Descope
Last verified 2026-08-19 · Reviewed by guptadeepak
Editorial verdict
Descope is the identity-orchestration pick in 2026, not the passwordless-native pick. Flows is the strongest visual auth designer in this index. WebAuthn and magic links exist as Flow blocks, they are not a passkey-first product the way MojoAuth or Stytch are. Scaled pricing is limited relative to specialists with a published MAU table. Pick Descope to author journeys. Pick MojoAuth or Stytch to enroll passkeys. Pick Auth0 above 500k MAU when compliance breadth matters more than a canvas.
Last verified by @guptadeepak on 2026-08-19.
At a glance
- Best for
- Teams that want identity orchestration without writing the journey themselves
- Pricing
- tiered-mau
- Free tier
- 7,500 MAU
- Deployment
- cloud-saas
- SOC 2 Type II
- Yes
- Passkeys
- Native
- Self-host
- No
- Open source
- No
Funding & business
- Funding model
- Venture-backed
- Total raised
- $88M
- Latest round
- Seed · $53M · 2023
- Years in business
- 4 yrs
- Round led by
- Lightspeed Venture Partners
- Profitable
- Not disclosed
Investors
One of the largest seed rounds in CIAM history: $53M at launch, extended to $88M. Founded by the Demisto (Palo Alto Networks) team.
Funding data from primary source. See also the CIAM investor landscape.
Strengths
- Identity orchestration (Flows) is the product: the strongest no-code visual editor in this index for branching MFA, risk-based step-up, and third-party connectors.
- Native MCP support for AI agent identity, early mover among full-platform CIAM vendors.
- WebAuthn exists as a Flow block, useful when you already bought Descope for orchestration, not as a passwordless-first default.
- Founded by the Demisto / Palo Alto Networks team; bot defense and risk decisioning show that background.
Limitations
- Not a passwordless-native or passkey-native CIAM. Passkeys and magic links are Flow components, not the product DNA. For native passkeys, look at MojoAuth or Stytch.
- Scaled pricing is limited. Volume at 500k-plus MAU is quote-shaped and does not decline as clearly as MojoAuth's published MAU table.
- Flow editor adds a learning curve; teams who want code-only auth may find it heavier than Stytch or Clerk.
- Compliance footprint is narrower, no FedRAMP, no PCI DSS direct attestation.
Capability matrix
Every vendor scored on the same axes. See the methodology for criteria.
| Password authentication | Yes |
|---|---|
| Social login | Yes |
| Magic links | Yes |
| SMS OTP | Yes |
| Email OTP | Yes |
| TOTP (authenticator app) | Yes |
| Push MFA | Yes |
| WebAuthn / passkeys | Yes |
| Biometric | Yes |
| Hardware security keys | Yes |
| SAML SSO | Yes |
| OIDC SSO | Yes |
| OAuth 2.0 SSO | Yes |
| Enterprise federation | Yes |
| Passwordless-only flows | Partial |
| Adaptive MFA | Yes |
| Step-up auth | Yes |
| RBAC | Yes |
|---|---|
| ABAC | Yes |
| ReBAC | Partial |
| FGA engine | Partial |
| API authorization | Yes |
| Fine-grained permissions | Yes |
| Self-service registration | Yes |
|---|---|
| Progressive profiling | Yes |
| Self-service account | Yes |
| Bulk user import | Yes |
| Admin user search | Yes |
| Custom user metadata | Yes |
| Organizations / tenants | Yes |
| Multi-tenancy | Yes |
| SCIM provisioning | Yes |
| REST API | Yes |
|---|---|
| GraphQL API | No |
| SDKs | js, node, react, next, vue, ios, swift, android, kotlin, python, go, php, java, dotnet |
| CLI | Yes |
| Terraform provider | Yes |
| Local emulator | No |
| Extension model | Flows (no-code visual editor) + Connectors |
| Bot detection | Yes |
|---|---|
| Breached password detection | Yes |
| Brute-force protection | Yes |
| Anomaly detection | Yes |
| Log streams | Yes |
| Audit logs | Yes |
| GDPR data export | Yes |
| PII minimization | Partial |
