Best MCP Identity and Access Management Tools 2026

Nine MCP IAM tools ranked by layer, deployment fit, live price, and implementation wall. Includes August 2026 cost math and a Monday rollout plan.

Wednesday, August 26, 2026Omid Saffari
Tools
  • OOkta
  • WWorkOS
  • DDescope
  • AAuth0
  • SScalekit
  • SStytch
  • PPermit.io
  • CCerbos
  • 11Password
Best MCP Identity and Access Management Tools 2026

Okta is the best MCP identity and access management tool for enterprises standardizing Claude connectors today, but only if Okta is already a budget line. A 250-seat Starter deployment lists at $18,000 a year, almost twice a planning case of $9,375 in manual connector approvals, so the business case is central revocation and policy control, not fewer login clicks.

The Short Answer

There is no single MCP identity product that does every identity job. The identity provider proves who the user is. An OAuth authorization server issues a scoped token. A policy engine decides whether that user or agent may call a specific tool. A credential vault protects the secret an MCP server may need downstream. Buying one layer and assuming it covers the other three is the most expensive mistake in this category.

For an enterprise that already uses Okta and wants centrally governed Claude connectors, Okta is the first shortlist. For a software company shipping its own MCP server, WorkOS is the strongest general starting point because AuthKit supplies the OAuth 2.1 authorization-server layer while Connect can preserve an existing login system. Descope is the deeper agent-identity option, Scalekit is the leaner cost play, and Permit.io or Cerbos become relevant when the hard problem is the decision made after login.

Prices and product details below were verified against nine vendors' live product and pricing pages on 26 August 2026. The ranking compares documented capabilities and current economics. It does not claim that every product was deployed in a production environment during this review.

At a Glance

ToolBest forStarting priceFree trial
1. OktaEnterprise-managed Claude connectors$6/user/month30 days
2. WorkOSShipping a production MCP server$0 through 1 million MAUsFree staging
3. DescopeAgent identity plus bring-your-own auth$0Free plan
4. Auth0Existing Auth0 deployments$022 days
5. ScalekitLow-cost standalone MCP auth$0Free environments
6. StytchB2B SaaS already on Stytch$0Free tier
7. Permit.ioDrop-in OAuth and tool policy proxy$25/monthFree Community plan
8. CerbosExternalized policy as code$0 open source3 months on Development
9. 1PasswordSupporting credential custody$24.95/month for 1014 days

The starting-price column is deliberately strict. Permit.io has a $0 Community plan, but its OAuth 2.1 proxy and consent editor begin on Pro at $25 per month, so $25 is the meaningful MCP gateway price. 1Password ranks ninth because it protects credentials rather than deciding access. That is a valuable role, but it is not an IAM control plane.

What Changed in August 2026

On 24 August 2026, Anthropic marked Enterprise-managed authorization as generally available. An administrator can authorize a supported MCP connector once, then users inherit access through identity-provider groups and roles on first login. The same enterprise authorization can carry across Claude chat, Claude Code, and Cowork.

The current connector list includes Datadog, Notion, Slack, Asana, Atlassian, Canva, Figma, Granola, Linear, and Supabase. Anthropic says Exa, Miro, and Zoom are coming soon. Okta is the only identity provider named for the generally available launch, with more identity providers promised later.

That changes the business case. The old workflow asked every employee to approve every connector and left revocation scattered across client and server relationships. The MCP Enterprise-Managed Authorization extension makes the enterprise identity provider the authority. It uses an Identity Assertion JWT Authorization Grant, or ID-JAG, which is an identity assertion that an MCP server exchanges for its own access token. In plain English, the enterprise signs who the user is, the server still issues the token it trusts, and revocation can begin centrally at the identity provider.

There is one live-page wrinkle worth taking seriously. Anthropic's dated update says generally available, while a lower "Getting started" section on the same page still says beta and asks customers to apply for access. The dated update is the newer status, but procurement should still confirm that the required connector and tenant are enabled before treating the feature as deployed.

The Consequence Is a Control Budget, Not a Convenience Budget

Consider a planning case with 250 employees, 6 connectors, 5 minutes per individual connector approval, and a $75 loaded hourly labor rate. That is 125 hours and $9,375 of one-time onboarding work. Okta Starter for the same 250 employees lists at $6 per user per month, or $18,000 per year, before any unpublished AI or MCP add-on.

The arithmetic makes the decision sharper. Buying Okta solely to save those approval minutes does not pay back in this scenario. Using an Okta estate that already exists can be compelling because the incremental identity cost may be small and the gain is central provisioning, policy inheritance, and revocation. A new Okta purchase needs a risk case: fewer orphaned grants, faster termination control, cleaner audit ownership, or a broader workforce identity program.

