WorkOS

Security for AI

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2019
Last updated 2026-08-01

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

This analysis is scoped to agent and user identity.

WorkOS runs an enterprise-identity business, and most of its adoption evidence covers that platform rather than the AI-agent products it now markets. By independent estimates it has reached $30 million in recurring revenue and more than 1,000 paying customers, with a roster including OpenAI, Anthropic, and xAI. That roster shows adoption of the core enterprise-identity platform, and the record does not say what those companies buy. The agent-line references on its own MCP page are MCP OAuth deployments, with Radar unnamed by any customer. The durable advantage is the authentication relationship WorkOS owns, and the agent controls are configuration a rival can rebuild. Auth0 under Okta is a close incumbent extending its identity infrastructure into agent auth for the same developers.

Sourced Details

Description WorkOS AuthKit provides an OAuth 2.1 authorization server for MCP applications, letting developers add fine-grained authorization to the agentic apps and workflows built on their MCP tools. [f1]
Founded 2019 [f2]
HQ San Francisco, California, US [f3]
Latest funding Series C, $100M, March 2026, led by Meritech and Sapphire ($2B valuation) [f4]
Deployment SaaS [f5]
Compliance SOC 2 Type 2 [f5]

Products

Product What it does
WorkOS AuthKit WorkOS AuthKit: OAuth 2.1 authorization server for MCP applications that handles agent authorization flows and token validation, enabling fine-grained authorization for agentic workflows.
WorkOS Radar WorkOS Radar: real-time authentication defense that detects bots and can allow AI agents acting for a user while denying malicious bots, even with valid credentials.
WorkOS FGA WorkOS Fine-Grained Authorization: per-tool permission scoping for agentic access, gained through the Warrant acquisition, granting agents access to specific tools rather than whole services.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

WorkOS AuthKit is an OAuth 2.1 authorization server for MCP applications that handles agent authorization flows and token validation, enabling fine-grained authorization for agentic workflows. It is mapped to the AI Defense Matrix. [f6]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 25 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 WorkOS defines the agent-access problem concretely for developers and MarkTechPost frames the same tool-level control need, but the pain is qualitative with no independent quantification. [s1, s6, s12]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 Public documentation covers AuthKit as an OAuth 2.1 authorization server for MCP, Radar's device-fingerprinting bot detection across more than 20 characteristics, and Fine-Grained Authorization for per-tool scoping. A free self-service tier makes the products testable, and MarkTechPost independently describes the FGA tool-scoping model, validation beyond marketing claims. [s1, s4, s12]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The Model Context Protocol wave is a real recent enabler and WorkOS demoed MCP auth in October 2025, but buyer-side demand for the scoped agent line is indirect (the SiliconANGLE funding theme and a MarkTechPost roundup) with no analyst category or named agent adoption. [s6, s10, s1]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Chief executive Michael Grinich is publicly identifiable, having authored and signed the Series C announcement, and Sacra names him as chief executive. Investors Meritech and Sapphire are press-verified backers of the $2 billion round. The public record does not surface a prior exit or a sustained publication record from the founding team in identity or AI security, so the evidence stays at adequate rather than strong. [s7, s11, s10]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Under the product-line scope, no public source names a customer using AuthKit MCP, Radar, or Fine-Grained Authorization for agents, so the line's own traction is unproven and the parent's elite roster (OpenAI, Anthropic, Vercel) and backing register only as an indirect-signal bump. [s7, s8, s10, s11]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Applying the product-line scope, the agent line discloses no line-level revenue and its commercial traction is unproven, and the roughly 30 million ARR is a Sacra estimate for the whole company, so output per dollar for the line stays unconfirmed. [s7, s11, s8]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Authentication is an established budget line for the parent, but the scoped line sells into agent security, a slot still forming, and the independent placement is limited to the MarkTechPost roundup, so the line's category is emerging rather than settled. [s12, s1]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 WorkOS embeds in the customer's authentication path and competes through developer experience, which is more than a quarterly feature for an incumbent to copy. But established identity providers and cloud platforms sell to the same developer buyer, and the agent controls are an extension of standard auth rather than a proprietary data moat. [s11, s1, s12]
Business Risks Okta or a cloud identity provider could add Model Context Protocol authorization and agent-versus-bot screening to their own developer platforms, treating WorkOS's agent controls as a checkbox inside a suite the buyer already runs…
  • Okta or a cloud identity provider could add Model Context Protocol authorization and agent-versus-bot screening to their own developer platforms, treating WorkOS's agent controls as a checkbox inside a suite the buyer already runs.
  • The agent line is built around the Model Context Protocol, so if enterprises consolidate on a different agent-tool interface, AuthKit's MCP authorization server loses the protocol it depends on.
  • No public evidence names a customer using Radar, AuthKit MCP, or FGA for AI agents rather than for employee login, so adoption of the scoped agent line remains unverified outside WorkOS's own framing.
  • Agent security may never form as a standalone budget line if platforms like WorkOS fold it into authentication, which secures the surface for WorkOS but leaves the scoped line without an independent purchase decision to win.
  • Revenue is an outside estimate rather than a disclosed figure, and an enterprise sales motion could consume the $100 million raised before agent-specific traction is proven publicly.
Problem & Market WorkOS frames the agent-access problem as a developer infrastructure gap rather than a threat-hunting one…

