← Back to all sparks
W

WorkOS

INFRA · APIS
Velocity7.5

WorkOS is building identity infrastructure for the AI agent era, shipping MCP auth and named agent credentials in a single week.

authdevtoolsai-agentsenterpriseidentitymcp
Current state
WorkOS has moved decisively beyond SSO-and-SCIM. The product now covers feature flags with custom targeting, SCIM debugging via dashboard-level log inspection, user groups with role assignment, and OIDC hardening (PKCE, Private Key JWT, pinned token-endpoint methods). The Android SDK rounds out its mobile surface. It is a multi-capability auth platform, not just an enterprise login kit.
Where it's heading
The last two weeks show a clear pivot toward agentic workloads: Agent Auth gives AI agents their own scoped, revocable identities, and MCP Enterprise-Managed Authorization lets identity providers control which agents can reach an MCP server. These are architectural additions that position WorkOS as the auth layer for AI systems, not just human users. Feature flags with custom targeting extend the product further into runtime configuration territory.
Prediction
Expect WorkOS to deepen the agent identity model — likely adding agent-specific audit trails, usage metering per agent identity, and federation between agent credentials and existing enterprise SSO trees. The AuthKit Waitlist API suggests growth-stage SaaS tooling is a secondary expansion surface.

Recent moves

  1. 8d ago

    Feature Flags Custom Targeting

    Feature flags now accept custom targeting rules against arbitrary app resources, moving WorkOS from a user-only flag system into general attribute-based targeting. This expands the product's footprint from auth into runtime configuration management, a logical adjacency for a platform that already controls user and group data.

  2. 12d ago

    Dashboard SCIM Logs

    Dashboard-level SCIM log inspection with full request/response payloads reduces the operational friction of debugging provisioning failures, previously requiring vendor support or raw log access. This is table-stakes for WorkOS customers with complex IDP configurations, and signals a push toward self-service enterprise operations.

  3. 12d ago

    WorkOS adds IDP-managed access control for MCP servers

    ⚡ SPARK

    MCP Enterprise-Managed Authorization puts IDP-controlled access gates on MCP servers, meaning enterprises can use existing identity policies to govern which AI agents reach which tools. This arrives alongside Agent Auth, showing WorkOS is building a coherent auth stack for AI systems rather than shipping isolated features.

  4. 14d ago

    Agent Auth

    ⚡ SPARK

    Agent Auth is a direct response to the agentic AI moment: instead of having AI agents run under a human user's credentials (insecure) or a shared service account (unauditable), they get their own scoped identities. This is the most directional WorkOS release in recent memory and extends the platform's addressable market to every team deploying AI agents in enterprise contexts.

  5. 14d ago

    Expanded Audit Log retention periods

    Extending audit log retention to 10 years is a compliance requirement for regulated industries (finance, healthcare) that previously had to export and store logs externally. This lowers the barrier for WorkOS adoption in sectors with long data retention mandates and is a direct competitive response to enterprise procurement checklist requirements.

  6. 19d ago

    Waitlist API and self-serve setup

    The Waitlist API and dashboard-configurable AuthKit Waitlist turns a previously manual process into a self-serve flow with API access, enabling products to build waitlist-gated launch mechanics without leaving the WorkOS ecosystem. This is a small feature with outsized appeal for growth-stage B2B products using WorkOS from day one.