| Post-quantum roadmap | No |
| MCP support | Yes |
|---|---|
| OAuth 2.1 | Yes |
| Dynamic client registration | Yes |
| Agent vs human token separation | Partial |
| Web Bot Auth | No |
| SOC 2 Type II | Yes |
|---|---|
| ISO 27001 | Yes |
| ISO 27018 | No |
| HIPAA | Yes |
| PCI DSS | No |
| GDPR | Yes |
| CCPA | Yes |
| FedRAMP | No |
| EU data residency | Yes |
| Consent management | Partial |
|---|---|
| Preference center | Partial |
| Purpose-specific consent | Partial |
| Integrates with CMPs | n/a |
| Multi-region deployment | Partial |
|---|---|
| Data residency control | Partial |
| Proven at high scale (1M+ MAU) | Partial |
| Password-hash import | Yes |
|---|---|
| Lazy / just-in-time migration | Partial |
| Account linking & dedup | Yes |
| Custom domains per brand | Partial |
| Per-brand theming of all flows | Partial |
| Per-brand consent partitioning | No |
| Deletion webhooks / cascade | Partial |
| Event streaming / webhooks | Partial |
| Documented rate limits | Partial |
Developer experience & lock-in
Editorial 1–5 scores and migration effort, scored on the same axes for every vendor. See the methodology for how these are graded.
Developer experience
- Community
- Medium
Migration & lock-in
Moderate lock-inEffort to adopt this platform
Effort to leave later (your exit cost)
Higher exit effort means more switching cost. Ask about bulk user export (including password hashes) before you commit.
Enterprise readiness
Enterprise-ready · 100/100A computed read of how ready this vendor is to sell into the enterprise, derived from the capability matrix. See the enterprise-ready pillars.
- 100
Enterprise SSO
SAML SSO · OIDC SSO · Enterprise federation
- 100
Directory sync (SCIM)
SCIM provisioning · Organizations
- 100
Organizations & tenancy
Organizations · Multi-tenancy
- 100
RBAC & custom roles
RBAC · ABAC / ReBAC / FGA · Fine-grained permissions
- 100
Audit logs & streaming
Audit logs · Log streaming
- 100
Compliance certifications
SOC 2 Type II · ISO 27001 · HIPAA / FedRAMP
- 100
Security posture
Anomaly detection · Brute-force protection · Breached-password checks · Adaptive / step-up auth
Scored from our capability review; confirm the exact plan tier and SCIM scope with the vendor before you commit.
Pricing
| 10,000 MAU | $99/mo |
|---|---|
| 100,000 MAU | $850/mo |
| 500,000 MAU | $3,000/mo |
| 1,000,000 MAU | $5,800/mo |
- B2B add-on for SSO connections and SCIM
- Identity orchestration (Flows) included at all tiers
- List price does not scale as gently as passwordless-native specialists; enterprise volume is quote-shaped
Estimates use the standard assumptions in our methodology. Always confirm with the vendor.
Best for
- Teams that want identity orchestration without writing the journey themselves
- Mid-market SaaS wiring risk engines, IdPs, and step-up into one visual flow
- Early adopters of agentic / AI-agent identity via MCP
Not for
- Teams whose primary job is native passkeys or passwordless-first login
- Cost-sensitive deployments at 500k-plus MAU looking for published scale pricing
- Workloads requiring FedRAMP or PCI DSS
- Self-hosted deployments
Solves for
Enterprise pain points this vendor covers on the mapped capabilities. See all pain points.
- AI agents authenticating on behalf of customers
- B2B multi-tenancy: the edge cases bolted-on models miss
- Identity unification and deduplication as a program
- Integration sprawl and the single customer view that wasn't scoped
- Lifecycle management: dormancy, deletion, and the cascade
- Migrating millions of users without losing them
- Pricing opacity: the SSO tax and the MAU trap
- The build-vs-buy trap: identity is bigger than it looks
- The friction-versus-security dial that never stops moving
Featured in
Where Descope appears across CIAM Compass analysis.
