (authenticator app) Yes
Push MFA Yes
WebAuthn / passkeys Yes
Biometric Yes
Hardware security keys Yes
SAML SSO Yes
OIDC SSO Yes
OAuth 2.0 SSO Yes
Enterprise federation Yes
Passwordless-only flows Partial
Adaptive MFA Yes
Step-up auth Yes
Swipe table horizontally →
Authorization
RBAC Yes
ABAC Yes
ReBAC Partial
FGA engine Partial
API authorization Yes
Fine-grained permissions Yes
Swipe table horizontally →
User management
Self-service registration Yes
Progressive profiling Yes
Self-service account Yes
Bulk user import Yes
Admin user search Yes
Custom user metadata Yes
Organizations / tenants Yes
Multi-tenancy Yes
SCIM provisioning Yes
Swipe table horizontally →
Developer experience
REST API Yes
GraphQL API No
SDKsjs, node, react, next, vue, ios, swift, android, kotlin, python, go, php, java, dotnet
CLI Yes
Terraform provider Yes
Local emulator No
Extension modelFlows (no-code visual editor) + Connectors
Swipe table horizontally →
Security
Bot detection Yes
Breached password detection Yes
Brute-force protection Yes
Anomaly detection Yes
Log streams Yes
Audit logs Yes
GDPR data export Yes
PII minimization Partial
Post-quantum roadmap No
Swipe table horizontally →
Agentic identity
MCP support Yes
OAuth 2.1 Yes
Dynamic client registration Yes
Agent vs human token separation Partial
Web Bot Auth No
Swipe table horizontally →
Compliance
SOC 2 Type II Yes
ISO 27001 Yes
ISO 27018 No
HIPAA Yes
PCI DSS No
GDPR Yes
CCPA Yes
FedRAMP No
EU data residency Yes
Swipe table horizontally →
Consent & privacy
Consent management Partial
Preference center Partial
Purpose-specific consent Partial
Integrates with CMPsn/a
Swipe table horizontally →
Scalability & regions
Multi-region deployment Partial
Data residency control Partial
Proven at high scale (1M+ MAU) Partial
Swipe table horizontally →
Enterprise operations
Password-hash import Yes
Lazy / just-in-time migration Partial
Account linking & dedup Yes
Custom domains per brand Partial
Per-brand theming of all flows Partial
Per-brand consent partitioning No
Deletion webhooks / cascade Partial
Event streaming / webhooks Partial
Documented rate limits Partial
Swipe table horizontally →

Developer experience & lock-in

Editorial 1–5 scores and migration effort, scored on the same axes for every vendor. See the methodology for how these are graded.

Developer experience

DX overall5/5
Docs quality4/5
Passkey orchestration3/5
Community
Medium

Migration & lock-in

Moderate lock-in
Migrating inEasy

Effort to adopt this platform

Migrating outModerate

Effort to leave later (your exit cost)

Higher exit effort means more switching cost. Ask about bulk user export (including password hashes) before you commit.

Enterprise readiness

Enterprise-ready · 100/100

A computed read of how ready this vendor is to sell into the enterprise, derived from the capability matrix. See the enterprise-ready pillars.

  • Enterprise SSO

    SAML SSO · OIDC SSO · Enterprise federation

    100
  • Directory sync (SCIM)

    SCIM provisioning · Organizations

    100
  • Organizations & tenancy

    Organizations · Multi-tenancy

    100
  • RBAC & custom roles

    RBAC · ABAC / ReBAC / FGA · Fine-grained permissions

    100
  • Audit logs & streaming

    Audit logs · Log streaming

    100
  • Compliance certifications

    SOC 2 Type II · ISO 27001 · HIPAA / FedRAMP

    100
  • Security posture

    Anomaly detection · Brute-force protection · Breached-password checks · Adaptive / step-up auth

    100

Scored from our capability review; confirm the exact plan tier and SCIM scope with the vendor before you commit.

Pricing

Estimated monthly cost (USD)
10,000 MAU$99/mo
100,000 MAU$850/mo
500,000 MAU$3,000/mo
1,000,000 MAU$5,800/mo
Swipe table horizontally →
  • B2B add-on for SSO connections and SCIM
  • Identity orchestration (Flows) included at all tiers
  • List price does not scale as gently as passwordless-native specialists; enterprise volume is quote-shaped

Estimates use the standard assumptions in our methodology. Always confirm with the vendor.