WorkOS frames the agent-access problem as a developer infrastructure gap rather than a threat-hunting one. Agents that call tools through the Model Context Protocol need an OAuth authorization server, should not carry long-lived secrets, and need their permissions scoped to specific tools instead of whole services. The company addresses this for engineering teams building AI-powered applications, the same buyer that already adopts its core authentication.

Corroboration for the problem exists outside WorkOS's own marketing. A MarkTechPost roundup of authentication platforms for AI agents describes tool-level permission scoping as the right abstraction for agentic access control, framing the same problem WorkOS sells against. SiliconANGLE tied the company's March 2026 funding to enterprises adopting agentic AI infrastructure and facing new access-control demands.

The buyer is specific and developer-led. WorkOS sells to the engineering teams shipping AI products, and its agent-facing controls target that audience at the moment those teams wire agents into Model Context Protocol servers and external tools. [s1, s10, s12]

Product Capabilities The agent-security line spans three documented products…

The agent-security line spans three documented products. AuthKit acts as an OAuth 2.1 authorization server for Model Context Protocol servers, based on the current MCP specification, and works with the official MCP software development kits. Radar screens authentication attempts and can tell an AI agent acting for a user apart from a malicious bot, allowing or denying the attempt even when the credentials are valid. Fine-Grained Authorization, which WorkOS gained by acquiring Warrant, scopes an agent's access to individual tools rather than to a whole service.

The capabilities can be verified beyond WorkOS's marketing pages. Public documentation explains how to use AuthKit as the authorization server for an MCP server, and Radar's product page describes device fingerprinting across more than 20 characteristics to separate legitimate users from attackers. A free self-service tier makes the products directly testable.

WorkOS demonstrated the agent path in public rather than only describing it. At its October 2025 conference, Tobin South showed MCP.shop, a working application where a user shopped through a conversational agent backed by AuthKit, and MarkTechPost independently described the FGA tool-scoping model as fitting agentic access control. [s1, s4, s6, s12]

Competitive Positioning WorkOS positions itself as the enterprise identity layer for developers, and its agent controls extend that position rather than opening a separate product…

WorkOS positions itself as the enterprise identity layer for developers, and its agent controls extend that position rather than opening a separate product. A MarkTechPost roundup ranks it first among authentication platforms for AI agents and MCP servers, citing the combination of MCP-compatible OAuth, Fine-Grained Authorization for tool scoping, and audit logs under one independent vendor.

Against the standalone non-human-identity vendors, WorkOS competes from a different starting point. Where those vendors lead with discovery and inventory of machine identities, WorkOS leads with the authentication and authorization path that developers already integrate, and it reaches the agent buyer through the core auth relationship rather than a new sale.

Against incumbents, the contest is direct. The same roundup notes that WorkOS lets teams add MCP OAuth without replacing an existing identity provider such as Okta or Entra ID, positioning the product next to the incumbents that sell to the same developer buyer. [s12, s1, s11]

Go-to-Market & Traction WorkOS runs a developer-led motion that converts free usage into enterprise contracts…

WorkOS runs a developer-led motion that converts free usage into enterprise contracts. Its pricing is published openly, the products are free at low volume, and enterprise features scale by connection and by monthly active users, a self-service entry that grows into a sales-assisted enterprise relationship.