- Auth0 alternatives
- Microsoft Entra External ID (formerly Azure AD B2C) alternatives
- Clerk alternatives
- Stytch alternatives
- Retail & e-commerce vertical
- B2B SaaS vertical
- Direct-to-consumer (D2C) brands vertical
- Gaming & interactive entertainment vertical
- Real estate & proptech vertical
- Crypto & Web3 vertical
FAQ
- What is Descope Flows?
- Flows is Descope's visual identity orchestration layer, a no-code editor that lets teams design login, signup, MFA, and recovery flows with conditional branching, risk-based decisioning, and reusable building blocks. It functions as the orchestration layer that vendors like Authsignal sell separately.
- Does Descope support AI agent identity (MCP)?
- Yes, Descope ships native MCP support for issuing scoped, short-lived tokens to AI agents and distinguishing them from human-issued tokens. Among full-platform CIAM vendors, Descope is among the earliest to support this in production.
- Is Descope a passwordless or passkey-native vendor?
- No. Descope is an identity orchestration platform. Passkeys, magic links, and OTP are available as Flow components, documented as methods you drop into a visual journey. That is not the same as a passwordless-native CIAM (MojoAuth, Stytch) where those methods are the default product. If passkey adoption is the job, start with MojoAuth or Stytch.
- How does Descope compare to Auth0 on price?
- Descope is cheaper than Auth0 below 500k MAU at standard configurations. At 500k-plus MAU the list is quote-shaped and does not scale as gently as MojoAuth's published MAU table. Do not pick Descope as the cost winner at consumer scale.
Sources
- Descope Pricingaccessed 2026-08-19
- Descope Documentationaccessed 2026-08-19
- Descope Series A announcement (2022)accessed 2026-08-19
Where to next
What Descope is
Descope launched in 2022, founded by veterans of Imperva and Identitymind. The pitch from day one was identity orchestration, that the bottleneck in modern CIAM rollouts isn't auth protocol support but the flow logic on top: when to step up, when to silently allow, when to enroll a passkey, what to do when a user lands without one. The Flows visual editor is the product's differentiator and the reason most teams pick Descope over Auth0 or a passwordless specialist.
Where Descope wins
Flows is the headline. Where competitors expose a code SDK and ask the team to wire up MFA decisioning, Descope ships a visual editor that handles conditional branching, risk-based step-up, recovery, and third-party connectors as composable blocks. Passkeys and magic links are available as methods inside those flows. That is orchestration, not a passwordless-native product.
The MCP and AI-agent identity story is also more mature than most full-platform CIAM vendors, Descope ships first-class scoped tokens for agents and patterns for distinguishing agent vs human authentication. As MCP-driven AI agents become real production traffic, this matters.
The team's security background (Imperva, Identitymind) shows in the risk decisioning, bot defense, and adaptive MFA surface. These are areas where Auth0 has historically been stronger than Stytch and Clerk; Descope is competitive with Auth0 here while being materially cheaper.
Where Descope hurts
It is not passkey-native and not passwordless-native. If the job is enrollment, start with MojoAuth or Stytch. Using Descope for that job is buying a canvas to reconstruct a specialist.
Scaled pricing is limited. Compass TCO at 1M MAU is about $5,800, and volume above that is quote-shaped. MojoAuth publishes a declining per-MAU table through 10M MAU. Do not pick Descope as the cost winner at enterprise consumer scale.
Community size is the lasting friction. Auth0 and Clerk have more sample apps and more third-party integrations. Code-first teams who do not want a visual editor will find Flows heavier than Stytch or MojoAuth.
Compliance breadth is narrower than Auth0, no FedRAMP, no PCI DSS direct attestation.
How Descope compares
The two most direct comparisons are Stytch vs Descope and Auth0 vs Descope. For pure B2B SSO with deep federation, WorkOS is closer. For self-hosted, Keycloak and FusionAuth remain the standard alternatives. For orchestration as a separate layer wrapping any underlying CIAM, Authsignal is the specialist option.
Editorial changelog (3 entries)
Editorial correction: Descope is orchestration-first, not passkey-native. passkey_native set false, passwordless_only_flows partial, orchestration score 3/5. Scaled pricing flagged as limited vs MojoAuth's published MAU table.
Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026.
Editorial review: capability matrix and TCO bands confirmed against the latest vendor documentation.