Descope adds agent-identity protocol to secure enterprise AI stacks

Descope's Cross-App Access standard replaces static API keys with short-lived tokens, letting enterprises govern AI agents via existing identity providers.

Colorful fiber optic cables are spread across a white surface, with a bright light emanating from a clear segment connecting blue and orange cables.

Descope, a California-based identity platform, has launched Cross-App Access (XAA) support inside its Agentic Identity Hub, giving enterprises a standards-based mechanism to govern how AI agents authenticate across applications and Model Context Protocol (MCP) servers. The move targets a rapidly widening security gap: as autonomous agents become the primary consumers of enterprise APIs, the identity infrastructure underneath them has not kept pace.

The core problem is structural. Most enterprises currently rely on static API keys, shared user sessions, or application-level authorisation to control what AI agents can access. A 2026 study by API management firm Gravitee found that only 22% of teams treat agents as independent identities, with the majority still using shared API keys that carry no expiration date, no per-tool scoping, and no awareness of which specific agent is making a request. A single compromised agent, borrowing a user's full session, can expose everything that user was authorised to touch.

A new identity layer for the agentic era

Descope's XAA implementation is built on the Identity Assertion JWT Authorization Grant (ID-JAG) and the Enterprise-Managed Authorization extension to MCP. In practice, the mechanism works like single sign-on for agents: an agent authenticated in one application can reach another application's API or MCP server using a short-lived cryptographic assertion minted by a shared identity provider, without triggering a second login or a repeated consent screen. Enterprises can route those assertions through providers they already run, including Okta and Ping Identity, and apply per-tenant, per-agent, and per-tool scope policies on every request rather than baking permissions into long-lived credentials.

"Every B2B company shipping an MCP server is about to hear the same question from its enterprise customers: can we govern agent access to this MCP server with our own identity provider?" said Rishi Bhargava, Co-Founder of Descope. The platform now supports both validation of incoming assertions from external identity providers and issuance of assertions for internally-run agents, alongside self-service setup flows that allow tenant administrators to configure the whole stack without raising a support ticket.

Convergence read-across: security meets the agentic workforce

The release sits at the intersection of two fast-moving trends that Disrupts readers are tracking from different angles. For cybersecurity teams, agentic identity is the next non-human identity (NHI) frontier, a category that grew sharply after the wave of machine-identity breaches tied to service accounts and secrets sprawl. Frost & Sullivan's 2025 Frost Radar for Non-Human Identity Solutions recognised Descope as a leader in this emerging category, noting its position as one of the first vendors to treat AI agents as a first-class identity type.

For enterprise technology buyers and their capital allocators, the broader implication is that the rollout of agentic AI at scale is contingent on resolving identity and authorisation infrastructure first. Vendors building MCP servers, including those connecting enterprise workflows to models such as Claude or ChatGPT, cannot credibly sell into large regulated organisations until they can answer the governance question Bhargava flags. That makes identity tooling a bottleneck asset in the agentic-AI adoption curve, and one that is attracting both venture capital and strategic interest from established security platforms looking to extend into the agent layer.

The XAA standard itself is open, built on OAuth 2.1 and JWT Bearer grant mechanisms that are already widely implemented. Descope's bet is that being among the first to deliver production-grade tooling on top of an open standard creates durable positioning, much as early SSO and SCIM adopters became embedded in enterprise procurement lists before the market consolidated. Whether a purpose-built agentic identity vendor can hold that ground against incumbents such as Okta and Microsoft Entra, both of which have signalled intent in the NHI space, is the strategic question that will define the category over the next 18 to 24 months.