Planning comparison of manual MCP approvals, Okta Starter licensing, and the existing-estate decision
The first budget question is whether workforce identity already exists, not whether centralized login looks convenient.

How These Tools Were Picked

The field was narrowed using six criteria:

  1. MCP-specific proof: the vendor had to document an MCP authorization, token, policy, or credential workflow on a first-party page.
  2. Layer clarity: the product's real job had to be explicit: identity provider, OAuth server, policy engine, gateway, or vault.
  3. Revocation path: a buyer needed to know where access ends when a user, agent, token, or credential is removed.
  4. Tool-level control: scope, policy, consent, or resource context had to reach beyond a simple successful login.
  5. Auditability: the product needed a credible record of identity, token, policy, or credential events.
  6. Public economics: every public tier, material limit, overage, and trial term had to be readable from the live pricing page.

Generic IAM vendors were cut when their current material did not prove an MCP-specific workflow. Open-source components were kept only when their layer and operating burden were clear. 1Password was kept as a supporting pick because secret custody is a real part of an MCP deployment, but it is ranked below products that actually authorize a session or tool call.

This matters because identity and MCP security overlap without being identical. A broader MCP security platform may add discovery, traffic inspection, observability, and runtime enforcement. The products below are ranked for the narrower question of who or what gets access, what token carries that access, what policy limits it, and where credentials live.

1. Okta: Best for Enterprise-Managed Claude Connectors

Okta is the best current choice for enterprises that already run Okta Workforce Identity and want centrally managed Claude connectors.

Okta documentation for securing AI MCP servers
Okta

Okta documents registration, configuration, validation, and lifecycle management for third-party MCP servers, with authorization through standard OAuth flows. Its custom authorization servers support Cross App Access and ID-JAG token exchange, while an external authorization server can use Security Token Service token exchange. That alignment matters because Anthropic currently names Okta as the launch identity provider for generally available Enterprise-managed authorization.

The wall is price and entitlement clarity. Workforce Identity has a $1,500 annual contract minimum, and the live pricing page does not publish a separate dollar figure for AI identity or MCP-specific add-ons. A company buying Okta from scratch for MCP alone is likely overbuying; a company already paying for Okta may be turning on a natural extension of its control plane.

Best for: Enterprises already using Okta that need group-based provisioning and central revocation for Claude connectors.
Standout: The only identity provider Anthropic names at the generally available launch.
Pricing: Starter $6 per user per month, Core Essentials $14 per user per month, Essentials $17 per user per month, Professional custom, and Enterprise custom, all billed annually. The annual contract minimum is $1,500. AI identity and MCP add-on pricing is not separately public.
Free trial: 30 days.

The upside
What it does well
4 points

  • Direct fit with Anthropic's current Enterprise-managed authorization launch.
  • Manages MCP server registration, configuration, validation, and lifecycle.
  • Supports ID-JAG and other token-exchange paths instead of relying on static credentials.
  • Extends an identity system many enterprises already use for groups, roles, and offboarding.
The downside
Where it falls short
3 points

  • Poor value if MCP is the only reason to buy a workforce identity suite.
  • AI and MCP-specific add-on pricing is not public.
  • The generally available Claude path currently names only Okta, which can make a multi-IdP strategy premature.

A Practical Okta Rollout

  1. Confirm the actual entitlement

    Ask Anthropic and Okta to confirm that the target Claude tenant, connector, and required authorization capability are enabled. The live Anthropic page contains both a generally available update and an older beta instruction, so a screenshot of the current tenant state belongs in the procurement record.

  2. Choose the token-exchange path

    Use an Okta custom authorization server when Cross App Access or ID-JAG is the intended path. If the MCP server uses an external authorization server, design around the documented Security Token Service exchange rather than passing a long-lived credential through the client.

  3. Map access to existing groups

    Start with one connector and two identity-provider groups: an allowed operating group and a denied control group. Keep tool scopes narrower than the application role so a successful login does not imply access to every MCP action.

  4. Test all three user surfaces

    Validate the same account in Claude chat, Claude Code, and Cowork. Then remove the account from the allowed group and verify that the central revocation path actually ends connector access.

Verdict: Pick Okta when it is already the enterprise identity authority and Claude connector governance is the immediate job. Skip it for a greenfield MCP product that needs an authorization server without a full workforce identity purchase.

2. WorkOS: Best for Shipping a Production MCP Server

WorkOS is the best general-purpose choice for a software company building an MCP server that needs standards-based authorization without replacing its existing login stack.

