# Vendor facets — Descope. No-code CIAM with an Agentic Identity Hub (MCP auth, DCR, CIMD, consent, # connections vault, XAA) and an MCP Express SDK that serves the MCP server's metadata. Headline: Descope's # discovery documents are PATH-SCOPED (// and /v1/apps/agentic///, fetched live); # the root of api.descope.com serves none, so the served identity tiers are not reached by the root-only # harvest even though the capability — registration_endpoint included — is real. Custom domain is Pro+. vendor: descope name: Descope website: https://www.descope.com areas: - identity registry_keys: [] rubric_schema_version: 0.22.0 generated: '2026-09-25' features_refreshed: '2026-09-25' basis: capability summary: >- Descope's strongest Kin Score lever is its MCP Express SDK, which serves protected-resource metadata from the provider's own MCP server and so can earn the verified RFC 9728 tier. Its own discovery documents, rich as they are (authorization_code, CIBA, token exchange, a registration endpoint), sit under a project path, so the served tiers of auth clarity, delegated identity and dynamic client registration are not read; the provider reaches only the OpenAPI fallback tiers it writes itself. Not detectable from the registry today, so capability-only. features: - id: agentic-identity-hub name: Agentic Identity Hub description: >- OAuth 2.1 authorization for MCP servers with per-tool scopes, DCR and CIMD, user consent, a connections vault, agent identities, XAA and RFC 8693 token exchange. source: https://docs.descope.com/agentic-identity-hub tier: unknown - id: path-scoped-discovery name: Path-scoped authorization server metadata description: >- MCP-app metadata served under /v1/apps/agentic/// (and path-inserted) with issuer, authorization_code, CIBA, token-exchange and registration_endpoint; project OIDC discovery under //. source: >- https://api.descope.com/v1/apps/agentic/P2DA3QqyF3N3BlmIqn1nr0LMFhrw/MS3AebdnI1nLELsiorZz77KmIleWt/.well-known/oauth-authorization-server tier: all - id: mcp-express-sdk name: '@descope/mcp-express SDK' description: >- Middleware that runs the MCP server as a resource server, exposes RFC 9728 protected-resource and RFC 8414 metadata endpoints, bearer auth and RFC 8707 resource indicators. source: https://github.com/descope/mcp-express tier: open-source - id: custom-domain name: Custom domain (CNAME) description: >- CNAME a subdomain to Descope as the SDK base URL for auth/session APIs and HttpOnly refresh cookies; Pro+ tier. source: https://docs.descope.com/how-to-deploy-to-production/custom-domain tier: paid maps: - feature: mcp-express-sdk check: protected_resource_metadata layer: agent_readiness grade: verified provider_must: >- Run its MCP/API server with the SDK on a host on its record, so /.well-known/oauth-protected-resource (naming Descope in authorization_servers) is served there. Descope's own mcp.descope.com serves one. points: 5 baseline_pass_rate: 0.133 - feature: mcp-express-sdk check: well_known_published layer: composite provider_must: Same — the served protected-resource document is one of the documents this check reads. catalog_pass_rate: 0.005 facet: discoverability points: 6 baseline_pass_rate: 0.018 - feature: path-scoped-discovery check: auth_clarity layer: agent_readiness grade: negotiable partial: true partial_note: >- The served tier needs a root discovery document on a provider host; Descope's live under a project path (the api.descope.com root answers none), so only the OpenAPI fallback is reachable. provider_must: Declare the Descope-backed oauth2 scheme in its own OpenAPI. points: 10 baseline_pass_rate: 0.474 - feature: path-scoped-discovery check: delegated_identity layer: agent_readiness grade: documented partial: true partial_note: Same path reason; the documented tier reads an authorizationCode flow in the provider's OpenAPI. provider_must: Declare the authorizationCode flow in its own OpenAPI. points: 6 baseline_pass_rate: 0.209 - feature: path-scoped-discovery check: dynamic_client_registration layer: agent_readiness conditional: true condition: >- Only if the provider's host answers the root /.well-known/oauth-authorization-server with Descope's metadata (e.g. the SDK's own AS-metadata endpoint on the MCP host) and that host is on its record. points: 6 baseline_pass_rate: 0.134 - feature: agentic-identity-hub check: oauth_scopes_enumerated layer: composite conditional: true condition: Only if the provider's own OpenAPI declares oauth2 and enumerates its per-tool scopes. catalog_pass_rate: 0.866 facet: contract_quality points: 4 baseline_pass_rate: 0.902 saturated: true saturated_note: >- 90% of providers with a contract, docs and a reference already earn this; the vendor cannot move it for most of its buyers. - feature: agentic-identity-hub check: reg_consent_model layer: composite conditional: true condition: Regulated regime only, and only when the provider documents the consent model its agent flows use. catalog_pass_rate: 0.126 facet: regulatory points: 7 baseline_pass_rate: 0.431 earns_nothing: - feature: custom-domain check: auth_clarity why: >- The fetched custom-domain page covers auth/session APIs and cookies, not the issuer; discovery stays under a project path either way. - feature: agentic-identity-hub check: consent_identity why: >- User consent to agent access is not an AI usage preference or Web Bot Auth / HTTP Message Signatures agent identity. out_of_reach: checks: - security_schemes_defined - oauth_flows_current - reg_fapi_profile note: The OpenAPI checks are the provider's contract; no FAPI profile appears on the fetched pages. unscored_practice: - feature: path-scoped-discovery why: CIMD and CIBA support in the served metadata are read by no dimension. surface: discoverability: reachable: 6.0 total: 54 contract_quality: reachable: 4.0 total: 211 regulatory: reachable: 7.0 total: 108 agent_readiness: reachable: 21.5 total: 139 hard_rule: >- A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. method: searched source: - >- https://api.descope.com/v1/apps/agentic/P2DA3QqyF3N3BlmIqn1nr0LMFhrw/MS3AebdnI1nLELsiorZz77KmIleWt/.well-known/oauth-authorization-server - https://docs.descope.com/agentic-identity-hub - https://docs.descope.com/how-to-deploy-to-production/custom-domain - https://github.com/descope/mcp-express measured: cohort: method: vendors-catalog.json detections (CNAME / header / URL shape / markup), never a name match detected: 0 in_baseline: 0 control: basis: providers earning contract_present + documentation_present + api_reference_present, minus the cohort n: 5216 metric: >- cohort_pct / control_pct = mean share of the check's points earned (derived and platform credit weighted), x100 measured_on: '2026-09-25' status: 'not measurable: 0 detected customers clear the baseline (need 20)' simulation: simulated_on: '2026-09-25' rubric: 0.23.0 population: providers publishing a contract (contract_present earned), replayable exactly providers: 8977 providers_unreplayable: 987 providers_moved: 8959 conditional_rows: excluded (they depend on what the API already does) composite_lift: median: 1.1 p75: 1.1 p90: 1.1 max: 1.2 mean_among_movers: 1.1 agent_readiness_lift: median: 8.6 p75: 8.7 p90: 10.1 max: 13.0 mean_among_movers: 8.4 facet_lift_median_among_movers: discoverability: 11.1 composite_band_moves: thin -> developing: 388 developing -> strong: 198 emerging -> thin: 107 strong -> exemplar: 69 minimal -> emerging: 1 agent_readiness_band_moves: agent-aware -> agent-ready: 3325 agent-ready -> agent-native: 285 method: >- each provider's own kin/checks file, the vendor's maps at their stated credit, the scorer's composite formula; from -> to, nothing written