Stytch

Security for AI acquired

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2020
Funding $126.3M
Last updated 2026-09-10

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Cloud communications company Twilio acquired Stytch in November 2025 and kept the brand. Stytch sells login and access control that developers build into their software. Its Connected Apps product lets an application give AI agents limited access to account data with the owner's consent. Founded in 2020, Stytch had raised $126.3 million, including a $90 million round led by Coatue Management in 2021. Crossmint, GenomOncology, and Spydr are customers using it for AI agents. It has not published customer counts or revenue for Connected Apps. A 2026 MarkTechPost review of agent-authentication platforms lists WorkOS, Auth0, and Descope as alternatives to it. Its clearest strength is how quickly developers can add it, an afternoon for Spydr and under a day for GenomOncology.

Sourced Details

Description Stytch Connected Apps handles authorization for AI agent and MCP workflows, letting developers control which apps and agents connect to their application through consent screens, scoped permissions, and admin allowlists. [f1]
Acquisition Twilio, announced 2025-10-30 [f2]
Founded 2020 [f3]
HQ San Francisco, California, US [f3]
Funding $126.3M total [f3]
Latest funding Series B, $90M (November 2021) [f3]
Deployment SaaS [f4]
Compliance ISO 27001, PCI DSS, SOC 2 [f4]

Products

Product What it does
Stytch Connected Apps Stytch Connected Apps: Authorization for AI agent and MCP workflows that connects agents to applications with consent management, scoped permissions, and admin allowlists.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Stytch Connected Apps provides authorization for AI agent and MCP workflows, connecting agents to applications with consent management, scoped permissions, and admin allowlists. It is mapped to the AI Defense Matrix. [f5]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 26 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Stytch defines a precise agent and MCP access problem, but the demand corroboration comes from a single non-vendor source (SC Media citing an Akeyless forecast) and the pain itself is technical rather than quantified, so it falls short of the multiple independent quantification a 4 needs. [s1, s2, s6]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 An independent review, not vendor copy, confirms the depth: MarkTechPost reports Connected Apps implements OAuth 2.1 with PKCE, Dynamic Client Registration, and a consent UI, and runs as a standalone layer over an existing identity provider. The official docs confirm the OAuth/OIDC authorization-server design. Matches Aembit on external-validation strength. [s2, s8, s1]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Buyer-side signals cluster in the last year, with MCP authorization an active need and Twilio paying to enter the market in late 2025. SC Media cites an Akeyless forecast that over 95% of organizations plan to deploy AI agents within the next year, a market-level adoption forecast that frames the category rather than demand evidence specific to Stytch. The enabler is MCP's 2024-2025 adoption creating demand for agent OAuth. [s6, s5, s8]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 The founders carry verifiable in-domain experience from engineering authentication at Plaid, but that is a prior senior role rather than a founder exit, and no sustained publication record appears in the line's evidence, so the team sits at the relevant-experience level. [s9, s5]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 The agent line carries named references now: Crossmint authenticates agents on Connected Apps, GenomOncology runs BioMCP on Stytch OAuth, and Spydr powers an MCP server, alongside the Twilio acquisition and an independent ranking. Held at 3 rather than 4 because these are vendor case studies without disclosed scale, revenue, or third-party validation, not for absence of named customers. The score stays a step below the tier above, which needs marketplace motion or independent corroboration the public record does not yet show here. [s11, s12, s13, s5, s8]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Stytch is a venture-backed developer-identity company now owned by Twilio, with the deal terms undisclosed, so output per capital cannot be confirmed from the public record. The acquisition removes independent burn-rate signals. Held at the score rather than lifted. [s5, s7]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 MarkTechPost and Security Boulevard place the line in agent authentication without vendor coaching, but that category is still forming around a recent ranked field and shifting labels, the same read applied to Descope, so it holds at present but unproven. [s8, s7]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 The capability is OAuth authorization plumbing that rival platforms can and do ship, with MarkTechPost naming WorkOS, Auth0, Descope, and Cloudflare as interchangeable for the same role. The moat is developer distribution, not agent-native IP, and the line now sits inside Twilio. [s8, s7]
Business Risks WorkOS, Auth0, or Descope could ship equivalent MCP authorization flows and erase Stytch's product lead, since an independent review treats them as interchangeable authorization servers for the same edge deployments…
  • WorkOS, Auth0, or Descope could ship equivalent MCP authorization flows and erase Stytch's product lead, since an independent review treats them as interchangeable authorization servers for the same edge deployments.
  • Stytch's agent-line references could stay small early-adopter case studies without disclosed scale or revenue, leaving the acquisition to carry the weight of public proof that the line has durable demand.
  • Twilio could fold Connected Apps into its broader Verify and Lookup authentication portfolio and retire the standalone Stytch brand, since the deal framed Stytch as anchoring the entire Twilio Platform.
  • Cloudflare could deepen first-party OAuth support in its Agents SDK and remove the edge-integration advantage that the independent review named as Stytch's clearest differentiator.
  • The ex-Plaid founding team could depart after the acquisition, weakening the team credibility that rests on their authentication background rather than on a long agent-specific research record.
Problem & Market AI agents need a way to prove who they are and to receive only the access a user has consented to grant, and Stytch built Connected Apps to provide that for developers…