WorkOS MCP authorization product page
WorkOS

AuthKit acts as an OAuth 2.1-compatible authorization server for an MCP application, while the developer still builds the tools and resource endpoints. WorkOS Connect can add the OAuth flow as standalone middleware while preserving an existing user system. That separation is useful when the product already knows who its users are but does not want to own discovery, consent, token issuance, and enterprise federation alone.

The wall is that "free AuthKit" does not mean the whole enterprise identity bill is free. AuthKit is $0 through 1 million monthly active users, yet SSO and Directory Sync connections, audit-log delivery, retained events, and a custom domain each have their own price. There is also no separate published MCP surcharge, so a serious estimate has to model those adjacent line items.

Best for: SaaS teams shipping a production MCP server while preserving an existing authentication system.
Standout: AuthKit for a full OAuth 2.1 authorization-server layer, plus Connect for a middleware path.
Pricing: Pay as you go or custom Annual Credits. AuthKit is $0 through 1 million monthly active users, then $2,500 per month for each additional 1 million. SSO and Directory Sync connections cost $125 each for 1 to 15, $100 each for 16 to 30, $80 each for 31 to 50, and $65 each for 51 to 100. Audit Logs cost $125 per month per SIEM connection plus $99 per month per million retained events. A custom domain is $99 per month. No MCP-specific surcharge is published.
Free trial: Free staging, with no credit card required until production.

The upside
What it does well
4 points

  • Clear MCP authorization-server role without requiring a replacement login system.
  • Public AuthKit allowance reaches 1 million monthly active users before a base MAU charge.
  • Enterprise SSO, directory, audit, and custom-domain costs are published.
  • Connect offers a migration-friendly path for products with existing auth.
The downside
Where it falls short
3 points

  • SSO, Directory Sync, Audit Logs, event retention, and custom domains can turn a $0 headline into a meaningful bill.
  • The application still owns MCP tools, resource endpoints, and application-specific authorization logic.
  • Annual Credits pricing requires sales contact.

Verdict: Pick WorkOS when the product team wants to ship OAuth correctly and keep its present user system. Skip it when the central problem is fine-grained tool authorization after the token has already been issued.

3. Descope: Best for Agent Identity and Bring-Your-Own Auth

Descope is the strongest all-in-one agent-identity candidate for teams that need MCP OAuth, credential handling, per-tool scopes, policy, and an option to keep a homegrown identity system.

Descope Agentic Identity Hub for MCP authorization
Descope

Agentic Identity Hub documents OAuth 2.1 and PKCE, Dynamic Client Registration and CIMD client registration, per-agent and per-tool scopes, credential storage and refresh, policy controls, and SIEM-exportable action logs. Bring Your Own Auth lets Descope remain the MCP authorization server while federating an existing identity provider. Its 50-plus connection templates also reduce the amount of bespoke credential plumbing around downstream services.

The wall appears in the tier boundary. Fine-grained authorization and external audit connectors begin on Growth at $799 per month billed annually, not on Free Forever or Pro. The lower tiers can prove identity and token flows, but the controls that make a larger agent rollout governable may move the buyer directly to Growth.

Best for: Agent products that need a broad identity control plane while keeping an existing IdP or login system.
Standout: MCP OAuth plus credential storage, per-tool scopes, policy, logs, and Bring Your Own Auth in one product family.
Pricing: Free Forever $0, Pro from $249 per month billed annually, Growth from $799 per month billed annually, and Enterprise custom. Free Forever includes 7,500 MAUs, 10 active tenants, 3 SSO connections, 1 federated OIDC app, 10,000 M2M exchanges, 2,000 monthly active consents, and 2,000 monthly active tokens. Pro includes 10,000 MAUs, 35 tenants, 5 SSO connections, 2 federated apps, 50,000 M2M exchanges, 5,000 monthly active consents, and 5,000 monthly active tokens. Growth includes 25,000 MAUs, 100 tenants, 10 SSO connections, unlimited federated apps, 100,000 M2M exchanges, 10,000 monthly active consents, and 10,000 monthly active tokens. Overage is $0.05 per MAU, $1 per tenant, $50 per SSO connection, $2 per 1,000 M2M exchanges, $0.05 per monthly active consent, and $0.05 per monthly active token.
Free trial: A free plan rather than a timed trial. Eligible startups can receive Pro free for one year.

The upside
What it does well
4 points

  • Covers more of the agent-identity stack than a narrow OAuth server.
  • Bring Your Own Auth reduces migration pressure.
  • Per-agent and per-tool scopes fit MCP's delegated-access problem.
  • Published MAU, tenant, SSO, M2M, consent, and token allowances make scenario pricing possible.
The downside
Where it falls short
3 points

  • Fine-grained authorization and external audit connectors require Growth.
  • Several separate usage meters make forecasting more involved.
  • Broad scope can be unnecessary for a team that only needs a lightweight OAuth facade.