The named-customer evidence is unusually strong for this corpus. WorkOS lists OpenAI, Anthropic, xAI, Cursor, Perplexity, and Vercel among its customers in the Series C announcement, and the about page quotes Vercel chief executive Guillermo Rauch and Cursor founder Arvid Lunnemark by name. Sacra estimates the company crossed 1,000 paying customers in early 2025 and reached roughly $30M in recurring revenue by October 2025.

The gap is that none of this adoption is tied publicly to the agent-security products. The customer roster and revenue confirm WorkOS broadly, while public materials do not name a customer running Radar, AuthKit MCP authorization, or Fine-Grained Authorization for AI agents specifically. The traction case is strong for the company and unproven for the scoped line. [s7, s8, s11, s9]

Team & Credibility Founder and chief executive Michael Grinich runs WorkOS, is publicly identifiable, and authored the Series C announcement…

Founder and chief executive Michael Grinich runs WorkOS, is publicly identifiable, and authored the Series C announcement. The company describes itself as a remote team of more than 100 builders, and its product breadth across authentication, Radar, Vault, and Fine-Grained Authorization points to a functioning engineering organization.

Investor signals are verifiable in press. Meritech and Sapphire led the $100 million round with participation from existing investors, and SiliconANGLE reported the financing alongside other agentic AI infrastructure rounds. These are credible backers placing a $2 billion valuation on the company.

What the public record does not show is a prior exit or a sustained publication record from the founding team in identity or AI security. The investor confidence and shipping pace are real signals, but the team's domain pedigree is not independently documented in the way a repeat-founder story would be, which holds the evidence at an adequate level. [s7, s8, s10]

Trust Readiness WorkOS sells to engineering teams that fold its authentication into their own products, so its trust posture is read through how directly a failure would reach customer systems…

WorkOS sells to engineering teams that fold its authentication into their own products, so its trust posture is read through how directly a failure would reach customer systems. Radar and AuthKit sit in the authentication path, meaning an outage or compromise at WorkOS would affect customer sign-in and agent access rather than a peripheral function.

The customer roster doubles as procurement evidence. OpenAI, Anthropic, Cursor, and Vercel running WorkOS in production is the kind of reference that enterprise buyers weigh, and several of those customers speak on the record about the relationship, which lowers the friction of a third-party security review.

Public materials cover much of what a developer buyer evaluates, including transparent pricing and detailed product documentation. What did not appear in the reviewed pages, scoped to the agent-security line, is specific compliance attestation or a vulnerability disclosure policy presented as agent-product evidence, which a security-focused buyer would ask for before routing agent authorization through the platform. [s8, s9, s1]

Competitors Aembit, Oasis Security, Token Security, Auth0, Descope…
Company Relationship Note Compare
Aembit competes with Builds identity and access management for non-human and agentic workloads, including an MCP authorization server, competing for the agent-access control the WorkOS line addresses. N/AWe scored these companies at different scopes, so the totals measure different things.
Oasis Security competes with Non-human identity and agentic access management vendor governing the machine and agent identities WorkOS authorizes through AuthKit. N/AWe scored these companies at different scopes, so the totals measure different things.
Token Security competes with Discovers and secures AI agents and non-human identities, overlapping the agent identity surface WorkOS controls through authentication. N/AWe scored these companies at different scopes, so the totals measure different things.
Auth0 competes with Developer-focused authentication platform owned by Okta, selling MCP and agent auth to the same developer buyer WorkOS targets. N/AWe scored these companies at different scopes, so the totals measure different things.
Descope competes with Authentication platform shipping an agentic identity offering with MCP support, competing directly for the agent-auth developer buyer. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with WorkOS.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