AI agents need a way to prove who they are and to receive only the access a user has consented to grant, and Stytch built Connected Apps to provide that for developers. The product turns an application into an OAuth and OIDC authorization server so agents, MCP clients, and external tools can reach user data without handling raw credentials.

The buyer is the engineering team adding agent or MCP support to a software product. SC Media framed the surrounding market as a race to secure autonomous agents and cited an Akeyless forecast that over 95% of organizations plan to deploy AI agents within the next year. That forecast is a market-level adoption projection that frames the category rather than a measure of demand for Stytch or Connected Apps. The demand signal specific to Stytch is Twilio's decision to acquire it in November 2025. [s1, s2, s6, s5]

Product Capabilities Connected Apps implements the authorization mechanics that agent and MCP workflows require, and an independent review confirms the depth rather than relying on Stytch's own claims…

Connected Apps implements the authorization mechanics that agent and MCP workflows require, and an independent review confirms the depth rather than relying on Stytch's own claims. MarkTechPost's 2026 roundup of agent-authentication platforms reported that Connected Apps implements OAuth 2.1 with PKCE, Dynamic Client Registration, and a consent UI, and can run as a standalone layer on top of an existing identity provider.

The product presents consent and permissions in terms a user can reason about. Stytch describes scoped, RBAC-based permissions grouped into logical sets, org-level visibility into every connected app and token, and a rule that an app inherits only the permissions the user already holds. The clearest differentiator the independent review named is a clean fit with Cloudflare Workers through Trusted Auth Tokens, which suits teams running agents at the edge. [s8, s2, s1]

Competitive Positioning Stytch competes in a defined field of agent-authentication providers, and an independent ranking places it near the top without vendor coaching…

Stytch competes in a defined field of agent-authentication providers, and an independent ranking places it near the top without vendor coaching. MarkTechPost's 2026 review ranked Stytch second among eight platforms and named WorkOS, Auth0, Descope, and Cloudflare among the alternatives that can serve the same MCP authorization role.

Stytch's edge in that field is reach rather than unique technology. Security Boulevard called the Twilio acquisition a watershed moment for developer-first identity and positioned the combination as a credible alternative to Auth0 built on a platform developers already trust. The same review noted that Connected Apps can sit on top of a competitor's identity stack, which lets a team adopt Stytch's agent flows without replacing what it already runs. [s8, s7]

Go-to-Market & Traction Stytch's agent line now shows both an acquisition and named early references…

Stytch's agent line now shows both an acquisition and named early references. Twilio announced the deal on October 30, 2025 and completed it on November 14, 2025, describing Stytch as an identity platform for AI agents that is built for developers. The acquisition remains a heavy proof point, and it is no longer the sole one.

