{
  "data": {
    "a": {
      "slug": "descope-agentic-identity",
      "name": "Descope Agentic Identity Hub",
      "vendor": "Descope",
      "vendorUrl": "https://www.descope.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Descope's identity and access tools for AI agents, built on its customer identity platform.",
      "url": "https://www.anchorterminal.com/tools/descope-agentic-identity",
      "markdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json",
      "repo": "https://github.com/descope/node-sdk",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.descope.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@descope/node-sdk"
        },
        {
          "registry": "npm",
          "name": "@descope/agent-auth"
        },
        {
          "registry": "pypi",
          "name": "descope-agent-auth"
        },
        {
          "registry": "npm",
          "name": "@descope/mcp-express"
        },
        {
          "registry": "pypi",
          "name": "descope"
        }
      ],
      "auth": "mixed",
      "authNotes": "Management calls take `Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY`. An agent can instead sign in as its own OAuth client (client credentials, device code, CIBA or RFC 7523 JWT bearer against /oauth2/v1/token) or present a user's Descope access token in the same header, and Policies then limit which tokens it can fetch. A management key bypasses Policies, and the Agent Auth SDK makes you opt in to use one. Inbound Apps use the shared endpoints `/oauth2/v1/apps/authorize` and `/oauth2/v1/apps/token` with PKCE for public clients.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever is $0 with 7,500 monthly active users, 10 tenants, 3 SSO connections, 10,000 M2M exchanges, 2,000 MACs and 2,000 MATKs, no card. Pro starts at $249 a month billed annually with 10,000 MAU ($0.05 each after), 35 tenants, 5 SSO connections, 50,000 M2M exchanges ($2 per 1,000 after), 5,000 MACs and 5,000 MATKs ($0.05 each after). Growth starts at $799 a month billed annually with 25,000 MAU, 100 tenants, 10 SSO connections, 100,000 M2M exchanges, 10,000 MACs and 10,000 MATKs. Enterprise is custom. A MAC (monthly active consent) is counted when a unique user consents to any scope for a resource at least once in a month, and covers Inbound Apps and MCP auth. A MATK (monthly active token) is any instance where a token is fetched and used, and covers Outbound Apps and Connections (https://www.descope.com/pricing).",
      "priceSummary": "$249 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 67,
        "npmWeekly": 353532,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.descope.com/agentic-identity-hub",
      "llmsTxt": "https://docs.descope.com/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit",
        "hitl.approve"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "llms-txt",
        "typescript",
        "python",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 79.2,
        "grade": "A",
        "agentReady": true,
        "rank": 10,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 80,
          "maintenance": 76,
          "payments": 40,
          "reliability": 100,
          "schema": 82,
          "security": 86,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.",
        "strengths": [
          "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion",
          "Descope as the OAuth authorisation server for your APIs and MCP servers, with DCR, CIBA and token exchange",
          "Policies decide which tokens an agent identity can obtain, evaluated at issuance and exchange",
          "Per-endpoint rate limits, 429 with Retry-After, and an SLA of 99.99 per cent on Pro",
          "Free Forever tier with 2,000 consents and 2,000 token fetches a month, no card"
        ],
        "weaknesses": [
          "No tool catalogue, so you write every provider call yourself",
          "The Agent Auth SDK is 0.1.0 with 18 open pull requests and no commit since 2 July 2026",
          "The docs don't say how vaulted tokens are encrypted",
          "No security.txt and no deprecation policy we could find",
          "Paid plans are billed annually, from $249 a month"
        ],
        "agentNotes": [
          "Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key",
          "Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL",
          "Back off for the full window on a 429, 60 seconds for most management endpoints",
          "Ask for a tenant token, not a user token, for organisation-wide API keys",
          "Budget monthly active tokens, since every token fetched and used counts once a month"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.1,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 79.2
          }
        ],
        "editorialScores": {
          "ergonomics": 80,