WorkOS is durable where the auth relationship is already embedded and exposed everywhere the agent line would stand on its own. Routing authentication and authorization through AuthKit, Radar, and FGA creates friction once a customer wires it in, and an authorization server agent apps call through is a layer other software depends on. Against that, the agent controls are software the customer configures rather than a service that accepts accountability, WorkOS collects the signals and the customer configures the policies, work a rival can rebuild, and the certifications are commercial table stakes. Auth0 under Okta is a close incumbent competitor extending existing identity infrastructure into MCP authentication, so the watch item is which one embeds the agent-authorization runtime first.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 AuthKit, Radar, and Fine-Grained Authorization are software the customer integrates and runs through SDKs and pays for as capabilities, with a free tier and self-serve signup, and no managed service or accountability layer is part of the offer.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Wiring MCP authorization, tool-scoping policies, and bot-versus-agent screening into how an application authenticates creates meaningful friction once embedded, while no network effect or data-residency lock raises it to 3.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 WorkOS publishes SOC 2 Type II, HIPAA, PCI DSS SAQ-D, GDPR, and CCPA through an inspectable trust center, but these are commercial attestations that ease procurement without blocking a substitute. The score stays at 1 because the cited trust center lists no authorization specific to the agent line that a replacement would have to clear.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Running an OAuth 2.1 authorization server for MCP, brokering tokens, scoping access to individual tools, and screening every sign-in with device fingerprinting is security-critical standards-based auth engineering, the kind of work this rubric places at the top rung.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The buyer is the enterprise engineering team that needs SSO, provisioning, and audit logging, where strict procurement reviews a replacement, but the agent line's named references are MCP OAuth deployments rather than agent-security buyers, so the whole-company customer base is not credited.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 3/3 An OAuth 2.1 authorization server and Fine-Grained Authorization are identity infrastructure that agent applications call through to reach tools and data rather than an end-user application.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 Radar's device fingerprinting spans more than 20 signals WorkOS collects, while its detection settings and Fine-Grained Authorization policies are customer-configured, and no named non-public dataset or cross-customer corpus is quoted in fetched sources.
Strategic Market Segmentation WorkOS aims the agent line at enterprise engineering teams that hit enterprise identity requirements early…

WorkOS aims the agent line at enterprise engineering teams that hit enterprise identity requirements early. MarkTechPost frames the target as teams that need single sign-on, SCIM provisioning, fine-grained authorization, and audit logging wired into MCP server access control, and the buyer is the developer building an AI-powered application. The agent controls can expand an existing AuthKit relationship, though WorkOS also markets MCP OAuth as standalone middleware for teams that already have their own users and login, so the cited record does not establish whether current agent-product adoption is mostly expansion or net-new.

The segment widens because agent identity rides on the same auth contract. A team wiring an agent into Model Context Protocol servers needs an OAuth authorization server, scoped tool permissions, and a way to detect bot-originated authentication and allow or deny it under configured policy, including AI agents acting for users, and WorkOS offers all three to the buyer it already serves. That lets it reach the agent buyer through the core auth relationship instead of cold outreach.

The open segmentation question is whether agent security becomes its own purchase. WorkOS names OpenAI, Anthropic, xAI, Cursor, Perplexity, and Vercel as customers, but those are company-level customer references, and no fetched source ties any of them to the agent products. If buyers never separate agent security from login, WorkOS keeps the surface by default rather than by winning a distinct contest.

Product Capabilities & AI Advantages The agent line spans three documented products built on standard protocols…

The agent line spans three documented products built on standard protocols. AuthKit acts as an OAuth 2.1 authorization server for Model Context Protocol apps based on the current MCP specification, Radar screens authentication attempts using proprietary device fingerprinting across more than 20 characteristics, and Fine-Grained Authorization scopes access to individual resources rather than a whole tenant. WorkOS documents FGA as a product that extends its RBAC system, and Sacra ties the capability to the Warrant acquisition. MarkTechPost describes the same tool-level scoping as the right abstraction for agentic access control.

Radar carries the one agent-specific capability that is not plain authentication. It can allow an AI agent that operates on a user's behalf while denying a malicious bot, blocking or permitting an attempt even when the credentials are correct. That distinction matters for agentic traffic, where a legitimate non-human caller and an attacker can both present valid credentials. FGA, by contrast, lists agents as a subject type whose support WorkOS still marks as coming soon, so today's agent scoping rests more on AuthKit and Radar than on FGA.

The verifiable footprint is solid for the category, with an independent roundup ranking WorkOS first among authentication platforms for agents and MCP servers. What holds up, though, is standards-based auth engineering with no demonstrated proprietary barrier. WorkOS presents Radar's detections as flexible settings tailored to the customer's app, and the tool-scoping policies are customer-defined, while the reviewed sources name no non-public cross-customer fingerprint corpus that a funded rival would have to reproduce.

Sales Engagement & Go-to-Market WorkOS runs a developer-led motion that converts free usage into enterprise contracts…

WorkOS runs a developer-led motion that converts free usage into enterprise contracts. AuthKit is free up to 1 million monthly active users and the agent controls layer onto that account, so a team can adopt MCP authorization or Radar as an expansion of an existing relationship rather than a new procurement. MarkTechPost notes the self-serve path and tailored enterprise pricing.