Named customers ship the agent product in public case studies. Crossmint uses Stytch Connected Apps to authenticate AI agents over a CLI, GenomOncology runs OAuth for its open-source BioMCP server on Cloudflare Workers, and Spydr powers a per-user MCP memory server on dynamically provisioned OAuth clients. What stays thin is independent corroboration of scale: these are vendor-published case studies without disclosed revenue, deployment counts, or third-party validation, so the agent-line traction is real and named but not yet independently sized. [s5, s4, s11, s12, s13, s8]

Team & Credibility Stytch's founders carry verifiable authentication experience from a recognized infrastructure company, which supports their claim to the problem…

Stytch's founders carry verifiable authentication experience from a recognized infrastructure company, which supports their claim to the problem. Co-founder and CTO Julianna Lamb described meeting co-founder Reed McGinley-Stempel at Plaid, where she worked as a backend engineer on authentication and fraud detection and prevention before they started Stytch.

The founders now work inside Twilio, which owns long-running authentication infrastructure and phone and email reputation graphs. Twilio framed the acquisition as extending its authentication scale to give agents verifiable identities, a statement of the parent's plans rather than a capability the agent team has demonstrated. The public record shows a credible founding background and an owner with assets it could contribute, while the team's own proof remains the founders' authentication work rather than a long record of agent-specific research. [s9, s5]

Trust Readiness Stytch's trust position rests on standard authorization protocols and on now operating under Twilio's ownership and policies…

Stytch's trust position rests on standard authorization protocols and on now operating under Twilio's ownership and policies. Connected Apps is built on OAuth and OIDC, the established frameworks for granting scoped access without sharing credentials, which gives buyers a familiar security model to evaluate.

Twilio's purchase changed the accountability picture in late 2025. Stytch's site now carries Twilio's terms of use and privacy policy, and Stytch told customers to expect no immediate changes to contracts, pricing, SDKs, API keys, or integrations after the deal. For a buyer, Twilio now sets the contractual and continuity terms, and the product's own record remains its named early references rather than independent scale. [s2, s5, s4]

Competitors Descope, WorkOS, Auth0, Aembit, Cloudflare…
Company Relationship Note Compare
Descope competes with Agentic Identity Hub provides inbound and outbound MCP authorization for AI agents. N/AWe scored these companies at different scopes, so the totals measure different things.
WorkOS competes with AuthKit offers standalone MCP OAuth as an authorization server for agents. N/AWe scored these companies at different scopes, so the totals measure different things.
Auth0 competes with Named by an independent review as an alternative MCP authorization server. N/AWe scored these companies at different scopes, so the totals measure different things.
Aembit competes with Agent-native workload and agent identity with MCP authorization-server support. N/AWe scored these companies at different scopes, so the totals measure different things.
Cloudflare adjacent Agents SDK coordinates transport and can use Stytch or rivals as the external auth server. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with Stytch.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Stytch brings specialized OAuth 2.1 and OIDC authorization-server engineering and a control-plane position beneath the agent tools developers build, the two parts of the line hardest for a rival to reproduce quickly. Neither is a lock. A 2026 independent review names WorkOS, Auth0, and Descope serving the same authorization-server function for differing buyer fits, and because those rivals run the same standardized OAuth flows, a team that routes agent consent and tokens through Connected Apps faces re-plumbing to leave, with code portability an inference, not a documented outcome. The evidenced edge is fast developer integration rather than agent-specific technology. Twilio completed its acquisition in November 2025 and now owns the line, so a buyer weighs it as part of that parent.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Connected Apps is a customer-integrated API and SDK product, an OAuth and OIDC authorization server the developer wires in and partly hosts, with no managed service or accountability layer in the offer.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Embedding the consent and token plane as the app's authorization server creates real re-plumbing friction once agent flows route through it, but the product markets itself as a standalone layer over an existing stack and no residency lock or network effect appears in fetched sources.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Stytch holds SOC 2, ISO 27001, and PCI-DSS, now retrieved through the Twilio Trust Center, but these are table-stakes assurance that eases procurement without blocking substitutes and no regime mandates this product class.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Standards-correct OAuth 2.1 and OIDC authorization-server engineering with PKCE, Dynamic Client Registration, a consent UI, and per-agent scoped tokens at scale is specialized identity engineering.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The buyer is the developer or engineering team adding agent auth through a self-serve, free-tier product, and the named references integrated in an afternoon to under 15 days rather than through procurement-gated enterprise rollouts.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 Connected Apps is the authorization and consent control plane that agents and MCP clients depend on to reach app data, positioned underneath the agent tools developers build rather than as an end-user application.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 OAuth tokens, consent records, and RBAC scopes are per-customer configuration a funded rival rebuilds from the same public protocols, with no named non-public cross-customer corpus, and Twilio's reputation and device-intelligence data is a parent asset rather than the line's.
Strategic Market Segmentation Stytch sells to the engineering team adding agent or MCP support to a software product, with an entry motion that runs developer-first rather than procurement-first…

