Install
npm install @workos-inc/nodeShowcase


Try itExperimental
See what an agent can do with WorkOS before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; the live MCP handshake runs real requests from our edge, right now — including, where the server allows it, one real read-only tool call (bring your own key for auth-gated servers); sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$mcp-probe → https://mcp.workos.com/mcplive — run just now from our edge$ press ▶ run to send one JSON-RPC initialize from our edge
Verified integrations
Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.
By theme — the product's score on each story themeBy theme
Agent auth — stories about agent auth in this arenaAgent authevidence →
Stories about agent auth in this arena
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Deployment control — stories about deployment control in this arenaDeployment controlevidence →
Stories about deployment control in this arena
Enterprise sso — stories about enterprise sso in this arenaEnterprise ssoevidence →
Stories about enterprise sso in this arena
Events webhooks — stories about events webhooks in this arenaEvents webhooksevidence →
Stories about events webhooks in this arena
Framework integration — stories about framework integration in this arenaFramework integrationevidence →
Stories about framework integration in this arena
Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordlessevidence →
Stories about mfa passwordless in this arena
Oauth oidc — stories about oauth oidc in this arenaOauth oidcevidence →
Stories about oauth oidc in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenantevidence →
Stories about orgs multitenant in this arena
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Rbac permissions — stories about rbac permissions in this arenaRbac permissionsevidence →
Stories about rbac permissions in this arena
Session management — stories about session management in this arenaSession managementevidence →
Stories about session management in this arena
User migration — stories about user migration in this arenaUser migrationevidence →
Stories about user migration in this arena
Story verdicts — every judged story with its evidenceStory verdicts
What’s free: 5 free · 3 paid · 0 enterprise · 26 not stated in evidence
Follow the green: where the map greys out is where WorkOS stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agent auth — stories about agent auth in this arenaAgent auth
Stories about agent auth in this arena
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓9/10
unlocks → Machine-readable spec · Versioning policy · API sandbox · Full data export · Require asynchronous human approval (e.g. CIBA-style confirmation) before an autonomous agent completes a sensitive transaction · Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge
Subscribe to events via webhooks
~5/10
Build against official SDKs
✓7/10
Issue scoped/least-privilege API credentials for an agent
~6/10
unlocks → Autonomous automations
Connect an agent via an official MCP server
✓8/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—–
Test against a sandbox environment without touching production data
—–
Explore an interactive API reference with runnable examples
—0/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
—0/10
Operate the product with natural-language commands
~6/10
unlocks → Autonomous automations
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
—0/10
Set up automations that run autonomously in the background
—0/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Deployment control — stories about deployment control in this arenaDeployment control
Stories about deployment control in this arena
Enterprise sso — stories about enterprise sso in this arenaEnterprise sso
Stories about enterprise sso in this arena
Events webhooks — stories about events webhooks in this arenaEvents webhooks
Stories about events webhooks in this arena
Framework integration — stories about framework integration in this arenaFramework integration
Stories about framework integration in this arena
Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless
Stories about mfa passwordless in this arena
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
~6/10
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed
~4/10
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
✓8/10
Oauth oidc — stories about oauth oidc in this arenaOauth oidc
Stories about oauth oidc in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant
Stories about orgs multitenant in this arena
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Rbac permissions — stories about rbac permissions in this arenaRbac permissions
Stories about rbac permissions in this arena
Session management — stories about session management in this arenaSession management
Stories about session management in this arena
User migration — stories about user migration in this arenaUser migration
Stories about user migration in this arena
Sorted by importance (agentic first) (high → low) · 56/56 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 9/10 | Tprobed | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Cclaimed | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Cclaimed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 3/10 | Cclaimed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none | untested | none yet | |
Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-in G Sso | security-engineer | Enterprise sso — stories about enterprise sso in this arenaEnterprise sso | 3 | fullfree | 9/10 | Xcommunity | |
Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks G Rbac | developer | Rbac permissions — stories about rbac permissions in this arenaRbac permissions | 3 | full | 8/10 | Cclaimed | |
Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loop C Machine identity | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | full | 8/10 | Cclaimed | |
Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens C Mcp | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | full | 8/10 | Tprobed | |
Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol details C Flows | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 3 | partial | 6/10 | Cclaimed | |
Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box C Orgs | developer | Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant | 3 | partial | 6/10 | Cclaimed | |
Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials C Machine identity | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | partial | 5/10 | Cclaimed | |
Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority C Delegation | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | partial | 4/10 | Cclaimed | |
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed G Mfa | security-engineer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 3 | partialfree | 4/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | none | 0/10 | ||
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ||
Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge C Frameworks | developer | Framework integration — stories about framework integration in this arenaFramework integration | 3 | none | 0/10 | ||
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ||
Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised session C Sessions | developer | Session management — stories about session management in this arenaSession management | 3 | none | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secrets C Device flow | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 2 | full | 9/10 | Cclaimed | |
Sync users and groups from customer directories via SCIM so deprovisioning in the IdP revokes app access G Sso | security-engineer | Enterprise sso — stories about enterprise sso in this arenaEnterprise sso | 2 | full | 9/10 | Xcommunity | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | full | 8/10 | Tprobed | |
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods G Passwordless | developer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 2 | fullfree | 8/10 | Cclaimed | |
Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code G Flows | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 2 | fullfree | 8/10 | Xcommunity | |
Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app") C Provider | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 2 | full | 8/10 | Cclaimed | |
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages C Frameworks | developer | Framework integration — stories about framework integration in this arenaFramework integration | 2 | fullfree | 7/10 | Xcommunity | |
Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM G Audit | security-engineer | Events webhooks — stories about events webhooks in this arenaEvents webhooks | 2 | partialpaid | 6/10 | Cclaimed | |
Bulk-import existing users — including password hashes — and export them again, so I am never locked in C Migration | developer | User migration — stories about user migration in this arenaUser migration | 2 | partial | 5/10 | Xcommunity | |
Give each customer organization its own SSO connection with verified domains and just-in-time provisioning G Orgs | security-engineer | Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant | 2 | partialpaid | 5/10 | Cclaimed | |
Subscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in sync C Webhooks | developer | Events webhooks — stories about events webhooks in this arenaEvents webhooks | 2 | partial | 5/10 | Cclaimed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 3/10 | Cclaimed | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | 0/10 | ||
Control where the auth system and its user data run — self-managed deployment, private instance, or my own database C Deployment | security-engineer | Deployment control — stories about deployment control in this arenaDeployment control | 2 | none | 0/10 | ||
Require asynchronous human approval (e.g. CIBA-style confirmation) before an autonomous agent completes a sensitive transaction C Delegation | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | n/a | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resets C Migration | founder | User migration — stories about user migration in this arenaUser migration | 1 | partial | 6/10 | Cclaimed | |
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows C Hardening | security-engineer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 1 | partialpaid | 6/10 | Cclaimed | |
Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles C Rbac | security-engineer | Rbac permissions — stories about rbac permissions in this arenaRbac permissions | 1 | partial | 5/10 | Cclaimed | |
Let users and admins see active sessions and devices and revoke them individually or all at once C Sessions | security-engineer | Session management — stories about session management in this arenaSession management | 1 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 36 stories with headroom
What would move WorkOS’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product
nonemoves Built-in AIimpact 45
WorkOS's MCP evidence describes external AI agents connecting to and operating WorkOS via its API/dashboard data (workos-docs-9, workos-docs-44) — this is WorkOS acting as a tool controlled by outside agents, not a built-in assistant inside WorkOS that users delegate tasks to.