Verdict: Pick Descope when agent identity is becoming a product capability, not a one-server integration. Skip it when the only missing piece is basic authorization-server plumbing and the policy layer already exists elsewhere.

4. Auth0: Best for Existing Auth0 Deployments

Auth0 is the most natural MCP identity choice for teams already standardized on Auth0 and needing resource-scoped tokens, on-behalf-of exchange, and downstream credential management.

Auth0 Auth for MCP documentation overview
Auth0

Auth for MCP implements OAuth 2.1 and OpenID Connect with sign-in, standards-based discovery and registration, and resource-scoped tokens. On-Behalf-Of Token Exchange turns an MCP client token into a short-lived internal API token scoped to the user and resource. Token Vault handles issuance, storage, rotation, and revocation for third-party API tokens used by the MCP server.

The wall is packaging. Auth for MCP appears in the live comparison, but M2M tokens are a Professional add-on and enterprise capabilities can carry separate add-ons. A $0 or $35 entry price can therefore be directionally correct while still understating a machine-heavy production architecture.

Best for: Products already using Auth0 that need to extend identity into MCP and downstream APIs.
Standout: On-Behalf-Of Token Exchange and Token Vault connect the user session to internal and third-party resources.
Pricing: Free $0, Essentials $35 per month, Professional $240 per month, and Enterprise custom at the live 500-MAU selector. Free allows up to 25,000 MAUs. M2M tokens are a Professional add-on, and some enterprise capabilities use separate add-ons.
Free trial: 22 days, then automatic conversion to Free.

The upside
What it does well
4 points

  • Standards-based discovery, registration, and resource-scoped tokens.
  • On-behalf-of exchange limits the token presented to an internal API.
  • Token Vault addresses downstream third-party credentials inside the same ecosystem.
  • Easy organizational fit for an existing Auth0 estate.
The downside
Where it falls short
3 points

  • Add-on packaging complicates the true machine-identity cost.
  • The public selector does not describe every production scenario in one flat price.
  • A greenfield buyer may find a more MCP-focused vendor easier to size.

Verdict: Pick Auth0 when MCP is an extension of an Auth0 identity architecture. Skip it when the organization has no Auth0 footprint and wants a narrowly scoped, easy-to-price MCP authorization service.

5. Scalekit: Best Low-Cost Standalone MCP Auth

Scalekit is the best price-led choice for a team that needs delegated OAuth and a credential vault without buying a large identity platform.

Scalekit MCP authentication and credential management product page
Scalekit

Scalekit handles delegated OAuth, token refresh, and credential storage, scopes permissions per tool call, and keeps credentials outside the agent and model. Its per-tenant vault uses AES-256 encryption and carries 90-day audit retention by default. That is a practical combination for an MCP server calling customer-owned SaaS services: the agent receives permission to act, but it never has to see the long-lived credential that makes the downstream call possible.

The wall is scale and plan interpretation. Free has hard caps rather than overages, while Growth introduces both user and organization overages. Standalone MCP Auth is $99 per month, and a separate customization add-on is also $99 per month, so a team must decide whether it is buying the broader Auth for SaaS plan or the standalone component before comparing quotes.

Best for: Startups and product teams that want delegated MCP OAuth plus credential custody at a readable entry price.
Standout: MCP Auth is included on Free, and a standalone MCP Auth option is publicly priced at $99 per month.
Pricing: Free $0 per month, Growth $99 per month, and Enterprise custom. Free includes 25,000 MAUs, 25 organizations, 1 SSO connection, 1 SCIM connection, and MCP Auth, with hard caps and no overages. Growth includes 100,000 MAUs and 100 organizations, then costs $0.05 per additional MAU and $1 per additional organization. After the first free SSO or SCIM connection, connections cost $60 each for 2 to 15, $45 for 16 to 30, $35 for 31 to 50, $30 for 51 to 100, and custom above 100. Standalone MCP Auth is $99 per month, and customization is a separate $99-per-month add-on.
Free trial: Development, QA, UAT, and staging environments are free.

The upside
What it does well
4 points

  • Public $99 standalone MCP Auth price is easy to compare.
  • Keeps downstream credentials outside the agent and model.
  • Per-tool scopes and refresh handling address the real delegated-access workflow.
  • Free non-production environments reduce evaluation cost.
The downside
Where it falls short
3 points

  • Free hard caps require a plan change instead of predictable overage.
  • The relationship between broader Auth for SaaS pricing and standalone MCP Auth needs careful scoping.
  • A 90-day default audit window may be shorter than an enterprise retention requirement.