Stytch sells to the engineering team adding agent or MCP support to a software product, with an entry motion that runs developer-first rather than procurement-first. Connected Apps turns the customer's own application into an OAuth and OIDC authorization server so agents and MCP clients reach user data without handling raw credentials. The pitch is a developer one, framed as adding the flows without the engineering lift or changing the existing auth stack.

The published pricing confirms the self-serve developer segment. Stytch meters by monthly active users and agents with a 10,000 free allowance, then charges for external active members and agents with volume discounts, a product-led model aimed at teams that start small and grow. That fits MarkTechPost's read of the ideal buyer as a B2B SaaS team adding MCP authentication on top of an existing stack without a full migration.

The named references sit at the early-adopter end of that segment. Crossmint, GenomOncology, and Spydr are developer-led teams whose cited stories describe integrations within days rather than multi-quarter rollouts. The open question is whether Stytch pulls the developer base up-market into larger agent deployments before rivals close the same distribution.

Product Capabilities & AI Advantages Stytch's claimed advantage is standards-correct authorization that a developer can drop in rather than build…

Stytch's claimed advantage is standards-correct authorization that a developer can drop in rather than build. An independent review, not vendor copy, reports that Connected Apps implements OAuth 2.1 with PKCE, Dynamic Client Registration, and a consent UI, and can run as a standalone layer over an existing identity provider. The docs confirm the OAuth and OIDC authorization-server design underneath.

The clearest differentiator the review named is a clean fit with Cloudflare Workers. Stytch's Trusted Auth Tokens integrate with Cloudflare's Agents SDK so teams building remote MCP servers at the edge get authorization without extra plumbing, while GenomOncology paired Stytch-issued tokens with a Cloudflare Worker to put a production OAuth gateway in front of its biomedical MCP server. The consent and RBAC layer presents scoped permissions in logical groupings and limits an app to permissions the user already holds.

The verifiable footprint is strong for the category, with independent ranking and named production deployments. What holds up, though, is developer distribution rather than agent-specific technology, because the same review names WorkOS, Auth0, and Descope as serving the identical authorization-server role, and no proprietary model or non-public training corpus appears in fetched sources.

Sales Engagement & Go-to-Market Stytch reached the agent-auth market with an existing developer following and a working OAuth product, then converted that into named agent references…

Stytch reached the agent-auth market with an existing developer following and a working OAuth product, then converted that into named agent references. Crossmint authenticates agents over a CLI on Connected Apps, GenomOncology runs OAuth for its open-source BioMCP server on Cloudflare Workers, and Spydr powers a per-user MCP memory server on dynamically provisioned OAuth clients. Each case study reports an integration measured in days, with GenomOncology reporting production-ready auth in under a day, which is the self-serve motion the free tier is built to feed.

The acquisition is the heaviest single proof point, and named references now sit beside it. Twilio completed its acquisition of Stytch on November 14, 2025, describing Stytch as an identity platform for AI agents built for developers and positioning it to anchor the broader Twilio Platform. That a public communications company paid to enter agent identity validates Twilio's strategic interest, while demand for the line stays unquantified in the cited record.

What stays thin is independent corroboration of scale. The named references are vendor-published case studies without disclosed revenue, deployment counts, or third-party validation, so the agent-line traction is real and named but not yet independently sized.

