← Back to all sparks
W

WorkOS

INFRA · APIS
Velocity6.3

WorkOS keeps widening its enterprise-auth platform, now making itself manageable by AI agents

enterprise-authenvironmentsmcpagenticaudit-logsdeveloper-platform
Current state
WorkOS is executing a broad platform-expansion cadence: environment management (Projects, self-serve environments, per-environment branding), directory and access controls (group roles, SCIM token rotation), audit log destinations (Snowflake), and developer surface (Pipes custom providers, API Gateway). The newest move exposes hundreds of management operations through an MCP server, making the platform programmatically and agent-manageable.
Where it's heading
The arc is from point auth features toward a full enterprise-identity platform with multi-environment operations and, increasingly, machine-driven administration. Shipping an MCP management server positions WorkOS for a world where AI agents provision and configure identity infrastructure, not just humans in a dashboard. The API Gateway hints at moving further into the request path.
Prediction
Expect the MCP server's operation coverage to deepen and more of the dashboard's configuration surface to become API- and agent-addressable, alongside continued environment- and project-level controls.

Recent moves

  1. 1d ago

    Step-up Auth

  2. 2d ago

    Management MCP Server

    ⚡ SPARK

    The most directional move in the set: WorkOS is making its own platform manageable by AI agents through an MCP server exposing hundreds of operations, a bet on machine-driven identity administration.

  3. 3d ago

    API Gateway

    Introduces an API Gateway that unifies API key and user auth at the edge, simplifying integration — a notable expansion of WorkOS further into the request path alongside its identity primitives.

  4. 4d ago

    Projects & Branding per Environment

    Adds organizational structure to the platform: environments can be grouped into Projects and given per-environment branding, part of the multi-environment operations buildout.

  5. 7d ago

    Waitlist

    Extends AuthKit with waitlists, letting teams collect and review signup requests before granting registration — an incremental addition to the hosted auth flow.

  6. 15d ago

    Roles for Groups

    Moves role management up to the group level with group role assignments, deepening the access-control surface for larger directories.