# Descope Documentation - Introduction - [Overview](/): Explore our developer docs to integrate Descope authentication and user management into your app. Get started with no-code workflows, SDKs, or APIs. - [Tutorials](/tutorials): Tutorial on how to use Descope to implement authentication methods, handle multi-tenancy, authorization, and customize flows. - [Learn the Lingo](/lingo): Explore a glossary of acronyms, concepts, and market terms from the world of identity and authentication. - Getting Started - [Getting Started](/getting-started): Quickstart guide on how to implement Descope Flows and authentication methods. - **Fullstack** - Next.js - [Next.js](/getting-started/nextjs/index): Learn how to integrate Descope with Next.js in your application. - [Protecting Routes with Middleware](/getting-started/nextjs/next-middleware): Learn how to protect specific pages and API routes in Next.js using Descope middleware. - [Reading Session and User Data](/getting-started/nextjs/user-and-session-data): Learn how to read session and user data using the Descope Next.js SDK. - [SSR Considerations](/getting-started/nextjs/ssr-considerations): Understand server-side rendering considerations when using Descope with Next.js. - [OIDC Client Login](/getting-started/nextjs/nextjs-oidc): Learn how to integrate Descope with Next.js in your application, using OIDC and our SDK. - [SvelteKit](/getting-started/sveltekit): Learn to integrate Descope with SvelteKit in your application. - **Web** - React - [React](/getting-started/react): Get started with React in minutes with Descope. - **Backend** - [Python](/getting-started/react/python): Learn how to integrate Descope with your React & Python in your application. - [Go](/getting-started/react/go): Learn how to integrate Descope with your React & Go in your application. - [Node.js](/getting-started/react/nodejs): Learn how to integrate Descope with your React & Node.js in your application. - [Java](/getting-started/react/java): Learn how to integrate Descope with your React & Java in your application. - [Ruby](/getting-started/react/ruby): Learn how to integrate Descope with your React & Ruby in your application. - [Django](/getting-started/react/django): Learn how to integrate Descope with your React & Django in your application. - [PHP](/getting-started/react/php): Learn how to integrate Descope with your React & PHP in your application. - [OIDC Client Login](/getting-started/react/react-oidc): Learn how to integrate Descope with a React application, using OIDC and our React SDK. - [TanStack Router](/getting-started/tanstack-router): Add Descope authentication to a client-side TanStack Router application using the Descope React SDK. - Vue.js - [Vue.js](/getting-started/vue.js): Get started with Vue.js in minutes with Descope. - **Backend** - [Python](/getting-started/vue.js/python): Learn how to integrate Descope with your Vue.js & Python in your application. - [Go](/getting-started/vue.js/go): Learn how to integrate Descope with your Vue.js & Go in your application. - [Node.js](/getting-started/vue.js/nodejs): Learn how to integrate Descope with your Vue.js & Node.js in your application. - [Java](/getting-started/vue.js/java): Learn how to integrate Descope with your Vue.js & Java in your application. - [Ruby](/getting-started/vue.js/ruby): Learn how to integrate Descope with your Vue.js & Ruby in your application. - [Django](/getting-started/vue.js/django): Learn how to integrate Descope with your Vue.js & Django in your application. - [PHP](/getting-started/vue.js/php): Learn how to integrate Descope with your Vue.js & PHP in your application. - HTML - [HTML](/getting-started/html): Get started with HTML in minutes with Descope. - **Backend** - [Python](/getting-started/html/python): Learn how to integrate Descope with your HTML & Python in your application. - [Go](/getting-started/html/go): Learn how to integrate Descope with your HTML & Go in your application. - [Node.js](/getting-started/html/nodejs): Learn how to integrate Descope with your HTML & Node.js in your application. - [Java](/getting-started/html/java): Learn how to integrate Descope with your HTML & Java in your application. - [Ruby](/getting-started/html/ruby): Learn how to integrate Descope with your HTML & Ruby in your application. - [Django](/getting-started/html/django): Learn how to integrate Descope with your HTML & Django in your application. - [PHP](/getting-started/html/php): Learn how to integrate Descope with your HTML & PHP in your application. - [OIDC Client Login](/getting-started/html/html-oidc): Learn how to integrate Descope with any frontend application using WebJS and OIDC. - Angular - [Angular](/getting-started/angular): Get started with Angular in minutes with Descope. - [Python](/getting-started/angular/python): Learn how to integrate Descope with your Angular & Python in your application. - [Go](/getting-started/angular/go): Learn how to integrate Descope with your Angular & Go in your application. - [Node.js](/getting-started/angular/nodejs): Learn how to integrate Descope with your Angular & Node.js in your application. - [Java](/getting-started/angular/java): Learn how to integrate Descope with your Angular & Java in your application. - [Ruby](/getting-started/angular/ruby): Learn how to integrate Descope with your Angular & Ruby in your application. - [Django](/getting-started/angular/django): Learn how to integrate Descope with your Angular & Django in your application. - [PHP](/getting-started/angular/php): Learn how to integrate Descope with your Angular & PHP in your application. - **Mobile** - Swift - [Swift](/getting-started/swift): Get started with Swift in minutes with Descope. - **Backend** - [Python](/getting-started/swift/python): Learn how to integrate Descope with your Swift & Python in your application. - [Go](/getting-started/swift/go): Learn how to integrate Descope with your Swift & Go in your application. - [Node.js](/getting-started/swift/nodejs): Learn how to integrate Descope with your Swift & Node.js in your application. - [Java](/getting-started/swift/java): Learn how to integrate Descope with your Swift & Java in your application. - [Ruby](/getting-started/swift/ruby): Learn how to integrate Descope with your Swift & Ruby in your application. - [Django](/getting-started/swift/django): Learn how to integrate Descope with your Swift & Django in your application. - [PHP](/getting-started/swift/php): Learn how to integrate Descope with your Swift & PHP in your application. - Kotlin - [Kotlin](/getting-started/kotlin): Get started with Kotlin in minutes with Descope. - **Backend** - [Python](/getting-started/kotlin/python): Learn how to integrate Descope with your Kotlin & Python in your application. - [Go](/getting-started/kotlin/go): Learn how to integrate Descope with your Kotlin & Go in your application. - [Node.js](/getting-started/kotlin/nodejs): Learn how to integrate Descope with your Kotlin & Node.js in your application. - [Java](/getting-started/kotlin/java): Learn how to integrate Descope with your Kotlin & Java in your application. - [Ruby](/getting-started/kotlin/ruby): Learn how to integrate Descope with your Kotlin & Ruby in your application. - [Django](/getting-started/kotlin/django): Learn how to integrate Descope with your Kotlin & Django in your application. - [PHP](/getting-started/kotlin/php): Learn how to integrate Descope with your Kotlin & PHP in your application. - React Native - [React Native](/getting-started/react-native): Get started with React Native in minutes with Descope. - **Backend** - [Python](/getting-started/react-native/python): Learn how to integrate Descope with your React Native & Python in your application. - [Go](/getting-started/react-native/go): Learn how to integrate Descope with your React Native & Go in your application. - [Node.js](/getting-started/react-native/nodejs): Learn how to integrate Descope with your React Native & Node.js in your application. - [Java](/getting-started/react-native/java): Learn how to integrate Descope with your React Native & Java in your application. - [Ruby](/getting-started/react-native/ruby): Learn how to integrate Descope with your React Native & Ruby in your application. - [Django](/getting-started/react-native/django): Learn how to integrate Descope with your React Native & Django in your application. - [PHP](/getting-started/react-native/php): Learn how to integrate Descope with your React Native & PHP in your application. - Flutter - [Flutter](/getting-started/flutter): Get started with Flutter in minutes with Descope. - [Python](/getting-started/flutter/python): Learn how to integrate Descope with your Flutter & Python in your application. - [Go](/getting-started/flutter/go): Learn how to integrate Descope with your Flutter & Go in your application. - [Node.js](/getting-started/flutter/nodejs): Learn how to integrate Descope with your Flutter & Node.js in your application. - [Java](/getting-started/flutter/java): Learn how to integrate Descope with your Flutter & Java in your application. - [Ruby](/getting-started/flutter/ruby): Learn how to integrate Descope with your Flutter & Ruby in your application. - [Django](/getting-started/flutter/django): Learn how to integrate Descope with your Flutter & Django in your application. - [PHP](/getting-started/flutter/php): Learn how to integrate Descope with your Flutter & PHP in your application. - **Backend** - [Python](/getting-started/python): Learn how to integrate Descope's Python SDK in your backend application. - [Go](/getting-started/go): Learn how to integrate Descope's Go SDK in your backend application. - [Node.js](/getting-started/nodejs): Learn how to integrate Descope's Node.js SDK in your backend application. - [Java](/getting-started/java): Learn how to integrate Descope's Java SDK in your backend application. - [Django](/getting-started/django): Learn how to integrate Descope's Python SDK in your Django application. - [Ruby](/getting-started/ruby): Learn how to integrate Descope's Ruby SDK in your backend application. - PHP - [PHP](/getting-started/php): Learn how to integrate Descope's PHP SDK in your backend application. - [Custom Caching](/getting-started/php/custom-caching): Learn how to implement a custom caching mechanism to store frequently accessed data. - [.NET](/getting-started/dotnet): Learn how to integrate Descope's DotNet SDK in your backend application. - **Libraries** - NextAuth - [NextAuth](/getting-started/nextauth): Get started with NextAuth in minutes with Descope. - [App Router](/getting-started/nextauth/app-router): Learn to integrate Descope with NextAuth App Router for efficient authentication routing. - [Pages Router](/getting-started/nextauth/pages-router): Discover how to set up Descope with NextAuth Pages Router for secure and efficient authentication. - [Built-in Functions](/getting-started/nextauth/functions): Explore using NextAuth functions with Descope for seamless application authentication. - [Next.js vs NextAuth with Descope](/getting-started/nextauth/nextauth-vs-native): A comparison of integrating Descope with Next.js natively vs. integrating with NextAuth - **Generic** - [OIDC Endpoints](/getting-started/oidc-endpoints): Get started with Descope's OIDC endpoints using Descope as an OIDC provider. - Web Development Platforms - [Web Development Platforms](/getting-started/web-development-platforms): Detailed walkthroughs on how to integrate Descope's authentication solutions across popular website builders like Webflow, Squarespace, etc. - [Bubble](/getting-started/web-development-platforms/bubble): If you're using Bubble to develop your web applications, this tutorial will walk you through how to integrate Descope into your Bubble site. - [FlutterFlow](/getting-started/web-development-platforms/flutterflow): If you're using FlutterFlow to develop your web applications, this tutorial will walk you through how to use Descope for your in app authentication. - [Framer](/getting-started/web-development-platforms/framer): If you're using Framer to develop your web applications, this tutorial will walk you through how to integrate Descope into your Framer site. - [Squarespace](/getting-started/web-development-platforms/squarespace): This guide will show you how to integrate Descope into your Squarespace website seamlessly. - [Webflow](/getting-started/web-development-platforms/webflow): If you're using Webflow to design and build your web applications, this tutorial will walk you through how to integrate Descope into your Webflow website. - [WeWeb](/getting-started/web-development-platforms/weweb): If you're using WeWeb to design and build your web applications, this tutorial will walk you through how to integrate Descope into your WeWeb website. - [WordPress](/getting-started/web-development-platforms/wordpress): If you're using WordPress to develop your web applications, this tutorial will walk you through how to integrate Descope into your WordPress site. - [Shopify](/getting-started/web-development-platforms/shopify): If you're using Shopify Plus to develop your web applications, this tutorial will walk you through how to integrate Descope into your Shopify Plus site. - Guides and Tutorials - AI Assistants - [AI Assistants](/ai-assistants): Connect Descope to Cursor, Claude Code, VS Code, and other AI assistants. - [Descope Skills](/ai-assistants/skills): Install official Descope Skills for Cursor, Claude Code, and other AI agents. - Business to Business (B2B) - [Business to Business (B2B)](/b2b): How Descope models B2B apps with tenants, SSO, Admin Portal, SCIM, RBAC, and tenant-level branding. - [A Primer on B2B Authentication Blog](https://www.descope.com/blog/post/b2b-authentication-overview) - Single Sign-On (SSO) - [Multiple SSO Providers Per Tenant](/sso/multi-sso): Configure more than one SAML or OIDC IdP on a single Descope tenant, route users by domain or ssoId, and manage Setup Suite and SCIM per connection. - [Just-in-Time (JIT) Provisioning](/sso/jit-provisioning): Enable or disable SSO JIT provisioning in Descope, understand how it creates and updates users on login, and when to use SCIM instead. - [SSO User and Group Mapping](/sso/sso-mapping): Map IdP attributes and groups to Descope users, RBAC roles, and FGA relations for SAML and OIDC SSO. - [SSO Login Flows](/sso/idp-initiated): SP-initiated and IdP-initiated SSO login flows in Descope, and how to configure IdP-initiated SSO. - [Risks in Merging SSO and Non-SSO Identities](/sso/merging-sso-identities-risk): Learn about the risks of merging SSO users with non-SSO identities, including security implications and best practices for identity management. - [SSO Setup Suite RBAC](/sso/sso-setup-suite-rbac): Learn how to configure SSO Setup Suite RBAC. - [Embedding SSO Setup Suite](/sso/sso-setup-suite-embed): Learn how to embed the SSO Setup Suite directly in your application. - [SSO and SCIM Tutorials](/sso/tutorials): Video walkthroughs of the SSO Setup Suite, SCIM, and IdP-initiated login with Descope. - MFA and Step-Up - MFA (Multi-factor Authentication) - [Overview](/mfa-and-step-up/mfa): Add layered security to your app utilizing Multi-factor Authentication (MFA). - With SDKs - [Client SDKs](/mfa-and-step-up/mfa/mfa-with-sdks/client-sdk): Add layered security to your app utilizing Multi-factor Authentication (MFA) via Descope Client SDKs. - [Backend SDKs](/mfa-and-step-up/mfa/mfa-with-sdks/backend-sdk): Add layered security to your app utilizing Multi-factor Authentication (MFA) via Descope Backend SDKs. - [Adaptive MFA](/mfa-and-step-up/mfa/adaptive-mfa): Learn how to implement adaptive MFA within your Descope flows. This guide has examples of trusted device, IP reputation, and impossible traveler adaptive MFA. - [Step-up Authentication](/mfa-and-step-up/step-up): Add layered security to your app utilizing Step-up authentication. - Fingerprinting - [Fingerprinting](/fingerprinting): This guide explains the fingerprinting capabilities available in Descope, including device fingerprinting, risk-based authentication, and bot detection. - EHR & Healthcare App Integrations - [Backend EHR Integrations](/healthcare/ehr-integrations): How to integrate Descope with Epic and other EHR systems using SMART Backend Services - [SMART on FHIR](/healthcare/smart-fhir): How to integrate Descope as an OAuth provider for SMART on FHIR applications, supporting both EHR Launch and Standalone Launch flows. - Model Context Protocol (MCP) - [Model Context Protocol (MCP)](/mcp): Learn how to use Descope to secure and authorize Model Context Protocol (MCP) servers with inbound, outbound, and SDK-based flows. - Server Examples - [Server Examples](/mcp/examples): Step-by-step examples for building secure MCP servers with Descope. - [Calendar MCP Server (w/ SSO)](/mcp/examples/multi-tenant-calendar): Learn how to build a secure calendar MCP server with SSO authentication, permission-based scopes, and multi-tenant support. - [Multi-Tenant MCP Server](/mcp/examples/b2b-mcp-server): Build one tenant-agnostic MCP server whose per-tenant toolset is driven by the token's scopes, so adding a tenant needs no redeploy. - SDKs - [MCP SDKs](/mcp/sdks): Server-side SDKs that add Descope authentication and authorization to your MCP server, in Express and Python. - [Express MCP SDK](/mcp/sdks/express): Add Descope authentication to your Express MCP server with drop-in middleware, per-tool scopes, and the required OAuth metadata endpoints. - [Python MCP SDK](/mcp/sdks/python): Learn how to use the Descope Python MCP SDK to integrate authentication, authorization, and connection token retrieval with your MCP servers. - MCP Gateways - [Gateways](/mcp/gateways): Learn how to model MCP servers, connections, and policies in Descope when building an MCP gateway for multiple customers or tenants. - [Golf.dev](/mcp/gateways/golf-dev): Use Descope as the identity and authorization layer for MCP servers, with Golf.dev Gateway enforcing access policies at runtime. - [Portkey](/mcp/gateways/portkey): Use Descope as the identity provider for Portkey's MCP Gateway with External OAuth, and forward validated claims to downstream MCP servers. - Integrations - [Skyflow Integration](/mcp/integrations/skyflow): Learn how to integrate Skyflow with Descope MCP servers to securely exchange tokens and access PII data based on user roles. - [Descope MCP Server](/mcp/mcp-server): Use the Descope MCP Server to manage your Descope project and search documentation from any MCP-compatible AI agent. - [Bring Your Own Auth](/mcp/bring-your-own-auth): Use your existing auth system with Descope to protect an MCP server. - [Calling External APIs from MCP Tools](/mcp/calling-apis-from-mcp): Learn how to configure your MCP server to exchange inbound tokens for downstream credentials using Descope STS. - SSO Integrations - [SSO Integrations](/sso-integrations): Learn about the SSO integrations that Descope offers, including Applications, Tenants / Custom Providers, and Descope as an Identity Federation Broker. - [IdP vs SP](/sso-integrations/idp-vs-sp): Learn about the relationship between identity providers and service providers, in the context of Descope. - Authentication - [Authentication](/auth-methods): Learn how to easily implement secure authentication flows and methods in your application with Descope. - One-Time Password (OTP) - [One-time Password (OTP)](/auth-methods/otp): Customize your one-time password (OTP) authentication flow with Descope. - SDKs - [Client SDKs](/auth-methods/otp/with-sdks/client): Add one-time password (OTP) authentication to your application using Descope Client SDKs. Read the detailed implementation guide with sample code. - [Mobile SDKs](/auth-methods/otp/with-sdks/mobile): Add one-time password (OTP) authentication to your application using Descope Mobile SDKs. Read the detailed implementation guide with sample code. - [Backend SDKs](/auth-methods/otp/with-sdks/backend): Add one-time password (OTP) authentication to your application using Descope Backend SDKs. Read the detailed implementation guide with sample code. - [Settings](/auth-methods/otp/settings): Customize your one-time password (OTP) authentication settings with Descope. - Magic Link - [Magic Link](/auth-methods/magic-link): Customize your magic link authentication flow with Descope. - SDKs - [Client SDKs](/auth-methods/magic-link/with-sdks/client): Add magic link authentication to your application using Descope Client SDKs. Read the detailed implementation guide with sample code. - [Mobile SDKs](/auth-methods/magic-link/with-sdks/mobile): Add magic link authentication to your application using Descope Mobile SDKs. Read the detailed implementation guide with sample code. - [Backend SDKs](/auth-methods/magic-link/with-sdks/backend): Add magic link authentication to your application using Descope Backend SDKs. Read the detailed implementation guide with sample code. - [Settings](/auth-methods/magic-link/settings): Customize your Magic Link authentication settings with Descope. - Enchanted Link - [Enchanted Link](/auth-methods/enchanted-link): Customize your enchanted link authentication flow with Descope. - SDKs - [Client SDKs](/auth-methods/enchanted-link/with-sdks/client): Add enchanted link authentication to your application using Descope Client SDKs. Read the detailed implementation guide with sample code. - [Mobile SDKs](/auth-methods/enchanted-link/with-sdks/mobile): Add enchanted link authentication to your application using Descope Mobile SDKs. Read the detailed implementation guide with sample code. - [Backend SDKs](/auth-methods/enchanted-link/with-sdks/backend): Add enchanted link authentication to your application using Descope Backend SDKs. Read the detailed implementation guide with sample code. - [Settings](/auth-methods/enchanted-link/settings): Customize your enchanted link authentication settings with Descope. - Social Login (OAuth) - [Social Login (OAuth)](/auth-methods/oauth): Customize your OAuth social login flows with Descope. - SDKs - [Client SDKs](/auth-methods/oauth/with-sdks/client): Add OAuth social logins to your application using Descope Client SDKs. Read the detailed implementation guide with sample code. - [Mobile SDKs](/auth-methods/oauth/with-sdks/mobile): Add OAuth social logins to your application using Descope Mobile SDKs. Read the detailed implementation guide with sample code. - [Backend SDKs](/auth-methods/oauth/with-sdks/backend): Add OAuth social logins to your application using Descope Backend SDKs. Read the detailed implementation guide with sample code. - [Settings](/auth-methods/oauth/settings): Customize your social login (OAuth) authentication settings with Descope. - [Google One Tap](/auth-methods/oauth/google-one-tap): Learn how to add Google One Tap authentication to your application using Descope SDKs and visual workflows. - Use Cases - [OAuth Scopes and Provider Tokens](/auth-methods/oauth/customize/custom-scopes): This guide covers the implementation of customized OAuth scopes and utilizing the provider's access token within Descope. - [Enforce OAuth Login for Google Emails](/auth-methods/oauth/customize/force-oauth-google): Learn how to force OAuth for specific users based on their email domain, such as Google, within Descope flows. - [Utilizing A User Picture from OAuth Provider](/auth-methods/oauth/customize/picture-oauth-login): Learn how to use the picture attribute from a successful OAuth login response to display a user's profile picture in your web application. - [Unsupported WebView for OAuth](/auth-methods/oauth/customize/unsupported-webview-oauth): Learn how to handle any disallowed useragent error coming from providers like Google using Descope Flows. - [Handling OAuth Providers With Unverified Emails](/auth-methods/oauth/customize/handle-oauth-provider-unverified-emails): Learn how to handle Social Authentication Provider That Provide Unverified Emails - Configuring OAuth Providers - [Configuring OAuth Providers](/auth-methods/oauth/providers): Learn how to configure default and custom OAuth providers with Descope for your application's social login. - Custom Providers - [Custom Providers](/auth-methods/oauth/providers/custom-providers): Overview for all the custom social login pages that we support - [Ethereum Wallet](/auth-methods/oauth/providers/custom-providers/ethereum-wallet): This guide covers the implementation of adding a custom Ethereum Wallet (social login) provider within Descope. - [KakaoTalk](/auth-methods/oauth/providers/custom-providers/kakaotalk): This guide covers the implementation of adding a custom KakaoTalk OAuth (social login) provider within Descope. - [LINE](/auth-methods/oauth/providers/custom-providers/line): This guide outlines the process for configuring a connection to LINE as a custom OAuth provider within Descope. - [Login.gov](/auth-methods/oauth/providers/custom-providers/logingov): This guide outlines the process for configuring a connection to Login.gov as a custom OAuth provider within Descope. - [Spotify](/auth-methods/oauth/providers/custom-providers/spotify): This guide covers the implementation of adding a custom Spotify OAuth (social login) provider within Descope. - [TikTok](/auth-methods/oauth/providers/custom-providers/tiktok): This guide covers the implementation of adding a custom TikTok OAuth (social login) provider within Descope. - Default Providers - [Apple](/auth-methods/oauth/providers/setting-up-your-own-apps/apple): This guide covers how to create a custom Apple login and integrate it within Descope. - [Facebook](/auth-methods/oauth/providers/setting-up-your-own-apps/facebook): Learn to integrate Descope flows by adding a Facebook Social Login. This guide covers creating and configuring a custom app to display your website's domain. - [GitHub](/auth-methods/oauth/providers/setting-up-your-own-apps/github): Learn how to integrate GitHub as a custom OAuth provider in Descope, with specific guides for both OAuth Apps and GitHub Apps. - [Google](/auth-methods/oauth/providers/setting-up-your-own-apps/google): When integrating Descope flows in a website, often you'll want to allow Social Login with Google as one of the authentication methods for your users. - [Microsoft](/auth-methods/oauth/providers/setting-up-your-own-apps/microsoft): When integrating Descope flows, often you'll want to allow Social Login with Microsoft as one of the authentication methods for your users. - Single Sign-On (SSO) - [SSO (Single Sign-on) Authentication](/auth-methods/sso): Customize your SSO (Single Sign-On) authentication flow with Descope. - [Getting Started](/auth-methods/sso/getting-started): Add SSO to your app with the Descope backend SDK, then connect each customer's IdP with the SSO Setup Suite. - [Flows](/auth-methods/sso/with-flows): Learn about how to utilize SSO based authentication in Flows. - SDKs - [Backend SDKs](/auth-methods/sso/with-sdks/backend): Add single sign-on (SSO) to your application using Descope Backend SDKs. Read the detailed implementation guide with sample code. - [Client SDK](/auth-methods/sso/with-sdks/client): Add single sign-on (SSO) to your application using Descope Client SDKs. Read the detailed implementation guide with sample code. - [Mobile SDKs](/auth-methods/sso/with-sdks/mobile): Add single sign-on (SSO) to your application using Descope Mobile SDKs. Read the detailed implementation guide with sample code. - [SSO Setup Suite](/auth-methods/sso/sso-setup-suite): Streamline SSO configuration with Descope's SSO Setup Suite. Enable self-service IdP setup, SCIM provisioning, and seamless integration for your B2B customers. - [Project-Level Settings](/auth-methods/sso/settings): Customize your single sign-on (SSO) authentication settings with Descope. - [Go-Live Checklist](/auth-methods/sso/launch-checklist): A checklist to run through before enabling SSO for real customers in production with Descope. - Manual Configuration - [SSO with OIDC](/auth-methods/sso/oidc): SSO (Single Sign-on) with OIDC Provider Configuration - [SSO with SAML](/auth-methods/sso/saml): SSO (Single Sign-on) with SAML Provider Configuration - Passkeys - [Passkeys (WebAuthn)](/auth-methods/passkeys): Customize your WebAuthn authentication flows ( \ biometrics \ passkeys) with Descope. - SDKs - [Client SDKs](/auth-methods/passkeys/with-sdks/client): Add WebAuthn \ biometrics \ passkeys to your application using Descope Client SDKs. Read the detailed implementation guide with sample code. - [Mobile SDKs](/auth-methods/passkeys/with-sdks/mobile): Add WebAuthn \ biometrics \ passkeys to your application using Descope mobile SDKs. Read the detailed implementation guide with sample code. - [Backend SDKs](/auth-methods/passkeys/with-sdks/backend): Add WebAuthn biometrics to your application using Descope Backend SDKs. Read the detailed implementation guide with sample code. - [Settings](/auth-methods/passkeys/settings): Customize your passkeys authentication settings with Descope. - [Developer's Guide to Passkeys](https://www.descope.com/blog/post/developer-guide-passkeys) - Authenticator Apps (TOTP) - [Authenticator Apps (TOTP)](/auth-methods/auth-apps): Customize your authentication applications (TOTP) with Descope. - SDKs - [Client SDKs](/auth-methods/auth-apps/with-sdks/client): Add TOTP authenticator apps to your application using Descope Client SDKs. Read the detailed implementation guide with sample code. - [Mobile SDKs](/auth-methods/auth-apps/with-sdks/mobile): Add TOTP authenticator apps to your application using Descope Mobile SDKs. Read the detailed implementation guide with sample code. - [Backend SDKs](/auth-methods/auth-apps/with-sdks/backend): Add TOTP authenticator apps to your application using Descope Backend SDKs. Read the detailed implementation guide with sample code. - [Settings](/auth-methods/auth-apps/settings): Customize your authenticator apps (totp) authentication settings with Descope. - Passwords - [Passwords](/auth-methods/passwords): Customize your password authentication flow with Descope. - SDKs - [Client SDKs](/auth-methods/passwords/with-sdks/client): Add password authentication to your application using Descope Client SDKs. Read the detailed implementation guide with sample code. - [Mobile SDKs](/auth-methods/passwords/with-sdks/mobile): Add password authentication to your application using Descope Mobile SDKs. Read the detailed implementation guide with sample code. - [Backend SDKs](/auth-methods/passwords/with-sdks/backend): Add password authentication to your application using Descope Backend SDKs. Read the detailed implementation guide with sample code. - [Settings](/auth-methods/passwords/settings): Customize your password authentication settings with Descope. - nOTP (WhatsApp) - [nOTP Authentication](/auth-methods/notp): nOTP authentication flow with Descope. - SDKs - [Client SDKs](/auth-methods/notp/with-sdks/client): Add nOTP login to your application using Descope Client SDKs. Read the detailed implementation guide with sample code. - [Backend SDKs](/auth-methods/notp/with-sdks/backend): Add nOTP login to your application using Descope Backend SDKs. Read the detailed implementation guide with sample code. - [Settings](/auth-methods/notp/settings): Customize your nOTP (WhatsApp) authentication settings with Descope. - Embedded Link - [Embedded Link](/auth-methods/embedded-link): Customize your embedded link authentication flow with Descope. - SDKs - [Backend SDKs](/auth-methods/embedded-link/with-sdks/backend): Add embedded link authentication to your application using Descope Backend SDKs. Read the detailed implementation guide with sample code. - [Settings](/auth-methods/embedded-link/settings): Customize your embedded link authentication settings with Descope. - Security Questions - [Security Questions](/auth-methods/security-questions): Customize your security questions mfa flow with Descope. - [Settings](/auth-methods/security-questions/settings): Customize your security questions authentication settings with Descope. - Recovery Codes - [Recovery Codes](/auth-methods/recovery-codes): Recovery codes with Descope. - [Settings](/auth-methods/recovery-codes/settings): Customize your recovery codes settings with Descope. - Push Authentication - [Push Authentication](/auth-methods/push): Add push notification authentication to your mobile app using the Descope mobile SDKs. Includes console setup, connector configuration, and sample