Pricing Model Stytch publishes its pricing, which is itself a positioning signal in a category where many security vendors hide it…

Stytch publishes its pricing, which is itself a positioning signal in a category where many security vendors hide it. The model meters by monthly active users and AI agents, with a 10,000 free allowance and volume discounts above that, billed under a single line for external active members and agents. Publishing the unit and a generous free tier signals a product-led motion aimed at developers who self-serve before talking to sales.

The charged unit reveals what Stytch believes buyers pay for. By counting active users and agents rather than seats, API calls, or connected apps, the pricing ties cost to the identities the product secures, so a team's bill grows with the agent population it authenticates. That aligns the meter with the problem the buyer is measuring.

The free-tier-then-usage structure fits the land-grab the company is running. Letting teams build for free up to a real threshold lowers the cost of starting, which suits an early market where the goal is to win developers before rivals do, though it also means revenue per customer stays modest until agent volume climbs.

Product Delivery & Operations Stytch delivers Connected Apps as a customer-integrated API and SDK product, not as a managed service with hands-on accountability for outcomes…

Stytch delivers Connected Apps as a customer-integrated API and SDK product, not as a managed service with hands-on accountability for outcomes. The team integrates Stytch SDKs and APIs, turns its application into an authorization server, and hosts parts of the authorization flow itself, which is why the case-study integrations complete in days rather than through a vendor-run onboarding. Stytch still runs the hosted auth services, token issuance, dashboard, and APIs underneath, but there is no analyst layer or hands-on accountability for outcomes in the offer.

The product is built to sit on top of what a customer already runs. MarkTechPost notes Connected Apps can operate as a standalone layer over an existing CIAM provider, so a team locked into legacy identity infrastructure adopts the MCP-specific flows without migrating its user database. One published customer case demonstrates the edge fit rather than a general delivery capability. GenomOncology's BioMCP server runs Stytch's serverless OAuth within Cloudflare Workers.

A share of the operational risk profile is the buyer's to carry. Because Stytch hands the customer software to integrate and parts of the flow to host rather than operating a SOC-style function for it, published uptime or support commitments specific to the agent line do not surface in fetched pages.

Earning Customers' Trust Stytch carries an enterprise attestation set, but the trust accountability now routes through its parent…

Stytch carries an enterprise attestation set, but the trust accountability now routes through its parent. Its compliance documents, including a SOC 2 report, ISO 27001 certification, CAIQ, and PCI-DSS, are retrieved from the Twilio Trust Center rather than from Stytch directly, with the Stytch-specific documents retrieved through that portal. Stytch is now owned by Twilio, so a buyer should review the current Stytch and Twilio legal terms as part of any formal procurement.

The attestations are real procurement assurance but not a moat. SOC 2, ISO 27001, and PCI-DSS ease an enterprise security review, yet no compliance regime mandates an agent-authorization product, and a funded rival can clear the same bars. The breadth is table-stakes for an identity vendor handling user data and tokens.

The architecture carries part of the trust case for the agent line. Connected Apps is built on OAuth and OIDC, the established frameworks for scoped delegated access without sharing credentials, and the product limits an app to permissions the user already holds. A buyer should still resolve data-handling and retention terms with Twilio in a formal review beyond the published certifications.

Platform Strategy & Ecosystem Positioning Stytch positions Connected Apps as the authorization and consent control plane that agent workflows depend on, rather than an end-user application…

Stytch positions Connected Apps as the authorization and consent control plane that agent workflows depend on, rather than an end-user application. Agents and MCP clients pass through it to reach app data, and the product gives an organization visibility into every connected app, user, and scope with the ability to revoke tokens. That places the line underneath the agent tools developers build.

The control-plane position is real but shared with the rails it rides on. The product is built to layer over an existing identity provider and integrates tightly with Cloudflare's Agents SDK, while the cited page describes Connected Apps as platform agnostic, running over whatever edge infrastructure and CIAM the customer already uses. Owning the consent layer is the bet, and it sits on infrastructure Stytch does not control.