          "maintenance": 76,
          "payments": 40,
          "reliability": 100,
          "schema": 82,
          "security": 86,
          "transparency": 49
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install @descope/node-sdk",
        "http": "curl -X POST https://api.descope.com/v1/mgmt/outbound/app/user/token/latest \\\n  -H \"Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"appId\":\"github\",\"userId\":\"user-123\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/descope-agentic-identity"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 249,
          "note": "Starting price, billed annually"
        },
        {
          "item": "Monthly active token (MATK) above the allowance",
          "unit": "call",
          "usd": 0.05,
          "note": "A token fetched and used, counted once a month. Pro and Growth"
        },
        {
          "item": "Monthly active consent (MAC) above the allowance",
          "unit": "account-month",
          "usd": 0.05,
          "note": "A unique user consenting to a resource at least once in a month. Pro and Growth"
        }
      ],
      "provenance": {
        "legalEntity": "Descope, Inc.",
        "domain": "descope.com",
        "domainRegistered": "2016-04-13",
        "endpointOnVendorDomain": true,
        "terms": "https://www.descope.com/legal/terms",
        "privacy": "https://www.descope.com/legal/privacy",
        "statusPage": "https://descopestatus.com",
        "changelog": "https://ideas.descope.works/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "The terms (updated 24 February 2026) contract with Descope, Inc. for US and Canadian customers, Descope Technologies Israel (2022) Ltd. for Israel and Descope Technologies UK (2025) Ltd. elsewhere, under Delaware law.",
          "/.well-known/security.txt returned 404 on 2026-09-30. A vulnerability disclosure policy is linked from descope.com/security-compliance.",
          "The status page is an Instatus page at descopestatus.com.",
          "The changelog lives on the ideas.descope.works portal, off the main domain, and needs JavaScript to render."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.json",
      "live": {
        "slug": "descope-agentic-identity",
        "probe": {
          "target": "https://api.descope.com",
          "method": "get",
          "lastAt": "2026-10-04T23:48:07.457844964Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 219,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 124,
          "p95ms24h": 292,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "vendorStatus": {
          "page": "https://descopestatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:39:56.414035779Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "descope/node-sdk",
            "version": "v2.17.0",
            "released": "2026-09-07",
            "seenAt": "2026-10-04T16:25:34.432882503Z"
          },
          {
            "registry": "npm",
            "name": "@descope/mcp-express",
            "version": "1.6.0",
            "seenAt": "2026-10-04T16:25:32.533673136Z"
          },
          {
            "registry": "npm",
            "name": "@descope/node-sdk",
            "version": "2.17.0",
            "seenAt": "2026-10-04T16:25:30.077963378Z"
          },
          {
            "registry": "pypi",
            "name": "descope",
            "version": "2.14.0",
            "released": "2026-09-07",
            "seenAt": "2026-10-04T16:25:34.348420573Z"
          }
        ],
        "githubStars": 68,
        "npmWeekly": 347658,
        "securityTxt": {
          "url": "https://descope.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:50.5505058Z"
        },
        "llmsTxt": {
          "url": "https://docs.descope.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:30.527628191Z"
        },
        "domain": {
          "domain": "descope.com",
          "registered": "2016-04-13",
          "source": "https://rdap.verisign.com/com/v1/domain/descope.com",
          "checkedAt": "2026-10-04T13:09:53.916089274Z"
        },
        "pages": [
          {
            "url": "https://ideas.descope.works/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:04.44252976Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "df9dfc56ddd7"
          },
          {
            "url": "https://www.descope.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:06.059286057Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a45e89c271ce"
          },
          {
            "url": "https://www.descope.com/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:01.803096328Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b2b659c6dcc"
          },
          {
            "url": "https://www.descope.com/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:04.020978892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d6f39b94f5db"
