The News
Descope has launched Cross-App Access (XAA) support within its Agentic Identity Hub, giving enterprises a standardized way to govern AI agent access to MCP servers using the identity providers they already operate. The announcement introduces five capabilities: ID-JAG token validation and issuance, self-service XAA tenant configuration, per-organization scope policies, and standards-based token exchange built on OAuth 2.1 and the Enterprise-Managed Authorization extension to MCP. The move positions Descope as one of the first identity platforms to treat AI agents as first-class identity principals rather than afterthoughts bolted onto human authentication flows.
Analyst Take
The identity gap that agentic AI is exposing
The enterprise software industry spent the better part of two decades building identity infrastructure for humans. Single sign-on, MFA, SCIM provisioning, and session management were all designed around a person sitting at a keyboard. AI agents are none of those things. They’re autonomous, they operate across tenants and application boundaries, and they initiate requests at machine speed with no human in the loop to catch a permission error. The result is a category-wide identity gap that is becoming commercially significant as MCP servers proliferate and agents become the primary consumers of enterprise APIs.
Descope’s XAA announcement attacks this gap. The core insight is elegant: if two applications already share a trusted identity provider, an agent authenticated by one application shouldn’t have to re-authenticate to reach the other. ID-JAG tokens, minted by the IdP both parties trust, replace the static API keys and inherited user sessions that currently dominate agentic deployments. The protocol matters here. Building on OAuth 2.1, JWT Bearer grants, and the Enterprise-Managed Authorization extension to MCP means Descope is betting on open standards rather than a proprietary credential scheme, which could reduce the lock-in risk that enterprise buyers legitimately worry about.
Why the authentication anti-patterns are the real story
The press release catalogs three identity anti-patterns that are currently endemic to MCP server deployments: static API keys with no expiration, agents borrowing the signed-in user’s full session, and authorization applied at the application level rather than per agent or per tool. Each of these is a meaningful security liability in its own right. Together, they describe a threat surface that grows with every new agent an organization deploys. Third-party research cited in the announcement found that only 22% of teams treat agents as independent identities, meaning the vast majority of agentic deployments today are operating with credentials that were never designed for autonomous systems.
For security teams, the practical implication is straightforward: if an agent inherits a user’s full session and that agent is compromised, the blast radius is the user’s entire permission set. Per-tool scoping and short-lived assertions, as Descope is implementing, constrain that radius materially. The self-service XAA setup feature is an underappreciated addition here. Tenant admins can configure their own identity provider, register agents, and map attributes without filing a support ticket. That matters because the operational burden of onboarding enterprise customers to a new auth scheme is often what kills adoption, not the technology itself.
What government and regulated-sector buyers should watch
The government technology market is navigating its own version of this problem, and the friction is particularly acute. According to ECI Research’s Google GovTech Survey, 31.8% of respondents identified FedRAMP/compliance approval friction for AI vendors as the single largest blocker preventing widespread AI adoption in their developer workflows. A standards-based identity protocol built on OAuth 2.1 and open MCP extensions is the right architectural posture for an eventual FedRAMP authorization push, though Descope has not announced a GovCloud offering and that gap will need to close before federal buyers can act.
The procurement dynamics compound the urgency. ECI Research’s Google GovTech Survey also found that 47.2% of respondents selected “Developer velocity and ease of integration” as the factor carrying the greatest weight in their final technical selection process, assuming baseline compliance requirements are met. That finding aligns precisely with what XAA is designed to deliver: a no-second-login integration path that reduces the friction of connecting agents to enterprise APIs. For ITDMs evaluating agentic identity platforms, the question to ask vendors isn’t just whether they support ID-JAG today but whether their token issuance and validation architecture can extend to GovCloud and air-gapped environments over the next 12–18 months.
The developer experience angle is equally relevant. ECI Research’s Google GovTech Survey found that 48.0% of respondents identified navigating compliance documentation and audit evidence collection as the greatest source of cognitive load for their developers today. Identity plumbing is a meaningful contributor to that burden. When every new MCP server integration requires custom credential management, scoping logic, and consent flows, that work falls on application developers. XAA’s self-service setup and standards-based token exchange are as much a developer productivity story as they are a security one.
Looking Ahead
Agentic identity is moving from a niche concern to a board-level infrastructure question faster than most security vendors anticipated. The proliferation of MCP servers across the enterprise software landscape means that every SaaS vendor with an AI integration strategy is now, functionally, also an identity decision-maker. Descope’s early positioning in this space is credible, and the standards-based approach gives it a defensible architecture as the market matures.
The competitive response will come quickly. Established identity players have the customer relationships and the compliance infrastructure that startups lack, and several have already signaled investment in non-human identity capabilities. Descope’s window to establish category leadership is real but not indefinite. The vendors that win this market will be those that can demonstrate FedRAMP-ready deployment options, deep integration with the major enterprise IdPs, and measurable reduction in the per-agent onboarding burden. Descope has made a credible first move. The question for the next few quarters is execution velocity.
Stay Ahead of Application Development Trends
Get weekly analyst insights, research notes, event coverage, and AppDevANGLE updates delivered directly to your inbox.
Subscribe for Weekly Insights
Join technology leaders, practitioners, and GTM teams following the trends shaping modern software delivery.
Looking for deeper research access?
Explore ECI Research reports, survey insights, and market analysis through the ECI Research Portal.
