Enterprise-Managed Authorization
Enterprise-Managed Authorization lets the enterprise identity provider decide which agents may reach which tools, for which users, using Cross App Access (XAA). Without it, every MCP server becomes its own authorization island with its own consent screen, and IT has no single place to answer that question.
Cross App Access (XAA) reuses the SSO trust the enterprise already has. The identity provider that signed the user in also vouches, in a short-lived signed JWT, that this user, through this client, may reach this resource. The client presents that JWT to the resource's authorization server and receives a normal access token in return, with no second login or consent screen.
That JWT is the XAA token, formally an Identity Assertion JWT Authorization Grant (ID-JAG). For the protocol in detail, see How XAA and ID-JAG Work.
Two Sides of XAA
Descope plays a different role depending on whose agents are connecting. When your company's agents reach third-party tools, Descope is the identity provider that issues XAA tokens. When your customers' agents reach an MCP server you host, Descope is the authorization server that accepts their XAA tokens.
Issue XAA Tokens for Your Agents
Let Claude Code, VS Code, and other pre-built clients reach third-party MCP servers that support XAA, governed by your Descope policies.
Accept Your Customers' XAA Tokens
Let each customer govern the agents that reach your MCP server with their own workforce IdP, such as Okta or Entra.
XAA also applies when the client is Claude (or similar) and the MCP server is yours. Descope can then be both issuer and validator. See Governing Agents Internally.
Enterprise-Managed Authorization and Gateways
XAA is one way to govern your company's agents. An MCP gateway is another, and the two work together. You can use XAA without a gateway, with nothing between the agent and the tool, or use XAA with a gateway when you also want controls in the request path. A gateway also covers tools that don't support XAA, by calling them with credentials from Connections.
For help choosing, see Governing Agents Internally.