A session-aware GraphQL API for the browser, so you can build fully custom user management, admin panels, and more directly in your frontend.
We are launching a remote MCP server that gives AI agents the same access to WorkOS as your dashboard login.
A managed gateway that handles API key verification, token decoding, and authorization so your backend does not have to.
How we turned a bug-finding prompt into a pipeline that scans our codebase for deep logic vulnerabilities and keeps the review queue worth reviewing.
WorkOS CEO Michael Grinich sat down with Dwarkesh Patel. The big ideas: exponential acceleration, losing control, the right to bear weights, and abundance.
A hands-on guide to deploying a spec-compliant remote MCP server on the final 2026-07-28 release, with AuthKit as the OAuth 2.1 authorization server, plus what to change if you're migrating off an earlier draft.
Notes from Dwarkesh Unplugged, our live interview with Dwarkesh Patel and Fei-Fei Li on data, the scaling era, and where the frontier of AI actually is.
A practical guide to CIAM platforms for B2B SaaS teams that also need modern, passwordless experiences for individual users, evaluated on the features that actually close deals.
A buyer's framework for evaluating CIAM providers with inbound SCIM support, and why splitting one continuous requirement into three separate "best of" categories gets the decision wrong
A buyer's checklist for what prebuilt auth UI actually promises, the tradeoffs vendors don't put in the demo, and how to tell a real "app-in-a-box" from a login screen with a good coat of paint
Hand-maintaining SDKs is painful, and outsourcing them is worse. Here's the open-source tool and CI safeguards WorkOS uses to ship SDK changes safely.
A practical guide to two identity systems that sound alike but solve opposite problems
How our quality program evolved into an agentic pipeline to triage, enrich, and fix issues.
What enterprise buyers actually mean when they ask for it, why it matters for deals, and how to implement it without an engineering project.
What 150 hours of engineering actually buys you, and what it doesn't.
A code-level checklist for auditing your SAML service provider implementation: XML parser configuration, signature validation, assertion extraction, replay prevention, and testing.
Static bearer tokens have been the default for SCIM auth for years. Here's why the client credentials grant is a better fit, and what changes when you use it.
Manage SSO, Directory Sync, organizations, and audit logs by just asking. No dashboard required.
Please try a different search
Our global team is growing and we’re hiring all types of roles.
WorkOS builds developer tools for quickly adding enterprise features to applications.
We use cookies for analytics and advertising. See our cookie policy for details.