Descope Agentic Identity Hub
Descope
Control plane for AI agent identity: OAuth 2.1 MCP auth, token vault connections, scoped policies and a user-linked audit trail.
Curated by Tiberiu ArvaVerified
Strengths
- OAuth 2.1 authorization for MCP servers
- Token vault for agent connections
- Enterprise-Managed Authorization (XAA)
Practitioner note
Practical for teams exposing APIs or MCP servers to agents that need consent and scoped tokens fast; Gateways are still early access, so do not plan runtime enforcement around them yet.
Warning
Governance posture
Reviewed 2026-09-30Multi-region data residency across seven regions (US, EU, UK, Canada, Singapore, Australia, Brazil).
SourceDescope-hosted SaaS; FedRAMP High authorized. (saas)
SourceAudit trail connects every agent action back to the originating user.
SourceDescope is SOC 2 Type 2 certified.
SourceDescope is ISO 27001 certified.
SourceISO/IEC 42001 is not mentioned on Descope's security and compliance page.
Identity and access-control tooling for agents, not itself an AI system placed on the market; AI Act obligations rest with the provider/deployer of the governed agents. (role: not-applicable)
Proprietary Descope service; agent and MCP-server identities are issued by Descope. (medium)
SourceEU AI Act obligations
Risk tier: Not applicable · as of 2026-08-23Source-backed information mapped from Descope Agentic Identity Hub's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.
This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.
Explore the category
Compare this tool against the rest of its category and the cloud platform foundation layer.
Return to the category grid to compare governance posture across every tracked tool.
Review Microsoft Foundry, Amazon Bedrock, and Gemini Enterprise Agent Platform as the foundation layer.
Track releases, deprecations, license changes, and other market movements.