Conversion at the company level is strong and independently corroborated. Sacra estimates WorkOS crossed 1,000 paying customers in early 2025 and reached roughly $30M in recurring revenue by October 2025, and SiliconANGLE reported the March 2026 round alongside other agentic AI infrastructure raises. The named roster spans OpenAI, Anthropic, xAI, Cursor, Perplexity, and Vercel.

The gap is that little of that traction is tied publicly to the agent products. The MCP page carries named MCP OAuth references, a founding engineer says Rube shipped on WorkOS in two weeks and Mux demonstrates an MCP integration, while no cited source names a customer running Radar or Fine-Grained Authorization specifically, so the company-level roster and revenue still stand apart from most of the scoped agent line.

Pricing Model WorkOS publishes its pricing, a transparency signal in a category where many rivals hide it…

WorkOS publishes its pricing, a transparency signal in a category where many rivals hide it. AuthKit is user-metered, free up to 1 million monthly active users and then $2,500 per additional million, while single sign-on and directory sync are connection-metered, priced per connection starting at $125 each with volume discounts. The published meters are users and connections, the units of the core auth business.

Radar does carry its own check-based meter rather than riding the AuthKit account for free. The published Radar price gives a first 1,000 checks free, then charges 100 dollars per month per 50k checks, so screening agent and user authentication attempts bills by volume of checks. That is a usage unit distinct from the per-user and per-connection model of employee login, even though MCP authorization rides the same AuthKit account and MarkTechPost describes the enterprise path as tailored pricing reached through sales.

The inferable belief is that buyers pay for authenticated identities, enterprise connections, and metered screening checks, not yet for agent governance packaged as a separate good. Whether WorkOS introduces an explicitly agent-specific or workload-specific unit as agent volume grows is the pricing question the public record does not settle.

Product Delivery & Operations WorkOS delivers the agent line as a hosted, developer-integrated service…

WorkOS delivers the agent line as a hosted, developer-integrated service. AuthKit runs as a managed OAuth 2.1 authorization server the customer points its MCP server at, Radar is integrated directly into AuthKit and analyzes every authentication attempt, and WorkOS hosts the authorization and identity services the customer integrates through its API. The customer wires these in through software development kits rather than receiving a managed operation.

The operational surface sits in the authentication path. Because Radar and AuthKit screen and authorize every sign-in, an outage or compromise at WorkOS would reach customer sign-in and agent access rather than a peripheral function, which is the operational counterpart to the trust posture a security buyer evaluates. WorkOS publishes a trust center that exposes gated compliance reports including a SOC 2 bridge letter, and it disclosed a statement on an April 2026 Vercel security incident.

The delivery model is software the customer configures and runs, not a service that accepts accountability for outcomes. WorkOS supplies the authorization and screening infrastructure, and the integrating team owns how it is deployed inside its own application.

Earning Customers' Trust WorkOS backs the agent line with an inspectable trust center rather than self-displayed badges alone…

WorkOS backs the agent line with an inspectable trust center rather than self-displayed badges alone. The portal lists SOC 2 Type II, HIPAA, PCI DSS SAQ-D, GDPR, and CCPA, and exposes gated downloads including a SOC 2 Type II plus HIPAA report and a PCI attestation of compliance. That breadth is meaningful procurement assurance for an enterprise buyer routing authentication through the platform.

The attestations are enterprise-grade but read as table-stakes rather than a moat. They ease a security review without blocking a substitute, and the cited record identifies commercial attestations but no agent-line-specific regulatory mandate, so a determined replacement could clear the same bars. The trust center also published a statement on an April 2026 Vercel security incident, which a buyer should read alongside the certifications.

The trust gap specific to agents is verification of agent behavior. The certifications cover how WorkOS handles data and operates, while a buyer routing agent authorization through AuthKit and Radar would still confirm in a formal review how agent decisions are logged and audited, since the published collateral is scoped to the company rather than to the agent products.

Platform Strategy & Ecosystem Positioning WorkOS positions the agent controls as part of an independent enterprise-identity platform rather than a point tool…

WorkOS positions the agent controls as part of an independent enterprise-identity platform rather than a point tool. MarkTechPost describes it as an independent company focused solely on enterprise authentication whose roadmap is not split across a broader platform, and notes that teams can add MCP OAuth without replacing an existing user database or identity provider such as Okta or Entra ID. The platform claim rests on owning the authentication and authorization surface the agent apps call through.