The acquisition reshaped the ecosystem story. Twilio frames Stytch as the identity layer anchoring its broader platform, which could put the line in front of Twilio's customer base. That potential reach is the parent's distribution asset and an external upside or risk, not a structural moat the agent line earned on its own, and no fetched source yet shows Connected Apps adoption converted through Twilio channels.

Team & Execution Capability Stytch's credibility comes from the authentication and authorization product and developer following it built as an independent company…

Stytch's credibility comes from the authentication and authorization product and developer following it built as an independent company. Twilio described buying that foundation to anchor an intelligent identity layer across its platform, which is the parent's plan for the asset rather than proof the agent team has produced on its own. The product addresses the identity domain directly rather than as an adjacent add-on.

The acquisition is the dominant team event. Twilio completed its purchase of Stytch on November 14, 2025 and describes the team and technology as augmenting its roadmap toward an intelligent identity layer for the whole Twilio Platform. Stytch's product remains live and separately branded inside Twilio, and Twilio now controls the funding and continuity decisions that venture investors once did.

The verifiable strength is the working product rather than a long agent-specific research record. Twilio's reach is a parent asset that could extend the team's work rather than evidence about the team itself. Fetched sources document the Connected Apps product and the Twilio deal but do not surface deep individual builds below the founders, so depth of the agent-line team beyond the principals is the open question.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 Stytch: Connected Apps official 2026-07-09
f2 Twilio completed its acquisition of Stytch (Nov 14, 2025) press 2026-06-16
f3 Sacra Stytch company profile research 2026-06-14
f4 AI Defense Matrix Catalog entry other 2026-06-13
f5 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (13)
Id Source Tier Accessed
s1 Stytch Connected Apps
“Power AI agent and MCP workflows, cross-app logins, and secure data sharing”
official 2026-06-13
s2 Stytch Connected Apps - Docs Overview
“Connected Apps is a Stytch product that enables your application to become an OAuth and OIDC Authorization server.”
official 2026-06-13
s3 Stytch homepage
“The identity platform for humans & AI agents.”
official 2026-06-13
s4 Stytch has joined Twilio (Oct 30, 2025)
“We're deepening our focus on building for the future where humans and agents both need to be authenticated and authorized.”
official 2026-06-13
s5 Twilio Acquired Stytch (Twilio blog, Nov 14, 2025)
“On November 14, we completed our acquisition of Stytch, an identity platform for AI agents that's built for developers.”
press 2026-06-13
s6 Twilio buys Stytch for AI identity (SC Media, Nov 10, 2025)
“A recent forecast from Akeyless suggests over 95% of organizations plan to deploy AI agents within the next year, driving urgent activity in the security sector.”
press 2026-06-13
s7 The Twilio-Stytch Acquisition: A Watershed Moment for Developer-First CIAM (Security Boulevard, Oct 2025)
“The Twilio-Stytch Acquisition: A Watershed Moment for Developer-First CIAM”
press 2026-06-13
s8 Best Authentication Platforms for AI Agents and MCP Servers in 2026 (MarkTechPost, May 2026)
“WorkOS, Stytch, Auth0, and Descope can all serve as the external authorization server, with Cloudflare handling transport, edge delivery, and session management.”
research 2026-06-13
s9 Interview with co-founder & CTO Julianna Lamb (Pulse 2.0, Jan 28, 2025)
“I've always been interested in startups and started my career at Strava before joining Plaid, where I met my co-founder, Reed.”
press 2026-06-13
s10 Stytch About
“Stytch is on a mission to help developers protect their applications and make auth that's simple and scalable.”
official 2026-06-13
s11 Authenticating AI agents via CLI: How Crossmint uses Stytch Connected Apps
“Authenticating AI agents via CLI: How Crossmint uses Stytch Connected Apps.”
official 2026-06-16
s12 How GenomOncology uses Stytch to secure open biomedical APIs for LLMs
“BioMCP connects LLMs to biomedical data through structured APIs. Stytch powers secure, serverless OAuth within Cloudflare Workers.”