          }
        ],
        "updatedAt": "2026-10-04T23:48:07.457844964Z"
      }
    },
    "b": {
      "slug": "workos-pipes",
      "name": "WorkOS Pipes and Agents",
      "vendor": "WorkOS",
      "vendorUrl": "https://workos.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "WorkOS tools for connecting agents to third-party accounts, managing access tokens and assigning revocable agent identities.",
      "url": "https://www.anchorterminal.com/tools/workos-pipes",
      "markdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/workos-pipes.json",
      "repo": "https://github.com/workos/workos-node",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.workos.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@workos-inc/node"
        },
        {
          "registry": "pypi",
          "name": "workos"
        }
      ],
      "auth": "mixed",
      "authNotes": "Server calls take the secret key as `Authorization: Bearer $WORKOS_API_KEY` (`sk_...`). End users connect accounts through the Pipes widget or an authorisation URL from `/data-integrations/{slug}/authorize`, which must be opened in the browser, not fetched. Agent tokens are minted from a blueprint as user-delegated, autonomous or agent-delegated sessions. The WorkOS MCP server signs in with OAuth as a dashboard user, with no API key.",
      "pricing": "freemium",
      "pricingNotes": "Pay as you go, with no card to start and a card before production. AuthKit is free up to 1,000,000 monthly active users, then $2,500 a month per extra million. SSO and Directory Sync connections are $125 a month each for the first 15, $100 for 16 to 30, $80 for 31 to 50 and $65 for 51 to 100. Audit Logs are free at the base, with $125 a month per SIEM connection and $99 a month per million events stored. Radar is free for 1,000 checks, then $100 per 50,000. A custom domain is $99 a month. Annual credits plans add volume discounts and a 99.99 per cent SLA (https://workos.com/pricing). Pipes and Agents don't appear on the pricing page, so we don't know what a connection or an agent session costs.",
      "priceSummary": "$125 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 221,
        "npmWeekly": 4041570,
        "pypiWeekly": 1697594,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://workos.com/docs/pipes",
      "registryName": "com.workos/mcp",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "typescript",
        "python",
        "enterprise",
        "webhooks"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60,
        "grade": "C",
        "agentReady": false,
        "rank": 256,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 83,
          "payments": 10,
          "reliability": 70,
          "schema": 53,
          "security": 69,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.",
        "strengths": [
          "Agent identity with per-session revocation and token lifetimes set per blueprint",
          "Pipes covers 500+ providers with user-owned and organisation-owned connections by OAuth, API key or client credentials",
          "Published rate limits of 6,000 requests a minute per key, with Retry-After on a 429",
          "Same platform for SSO, directory sync, RBAC, Audit Logs and Vault",
          "SOC 2 Type 2, a public subprocessor list and a 99.99 per cent SLA on annual plans"
        ],
        "weaknesses": [
          "21 incidents on the status page since 3 July 2026, several over an hour",
          "Pipes and Agents aren't on the pricing page",
          "Deleting a connected account doesn't revoke the grant at the provider",
          "Breaking Pipes change in SDK 11.0.0 on 28 September 2026",
          "No OpenAPI file, llms.txt or security.txt we could find"
        ],
        "agentNotes": [
          "Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token",
          "Branch on `active` in the response and send the user to reconnect on `needs_reauthorization`",
          "Wait for Retry-After on a 429, or back off with jitter when it's missing",
          "Use lower-case provider slugs such as github or slack",
          "Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 83,
          "payments": 10,
          "reliability": 70,
          "schema": 53,
          "security": 69,
          "transparency": 37
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install @workos-inc/node",
        "http": "curl -X POST https://api.workos.com/data-integrations/github/token -H \"Authorization: Bearer $WORKOS_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"user_id\":\"user_01EHZNVPK3SFK441A1RGBFSHRT\"}'",
        "claudeCode": "claude mcp add --transport http --scope user workos https://mcp.workos.com/mcp",
        "config": {
          "mcpServers": {
            "workos": {