Verdict: Pick Scalekit when connection count and a standalone MCP auth price dominate the decision. Skip it when a very large MAU allowance or a broader enterprise identity ecosystem matters more.

6. Stytch: Best for B2B SaaS Already on Stytch

Stytch is the cleanest choice for a B2B SaaS product that already models customers as organizations and wants MCP clients to behave like Connected Apps.

Stytch Connected Apps guide for MCP authentication
Stytch

Stytch uses the authorization-code grant, provides an OAuth consent component, publishes protected-resource and authorization-server metadata, issues access and refresh tokens, validates scopes, and supports Dynamic Client Registration. The model is familiar to a SaaS builder: an MCP client becomes another connected application, with an explicit consent and token lifecycle rather than a special API-key exception.

The wall is public forecasting beyond the included tier. The static pricing page publishes add-on rates for branding, SSO or SCIM connections, and fraud fingerprints, but additional MAU and M2M rates sit behind an interactive calculator. That makes the free tier easy to understand and a high-volume production estimate less transparent.

Best for: B2B SaaS products already using Stytch organizations and authentication.
Standout: MCP clients map directly to Stytch Connected Apps with consent, metadata, scopes, and token lifecycle.
Pricing: Pay as you go starts at $0, and Enterprise is custom. The free included usage covers 10,000 monthly active users and AI agents, unlimited organizations, 5 SSO or SCIM connections, and 1,000 M2M tokens. Branding and email customization cost $99. Each additional SSO or SCIM connection costs $125. Fraud prevention costs $0.005 per fingerprint after 10,000 included fingerprints. Additional MAU and M2M rates require the interactive calculator.
Free trial: A free usage tier rather than a timed trial.

The upside
What it does well
4 points

  • Connected Apps is a coherent mental model for MCP client authorization.
  • Includes consent UI, metadata, access and refresh tokens, scope checks, and dynamic registration.
  • Free allowance includes users, AI agents, organizations, SSO or SCIM, and M2M tokens.
  • Strong fit when Stytch already owns the product's B2B identity model.
The downside
Where it falls short
3 points

  • Higher-volume MAU and M2M prices are not visible in the static pricing page.
  • Teams outside the Stytch ecosystem gain less from the Connected Apps fit.
  • Tool-level business policy still belongs in application logic or a dedicated policy layer.

Verdict: Pick Stytch when MCP is one more connected-app surface in an existing Stytch B2B product. Skip it when a public, line-by-line high-volume estimate is required before a sales conversation.

7. Permit.io: Best Drop-In Proxy With Tool Policy

Permit.io is the best drop-in option when login already works but every MCP tool call needs an explicit authorization decision, consent record, and audit trail.

Permit.io MCP Gateway product page
Permit.io

Permit MCP Gateway connects an existing identity provider, handles OAuth 2.1 sessions and token exchange, and checks tool calls against role-based, attribute-based, or relationship-based policy. Those three policy models answer progressively richer questions: what role the caller has, what attributes surround the request, and what relationship the caller has to the resource. The gateway also provides consent screens, provisions agent identities, and records the decision chain.

The wall is hidden by the free headline unless the buyer reads the feature boundary. Community is $0, but it does not include the OAuth 2.1 proxy or consent editor. The MCP gateway capability that makes Permit.io distinctive begins on Pro at $25 per month, while enterprise controls such as SSO, shadow-agent detection, human approval, and private deployment sit on Enterprise.

Best for: Teams with an existing IdP that need a policy-enforcing proxy in front of MCP servers.
Standout: OAuth session handling and fine-grained tool policy in the same gateway.
Pricing: Community $0, Pro starting at $25 per month, and Enterprise custom. Community includes 1,000 human and agentic MAUs, 10 tenants, 1 environment, and 7-day logs, but not the OAuth 2.1 proxy or consent editor. Pro includes up to 50,000 MAUs, 20,000 tenants, 50 environments, the OAuth 2.1 proxy, consent editor, 21-day-plus logs, a 99.95% SLA, and SSO as an add-on. Enterprise includes unlimited MAUs, tenants, and environments, plus SSO, shadow-agent detection, human approvals, on-premises or VPC deployment, and a 99.99% SLA.
Free trial: Community requires no credit card; the relevant OAuth gateway starts on paid Pro.

