Descope Unveils Cross-App Access (XAA) Support, Letting Enterprises Manage AI Agent Access With Their Existing Identity Providers
Organizations can now use Descope to validate ID-JAG tokens from their customers' identity providers, issue ID-JAG
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
LOS ALTOS, Calif., Sept. 01, 2026 (GLOBE NEWSWIRE) — Descope, a leading customer and agentic identity platform, today announced Cross-App Access (XAA) support in its Agentic Identity Hub, giving organizations a way to let every enterprise customer govern AI agent access through the identity provider (IdP) they already trust. Descope is among the first identity providers to support both:
- ID-JAG token validation, enabling SSO-like login for any AI agent accessing Descope customers’ MCP servers
- ID-JAG token issuance, enabling SSO-like login for Descope customers’ AI agents accessing any MCP server
AI agents are becoming the primary consumers of enterprise APIs, and B2B companies are building MCP servers so those agents can reach intended services and data. However, many MCP servers use identity anti-patterns that were not designed for autonomous agents.
- Static API keys sit in configuration files and environment variables with no expiration and no tool-level scoping.
- Agents borrow the signed-in user’s session and inherit every permission that user holds, which greatly increases the blast radius of a single compromised agent.
- Authorization is applied at the application level rather than per user, per tenant, per agent, or per tool, leaving agents over-permissioned by default.
2026 research from Gravitee found that only 22% of teams treat agents as independent identities, with most relying on shared API keys.
Cross-App Access is an open protocol built to standardize how AI agents receive access to another application’s APIs or MCP server. Built on the Identity Assertion JWT Authorization Grant and adopted as the Enterprise-Managed Authorization extension to the Model Context Protocol, it replaces static API keys and repeated consent screens with short-lived assertions minted by the identity provider both applications already trust. An agent signed in to one application reaches another application’s API or MCP server with no second login.
“Every B2B company shipping an MCP server is about to hear the same question from its enterprise customers: can we govern agent access to this MCP server with our own identity provider?” said Rishi Bhargava, Co-Founder of Descope. “Descope’s Cross-App Access support helps customers deploy enterprise-ready MCP servers that can validate assertions coming in from their customers’ identity providers and even let tenant admins configure XAA support entirely on their own. This is a huge unlock for any business that has high hopes for their Claude connector or ChatGPT plugin.”
New Cross-App Access capabilities in the Agentic Identity Hub include:
- ID-JAG validation, which helps B2B companies let their enterprise customers govern agent access through the identity provider they already trust. Organizations can register a trusted issuer for each tenant, accept assertions from Okta, Ping, and other standards-compliant providers, and validate a standard access token at the MCP server without implementing the protocol themselves.
- ID-JAG issuance, which makes Descope the identity provider for the AI agents an organization runs internally. Security teams can grant those agents scoped, short-lived access to any MCP server / API, with policies evaluated on every request instead of being baked into a long-lived credential.
- Self-service XAA setup, which adds Cross-App Access to Descope’s SSO Setup Suite alongside SSO, SCIM, and JIT provisioning. Tenant admins can choose their identity provider, establish trusted issuers, register their AI agents, and map user attributes through a guided flow without any support ticket or manual back-and-forth.
- Per-organization scope policies, which let companies grant different levels of agent access to different enterprise customers on the same MCP server. Policies can be created based on user roles, tenant membership, and claims carried over from the customer’s identity provider.
- Standards-based token exchange, which builds on the OAuth 2.1, DCR, CIMD, and consent management support already in the Agentic Identity Hub. Cross-App Access follows the Enterprise-Managed Authorization extension to MCP, using OAuth 2.0 Token Exchange to mint assertions and the JWT Bearer grant to redeem them.
Cross-App Access support builds on the Descope Agentic Identity Hub, which handles authentication and access control for hundreds of MCP servers and millions of monthly agentic transactions. Descope, a member of the Agentic AI Foundation (AAIF), was named a Leader in the 2025 Frost Radar for Non-Human Identity Solutions, where Frost & Sullivan analyst Dolores Aleman described Descope as “one of the first vendors to treat AI agents as a first-class identity type.”
Learn more about Descope’s support for Cross-App Access in this blog.
About Descope
Descope is a no / low code customer and agentic identity platform that helps organizations easily create and modify authentication and authorization journeys for customers, partners, AI agents, and MCP servers. Thousands of organizations use Descope to improve customer experience, prevent account takeover, and securely adopt agentic AI and MCP with identity controls built-in.
Media Contact
Christine Penwell
Offleash for Descope
descope@offleashpr.com