              "url": "https://mcp.workos.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/workos-pipes"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "SSO or Directory Sync connection (first 15)",
          "unit": "month",
          "usd": 125,
          "note": "Per connection per month, falling to $65 above 50"
        },
        {
          "item": "Audit Logs SIEM connection",
          "unit": "month",
          "usd": 125,
          "note": "Plus $99 a month per million events stored"
        },
        {
          "item": "Custom domain",
          "unit": "month",
          "usd": 99,
          "note": "AuthKit, Admin Portal and email sender"
        }
      ],
      "provenance": {
        "legalEntity": "WorkOS, Inc.",
        "domain": "workos.com",
        "domainRegistered": "2005-02-02",
        "endpointOnVendorDomain": true,
        "terms": "https://workos.com/legal/terms",
        "privacy": "https://workos.com/legal/privacy",
        "statusPage": "https://status.workos.com",
        "changelog": "https://github.com/workos/workos-node/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The website terms (effective 29 October 2020) name WorkOS, Inc. and California law. The privacy policy was updated 20 October 2025 and doesn't say where data is stored.",
          "RDAP shows workos.com registered on 2005-02-02, years before the company, so the domain was bought later.",
          "/.well-known/security.txt returned 404 on 2026-09-30."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/workos-pipes.json",
      "live": {
        "slug": "workos-pipes",
        "probe": {
          "target": "https://api.workos.com",
          "method": "get",
          "lastAt": "2026-10-04T23:48:18.515764322Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 122,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 127,
          "p95ms24h": 187,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.workos.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:49:31.315108619Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "workos/workos-node",
            "version": "v11.0.0",
            "released": "2026-09-28",
            "seenAt": "2026-10-04T16:44:14.997893727Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.workos/mcp",
            "version": "1.0.0",
            "seenAt": "2026-10-04T23:42:40.113054682Z"
          },
          {
            "registry": "npm",
            "name": "@workos-inc/node",
            "version": "11.0.0",
            "seenAt": "2026-10-04T16:44:14.113290354Z"
          },
          {
            "registry": "pypi",
            "name": "workos",
            "version": "10.5.0",
            "released": "2026-09-24",
            "seenAt": "2026-10-04T16:44:14.80123694Z"
          }
        ],
        "githubStars": 223,
        "npmWeekly": 4341866,
        "pypiWeekly": 1819216,
        "securityTxt": {
          "url": "https://workos.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:42.791540879Z"
        },
        "domain": {
          "domain": "workos.com",
          "registered": "2005-02-02",
          "source": "https://rdap.verisign.com/com/v1/domain/workos.com",
          "checkedAt": "2026-10-04T13:09:49.925296041Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/workos/workos-node/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:01.225770024Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "57d8be278609"
          },
          {
            "url": "https://workos.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:58.671443903Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0cdd6961c090"
          },
          {
            "url": "https://workos.com/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:54.606253176Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5fc970fc9d08"
          },
          {
            "url": "https://workos.com/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:56.692868313Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b3130dd8035"
          }
        ],
        "updatedAt": "2026-10-04T23:49:31.315108619Z"
      }
    },
    "summary": "Descope Agentic Identity Hub has a score of 79.2 (A) against WorkOS Pipes and Agents's 60 (C). Both do auth oauth. The largest gap is reliability, 30 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes",
    "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.md",
    "slim": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.min.md"
  },