code. - [Settings](/auth-methods/push/settings): Configure push authentication and its APNs and FCM connectors with Descope. - Device Authentication - [Device Authentication](/auth-methods/device-auth): Create OAuth Device Authentication flow with Descope for smart TVs, IoT devices, and other input-constrained devices. - [Settings](/auth-methods/device-auth/settings): Customize your device authentication settings with Descope. - Authorization - [Authorization](/authorization): Learn how to easily implement authorization via RBAC and Fine-Grained Authorization (FGA) within the backend of your app with Descope. - Role-Based Access Control (RBAC) - [Role-Based Access Control (RBAC)](/authorization/role-based-access-control): Learn how to assign roles and permissions to the application's end users and configure user roles with Descope. - Examples - [B2B RBAC Example](/authorization/role-based-access-control/examples/b2b-rbac): Discover how Descope's Roles and Permissions features support fine-grained access controls and streamline authentication development. - [RBAC Management](/authorization/role-based-access-control/with-sdks): Learn how to assign roles and permissions to the application's end users and configure user roles with Descope SDKs. - Relationship-Based Access Control - [Overview](/authorization/rebac): Relationship-Based Access Control (ReBAC) allows you to manage access permissions in your application based on relationships between entities - Examples - [Google Drive](/authorization/rebac/examples/google-docs): Learn how to implement ReBAC for a collaborative document platform like Google Drive with hierarchical folder structures and granular file permissions. - [IoT Device Management](/authorization/rebac/examples/iot-rebac): Learn how to implement ReBAC for IoT device management with hierarchical access control for device groups and individual devices. - [Defining a Schema](/authorization/rebac/define-schema): Learn how to define a ReBAC (Relationship-Based Access Control) schema for your application with Descope. - [Managing a Schema](/authorization/rebac/implement-schema): Learn how to implement a ReBAC (Relationship-Based Access Control) schema for your application with Descope. - [Creating Relations](/authorization/rebac/create-relations): Learn how to create, update, filter, and delete relations in Descope's Fine-Grained Authorization (FGA) system. - [Checking Relations](/authorization/rebac/check-relations): Learn how to implement relations checking with Descope, a comprehensive access control solution. - Attribute-Based Access Control - [Overview](/authorization/abac): Learn how Descope supports Attribute-Based Access Control (ABAC) using custom attributes for fine-grained authorization decisions. - [Implementing ABAC](/authorization/abac/implement): Learn how to effortlessly implement Attribute-Based Access Control (ABAC) for your app with Descope. - [FGA Cache](/authorization/fga-cache): Learn how to use Descope AuthZ Cache to accelerate Fine-Grained Authorization (FGA) checks for ReBAC, ABAC, and all authz service operations. - Sessions - [Sessions in Descope](/sessions): Learn how Descope handles session tokens and refresh tokens for secure session management. - Management - [Overview](/sessions/management): Manage Descope session tokens on web and mobile — storage, refresh, logout, and sending tokens to your backend. - [Web Client Sessions](/sessions/management/web): How web apps retrieve Descope session tokens with the Client SDK, send them to your backend, and manage logout and session state in the browser. - [Mobile Sessions](/sessions/management/mobile): How Descope Mobile SDKs store, refresh, and manage session tokens on iOS, Android, Flutter, and React Native. - Validation - [Overview](/sessions/validation): Validate Descope session tokens on your backend or at an API gateway before serving protected resources. - Backend SDKs - [Backend](/sessions/validation/backend): Learn how Descope Backend SDK can validate session for secure session management. - [Validating JWTs Offline](/sessions/validation/backend/offline-jwt-validation): Learn how to validate JSON Web Tokens (JWTs) via SDK offline and in middleware - JWT Authorizers - [JWT Authorizers](/sessions/validation/jwt-authorizers): This guide is about how to use GCP, AWS, other services with Descope JWTs using the OIDC standard. - [AWS API Gateway](/sessions/validation/jwt-authorizers/aws-jwt-authorizer): Learn how to configure Descope JWTs to work with AWS API Gateway. - [GCP API Gateway](/sessions/validation/jwt-authorizers/gcp-api-gateway): Discover how to integrate Descope JWTs for secure authentication with GCP API Gateway. - [Azure API Management](/sessions/validation/jwt-authorizers/azure-jwt-authorizer): Learn how to configure Descope JWTs to work with Azure API Management (APIM). - [AWS AppSync](/sessions/validation/jwt-authorizers/aws-app-sync): Learn how to configure Descope JWTs to work with AWS AppSync. - [.NET](/sessions/validation/jwt-authorizers/dotnet-jwt-validation): Learn how to validate Descope JWTs through .NET libraries. - [Python FastAPI](/sessions/validation/jwt-authorizers/python-fastapi-jwt-authorizer): Learn how to verify Descope JWTs in a Python FastAPI backend application - [Google Apigee](https://www.descope.com/blog/post/jwt-authorizer-oidc) - [Kong](https://www.descope.com/blog/post/kong-gateway-authentication) - [Token Introspection](/sessions/introspection): Validate access tokens and read live user claims, roles, and permissions using Descope UserInfo endpoints for Federated and Inbound Apps. - Flows - [Overview](/flows): Learn about Descope Flows, a visual no-code interface to build screens and authentication flows for common user interactions with your application - Introduction To Flows - [Flow Library](/flows/intro-to-flows/flow-library): Learn how to utilize Descope's flow library to explore flow templates to use within your application. - [Flow Notes](/flows/intro-to-flows/flow-notes): Learn how to annotate steps in the Descope flow editor with notes, so anyone opening the flow can understand what each part of it does. - [Flow Versioning](/flows/intro-to-flows/flow-versioning): Learn how to utilize Descope's flow versioning to manage changes, track history, and restore previous versions whenever needed. - [Subflows](/flows/intro-to-flows/subflows): Learn about Descope Subflows, a way to utilize our visual no-code interface between one or more flows. - Screens - [Screens](/flows/screens): Learn how to customize and utilize components within Descope screen. - [Buttons](/flows/screens/buttons): This article will teach you how to configure buttons within Descope flows. - [Text](/flows/screens/text): This article will show how to use the text component in a Descope flow. - [Images and Logos](/flows/screens/images-and-logos): This article will show how to use images and logos in a Descope flow. - Inputs - [Inputs](/flows/screens/inputs): Learn how to customize and utilize inputs within Descope screen. - [Checkboxes](/flows/screens/inputs/checkboxes): The article will cover how to implement checkboxes within your Descope flows. - [Date](/flows/screens/inputs/date-component): This article will show how to use date type custom attribute and how to utilize the selection in a flow. - [Login ID](/flows/screens/inputs/login-ids): This article will show how to use the email, phone and email/phone components in a Descope flow. - [Multi-Select](/flows/screens/inputs/multiselect-component): This article will show how to use the multi select component and how to utilize the selection in a flow. - [One Time Code](/flows/screens/inputs/one-time-code): This article will show how to use one time code component and how to utilize the selection in a flow. - [Password](/flows/screens/inputs/passwords): Learn how to customize and utilize the password component within Descope screen. - [Phone Numbers](/flows/screens/inputs/phone-numbers): Learn how to customize and utilize the phone number component within Descope screen. - [Single-Select](/flows/screens/inputs/singleselect-component): This article will show how to use the single select component and how to utilize the selection in a flow. - [Switch Tenant](/flows/screens/inputs/tenantselect-component): Learn how to use the Switch Tenant component and set it up in your flow. - [Textarea](/flows/screens/inputs/textarea): This article will show how to use the textarea component in a Descope flow. - [Upload Document](/flows/screens/inputs/uploaddocument-component): This article will show how to use the upload document component to use the document in original format and in bytes. - [Bring Your Own Screen](/flows/screens/byos): Learn how to use Descope flows with your own screens - [Containers](/flows/screens/containers): This article will teach you how to configure containers within Descope flow screens. - Actions - [Actions](/flows/actions): Learn how to utilize actions within your Descope flows. - [Authentication Methods](/flows/actions/authentication-methods): Learn about different authentication methods available in Descope and how to use them in your flows. - [Custom Claims](/flows/actions/custom-claims): Use the Custom Claims flow action to add claims to a user's JWT during a Descope flow. - [Using Messaging Templates](/flows/actions/email-sms-templates-in-flows): This article will show you how to customize email, voice, and sms templates for OTP, enchanted link, and magic link within Descope flows. - [End Action](/flows/actions/end-action): This article will show you how to use the End action in Descope flows. - [External Authentication](/flows/actions/external-authentication): Use the External Authentication flow action to redirect users to your existing login page and complete authentication. - [Generate Audit Event](/flows/actions/generate-audit-event): This doc will show you how to use the generate audit event action within a flow. - [Generate JWT](/flows/actions/generate-jwt): Use the Generate JWT action to provision a user from a third-party IdP. - [Load User](/flows/actions/load-user): This doc will show you how to use load user action within a flow. - [Link User Identities Across Different Auth Methods](/flows/actions/multiple-login-id): Learn how to associate multiple login IDs for different authentication methods in your Descope flows. - [Check Rate Limit](/flows/actions/rate-limit-action): When you need to block certain sensitive flow parts and want to rate limit by ASN / IP / JA4 you can use this action to do so. - [Reset Form](/flows/actions/reset-form-action): When you're designing a flow and need to reset all of the previous user inputs you can use this action to do so. - [Scriptlets](/flows/actions/scriptlets): Run custom JavaScript in a Descope Flow with the Scriptlet action. - [User Invite](/flows/actions/user-invite): This doc will show you how to invite users within a flow. - [Validate Email Address](/flows/actions/validate-email-action): Use the Validate Email Address action in Descope Flows to check email format and verify the domain has MX records before sending. - [Verify Token](/flows/actions/verify-token): This doc will show you how to verify tokens within a flow. - Conditions - [Conditions](/flows/conditions): Learn how to customize your authentication flow with conditions - [User.loggedIn Condition](/flows/conditions/isloggedin): Learn how to use the isLoggedIn conditional in Descope Flows to streamline authentication processes and customize user experiences. - [IP Address Check](/flows/conditions/ipaddress): Learn how to use the ipAddress dynamic value in Descope Flows to streamline authentication processes and customize user experiences. - [Checking for Disposable Email Type](/flows/conditions/disposable-email): Condition to check if the email domain is disposable email type - [Flow A/B Testing](/flows/conditions/flow-ab-testing): This guide covers how to A/B test in Descope Flows. - [How to Check Free Email Type](/flows/conditions/free-email): Condition to check if the email domain is free email type - [failedPasswordAttempts Condition](/flows/conditions/password-attempts): Condition to check failedPasswordAttempts for custom handling in Flows - [remainingOTPAttempts Condition](/flows/conditions/remaining-otp-attempts): Condition to check remainingOTPAttempts for custom OTP lockout handling in Flows - [Restrictions](/flows/conditions/restrictions): Learn how to manage user access with restrictions in Descope - [Enforcing SSO](/flows/conditions/sso-enforced): Learn how to use the ssoEnabled and tenant.enforceSSO conditions in Descope Flows to streamline authentication processes and customize user experiences. - Dynamic Values - [Dynamic Values](/flows/dynamic-keys): Learn how to utilize Descope's dynamic keys, values, and placeholders to enhance your Descope flows and messaging templates. - [Flow Inputs](/flows/dynamic-keys/flow-inputs): Learn how to configure and utilize Descope flow inputs within your application. - Management Flows - [Management Flows](/flows/management-flows): In this article, you will learn about management flows in Descope. - [Management Flows with SDKs](/flows/management-flows/with-sdks): Learn how to easily implement management flows for your app with Descope using the Descope backend SDKs. - Use Cases - [Authenticated Flows](/flows/use-cases/authenticated-flows): In this article, you will learn how to start authenticated flows in Descope mobile sdks. - [Testing Authenticated Flows with JWT Input](/flows/use-cases/flow-runner-jwt-input): Learn how to provide a refresh JWT to the Descope flow runner to test post-auth flows, step-up authentication, impersonation, and MFA enrollment. - [Backend Webhooks from Flows](/flows/use-cases/backend-webhooks): Send flow context and user data to your backend in real time using the Generic HTTP connector, with a request body formatted exactly how you need it. - [Backup Custom Schemes](/flows/use-cases/backup-custom-schemes): In this article, you will learn how to handle Custom Schemes in Android for running flows in Descope mobile sdks. - [Device Fingerprinting](/flows/use-cases/implementing-fingerprinting): This guide shows Descopers how to configure and use device fingerprinting functionality in their Descope Flows. - [Email Verification Outside of Sign Up/In](/flows/use-cases/email-verification): Learn how to utilize embedded links to verify a user's email outside of the standard sign up/in flow without magic link. - [Checking for Email Scanners](/flows/use-cases/email-scanner): Condition to check if the email is being scanned and prevent magic link invalidation - [Manage User Consent and Preferences](/flows/use-cases/manage-user-preference): Learn how to manage consent and user preferences in your flow. - [Embedded OTP with Generic HTTP Connectors](/flows/use-cases/embedded-otp): Learn how to utilize embedded OTP codes for authenticating users when sending customized notifications with your messaging connectors within Descope. - [Remember User Flow](/flows/use-cases/remember-me-flow): Learn how to implement the "Remember User" functionality in your Descope flows to streamline sign-in experiences. - [Block Users by IP Address](/flows/use-cases/block-users-by-ip-address): Learn how to use Descope Lists to block users by IP address, preventing abusive or fraudulent traffic from accessing your authentication flows. - [Adding a Recovery Email](/flows/use-cases/recovery-email): Learn how to let users add, verify and use a recovery email in your flows. - [Enabling OAuth Sign-In for Pre-Created Users](/flows/use-cases/oauth-signin-pre-created-users): How to let pre-created users sign in with OAuth when sign-ups are disabled by verifying their email and linking the OAuth identity to their existing account. - [Step-Up Authentication for Third-Party IdP Sign-Ins](/flows/use-cases/step-up-with-generate-jwt): Issue a stepped-up JWT when signing a user in through a homegrown or third-party IdP, so a single sign-in can satisfy both authentication and step-up. - Widgets - [Widgets](/widgets): Learn about Descope widgets, a way to use designated components to delegate operations to your customers. - [User Widgets](/widgets/users): Learn about Descope user widgets that enable end-users to manage their profiles, authentication methods, and application access. - [Admin Widgets](/widgets/admins): Learn about Descope admin widgets that enable administrators to manage users, roles, access keys, and audit logs. - [Admin Portal](/widgets/admin-portal): Learn how to use the Descope Admin Portal to provide users and tenant admins with a hosted identity management experience built from Descope widgets. - Agentic Identity Hub - [Agentic Identity Hub](/agentic-identity-hub): Manage authentication, authorization, and external credentials for AI agents using Descope's Agentic Identity Hub. - Auth Patterns - [Auth Patterns](/agentic-identity-hub/auth-patterns): Credential issuance patterns, integration architectures, and the OAuth standards behind the Agentic Identity Hub. - [Downstream Credential Access](/agentic-identity-hub/auth-patterns/downstream-credential-access): Exchange inbound access tokens for downstream credentials scoped to Descope Resources or Connections, from MCP servers, APIs, or any intermediate service. - Core Components - [Agentic Identity](/agentic-identity-hub/core-components/agents): Learn how to view, manage, and revoke access for AI agents in the Agentic Identity Hub. - MCP Servers - [MCP Servers](/agentic-identity-hub/core-components/mcp-servers): Learn how to configure MCP servers and onboard clients using Descope OAuth 2.1, SSO, audience-scoped tokens, and tool-level scopes. - [MCP Server Settings](/agentic-identity-hub/core-components/mcp-servers/settings): Learn how to configure MCP server settings, including server details, client registration, scopes, and flows. - [Managing MCP Servers](/agentic-identity-hub/core-components/mcp-servers/management): Learn how to create, list, update, and delete MCP Servers using the Descope Management API. - [Registration Methods](/agentic-identity-hub/core-components/mcp-servers/registration-methods): Learn about the client registration methods for MCP servers. - [Discovery Endpoints](/agentic-identity-hub/core-components/mcp-servers/discovery-url): Learn how the well-known discovery endpoint works for MCP servers and understand the OAuth metadata structure. - Clients - [Clients](/agentic-identity-hub/core-components/clients): Learn how to view, create, and manage OAuth clients for MCP servers and autonomous agents in the Agentic Identity Hub. - [Workload Identity](/agentic-identity-hub/core-components/clients/workloads): Exchange cloud workload OIDC tokens from AWS or GCP for Descope access tokens using the JWT-Bearer grant type. - Connections - [Connections](/agentic-identity-hub/core-components/connections): Discover how Descope's Connections enable seamless integration with third-party platforms, enhancing user experiences with additional OAuth consents. - [Creating a Connection](/agentic-identity-hub/core-components/connections/create-connections): Learn how to create a Connection in Descope to vault third-party OAuth tokens or API keys for MCP tools and backend services. - [Storing Tokens](/agentic-identity-hub/core-components/connections/storing-connections): Learn the four ways to store user and tenant tokens for Connections, and when to use each one. - [Fetching Tokens](/agentic-identity-hub/core-components/connections/fetching-connection-tokens): Learn how to fetch connection tokens for users and tenants to access third-party APIs securely. - [Multi-Tenancy with Connections](/agentic-identity-hub/core-components/connections/multi-tenancy): Learn how user and tenant-scoped connection tokens work, including tenant-associated user tokens and tenant-level shared tokens. - [Agent Auth SDK](/agentic-identity-hub/agent-auth-sdk): Sign your agents in to Descope and fetch Resource and Connection tokens for the APIs and MCP servers they call, with the Agent Auth SDK. - Enterprise-Managed Authorization - [Enterprise-Managed Authorization](/agentic-identity-hub/enterprise-managed-authorization): Use Descope for enterprise-managed authorization (ID-JAG) to govern the agents you run or let customers manage access to MCP servers you sell. - Issuing ID-JAGs - [Issuing ID-JAGs](/agentic-identity-hub/enterprise-managed-authorization/issue-id-jags): Make Descope the IdP for the AI agents you run so they can reach third-party MCP servers and backend APIs, by minting ID-JAGs on demand. - [Claude Code](/agentic-identity-hub/enterprise-managed-authorization/issue-id-jags/claude-code): Point Claude Code at your Descope project as its ID-JAG identity provider, then connect to MCP servers with no per-server login prompt. - [VS Code](/agentic-identity-hub/enterprise-managed-authorization/issue-id-jags/vscode): Configure VS Code to authenticate to your Descope project once, then connect to enterprise-managed MCP servers silently. - [Validating ID-JAGs](/agentic-identity-hub/enterprise-managed-authorization/validate-id-jags): Turn on ID-JAG validation for your MCP server so enterprise customers can manage access with their own IdP, like Okta or Entra. - [Agent Authorization](/agentic-identity-hub/policies): How policies govern agent access to Resources and Connections, with recommended patterns for MCP servers, backend APIs, and third-party credential brokering. - Resources - [Resources](/resources): Define API and MCP Server Resources in Descope with OAuth scopes, RBAC role mapping, and connection scope mapping for agent and client access. - [Management](/resources/managing-resources): Create API and MCP Server Resources in Descope, associate them with Inbound Apps and agentic Clients, and delete Resources when they are no longer needed. - [Scopes and Roles](/resources/scopes-and-roles): Map OAuth scopes on API Resources to Descope RBAC roles, and map MCP Server Resource scopes to Connection scopes for third-party tool access. - [Policies](/policies): Define authorization policies across all Descope Applications and Agentic Clients. - Applications - [Applications](/identity-federation): Learn about Descope's three types of applications and how they enable different identity federation scenarios - Federated Apps - [Federated Apps](/identity-federation/applications): Integrate and manage Federated Applications with Descope. Follow our guides to set up your applications' SSO securely and seamlessly. - OIDC - [OIDC](/identity-federation/applications/oidc-apps): Configure Descope as an OpenID Connect Identity Provider for your applications. - [Using OIDC Endpoints](/identity-federation/applications/oidc-apps/oidc-endpoints): Get started with Descope's OIDC endpoints using Descope as an OIDC provider. - [SAML](/identity-federation/applications/saml-apps): Configure Descope as a SAML Identity Provider. Set up SP-initiated SSO, IdP-initiated SSO, and single logout for your federated applications. - [Managing with SDKs](/identity-federation/applications/sdks): Learn how to manage Descope Applications with our Management SDK. - Setup Guides - [Setup Guides](/identity-federation/applications/setup-guides): List of all setup guides for Descope as an IdP - [AWS Cognito (OIDC)](/identity-federation/applications/setup-guides/aws-cognito): Learn how to configure Descope as an OIDC provider with AWS Cognito to handle user authentication. - Auth0 - [Overview](/identity-federation/applications/setup-guides/auth0): Learn how to set up Descope as a federated Identity Provider (IdP) to implement authentication for applications that currently use Auth0. - [OIDC](/identity-federation/applications/setup-guides/auth0/auth0-oidc): Implement OpenID Connect (OIDC) with Auth0 and Descope for secure SSO. Follow our guide for a smooth setup process. - [SAML](/identity-federation/applications/setup-guides/auth0/auth0-saml): Integrate SAML-based SSO with Auth0 and Descope. Follow our guide for a smooth setup process. - [Azure AD B2C (OIDC)](/identity-federation/applications/setup-guides/azure-ad-b2c-oidc): Configure Descope as a federated IdP with Azure AD B2C, enabling seamless integration of Descope Flows for enhanced authentication in your apps. - [Document360 (OIDC)](/identity-federation/applications/setup-guides/document360-oidc): Learn how to set up Descope as a federated Identity Provider (IdP) to implement authentication for Document360. - [Firebase (OIDC)](/identity-federation/applications/setup-guides/firebase-oidc): this guide covers how to set up Descope as a federated Identity Provider (IdP) to implement Descope Flows for applications that currently use Firebase. - Keycloak - [Overview](/identity-federation/applications/setup-guides/keycloak): Learn how to integrate Keycloak with Descope for effective single sign-on (SSO) authentication. A comprehensive setup guide is available. - [OIDC](/identity-federation/applications/setup-guides/keycloak/keycloak-oidc): Implement OpenID Connect (OIDC) with Keycloak and Descope for robust SSO. Follow our detailed setup instructions. - [SAML](/identity-federation/applications/setup-guides/keycloak/keycloak-saml): Integrate SAML-based SSO with Keycloak and Descope. Easy-to-follow setup guide included. - [Metabase (SAML)](/identity-federation/applications/setup-guides/metabase-saml): This guide provides a comprehensive walkthrough for setting up Metabase as your Identity Provider (IdP) for SSO with your Descope project - [Ping Identity (OIDC)](/identity-federation/applications/setup-guides/ping-identity): This guide covers how to set up Descope as a federated Identity Provider (IdP) to implement Descope Flows for applications that currently use Ping Identity - [Retool (OIDC)](/identity-federation/applications/setup-guides/retool-oidc): How you can configure SSO with OIDC and Descope to work with your Retool resources and apps. - [Zoho (SAML)](/identity-federation/applications/setup-guides/zoho-saml): Learn how to set up Descope as a federated Identity Provider (IdP) to implement authentication for Zoho. - Inbound Apps - [Inbound Apps](/identity-federation/inbound-apps): Discover how to configure inbound apps in Descope to streamline user consent, permissions, and integration with third-party platforms. - [Creating Inbound Apps](/identity-federation/inbound-apps/creating-inbound-apps): Step-by-step guide to setting up an Inbound App in Descope. - [Authorization Server Endpoints](/identity-federation/inbound-apps/authorization-server): Descope OAuth 2.0 authorization server endpoints for Inbound Apps (authorize, token, revoke, and userinfo) with links to the API reference. - [Using Inbound Apps](/identity-federation/inbound-apps/using-inbound-apps): Learn how to integrate inbound apps with Descope to streamline OAuth authentication, manage user consent, and securely connect third-party applications. - [Developing APIs with OAuth](/identity-federation/inbound-apps/developing-apis): Guide to designing and implementing APIs that enforce OAuth-based authentication and authorization. - [Use Cases for Inbound Apps](/identity-federation/inbound-apps/inbound-apps-use-cases): A list of popular use cases for inbound apps, and how they can be implemented. - [Managing with SDKs](/identity-federation/inbound-apps/sdks): Learn how to manage inbound applications using the Descope backend SDKs. - Outbound Apps - [Outbound Apps](/identity-federation/outbound-apps): Discover how Descope's Outbound Apps enable seamless integration with third-party platforms, enhancing user experiences with additional OAuth consents. - [Creating an Outbound App](/identity-federation/outbound-apps/creating-outbound-apps): Learn how to create an Outbound App with Descope, a secure way to connect your users to third-party services. - [Connecting Outbound Apps](/identity-federation/outbound-apps/connect): Learn how to connect users to third-party services with Descope Outbound Apps using JavaScript SDKs or Flow Actions. - [Using Outbound Apps](/identity-federation/outbound-apps/using-outbound-apps): Learn how to integrate outbound apps with Descope to securely manage third-party OAuth tokens, handle token refresh, and access external APIs. - [Example Tools](/identity-federation/outbound-apps/examples): See how to use Descope Outbound Apps from the backend to fetch access tokens for providers like Salesforce, HubSpot, and Google Calendar. - [Managing with SDKs](/identity-federation/outbound-apps/sdks): Learn how to manage outbound applications using the Descope backend SDKs. - [Auth Hosting](/identity-federation/auth-hosting): Configure and use the Descope Auth Hosting App to deliver authentication flows without embedding the Descope SDK in your own application. - SDKs - Client SDK - [Client SDK Reference](/client-sdk): Use Descope Client SDKs to add authentication to your app with secure session management. Supports JavaScript, React, Web Components, and more. - [Auth Helpers](/client-sdk/auth-helpers): Learn how the Auth class in Descope SDK handles user authentication operations within your web client application. - [Initialize SDK](/client-sdk/initialize-sdk): Learn how to initialize Descope Client sdks - Descope Components - [Descope Components](/client-sdk/descope-components): Learn about the Descope components and how to implement them within your application. - [Request Hooks](/client-sdk/descope-components/request-hooks): Intercept and observe HTTP requests made by the Descope SDK using beforeRequest, afterRequest, and transformResponse hooks. - Mobile SDK - [Mobile SDK Reference](/mobile-sdk): Use Descope Mobile SDKs to add authentication to your app with secure session management. Supports Swift. - [Native Flows](/mobile-sdk/native-vs-browser-flows): Learn how native flows work with Descope on mobile. - [Auth Helpers](/mobile-sdk/auth-helpers): Learn how the Auth class in Descope SDK handles user authentication operations within your mobile application. - [Logging](/mobile-sdk/logging): Enable and configure logging in the Descope Swift, Kotlin, Flutter, and React Native SDKs. - [Network Client](/mobile-sdk/network-client): Override how the Descope Swift, Kotlin, Flutter, and React Native SDKs perform HTTP requests, for unit testing and custom transport. - Backend SDK - [Backend SDK](/backend-sdk): Use Descope Backend SDKs to add authentication to your app with your own developed backend APIs. - [Logging](/backend-sdk/logging): Enable and configure logging in the Descope Go, Ruby, Node.js, and PHP backend SDKs. - Integrations and Connectors - Connectors - [Overview of Connectors](/connectors): Overview for all the connectors that we support. - [Connectors in Flows](/connectors/connectors-in-flows): Learn how to utilize Descope Connectors to enrich your flows by interacting with 3rd party services - Setup Guides - App Analytics - [App Analytics Connectors](/connectors/connector-configuration-guides/analytics): App Analytics Connectors Overview - [Amplitude](/connectors/connector-configuration-guides/analytics/amplitude): Descope's Amplitude connector allows you to collect events from web and mobile apps to your Amplitude account. - [Google Cloud Logging](/connectors/connector-configuration-guides/analytics/google-cloud-logging): Descope's Google Cloud Logging connector allows you to send logs and stream audit events to your Google Cloud Logging account. - [Mixpanel](/connectors/connector-configuration-guides/analytics/mixpanel): Descope's Mixpanel connector allows you to send logs and stream audit events to your Mixpanel account. - [mParticle](/connectors/connector-configuration-guides/analytics/mparticle): Using Descope's connectors allows you to use mParticle to update events and user details in mParticle platform from web and mobile apps. - [Open Telemetry](/connectors/connector-configuration-guides/analytics/open-telemetry): Descope's Open Telemetry connector allows you to send logs and stream audit events to your Open Telemetry Collector instance. - [Segment](/connectors/connector-configuration-guides/analytics/segment): Using Descope's connectors allows you to use Segment to collect events from web and mobile apps and better understand your customer's needs. - Audit & Troubleshooting - [Audit & Troubleshooting](/connectors/connector-configuration-guides/audit-and-troubleshooting): Audit & Troubleshooting Connectors Overview - [AWS