The upside
What it does well
4 points

  • Adds OAuth and tool-level policy without replacing the existing IdP.
  • Supports role, attribute, and relationship policy models.
  • Consent and decision-chain audit records help explain why a tool call was allowed.
  • Pro has a low published starting price for a real MCP gateway feature set.
The downside
Where it falls short
3 points

  • The $0 Community plan excludes the defining OAuth proxy and consent editor.
  • Enterprise-grade SSO and human-approval controls require a higher custom tier.
  • A gateway adds another production hop and operating dependency.

Verdict: Pick Permit.io when the missing control is "may this identity perform this tool action now?" Skip it when the application still lacks a reliable identity and token-issuance layer upstream.

8. Cerbos: Best for Externalized Policy as Code

Cerbos is the best policy-as-code choice for a team that wants MCP authorization decisions expressed outside application code and deployed across services.

Cerbos policy as code integration for MCP
Cerbos

Cerbos evaluates user, agent, request, and resource context, then returns an allow or deny decision and preserves an audit trail. The vendor states sub-millisecond policy-decision latency. This is useful when the same rule must govern several MCP servers, such as permitting a finance agent to read invoices for its own business unit but not to approve payment.

The wall is categorical, not just commercial: Cerbos is not an identity provider and not an OAuth authorization server. It belongs after identity and token validation. A team that selects Cerbos still needs a trustworthy subject, a token flow, and possibly a credential vault; what Cerbos replaces is scattered authorization logic, not the rest of the identity stack.

Best for: Engineering teams that want centrally managed, auditable authorization policy across multiple MCP servers.
Standout: Context-aware policy decisions with a stated sub-millisecond evaluation time.
Pricing: Open source is free forever. Cerbos Hub Proof of Concept is $0 per month, Development starts at $25 per month, Production starts at $933 per month, and Enterprise is custom. Proof of Concept includes 100 monthly active principals and 1 week of unified audit logs. Development includes the first 100 principals and 3 months of logs. Production includes the first 5,000 principals and 1 year of logs.
Free trial: 3 months on Development.

The upside
What it does well
4 points

  • Keeps authorization policy out of individual MCP tool implementations.
  • Evaluates user, agent, request, and resource context.
  • Open-source path makes local evaluation possible without a platform fee.
  • Production tier publishes its included principal count and log retention.
The downside
Where it falls short
3 points

  • Does not authenticate users or issue OAuth tokens.
  • Production jumps from a $25 Development starting price to $933 per month.
  • Policy-as-code requires engineering ownership and a disciplined rule lifecycle.

Verdict: Pick Cerbos when authorization logic is the bottleneck and the identity layer is already sound. Skip it when the project still needs an IdP or OAuth server and the team expects one product to supply both.

9. 1Password: Best Supporting Credential Custody

1Password is the best supporting pick for keeping MCP credentials out of configuration files and agent context, but it is not a substitute for authorization.

1Password and Runlayer secure MCP credentials workflow
1Password

In its Runlayer integration, 1Password accepts op:// references in MCP credential fields, resolves the live secret when the proxy connects, and leaves no raw credential stored in Runlayer. SHA-256 hash comparison detects rotation, and fetch and rotation events are logged. That is a meaningful security improvement for an MCP server that must call an older service with an API key.

The wall is equally important: credential custody is not access control. 1Password can protect and rotate the secret, but it does not decide whether a user or agent may invoke a tool against a particular resource. Pair it with an IdP, OAuth server, and policy layer where the application requires delegated access.

Best for: Teams that need controlled storage, retrieval, and rotation of downstream MCP credentials.
Standout: Live op:// references let a proxy fetch a credential at connection time without storing the raw value.
Pricing: Teams Starter Pack is $24.95 per month billed annually for 10 members, with additional seats at $4.99 each for up to 10 more. Business is $8.99 per user per month billed annually. Enterprise and volume pricing are custom.
Free trial: 14 days for Teams Starter Pack and Business.

The upside
What it does well
4 points

  • Keeps raw downstream secrets outside agent context and proxy storage.
  • Supports rotation detection and logs fetch and rotation events.
  • Fits an existing business password and secrets-management budget.
  • Public Teams and Business prices make the entry case easy to estimate.
The downside
Where it falls short
3 points

  • Does not authenticate an MCP user or authorize a tool call.
  • The documented MCP workflow depends on the Runlayer integration.
  • Adds a credential layer without removing the need for OAuth and policy controls.

Verdict: Pick 1Password as a vault beside the identity stack, especially when legacy APIs still require long-lived secrets. Do not buy it as the MCP IAM system itself.