That position is a coexistence play rather than a rip-and-replace. The MCP authorization server and its tool scoping sit alongside whatever directory the customer already runs, so the platform reach comes from being the auth layer developers already integrate rather than from a proprietary data network. Radar sits inside that account rather than atop an external directory, since WorkOS describes it as directly integrated into AuthKit and analyzing every authentication attempt there.

The exposure is that the incumbents sell to the same developer buyer. Sacra names AWS, Google, and Microsoft as cloud providers that can bundle identity into other services, and Auth0 under Okta also offers MCP authorization for teams already using its identity infrastructure, so the layer WorkOS occupies is ground the platforms are well positioned to contest.

Team & Execution Capability WorkOS runs a sustained enterprise authentication business under a publicly identifiable founder…

WorkOS runs a sustained enterprise authentication business under a publicly identifiable founder. Chief executive Michael Grinich authored and signed the Series C announcement, and Sacra names him as chief executive of a company estimated at roughly $30M in recurring revenue with more than 1,000 paying customers. That profile is a team operating an identity business at scale rather than a set of stated intentions.

The backer bench is press-verified. Meritech and Sapphire led the $100 million round at a $2 billion valuation, with participation from Audacious, Craft, Abstract, and Greenoaks, and SiliconANGLE reported the financing alongside other agentic AI infrastructure rounds. That is credible capital placed on the company's direction.

The execution signal that matters for the agent line is product breadth shipped from one auth core. WorkOS built AuthKit MCP authorization, Radar, and Fine-Grained Authorization from the Warrant acquisition onto the same platform, though the public record does not surface a prior exit or a sustained publication record from the founding team in identity or AI security.