S3](/connectors/connector-configuration-guides/audit-and-troubleshooting/aws-s3): Descope's AWS S3 connector allows you to send logs and stream audit events to your AWS S3 account. - [Coralogix](/connectors/connector-configuration-guides/audit-and-troubleshooting/coralogix): Descope's Coralogix connector allows you to send logs and stream audit events to your Coralogix account. - [Cribl](/connectors/connector-configuration-guides/audit-and-troubleshooting/cribl): Descope's Cribl connector allows you to send logs and stream audit events to your Cribl Stream instance. - [Datadog](/connectors/connector-configuration-guides/audit-and-troubleshooting/datadog): Descope's Datadog connector allows you to send logs and stream audit events to your Datadog account. - [Groundcover](/connectors/connector-configuration-guides/audit-and-troubleshooting/groundcover): Descope's groundcover connector allows you to send logs and stream audit events to your groundcover account. - [Logz.io](/connectors/connector-configuration-guides/audit-and-troubleshooting/logzio): Descope's Logz.io connector allows you to send logs and stream audit events to your Logz.io account. - [New Relic](/connectors/connector-configuration-guides/audit-and-troubleshooting/newrelic): Learn how to send audit events with New Relic Connector within your applications. - [Pendo](/connectors/connector-configuration-guides/audit-and-troubleshooting/pendo): Descope's Pendo connector allows you to send logs and stream audit events to your Pendo account. - [Snowflake](/connectors/connector-configuration-guides/audit-and-troubleshooting/snowflake): Descope's Snowflake connector allows you to send logs and stream audit events to your Snowflake data warehouse. - [Splunk](/connectors/connector-configuration-guides/audit-and-troubleshooting/splunk): Descope's Splunk connector allows you to send logs and stream audit events to your Splunk instance. - [Sumo Logic](/connectors/connector-configuration-guides/audit-and-troubleshooting/sumologic): The Sumo Logic connector allows you to send logs and stream audit events from Descope to your Sumo Logic account. - Fraud & Risk - [Fraud & Risk Connectors](/connectors/connector-configuration-guides/fraud): Fraud Connectors Overview - [AbuseIPDB](/connectors/connector-configuration-guides/fraud/abuseipdb): Leverage Descope's AbuseIPDB connector to establish a reputation-based score on a user's originating IP address - [Bitsight](/connectors/connector-configuration-guides/fraud/bitsight): Use Descope's Bitsight Threat Intelligence connector to detect leaked credentials & enrich suspicious IoCs during auth flows. - [Alloy](/connectors/connector-configuration-guides/fraud/alloy): Use Descope's Alloy connector for identity verification and fraud monitoring through Alloy's Journey and Events APIs. - [Darwinium](/connectors/connector-configuration-guides/fraud/darwinium): Use Descope's Darwinium connector for AI-powered fraud detection and device intelligence across the entire customer journey - [Forter](/connectors/connector-configuration-guides/fraud/forter): Use Descope's connector to Forter to astablish a ML based risk score on user's behavior, thus helping you detect fraud or hacker associated connections. - [Fingerprint](/connectors/connector-configuration-guides/fraud/fingerprint): Use Descope's connector to Fingerprint to perform device detection for malicious or bot activity. - [reCAPTCHA Enterprise](/connectors/connector-configuration-guides/fraud/recaptcha-enterprise): Utilize Descope's reCAPTCHA Enterprise connector for enhanced security in your applications - [reCAPTCHA v3](/connectors/connector-configuration-guides/fraud/recaptcha-v3): Use Descope's reCAPTCHA v3 connector to secure your authentication flow. - [Reassigned](/connectors/connector-configuration-guides/fraud/reassigned): Learn how to integrate Reassigned's RND database to detect phone number risk and protect against number recycling fraud. - [Traceable](/connectors/connector-configuration-guides/fraud/traceable): Leverage Descope's Traceable connector to easily add deep, contextual user behavioral data to your authentication and user journey flows. - [Telesign](/connectors/connector-configuration-guides/fraud/telesign): Learn how to integrate Telesign Phone Number Intelligence API for risk assessment in your applications. - [Arkose Labs](/connectors/connector-configuration-guides/fraud/arkose): Leverage Descope's Arkose Labs connector to protect your authentication flow from bot attacks - [AWS SES Email Validation](/connectors/connector-configuration-guides/fraud/aws-ses-email-validation): Use Descope's AWS SES Email Validation connector to check email syntax, DNS records, mailbox existence, and deliverability using Amazon SES. - [Elephant](/connectors/connector-configuration-guides/fraud/elephant): Leverage Descope's Elephant connector to establish an identity trust score for new users - [hCaptcha](/connectors/connector-configuration-guides/fraud/hcaptcha): Use Descope's hCaptcha connector to secure your authentication flow - [Pwned](/connectors/connector-configuration-guides/fraud/pwned): Leverage Descope's Have I Been Pwned connector to verify password security by checking against known data breaches - [Sardine](/connectors/connector-configuration-guides/fraud/sardine): Use Descope's connector to Sardine AI to evaluate login and onboarding risk using machine learning-based fraud detection. - [Turnstile](/connectors/connector-configuration-guides/fraud/turnstile): Use Descope's Cloudflare Turnstile connector to easily add CAPTCHA protection to your authentication and user journey flows. - [Unibeam](/connectors/connector-configuration-guides/fraud/unibeam): Use Descope's Unibeam connector for SIM-based passwordless authentication and transaction approval using Unibeam's OnSim technology. - KYC - [KYC](/connectors/connector-configuration-guides/kyc): Overview of Descope KYC connectors for verifying user identity and documents within flows. - [AWS Rekognition](/connectors/connector-configuration-guides/kyc/aws-rekognition): Use Descope's AWS Rekognition Connector to achieve facial recognition in your authentication flow - [Incode](/connectors/connector-configuration-guides/kyc/incode): Use Descope's Incode Connector to achieve facial recognition in your authentication flow - Localization - [Localization](/connectors/connector-configuration-guides/localization): Localization Connectors Overview - [AWS Translate](/connectors/connector-configuration-guides/localization/aws-translate): Use Descope's AWS Translate connector to support automatic localization in your authentication flow - [Google Cloud Translation](/connectors/connector-configuration-guides/localization/google-cloud-translation): Use Descope's Google Cloud Translation connector to support automatic localization in your authentication flow - [Lokalise](/connectors/connector-configuration-guides/localization/lokalise): Use Descope's Lokalise connector to support automatic localization in your authentication flow - [Smartling](/connectors/connector-configuration-guides/localization/smartling): Use Descope's Smartling connector to support automatic localization in your authentication flow - CRM & Support - [CRM & Support](/connectors/connector-configuration-guides/marketing): Marketing Connectors Overview - [HubSpot](/connectors/connector-configuration-guides/marketing/hubspot): Harness the power of Descope's HubSpot connector to manage contacts seamlessly within your flow - [Intercom](/connectors/connector-configuration-guides/marketing/intercom): Integrate Intercom to manage contacts seamlessly within your Descope projects. - [Salesforce](/connectors/connector-configuration-guides/marketing/salesforce): Use Salesforce Connector to execute queries within your flow. This guide walks you through setting up the connector and incorporating it into your flow. - Messaging - [Messaging Connectors](/connectors/connector-configuration-guides/messaging): Messaging Connectors Overview - [Apple Push Notification (APN)](/connectors/connector-configuration-guides/messaging/apple-push-notification): Learn how to send push notifications using Apple's Push Notification service with the Descope APN connector. - [Firebase Cloud Messaging (FCM)](/connectors/connector-configuration-guides/messaging/firebase-cloud-messaging): Learn how to send push notifications using Google's Firebase Cloud Messaging service with the Descope FCM connector. - [8x8](/connectors/connector-configuration-guides/messaging/8x8): Using Descope's connectors allows you to use 8x8 to send SMS messages with your own 8x8 account - [Adobe Campaign Classic](/connectors/connector-configuration-guides/messaging/adobe-campaign-manager): Use Descope's Adobe Campaign Classic connector to send authentication emails via Adobe Campaign Classic (ACC) as your mail server. - [AWS SES](/connectors/connector-configuration-guides/messaging/aws-ses): Learn how to send emails using the AWS SES Connector within your applications. - [AWS SNS](/connectors/connector-configuration-guides/messaging/aws-sns): Learn how to send SMS messages using the AWS SNS Connector within your applications. - [Customer.io](/connectors/connector-configuration-guides/messaging/customer-io): Using Descope's Customer.io connector allows you to send authentication emails through Customer.io in your authentication flow. - [Infobip](/connectors/connector-configuration-guides/messaging/infobip): Using Descope's connectors allows you to use Infobip to send SMS with your own Infobip account - [MailerSend](/connectors/connector-configuration-guides/messaging/mailersend): Using Descope's MailerSend connector allows you to send emails through MailerSend in your authentication flow. - [Mandrill](/connectors/connector-configuration-guides/messaging/mandrill): Using Descope's connectors allows you to use Mandrill to send email messages with your own Mandrill account - [Mitto](/connectors/connector-configuration-guides/messaging/mitto): Using Descope's connectors allows you to use Mitto to send SMS with your own Mitto account - [OneSignal](/connectors/connector-configuration-guides/messaging/onesignal): Using Descope's OneSignal connector allows you to send email and SMS messages through OneSignal in your authentication flow. - [Postmark](/connectors/connector-configuration-guides/messaging/postmark): Using Descope's Postmark connector allows you to send transactional emails through your Postmark account in your authentication flow. - [Salesforce Marketing Cloud (SFMC)](/connectors/connector-configuration-guides/messaging/salesforce-marketing-cloud): Using Descope's Salesforce Marketing Cloud connector allows you to send emails using your SFMC account in your authentication flow. - [SendGrid](/connectors/connector-configuration-guides/messaging/sendgrid): Using Descope's SendGrid connector allows you to send emails without having to maintain email servers in your authentication flow. - [Slack](/connectors/connector-configuration-guides/messaging/slack): Using Descope's connectors allows you to use Slack to send messages to a slack channel - [Generic SMS Gateway](/connectors/connector-configuration-guides/messaging/sms-gateway): Use Descope's Generic SMS Gateway connector to send SMS messages through your own API. - [SMTP](/connectors/connector-configuration-guides/messaging/smtp): Using Descope's connectors allows you to use SMTP to send emails with your own email servers and trigger sending within the authentication flow. - [Telesign Messaging](/connectors/connector-configuration-guides/messaging/telesign-messaging): Using Descope's connectors allows you to use Telesign to send SMS with your own Telesign account - [Twilio Verify](/connectors/connector-configuration-guides/messaging/twilio-verify): Learn how to configure Descope's Twilio Verify connector for user authentication through voice, SMS, and email OTP verification - [Twilio](/connectors/connector-configuration-guides/messaging/twilio): Using Descope's connectors allows you to use Twilio to send SMS and make voice calls with your own Twilio account - [WhatsApp Cloud API](/connectors/connector-configuration-guides/messaging/whatsapp-api): Learn how to send messages via Whatsapp using the WhatsApp Cloud API Connector within your flows. - Webhooks - [Webhook Connectors](/connectors/connector-configuration-guides/network): Webhook Connectors Overview - [Audit Webhook](/connectors/connector-configuration-guides/network/audit-webhook): Descope's Audit Webhook Connector is used to send audit logs to your own API. - [Generic HTTP](/connectors/connector-configuration-guides/network/generic-http): Learn how to configure and utilize advanced features of Descope's generic HTTP connector. - External Token - [External Token Connectors](/connectors/connector-configuration-guides/token): External Token Connectors Overview - [Firebase](/connectors/connector-configuration-guides/token/firebase): Use Descope's Firebase Token Connector to generate a Firebase token whenever authenticating - [Generic Token](/connectors/connector-configuration-guides/token/generic-token): Use Descope's Generic Token Connector to generate a custom external token when a flow has completed - [Supabase](/connectors/connector-configuration-guides/token/supabase): Use Descope's Supabase Token Connector to generate a Supabase token whenever authenticating - Other - [Docebo](/connectors/connector-configuration-guides/other/docebo): Use Descope's Docebo Connector to fetch user information from Docebo's User API endpoint. - [SQL](/connectors/connector-configuration-guides/other/generic-sql): Use Descope's SQL Connector to query relational databases such as PostgreSQL, MySQL, MariaDB, and Oracle directly from your Descope flows. - [LDAP](/connectors/connector-configuration-guides/other/ldap): Use Descope's LDAP Connector to authenticate users against an LDAP directory server with support for username/password and mutual TLS authentication. - [PingDirectory](/connectors/connector-configuration-guides/other/ping-directory): Use Descope's PingDirectory Connector to authenticate LDAP users through PingDirectory's REST API with username/password. - [Connectors with Localhost](/connectors/connector-localhost-usage): Learn how to test connectors against APIs running on localhost using tunneling services. - [JSON Array Handling](/connectors/connector-json-usage): How to properly handle JSON arrays when using HTTP connectors. - [Descope Engine](/connectors/descope-engine): Deploy the Descope Engine to run connector actions inside your private network. - [HMAC Authentication Types](/connectors/connector-hmac-usage): How to use the HMAC Authentication Type with HTTP Connectors. - Other Integrations - [KrakenD](/other-integrations/krakend): Learn how to best use Descope with the KrakenD API Gateway - Management - [Management Overview](/management): Learn how to manage users, tenants, and access keys, and configure authorization and session settings. - Users - [User Management](/management/user-management): Learn how to easily implement user management and authorization for your app with Descope. - [Users with SDKs](/management/user-management/sdks): Learn how to easily implement user management and authorization for your app with Descope e using the Descope backend SDKs. - [Inviting Users](/management/user-management/invite-users): This guide will cover customizing user invite templates and the various options you have when inviting users within Descope. - [Exporting Users](/management/user-management/user-exporting): This guide will cover the fundamentals of user exporting with Descope. - [Anonymous Users](/management/user-management/anonymous-users): Learn how to configure Anonymous Users with Descope - [Tracking User Updates](/management/user-management/user-tracking): Learn how to track user updates using Descope's Search Users API and Audit Webhooks. - Access Keys - [Access Keys](/management/m2m-access-keys): Learn how to easily implement access key management and authorization for your app with Descope. - [Access Keys with SDKs](/management/m2m-access-keys/sdks): Learn how to easily implement access key management and authorization for your app via backend SDKs with Descope. - Tenants - [Tenants](/management/tenant-management): Learn how to create and update tenants for your B2B app using the Descope console or API. - [Tenants with SDKs](/management/tenant-management/sdks): Learn how to create and update tenants for your B2B app using the Descope backend SDKs. - [Configuring a Tenant](/management/tenant-management/tenant): Configure a tenant's authentication, authorization, styling, users, and settings in Descope, matching the Build, Manage, and Settings areas of the Console. - [Sub-tenants](/management/tenant-management/sub-tenants): Learn about Descope's sub-tenant hierarchy system and management. - [Exporting Tenants](/management/tenant-management/tenant-exporting): This guide will cover the fundamentals of tenant exporting with Descope. - Handling Tenants in Flows - [Handling Tenants in Flows](/management/tenant-management/handling-tenants-in-flows): Create and update tenants, and add users to tenants, using Descope Flows. - [Create or Modify Tenant](/management/tenant-management/handling-tenants-in-flows/add-attributes-to-tenant): Create a tenant or update tenant attributes using Descope Flow actions. - [Add User to Tenant](/management/tenant-management/handling-tenants-in-flows/add-user-to-tenant): Assign a user to a tenant in a Descope Flow with Update User / Add Tenant or User / Invite. - [Tenant Select Component](/flows/screens/inputs/tenantselect-component) - SSO - [SSO](/management/tenant-management/sso): Manage tenant SSO configurations in Descope with the Setup Suite, Console, Management SDKs, and APIs. - [With SDKs](/management/tenant-management/sso/sdks): Learn how to easily implement SSO management and authorization for your app via backend SDKs with Descope. - [SAML Certificate and Metadata Rotation](/management/tenant-management/sso/cert-and-metadata-rotation): Keep SAML SSO working when the IdP rotates signing certificates or when you rotate Descope SP signing and encryption keys. - [Authorization with SSO Providers](/management/tenant-management/sso/how-authorization-works-with-sso-providers): Understand how authorization works with SSO providers in Descope. Learn about access control, roles, and permissions to secure your applications effectively. - [Configuring a Mock SAML Tenant](/management/tenant-management/sso/mock-saml-testing): This article will show how you can test SSO using a Mock SAML IDP. - [SAML Signing And Encryption Keys](/management/tenant-management/sso/saml-signing): This article will show how you can use your own certificates for SAML request signing and response encryption on your tenant. - SCIM - [SCIM](/management/tenant-management/scim): Learn how to provision and manage users and groups using SCIM with Descope, including setup guides for Okta, Azure, and other IdPs. - [SCIM with Azure](/management/tenant-management/scim/azure-scim): Learn how to set up SCIM provisioning between Microsoft Entra ID (Azure) and Descope to automate user and group management. - [SCIM with Okta](/management/tenant-management/scim/okta-scim): Learn how to configure SCIM provisioning between Okta and Descope to automate user and group lifecycle management. - [SCIM Best Practices](/management/tenant-management/scim/scim-best-practices): Best practices for onboarding users with SCIM — group-based app assignment, provisioning vs. role mapping, and audit-log verification. - Styling and Theming - [Styling and Theming](/management/styles): Learn how to use CSS code mode within Descope styling and themes - [Themes with SDKs](/management/styles/managing-themes-sdks): This guide will cover how to manage themes with SDKs. - [Advanced Styling Examples](/management/styles/advanced-styling-examples): This guide will cover common advanced styling options. - Flows - [Flows](/management/flows): Learn about Managing Descope Flows within your project - [Flows with SDKs](/management/flows/with-sdks): Learn about Managing Descope Flows with backend SDKs - [Localization](/management/localization): Learn how to customize localization and translation within Descope flows and messaging templates. - Token - [Token Claims](/management/token): Manage token claims in Descope using JWT Templates and flow actions to shape JWT payloads for your applications and integrations. - [JWTs with SDKs](/management/token/sdks): Learn how to easily implement jwt management for your app with Descope using the Descope backend SDKs. - [JWT Templates](/management/token/jwt-templates): Learn how to utilize user and access key JWT Templates within your Descope project. - [Messaging Templates](/management/messaging-templates): Learn how to customize and manage email, voice, and SMS templates for authentication flows and user invitations in Descope. - [Sidebar Preferences](/management/sidebar-preferences): Personalize which pages appear in your Descope Console sidebar. - Projects - [Project Settings](/management/project-settings): Learn how to customize your Descope project settings. - [Project Dashboards](/management/project-settings/project-dashboard): Learn how to use the Descope Project Dashboards to monitor user activity, tenant metrics, operations & security, and flow analytics. - [External Token](/management/project-settings/external-token): Generate a Firebase, Supabase, or custom token at the end of a Descope flow alongside Descope session tokens. - [Multi-Region Support](/management/project-settings/multi-regional): Learn how to use Descope with multi-regional support, including Descope base URLs, regional API hosts, and custom domains. - [Project Versioning](/management/project-settings/project-versioning): Learn how to use the Descope Project Versioning to manage your project versions using project tags. - [Projects with SDKs](/management/project-settings/sdks): Learn how to easily implement project management with Descope using the Descope backend SDKs. - Company Settings - [Company Settings](/management/company-settings): Learn how to customize your Descope company settings. - [Descopers with SDKs](/management/company-settings/descopers-sdks): Learn how to create and update Descopers using the Descope backend SDKs. - [Management Keys with SDKs](/management/company-settings/mgmt-keys-sdks): Learn how to create and update Management Keys using the Descope backend SDKs. - Deployments and Testing - Deploy to Production - [Deploy to Production](/how-to-deploy-to-production): Guide describing things to handle when deploying to Production with Descope. - [Custom Domain](/how-to-deploy-to-production/custom-domain): Guide describing how to configure CNAME and manage sessions within cookies with Descope. - [Managing Environments](/how-to-deploy-to-production/managing-environments): Learn how to manage your Descope environments and migrate your configurations between non-production and production environments. - [Multi-Region Architecture](/how-to-deploy-to-production/multi-region-architecture): Learn how to handle data residency requirements when deploying applications across multiple regions with Descope - [Project Snapshot](/how-to-deploy-to-production/project-snapshot): Guide describing the content and structure of a Descope project snapshot. - [Public Static IPs](/how-to-deploy-to-production/public-static-ips): Guide describing how to configure firewall and allowlisting rules with Descope's static IPs for both projects and connectors. - CI/CD Tools - [Github Template](/managing-environments/manage-envs-in-github): Streamline DevOps with Descope's GitHub CI/CD Template for Seamless Transitions - [GitLab Template](/managing-environments/manage-envs-in-gitlab): Streamline DevOps with Descope's GitLab CI/CD Template for Seamless Transitions - [Pulumi](/managing-environments/pulumi): Streamline DevOps with Descope's Pulumi Provider - [Terraform](/managing-environments/terraform): Streamline DevOps with Descope's Terraform Provider - CLI - [CLI](/cli): Use the Descope CLI to build applications on top of the Descope platform. - [create-descope-app](/cli/create-descope-app): Use the create-descope-app CLI to create a new Descope application. - [descope](/cli/descope): Streamline DevOps and Easily Perform Common Tasks with Descope's Command Line Tool - Testing - [Developing Locally with Cookies](/unit-testing/local-testing-tokens): Manage SameSite Descope cookie restrictions in localhost testing by creating separate dev and prod projects. - E2E Testing Guides - [Cypress](/unit-testing/e2e-testing-guides/e2e-cypress): Discover the step-by-step process to automate your web application testing using Cypress. - [Playwright](/unit-testing/e2e-testing-guides/e2e-playwright): Learn how to test Descope flows with Playwright, an automated testing tool for web applications. - Test Users - [Test Users](/test-users): Learn how to easily implement test user management and authorization for your app with Descope. - [With SDKs](/test-users/sdks): Learn how to easily implement test user for your app with Descope using the Descope backend SDKs. - [Static OTP Guide](/test-users/static-otp-guide): Learn how to set up a static OTP test user so Mobile App Store reviewers can sign in to your mobile app without receiving a real OTP. - User Impersonation - [User Impersonation](/user-impersonation): This guide will cover the fundamentals of user impersonation and how to impersonate users with Descope. - [With SDKs](/user-impersonation/impersonation-with-sdks): Learn how to easily implement user impersonation for your app with Descope using the Descope backend SDKs. - Migrate to Descope - [Overview](/migrate): Learn how to migrate to Descope from third-parties - [SSO Migration](/migrate/sso): This article will show how you can migrate SSO tenants to Descope from any other authentication provider. - [Session Migration](/migrate/session-migration): Seamlessly migrate active user sessions from existing authentication providers to Descope without requiring re-authentication. - [From Auth0](/migrate/auth0): This guide will cover how to migrate your Auth0 users to Descope. - [From Okta CIS](/migrate/okta-cis): This guide covers how to migrate your Okta Customer Identity Solution (CIS) users to Descope. - From Azure B2C - [From Azure AD B2C](/migrate/azure-ad-b2c): This guide covers how to migrate your Azure AD B2C users to Descope. - [Custom Policies](/migrate/azure-ad-b2c/b2c-flows-migration): This guide covers how to migrate your Azure AD B2C custom policies to Descope flows. - [From Cognito](/migrate/cognito): This guide covers how to migrate your AWS Cognito users to Descope. - [From Firebase](/migrate/firebase): Learn how to seamlessly migrate your Firebase users to Descope using our comprehensive migration tool. - [From Ping](/migrate/ping): This guide will cover how to migrate your Ping users to Descope. - [From Keycloak](/migrate/keycloak): Learn how to migrate your Keycloak users, realms, and identity providers to Descope using our Custom Data Store migration or JIT provisioning approaches. - [From Clerk](/migrate/clerk): Learn how to migrate your Clerk users, organizations, roles, and sessions to Descope. - Custom Data Store - [From Custom Data Store](/migrate/custom): Discover how to efficiently migrate your users from any custom data store to Descope with our detailed guide and user management API. - [User JSON Formatting](/migrate/custom/user-format-json): Learn how to import users from a JSON file into Descope's User Management portal. - Security and Privacy - Security Best Practices - [Storing Refresh Tokens](/security-best-practices/refresh-token-storage): A guide and overview of how refresh token storage works with Descope and how to ensure you manage it securely. - [Storing Session Tokens](/security-best-practices/session-token-storage): A guide and overview of how session token storage works with Descope and how to ensure you manage it securely. - [M2M Security](/security-best-practices/m2m-security): Security philosophy behind machine-to-machine (M2M) authentication using the client credentials flow or Descope Access Keys to exchange for JWTs with Descope. - [JWT Claims](/security-best-practices/custom-claims): A guide and overview of how to properly manage and use custom claims in your tokens. - [Preventing User Enumeration](/security-best-practices/preventing-user-enumeration): This guide explains how to prevent user enumeration with Descope - [Content Security Policy](/security-best-practices/content-security-policy): Content Security Policy - Understanding how to effectively implement it in your application - [Cross-Site Cookies](/security-best-practices/crossite-cookies): Cross-Site Cookies - Understanding the Domain and SameSite Attributes - [Firewall ACL Configuration](/security-best-practices/firewall-acl): Guide for configuring firewall ACLs for Descope services. - [Certificate Verify Mode (Go)](/security-best-practices/golang-cert-verification): Learn how to utilize the certificate verify mode within the Descope backend Go SDK. - [SAML Security](/security-best-practices/saml-security): How Descope secures the SAML exchange as the service provider, covering request signing, response encryption, certificates, and assertion validation. - FedRAMP - [FedRAMP High Authorization](/fedramp): Descope is FedRAMP High Authorized. Learn how FedRAMP deployments are handled with Descope. - [FedRAMP Security Admin Guide](/fedramp/fedramp-security-guide): Complete guide for managing administrative accounts in Descope with FedRAMP compliance requirements and security best practices. - [Federated Identity Providers](/fedramp/federated-identity-providers): Background on which external identity providers carry a FedRAMP High authorization. - [Rate Limits](/rate-limiting): This guide details the rate limits present within Descope's API and SDK. - [Password Hashing](/password-hashing): How Descope securely hashes passwords using Argon2id - Additional Security Features - [JWK Rotation](/additional-security-features-in-descope/jwk-rotation): A guide on how JWK rotation works in Descope and how you control it within the Console - [Refresh Token Rotation](/additional-security-features-in-descope/refresh-token-rotation): A guide and overview of how refresh token rotation works with Descope and how it secures your sessions. - [Request Security Headers](/additional-security-features-in-descope/request-security-headers): A guide on how to view and use the security related headers in Descope's audit trail and flows - [Single Active Session](/additional-security-features-in-descope/single-active-session): Learn how to implement single active sessions across devices with Descope SDK. Enhance security, prevent conflicts, and ensure seamless user experiences. - Errors and Troubleshooting - [Common Errors](/common-errors): This article covers the common errors that that Descope can return. - [Error Handling in SDKs](/sdk-error-handling): Learn how the Descope SDKs type and surface errors, and how to check for specific error codes. - Handling Flow Errors - [Customizing Flow Errors](/handling-flow-errors/customizing-flow-errors): This guide covers how to handle errors within Descope flows. - [Troubleshooting Flows](/handling-flow-errors/troubleshooting-flows): Learn about Troubleshooting Flows within your project - [How to Debug Flows](/handling-flow-errors/debug-flows): How to debug the Flows you've created. - [Flow Activity](/flow-activity): Trace flow executions end-to-end, inspect per-task status and timing, and navigate to relevant audit and troubleshooting logs. - Audit - [Overview](/audit-trails-and-integrations): Learn how to search and review project-level and company-level audit events in the Descope audit trail. - Audit Events - [Audit Events](/audit-trails-and-integrations/audit-events): This article covers project-level and company-level audit events that Descope logs. - [SCIM Audit Events](/audit-trails-and-integrations/audit-events/scim-audit-events): Learn how Descope records detailed audit entries for SCIM provisioning, including requests, results, membership changes, and errors. - [Filtering Audit Events](/audit-trails-and-integrations/filtering-audit-events): Learn how to filter Descope audit events by event type, user, date range, and more using the Descope Console, Backend SDKs, or REST API. - [With SDKs](/audit-trails-and-integrations/sdks): Search and create Descope audit events programmatically using backend SDKs. - [Audit Trail Streaming](/audit-trails-and-integrations/audit-trail-streaming): This guide will cover the fundamentals and one use case regarding streaming your Descope audit trail to a third-party service. - [Masking PII in Audit Logs](/audit-trails-and-integrations/masking-pii-in-audit-logs): Control which personally identifiable information gets masked before audit and troubleshoot logs are forwarded to external connectors. - Connectors - [Audit Webhook](/connectors/connector-configuration-guides/network/audit-webhook) - [Datadog](/connectors/connector-configuration-guides/audit-and-troubleshooting/datadog) - [New Relic](/connectors/connector-configuration-guides/audit-and-troubleshooting/newrelic) - [Sumo Logic](/connectors/connector-configuration-guides/audit-and-troubleshooting/sumologic) - Other - [SSO Troubleshooting](/other-troubleshooting/sso-troubleshooting): Learn how to troubleshoot SSO configuration issues and help your customers resolve SSO-related problems. - [Hash-Based Routing](/other-troubleshooting/angular-hash-routing): If you're using Angular with hash-based routing you may encounter issues with Magic Link and Oauth not working. This guide explains how to resolve this issue. - [Email Sending Delay](/other-troubleshooting/email-sending-delay): Learn how to debug delays in emails sent to users - [Mitigating High Spam Report Rates](/other-troubleshooting/mitigating-high-spam-reports): Reduce and prevent high email spam complaint rates - [esModuleInterop Issue](/other-troubleshooting/nodejs-typeerror): If you're using our Node.js SDK, you may come across an issue when compiling relating to esModuleInterop. This guide explains how to resolve this issue. - [Cookies with Safari](/other-troubleshooting/safari-cookies): Describe why sessionTokenViaCookie doesn't work in Safari - [Self Signed Certificates](/other-troubleshooting/self-signed-certs): How to diagnose and resolve TLS errors caused by self-signed certificates when using Descope SDKs in development and corporate environments. - Support - [Support](/support): Here you will find details on how to contact the Descope Support team - [Collect Debugging Information](/support/generate-debug-info): Learn how to generate debugging information when reporting issues to the Descope team. - [Changelog](https://ideas.descope.works/changelog) - [Feature Requests](/support/descope-fr-portal): Here you will find details on how to use the Descope Feature Request Portal. - [Account and Project Notifications](/support/mail-subscription): Learn how to subscribe to email-based project and account notifications with Descope. - [Deleting Your Account](/support/delete-company): Here you will find details on how to delete your account and company. - [Community Forum](https://www.descope.com/community) - API Reference - [REST API Reference](/api): Use the Descope REST API to build authentication and user management for your app while retaining full control over your UI. - [OpenAPI Specification](/api/openapi-spec): Download the Descope OpenAPI (Swagger) specification to import into Postman, generate clients, or browse with any OpenAPI tool. - One-Time Password (OTP) - [OTP Authentication API Overview](/api/otp): Use the Descope REST API to build one-time password (OTP) authentication for your application. - Email - [Sign-Up](/api/otp/email/sign-up): ### Sign-up new end user by sending an OTP code via email Initiate a sign-up process by sending a One-Time Password (OTP) to a new end user. Descope will generate and deliver the OTP code to the email address specified. Sending multiple OTP codes (for example, when an end user tries to sign-up a second or third time) will invalidate any OTP code that has already been sent. This endpoint will return an empty response object when it completes successfully. The endpoint will return a failure code if the email address is already registered. ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/email/verify-otp) endpoint to complete the user sign-up process. After successfully verifying OTP code the end user will be signed-in. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Use the [Sign-In](/api/otp/email/sign-in) endpoint to sign-in an existing end user. - Use the [Sign-In with Auto Sign-up](/api/otp/email/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In](/api/otp/email/sign-in): ### Sign-in existing end user by sending an OTP code via email Initiate a sign-in process by sending a One-Time Password (OTP) to an existing end user. Descope will generate and deliver the OTP code to the email address specified. Sending multiple OTP codes (for example, when an end user tries to sign-in a second or third time) will invalidate any OTP code that has already been sent. This endpoint will return an empty response object when it completes successfully. The endpoint will return a failure code if the email address is not yet registered. ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/email/verify-otp) endpoint to complete the user sign-in process. After successfully verifying the code the end user will be signed-in. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/otp/email/sign-up) endpoint to sign-up a new end user. - Use the [Sign-In with Auto Sign-up](/api/otp/email/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In with Auto Sign-up](/api/otp/email/sign-in-auto-sign-up): ### Sign-in end user (with automatic sign-up) by sending an OTP code via email Initiate a process that implements both sign-in and sign-up using a single endpoint. Descope will generate and deliver the One-Time Password (OTP) to the end user via email. If the email address is already registered (the end user exists) the user will be signed in. If the email address is not registered (the end user is not yet registered) the user will be signed up. Sending multiple OTP codes (for example, when an end user tries to sign-up/sign-in a second or third time) will invalidate any OTP code that has already been sent. This endpoint will return an empty response object when it completes successfully. ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/email/verify-otp) endpoint to complete the user sign-in process. After successfully verifying the code the end user will be signed-in. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/otp/email/sign-up) endpoint if you want a sign-up flow that will fail if the end user is already registered. - Use the [Sign-In](/api/otp/email/sign-in) endpoint if you want a sign-in flow that will fail if the end user isn't yet registered. - [Verify OTP Code](/api/otp/email/verify-otp): ### Verify the validity of an OTP code sent via email Verify that the OTP code entered by the end user matches the OTP code that was sent. The Verify OTP code endpoint completes the OTP via email flow for: - [Sign-Up](/api/otp/email/sign-up) - [Sign-In](/api/otp/email/sign-in) - [Sign-In with Auto Sign-up](/api/otp/email/sign-in-auto-sign-up) - [Update Email](/api/otp/email/update-email) The response object includes the session JWT `sessionJwt` and refresh JWT `refreshJwt` when the endpoint completes successfully, and the end user will be signed in. For an update email flow, the new email address will replace the original email address. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - [Update Email](/api/otp/email/update-email): ### Update Email Address of Existing User Update the email of an existing end user by sending an OTP code to the new email address. After successfully verifying the code the new email address will be used to deliver new OTP messages via email. The bearer token requires both the ProjectId and refresh JWT in the format `:`, and can therefore only be run for end users who are currently signed-in. This endpoint will return an empty response object when it completes successfully. Descope allows you to associating multiple login IDs for a user during API update calls. For details on how this feature works, please review the details [here](/manage/users#associating-multiple-login-ids-for-a-user). ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/email/verify-otp) endpoint to complete the update process. After successfully verifying the code the new email address will replace the original email address. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - See the [Verify OTP Code](/api/otp/email/verify-otp) endpoint, which will return the Refresh Jwt needed. - Text Message (SMS) - [Sign-Up](/api/otp/sms/sign-up): ### Sign-up new end user by sending an OTP code via SMS Initiate a sign-up process by sending a One-Time Password (OTP) to a new end user. Descope will generate and deliver the OTP code via SMS to the phone number specified. Sending multiple OTP codes (for example, when an end user tries to sign-up a second or third time) will invalidate any OTP code that has already been sent. This endpoint will return an empty response object when it completes successfully. The endpoint will return a failure code if the phone number is already registered. ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/sms/verify-otp) endpoint to complete the user sign-up process. After successfully verifying the OTP code the end user will be signed-in. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - Use the [Sign-In](/api/otp/sms/sign-in) endpoint to sign-in an existing end user. - Use the [Sign-In with Auto Sign-up](/api/otp/sms/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In](/api/otp/sms/sign-in): ### Sign-in existing end user by sending an OTP code via SMS Initiate a sign-in process by sending a One-Time Password (OTP) to an existing end user. Descope will generate and deliver the OTP code to the phone number specified. Sending multiple OTP codes (for example, when an end user tries to sign-in a second or third time) will invalidate any OTP code that has already been sent. This endpoint will return an empty response object when it completes successfully. The endpoint will return a failure code if the phone number is not yet registered. ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/sms/verify-otp) endpoint to complete the user sign-in process. After successfully verifying the code the end user will be signed-in. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/otp/sms/sign-up) endpoint to sign-up a new end user. - Use the [Sign-In with Auto Sign-up](/api/otp/sms/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In with Auto Sign-up](/api/otp/sms/sign-in-auto-sign-up): ### Sign-in end user (with automatic sign-up) by sending an OTP code via SMS Initiate a process that implements both sign-in and sign-up using a single endpoint. Descope will generate and deliver the One-Time Password (OTP) to the end user via SMS. If the phone number is already registered (the end user exists) the user will be signed in. If the phone number is not registered (the end user is not yet registered) the user will be signed up. Sending multiple OTP codes (for example, when an end user tries to sign-up/sign-in a second or third time) will invalidate any OTP code that has already been sent. This endpoint will return an empty response object when it completes successfully. ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/sms/verify-otp) endpoint to complete the user sign-in process. After successfully verifying the code the end user will be signed-in. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/otp/sms/sign-up) endpoint if you want a sign-up flow that will fail if the end user is already registered. - Use the [Sign-In](/api/otp/sms/sign-in-auto-sign-up) endpoint if you want a sign-in flow that will fail if the end user isn't yet registered. - [Verify OTP Code](/api/otp/sms/verify-otp): ### Verify the validity of an OTP code via SMS Verify that the OTP code entered by the end user matches the OTP code that was sent. The Verify OTP code endpoint completes the OTP via SMS flow for: - [Sign-Up](/api/otp/sms/sign-up) - [Sign-In](/api/otp/sms/sign-in) - [Sign-In with Auto Sign-up](/api/otp/sms/sign-in-auto-sign-up) - [Update Email](/api/otp/sms/update-phone) The response object includes the session JWT `sessionJwt` and refresh JWT `refreshJwt` when it completes successfully, and the end user will be signed in. For an update phone number flow, the new phone number will replace the original phone number. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - [Update Phone](/api/otp/sms/update-phone): ### Update phone number of Existing User Update the phone number of an existing end user by sending an OTP code to the new phone number. After successfully verifying the code the new phone number will be used to deliver new OTP messages via SMS. The bearer token requires both the ProjectId and refresh JWT in the format `:`, and can therefore only be run for end users who are currently signed-in. This endpoint will return an empty response object when it completes successfully. Descope allows you to associating multiple login IDs for a user during API update calls. For details on how this feature works, please review the details [here](/manage/users#associating-multiple-login-ids-for-a-user). ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/sms/verify-otp) endpoint to complete the update process. After successfully verifying the code the newphone number will replace the original phone number. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - Successful execution will return an empty body - To try this endpoint - need to provide `Project ID:Refresh JWT` as bearer. You can acquire the Session JWT by signing in the user and collecting it from the response. - Voice Message (Phone) - [Sign-Up](/api/otp/phone/sign-up): ### Sign-up new end user by sending an OTP code via Voice Initiate a sign-up process by sending a One-Time Password (OTP) to a new end user. Descope will generate and deliver the OTP code via Voice to the phone number specified. Sending multiple OTP codes (for example, when an end user tries to sign-up a second or third time) will invalidate any OTP code that has already been sent. This endpoint will return an empty response object when it completes successfully. The endpoint will return a failure code if the phone number is already registered. ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/phone/verify-otp) endpoint to complete the user sign-up process. After successfully verifying the OTP code the end user will be signed-in. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - Use the [Sign-In](/api/otp/phone/sign-in) endpoint to sign-in an existing end user. - Use the [Sign-In with Auto Sign-up](/api/otp/phone/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In](/api/otp/phone/sign-in): ### Sign-in existing end user by sending an OTP code via Voice Initiate a sign-in process by sending a One-Time Password (OTP) to an existing end user. Descope will generate and deliver the OTP code to the phone number specified. Sending multiple OTP codes (for example, when an end user tries to sign-in a second or third time) will invalidate any OTP code that has already been sent. This endpoint will return an empty response object when it completes successfully. The endpoint will return a failure code if the phone number is not yet registered. ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/phone/verify-otp) endpoint to complete the user sign-in process. After successfully verifying the code the end user will be signed-in. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/otp/phone/sign-up) endpoint to sign-up a new end user. - Use the [Sign-In with Auto Sign-up](/api/otp/phone/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In with Auto Sign-up](/api/otp/phone/sign-in-auto-sign-up): ### Sign-in end user (with automatic sign-up) by sending an OTP code via Voice Initiate a process that implements both sign-in and sign-up using a single endpoint. Descope will generate and deliver the One-Time Password (OTP) to the end user via Voice. If the phone number is already registered (the end user exists) the user will be signed in. If the phone number is not registered (the end user is not yet registered) the user will be signed up. Sending multiple OTP codes (for example, when an end user tries to sign-up/sign-in a second or third time) will invalidate any OTP code that has already been sent. This endpoint will return an empty response object when it completes successfully. ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/phone/verify-otp) endpoint to complete the user sign-in process. After successfully verifying the code the end user will be signed-in. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/otp/phone/sign-up) endpoint if you want a sign-up flow that will fail if the end user is already registered. - Use the [Sign-In](/api/otp/phone/sign-in-auto-sign-up) endpoint if you want a sign-in flow that will fail if the end user isn't yet registered. - [Verify OTP Code](/api/otp/phone/verify-otp): ### Verify the validity of an OTP code via Voice Verify that the OTP code entered by the end user matches the OTP code that was sent. The Verify OTP code endpoint completes the OTP via Voice flow for: - [Sign-Up](/api/otp/phone/sign-up) - [Sign-In](/api/otp/phone/sign-in) - [Sign-In with Auto Sign-up](/api/otp/phone/sign-in-auto-sign-up) - [Update Phone](/api/otp/phone/update-phone) The response object includes the session JWT `sessionJwt` and refresh JWT `refreshJwt` when it completes successfully, and the end user will be signed in. For an update phone number flow, the new phone number will replace the original phone number. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - [Update Phone](/api/otp/phone/update-phone): ### Update phone number of Existing User Update the phone number of an existing end user by sending an OTP code to the new phone number. After successfully verifying the code the new phone number will be used to deliver new OTP messages via Voice. The bearer token requires both the ProjectId and refresh JWT in the format `:`, and can therefore only be run for end users who are currently signed-in. This endpoint will return an empty response object when it completes successfully. Descope allows you to associating multiple login IDs for a user during API update calls. For details on how this feature works, please review the details [here](/manage/users#associating-multiple-login-ids-for-a-user). ### Next Steps Verify the OTP code using the [Verify OTP Code](/api/otp/phone/verify-otp) endpoint to complete the update process. After successfully verifying the code the newphone number will replace the original phone number. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email address and phone number. - Successful execution will return an empty body - To try this endpoint - need to provide `Project ID:Refresh JWT` as bearer. You can acquire the Session JWT by signing in the user and collecting it from the response. - Magic Link - [Magic Link Authentication API Overview](/api/magic-link): Use the Descope REST API to build magic link authentication for your application. - Email - [Sign-Up](/api/magic-link/email/sign-up): ### Sign-up new end user by sending a magic link via email Initiate a sign-up process by sending a magic link to a new end user. Descope will generate and deliver a clickable magic link to the email address specified. The clickable magic link is made up of two parts - the URI you provide in the `URI` field and the magic link token generated by Descope. For example, if `URI=https://app.mycompany.com/magiclink/verify`, the clickable magic link will be `https://app.mycompany.com/magiclink/verify?t=magic-link-token.` Magic links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/magiclink), so sending multiple magic links (for example, when an end user tries to sign-up a second or third time) does not invalidate magic links that have already been sent. The endpoint will return a failure code if the email address is already registered. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. ### Next Steps Verify the magic link token using the [Verify Token](/api/magic-link/verification/verify-token) endpoint. ### See Also - See [Magic link Authentication](/auth-methods/magic-link/with-sdks/client#introduction) for details about implementing magic links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Use the [Sign-In](/api/magic-link/email/sign-in) endpoint to sign-in an existing end user. - Use the [Sign-In with Auto Sign-up](/api/magic-link/email/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In](/api/magic-link/email/sign-in): ### Sign-in existing end user by sending a magic link via email Initiate a sign-in process by sending a magic link to an existing end user. Descope will generate and deliver a clickable magic link to the email address specified. The clickable magic link is made up of two parts - the URI you provide in the `URI` field and the magic link token generated by Descope. For example, if `URI=https://app.mycompany.com/magiclink/verify`, the clickable magic link will be `https://app.mycompany.com/magiclink/verify?t=magic-link-token.` Magic links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/magiclink), so sending multiple magic links (for example, when an end user tries to sign-up a second or third time) does not invalidate prior magic links that have already been sent. The endpoint will return a failure code if the email address is not registered. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. ### Next Steps Verify the magic link token using the [Verify Token](/api/magic-link/verification/verify-token) endpoint. ### See Also - See [Magic link Authentication](/auth-methods/magic-link/with-sdks/client#introduction) for details about implementing magic links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/magic-link/email/sign-up) endpoint to sign-up a new end user. - Use the [Sign-In with Auto Sign-up](/api/magic-link/email/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In with Auto Sign-up](/api/magic-link/email/sign-in-auto-sign-up): ### Sign-in end user (with automatic sign-up) by sending a magic link via email Initiate a process that implements both sign-in and sign-up using a single endpoint. Descope will generate and deliver a clickable magic link to the email address specified. If the email address is already registered (the end user has already registered) the user will be signed in. If the email address is not registered (the end user is not yet registered) the user will be signed up. The clickable magic link is made up of two parts - the URI you provide in the `URI` field and the magic link token generated by Descope. For example, if `URI=https://app.mycompany.com/magiclink/verify`, the clickable magic link will be `https://app.mycompany.com/magiclink/verify?t=magic-link-token.` Magic links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/magiclink), so sending multiple magic links (for example, when an end user tries to sign-up a second or third time) does not invalidate prior magic links that have already been sent. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. ### Next Steps Verify the magic link token using the [Verify Token](/api/magic-link/verification/verify-token) endpoint. ### See Also - See [Magic link Authentication](/auth-methods/magic-link/with-sdks/client#introduction) for details about implementing magic links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/magic-link/email/sign-up) endpoint if you want a sign-up flow that will fail if the end user is already registered. - Use the [Sign-In](/api/magic-link/email/sign-in) endpoint if you want a sign-in flow that will fail if the end user isn't yet registered. - [Update Email](/api/magic-link/email/update-email): ### Update email of end user by sending magic link via email Update the email address of an existing end user by sending a magic link to the new email address. Descope will generate and deliver a clickable magic link to the new email address specified. After successfully verifying the magic link token the new email address will be used to deliver new magic links via email. The clickable magic link is made up of two parts - the URI you provide in the `URI` field and the magic link token generated by Descope. For example, if `URI=https://app.mycompany.com/magiclink/verify`, the clickable magic link will be `https://app.mycompany.com/magiclink/verify?t=magic-link-token.` Magic links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/magiclink), so sending multiple magic links (for example, when an end user tries to sign-up a second or third time) does not invalidate prior magic links that have already been sent. The bearer token requires both the ProjectId and refresh JWT in the format `:`, and can therefore only be run for end users who are currently signed-in. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. Descope allows you to associating multiple login IDs for a user during API update calls. For details on how this feature works, please review the details [here](/manage/users#associating-multiple-login-ids-for-a-user). ### Next Steps Verify the magic link token using the [Verify Token](/api/magic-link/verification/verify-token) endpoint. ### See Also - See [Magic link Authentication](/auth-methods/magic-link) for details about implementing magic links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Text Message (SMS) - [Sign-Up](/api/magic-link/sms/sign-up): ### Sign-up new end user by sending a magic link via SMS Initiate a sign-up process by sending a magic link to a new end user. Descope will generate and deliver a clickable magic link to the phone number specified. The clickable magic link is made up of two parts - the URI you provide in the `URI` field and the magic link token generated by Descope. For example, if `URI=https://app.mycompany.com/magiclink/verify`, the clickable magic link will be `https://app.mycompany.com/magiclink/verify?t=magic-link-token.` Magic links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/magiclink), so sending multiple magic links (for example, when an end user tries to sign-up a second or third time) does not invalidate magic links that have already been sent. The endpoint will return a failure code if the email address is already registered. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. ### Next Steps Verify the magic link token using the [Verify Token](/api/magic-link/verification/verify-token) endpoint. ### See Also - See [Magic link Authentication](/auth-methods/magic-link) for details about implementing magic links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Use the [Sign-In](/api/magic-link/sms/sign-up) endpoint to sign-in an existing end user. - Use the [Sign-In with Auto Sign-up](/api/magic-link/sms/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In](/api/magic-link/sms/sign-in): ### Sign-in existing end user by sending a magic link via SMS Initiate a sign-in process by sending a magic link to an existing end user. Descope will generate and deliver a clickable magic link as an SMS to the phone number specified. The clickable magic link is made up of two parts - the URI you provide in the `URI` field and the magic link token generated by Descope. For example, if `URI=https://app.mycompany.com/magiclink/verify`, the clickable magic link will be `https://app.mycompany.com/magiclink/verify?t=magic-link-token.` Magic links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/magiclink), so sending multiple magic links (for example, when an end user tries to sign-up a second or third time) does not invalidate prior magic links that have already been sent. The endpoint will return a failure code if the email address is not registered. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. ### Next Steps Verify the magic link token using the [Verify Token](/api/magic-link/verification/verify-token) endpoint. ### See Also - See [Magic link Authentication](/auth-methods/magic-link) for details about implementing magic links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/magic-link/sms/sign-up) endpoint to sign-up a new end user. - Use the [Sign-In with Auto Sign-up](/api/magic-link/sms/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In with Auto Sign-up](/api/magic-link/sms/sign-in-auto-sign-up): ### Sign-in end user (with automatic sign-up) by sending a magic link via SMS Initiate a process that implements both sign-in and sign-up using a single endpoint. Descope will generate and deliver a clickable magic link as an SMS to the phone number specified. If the phone number is already registered (the end user has already registered) the user will be signed in. If the email address is not registered (the end user is not yet registered) the user will be signed up. The clickable magic link is made up of two parts - the URI you provide in the `URI` field and the magic link token generated by Descope. For example, if `URI=https://app.mycompany.com/magiclink/verify`, the clickable magic link will be `https://app.mycompany.com/magiclink/verify?t=magic-link-token.` Magic links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/magiclink), so sending multiple magic links (for example, when an end user tries to sign-up a second or third time) does not invalidate prior magic links that have already been sent. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. ### Next Steps Verify the magic link token using the [Verify Token](/api/magic-link/verification/verify-token) endpoint. ### See Also - See [Magic link Authentication](/auth-methods/magic-link) for details about implementing magic links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/magic-link/sms/sign-up) endpoint if you want a sign-up flow that will fail if the end user is already registered. - Use the [Sign-In](/api/magic-link/sms/sign-in) endpoint if you want a sign-in flow that will fail if the end user isn't yet registered. - [Update Phone Number](/api/magic-link/sms/update-phone): ### Update phone number of end user by sending magic link via SMS Update the phone number of an existing end user by sending a magic link to the new phone number. Descope will generate and deliver a clickable magic link as an SMS to the new phone number specified. After successfully verifying the magic link token the new phone number will be used to deliver new magic links via SMS. The clickable magic link is made up of two parts - the URI you provide in the `URI` field and the magic link token generated by Descope. For example, if `URI=https://app.mycompany.com/magiclink/verify`, the clickable magic link will be `https://app.mycompany.com/magiclink/verify?t=magic-link-token.` Magic links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/magiclink), so sending multiple magic links (for example, when an end user tries to sign-up a second or third time) does not invalidate prior magic links that have already been sent. The bearer token requires both the ProjectId and refresh JWT in the format `:`, and can therefore only be run for end users who are currently signed-in. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. Descope allows you to associating multiple login IDs for a user during API update calls. For details on how this feature works, please review the details [here](/manage/users#associating-multiple-login-ids-for-a-user). ### Next Step Verify the magic link token using the [Verify Token](/api/magic-link/verification/verify-token) endpoint. ### See Also - See [Magic link Authentication](/auth-methods/magic-link) for details about implementing magic links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Verification - [Verify Token](/api/magic-link/verification/verify-token): ### Verify the magic link token from the end user Verify that the magic link token in the URL clicked by the end user matches and has not expired. This endpoint completes the magic link flow for: * sign up * [Sign-Up via email](/api/magic-link/email/sign-up) * [Sign-Up via SMS](/api/magic-link/sms/sign-up) * sign-in * [Sign-In via email](/api/magic-link/email/sign-in) * [Sign-In via SMS](/api/magic-link/sms/sign-in) * sign-in with auto sign-up * [Sign-In with Auto Sign-up via email](/api/magic-link/email/sign-in-auto-sign-up) * [Sign-In with Auto Sign-up via SMS](/api/magic-link/sms/sign-in-auto-sign-up) * update data * [update email](/api/magic-link/email/sign-up) * [update phone number](/api/magic-link/email/sign-up) ### Next Steps The response object will contain the user's details including the session and refresh JWTs. ### See Also - See [Magic link Authentication](/auth-methods/magic-link/with-sdks/client#introduction) for details about implementing magic links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Embedded Link - [Generate Embedded Link](/api/magic-link/embedded-link/generate): ### Generate an embedded link for an existing user Initiate a sign-in process by generating an embdedded link for an existing user utilizing a management key. The endpoint will return a token which can then be verified using the Magic Link [Verify Token](/api/magic-link/verification/verify-token) endpoint. ### Next Steps Verify the embedded link token using the [Verify Token](/api/magic-link/verification/verify-token) endpoint. ### See Also - See [Embedded link Authentication](/customize/auth/embeddedlink/) for details about implementing embedded links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Enchanted Link - [Enchanted Link Authentication API Overview](/api/enchanted-link): Use the Descope REST API to build enchanted link authentication for your application. - [Sign-Up](/api/enchanted-link/sign-up): ### Sign-up new end user by sending an enchanted link via email Initiate a sign-up process by sending an enchanted link to a new end user. Descope will generate and deliver 3 clickable links to the email address specified, each is numbered with random 2 digit number. When you initiate the enchanted link, the `linkId` will be returned. This `linkId` needs to be displayed to the user to indicate which link for the user to click once they receive the email. Only when the correct link is clicked will the user be successfully verified and logged in. Each clickable link is made up of two parts - the URI you provide in the `URI` field and the enchanted link token generated by Descope. For example, if `URI=https://app.mycompany.com/enchantedlink/verify`, the clickable enchanted link will be `https://app.mycompany.com/enchantedlink/verify?t=enchanted-link-token.` Enchanted links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/enchantedlink), so sending multiple enchanted links (for example, when an end user tries to sign-up a second or third time) does not invalidate links that have already been sent. The return body will include `linkId` and `pendigRef`. The `linkId` (a 2 digit number) should be presented to the user, so they will know which link to click in the delivered email. The endpoint will return a failure code if the email address is already registered. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. ### Next Steps 1. Verify the enchanted link token using the [Verify Token](/api/enchanted-link/verify-token) endpoint. 2. Poll for the successful completion of the token verification using the [Poll Session](/api/enchanted-link/poll-session) endpoint, providing the `pendingRef` returned by the this endpoint. ### See Also - See [Enchanted link Authentication](/api/enchantedlink/) for details about implementing enchanted links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Use the [Sign-In](/api/enchanted-link/sign-in) endpoint to sign-in an existing end user. - Use the [Sign-In with Auto Sign-up](/api/enchanted-link/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In](/api/enchanted-link/sign-in): ### Sign-in existing user by sending an enchanted link via email Initiate a sign-in process by sending an enchanted link to a new end user. Descope will generate and deliver 3 clickable links to the email address specified, each is numbered with random 2 digit number. When you initiate the enchanted link, the `linkId` will be returned. This `linkId` needs to be displayed to the user to indicate which link for the user to click once they receive the email. Only when the correct link is clicked will the user be successfully verified and logged in. Each clickable link is made up of two parts - the URI you provide in the `URI` field and the enchanted link token generated by Descope. For example, if `URI=https://app.mycompany.com/enchantedlink/verify`, the clickable enchanted link will be `https://app.mycompany.com/enchantedlink/verify?t=enchanted-link-token.` Enchanted links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/enchantedlink), so sending multiple enchanted links (for example, when an end user tries to sign-up a second or third time) does not invalidate links that have already been sent. The return body will include `linkId` and `pendigRef`. The `linkId` (a 2 digit number) should be presented to the user, so they will know which link to click in the delivered email. The endpoint will return a failure code if the email address is already registered. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. ### Next Steps 1. Verify the enchanted link token using the [Verify Token](/api/enchanted-link/verify-token) endpoint. 2. Poll for the successful completion of the token verification using the [Poll Session](/api/enchanted-link/poll-session) endpoint, providing the `pendingRef` returned by the this endpoint. ### See Also - See [Enchanted link Authentication](/api/enchantedlink/) for details about implementing enchanted links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/enchanted-link/sign-up) endpoint to sign-up a new end user. - Use the [Sign-In with Auto Sign-up](/api/enchanted-link/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Sign-In with Auto Sign-Up](/api/enchanted-link/sign-in-auto-sign-up): ### Sign-in end user (with automatic sign-up) by sending an enchanted link via email Initiate a process that implements both sign-in and sign-up using a single endpoint. If the email address is already registered (the end user has already registered) the user will be signed in. If the email address is not registered (the end user is not yet registered) the user will be signed up. Descope will generate and deliver 3 clickable links to the email address specified, each is numbered with random 2 digit number. When you initiate the enchanted link, the `linkId` will be returned. This `linkId` needs to be displayed to the user to indicate which link for the user to click once they receive the email. Only when the correct link is clicked will the user be successfully verified and logged in. Each clickable link is made up of two parts - the URI you provide in the `URI` field and the enchanted link token generated by Descope. For example, if `URI=https://app.mycompany.com/enchantedlink/verify`, the clickable enchanted link will be `https://app.mycompany.com/enchantedlink/verify?t=enchanted-link-token.` Enchanted links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/enchantedlink), so sending multiple enchanted links (for example, when an end user tries to sign-up a second or third time) does not invalidate links that have already been sent. The return body will include `linkId` and `pendigRef`. The `linkId` (a 2 digit number) should be presented to the user, so they will know which link to click in the delivered email. The endpoint will return a failure code if the email address is already registered. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. ### Next Steps 1. Verify the enchanted link token using the [Verify Token](/api/enchanted-link/verify-token) endpoint. 2. Poll for the successful completion of the token verification using the [Poll Session](/api/enchanted-link/poll-session) endpoint, providing the `pendingRef` returned by the this endpoint. ### See Also - See [Enchanted link Authentication](/api/enchantedlink/) for details about implementing enchanted links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - Use the [Sign-Up](/api/enchanted-link/sign-up) endpoint to sign-up a new end user. - Use the [Sign-In with Auto Sign-up](/api/enchanted-link/sign-in-auto-sign-up) endpoint to create a single sign-up and sign-in flow, which will create a new end user if they are not already registered. - [Verify Token](/api/enchanted-link/verify-token): ### Verify Enchanted Link token from user Verify that the enchanted link token in the URL clicked by the end user matches and has not expired. This endpoint completes the enchanted link flow for: * sign up * [Sign-Up via email](/api/enchanted-link/sign-up) * sign-in * [Sign-In via email](/api/enchanted-link/sign-in) * sign-in with auto sign-up * [Sign-In with Auto Sign-up via email](/api/enchanted-link/sign-in-auto-sign-up) * Update data * [update email](/api/enchanted-link/update-email) ### Next Steps Poll for the successful completion of the token verification using the [Poll Session](/api/enchanted-link/poll-session) endpoint, providing the `pendingRef` returned by the this endpoint. The response object will be empty when this endpoint completes successfully. The session information will be returned by the the [Poll Session](/api/enchanted-link/poll-session) endpoint. ### See Also - See [Enchanted link Authentication](/api/enchantedlink/) for details about implementing enchanted links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - [Poll Session](/api/enchanted-link/poll-session): ### Poll user session for successful completion of token verification This endpoint is used to wait for the enchanted link verification by the end user. Use this endpoint in a poling way, until it returns a successful JWT, or timeout error. The response object includes the session JWT `sessionJwt` and refresh JWT `refreshJwt` when this endpoint completes successfully. ### See Also - See [Enchanted link Authentication](/api/enchantedlink/) for details about implementing enchanted links. - [Update Email](/api/enchanted-link/update-email): ### Update email of end user by sending enchanted link via email Update the email address of an existing end user by sending an enchanted link to the new email address. Descope will generate and deliver 3 clickable links to the email address specified, each is numbered with random 2 digit number. Only the right link (based on the number returned will be successfully verified when clicked) Each clickable link is made up of two parts - the URI you provide in the `URI` field and the enchanted link token generated by Descope. For example, if `URI=https://app.mycompany.com/enchantedlink/verify`, the clickable enchanted link will be `https://app.mycompany.com/enchantedlink/verify?t=enchanted-link-token.` Enchanted links expire in the time frame configured in the [Descope console](https://app.descope.com/settings/authentication/enchantedlink), so sending multiple enchanted links (for example, when an end user tries to sign-up a second or third time) does not invalidate links that have already been sent. The bearer token requires both the ProjectId and refresh JWT in the format `:`, and can therefore only be run for end users who are currently signed-in. Note that `URI` is an optional parameter. If omitted - the project setting will apply. If provided - it should to be part of the allowed `Approved Domains` configured in the project settings. Once the token is successfully verified - the email address will be updated. Descope allows you to associating multiple login IDs for a user during API update calls. For details on how this feature works, please review the details [here](/manage/users#associating-multiple-login-ids-for-a-user). ### Next Steps 1. Verify the enchanted link token using the [Verify Token](/api/enchanted-link/verify-token) endpoint. 2. Poll for the successful completion of the token verification using the [Poll Session](/api/enchanted-link/poll-session) endpoint, providing the `pendingRef` returned by the this endpoint. ### See Also - See [Enchanted link Authentication](/api/enchantedlink/) for details about implementing enchanted links. - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Social Login (OAuth) - [OAuth Social Login API Overview](/api/oauth): Use the Descope REST API to build OAuth social logins for your application. - [Sign-Up / Sign-In](/api/oauth/sign-up-sign-in): ### Authorize end user to sign-up or sign-in using social login credentials Initiate a social login (OAuth) sign-up or sign-in process for an end user. Descope will coordinate the authorization process with the OAUth provider specified in the `provider` field. Specify the URL you want to redirect the end user to after a successful sign-in in the `redirectURL` parameter. When the OAuth authorization completes successfully, the endpoint returns a URL `url` that has a unique code `` appended as a URL parameter to the `redirectURL` you provided. For example, if `redirectURL = https://oauth.mycompany.com/shopping.htm` then `url = https://oauth.mycompany.com/shopping.htm?code=`. The unique code will be exchanged for a valid user object in the next step. After the end user successfully authenticates with the OAuth provider the end user session is redirected to `url`. ### Next Steps Call the [Exchange Code](/api/oauth/exchange-code) endpoint from the flow that responds to the URL specified in the `redirectURL` field, to exchange the unique code for a user session object. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on the stepup, mfa, and customClaims parameters. - [Create Redirect URI for Sign-In Request](/api/oauth/redirect-sign-in): ### Create an OAuth Redirect URI for user Sign-In Request This endpoint allows you to create an OAuth Redirect URI for user Sign-Up Request. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - [Create Redirect URI for Sign-Up Request](/api/oauth/redirect-sign-up): ### Create an OAuth Redirect URI for user Sign-In Request This endpoint allows you to create an OAuth Redirect URI for user Sign-In Request. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - [Starts a full OAuth flow using native APIs](/api/oauth/o-auth-native-start): Starts a full OAuth flow using native APIs - [Exchange Code](/api/oauth/exchange-code): ### Exchange OAuth code for Descope user session This endpoint will exchange the OAuth code for the Descope session information needed for managing the end user session. Call this endpoint from your code flow that responds to the `url` that was returned by the [Sign-In](/api/oauth/sign-up-sign-in) endpoint. The unique code `` is appended as a URL parameter: `code=`, for example, `url = https://oauth.mycompany.com/shopping.htm?code=`. ### Next Steps 1. Extract the unique code `` from the URL parameter. 2. Call this endpoint, passing the `` as the request parameter The response object includes the session JWT (sessionJwt) and refresh JWT (refreshJwt) when this endpoint completes successfully. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - [Finishes a full OAuth flow using native APIs](/api/oauth/o-auth-native-finish): Finishes a full OAuth flow using native APIs - [Creating OAuth redirect URI for update user request](/api/oauth/redirect-update-user): Creating OAuth redirect URI for update user request - Google One Tap - [Exchanges one tap id token for a JWT](/api/onetap/exchange-one-tap-id-token): Exchanges one tap id token for a JWT - [Verifies one tap id token for a code](/api/onetap/verify-one-tap-id-token): Verifies one tap id token for a code - [Get Google One Tap Client ID Configuration](/api/onetap/get-one-tap-client-id): Get the client ID configuration for Google One Tap integration - Authenticator App (TOTP) - [TOTP API Overview](/api/totp): Use the Descope REST API to add TOTP authenticator apps to your application. - [Sign-Up](/api/totp/sign-up): ### Sign-up new end user via TOTP Initiate a TOTP sign-up process for a new end user. Descope will generate a TOTP key (also called a secret or seed) that will be entered into the end user's authenticator app so that TOTP codes can be successfully verified. The new end user will be registered after the full TOTP sign-up flow has successfully completed. If the end user is already registered use the [add/update](/api/totp/add-update-key) endpoint to add TOTP funtionality to an existing end user, to prevent the same person being registered twice. ### Next Steps 1. Display the TOTP key so it can be entered into their authenticator app. The TOTP key is returned in the response object in three ways, to ensure it can easily be entered into the end user's authenticator app. 2. Prompt the end user user for a TOTP code generated by their authenticator app. 3. Verify the TOTP code using the [Sign-In / Verify](/api/totp/sign-in-verify) endpoint to complete the sign-in process. After successfully verifying the TOTP code the new end user will be registered using the details you provided in the body of this endpoint. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Use the [add/update](/api/totp/add-update-key) endpoint to add TOTP funtionality to an existing end user. - [Sign-In / Verify](/api/totp/sign-in-verify): ### Verify the TOTP of an end user Verify the TOTP code of an end user. This endpoint is the final API call for the following TOTP flows: * Sign-In - If the end user is already registered, this end-point is the only call you need to sign-in that user. * Sign-Up - If you are implementing a sign-up flow, this endpoint will verify the TOTP code and complete the sign-up process * Add/ Update - If you are implementing an Add / Update flow, this endpoint completes the process of adding/updating the TOTP key for that user. The response object includes the session JWT `sessionJwt` and refresh JWT `refreshJwt` when the endpoint completes successfully, and the end user will be signed in. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on loginOptions. - [Add / Update Key](/api/totp/add-update-key): ### Add or update TOTP key for existing end user Initiate a flow to add TOTP functionality for an existing end user, or to update the TOTP key for an existing end user. Descope will generate a TOTP key (also called a secret or seed) that will be entered into the end user's authenticator app so that TOTP codes can be successfully verified. The new end user will be registered after the full Add / Update TOTP flow has successfully completed. The bearer token requires both the ProjectId and refresh JWT in the format `:`, and can therefore only be run for end users who are currently signed-in. If the end user is not yet registered use the [Sign-Up](/api/totp/sign-up) endpoint to register the user. ### Next Steps 1. Display the TOTP key to the end user so the key can be entered into the authenticator app. Use any of the following methods to display the key to your end user: * (recommended) Redirect the end user session to the `provisioningURL` returned in the response body. The URL displays the key as a QR code that can be scanned directly from the authenticator app. * Render the QR code using your own web page using the `image` (the QR code as Base64) returned in the response body. * If your end user cannot scan a QR code, present the `key` returned in the response body so the key can be pasted into their authenticator app. If the authenticator app prompts, the end user must select key type: "time based". 2. Prompt the end user user for a TOTP code generated by their authenticator app. 3. Verify the TOTP code using the [Sign-In / Verify](/api/totp/sign-in-verify) endpoint to complete the Add / Update process. After successfully verifying the TOTP code the new TOTP key will be used to validate future TOTP code. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - nOTP - [nOTP Authentication API Overview](/api/notp): Use the Descope REST API to build an authentication process that relies on nOTP and WhatsApp. - [Sign-Up](/api/notp/sign-up): Create a new user using NOTP - [Sign-In](/api/notp/sign-in): Login a user using NOTP - [Sign-In with Auto Sign-Up](/api/notp/sign-in-auto-sign-up): Login in using NTOP. If the user does not exist, a new user will be created with the given identifier - [Get NoTP Pending Session](/api/notp/pending-session): Get a session that was generated by NOTP Sign in / Sign up request, and verified with Verify request - Single Sign-On (SSO) - [SAML SSO API Overview](/api/sso): Use the Descope REST API to add SAML single sign-on (SSO) for your application. - [Start SSO](/api/sso/start-sso): ### Authorize end user to sign-in using SAML SSO Initiate a SAML SSO (Single Sign-On, "sign-in" in Descope terminology) process for an end user. Descope will coordinate the sign-in process with the service provider. Specify the URL you want to redirect the end user to after a successful sign-in in the `redirectURL` parameter. When the SSO sign-in completes successfully, the endpoint returns a URL `url` that has a unique code ``, also called a token) appended as a URL parameter to the `redirectURL` you provided. For example, if `redirectURL = https://sso.mycompany.com/mywork.htm` then `url = https://sso.mycompany.com/mywork.htm?code=`. The unique code will be exchanged for a valid user object in the next step. After the end user has been successfully authenticated with the identity provider (IdP) the end user session is redirected to `url`. ### Next Steps Call the [Exchange Code](/api/sso/exchange-code) endpoint from the flow that responds to the URL specified in the `redirectURL` field, to exchange the unique code for a user session object. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - See [User Login Options](/api/overview#user-login-options) for further details on the stepup, mfa, and customClaims parameters. - [Exchange Code](/api/sso/exchange-code): ### Exchange OAuth code for Descope user session This endpoint will exchange the OAuth code for the Descope session information needed for managing the end user session. Call this endpoint from your code flow that responds to the `url` that was returned by the [Sign-In](/api/oauth/sign-up-sign-in) endpoint. The unique code `` is appended as a URL parameter: `code=`, for example, `url = https://oauth.mycompany.com/shopping.htm?code=`. ### Next Steps 1. Extract the unique code `` from the URL parameter. 2. Call this endpoint, passing the `` as the request parameter The response object includes the session JWT (sessionJwt) and refresh JWT (refreshJwt) when this endpoint completes successfully. ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - WebAuthn - [Finalize Add WebAuthn](/api/web-authn/web-authn-device-add-finish): Finalize adding a new WebAuthn device - [Add WebAuthn Device](/api/web-authn/web-authn-device-add-start): Add a new WebAuthn device to an existing user - [User Sign-In with Auto Sign-Up](/api/web-authn/web-authn-sign-up-in-start): Use to login with WebAuthn, if user doesn't exist a new user will be created - [Finalize Sign-In](/api/web-authn/web-authn-signin-finish): Finalize a WebAuthn signin operation - [User Sign-In](/api/web-authn/web-authn-signin-start): Login an existing user with WebAuthn - [Finalize Sign-Up](/api/web-authn/web-authn-signup-finish): Finalize a WebAuthn signup operation - [User Sign-Up](/api/web-authn/web-authn-signup-start): Create a new user using WebAuthn - Passwords - [Password Authentication API Overview](/api/passwords): Use the Descope REST API to build password authentication for your application. - [Sign-Up User](/api/passwords/sign-up): ### Sign-Up a new user utilizing password authentication. This endpoint will return the user's JWT. ### Next Steps Verify the user's email to allow for password reset by updating the email via [OTP](/api/otp/email/update-email), [Enchanted Link](/api/enchanted-link/update-email), or [Magic Link](/api/magic-link/email/update-email) Add tenants to the user via [Update User Add Tenant](/api/management/users/update-user-add-tenant) Add roles to the user via [Update User Add Role](/api/management/users/update-user-add-roles) ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Use the [Sign-In](/api/passwords/sign-in) endpoint to sign-in an existing end user. - [Sign-In User](/api/passwords/sign-in): ### Sign-In an existing user utilizing password authentication. This endpoint will return the user's JWT. ### Next Steps Verify the user's email to allow for password reset by updating the email via [OTP](/api/otp/email/update-email), [Enchanted Link](/api/enchanted-link/update-email), or [Magic Link](/api/magic-link/email/update-email) Add tenants to the user via [Update User Add Tenant](/api/management/users/update-user-add-tenant) Add roles to the user via [Update User Add Role](/api/management/users/update-user-add-roles) ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - Use the [Sign-Up](/api/passwords/sign-up) endpoint to sign-up a new end user. - [Replace Password](/api/passwords/replace-password): ### Replace the user's password of an existing user utilizing the password API. ### Next Steps Sign the user in with their new password via [Sign-In](/api/passwords/sign-in) ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - You can also utilize [Update Password](/api/passwords/update-password) or [Reset Password](/api/passwords/email/password-reset) as alternatives to change a user's password. - [Update Password](/api/passwords/update-password): ### Update the user's password of an existing user utilizing the password API. ### Next Steps Sign the user in with their new password via [Sign-In](/api/passwords/sign-in) ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - You can also utilize [Replace Password](/api/passwords/replace-password) or [Reset Password](/api/passwords/email/password-reset) as alternatives to change a user's password. - [Get Password Policy](/api/passwords/password-policy): ### Get the configured password policy for the project. ### See Also - See [Password Policy Customization](/auth-methods/passwords#password-policy) for further details on password policy configuration. - Email - [Reset Password](/api/passwords/email/password-reset): ### Sent a password reset email to an existing user utilizing the password API. ### Next Steps You will then need to verify the user after the password reset is sent via email, this would need to be done via [Verify Magic Link](/api/magic-link/verification/verify-token). ### See Also - See [The User Object](/api/overview#the-user-object) for further details on how to identify users and their contact information such as email addresses and phone number. - You can also utilize [Update Password](/api/passwords/update-password) or [Replace Password](/api/passwords/replace-password) as alternatives to change a user's password. - Recovery Codes - [Generate recovery codes for a user](/api/passwords/recovery-codes/generate-user-recovery-codes): Generate recovery codes for a user - [Sign in a user using a recovery code](/api/passwords/recovery-codes/sign-in-recovery-code): Sign in a user using a recovery code - Security Questions - [Get the security questions for a user to verify](/api/passwords/security-questions/get-user-security-verify-questions): Get the security questions for a user to verify - [Sets up security questions for a user](/api/passwords/security-questions/setup-user-security-questions): Sets up security questions for a user - [Verifies the security questions for a user](/api/passwords/security-questions/verify-user-security-questions): Verifies the security questions for a user - Access Keys (API Keys) - [Exchange Key](/api/access-keys/exchange-key): ### Exchange API key for access token This API Endpoint will take an API key for the project and provide an access token to be used for accessing the application. The session token JWT token will be valid for the configured [Session Token Timeout](/project-settings#session-token-timeout), and its expiration time will be provided in the `expiration` field of the response object. - Session - [Token Validation Key (V1)](/api/session/get-keys): ### Get public key for session token validation (V1) This API endpoint will return the public key needed to handle the session token JWT validation. `projectId` is provided as a GET parameter, so this endpoint can be executed with a browser. - [Token Validation Key (V2)](/api/session/get-keys-v2): ### Get public key for session token validation (V2) This API endpoint will return the public key needed to handle the session token JWT validation. `projectId` is provided as a GET parameter, so this endpoint can be executed with a browser. This endpoint differentiates from [Token Validation Key (V1)](/api/session/get-keys) as the data is returned in JSON format rather than an array. - [Refresh Session](/api/session/refresh-session): ### Refresh the session token, using a valid fresh token This API endpoint will provide a new valid session token for an existing signed-in user, by validating the provided refresh token. The refresh token is provided as part of the HTTP Authorization Bearer. - [My Details](/api/session/my-details): ### Get current signed-in user details This API Endpoint will return the current user's details. This endpoint requires the user to be signed in and have a valid `refreshJwt`. The `refreshJwt` is then used as part of the Authorization Bearer to perform this task. - [Get Session History](/api/session/session-history): ### Get user's session history This API Endpoint will return the current user's session history including geo-location and IP address. This endpoint requires the user to be signed in and have a valid `refreshJwt`. The `refreshJwt` is then used as part of the Authorization Bearer to perform this task. - [Select an active tenant](/api/session/active-tenant): ### Set the active tenant for the user's current session This endpoint allows you to get a new session token and refresh token with the `dct` claim on the JWT which shows the active selected tenant for the user. See [Tenant Selection Article](/knowledgebase/descopeflows/tenantselectcomponent/) for more details of the usage. - [Sign-Out](/api/session/sign-out): ### Log the user out from the provided session This API endpoint will sign the user out of the provided session using the `refreshToken`. Successfully executing this endpoint will invalidate the provided refresh tokens. Response will also include all user tokens and fields empty, so the executing client will remove cookies as well. - [Sign-Out All Active Sessions](/api/session/sign-out-all-devices): ### Log the user out from all signed-in sessions This API endpoint will sign the user out of all the devices they are currently signed-in with. Successfully executing this endpoint will invalidate all user's refresh tokens. Response will include all user tokens and fields empty, so client will remove cookies as well. - [Validate Session](/api/session/validate-session): ### Validate and parse a user's session JWT. This endpoint is used to validate a users session using the Project ID and the user's session JWT. Upon successful validate of the user, you will receive the parsed JWT. When posting to this endpoint from an application, you get the JWT from local or cookie storage, and prepend it with project ID and use that as the bearer. - Inbound Apps (OAuth) - [Inbound Apps (OAuth) API Overview](/api/third-party-apps): REST API reference for Descope's OAuth 2.0 authorization server used by Inbound Apps — authorize, token, revoke, and userinfo endpoints. - [OAuth 2.0 authorize endpoint (GET)](/api/third-party-apps/authorization-get): Start the authorization code flow for an [Inbound App](/identity-federation/inbound-apps). Redirect the user-agent to this endpoint with `client_id`, `redirect_uri`, `response_type=code`, `scope`, `state`, and PKCE parameters. See [Authorization server endpoints](/identity-federation/inbound-apps/authorization-server) for the full flow. - [OAuth 2.0 authorize endpoint (POST)](/api/third-party-apps/authorization-post): Start authorization with a JSON request body (non-browser clients). Same semantics as the GET endpoint. See [Authorization server endpoints](/identity-federation/inbound-apps/authorization-server). - [OAuth 2.0 token endpoint (Inbound Apps)](/api/third-party-apps/token-endpoint): Exchange authorization codes, refresh tokens, client credentials, JWT bearer assertions, and RFC 8693 token-exchange requests for [Inbound App](/identity-federation/inbound-apps) access tokens. Supported `grant_type` values and examples are documented in [Authorization server endpoints](/identity-federation/inbound-apps/authorization-server) and [Using Inbound Apps](/identity-federation/inbound-apps/using-inbound-apps). - [OIDC revoke endpoint](/api/third-party-apps/revoke-token): OIDC revoke endpoint - [Third Party application Get UserInfo