Descope
Add auth to your apps and MCPs
- Category
- Security
- Primary Subcategory
- Authentication & Identity Platforms
Integration details
Description
Descope brings a first-class authentication and identity management experience into ChatGPT. Manage users, tenants, roles, and access control across your Descope projects through natural language. Build and modify auth flows for signup, login, MFA, SSO, and federation without leaving the conversation. Configure auth, consent, and credential management for your MCP servers and AI agents, and easily search Descope documentation when you need guidance.
- Integration type
- Plugin
- Verification status
- Not applicable
- Platform
- ChatGPT
- Primary Subcategory
- Authentication & Identity Platforms
- Secondary Subcategories
- None listed
- Brand
- Descope
- Access
- Account required
- First tracked
- 2026-07-22
- Tool count
- 23
- Geography
- US
The Primary Subcategory used for this profile’s headline score.
Other Subcategories where the Integration is listed.
Get alerts for Descope
Get updates when Descope’s Discoverability Score or category rank changes.
ChatGPT Plugin Discovery Score
ChatGPT Plugin discovery is coming soon
ChatGPT can surface a Plugin when it matches a user's request.Your Plugin Discovery Score measures how often yours appears.
No spam. Unsubscribe any time.
What discovery looks like

Competing in ChatGPT Authentication & Identity Platforms
View Category23 tools agents can invoke
Ask a natural-language question about using Descope in code (SDKs, flows, integration). Returns a grounded answer from Descope docs. Use for 'how do I...' questions about integrating Descope, NOT for managing a project's data: use the bucket tools (e.g. `users_read`, `tenants_write`) for that.
docs_ask_question
Discover the bucketed catalog of management operations (users, tenants, roles, flows, ...). Project selection, identity, and onboarding are NOT management operations: they live on the `session` tool (listProjects, selectProject, whoami) and also appear here as the read-only `session` bucket. Two modes: (1) Pass `operationId` to return the full input/output schema for that operation (use this before invoking a bucket tool with placeholder args). (2) Omit `operationId` to list operations grouped by bucket; `bucket` filters to one bucket and `filter="allowed_only"` restricts to ops the caller's role can invoke.
list_operations
Requires write elevation. Call `session({action: "elevate", args: {reason: <verbatim user request>}})` before invoking any operation in this bucket. Manage FGA schema, FGA backups, FGA relations, role and permission CRUD (single + batch), policy rules, resource details, and auth access policy rules and settings. Call `list_operations({bucket: "access_control_write"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
access_control_write
Requires write elevation. Call `session({action: "elevate", args: {reason: <verbatim user request>}})` before invoking any operation in this bucket. Create, update, and delete MCP servers; manage MCP server clients and rotate client secrets; manage dynamic registration templates; revoke agentic identities. Call `list_operations({bucket: "agentic_write"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
agentic_write
Requires write elevation. Call `session({action: "elevate", args: {reason: <verbatim user request>}})` before invoking any operation in this bucket. Create, rotate, and delete access keys (creation returns the cleartext bearer credential); configure password settings; update JWT; generate JWT for sign-in or sign-up; impersonate or stop impersonating a user. Call `list_operations({bucket: "auth_keys_write"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
auth_keys_write
Requires write elevation. Call `session({action: "elevate", args: {reason: <verbatim user request>}})` before invoking any operation in this bucket. Manage SSO settings and IDP apps (OIDC, SAML, WS-Fed); manage Inbound Apps and Outbound Apps including connections, API keys, and consents. Operations: - `ConfigureSSOOIDCSettings`: Configure SSO Settings - `ConfigureSSORedirectURL`: Configure SSO Settings - `ConfigureSSOSAMLSettings`: Configure SSO Settings - `ConfigureSSOSAMLSettingsByMetadata`: Configure SSO Settings by metadata - `ConnectOutboundApp`: Connect to outbound application - `CreateOutboundApp`: Create outbound application - `CreateOutboundAppByDcrPreset`: Create outbound application according to existing dcr preset - `CreateOutboundAppByTemplate`: Create outbound application by existing template - `CreateSSOOIDCApplication`: Create SSO OIDC IDP application - `CreateSSOSAMLApplication`: Create SSO SAML IDP application - `CreateSSOWSFedApplication`: Create SSO WS-Fed IDP application - `CreateThirdPartyApplication`: Create Inbound App - `DeleteOutboundApp`: Delete outbound application - `DeleteOutboundAppTokenByID`: Delete outbound application token by id - `DeleteOutboundAppUserTokens`: Delete outbound application tokens by appId or userId - `DeleteSSOApplication`: Delete SSO IDP application - `DeleteSSOSettings`: Delete SSO Settings for a tenant - `DeleteThirdPartyApplication`: Delete Inbound App - `DeleteThirdPartyApplicationConsents`: Delete Inbound App consents - `DeleteThirdPartyApplicationTenantConsents`: Delete Inbound App tenant consents - `DeleteThirdPartyApplications`: Delete Inbound App - `NewSSOSettingsRequest`: New SSO Settings for a tenant - `PatchThirdPartyApplication`: Patch Inbound App - `RecalculateSSOMappings`: Recalculate SSO Mappings - `RegisterThirdPartyApplication`: RegisterThirdPartyApplication - `RotateThirdPartyApplicationSecret`: Rotate Inbound App secret by application ID - `UpdateOutboundApp`: Update outbound application - `UpdateSSOOIDCApplication`: Update SSO OIDC IDP application - `UpdateSSOProviderIDs`: Update SSO Provider IDs - `UpdateSSOSAMLApplication`: Update SSO SAML IDP application - `UpdateSSOWSFedApplication`: Update SSO WS-Fed IDP application - `UpdateThirdPartyApplication`: Update Inbound App - `UploadOutboundAppTenantAPIKey`: Upload tenant API key for outbound app - `UploadOutboundAppUserAPIKey`: Upload user API key for outbound app Example: `connect_write({operation: "CreateOutboundApp", args: { /* see schema */ }})` For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
connect_write
Requires write elevation. Call `session({action: "elevate", args: {reason: <verbatim user request>}})` before invoking any operation in this bucket. Import flows and themes, delete flows, complete external auth flow, and import flow localization. Call `list_operations({bucket: "flows_write"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
flows_write
Requires write elevation. Call `session({action: "elevate", args: {reason: <verbatim user request>}})` before invoking any operation in this bucket. Manage project (rename, delete), import/export snapshots, manage lists, descopers, and messaging localization imports. Call `list_operations({bucket: "project_write"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
project_write
Requires write elevation. Call `session({action: "elevate", args: {reason: <verbatim user request>}})` before invoking any operation in this bucket. Create, update, delete tenants; configure tenant settings, default roles, SSO suffix cleanup, and admin links. Sending a tenant admin link emails it to the recipient. Call `list_operations({bucket: "tenants_write"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
tenants_write
Requires write elevation. Call `session({action: "elevate", args: {reason: <verbatim user request>}})` before invoking any operation in this bucket. Create and delete test users; generate test OTP, magic link, and enchanted link (the code/link is returned to the caller, not delivered). Call `list_operations({bucket: "tests_write"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
tests_write
Requires write elevation. Call `session({action: "elevate", args: {reason: <verbatim user request>}})` before invoking any operation in this bucket. Create, update, patch, batch-patch, and delete users; manage user credentials (passwords, passkeys, TOTP) and SCIM user mutations. Operations: - `CreateSCIMUser`: Create SCIM User - `CreateUserCustomAttribute`: Create User Custom Attribute - `CreateUsers`: Create Users - `DeleteSCIMUser`: Delete SCIM User - `DeleteUserCustomAttribute`: Delete User Custom Attribute - `DeleteUsers`: Delete Users - `ExpireUserPassword`: Expire User Passwsord - `ImportUserPasskeys`: Import User Passkeys - `ListTrustedDevicesForUsers`: List Trusted Devices - `LoadUsers`: Load Users - `LogoutAllUserDevices`: Logout user from all its devices. - `PatchUser`: Patch User - `PatchUserBatch`: Patch Users Batch - `RemoveUserPasskeys`: Remove User Passkeys - `RemoveUserTOTP`: Remove User TOTP - `SCIMPatchUser`: Patch SCIM User - `SetUserActivePassword`: Set User Password - `SetUserTemporaryPassword`: Set User temporary Password - `UpdateSCIMUser`: Update SCIM User - `UpdateUser`: Update User - `UpdateUserImpersonationConsent`: Update User Impersonation Consent - `UpdateUserRemoveTrustedDevices`: Delete Trusted Devices Example: `users_write({operation: "CreateUsers", args: { /* see schema */ }})` For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
users_write
Read FGA schema, FGA backups, mappable schema/resources, role definitions, permissions, policy rules, ReBAC relations, authorization queries, and auth access policy rules and settings. Call `list_operations({bucket: "access_control_read"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
access_control_read
