Case Study: Clerk achieves secure MCP agent authentication and delegation with WorkOS

A WorkOS Case Study

Preview of the Clerk Case Study

Clerk ships MCP client registration in 2 weeks with WorkOS

Clerk, an authentication service provider, faced the challenge of verifying the identity of agents (like AI tools) connecting to its authorization servers. The existing standards, Dynamic Client Registration (DCR) and Client ID Metadata Documents (CIMD), only solved half the problem by identifying the software but not the user authorizing it or the specific permissions it should have.

WorkOS provided a solution through its support for the open `auth.md` protocol (Agent Registration in AuthKit). This approach builds upon CIMD to not only verify the client software but also securely establish user delegation, determining on whose authority the agent acts and what it is permitted to do. By implementing this, Clerk enabled a more secure and flexible system that can enforce step-up authentication and per-step scoping, a capability missing from DCR and CIMD alone.


View this case study…

WorkOS

82 Case Studies