endpoint](/api/third-party-apps/user-info-get): Third Party application Get UserInfo endpoint - [Third Party application Post UserInfo endpoint](/api/third-party-apps/user-info-post): Third Party application Post UserInfo endpoint - Applications - [OIDC Authorize Entra MFA](/api/federated-apps/oidc-auth-z-endpoint-entra-mfa): OIDC Entra MFA authorization endpoint - [OIDC Finish Authorize](/api/federated-apps/oidc-auth-z-endpoint-finish-get): OIDC GET authorization endpoint finish - [OIDC Finish Authorize](/api/federated-apps/oidc-auth-z-endpoint-finish-post): OIDC POST authorization endpoint finish - [OIDC Authorize](/api/federated-apps/oidc-auth-z-endpoint-get-start): OIDC GET authorization endpoint start - [OIDC Authorize](/api/federated-apps/oidc-auth-z-endpoint-post-start): OIDC POST authorization endpoint start - [OIDC Device](/api/federated-apps/oidc-device-endpoint): OIDC device endpoint (sso app) - [OIDC End Session](/api/federated-apps/oidc-end-session-endpoint-get): OIDC end session GET endpoint - [OIDC End Session](/api/federated-apps/oidc-end-session-endpoint-post): OIDC end session POST endpoint - [OIDC Introspect](/api/federated-apps/oidc-introspection-endpoint): OIDC token introspection endpoint (RFC 7662) - [OIDC Authorize](/api/federated-apps/oidc-project-id-auth-z-endpoint-get-start): OIDC GET authorization endpoint start (by projectId, for an imported client_id) - [OIDC Authorize](/api/federated-apps/oidc-project-id-auth-z-endpoint-post-start): OIDC POST authorization endpoint start (by projectId, for an imported client_id) - [OIDC Device](/api/federated-apps/oidc-project-id-device-endpoint): OIDC device endpoint (by projectId, for an imported client_id) - [OIDC End Session](/api/federated-apps/oidc-project-id-end-session-endpoint-get): OIDC end session GET endpoint (by projectId, for an imported client_id) - [OIDC End Session](/api/federated-apps/oidc-project-id-end-session-endpoint-post): OIDC end session POST endpoint (by projectId, for an imported client_id) - [OIDC Token](/api/federated-apps/oidc-project-id-token-endpoint): OIDC token endpoint (by projectId, for an imported client_id) - [OIDC Revoke](/api/federated-apps/oidc-revocation-endpoint): OIDC revoke endpoint - [OIDC Token](/api/federated-apps/oidc-token-endpoint): OIDC token endpoint - [OIDC UserInfo](/api/federated-apps/oidc-user-info-endpoint-get): OIDC Get UserInfo endpoint - [OIDC UserInfo](/api/federated-apps/oidc-user-info-endpoint-post): OIDC POST UserInfo endpoint - [OIDC PAR](/api/federated-apps/oidcpar-endpoint): Pushed Authorization Request endpoint for federated OIDC apps (RFC 9126). - [OIDC Authorize Entra MFA](/api/federated-apps/oidcsso-app-auth-z-endpoint-entra-mfa): OIDC Entra MFA authorization endpoint (SSO App) - [OIDC Authorize](/api/federated-apps/oidcsso-app-auth-z-endpoint-get-start): OIDC GET authorization endpoint start (sso app) - [OIDC Authorize](/api/federated-apps/oidcsso-app-auth-z-endpoint-post-start): OIDC POST authorization endpoint start (sso app) - [OIDC End Session](/api/federated-apps/oidcsso-app-end-session-endpoint-get): OIDC end session GET endpoint (sso app) - [OIDC Introspect](/api/federated-apps/oidcsso-app-introspection-endpoint): OIDC token introspection endpoint (RFC 7662, sso app) - [OIDC PAR (SSO app)](/api/federated-apps/oidcsso-app-par-endpoint): Pushed Authorization Request endpoint for a federated OIDC SSO application (RFC 9126). - [OIDC Revoke](/api/federated-apps/oidcsso-app-revocation-endpoint): OIDC revoke endpoint (sso app) - [OIDC Token](/api/federated-apps/oidcsso-app-token-endpoint): OIDC token endpoint (sso app) - [OIDC UserInfo](/api/federated-apps/oidcsso-app-user-info-endpoint-get): OIDC Get UserInfo endpoint (sso app) - [OIDC UserInfo](/api/federated-apps/oidcsso-app-user-info-endpoint-post): OIDC POST UserInfo endpoint (sso app) - [OIDC End Session](/api/federated-apps/oidsso-app-c-end-session-endpoint-post): OIDC end session POST endpoint (sso app) - [SAML IDP Finish](/api/federated-apps/samlidp-finish-endpoint): SAML IDP finish endpoint - [SAML IDP Initiate POST](/api/federated-apps/samlidp-initiate-http-post-binding): SAML IDP Initiate HTTP POST binding login flow - [SAML IDP Initiate Redirect](/api/federated-apps/samlidp-initiate-http-redirect-binding): SAML IDP Initiate HTTP redirect binding login flow - [SAML IDP POST Binding](/api/federated-apps/samlidphttp-post-binding): SAML IDP HTTP POST binding login flow - [SAML IDP Redirect Binding](/api/federated-apps/samlidphttp-redirect-binding): SAML IDP http redirect binding login flow - [WS-Fed IDP Finish](/api/federated-apps/ws-fed-idp-finish-endpoint): WS-Fed IDP finish endpoint after authentication - [WS-Fed IDP Initiate](/api/federated-apps/ws-fed-idp-initiate-get): WS-Fed IDP-initiated sign-in (GET) - [WS-Fed IDP Initiate](/api/federated-apps/ws-fed-idp-initiate-post): WS-Fed IDP-initiated sign-in (POST) - [WS-Fed IDP Passive](/api/federated-apps/ws-fed-idp-passive-get): WS-Fed IDP passive sign-in endpoint (GET) - [WS-Fed IDP Passive](/api/federated-apps/ws-fed-idp-passive-post): WS-Fed IDP passive sign-in endpoint (POST) - Management - Flows and Styles - [Flow and Style Management API Overview](/api/management/flows): Use the Descope API to manage your project's flows and styles with a management key. - [List/Search Flows](/api/management/flows/list-flows): ### List or search flows within a project utilizing a management key. This endpoint is used to list or search flows within a project. To list all flows, send an empty body such as: `{ }` or `{ "ids": [] }`. To search for a flow or several flows, send a body with the flowIds you want to search such as `{ "ids": ["sign-in"] }` or `{ "ids": ["sign-in", "sign-up"] }`. ### See Also - See [Flow Overview](/customize/flows/) for more information on flows. - See [Manage Flows](/customize/manage_flows/) for more information on managing (export, import, delete, disable, enable) flows. - [Export Flow](/api/management/flows/export-flow): ### Export an existing flow from a project utilizing a management key. This endpoint is used to export an existing flow from a project. The response is the JSON which includes the flow and associated screens. ### See Also - See [Flow Overview](/customize/flows/) for more information on flows. - See [Manage Flows](/customize/manage_flows/) for more information on managing (export, import, delete, disable, enable) flows. - [Import Flow](/api/management/flows/import-flow): ### Import a flow within a project utilizing a management key. This endpoint is used to import a flow to a project. The request items for the `flow` and `screen` this endpoint can be received from the export flow endpoint. ### See Also - See [Flow Overview](/customize/flows/) for more information on flows. - See [Manage Flows](/customize/manage_flows/) for more information on managing (export, import, delete, disable, enable) flows. - [Export Theme](/api/management/flows/export-theme): ### Export a theme from a project utilizing a management key. This endpoint is used to export a theme from a project. The response is the JSON of the theme. ### See Also - See [Styles Overview](/management/project-settings/styles) for more information on styles and themes - [Import Theme](/api/management/flows/import-theme): ### Import a theme to a project utilizing a management key. This endpoint is used to import a theme from a project. The request body for this endpoint can be received from the export theme endpoint. ### See Also - See [Styles Overview](/management/project-settings/styles) for more information on styles and themes - [Get Management Flow async result](/api/management/flows/get-management-flow-async-result): Get the result from an async management flow execution (if any), using a valid management key. - [Run Management Flow asynchronously](/api/management/flows/run-management-flow-async): Run a management flow asynchronously, using a valid management key. - [Run Management Flow](/api/management/flows/run-management-flow): Run a management flow, using a valid management key. - [Complete External Authentication](/api/management/flows/complete-external-auth-flow): Complete an external authentication flow step. Called by the customer's backend after authenticating the user on their own page. Requires a valid management key. - [List Flow Templates](/api/management/flows/list-flow-templates): List all available flow templates - [Export Flow Localization](/api/management/flows/export-flow-localization): Export flow localization, using a valid management key. - [Import Flow Localization](/api/management/flows/import-flow-localization): Import flow localization, using a valid management key. - [List all widgets](/api/management/flows/list-widgets): List all widgets in project - Users - [User Management API Overview](/api/management/users): Use the Descope API to manage your application users with a management key. - Test Users - [Test User Management API Overview](/api/management/users/test-users): Use the Descope API to manage your application's test users with a management key. - [Generate OTP](/api/management/users/test-users/generate-otp): ### Generate an OTP verification code for a test user. This endpoint is used to generate an OTP verification code for a test user. You can define whether this is sent via email or sms. Once you generate the OTP code, you must verify the OTP code via [verify OTP email](/api/otp/email/verify-otp) or [verify OTP sms](/api/otp/sms/verify-otp) ### See Also - See [OTP Authentication](/api/otp/) for details about implementing OTP. - See [Create a user](/api/management/users/create-user) with the `test` flag set to true to set it as a test user. - See [Manage Test Users](/manage/testusers/) for more information on test users. - [Generate Magic Link](/api/management/users/test-users/generate-magic-link): ### Generate a Magic Link for a test user. This endpoint is used to generate a Magic Link for a test user. You can define whether this is sent via email or sms. Once you generate the Magic Link Token must be verified via [verify token](/api/magic-link/verification/verify-token) ### See Also - See [Magic link Authentication](/api/magiclink/) for details about implementing magic links. - See [Create a user](/api/management/users/create-user) with the `test` flag set to true to set it as a test user. - See [Manage Test Users](/manage/testusers/) for more information on test users. - [Generate Enchanted Link](/api/management/users/test-users/generate-enchanted-link): ### Generate a Enchanted Link for a test user. This endpoint is used to generate a Enchanted Link for a test user. You can define whether this is sent via email or sms. Once you generate the Enchanted Link Token must be verified via [verify token](/api/enchanted-link/verify-token) ### See Also - See [Enchanted link Authentication](/api/enchantedlink/) for details about implementing enchanted links. - See [Create a user](/api/management/users/create-user) with the `test` flag set to true to set it as a test user. - See [Manage Test Users](/manage/testusers/) for more information on test users. - [Delete All Test Users](/api/management/users/test-users/delete-all-test-users): ### Delete all test users This endpoint is used to delete all test users from a project. This action will delete these users forever and they will not be recoverable. ### See Also - See [Manage Test Users](/manage/testusers/) for more information on test users. - [Load User](/api/management/users/load-user): ### Load a user's data, using a valid management key. This API endpoint takes the user's loginId and then returns details of a user utilizing a valid management key. The response includes the following; however, there are additional items in the response that you can see below by expanding the response 200 OK. - loginIds - userId - name - email - phone - verified settings (phone, email) - Tenant configurations - which tenantIds, which roleNames _Note: Suppose you frequently load a user for a specific user detail, such as their email address or a particular custom attribute. In that case, you can save execution time and additional API/SDK calls to load the user by adding the items to the custom claim. For details on adding items to the custom claims, see [this documentation](/security-best-practices/custom-claims#using-custom-claims-within-descope-flows)._ _Note: If you have access to all federated applications, the list will return as an empty array. Descope allows you to restrict which apps each user has access to, but by default gives access to all applications._ ### Next Steps Once you have this data, you can utilize the response to prepare the payload to perform an [Update](/api/management/users/update-user) on the user. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Get User Provider Token](/api/management/users/get-user-provider-token): ### Get an existing user's provider token, using a valid management key. This API endpoint will loads the user's access token generated by the OAuth/OIDC provider, using a valid management key. When querying for OAuth providers, this only applies when utilizing your own account with the provider and have selected `Manage tokens from provider` selected under the [social auth methods](https://app.descope.com/settings/authentication/social). ### Query Params - `loginId` - The loginId of the user you want to get the provider token for. - `provider` - The provider you want to get the token for. - `withRefreshToken (optional)` - set to true to also return the refresh token. - `forceRefresh (optional)` - set to true to force a refresh of the token. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Provider Options](/auth-methods/oauth#social-login-oauth-providers) for a the out of the box list of providers. - [Search Users](/api/management/users/search-users): ### Search for users, using a valid management key. This API endpoint will search for users utilizing a valid management key. Searches can be defined with any combination of roles or tenants. You can also only send the request with an empty payload to return all users. The response will include the following details on all users within an array of objects: - loginIds - userId - name - email - phone - verified settings (phone, email) - Tenant configurations (tenantIds, roleNames) ### Next Steps You can then parse through the response in order to find any users which you may need to delete, update, etc. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Create User](/api/management/users/create-user): ### Create a new user, using a valid management key. This API endpoint will create a new user utilizing a valid management key. This API endpoint allows you to configure all aspects of a user: - loginId - email - phone - verified settings (phone, email) - one must be set to true - displayName - roleNames - Tenant configurations - which tenantIds, which roleNames. The userTenants can include multiple items Ex: ``` "userTenants": [ { "tenantId": "T2IMjmRfYTQHlbaastz3im59ERS3", "roleNames": [ "Test" ] }, { "tenantId": "T2Igau6dX1R6SkomtFCdBLrc3r67", "roleNames": [ "Test" ] } ``` Additionally, you can create a user with multiple login IDs by passing an array of loginIds in string format within the `additionalIdentifiers` key. ### Next Steps Once the user is created, the user can then login utilizing any sign-in api supported. This will then switch the user from invited to active. ### See also - See [Manage User](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Batch Create Users](/api/management/users/batch-create-users): ### Batch Create Users, using a valid management key. This API endpoint will batch create new users utilizing a valid management key. This API endpoint allows you to configure all aspects of a user: - loginId - email - phone - verified settings (phone, email) - one must be set to true - displayName - roleNames - Tenant configurations - which tenantIds, which roleNames. The userTenants can include multiple items Ex: ``` "userTenants": [ { "tenantId": "T2IMjmRfYTQHlbaastz3im59ERS3", "roleNames": [ "Test" ] }, { "tenantId": "T2Igau6dX1R6SkomtFCdBLrc3r67", "roleNames": [ "Test" ] } ``` Additionally, you can create a user with multiple login IDs by passing an array of loginIds in string format within the `additionalIdentifiers` key. You can also decide whether to invite the users, configure the inviteUrl, and whether to send invites via email or SMS. When importing with hashed passwords, see [this guide](/migrate/custom#importing-passwords) for further detailed configuration of password hash formats. ### Next Steps Once the user is created, the user can then login utilizing any sign-in api supported. This will then switch the user from invited to active. ### See also - See [Manage User](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Patch User](/api/management/users/patch-user): ### Patch a user's details, using a valid management key. This API endpoint will patch a user's details of a user utilizing a valid management key. Additionally, you can patch a user with multiple login IDs by passing an array of loginIds in string format within the `additionalIdentifiers` key. This allows you to add additional login identifiers to an existing user without performing a full user update. When adding additional identifiers to a user who has an SSO login ID, the user may be able to authenticate outside of SSO whenever SSO is not enforced and non-SSO methods (such as magic link or password) are available. See [Risks in Merging SSO and Non-SSO Identities](/sso/merging-sso-identities-risk) before using this field on SSO users. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Update User](/api/management/users/update-user): ### Updates a user's details, using a valid management key. This API endpoint will update a user's details of a user utilizing a valid management key. It is important to understand the update will take the configurations for the user provided and will overwrite all user settings. This means that if the user currently has email and phone, but the update only includes email, the phone and other non-provided configurations will be removed. This API endpoint will remove any details that are not provided. It is preferred to use other updates supported by the API, such as the following options: - [Update User Status](/api/management/users/update-user-status) - [Update User Email](/api/management/users/update-user-email) - [Update User Phone](/api/management/users/update-user-phone) - [Update User Display Name](/api/management/users/update-user-display-name) - [Update User Add Tenant](/api/management/users/update-user-add-tenant) - [Update User Remove Tenant](/api/management/users/update-user-remove-tenant) - [Update User Add Role](/api/management/users/update-user-add-roles) - [Update User Remove Role](/api/management/users/update-user-remove-roles) Additionally, you can update a user with multiple login IDs by passing an array of loginIds in string format within the `additionalIdentifiers` key. It is suggested to gather the current user configurations via [Load User](/api/management/users/load-user) in order to assist you in building the payload for this api endpoint. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Update User Status](/api/management/users/update-user-status): ### Updates an existing user's status, using a valid management key. This API endpoint allows you to update the user's status granularly without updating all user details. Available statuses to utilize: - invited - enabled - disabled The response returns the user's details in json format. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Update User Email](/api/management/users/update-user-email): ### Updates an existing user's email, using a valid management key. This API endpoint allows you to update the user's email granularly without updating all user details. The response returns the user's details in json format. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Update User Login ID](/api/management/users/update-user-login-id): ### Updates an existing user's login ID, using a valid management key. This API endpoint allows you to update a user's Login ID. If you'd like to remove a login ID, provide an empty string for the new login ID. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Update User Phone](/api/management/users/update-user-phone): ### Updates an existing user's phone number, using a valid management key. This API endpoint allows you to update the user's phone number granularly without updating all user details. The response returns the user's details in json format. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Update User Display Name](/api/management/users/update-user-display-name): ### Updates an existing user's display name, using a valid management key. This API endpoint allows you to update the user's display name granularly without updating all user details. The response returns the user's details in json format. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Update User Picture](/api/management/users/update-user-picture): ### Update an existing user's profile picture, using a valid management key. This API endpoint allows you to update a user's profile picture granularly without updating all user details. The response returns the user's details in json format. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Manage Tenants](/management/tenant-management) for further details on managing tenants. - [Update User Custom Attribute](/api/management/users/update-user-custom-attribute): ### Update an existing user's custom attributes, using a valid management key. This API endpoint allows you to update a user's custom attributes granularly without updating all user details. The response returns the user's details in json format. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Manage Tenants](/management/tenant-management) for further details on managing tenants. - [Update JWT](/api/management/users/update-jwt): ### Updates a JWT with custom claims, using a valid management key. This API endpoint will update a JWT with custom claims. This endpoint takes the JWT as well as the `customClaims` json. - [Expire User Passwsord](/api/management/users/expire-user-password): ### Expire an existing user's password, using a valid management key. This API endpoint allows you to expire an existing user's password. Upon next login, the user will need to follow the reset password flow. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Manage Tenants](/management/tenant-management) for further details on managing tenants. - See [Reset Password](/api/passwords/email/password-reset) for sending the password reset email. - [Set Active Password for User](/api/management/users/set-user-active-password): ### Set an active password for an existing user, using a valid management key. This API endpoint allows you to set an active password for an existing user. This will allow the user to authenticate with this password without changing it. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Manage Tenants](/management/tenant-management) for further details on managing tenants. - [Set Temporary Password for User](/api/management/users/set-user-temp-password): ### Set a temporary password for an existing user, using a valid management key. This API endpoint allows you to set a temporary password for an existing user. This will require the user to change their password on next authentication. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Manage Tenants](/management/tenant-management) for further details on managing tenants. - [Update User Add Tenant](/api/management/users/update-user-add-tenant): ### Add a tenant to an existing user, using a valid management key. This API endpoint allows you to add a user to a tenant granularly without updating all user details. The response returns the user's details in json format. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Manage Tenants](/management/tenant-management) for further details on managing tenants. - [Update User Remove Tenant](/api/management/users/update-user-remove-tenant): ### Removes a tenant from an existing user, using a valid management key. This API endpoint allows you to remove a user from a tenant granularly without updating all user details. The response returns the user's details in json format. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Manage Tenants](/management/tenant-management) for further details on managing tenants. - [Update User Add Roles](/api/management/users/update-user-add-roles): ### Add roles to an existing user, using a valid management key. This API endpoint allows you to add roles to a user granularly without updating all user details. `roleNames` is an array of the role names in string format. The `tenantId` is optional; if provided, the user must be a member of that tenant The response returns the user's details in json format. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Manage Roles](/manage/roles/) for further details on managing roles. - [Set User's Roles](/api/management/users/update-user-set-roles): ### Set an existing user's roles, using a valid management key. This API endpoint allows you to set a user's roles. This will override the current roles associated to the user and will set all passed roles. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Manage Roles](/manage/roles/) for further details on managing roles. - [Update User Remove Roles](/api/management/users/update-user-remove-roles): ### Remove roles from an existing user, using a valid management key. This API endpoint allows you to remove roles from a user granularly without updating all user details. `roleNames` is an array of the role names in string format. The `tenantId` is optional; if provided, the user must be a member of that tenant The response returns the user's details in json format. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Manage Roles](/manage/roles/) for further details on managing roles. - [Add Application to User](/api/management/users/update-user-add-sso-apps): ### Add Applications to an existing user, using a valid management key. This API endpoint allows you to add Applications to a user granularly without updating all user details. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Applications](/manage/idpapplications/) for further details on Applications. - [Set Applications to User](/api/management/users/update-user-set-sso-apps): ### Set Applications for an existing user, using a valid management key. This API endpoint allows you to set the associated Applications for a user. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Applications](/manage/idpapplications/) for further details on Applications. - [Remove Application to User](/api/management/users/update-user-remove-sso-apps): ### Remove Applications from an existing user, using a valid management key. This API endpoint allows you to remove Applications from a user granularly without updating all user details. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Applications](/manage/idpapplications/) for further details on Applications. - [Log user out of all sessions](/api/management/users/logout-all-user-devices): ### Log a user out of all sessions, using a valid management key. This API endpoint allows you to log a user out of all active sessions. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - See [Manage Roles](/manage/roles/) for further details on managing roles. - [Delete User's Passkeys](/api/management/users/remove-user-passkeys): ### Delete a user's Passkeys, using a valid management key. This API endpoint will delete all existing passkeys for the user ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Delete User](/api/management/users/delete-user): ### Delete a user, using a valid management key. This API endpoint will delete a user utilizing a valid management key based on the provided user loginId. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Batch Delete Users](/api/management/users/batch-delete-users): ### Delete users, using a valid management key. This API endpoint will delete users utilizing a valid management key. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Impersonate User](/api/management/users/impersonate): ### Impersonate a user, using a valid management key. This API endpoint will allow you to impersonate a user using a login ID. The impersonator user must have the impersonation permission in order for this request to work. The response would be a refresh JWT of the impersonated user - [Anonymous User](/api/management/users/anonymous): ### Anonymous User Anonymous Users are identified with a unique Descope JWT type. Eventually, create a token that we can use as the defined anonymous identity. Signed by Descope. For more info, please refer to our anonymous users documentation. - [Stop Impersonation](/api/management/users/stop-impersonation): Stop impersonation as a different user - Custom Attributes - [Get Available Custom Attributes](/api/management/users/custom-attributes/user-custom-attributes): ### Get available custom attributes to configure on users within a project, using a valid management key. This API endpoint will return the available user custom attributes within a project. ### See also - See [Custom Attributes](/manage/users#custom-user-attributes) for further details on custom user attributes - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Create a Custom Attributes](/api/management/users/custom-attributes/create-user-custom-attribute): ### Create a custom attributes to configure on users within a project, using a valid management key. This API endpoint will create a custom attribute within a project. ### See also - See [Custom Attributes](/manage/users#custom-user-attributes) for further details on custom user attributes - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Delete a Custom Attributes](/api/management/users/custom-attributes/delete-user-custom-attribute): ### Delete a custom attributes to configure on users within a project, using a valid management key. This API endpoint will delete a custom attribute within a project. ### See also - See [Custom Attributes](/manage/users#custom-user-attributes) for further details on custom user attributes - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Delete User's TOTP Seed](/api/management/users/delete-user-totp-seed): ### Delete an existing user's TOTP, using a valid management key. This API endpoint allows you to delete an existing user's TOTP seed. ### See also - See [Manage Users](/manage/users) for further details on managing users. - See [The User Object](/api/overview#the-user-object) for further details on the user object. - [Create Test User](/api/management/users/create-test-user): Create a test user, using a valid management key. - [Load Users](/api/management/users/load-users): Load users by their IDs, using a valid management key. - [Search test Users](/api/management/users/search-test-users): Search test users, using a valid management key. - [Patch Users Batch](/api/management/users/patch-user-batch): Patch users in batch, using a valid management key. - [Update User Impersonation Consent](/api/management/users/update-user-impersonation-consent): Update user impersonation consent, using a valid management key. This allows granting impersonation consent without requiring the user-facing consent flow. - [Users Authentication History V2](/api/management/users/users-auth-history-v-2): Load users' authentication history by user IDs, using a valid management key. V2 endpoint with improved request body handling. - [List Trusted Devices](/api/management/users/list-trusted-devices-for-users): List trusted devices for one or more users. - [Delete Trusted Devices](/api/management/users/update-user-remove-trusted-devices): Delete user trusted devices by IDs. - [Import User Passkeys](/api/management/users/import-user-passkeys): Import passkey credentials for a user, using a valid management key. - Access Keys - [Access Key Management API Overview](/api/management/access-keys): Use the Descope API to manage your access keys with a management key. - [Load An Access Key](/api/management/access-keys/load-access-key): ### Load an access key, using a valid management key. This API endpoint allows administrators to load the details of an existing access key. The response contains details of the access key including associated roles and tenants as well as details of the key's creation, status, and expiration. ### Next Steps Once you have this data, you can utilize the response to [Update an access key](/api/management/access-keys/update-access-key), [Activate an access key](/api/management/access-keys/activate-access-key), [Deactivate an access key](/api/management/access-keys/deactivate-access-key), or [Delete an access key](/api/management/access-keys/delete-access-key). ### See also - See [Access Key Management](/access-keys) for further details on managing access keys. - [Search Access Keys](/api/management/access-keys/search-access-keys): ### Search access keys, using a valid management key. This API endpoint allows administrators to search for details of existing access keys for a given array of tenants. The response contains an array of details for the access keys returned by the search including associated roles and tenants as well as details of the key's creation, status, and expiration. ### Next Steps Once you have this data, you can utilize the response to [Update an access key](/api/management/access-keys/update-access-key), [Activate an access key](/api/management/access-keys/activate-access-key), [Deactivate an access key](/api/management/access-keys/deactivate-access-key), or [Delete an access key](/api/management/access-keys/delete-access-key). ### See also - See [Access Key Management](/access-keys) for further details on managing access keys. - [Create Access Key](/api/management/access-keys/create-access-key): ### Create an access key, using a valid management key. This API endpoint allows administrators to create an access key. During the creation of the access key, you can set the name, expiration time, roles and tenant:role pairs to associated with the key. ### Next Steps Once you have the access key, you can utilize it to configure external items such as [SCIM](/api/scimmanagement/), or use it to [exchange for a JWT](/api/access-keys/exchange-key). ### See also - See [Access Key Management](/access-keys) for further details on managing access keys. - [Update Access Key](/api/management/access-keys/update-access-key): ### Update an existing access key, using a valid management key. This API endpoint allows administrators to update an existing access key. With this endpoint, you can only update the access key's name. ### See also - See [Access Key Management](/access-keys) for further details on managing access keys. - [Activate Access Key](/api/management/access-keys/activate-access-key): ### Activate an existing access key, using a valid management key. This API endpoint allows administrators to activate an existing access key. ### Next Steps Once you have reactivated the access key, you can utilize it to configure external items such as [SCIM](/api/scimmanagement/), or use it to [exchange for a JWT](/api/access-keys/exchange-key). ### See also - See [Access Key Management](/access-keys) for further details on managing access keys. - [Deactivate Access Key](/api/management/access-keys/deactivate-access-key): ### Deactivate an existing access key, using a valid management key. This API endpoint allows administrators to deactivate an existing access key. Once the access key has been deactivated, it's access will be revoked until reactivated. ### See also - See [Access Key Management](/access-keys) for further details on managing access keys. - [Delete Access Key](/api/management/access-keys/delete-access-key): ### Delete an existing access key, using a valid management key. This API endpoint allows administrators to delete an existing access key. Once the access key has been deleted, it's access will be revoked. ### See also - See [Access Key Management](/access-keys) for further details on managing access keys. - [Batch Activate Access Keys](/api/management/access-keys/batch-activate-access-keys): ### Activate existing access keys in batch, using a valid management key. This API endpoint allows administrators to activate existing access keys in batch. ### Next Steps Once you have reactivated the access key, you can utilize it to configure external items such as [SCIM](/api/scimmanagement/), or use it to [exchange for a JWT](/api/access-keys/exchange-key). ### See also - See [Access Key Management](/access-keys) for further details on managing access keys. - [Batch Deactivate Access Keys](/api/management/access-keys/batch-deactivate-access-keys): ### Deactivate existing access keys in batch, using a valid management key. This API endpoint allows administrators to deactivate existing access keys in batch. Once the access keys have been deactivated, their access will be revoked until reactivated. ### See also - See [Access Key Management](/access-keys) for further details on managing access keys. - [Batch Delete Access Keys](/api/management/access-keys/batch-delete-access-keys): ### Delete existing access keys in batch, using a valid management key. This API endpoint allows administrators to delete existing access keys in batch. Once the access keys have been deleted, their access will be revoked. ### See also - See [Access Key Management](/access-keys) for further details on managing access keys. - [Import Access Key](/api/management/access-keys/import-access-keys): Import an access key by providing its plaintext value, using a valid management key. - Applications - [Application Management API Overview](/api/management/sso-apps): Use the Descope REST API to manage Applications within Descope - [Load Application by ID](/api/management/sso-apps/load-sso-application-by-id): ### Load Application by ID within a project This endpoint returns details of a specific Application within your Descope project. ### See Also - Review our [documentation](/manage/idpapplications/) around Applications within Descope. - [Create OIDC Application](/api/management/sso-apps/create-sso-oidc-application): ### Create OIDC Application within a project This endpoint creates an OIDC Application within your Descope project. ### See Also - Review our [documentation](/manage/idpapplications/) around Applications within Descope. - [Update OIDC Application](/api/management/sso-apps/update-sso-oidc-application): ### Update OIDC Application within a project This endpoint updates an OIDC Application within your Descope project. ### See Also - Review our [documentation](/manage/idpapplications/) around Applications within Descope. - [Delete Application](/api/management/sso-apps/delete-sso-application): ### Delete an Application within a project This endpoint deletes an Application within your Descope project. ### See Also - Review our [documentation](/manage/idpapplications/) around Applications within Descope. - [Create SSO WS-Fed IDP application](/api/management/sso-apps/create-ssows-fed-application): Create a new SSO WS-Fed IDP application, using a valid management key. - [Update SSO WS-Fed IDP application](/api/management/sso-apps/update-ssows-fed-application): Update a SSO WS-Fed IDP application, using a valid management key. - Tenants - [Tenant Management API Overview](/api/management/tenants): Use the Descope API to manage your tenants with a management key. - [Load All Tenants](/api/management/tenants/load-all-tenants): ### Load all tenants, using a valid management key. This API endpoint returns details of all configured tenants within the Descope instance. The response includes an array of the tenants and these details for each tenant: - id - name - selfProvisioningDomains ### Next Steps - Once you have this data, you can utilize the response to add users to the tenant via [Update User](/api/management/users/update-user) or [Create User](/api/management/users/create-user) - You can also apply sso configurations to the tenant via the [SSO Management API](/api/ssomanagement/) ### See also - See [Tenant Management](/management/tenant-management) for further details on managing tenants. - [Load Tenant By ID](/api/management/tenants/load-tenant-by-id): ### Load tenant by ID, using a valid management key. This API endpoint returns details of the tenant within the Descope instance that matches the ID provided. The response includes an array of the tenants and these details for each tenant: - id - name - selfProvisioningDomains ### Next Steps - Once you have this data, you can utilize the response to add users to the tenant via [Update User](/api/management/users/update-user) or [Create User](/api/management/users/create-user) - You can also apply sso configurations to the tenant via the [SSO Management API](/api/ssomanagement/) ### See also - See [Tenant Management](/management/tenant-management) for further details on managing tenants. - [Search Tenants](/api/management/tenants/search-tenants): ### Search all tenants, using a valid management key. This API endpoint returns details of configured tenants within the Descope instance that match the search parameters. The response includes an array of the tenants and these details for each tenant: - id - name - selfProvisioningDomains ### Next Steps - Once you have this data, you can utilize the response to add users to the tenant via [Update User](/api/management/users/update-user) or [Create User](/api/management/users/create-user) - You can also apply sso configurations to the tenant via the [SSO Management API](/api/ssomanagement/) ### See also - See [Tenant Management](/management/tenant-management) for further details on managing tenants. - [Create Tenant](/api/management/tenants/create-tenant): ### Create a new tenant, using a valid management key. This API endpoint will create a new tenant utilizing a valid management key. Creation of a new tenant can set the name, id, and selfProvisioningDomains. The id and selfProvisioningDomains are not mandatory. The id will be autogenerated if not provided. The response will always include the tenantId. ### Next Steps - You can then add users to the tenant via [Update User](/api/management/users/update-user) or [Create User](/api/management/users/create-user) - You can also apply sso configurations to the tenant via the [SSO Management API](/api/ssomanagement/) ### See also - See [Tenant Management](/management/tenant-management) for further details on managing tenants. - [Update Tenant](/api/management/tenants/update-tenant): ### Update a tenant, using a valid management key. This API endpoint will update a tenant utilizing a valid management key. Utilizing this API endpoint will allow you to update the name or selfProvisioningDomains settings of the tenant. ### Next Steps - You can then add users to the tenant via [Update User](/api/management/users/update-user) or [Create User](/api/management/users/create-user) - You can also apply sso configurations to the tenant via the [SSO Management API](/api/ssomanagement/) ### See also - See [Tenant Management](/management/tenant-management) for further details on managing tenants. - [Delete Tenant](/api/management/tenants/delete-tenant): ### Delete a tenant, using a valid management key. This API endpoint will delete a tenant utilizing a valid management key based on the provided user tenandId. ### See also - See [Tenant Management](/management/tenant-management) for further details on managing tenants. - Password Settings - [Get Tenant Password Settings](/api/management/tenants/passwords/get-password-settings): ### Get password settings for a tenant This endpoint allows you to get the password settings of a given tenant. ### See Also - See [tenant password settings](/customize/tenant#passwords) for details about tenant password settings. - [Update Tenant Password Settings](/api/management/tenants/passwords/configure-password-settings): ### Update password settings for a tenant This endpoint allows you to update the password settings of a given tenant. ### See Also - See [tenant password settings](/customize/tenant#passwords) for details about tenant password settings. - Session Settings - [Get Tenant Session Settings](/api/management/tenants/session/get-tenant-settings): ### Get session settings for a tenant This endpoint allows you to get the session settings of a given tenant. ### See Also - See [tenant session settings](/customize/tenant#session-management) for details about tenant session settings. - [Update Tenant Session Settings](/api/management/tenants/session/configure-tenant-settings): ### Update session settings for a tenant This endpoint allows you to update the session settings of a given tenant. ### See Also - See [tenant session settings](/customize/tenant#session-management) for details about tenant session settings. - SSO - [SSO Management API Overview](/api/management/tenants/sso): Use the Descope API to manage your tenants' SSO configurations with a management key. - [Get Tenant's SAML/OIDC Settings](/api/management/tenants/sso/load-sso-settings): ### Get the current SAML/OIDC configuration settings of a tenant, using a valid management key. This API endpoint allows you to get the current SAML/OIDC configuration settings of a tenant. ### See also - See [SSO Configuration](/sso) for further details on managing SSO Configurations on a tenant. - [Set Tenant's SAML Settings](/api/management/tenants/sso/configure-sso-saml-settings): ### Configure the SAML Settings, using a valid management key. This API endpoint will configure the SAML settings on a tenant utilizing a valid management key. This API endpoint accepts idpURL, entityId, idpCert, and redirectURL which will be applied to the tenant under SSO Configuration section and will select the option to "Enter the connection details manually" This endpoint also accepts the attribute mapping you would like to be configured on the SAML settings. These configurations will need to be captured directly from your idp provider. The values for each field can be obtained from the admin console of the identity provider. Alternatively, administrators can configure SAML without applying these setting manually via [Configure SAML Metadata URL](/api/management/tenants/sso/configure-sso-saml-settings-by-metadata) ### See also - See [SSO Configuration](/sso) for further details on managing SSO Configurations on a tenant. - [Set Tenant's SAML Settings via Metadata URL](/api/management/tenants/sso/configure-sso-saml-settings-by-metadata): ### Configure the SAML Metadata URL, using a valid management key. This API endpoint will configure the SAML Metadata URL on a tenant utilizing a valid management key. This API endpoint accepts idpMetadataURL which will be applied to the tenant under SSO Configuration section and will select the option to "Retrieve the connection details dynamically using a metadata URL" This endpoint also accepts the attribute mapping you would like to be configured on the SAML settings. This Metadata URL can can be obtained from the admin console of the identity provider. Configuring SAML via Metadata URL allows administrators to configure SAML without applying these setting manually via [Configure SAML Settings](/api/management/tenants/sso/configure-sso-saml-settings) ### See also - See [SSO Configuration](/sso) for further details on managing SSO Configurations on a tenant. - [Set Tenant's OIDC Settings](/api/management/tenants/sso/configure-sso-oidc-settings): ### Configure the OIDC settings of a tenant, using a valid management key. This API endpoint will configure the OIDC settings on a tenant utilizing a valid management key. This endpoint accepts the OIDC configuration settings as well as the attribute mapping you would like to be configured on the SAML settings. ### See also - See [SSO Configuration](/sso) for further details on managing SSO Configurations on a tenant. - [Create New SSO Settings](/api/management/tenants/sso/create-sso-settings): ### Create new SSO settings for a tenant, using a valid management key. This API endpoint allows you to create a new SSO configuration for a tenant. The endpoint accepts the tenant ID, an optional SSO ID, and a display name for the SSO configuration. ### See also - See [SSO Configuration](/sso) for further details on managing SSO Configurations on a tenant. - [Delete Tenant's SAML/OIDC Settings](/api/management/tenants/sso/delete-sso-settings): ### Delete the current SAML/OIDC configuration settings of a tenant, using a valid management key. This API endpoint allows you to delete the current SAML/OIDC configuration settings of a tenant. Use this with caution as this endpoint deletes the configuration and is irreversible. ### See also - See [SSO Configuration](/sso) for further details on managing SSO Configurations on a tenant. - [Load all SSO Settings for a tenant](/api/management/tenants/sso/load-all-sso-settings): Load all SSO Settings for a tenant, using a valid management key. - [Configure SSO Redirect URL](/api/management/tenants/sso/configure-sso-redirect-url): Configure tenant SSO Redirect URL, using a valid management key. - [Recalculate SSO Mappings](/api/management/tenants/sso/recalculate-sso-mappings): Recalculate SSO group to role mappings for all users in a tenant, using a valid management key. - Admin Links - [Generate SSO Admin Link](/api/management/tenants/admin-links/generate-tenant-admin-link-sso): ### Generate an SSO admin link for a tenant, using a valid management key. This API endpoint generates an SSO admin link that allows a tenant administrator to configure SSO settings. - [Revoke SSO Admin Link](/api/management/tenants/admin-links/revoke-tenant-admin-link-sso): ### Revoke an SSO admin link for a tenant, using a valid management key. This API endpoint revokes an existing SSO admin link for a tenant. - [Send SSO Admin Link](/api/management/tenants/admin-links/send-tenant-admin-link-sso): ### Send an SSO admin link to a tenant administrator, using a valid management key. This API endpoint sends an SSO admin link via email to the specified tenant administrator. - [Authenticated SSO Admin Link](/api/management/tenants/admin-links/authenticated-tenant-admin-link-sso): ### Authenticated SSO admin link for a tenant, using a valid management key. This API endpoint handles authenticated SSO admin link requests for a tenant. - SCIM - [SCIM Management API Overview](/api/management/tenants/scim): Use the Descope API to manage your tenants' SCIM configurations with a management key. - [Search SCIM Groups](/api/management/tenants/scim/search-scim-groups): ### Search SCIM groups, using a valid access key. This endpoint allows administrators to search SCIM groups. These groups have been created and associated to the Application and Descope tenant. The response includes an array of group objects within the Resources object. These group objects include details about the groups including the members. It is important to note the bearer token for SCIM API endpoints. The format is `ProjectId:AccessKey` the access key must be associated with the applicable tenant and has the tenant admin role. ### Next Steps Once you have this data, you can [Update an Existing SCIM Group](/api/management/tenants/scim/update-scim-group) or [Delete an Existing SCIM Group](/api/management/tenants/scim/delete-scim-group). You can add or remove users from the SCIM groups via [Update SCIM Group](/api/management/tenants/scim/update-scim-group). ### See also - See [SCIM Management](/scim) for further details on managing SCIM provisioning. - [Create SCIM Group](/api/management/tenants/scim/create-scim-group): ### Create a SCIM group, using a valid access key. This endpoint allows administrators to create new SCIM groups within their environement. When creating the group, you can configure the groupId, displayName, and it's members. The response includes the new group's group object which includes details about the groups including the members. It is important to note the bearer token for SCIM API endpoints. The format is `ProjectId:AccessKey` the access key must be associated with the applicable tenant and associated with the tenant admin role. ### Next Steps Once you have created the group, you can later add or remove users from the SCIM groups via [Update SCIM Group](/api/management/tenants/scim/update-scim-group). ### See also - See [SCIM Management](/scim) for further details on managing SCIM provisioning. - [Load SCIM Group](/api/management/tenants/scim/load-scim-group): ### Load an existing SCIM group, using a valid access key. This endpoint allows administrators to load an existing SCIM group using the SCIM groupId, which is a required field, and optionally the displayName. The response includes the group's object which includes details about the groups including the members. It is important to note the bearer token for SCIM API endpoints. The format is `ProjectId:AccessKey` the access key must be associated with the applicable tenant and associated with the tenant admin role. ### Next Steps Once you have this data, you can add or remove users from the SCIM groups via [Update SCIM Group](/api/management/tenants/scim/update-scim-group). ### See also - See [SCIM Management](/scim) for further details on managing SCIM provisioning. - [Update SCIM Group](/api/management/tenants/scim/update-scim-group): ### Update an existing SCIM group, using a valid access key. This endpoint allows administrators to update an existing SCIM group using the SCIM group ID, which is a required field. You can update the display name and members through this API endpoint. The response includes the group's object which includes details about the groups including the members. It is important to note the bearer token for SCIM API endpoints. The format is `ProjectId:AccessKey` the access key must be associated with the applicable tenant and associated with the tenant admin role. ### See also - See [SCIM Management](/scim) for further details on managing SCIM provisioning. - [Delete SCIM Group](/api/management/tenants/scim/delete-scim-group): ### Delete an existing SCIM group, using a valid access key. This endpoint allows administrators to delete an existing SCIM group using using the SCIM groupId, which is a required field, and optionally the displayName. It is important to note the bearer token for SCIM API endpoints. The format is `ProjectId:AccessKey` the access key must be associated with the applicable tenant and associated with the tenant admin role. ### See also - See [SCIM Management](/scim) for further details on managing SCIM provisioning. - [Patch SCIM Group](/api/management/tenants/scim/patch-scim-group): Patch SCIM Group, using a valid access key. - [Load SCIM User](/api/management/tenants/scim/load-scim-user): ### Load an existing SCIM user, using a valid access key. This endpoint allows administrators to load an existing SCIM user. The response includes the user's object, which includes details about the users including their email, phone, username, name, etc. It is important to note the bearer token for SCIM API endpoints. The format is `ProjectId:AccessKey` the access key must be associated with the applicable tenant and associated with the tenant admin role. ### Next Steps Once you have user data, you can utilize [Update SCIM Group](/api/management/tenants/scim/update-scim-group) to add or remove the user on groups. ### See also - See [SCIM Management](/scim) for further details on managing SCIM provisioning. - [Update SCIM User](/api/management/tenants/scim/update-scim-user): ### Update an existing SCIM user, using a valid access key. This endpoint allows administrators to update an existing SCIM user. Through this API endpoint, administrators can update the displayName, phoneNumbers, emails, and if the user is active. The response includes the user's object, which includes details about the users including their email, phone, username, name, etc. It is important to note the bearer token for SCIM API endpoints. The format is `ProjectId:AccessKey` the access key must be associated with the applicable tenant and associated with the tenant admin role. ### See also - See [SCIM Management](/scim) for further details on managing SCIM provisioning. - [Delete SCIM User](/api/management/tenants/scim/delete-scim-user): ### Delete an existing SCIM User, using a valid access key. This API endpoint allows administrators to delete an existing SCIM user from the Descope tenant. It is important to note the bearer token for SCIM API endpoints. The format is `ProjectId:AccessKey` the access key must be associated with the applicable tenant and associated with the tenant admin role. ### See also - See [SCIM Management](/scim) for further details on managing SCIM provisioning. - [Load SCIM Resource Types](/api/management/tenants/scim/load-scim-resource-types): ### Load SCIM resource types, using a valid access key. This API endpoint allows administrators to load the resource types available within the SCIM provisioning. The response includes an array of the available resource types. It is important to note the bearer token for SCIM API endpoints. The format is `ProjectId:AccessKey` the access key must be associated with the applicable tenant and associated with the tenant admin role. ### See also - See [SCIM Management](/scim) for further details on managing SCIM provisioning. - [Load SCIM Service Provider Config](/api/management/tenants/scim/load-scim-service-provider-config): ### Load the supported SCIM provisioning service provider configuration, using a valid access key. This API endpoint allows administrators to load the supported SCIM provisioning service provider configuration. The response includes detailed information on the applicable configurations and schemas within your IdP for SCIM provisioning. It is important to note the bearer token for SCIM API endpoints. The format is `ProjectId:AccessKey` the access key must be associated with the applicable tenant and associated with the tenant admin role. ### See also - See [SCIM Management](/scim) for further details on managing SCIM provisioning. - Groups - [Group Management API Overview](/api/management/tenants/groups): Use the Descope API to manage your tenants' Group configurations with a management key. - [Load All External Groups for a Tenant](/api/management/tenants/groups/load-groups): ### Load all external groups for a tenant, using a valid management key. This API endpoint allows administrators to load all external groups that are associated to a tenant. The response contains an array of group objects including the group id, display name, and an array of associated members. ### Next Steps Administrators can review this information and make changes within their IdP or if necessary, [Create a SCIM Group](/api/management/tenants/scim/create-scim-group), [Update an Existing SCIM Group (adding new members)](/api/management/tenants/scim/update-scim-group), or [Delete an Existing SCIM Group](/api/management/tenants/scim/delete-scim-group) ### See also - See [SSO Configuration](/sso) for further details on managing SSO Configurations on a tenant. - [Load All External Groups for Specific Members](/api/management/tenants/groups/load-member-groups): ### Load all external group for specific members, using a valid management key. This API endpoint allows administrators to load all external groups for specific members associated with a specific tenant. The tenantId is required and the loginId or userId are optional for further filtering. The response contains an array of group objects including the group id, display name, and an array of associated members. ### Next Steps Administrators can review this information and make changes within their IdP or if necessary, [Create a SCIM Group](/api/management/tenants/scim/create-scim-group), [Update an Existing SCIM Group (adding new members)](/api/management/tenants/scim/update-scim-group), or [Delete an Existing SCIM Group](/api/management/tenants/scim/delete-scim-group) ### See also - See [SSO Configuration](/sso) for further details on managing SSO Configurations on a tenant. - [Load All Members of a specific External Group](/api/management/tenants/groups/load-group-members): ### Load all members of a specific External group, using a valid management key. This API endpoint allows administrators to load all members of a specific external group that is associated to a tenant. The response contains an array of group objects including the group id, display name, and an array of associated members. ### Next Steps Administrators can review this information and make changes within their IdP or if necessary, [Create a SCIM Group](/api/management/tenants/scim/create-scim-group), [Update an Existing SCIM Group (adding new members)](/api/management/tenants/scim/update-scim-group), or [Delete an Existing SCIM Group](/api/management/tenants/scim/delete-scim-group) ### See also - See [SSO Configuration](/sso) for further details on managing SSO Configurations on a tenant. - [Update Tenant Default Roles](/api/management/tenants/update-tenant-default-roles): Update tenant default roles, using a valid management key. - Permissions - [Permissions Management API Overview](/api/management/permissions): Use the Descope API to create, update, and delete permissions. - [Load All Permission](/api/management/permissions/load-all-permissions): ### Load all permissions, using a valid management key. This API endpoint returns details all permissions configured within the Descope instance. The response includes an array of permissions and these details of each permission: - name - description - systemDefault ### Next Steps Once you have this data, you can utilize the response to [Create Roles](/api/management/roles/create-role) or [Update Roles](/api/management/roles/update-role) ### See also - See [User Authorization](/manage/roles/) for further details on managing roles and permissions. - [Create Permission](/api/management/permissions/create-permission): ### Create a permission, using a valid management key. This API endpoint allows administrators to create a new permission. The endpoint takes the following two parameters: - name (required) - description (optional) ### Next Steps Once you have this data, you can utilize the newly created role to [Create Roles](/api/management/roles/create-role) or [Update Roles](/api/management/roles/update-role) ### See also - See [User Authorization](/manage/roles/) for further details on managing roles and permissions. - [Update Permission](/api/management/permissions/update-permission): ### Update a permission, using a valid management key. This API endpoint allows administrators to update an existing permission. The endpoint takes the following two parameters: - name (required) - description (optional - though if not provided, it will be removed from the permission) ### Next Steps Once you have this data, you can utilize the newly created role to [Create Roles](/api/management/roles/create-role) or [Update Roles](/api/management/roles/update-role) ### See also - See [User Authorization](/manage/roles/) for further details on managing roles and permissions. - [Delete Permission](/api/management/permissions/delete-permission): ### Delete a permission, using a valid management key. This API endpoint allows administrators to delete an existing permission. The endpoint takes the following one parameter: - name (required) ### See also - See [User Authorization](/manage/roles/) for further details on managing roles and permissions. - [Bulk Create Permissions](/api/management/permissions/create-permissions): Bulk create Permissions, using a valid management key. - [Bulk Update Permissions](/api/management/permissions/update-permissions): Bulk update Permissions, using a valid management key. - [Bulk Delete Permissions](/api/management/permissions/delete-permissions): Bulk delete Permissions, using a valid management key. - Roles - [Role Management API Overview](/api/management/roles): Use the Descope API to create, manage, and delete roles using a management key. - [Load All Roles](/api/management/roles/load-all-roles): ### Load all roles, using a valid management key. This API endpoint allows administrators to load all existing roles. This endpoint returns an array of roles including their name, description, and permissionsNames. ### See also - See [User Authorization](/manage/roles/) for further details on managing roles and permissions. - [Search Roles](/api/management/roles/search-roles): ### Search roles, using a valid management key. This API endpoint allows administrators to search against existing roles. This endpoint returns an array of roles including their name, description, and permissionsNames