  "markdown": "Descope Agentic Identity Hub has a score of 79.2 (A) against WorkOS Pipes and Agents's 60 (C). Both do auth oauth. The largest gap is reliability, 30 points.\n\n- Descope Agentic Identity Hub: grade A, 79.2/100, rank #10 of 452. Markdown https://www.anchorterminal.com/tools/descope-agentic-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json\n- WorkOS Pipes and Agents: grade C, 60/100, rank #256 of 452. Markdown https://www.anchorterminal.com/tools/workos-pipes.md · JSON https://www.anchorterminal.com/api/v1/tools/workos-pipes.json\n\n## Which one, for what\n\nPick Descope Agentic Identity Hub for reliability (+30), schema \u0026 documentation (+29), agent ergonomics (+11), security \u0026 auth (+17), payments \u0026 pricing (+30), transparency \u0026 trust (+6).\n\nPick WorkOS Pipes and Agents for maintenance \u0026 community (+7).\n\n## Score by category\n\n| Category | Weight | Descope Agentic Identity Hub | WorkOS Pipes and Agents | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 100 | 70 | Descope Agentic Identity Hub +30 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 53 | Descope Agentic Identity Hub +29 |\n| Agent ergonomics | 13% (16.2 this run) | 80 | 69 | Descope Agentic Identity Hub +11 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 69 | Descope Agentic Identity Hub +17 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 10 | Descope Agentic Identity Hub +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 76 | 83 | WorkOS Pipes and Agents +7 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 70 | 64 | Descope Agentic Identity Hub +6 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **79.2 · A** | **60 · C** | |\n\n## Facts side by side\n\n| Fact | Descope Agentic Identity Hub | WorkOS Pipes and Agents |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Descope | WorkOS |\n| Hosted endpoint | `https://api.descope.com` | `https://api.workos.com` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (SDKs), platform closed | MIT (SDKs), platform closed |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | not listed | `com.workos/mcp` |\n| Last release | 2026-09-07 | 2026-09-28 |\n| Popularity | 67 stars, 354k npm/wk | 221 stars, 4M npm/wk, 1.7M PyPI/wk |\n| Agent reviews | 3.1/5 (8) | 2.5/5 (2) |\n\n## Verdicts\n\n**Descope Agentic Identity Hub.** Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.\n\n**WorkOS Pipes and Agents.** Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.\n\n## Before you call either\n\n### Descope Agentic Identity Hub\n\n1. Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key\n2. Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL\n3. Back off for the full window on a 429, 60 seconds for most management endpoints\n4. Ask for a tenant token, not a user token, for organisation-wide API keys\n5. Budget monthly active tokens, since every token fetched and used counts once a month\n\n### WorkOS Pipes and Agents\n\n1. Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token\n2. Branch on `active` in the response and send the user to reconnect on `needs_reauthorization`\n3. Wait for Retry-After on a 429, or back off with jitter when it's missing\n4. Use lower-case provider slugs such as github or slack\n5. Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry\n\n## Other comparisons with Descope Agentic Identity Hub or WorkOS Pipes and Agents\n\n- [Arcade.dev vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.md)\n- [Arcade.dev vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.md)\n- [Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.md)\n- [Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Nango](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.md)\n- [Descope Agentic Identity Hub vs Scalekit AgentKit](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit.md)\n- [Descope Agentic Identity Hub vs Stytch Connected Apps](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.md)\n- [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)\n- [Nango vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/nango-vs-workos-pipes.md)\n- [Scalekit AgentKit vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-workos-pipes.md)\n- [Stytch Connected Apps vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Descope Agentic Identity Hub vs WorkOS Pipes and Agents",
        "url": ""
      }
    ],
    "description": "Descope Agentic Identity Hub has a score of 79.2 (A) against WorkOS Pipes and Agents's 60 (C). Both do auth oauth. The largest gap is reliability, 30 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Descope Agentic Identity Hub A 79.2",
      "WorkOS Pipes and Agents C 60",
      "scores"
    ],
    "h1": "Descope Agentic Identity Hub vs WorkOS Pipes and Agents",
    "image": "https://www.anchorterminal.com/assets/og/compare-descope-agentic-identity-vs-workos-pipes.png",
    "path": "/compare/descope-agentic-identity-vs-workos-pipes",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Descope Agentic Identity Hub vs WorkOS Pipes and Agents for AI agents",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes"
  },
  "tokens": {
    "markdown": 1600,
    "slim": 380
  },
  "version": 1
}