The Five Layers That Must Fit Together

The ranking only becomes useful when each product is placed in the correct layer. One vendor may cover several layers, but the jobs remain distinct:

  • IdP: proves the human or workload identity and owns group membership and offboarding.
  • OAuth: issues a token to a specific MCP client for a specific protected resource and scope.
  • Policy: decides whether the authenticated subject may perform the requested tool action against the requested resource.
  • Vault: protects any downstream secret that cannot be replaced by delegated OAuth.
  • MCP server: exposes the tools and resources, validates the token, and enforces the final decision.
MCP identity architecture from identity provider through OAuth, policy, vault, and MCP server
A complete MCP access path uses complementary layers; a successful login is only the first decision.

Revocation completes the loop. If the IdP removes the user but a server accepts a long-lived token forever, central offboarding is theater. If OAuth issues a narrow token but the MCP server never checks resource context, the token is only a coarse gate. If policy is precise but a raw downstream API key sits in agent context, the last mile remains exposed.

That is why Okta, WorkOS, Permit.io, Cerbos, and 1Password are not interchangeable competitors. In a mature deployment they could be parts of the same architecture. The buying question is which missing layer deserves a vendor and which layers the product team can operate safely itself.

Who Should Pick What

Pick Okta if Okta already owns workforce identity and the immediate move is governed access to supported Claude connectors. The choice flips away from Okta when a new workforce identity contract is required solely for MCP.

Pick WorkOS if a SaaS team is exposing its own MCP server and needs an OAuth 2.1 authorization server without replacing the current login system. The choice flips to Descope when agent identity, credential templates, consent metering, and policy controls need to live in one broader platform.

Pick Descope if the product is becoming an agent platform and Bring Your Own Auth prevents a disruptive identity migration. The choice flips to Scalekit when the deployment is smaller, price clarity matters more, and standalone MCP Auth covers the job.

Pick Auth0 or Stytch when one already owns the product's identity model. Existing architecture is a feature: migrations create risk, duplicate user stores, and confusing revocation ownership. A greenfield buyer should compare them with WorkOS, Descope, and Scalekit based on the layer still missing.

Pick Permit.io when the system needs an OAuth-aware gateway that can enforce role, attribute, or relationship policy on every tool call. Pick Cerbos when token validation already exists and policy-as-code is the only missing control. Permit.io packages more of the proxy path; Cerbos keeps the authorization decision layer more explicit.

Pick 1Password only as the credential-custody layer. It belongs next to the winner when a downstream API still requires a stored secret. It never replaces the winner.

The Cost Math That Flips the Choice

Public starting prices are useful only when the unit matches the architecture. Okta charges per workforce user. WorkOS and Scalekit can charge around enterprise connections as well as user volume. Descope meters MAUs, tenants, SSO, M2M exchanges, consents, and active tokens. Permit.io and Cerbos attach material value to policy and audit tiers. A one-number ranking would hide the unit that drives the bill.

Case 1: A 250-Person Company Standardizing Claude

Okta Starter lists at $6 per user per month. For 250 seats, that is $1,500 per month and $18,000 per year. The earlier planning case puts individual approvals at 125 hours and $9,375 once.

The rule is simple. If the company already pays for Okta, measure the incremental authorization add-on, implementation, and connector cost against the benefit of central revocation and audit ownership. If the company does not use Okta, do not pretend the $18,000 annual identity purchase is an approval-automation project. It is a workforce security program and must be justified as one.

Case 2: A SaaS Product With 10 Enterprise Connections

Ten WorkOS SSO connections cost $125 each at the published 1-to-15 tier, or $1,250 per month. Scalekit Growth is $99 per month and includes the first connection; 9 more at $60 each produce a $639 monthly case. The listed difference is $611 per month and $7,332 per year.

Scalekit wins that narrow connection-count case. WorkOS can win when AuthKit's $0 allowance through 1 million monthly active users matters, because Scalekit Growth includes 100,000 MAUs before $0.05-per-user overage. The decision flips when the WorkOS user-volume advantage is worth more than the Scalekit connection-price advantage.

Case 3: Policy Becomes the Expensive Part

Permit.io Pro starts at $25 per month and includes the OAuth proxy and consent editor. Cerbos Development also starts at $25 per month, but its purpose is externalized policy, not token issuance, and its Production tier starts at $933 per month with 5,000 monthly active principals and 1 year of logs. Descope Growth starts at $799 per month and is the first Descope tier with fine-grained authorization and external audit connectors.

These are not three prices for the same product. Permit.io is the low-entry gateway and policy bundle. Cerbos is the dedicated policy-as-code path with a much higher published production tier. Descope Growth is a broad identity platform tier in which policy and external auditing arrive alongside larger identity allowances. Compare the operating model before comparing the dollar figure.

