Descope

Descope

Descope runs authentication and user management scripts on websites, handling login flows, multi-factor authentication, single sign-on (SSO), and session token management. Scripts load on pages requiring user identity verification and may set session cookies or local storage tokens.

Overview

Descope is an authentication-as-a-service platform that provides no-code and SDK-based tools for building login and identity verification flows. It competes with Auth0, Clerk, and Frontegg in the developer-facing authentication infrastructure market. Descope deploys scripts on pages where user authentication is required, handling the complete identity verification lifecycle from initial login through session maintenance and re-authentication.

What This Script Does

Descope scripts load on login, registration, and protected pages of web applications. Client-side behavior includes:

Authentication component rendering: Descope's SDK renders login and registration UI components — including password fields, magic link interfaces, social login buttons, and passkey prompts. These components may load as embedded flows within the application or as hosted page components served from Descope's infrastructure.

Session token storage: After successful authentication, Descope issues session tokens (JWTs) that are stored in browser cookies or local storage. Session cookies are typically HttpOnly and Secure, preventing JavaScript access for security reasons. The token expiry depends on the application's session configuration.

Refresh token management: Descope manages session refresh flows, transparently exchanging short-lived access tokens for new ones without requiring the user to re-authenticate. Refresh token cookies may persist for longer periods (days to weeks) depending on configuration.

MFA and step-up authentication: Descope handles multi-factor authentication flows including TOTP, SMS OTP, email magic links, and WebAuthn/passkeys. Verification requests are made to Descope's API servers.

SSO flows: For enterprise SSO, Descope handles SAML and OIDC protocol exchanges, including browser redirects to enterprise identity providers and token parsing on return.

Telemetry: Descope may collect SDK usage telemetry including authentication event types and error rates for platform reliability monitoring. This telemetry does not include credential data.

Consent & Compliance

GDPR and ePrivacy Directive: Descope's session and refresh token cookies are strictly necessary for delivering the authenticated application service. Users explicitly initiate authentication and cannot access the application without these mechanisms. The ePrivacy Directive exempts technically necessary cookies from consent requirements. Under GDPR, authentication processing is lawful under contract performance (Article 6(1)(b)). Any telemetry data Descope collects for platform operations is processed under legitimate interests. Operators must include Descope as a data processor in their records of processing activities and execute a Data Processing Agreement.

CCPA/CPRA: Authentication credentials and session token data are personal information under CCPA. Descope processes this data as a service provider; this does not constitute a sale or sharing of personal information provided a compliant service provider agreement is in place.

Consent category: essential and functional (mixed). Authentication cookies are essential. Functional components such as user preferences or extended session management may cross into functional territory.

Should You Block This Without Consent?

No.

Descope provides authentication infrastructure that is technically necessary for the application to function for logged-in users. Blocking Descope scripts would prevent users from signing in, break session management, and make authenticated features entirely inaccessible. Authentication infrastructure is exempt from cookie consent requirements under the ePrivacy Directive's necessity exemption.

Is Descope GDPR compliant?

Descope typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Descope can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Descope, not on Descope itself.

Visit website

Consent Categories

Also Known As

descopedescope authdescope authenticationdescope ssoidentity management consent

Industries

Computers Electronics and TechnologyProgramming and Developer Software

Tracked Domains (1)

descope.comEssential

descope.com is an essential domain operated by Descope, used to keep the site working, including security, load balancing, and sessions.

Frequently Asked Questions

Related Vendors

Friendbuy
Friendbuy
Friendbuy is a referral and loyalty marketing platform for e-commerce and subscription brands. Its scripts embed referral widgets, track social sharing events, set cookies for conversion attribution across sessions, and collect participant data to manage referral reward programs.
Raygun
Raygun
Raygun is an application monitoring platform for error tracking and real user monitoring. The Raygun script captures JavaScript crashes, browser performance metrics, and user journey data for debugging and performance optimization.
Frontegg
Frontegg
Frontegg is a user management and authentication platform that provides embeddable login experiences. Its scripts handle login flows, single sign-on, multi-factor authentication, and session token management via cookies, controlling user access and identity verification on web applications.
Imgix
Imgix
Imgix is an image content delivery network and real-time processing service. It serves optimized images from global edge servers using URL-based transformations for resizing, cropping, and format conversion. It does not set cookies or collect personal data, operating purely as an asset delivery layer.
Enzuzo
Enzuzo
Enzuzo is a privacy compliance and consent management platform for websites. Its scripts display cookie consent banners, record visitor consent preferences, and conditionally block or allow third-party scripts and cookies based on the consent choices made by each visitor.
Lemon Squeezy
Lemon Squeezy
Lemon Squeezy is a payment and subscription platform for selling digital products and software. Its scripts embed checkout overlays and payment forms on websites, handle secure payment processing through iframe-based flows, and may set cookies to maintain cart state and attribute purchase sessions.

Manage consent for Descope

ConsentStack automatically detects and manages Descope trackers so your site stays compliant with global privacy regulations.