Sources

Company Detail Sources (6)
Id Source Tier Accessed
f1 WorkOS: Secure auth for MCP servers official 2026-07-09
f2 Sacra WorkOS company profile research 2026-06-13
f3 Craft WorkOS headquarters and office locations research 2026-06-14
f4 WorkOS raises $100M Series C hits $2B valuation official 2026-06-13
f5 AI Defense Matrix Catalog entry other 2026-06-13
f6 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (12)
Id Source Tier Accessed
s1 WorkOS secure auth for MCP servers
“WorkOS AuthKit supports OAuth 2.1 as a compatible authorization server for MCP apps, based on the latest MCP protocol specification. This enables fine-grained authorization for agentic applications and workflows.”
official 2026-06-13
s2 AuthKit Model Context Protocol documentation
“How to use AuthKit as the authorization server for your MCP server.”
official 2026-06-13
s3 WorkOS Radar product page
“Radar automatically blocks common threats like credential stuffing and brute force attacks, with flexible settings that can be tailored to your app.”
official 2026-06-13
s4 Introducing Radar real-time protection against bots fraud abuse
“Radar leverages proprietary device fingerprinting based on over 20 characteristics to identify which device is being used to authenticate with AuthKit.”
official 2026-06-13
s5 How to build secure AI agents that are Enterprise Ready
“How can you build secure, compliant AI agents while maintaining performance and fostering innovation?”
official 2026-06-13
s6 MCP.shop Demo How WorkOS Powers Identity and Auth for AI Agents
“Early in the Enterprise Ready Conference program, Tobin South from WorkOS’s AI Agents team took the stage with a deceptively simple demonstration.”
official 2026-06-13
s7 WorkOS raises $100M Series C hits $2B valuation
“WorkOS has raised $100 million in Series C financing, valuing the company at $2 billion. The round was led by Meritech and Sapphire. The fastest-growing AI companies already use WorkOS, including OpenAI, Anthropic, xAI, Cursor, Perplexity, Sierra, Baseten, Fal, Replit, Vercel.”
official 2026-06-13
s8 About WorkOS
“WorkOS is a team of 100+ builders dedicated to spreading developer joy. The Powered by WorkOS section carries customer testimonials, including Vercel's Guillermo Rauch (Founder and CEO) and Cursor's Arvid Lunnemark (Founder), who says Cursor now completely runs on WorkOS.”
official 2026-06-19
s9 WorkOS pricing
“Transparent pricing that scales with your growth. Start fast, grow with confidence, and pay only for what you need.”
official 2026-06-13
s10 SiliconANGLE on agentic AI infrastructure funding including WorkOS
“Venture capital funding continues to flow into artificial intelligence and agentic AI governance, control and security as three startups announced new funding yesterday and today, with JetStream Security raising $34 million, Guild.ai raising $44 million and WorkOS raising $100 million.”
press 2026-06-13
s11 Sacra WorkOS revenue funding and product analysis
“Sacra estimates that WorkOS hit $30M in annual recurring revenue (ARR) in October 2025. The company crossed 1,000 paying customers in early 2025. The Warrant acquisition added fine-grained authorization. CEO Michael Grinich. Radar for fraud detection and Vault for encryption key management.”
research 2026-06-13
s12 MarkTechPost best authentication platforms for AI agents and MCP servers 2026
“FGA enables tool-level permission scoping, which is the right abstraction for agentic access control: rather than granting an agent access to a service, you grant it access to specific tools. WorkOS lets teams add MCP OAuth for organizations already running Okta, Entra ID, or an internal directory.”
research 2026-06-13
Deep-Dive Sources (11)
Id Source Tier Accessed
s1 WorkOS: secure auth for MCP servers
“WorkOS AuthKit supports OAuth 2.1 as a compatible authorization server for MCP apps, based on the latest MCP protocol specification. This enables fine-grained authorization for agentic applications and workflows.”
official 2026-06-17
s2 WorkOS blog: Introducing Radar real-time protection against bots fraud abuse
“Or you might want certain kinds of bots to be able to sign in, such as AI agents that are operating on your users' behalf. Radar can determine that an authentication is coming from a bot and allow or deny that attempt, even if the credentials are correct.”
official 2026-06-17
s3 WorkOS Radar product page (device fingerprinting)
“Radar leverages proprietary device fingerprinting based on over 20 characteristics to identify which device is being used to authenticate with AuthKit.”
official 2026-06-17
s4 WorkOS Role-Based Access Control product page
“Set up enterprise-grade RBAC in minutes. Simplify roles and permissions and fine-tune user access with WorkOS.”
official 2026-06-17
s5 WorkOS pricing (per-user and per-connection units)
“Up to 1 million users Free. Per additional 1M users $2,500 / mo. Number of connections 1-15 $125 / ea.”
official 2026-06-17
s6 WorkOS: WorkOS raises 100M Series C hits 2B valuation
“WorkOS has raised $100 million in Series C financing, valuing the company at $2 billion. The fastest-growing AI companies already use WorkOS, including OpenAI, Anthropic, xAI, Cursor, Vercel. These teams hit enterprise requirements at once, expecting SSO, SCIM, permissions, and auditability.”
official 2026-06-18
s7 WorkOS Trust Center (compliance and gated reports)
“Compliance SOC 2 Type II GDPR CCPA HIPAA PCI DSS - SAQ D, Service Provider. Compliance Reports SOC 2 Type II + HIPAA. Attestations PCI AOC for SAQ-D.pdf. WorkOS SOC 2 Bridge Letter.”
official 2026-06-17
s8 Sacra: WorkOS revenue funding and product analysis
“Sacra estimates that WorkOS hit $30M in annual recurring revenue (ARR) in October 2025. The company crossed 1,000 paying customers in early 2025. The Warrant acquisition added fine-grained authorization capabilities. The average revenue per customer sits around $20,000 annually.”
research 2026-06-18
s9 MarkTechPost: WorkOS and Auth0 by Okta among best authentication platforms for AI agents and MCP servers in 2026
“FGA enables tool-level permission scoping, the right abstraction for agentic access control: rather than granting an agent access to a service, you grant it access to specific tools within that service. WorkOS lets teams add MCP OAuth without replacing Okta or Entra ID.”
research 2026-06-18
s10 SiliconANGLE on agentic AI infrastructure funding including WorkOS
“Venture capital funding continues to flow into artificial intelligence and agentic AI governance, control and security as three startups announced new funding, with JetStream Security raising $34 million, Guild.ai raising $44 million and WorkOS raising $100 million.”
press 2026-06-17
s11 WorkOS Docs: Fine-Grained Authorization (FGA)
“Fine-Grained Authorization (FGA) extends the existing WorkOS RBAC system. Subjects are the users, groups, devices, or agents that can be granted access. Today that's primarily organization memberships (users), with support for other subject types like agents and services coming soon.”
official 2026-06-18

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.