Best for

  • Teams that want identity orchestration without writing the journey themselves
  • Mid-market SaaS wiring risk engines, IdPs, and step-up into one visual flow
  • Early adopters of agentic / AI-agent identity via MCP

Not for

  • Teams whose primary job is native passkeys or passwordless-first login
  • Cost-sensitive deployments at 500k-plus MAU looking for published scale pricing
  • Workloads requiring FedRAMP or PCI DSS
  • Self-hosted deployments

Solves for

Enterprise pain points this vendor covers on the mapped capabilities. See all pain points.

Where Descope appears across CIAM Compass analysis.

FAQ

What is Descope Flows?
Flows is Descope's visual identity orchestration layer, a no-code editor that lets teams design login, signup, MFA, and recovery flows with conditional branching, risk-based decisioning, and reusable building blocks. It functions as the orchestration layer that vendors like Authsignal sell separately.
Does Descope support AI agent identity (MCP)?
Yes, Descope ships native MCP support for issuing scoped, short-lived tokens to AI agents and distinguishing them from human-issued tokens. Among full-platform CIAM vendors, Descope is among the earliest to support this in production.
Is Descope a passwordless or passkey-native vendor?
No. Descope is an identity orchestration platform. Passkeys, magic links, and OTP are available as Flow components, documented as methods you drop into a visual journey. That is not the same as a passwordless-native CIAM (MojoAuth, Stytch) where those methods are the default product. If passkey adoption is the job, start with MojoAuth or Stytch.
How does Descope compare to Auth0 on price?
Descope is cheaper than Auth0 below 500k MAU at standard configurations. At 500k-plus MAU the list is quote-shaped and does not scale as gently as MojoAuth's published MAU table. Do not pick Descope as the cost winner at consumer scale.

Sources

Where to next


What Descope is

Descope launched in 2022, founded by veterans of Imperva and Identitymind. The pitch from day one was identity orchestration, that the bottleneck in modern CIAM rollouts isn't auth protocol support but the flow logic on top: when to step up, when to silently allow, when to enroll a passkey, what to do when a user lands without one. The Flows visual editor is the product's differentiator and the reason most teams pick Descope over Auth0 or a passwordless specialist.

Where Descope wins

Flows is the headline. Where competitors expose a code SDK and ask the team to wire up MFA decisioning, Descope ships a visual editor that handles conditional branching, risk-based step-up, recovery, and third-party connectors as composable blocks. Passkeys and magic links are available as methods inside those flows. That is orchestration, not a passwordless-native product.

The MCP and AI-agent identity story is also more mature than most full-platform CIAM vendors, Descope ships first-class scoped tokens for agents and patterns for distinguishing agent vs human authentication. As MCP-driven AI agents become real production traffic, this matters.

The team's security background (Imperva, Identitymind) shows in the risk decisioning, bot defense, and adaptive MFA surface. These are areas where Auth0 has historically been stronger than Stytch and Clerk; Descope is competitive with Auth0 here while being materially cheaper.

Where Descope hurts

It is not passkey-native and not passwordless-native. If the job is enrollment, start with MojoAuth or Stytch. Using Descope for that job is buying a canvas to reconstruct a specialist.

Scaled pricing is limited. Compass TCO at 1M MAU is about $5,800, and volume above that is quote-shaped. MojoAuth publishes a declining per-MAU table through 10M MAU. Do not pick Descope as the cost winner at enterprise consumer scale.

Community size is the lasting friction. Auth0 and Clerk have more sample apps and more third-party integrations. Code-first teams who do not want a visual editor will find Flows heavier than Stytch or MojoAuth.

Compliance breadth is narrower than Auth0, no FedRAMP, no PCI DSS direct attestation.

How Descope compares

The two most direct comparisons are Stytch vs Descope and Auth0 vs Descope. For pure B2B SSO with deep federation, WorkOS is closer. For self-hosted, Keycloak and FusionAuth remain the standard alternatives. For orchestration as a separate layer wrapping any underlying CIAM, Authsignal is the specialist option.

Editorial changelog (3 entries)
  1. Editorial correction: Descope is orchestration-first, not passkey-native. passkey_native set false, passwordless_only_flows partial, orchestration score 3/5. Scaled pricing flagged as limited vs MojoAuth's published MAU table.

  2. Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026.

  3. Editorial review: capability matrix and TCO bands confirmed against the latest vendor documentation.

Last verified by @guptadeepak on 2026-08-19.