that match the search parameters. ### See also - See [User Authorization](/manage/roles/) for further details on managing roles and permissions. - [Create Role](/api/management/roles/create-role): ### Create a role, using a valid management key. This API endpoint allows administrators to create a new role. The endpoint takes the following three parameters: - name (required) - description (optional) - permissionNames (optional) ### See also - See [User Authorization](/manage/roles/) for further details on managing roles and permissions. - [Update Role](/api/management/roles/update-role): ### Update an existing role, using a valid management key. This API endpoint allows administrators to update an existing role. The endpoint takes the following four parameters: - name (required) - newName (required) - description (optional - though if not provided, it will be removed from the role)) - permissionNames (optional - though if not provided, it will be removed from the role)) ### See also - See [User Authorization](/manage/roles/) for further details on managing roles and permissions. - [Delete Role](/api/management/roles/delete-role): ### Delete a role, using a valid management key. This API endpoint allows administrators to delete an existing role. The endpoint takes the following one parameter: - name (required) ### See also - See [User Authorization](/manage/roles/) for further details on managing roles and permissions._override/App.tsx - [Batch Delete Roles](/api/management/roles/delete-roles): ### Delete roles in batch, using a valid management key. This API endpoint allows administrators to delete roles in batch. The endpoint takes the following one parameter: - roleNames (required) ### See also - See [User Authorization](/manage/roles/) for further details on managing roles and permissions. - [Bulk Create Roles](/api/management/roles/create-roles): Bulk create Roles, using a valid management key. - [Bulk Update Roles](/api/management/roles/update-roles): Bulk update Roles, using a valid management key. - Projects - [Project Management API Overview](/api/management/projects): Use the Descope API to manage your projects with a management key. - [Rename Project](/api/management/projects/rename-project): ### Rename a project utilizing a management key. This endpoint allows you to update the name of a project. The body only requires the `name` argument. ### See Also - See [Managing Environments](/customize/environments/) for details about managing environments. - [Export Project](/api/management/projects/export-project): ### Export a project utilizing a management key. This endpoint is used to export a project. The response is the JSON of the project items. ### See Also - See [Managing Environments](/customize/environments/) for details about managing environments. - [Import Project](/api/management/projects/import-project): ### Import a project utilizing a management key. This endpoint is used to import a project. The argument of `files` should be the output of the [export project endpoint](/api/management/projects/export-project) You can also exclude items from the export when importing by utilizing the flags below within the `exclude` array. ``` The entire project: project Project specific items: project.domain project.trustedDomains project.tokenResponseMethod project.selfProvisioning project.rotateJwt project.cookiepolicy project.refreshTokenExpiration project.stepupTokenExpiration project.sessionTokenExpiration project.keySessionTokenExpiration project.inviteUrl project.inviteEmail project.inviteSms project.inviteMagicLink project.conformanceJwt project.inactivity Auth Methods, Flows, styles, etc: magicLink enchantedLink embeddedLink otp totp sso oauth webauthn password styles flows connectors authorization attributes ssoApps ``` You can also import secrets for connectors and OAuth Providers using the `inputSecrets` argument. ### See Also - See [Managing Environments](/customize/environments/) for details about managing environments. - [Clone Project](/api/management/projects/clone-project): ### Clone a project utilizing a management key. This endpoint allows you to clone the current project, including its settings and configurations. _Note: This requires a pro or enterprise tier licenses. Users, tenants and access keys are not cloned._ ### See Also - See [Managing Environments](/customize/environments/) for details about managing environments. - [Delete Project](/api/management/projects/delete-project): ### Delete a project utilizing a management key. This endpoint allows you to delete a project. This action is irreversible, use with caution. ### See Also - See [Managing Environments](/customize/environments/) for details about managing environments. - [Clone Project (Async)](/api/management/projects/clone-project-async): Clone a project, including its settings and configurations. Users, tenants and access keys are not cloned. This API is asynchronous and will return a unique ID that can be used to track the progress of the clone operation. - [Get Clone Project Process](/api/management/projects/get-clone-project-process): Get the status of an asynchronous clone project process. This returns an object describing the new project details or an error if the process failed, using a valid management key. - [Export Messaging Localization](/api/management/projects/export-messaging-template-localization): Export messaging localization, using a valid management key. - [Import Messaging Localization](/api/management/projects/import-messaging-localization): Import messaging localization, using a valid management key. - Fine-Grained Authorization (FGA) - [Fine-Grained Authorization (FGA) API Overview](/api/management/fga): Use the Descope API to manage Fine-Grained Authorization (FGA) with a management key. - [Check FGA Permission](/api/management/fga/check-permission): ### Check FGA permission This endpoint allows you to check if a target has a specific relation to a resource using Fine-Grained Authorization. - [Get FGA Relations](/api/management/fga/create-relations): ### Get FGA relations This endpoint allows you to retrieve relations for a given target or resource using Fine-Grained Authorization. - [Delete FGA Relations](/api/management/fga/delete-relations): ### Delete FGA relations This endpoint allows you to delete relations using Fine-Grained Authorization. - [Get FGA Schema](/api/management/fga/get-schema): ### Get FGA schema This endpoint allows you to retrieve the current Fine-Grained Authorization schema for your project. - [Save FGA Schema](/api/management/fga/save-schema): ### Save FGA schema This endpoint allows you to save (create or update) the Fine-Grained Authorization schema for your project. - [Get Mappable Resources](/api/management/fga/get-mappable-resources): ### Get mappable resources This endpoint allows you to retrieve mappable resources for Fine-Grained Authorization. - [Get Mappable Schema](/api/management/fga/get-mappable-schema): ### Get mappable schema This endpoint allows you to retrieve the mappable schema for Fine-Grained Authorization. - [Search for FGA mappable resources](/api/management/fga/search-mappable-resources): Search for FGA mappable resources. - [Delete All FGA Relations](/api/management/fga/delete-all-fga-relations): Delete all project FGA relations - [Load FGA Resources](/api/management/fga/load-resources-details): ### Load FGA resources This endpoint allows you to load resources for Fine-Grained Authorization. - [Save FGA Resources](/api/management/fga/save-resources-details): ### Save FGA resources This endpoint allows you to save resources for Fine-Grained Authorization. - Audit - [Search Audit](/api/management/audit/search-audit): ### Search the audit log, using a valid management key. This API endpoint allows you to search the audit log utilizing various search parameters and returns the results in JSON format. - [Create Audit Event](/api/management/audit/create-audit-event): ### Create an audit log event, using a valid management key. This API endpoint allows you to create an audit log utilizing various parameters and returns the results in JSON format. - [Search Analytics](/api/management/audit/search-analytics): Search analytics (summarized) data grouped by time periods, using a valid management key. - Descopers - [Create Descoper](/api/management/descopers/create-descopers): Create a descoper - [Get Descoper](/api/management/descopers/get-descoper): Get a descoper - [Update Descoper](/api/management/descopers/update-descoper): Update a descoper - [Delete Descoper](/api/management/descopers/delete-descoper): Delete a descoper - [List Descopers](/api/management/descopers/list-descopers): List descopers - Inbound Apps - [Create third party application](/api/management/third-party-apps/create-third-party-application): Create a new third party application, using a valid management key. - [Load All third party applications](/api/management/third-party-apps/load-all-third-party-applications): Loads all project third party applications, using a valid management key. - [Load third party application by ID](/api/management/third-party-apps/load-third-party-application): Loads project third party application by id, using a valid management key. - [Update third party application](/api/management/third-party-apps/update-third-party-application): Update a third party application, using a valid management key. - [Patch third party application](/api/management/third-party-apps/patch-third-party-application): Patch a third party application, using a valid management key. - [Get third party application secret](/api/management/third-party-apps/get-third-party-application-secret): Get a third party application secret, using a valid management key. - [Rotate third party application secret by application ID](/api/management/third-party-apps/rotate-third-party-application-secret): Rotate the project third party application secret by the application id, using a valid management key. - [Search third party application consents](/api/management/third-party-apps/search-third-party-application-consents): Search OAuth user consents for [Inbound Apps](/identity-federation/inbound-apps). Filter by `appId`, `userId`, `consentId`, or `tenantId`. For [agentic identities](/agentic-identity-hub/core-components/agents) (MCP server authorizations), use [Search agentic identities](/api/management/agentic-identity-hub/search-agentic-identities) instead — it returns agent name, resource ID, and client ID alongside each consent. - [Delete third party application consents](/api/management/third-party-apps/delete-third-party-application-consents): Delete OAuth user consents for [Inbound Apps](/identity-federation/inbound-apps). Provide `consentIds`, or filter by `appId`, `userIds`, and optional `tenantId`. To revoke [agentic identities](/agentic-identity-hub/core-components/agents), use [Revoke agentic identities](/api/management/agentic-identity-hub/revoke-agentic-identities) instead — it scopes deletion to agentic consents and supports `clientId` and `resourceId` filters. - [Delete third party application consents by tenant](/api/management/third-party-apps/delete-third-party-application-tenant-consents): Delete all OAuth user consents for an [Inbound App](/identity-federation/inbound-apps) within a tenant. Provide `tenantId` and optional `appId` or `consentIds`. - [Delete third party application](/api/management/third-party-apps/delete-third-party-application): Delete a third party application, using a valid management key. - [Batch delete third party applications](/api/management/third-party-apps/batch-delete-third-party-applications): Delete multiple third party applications in batch, using a valid management key. - Outbound Apps - [Outbound Apps](/api/management/outbound-apps): Manage outbound applications that allow your users to authenticate with external services. - [List All Outbound Apps](/api/management/outbound-apps/list-all-outbound-apps): ### List all outbound applications This endpoint allows you to retrieve all outbound applications configured in your project. - [List Outbound Apps with User Token](/api/management/outbound-apps/list-outbound-apps-with-user-token): ### List outbound applications with user token This endpoint allows you to retrieve outbound applications that have a user token available. - [Get Outbound App by ID](/api/management/outbound-apps/get-outbound-app-by-id): ### Get outbound application by ID This endpoint allows you to retrieve a specific outbound application by its ID. - [Create Outbound App](/api/management/outbound-apps/create-outbound-app): ### Create outbound application This endpoint allows you to create a new outbound application. - [Update Outbound App](/api/management/outbound-apps/update-outbound-app): ### Update outbound application This endpoint allows you to update an existing outbound application. - [Delete Outbound App](/api/management/outbound-apps/delete-outbound-app): ### Delete outbound application This endpoint allows you to delete an outbound application. - [Fetch Outbound App User Token](/api/management/outbound-apps/fetch-outbound-app-user-token): ### Fetch outbound application user token This endpoint allows you to fetch the user token for an outbound application. - [Fetch Latest Outbound App User Token](/api/management/outbound-apps/fetch-latest-outbound-app-user-token): ### Fetch latest outbound application user token This endpoint allows you to fetch the latest user token for an outbound application. - [Fetch Outbound App Tenant Token](/api/management/outbound-apps/fetch-outbound-app-tenant-token): ### Fetch outbound application tenant token This endpoint allows you to fetch the tenant token for an outbound application. - [Fetch Latest Outbound App Tenant Token](/api/management/outbound-apps/fetch-latest-outbound-app-tenant-token): ### Fetch latest outbound application tenant token This endpoint allows you to fetch the latest tenant token for an outbound application. - [Delete outbound application token by id](/api/management/outbound-apps/delete-outbound-app-token-by-id): Delete outbound application token by id, using a valid management key. - [Delete outbound application tokens by appId or userId](/api/management/outbound-apps/delete-outbound-app-user-tokens): Delete outbound application tokens by appId or userId, using a valid management key. - [Create outbound application according to existing dcr preset](/api/management/outbound-apps/create-outbound-app-by-dcr-preset): Create a new outbound application according to existing dcr preset, using a valid management key. - [Create outbound application by existing template](/api/management/outbound-apps/create-outbound-app-by-template): Create a new outbound application by existing template using a valid management key. - [Connect to outbound application](/api/management/outbound-apps/connect-outbound-app): Connect to outbound application, using a valid JWT. - [Upload user API key for outbound app](/api/management/outbound-apps/upload-outbound-app-user-api-key): Upload/set a static API key for a user on an apikey-type outbound application, using a valid management key. - [Upload tenant API key for outbound app](/api/management/outbound-apps/upload-outbound-app-tenant-api-key): Upload/set a static API key for a tenant on an apikey-type outbound application, using a valid management key. - [Upload Outbound App User OAuth Token](/api/management/outbound-apps/upload-outbound-app-user-oauth-token): ### Upload a user OAuth token for an outbound application Import a pre-existing user-scoped OAuth token into an outbound application without requiring the user to re-run the OAuth flow. Requires a management key. - [Upload Outbound App Tenant OAuth Token](/api/management/outbound-apps/upload-outbound-app-tenant-oauth-token): ### Upload a tenant OAuth token for an outbound application Import a pre-existing tenant-scoped OAuth token into an outbound application without requiring the user to re-run the OAuth flow. Requires a management key. - [Batch Upload Outbound App User OAuth Tokens](/api/management/outbound-apps/batch-upload-outbound-app-user-oauth-tokens): ### Batch upload user OAuth tokens for an outbound application Import pre-existing user-scoped OAuth tokens in a single request. This operation is all-or-nothing: if any token fails validation, the entire batch is rejected and no tokens are committed. Fix the reported failures and retry the full batch. Requires a management key. - [Batch Upload Outbound App Tenant OAuth Tokens](/api/management/outbound-apps/batch-upload-outbound-app-tenant-oauth-tokens): ### Batch upload tenant OAuth tokens for an outbound application Import pre-existing tenant-scoped OAuth tokens in a single request. This operation is all-or-nothing: if any token fails validation, the entire batch is rejected and no tokens are committed. Fix the reported failures and retry the full batch. Requires a management key. - Agentic Identity - [Search agentic identities](/api/management/agentic-identity-hub/search-agentic-identities): List [agentic identities](/agentic-identity-hub/core-components/agents) — authorization records that bind an OAuth client to a user, tenant, or autonomous client. Filter by `clientId`, `resourceId`, `userId`, or `consentId`. Returns consent details, agent name, resource ID, and client ID for each identity. Use `page` (zero-based) and `limit` for pagination. - [Revoke agentic identities](/api/management/agentic-identity-hub/revoke-agentic-identities): Revoke agentic identities and invalidate their consents — the same operation as [revoking access in the Console](/agentic-identity-hub/core-components/agents#revoking-access). Combine filters to narrow scope: - `clientId` + `userId` — one user's grant to a specific agent - `consentId` + `userId` — a specific consent for a user - `resourceId` + `userId` — all of a user's grants on one MCP server [Resource](/resources) - `userId` alone — all agentic identities for that user across every MCP server Returns the number of identities revoked in `revoked`. - Access Key Management - [Rotate Access Key](/api/management/access-key-management/rotate-access-key): Rotate an access key — regenerates the secret for an existing access key while preserving the same key ID, name, roles, tenants, expiry and metadata. The new cleartext is returned exactly once and the previous secret stops working immediately. - Dynamic Registration Templates Management - [Create dynamic registration template](/api/management/dynamic-registration-templates-management/create-dynamic-registration-template): Create a new dynamic registration template, using a valid management key. - [Delete dynamic registration template](/api/management/dynamic-registration-templates-management/delete-dynamic-registration-template): Delete a dynamic registration template by id, using a valid management key. - [Delete dynamic registration templates](/api/management/dynamic-registration-templates-management/delete-dynamic-registration-templates): Delete multiple dynamic registration templates by id, using a valid management key. - [Load all dynamic registration templates](/api/management/dynamic-registration-templates-management/load-all-dynamic-registration-templates): Load all dynamic registration templates, using a valid management key. - [Load dynamic registration template](/api/management/dynamic-registration-templates-management/load-dynamic-registration-template): Load a dynamic registration template by id, using a valid management key. - [Update dynamic registration template](/api/management/dynamic-registration-templates-management/update-dynamic-registration-template): Update an existing dynamic registration template, using a valid management key. - Embedded Link - [Generate a token for user sign up, later can be verified with magiclink](/api/management/embedded-link/embedded-link-signup): Generate a token for user sign up - Engines Management - [Create engine](/api/management/engines-management/create-engine): Create a new engine, returning its ID and secret. Requires a valid management key. - [Delete engine](/api/management/engines-management/delete-engine): Delete an engine, using a valid management key. - [Load engine by ID](/api/management/engines-management/load-engine): Load an engine by ID, using a valid management key. - [Load all engines](/api/management/engines-management/load-engines): Load all engines for the project, using a valid management key. - [Rotate engine secret](/api/management/engines-management/rotate-engine-secret): Rotate an engine's secret, returning the new secret. The previous secret is immediately invalidated. Requires a valid management key. - [Update engine](/api/management/engines-management/update-engine): Update an existing engine, using a valid management key. - Generic Auth - [Generate JWT for Sign-In](/api/management/generic-auth/generate-jwt-sign-in): Generate a JWT for an existing user, using a valid management key. - [Generate JWT for Sign-Up or Sign-In](/api/management/generic-auth/generate-jwt-sign-up-or-in): Create a new user and generate a JWT for them, or just generate a JWT if the user already exists. Uses a valid management key. - [Generate JWT for Sign-Up](/api/management/generic-auth/generate-jwt-sign-up): Create a new user and generate a JWT for them, using a valid management key. - JWT Templates - [Apply JWT Template From Library](/api/management/jwt-templates/apply-jwt-template-from-library): Materialise a library entry as a new project JWT template. Optional overrides let the caller pick a different name, swap tags, or amend the claim body before save. Strict validation runs as if it were a create. - [Create JWT Template](/api/management/jwt-templates/create-jwt-template): Create a new JWT template. Strict validation runs first — if it fails, the response carries a list of `ValidationIssue`s with stable codes (RESERVED_CLAIM_KEY, NAME_MISSING, …) and the template is not saved. type must be "user" or "key". authSchema in {default,tenantOnly,none}. issuerType in {legacy,inbound,federated}. emptyClaimPolicy in {none,nil,delete}. The `template` field is the JSON object whose keys are claim names. - [Delete JWT Template](/api/management/jwt-templates/delete-jwt-template): Delete a JWT template by id. The project's default templates are restored where this one was referenced. - [List JWT Template Library](/api/management/jwt-templates/list-jwt-template-library): List the curated JWT template library Descope ships — starter templates with documented use cases, optional logos, and `experimental` flags. - [List JWT Templates](/api/management/jwt-templates/list-jwt-templates): List every JWT template defined on the current project. Returns full field detail for each — name, description, type (key|user), tags, claim body, authSchema, issuerType, etc. - [Load JWT Template Library Entry](/api/management/jwt-templates/load-jwt-template-library-entry): Load a single library entry by id, including the full claim body — required before applying. - [Load JWT Template](/api/management/jwt-templates/load-jwt-template): Load a single JWT template by id. - [Update JWT Template](/api/management/jwt-templates/update-jwt-template): Update an existing JWT template by id. Same strict validation as CreateJwtTemplate runs first; on failure the existing template is unchanged. - [Validate JWT Template](/api/management/jwt-templates/validate-jwt-template): Dry-run validate a JWT template without saving. Pass either an inline `template` payload (to validate before create/update) or an existing `id` (to lint a saved template). Returns a list of `ValidationIssue`s — empty list means valid. - Lists - [Add IPs to List](/api/management/lists/add-i-ps-to-list): Add one or more IPs to an existing IP list - [Add Texts to List](/api/management/lists/add-texts-to-list): Add one or more text items to an existing text list - [Check IP in List](/api/management/lists/check-ip-in-list): Check if a specific IP exists in a list - [Check Text in List](/api/management/lists/check-text-in-list): Check if a specific text exists in a list - [Clear List](/api/management/lists/clear-list): Clear all IPs from a list - [Create List](/api/management/lists/create-list): Create a new list - [Delete List](/api/management/lists/delete-list): Delete a list by ID - [Get All Lists](/api/management/lists/get-all-lists): Get all lists - [Get List By Name](/api/management/lists/get-list-by-name): Get a list by name - [Get List](/api/management/lists/get-list): Get a list by ID - [Import Lists](/api/management/lists/import-lists): Import multiple lists - [Remove IPs from List](/api/management/lists/remove-i-ps-from-list): Remove one or more IPs from an existing IP list - [Remove Texts from List](/api/management/lists/remove-texts-from-list): Remove one or more text items from an existing text list - [Update List](/api/management/lists/update-list): Update an existing list - Management Keys - [Create Management Key](/api/management/management-keys/create-management-key): Create a management key using another management key. - [Delete Management Key](/api/management/management-keys/delete-management-keys): Delete a management key using another management key. - [Get Management Key](/api/management/management-keys/get-management-key): Get a management key using another management key. - [Search Management Keys](/api/management/management-keys/search-management-keys): Search management keys using another management key. - [Update Management Key](/api/management/management-keys/update-management-key): Update a management key using another management key. All supported fields will be reset if not provided. - MCP Server Clients - [Create MCP Server Client](/api/management/mcp-server-client-management/create-mcp-server-client): Create an MCP Server Client, using a valid management key. - [Delete MCP Server Client](/api/management/mcp-server-client-management/delete-mcp-server-client): Delete an MCP Server Client by ID, using a valid management key. - [Delete MCP Server Clients](/api/management/mcp-server-client-management/delete-mcp-server-clients): Delete multiple MCP Server Clients by IDs, using a valid management key. - [Get MCP Server Client Secret](/api/management/mcp-server-client-management/get-mcp-server-client-secret): Get MCP Server Client secret, using a valid management key. - [Load MCP Server Client](/api/management/mcp-server-client-management/load-mcp-server-client): Load an MCP Server Client by ID, using a valid management key. - [Rotate MCP Server Client Secret](/api/management/mcp-server-client-management/rotate-mcp-server-client-secret): Rotate MCP Server Client secret, using a valid management key. - [Search MCP Server Clients](/api/management/mcp-server-client-management/search-mcp-server-clients): Search MCP Server Clients for a specific MCP Server, using a valid management key. - [Update MCP Server Client](/api/management/mcp-server-client-management/update-mcp-server-client): Update an MCP Server Client, using a valid management key. - MCP Servers - [Create MCP Server](/api/management/mcp-server-management/create-mcp-server): Create an MCP Server, using a valid management key. - [Delete MCP Server](/api/management/mcp-server-management/delete-mcp-server): Delete an MCP Server by ID, using a valid management key. - [Delete MCP Servers](/api/management/mcp-server-management/delete-mcp-servers): Delete multiple MCP Servers by IDs, using a valid management key. - [Load All MCP Servers](/api/management/mcp-server-management/load-all-mcp-servers): Load all MCP Servers for a project, using a valid management key. - [Load MCP Server](/api/management/mcp-server-management/load-mcp-server): Load an MCP Server by ID, using a valid management key. - [Update MCP Server](/api/management/mcp-server-management/update-mcp-server): Update an MCP Server, using a valid management key. - Otp Management - [Get OTP Settings for a tenant](/api/management/otp-management/get-tenant-otp-settings): Get OTP Settings for a tenant, using a valid management key. - [Set OTP Settings for a tenant](/api/management/otp-management/set-tenant-otp-settings): Set OTP Settings for a tenant, using a valid management key. - Outbound Scim Management - [Create outbound SCIM configuration](/api/management/outbound-scim-management/create-outbound-scim-configuration): Create a new outbound SCIM configuration, using a valid management key. Configures a SCIM connector that provisions users from a federated application to an external SCIM 2.0 service provider. - [Delete outbound SCIM configuration](/api/management/outbound-scim-management/delete-outbound-scim-configuration): Delete an outbound SCIM configuration, using a valid management key. - [Load outbound SCIM configuration](/api/management/outbound-scim-management/load-outbound-scim-configuration): Load an outbound SCIM configuration by id. Response merges connector config with webhook status (enabled flag, last export/processing times, failure counter). - [Enable or disable an outbound SCIM configuration](/api/management/outbound-scim-management/set-outbound-scim-enabled): Enable or disable a specific outbound SCIM configuration. Separate from Update because enable/disable is a high-frequency toggle. - [Update outbound SCIM configuration](/api/management/outbound-scim-management/update-outbound-scim-configuration): Update an existing outbound SCIM configuration, using a valid management key. - Policy Rules Management - [Create policy rule](/api/management/policy-rules-management/create-policy-rule): Create a new policy rule row using a valid management key. The id is server-generated. - [Delete policy rule](/api/management/policy-rules-management/delete-policy-rule): Delete a policy rule row matched by id. Idempotent. - [Load policy rule settings](/api/management/policy-rules-management/load-policy-rule-settings): Load the project-level policy rule settings (default action). - [Load policy rule](/api/management/policy-rules-management/load-policy-rule): Load a single policy rule row by id. - [Reorder a policy rule](/api/management/policy-rules-management/reorder-policy-rule): Move one policy rule to a 1-based position in the evaluation order; rules in between shift accordingly. Rules are evaluated first-match in this order. - [Search policy rules](/api/management/policy-rules-management/search-policy-rules): Search policy rule rows by filters (text, action_kind, effect, principal_type, resource_type, enabled). Paged and sorted. - [Update policy rule settings](/api/management/policy-rules-management/update-policy-rule-settings): Update the project-level policy rule settings. defaultAction is allow or block; the choice is one-way and cannot be reset to the unconfigured state. - [Update policy rule](/api/management/policy-rules-management/update-policy-rule): Replace an existing policy rule row matched by id. - Resource Policies - Resources - [Load resource by ID](/api/management/resources-management/load-resource): Load a resource by ID, using a valid management key. - [Load resource by URI](/api/management/resources-management/load-resource-by-uri): Load a resource by URI, using a valid management key. - [Load all resources](/api/management/resources-management/load-all-resources): Load all resources, using a valid management key. - [Create resource](/api/management/resources-management/create-resource): Create a new resource, using a valid management key. - [Update resource](/api/management/resources-management/update-resource): Update a resource, using a valid management key. - [Delete resource](/api/management/resources-management/delete-resource): Delete a resource, using a valid management key. - [Delete resources batch](/api/management/resources-management/delete-resources): Delete multiple resources, using a valid management key. - Scope Claim Mapping - [Delete Scope Claim Mapping](/api/management/scope-claim-mapping/delete-scope-claim-mapping): Remove the project-wide scope-to-claims mapping. - [Get Scope Claim Mapping](/api/management/scope-claim-mapping/get-scope-claim-mapping): Get the project-wide mapping of OIDC scopes to JWT claims. Returns an empty mapping when none has been configured. - [Set Scope Claim Mapping](/api/management/scope-claim-mapping/set-scope-claim-mapping): Replace the project-wide mapping of OIDC scopes to JWT claims. Each value may be a static string or a {{...}} template resolved at token-generation time.