All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This analysis is scoped to agent and user identity.
WorkOS runs an enterprise-identity business, and most of its adoption evidence covers that platform rather than the AI-agent products it now markets. By independent estimates it has reached $30 million in recurring revenue and more than 1,000 paying customers, with a roster including OpenAI, Anthropic, and xAI. The record does not say what those companies buy, and the agent-line references on its own MCP page are MCP OAuth deployments, with Radar and the other agent controls unnamed by any customer. The durable advantage is the authentication relationship WorkOS owns, and the agent controls are configuration a funded rival can rebuild. Auth0 under Okta sells the same agent auth to the same developers, so a buyer's real choice is which vendor ships the agent-authorization layer they embed.
| Description | WorkOS AuthKit provides an OAuth 2.1 authorization server for MCP applications, letting developers add fine-grained authorization to the agentic apps and workflows built on their MCP tools. | [f1] |
|---|---|---|
| Founded | 2019 | [f2] |
| HQ | San Francisco, California, US | [f3] |
| Latest funding | Series C, $100M, March 2026, led by Meritech and Sapphire ($2B valuation) | [f4] |
| Deployment | SaaS | [f5] |
| Compliance | SOC 2 Type 2 | [f5] |
| Product | What it does |
|---|---|
| WorkOS AuthKit | WorkOS AuthKit: OAuth 2.1 authorization server for MCP applications that handles agent authorization flows and token validation, enabling fine-grained authorization for agentic workflows. |
| WorkOS Radar | WorkOS Radar: real-time authentication defense that detects bots and can allow AI agents acting for a user while denying malicious bots, even with valid credentials. |
| WorkOS FGA | WorkOS Fine-Grained Authorization: per-tool permission scoping for agentic access, gained through the Warrant acquisition, granting agents access to specific tools rather than whole services. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
WorkOS AuthKit is an OAuth 2.1 authorization server for MCP applications that handles agent authorization flows and token validation, enabling fine-grained authorization for agentic workflows. It is mapped to the AI Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 4/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | WorkOS: Secure auth for MCP servers | official | 2026-07-09 |
| f2 | Sacra WorkOS company profile | research | 2026-06-13 |
| f3 | Craft WorkOS headquarters and office locations | research | 2026-06-14 |
| f4 | WorkOS raises $100M Series C hits $2B valuation | official | 2026-06-13 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-13 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | WorkOS secure auth for MCP servers “WorkOS AuthKit supports OAuth 2.1 as a compatible authorization server for MCP apps, based on the latest MCP protocol specification. This enables fine-grained authorization for agentic applications and workflows.” | official | 2026-06-13 |
| s2 | AuthKit Model Context Protocol documentation “How to use AuthKit as the authorization server for your MCP server.” | official | 2026-06-13 |
| s3 | WorkOS Radar product page “Radar automatically blocks common threats like credential stuffing and brute force attacks, with flexible settings that can be tailored to your app.” | official | 2026-06-13 |
| s4 | Introducing Radar real-time protection against bots fraud abuse “Radar leverages proprietary device fingerprinting based on over 20 characteristics to identify which device is being used to authenticate with AuthKit.” | official | 2026-06-13 |
| s5 | How to build secure AI agents that are Enterprise Ready “How can you build secure, compliant AI agents while maintaining performance and fostering innovation?” | official | 2026-06-13 |
| s6 | MCP.shop Demo How WorkOS Powers Identity and Auth for AI Agents “Early in the Enterprise Ready Conference program, Tobin South from WorkOS’s AI Agents team took the stage with a deceptively simple demonstration.” | official | 2026-06-13 |
| s7 | WorkOS raises $100M Series C hits $2B valuation “WorkOS has raised $100 million in Series C financing, valuing the company at $2 billion. The round was led by Meritech and Sapphire. The fastest-growing AI companies already use WorkOS, including OpenAI, Anthropic, xAI, Cursor, Perplexity, Sierra, Baseten, Fal, Replit, Vercel.” | official | 2026-06-13 |
| s8 | About WorkOS “WorkOS is a team of 100+ builders dedicated to spreading developer joy. The Powered by WorkOS section carries customer testimonials, including Vercel's Guillermo Rauch (Founder and CEO) and Cursor's Arvid Lunnemark (Founder), who says Cursor now completely runs on WorkOS.” | official | 2026-06-19 |