official 2026-06-16
s13 AI Memory with Boundaries: How Spydr Used Stytch to Power their MCP Server
“Stytch powers Spydr's per-user memory access using secure, dynamically provisioned OAuth clients.”
official 2026-06-16
Deep-Dive Sources (13)
Id Source Tier Accessed
s1 Stytch homepage: the identity platform for humans and AI agents
“The identity platform for humans & AI agents. One integration for authentication, authorization, and security, making your app enterprise-ready and agent-ready.”
official 2026-06-18
s2 Stytch Connected Apps product page
“Power AI agent and MCP workflows, cross-app logins, and secure data sharing, Connected Apps makes it all possible without the engineering lift or changing your auth stack.”
official 2026-06-18
s3 Stytch Connected Apps docs overview
“Connected Apps is a Stytch product that enables your application to become an OAuth and OIDC Authorization server. Being an Authorization Server means that your Stytch-powered app can safely and securely share user data with other applications or services.”
official 2026-06-17
s4 Stytch pricing page (per-MAU model with a free tier for users and agents)
“Always free: 10,000 monthly active users and AI agents. Full suite of authn and authz features, OAuth, SSO, Sessions, and RBAC. External active members and agents, 10,000 included, Volume discounts.”
official 2026-06-17
s5 Twilio: Building Trust in the Age of AI (acquisition completed November 14, 2025)
“On November 14, we completed our acquisition of Stytch, an identity platform for AI agents that's built for developers. Stytch's talented team and proven technology will help Twilio augment our roadmap and build an intelligent identity layer that anchors the entire Twilio Platform.”
press 2026-06-18
s6 MarkTechPost: best authentication platforms for AI agents and MCP servers in 2026
“It implements OAuth 2.1 with PKCE, Dynamic Client Registration, and consent UI, and can operate as a standalone layer on top of existing CIAM providers. WorkOS, Stytch, Auth0, and Descope can all serve as the external authorization server.”
research 2026-06-17
s7 Stytch customer story: Crossmint authenticates AI agents via CLI
“By integrating the Stytch Node SDK into their CLI tool, whenever a developer or agent runs crossmint init, OAuth device code flow initiates. Stytch issues a scoped token. Autonomous agents can then provision Crossmint projects and resources.”
official 2026-06-17
s8 Stytch customer story: GenomOncology secures BioMCP for LLMs
“BioMCP connects LLMs to biomedical data through structured APIs. Stytch powers secure, serverless OAuth within Cloudflare Workers, eliminating the need for custom auth infrastructure. GenomOncology was fully integrated with production-ready auth in under a day.”
official 2026-06-17
s9 Stytch customer story: Spydr powers an MCP server with per-user memory
“Stytch powers Spydr's per-user memory access using secure, dynamically provisioned OAuth clients, ensuring every AI agent gets isolated, scoped access without brittle tokens or shared secrets. Spydr replaced their in-house auth with Stytch's in within an afternoon.”
official 2026-06-17
s10 Stytch docs: compliance documents via the Twilio Trust Center
“You can find Stytch's compliance documents, including our SOC 2 report, ISO 27001 certification, CAIQ, PCI-DSS, and more in the Twilio Trust Center. Be sure to look for the Stytch-specific documents, whose names start with Stytch.”
official 2026-06-18
s11 VentureBeat: Connected Apps untangles authorization tie-ups for AI agents
“Connected Apps is built on OAuth protocol OpenID Connect (OIDC) and incorporates consent and access management, human-in-the-loop authorization and standards-driven architecture to help protect sensitive B2B data.”
press 2026-06-30
s12 TechCrunch: Stytch, an API-first passwordless startup, raises $90M Series B at $1B valuation
“Stytch, an API-first passwordless authentication startup, has secured $90 million in Series B funding, pushing the company over the $1 billion valuation line.”
press 2026-06-30
s13 SC Media: Twilio buys Stytch for AI identity
“In a major move, cloud communications firm Twilio has announced its acquisition of identity management provider Stytch, aiming to build an intelligent identity layer to verify trust between humans and AI agents in real-time.”
press 2026-06-30

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.