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events
nonemoves PA Scoreimpact 30
WorkOS exposes events (Directory Sync updates, Audit Log events) via webhooks/Events API, but there is no evidence of a user-defined rules engine that lets an AI-native user specify conditional triggers and automated actions — it only ships raw event delivery, not rule authoring or automation logic.
Framework integration — stories about framework integration in this arenaProtect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge
nonemoves PA Scoreimpact 30
The evidence pack covers WorkOS's Node SDK, SSO, Directory Sync, RBAC, Audit Logs, Vault, and MCP server, but contains no mention of a Next.js-specific SDK, middleware, or edge-based session verification.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
WorkOS documents only importing data (e.g., migrating FROM Auth0 INTO WorkOS) and offers audit-log export, but there is no documented capability for a user/customer to export all their identity, SSO, directory, RBAC, or vault data in open formats to leave the platform; a community thread explicitly raises this exact lock-in/export concern without any WorkOS response in the evidence pack.
Openness — open source, data portability, and self-hosting storiesSelf-host the core product
nonemoves PA Scoreimpact 30
WorkOS is presented entirely as a hosted SaaS platform with an API/SDK model; there is no evidence of a self-hostable core product, open-source server, or on-prem deployment option.
Session management — stories about session management in this arenaManage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised session
nonemoves PA Scoreimpact 30
WorkOS/AuthKit is an authentication platform where session lifecycle management (expiry, refresh, revocation) would be a natural and expected capability, so the axis applies — but the evidence pack contains no documentation of session expiry policies, token refresh mechanics, or server-side session/token revocation for compromised sessions.
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
Missing: any AI-driven insights/analytics dashboard, evidence of suggestion generation from customer data, or reporting on usage/security patterns via AI.
Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the background
nonemoves Built-in AIimpact 30
Missing: any scheduler/trigger system, evidence of agents running unattended over time, or documented autonomous workflow execution.
Showing the top 8 of 36 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map7 surfaces · 33 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
docs32 stories
- Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority
- Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secrets
- Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loop
- Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials
- Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Use an official CLI
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Subscribe to events via webhooks
- Operate the product with natural-language commands
- Perform bulk operations across many items at once
- Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-in
- Sync users and groups from customer directories via SCIM so deprovisioning in the IdP revokes app access
- Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM
- Subscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in sync
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
- Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
- Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed
- Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
- Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol details
- Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code
- Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")
- Do everything through the API that I can do in the UI
- Give each customer organization its own SSO connection with verified domains and just-in-time provisioning
- Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box
- Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles
- Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks
- Bulk-import existing users — including password hashes — and export them again, so I am never locked in
- Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resets
Hacker News5 stories
- Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-in
- Sync users and groups from customer directories via SCIM so deprovisioning in the IdP revokes app access
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
- Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code
- Bulk-import existing users — including password hashes — and export them again, so I am never locked in
Pricing docs5 stories
- Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
- Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
- Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
- Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code
OpenAPI spec4 stories
GitHub README4 stories
workos.com4 stories
- Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-in
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
- Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
- Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
7 of 21 testable claims verified · 0 contradicted → integrity 33/100
32 distinct capability claims found in WorkOS’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
7
Verified
14
Unverified
0
Contradicted
12
Undersold
Verified (10)
“Works with any identity provider supporting SAML or OIDC protocols”
Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-infullproof ↗
“Directory Sync APIs and admin tools implement enterprise user lifecycle management”
Sync users and groups from customer directories via SCIM so deprovisioning in the IdP revokes app accessfullproof ↗
“AuthKit provides secure authentication for protecting an MCP server”
Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokensfullproof ↗