| s9 | WorkOS pricing “Transparent pricing that scales with your growth. Start fast, grow with confidence, and pay only for what you need.” | official | 2026-06-13 |
| s10 | SiliconANGLE on agentic AI infrastructure funding including WorkOS “Venture capital funding continues to flow into artificial intelligence and agentic AI governance, control and security as three startups announced new funding yesterday and today, with JetStream Security raising $34 million, Guild.ai raising $44 million and WorkOS raising $100 million.” | press | 2026-06-13 |
| s11 | Sacra WorkOS revenue funding and product analysis “Sacra estimates that WorkOS hit $30M in annual recurring revenue (ARR) in October 2025. The company crossed 1,000 paying customers in early 2025. The Warrant acquisition added fine-grained authorization. CEO Michael Grinich. Radar for fraud detection and Vault for encryption key management.” | research | 2026-06-13 |
| s12 | MarkTechPost best authentication platforms for AI agents and MCP servers 2026 “FGA enables tool-level permission scoping, which is the right abstraction for agentic access control: rather than granting an agent access to a service, you grant it access to specific tools. WorkOS lets teams add MCP OAuth for organizations already running Okta, Entra ID, or an internal directory.” | research | 2026-06-13 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | WorkOS: secure auth for MCP servers “WorkOS AuthKit supports OAuth 2.1 as a compatible authorization server for MCP apps, based on the latest MCP protocol specification. This enables fine-grained authorization for agentic applications and workflows.” | official | 2026-06-17 |
| s2 | WorkOS blog: Introducing Radar real-time protection against bots fraud abuse “Or you might want certain kinds of bots to be able to sign in, such as AI agents that are operating on your users' behalf. Radar can determine that an authentication is coming from a bot and allow or deny that attempt, even if the credentials are correct.” | official | 2026-06-17 |
| s3 | WorkOS Radar product page (device fingerprinting) “Radar leverages proprietary device fingerprinting based on over 20 characteristics to identify which device is being used to authenticate with AuthKit.” | official | 2026-06-17 |
| s4 | WorkOS Role-Based Access Control product page “Set up enterprise-grade RBAC in minutes. Simplify roles and permissions and fine-tune user access with WorkOS.” | official | 2026-06-17 |
| s5 | WorkOS pricing (per-user and per-connection units) “Up to 1 million users Free. Per additional 1M users $2,500 / mo. Number of connections 1-15 $125 / ea.” | official | 2026-06-17 |
| s6 | WorkOS: WorkOS raises 100M Series C hits 2B valuation “WorkOS has raised $100 million in Series C financing, valuing the company at $2 billion. The fastest-growing AI companies already use WorkOS, including OpenAI, Anthropic, xAI, Cursor, Vercel. These teams hit enterprise requirements at once, expecting SSO, SCIM, permissions, and auditability.” | official | 2026-06-18 |
| s7 | WorkOS Trust Center (compliance and gated reports) “Compliance SOC 2 Type II GDPR CCPA HIPAA PCI DSS - SAQ D, Service Provider. Compliance Reports SOC 2 Type II + HIPAA. Attestations PCI AOC for SAQ-D.pdf. WorkOS SOC 2 Bridge Letter.” | official | 2026-06-17 |
| s8 | Sacra: WorkOS revenue funding and product analysis “Sacra estimates that WorkOS hit $30M in annual recurring revenue (ARR) in October 2025. The company crossed 1,000 paying customers in early 2025. The Warrant acquisition added fine-grained authorization capabilities. The average revenue per customer sits around $20,000 annually.” | research | 2026-06-18 |
| s9 | MarkTechPost: WorkOS and Auth0 by Okta among best authentication platforms for AI agents and MCP servers in 2026 “FGA enables tool-level permission scoping, the right abstraction for agentic access control: rather than granting an agent access to a service, you grant it access to specific tools within that service. WorkOS lets teams add MCP OAuth without replacing Okta or Entra ID.” | research | 2026-06-18 |
| s10 | SiliconANGLE on agentic AI infrastructure funding including WorkOS “Venture capital funding continues to flow into artificial intelligence and agentic AI governance, control and security as three startups announced new funding, with JetStream Security raising $34 million, Guild.ai raising $44 million and WorkOS raising $100 million.” | press | 2026-06-17 |
| s11 | WorkOS Docs: Fine-Grained Authorization (FGA) “Fine-Grained Authorization (FGA) extends the existing WorkOS RBAC system. Subjects are the users, groups, devices, or agents that can be granted access. Today that's primarily organization memberships (users), with support for other subject types like agents and services coming soon.” | official | 2026-06-18 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.