Read MCP server definitions, MCP server clients including client secrets, dynamic registration templates, and agentic identities. Call `list_operations({bucket: "agentic_read"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
agentic_read
Search audit events and analytics. Call `list_operations({bucket: "audits_read"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
audits_read
Read access key metadata (without bearer credentials) and password policy settings. Call `list_operations({bucket: "auth_keys_read"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
auth_keys_read
Read SSO settings and SSO IDP apps, Inbound Apps, Outbound Apps, and Outbound App tokens including client secrets. Call `list_operations({bucket: "connect_read"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
connect_read
Read flow definitions and templates, themes, flow localization, and widgets. Call `list_operations({bucket: "flows_read"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
flows_read
Read project metadata, clone state, snapshot exports, lists (IP and text), descopers, and messaging localization. Call `list_operations({bucket: "project_read"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
project_read
Read tenant records, tenant settings, and tenant admin-link SSO state. Call `list_operations({bucket: "tenants_read"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
tenants_read
Search test users. Call `list_operations({bucket: "tests_read"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
tests_read
Read user records, custom attributes, group membership, trusted devices, and auth history. Call `list_operations({bucket: "users_read"})` to discover currently available operations. For a single operation's full input/output schema, call `list_operations({operationId: "<op>"})`. Operations call the Descope Management API. See https://docs.descope.com/api/management for the full reference.
users_read
Semantic search across Descope documentation, SDK references, and GitHub. Use this to locate concepts, APIs, or error messages when helping a developer integrate Descope.
docs_search
Session primitives: identity, project selection, onboarding state, and write-mode elevation. Pass action and optional args. Actions: - whoami: returns current session context (project, user, roles, elevated flag, available_buckets). Read-only. - listProjects: lists projects the authenticated user can access. Read-only. Call only when you need to display projects to the user; do NOT call as a prerequisite for bucket tools. - selectProject: args.projectId required. Switches the target project. Call only on explicit user request or when a bucket tool returns a project selection error. - getProjectStatus: args.existing_context optional. Returns current project state plus an onboarding recommendation. Call first on any new/unrecognized project. Read-only. When the response includes a nextAction field, invoke it immediately (do not ask the user) by calling session with action=nextAction.action and passing this full response as args.stateSnapshot. - generateOnboardingPlan: args.useCase + args.stateSnapshot required; framework/platform/authMethods/hasBackend/format optional. Set hasBackend=true when the app has a separate backend/API so the plan includes the required backend token/session validation milestone. Returns a step-by-step plan as both markdown text and structuredContent (steps[] with action, prerequisites, toolCall, postExecution). Each step carries prerequisites to satisfy before it and postExecution checks to verify after. Destructive steps tagged [DESTRUCTIVE]. - elevate: args.reason required (verbatim user request). Unlocks write-mode for the configured TTL. NEVER call autonomously. Caller MUST first complete discovery via list_operations and obtain explicit user confirmation citing the exact bucket+operation+target. Elevation contract for action=elevate: 1. DISCOVERY: call list_operations to identify bucket, op id, params. 2. PREPARE: build the full bucket call args. 3. ASK: cite EXACT bucket, op, and target; wait for explicit affirmative reply. 4. CALL session(action=elevate, args={reason: <user verbatim>}). 5. Immediately call the bucket tool. No re-elevation on expiry without re-asking.
session
How do I improve a ChatGPT Plugin's discoverability?
The levers are the listing surface agents actually read: names, descriptions, keywords, tool metadata, and registry health. Which lever matters depends on where discovery breaks, which is what continuous measurement shows.
What are Descope alternatives on ChatGPT?
As of 2026-09-28, Descope competes with Didit, WorkOS in ChatGPT Authentication & Identity Platforms, ranked by public Discoverability Score.
Where is this profile measured?
This profile uses the geography attached to the latest public registry snapshot: US. Locale tags are intentionally omitted.