AI Tool Profile

Descope MCP Server: Security Model, Pricing, and Evaluation

Descope MCP Server gives authenticated AI assistants read-first access to Descope documentation and identity-project administration, with explicit out-of-band elevation for writes.

Identity engineer reviewing a read-only MCP operation path before requesting a locked write

Verification & Sources

Evidence state
Recheck due
Source links
5
Freshness
Needs recheck: checked July 27, 2026
Last updated
July 27, 2026
What this evidence state means
Definition
The claim was previously checked, but its review window expired or a material change may have invalidated it.
Required provenance
The prior evidence and check date are retained, together with the expiry or change signal that triggered recheck.
Owner
Kingy freshness queue owner and assigned editorial reviewer
Freshness rule
This is already outside its freshness rule. It must not be presented as current until reviewed against current evidence.
Disputes and corrections
Use “Suggest a correction” on the record. Kingy editorial reviews the cited evidence, records material corrections, and changes or removes the state when it is not supported.
Suggest a correction

Form submissions, correction notes, score details, URLs, and analytics events may be stored for editorial review, spam prevention, product improvement, and follow-up. Do not submit secrets, unreleased financials, private customer data, or regulated personal data through these forms.

Kingy verdict: Descope MCP Server is one of the more concrete identity-administration MCP products because the security model is documented at the operation level: sessions begin read-only, write requests require explicit approval plus an out-of-band one-time passcode, and elevation expires after 15 minutes. That architecture reduces silent-write risk, but it does not make a broadly connected identity console low risk.

What the server exposes

Descope launched the hosted remote server on June 8, 2026. An MCP-compatible assistant can search Descope documentation, inspect project configuration, query users and tenants, review audit logs, examine access-control objects, and work with authentication flows, connections, keys and agentic-identity configuration. The documented endpoint is remote rather than a package customers install locally. That delivery model simplifies client setup but also makes Descope account authentication, service availability and vendor-side change management part of the operating dependency.

The useful distinction is between documentation work and project administration. docs_search and docs_ask_question provide grounded product help; read buckets expose live project state; write buckets can change users, credentials, flows, roles, tenants and MCP registrations. Teams should inventory which buckets their client can call instead of treating “connected to Descope” as one permission.

Security model and limits

Read tools become available after authentication. For a write, the assistant must identify the operation and arguments, show the target, wait for approval, and trigger a one-time passcode through a channel it does not control. The elevated window then closes automatically after 15 minutes. Sessions are scoped to one Descope company, and administrative MCP events are logged.

This is a meaningful human-control boundary, not proof that every proposed change is safe. A user can still approve a destructive or mis-scoped action. Acceptance testing should cover project selection, tenant boundaries, redaction, audit completeness, credential rotation, revocation, replay resistance, client disconnects and what happens when a multi-step workflow crosses the elevation timeout.

Pricing and availability

The MCP Server is offered with Descope’s identity platform. Descope currently publishes Free at $0, Pro from $249 per month, Growth from $799 per month and Enterprise by quote, with different usage and feature allowances. Public material does not isolate every MCP operation or limit by tier, so confirm entitlement in the console or contract rather than assuming the full write catalog is included in the free plan.

How Kingy would evaluate it

Start with a disposable project and read-only tasks: list roles, summarize an audit window and compare a flow against a documented policy. Then enable one narrowly scoped write, capture the proposed arguments, approve it, verify the resulting audit event and test automatic reversion after the 15-minute window. Repeat with a rejected OTP and a second company to confirm isolation.

Kingy reviewed Descope’s announcement, current MCP documentation, pricing table and Agentic Identity Hub materials. We did not connect a production Descope tenant or validate the control path independently. The strongest reason to trial the server is its inspectable elevation contract; the strongest reason to proceed cautiously is the breadth of identity infrastructure available behind that contract.

Primary sources

Launch History

AI Developer Tools

Descope MCP Server

Descope launched a hosted remote MCP server for documentation search and identity-project administration, with read-only sessions by default and explicit out-of-band approval for writes.

Recheck due Free: Yes API: Yes Open: No
Clear use caseDeveloper-friendly
Launch readiness
7.7 / 10
Demo evidence
Not scored yet
Creator-story fit
Not scored yet
Score definitions and rubric

These are launch-record readiness heuristics, not product ratings.

Launch readiness

How complete and reviewable the launch record is, not the quality of the product.

Inputs and weights: Launch date 15%; qualifying source 10%; what launched 10%; demo 15%; category 10%; audience 10%; editorial assessment 10%; traction evidence 10%; creator or audience fit 10%.

Evidence inputs: Reviewed launch metadata, public source links, demo links, taxonomy, audience, editorial notes, and recorded traction signals.

Demo evidence

Whether the record contains useful, reviewable demonstration evidence; it is not a rating of product output quality.

Inputs and weights: Working demo URL 45%; video walkthrough 25%; clear description of what launched 10%; audience 10%; editorial assessment 10%.

Evidence inputs: Demo and video URLs plus the reviewed launch description, audience, and editorial notes.

Creator-story fit

Whether a launch has enough demonstrable evidence and audience relevance for a useful creator story; it does not predict views or guarantee coverage.

Inputs and weights: Demo evidence 25%; visual creator category 15%; audience 15%; editorial assessment 15%; traction evidence 10%; pricing clarity 10%; API or open-weight evidence 10%.

Evidence inputs: Reviewed demo, category, audience, editorial, traction, pricing, API, and open-weight fields.

Scale
0.0–10.0. A present qualifying input receives its published weight; a missing input receives zero. Scores are rounded to one decimal.
Assigned by
Suggested by the deterministic field-completeness helper and assigned or approved by a Kingy editorial reviewer.
Rubric and check date
Rubric version P0-2026-08-10. The record’s “Last verified” date is the score check date. Checked: 2026-07-27.
Confidence and missing data
Confidence depends on source completeness. “Not scored yet” means no reviewed value; “Needs review” means the value or score set failed validation.
Freshness
Recalculate after a material launch, source, demo, pricing, audience, or traction change and during the record freshness review.
Disputes
Use “Suggest a correction” on the record and cite the relevant evidence. Commercial relationships cannot buy or alter a score.

Descope MCP Server stands out for a documented read-only default, out-of-band one-time-passcode approval and a 15-minute write window. Those controls reduce silent-write risk but…