“Connected agents can read/write dashboard data (orgs, connections, users, branding) via the WorkOS API”
“Connected agents can read/write dashboard data (orgs, connections, users, branding) via the WorkOS API”
Drive the product through a documented public APIfullproof ↗
“Official WorkOS MCP server lets MCP-compatible AI agents act on a WorkOS workspace”
“Customizable hosted UI for authentication at any scale”
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pagesfullproof ↗
“Lets customers connect their third-party accounts to your application (social login)”
Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom codefullproof ↗
“Directory Sync sends automatic updates via webhooks or the Events API, supporting SCIM-based directory providers”
Sync users and groups from customer directories via SCIM so deprovisioning in the IdP revokes app accessfullproof ↗
“Built-in support for acting as an MCP server and OAuth application provider”
Unverified (22)
“Official Node.js SDK installable via npm”
“Define custom roles at org/tenant level, assign permissions, and enforce access policies at scale”
Define roles and permissions and have them enforced and surfaced in session tokens for authorization checksfullproof ↗
“Configure and export Audit Log Events from applications”
Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEMpartialproof ↗
“Migration tool produces a package with users, organizations, memberships, roles, and SSO handoff files”
Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resetspartialproof ↗
“Supports public client initialization with just a client ID for apps that can't store secrets”
Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol detailspartialproof ↗
“Enables self-serve onboarding experience for IT admins setting up SSO”
Give each customer organization its own SSO connection with verified domains and just-in-time provisioningpartialproof ↗
“CLI Auth lets command-line apps authenticate users via OAuth 2.0 Device Authorization Flow”
Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secretsfullproof ↗
“Enroll users in multi-factor authentication for extra security”
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where neededpartialproof ↗
“Protects applications from bots, fraud, and abuse”
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flowspartialproof ↗
“Migrate existing users, organizations, and enterprise SSO connections from Auth0 via export/import”
Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resetspartialproof ↗
“SDK automatically retries transient failures (network errors, timeouts, rate limits, server errors) with exponential backoff and jitter”
“Directory Sync sends automatic updates via webhooks or the Events API, supporting SCIM-based directory providers”
Subscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in syncpartialproof ↗
“Offers log streaming per SIEM connection to export audit logs”
Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEMpartialproof ↗
“AuthKit is a spec-compatible OAuth authorization server”
Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol detailspartialproof ↗
“AuthKit bundles email/password, social login, passkeys, MFA, magic auth, and enterprise SSO in one integration”
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methodsfullproof ↗
“Roles are assigned via API and enforced through session JWTs, with org-scoped roles and IdP role assignment via SSO/Directory Sync”
Define roles and permissions and have them enforced and surfaced in session tokens for authorization checksfullproof ↗
“Built-in support for acting as an MCP server and OAuth application provider”
Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")fullproof ↗
“M2M applications provide programmatic API access credentials to customers/partners”
Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loopfullproof ↗
“Applications can become an OAuth provider with a 'Sign in with your app' button for third parties”
Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")fullproof ↗
“WorkOS CLI includes a migrations tool for exporting Auth0 data”
“WorkOS CLI includes a migrations tool for exporting Auth0 data”
Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resetspartialproof ↗
“Passwordless sign-in via a six-digit code sent by email (magic auth)”
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methodsfullproof ↗
Undersold (12)
Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authoritypartialproof ↗
Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentialspartialproof ↗
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationpartialproof ↗
Issue scoped/least-privilege API credentials for an agentpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Do everything through the API that I can do in the UIfullproof ↗
Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the boxpartialproof ↗
Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple rolespartialproof ↗
Bulk-import existing users — including password hashes — and export them again, so I am never locked inpartialproof ↗
Claims outside our story set (4)
Real capability claims found in WorkOS’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“WorkOS Vault is an encryption key management service for storing tokens, passwords, certificates, and files”
source ↗“Controls rollout of new features in an application (feature flags)”
source ↗“Vault supports bring-your-own-key integration with AWS KMS, Google Cloud KMS, and Azure Key Vault”
source ↗“Can store additional custom metadata about users and organizations”
source ↗
Business model
AuthKit user management is free up to 1M monthly-active users; enterprise features are priced per unit (per SSO or Directory Sync connection per month), with volume/enterprise discounts via sales.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
Agent surface uptime MCP 100% · llms.txt 100% (30d, checked every 6h since Sep 8 '26)