The Ones to Avoid

The weakest MCP identity choices are patterns, not necessarily bad companies. Avoid these three buying shortcuts.

Raw API Keys as the Primary Identity System

A static API key can identify an application, but it does not naturally carry a human identity, a consent event, a narrow delegated scope, or a clean group-based offboarding path. If a legacy API still requires one, keep it in a vault such as 1Password or a vendor credential store and place an OAuth and policy decision in front of it. Do not give the raw key to the model or treat possession of the key as permission for every tool action.

A Generic IAM Vendor With No Documented MCP Path

Strong workforce identity does not automatically create MCP protected-resource metadata, client registration, consent, token exchange, tool scopes, or server validation. A generic IdP may still be the right authority, but demand a documented architecture for the MCP client and server before signing on the strength of a broad IAM feature list.

A Homegrown OAuth Proxy Without a Platform Reason

Owning an OAuth proxy means owning discovery, client registration, redirect validation, consent, token issuance, refresh, revocation, key rotation, audit logs, abuse controls, and every interoperability edge that arrives later. Build it when authorization is core intellectual property or a regulatory requirement makes vendor use impossible. Otherwise, the maintenance surface is larger than the first demo suggests.

The Monday Move

Do not begin with a nine-vendor request for proposal. Begin with one access path that matters, preferably a connector touching customer, financial, source-code, or operational data. The objective for Monday is to find the earliest broken layer and put a named owner on it.

  1. Inventory the current path

    Write down the user or agent, MCP client, identity provider, authorization server, MCP server, downstream system, stored credential, and audit destination for one connector. Mark any box whose owner cannot explain how access is revoked.

  2. Define one narrow permission

    Choose one tool and one resource boundary, such as read-only access to a single workspace. Separate successful login from permission to invoke that tool. This exposes whether the missing control is OAuth scope, application policy, or both.

  3. Price the real unit

    Count workforce seats, MAUs, organizations, SSO or SCIM connections, M2M exchanges, consents, active tokens, policy principals, audit retention, and SIEM connections. Use only the units the shortlisted vendor actually charges.

  4. Run the removal test

    Grant the permission, use it from the intended MCP client, remove the user or group, and verify that access ends at every relevant surface. Record the delay and the audit evidence. A rollout is not governed until removal works.

  5. Expand by risk, not popularity

    After the first connector passes, add the next connector with the highest consequence of misuse. Reuse the identity and revocation pattern, but define fresh tool and resource scopes instead of copying blanket access.

The result should be a one-page control record, not a slide deck: who is authoritative, what token is issued, what policy is checked, where secrets live, how revocation works, what it costs at the next usage tier, and who responds when a check fails.

Frequently Asked Questions

Are there free MCP identity and access management tools?

Yes. WorkOS AuthKit is $0 through 1 million MAUs, while Descope, Auth0, Scalekit, Stytch, Permit.io, and Cerbos each have a $0 entry path. Read the feature boundary: Permit.io Community excludes the OAuth 2.1 proxy and consent editor, Descope fine-grained authorization begins on Growth, and a production Cerbos deployment may need a paid Hub tier.

What are examples of MCP IAM tools?

Okta is an identity provider and enterprise authorization control plane. WorkOS, Descope, Auth0, Scalekit, and Stytch can supply MCP OAuth or connected-app authorization. Permit.io and Cerbos specialize in policy decisions, while 1Password protects downstream credentials. They are examples of different layers, not nine interchangeable suites.

Is AWS IAM enough for MCP?

AWS IAM controls authentication, authorization, and permissions for AWS resources and AWS accounts. That can be sufficient for the AWS-resource side of a deliberately AWS-bound system, but it does not remove the need to design the MCP client authorization, consent, token, tool-policy, audit, and revocation path. If the server fronts non-AWS services or serves users from another enterprise IdP, treat AWS IAM as one layer rather than the complete answer.

What is the difference between cloud IAM and MCP IAM?

Cloud IAM governs identities and permissions around cloud accounts and resources. MCP IAM governs how a human or agent connects through an MCP client to an MCP server, which token represents that access, and which tools and downstream resources the session may use. The two meet when an MCP tool calls a cloud resource, but the cloud policy and the MCP session still need an explicit bridge.

Final Takeaways

Get the AI Business Workflow Audit Checklist

Use the AI Business Workflow Audit Checklist to map the identity, policy, secret, and ownership gaps in your next automation rollout.

Last Updated

Aug 26, 2026

CategoryBuild
Newsletter

One letter, every Sunday. Working systems, not hot takes.

Build logs, working systems, and field notes from running a portfolio of AI ventures.

Weekly. No spam. Unsubscribe anytime.