{
 "categories": [
  "identity",
  "developer-tools"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-18",
   "fact": "homepage",
   "note": "WorkOS documents an enterprise-ready authentication and identity API. Canonical homepage is https://workos.com/.",
   "source": "https://workos.com/docs/reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "license",
   "note": "Pricing lists the first 1 million active users as free, then $2,500 per additional 1 million users. SSO connections are priced separately from $125.",
   "source": "https://workos.com/pricing",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.api.exists",
   "note": "WorkOS documents a REST API for authenticating users, syncing directories, enforcing access controls, and streaming audit logs.",
   "source": "https://workos.com/docs/reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.api.kinds[0]",
   "note": "The API is organized around REST. It accepts JSON request bodies, returns JSON, and uses standard HTTP verbs and status codes.",
   "source": "https://workos.com/docs/reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.api.auth[0]",
   "note": "Requests authenticate with an account API key. Example header is Authorization: Bearer sk_example_.... Missing or incorrect keys return 401. All requests must use HTTPS.",
   "source": "https://workos.com/docs/reference/api-authentication",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.api.coverage",
   "note": "The reference covers users, directories, access controls, and audit logs. Production API keys are generated after unlocking Production access and can be viewed only once. This is not a claim that every Dashboard control is in REST.",
   "source": "https://workos.com/docs/reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.api.docs",
   "note": "Opened as the current WorkOS API reference getting-started page.",
   "source": "https://workos.com/docs/reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.sdk.exists",
   "note": "WorkOS documents official open-source client libraries.",
   "source": "https://workos.com/docs/sdks",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.sdk.languages",
   "note": "Backend SDKs listed include Node.js, Python, Go, PHP, Ruby, Java, .NET, Rust, and Elixir.",
   "source": "https://workos.com/docs/sdks",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.sdk.official",
   "note": "The page calls them official open-source client libraries.",
   "source": "https://workos.com/docs/sdks",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.mcp.first_party",
   "note": "WorkOS documents a remote management MCP at https://mcp.workos.com/mcp over Streamable HTTP with WorkOS Connect OAuth. The page separately points AuthKit for MCP at builders of other MCP servers.",
   "source": "https://workos.com/docs/mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.cli.exists",
   "note": "The WorkOS CLI is a standalone executable for installing AuthKit integrations and managing WorkOS resources. Management commands support --json. mcp and setup commands wire the hosted MCP into coding agents.",
   "source": "https://workos.com/docs/cli",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.extensibility.webhooks",
   "note": "Webhook endpoints are created at https://api.workos.com/webhook_endpoints. Objects include a secret used to sign payloads and event types such as user.created.",
   "source": "https://workos.com/docs/reference/webhooks",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.data_access.export[0]",
   "note": "The REST API returns JSON-encoded responses.",
   "source": "https://workos.com/docs/reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.data_access.import[0]",
   "note": "The REST API accepts JSON-encoded request bodies for create and update operations.",
   "source": "https://workos.com/docs/reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "https://workos.com/docs/llms.txt is a first-party WorkOS documentation index, including the MCP server and CLI.",
   "source": "https://workos.com/docs/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "verdict.scores.api",
   "note": "Broad documented REST plus official SDKs, webhook endpoints, and API-key auth. Production-key unlock is an operational limit, scored 8.",
   "source": "https://workos.com/docs/reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "verdict.scores.mcp",
   "note": "Official hosted management MCP with OAuth and role inheritance. Admin kill-switch and no credential minting keep it at 8.",
   "source": "https://workos.com/docs/mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "verdict.scores.cli",
   "note": "Official standalone CLI with --json, resource coverage, and explicit MCP install. Scored 8.",
   "source": "https://workos.com/docs/cli",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "freshness.watch[0].url",
   "note": "Opened as the current WorkOS management MCP guide, including endpoint, OAuth, permissions, and limits.",
   "source": "https://workos.com/docs/mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "freshness.watch[1].url",
   "note": "Opened as the current REST API getting-started page.",
   "source": "https://workos.com/docs/reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "freshness.watch[2].url",
   "note": "Opened as the current CLI documentation.",
   "source": "https://workos.com/docs/cli",
   "tier": "declared"
  },
  {
   "date": "2026-09-18",
   "fact": "freshness.watch[3].url",
   "note": "Opened as the current API-key authentication page.",
   "source": "https://workos.com/docs/reference/api-authentication",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-18",
  "volatility": "high",
  "watch": [
   {
    "type": "mcp",
    "url": "https://workos.com/docs/mcp"
   },
   {
    "type": "docs",
    "url": "https://workos.com/docs/reference"
   },
   {
    "type": "docs",
    "url": "https://workos.com/docs/cli"
   },
   {
    "type": "docs",
    "url": "https://workos.com/docs/reference/api-authentication"
   }
  ]
 },
 "homepage": "https://workos.com/",
 "id": "workos",
 "license": "freemium",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "api-key"
   ],
   "coverage": "partial",
   "docs": "https://workos.com/docs/reference",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": true
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": [
    "json"
   ]
  },
  "extensibility": {
   "scripting": [],
   "webhooks": true
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. The WorkOS REST API, official SDKs, CLI, hosted management MCP, and webhook endpoints cover workspace automation without browser control.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": true,
   "languages": [
    "javascript",
    "python",
    "go",
    "php",
    "ruby",
    "java",
    "dotnet",
    "rust",
    "elixir"
   ],
   "official": true
  }
 },
 "name": "WorkOS",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "auth0",
   "okta",
   "stytch",
   "fusionauth"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "WorkOS",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": 8,
   "computer_use": null,
   "integrations": null,
   "mcp": 8,
   "overall": 8,
   "rpa": null
  },
  "summary": "WorkOS is automatable today through the REST API. The API is organized around REST at https://api.workos.com, accepts and returns JSON, and authenticates with a secret API key as Authorization Bearer. Keys are prefixed with sk_. Official backend SDKs are listed for Node.js, Python, Go, PHP, Ruby, Java, .NET, Rust, and Elixir. First-party management MCP is hosted at https://mcp.workos.com/mcp over Streamable HTTP with WorkOS Connect OAuth. The agent inherits the dashboard user's role. Admins can disable MCP, block production, or force read-only. The server cannot mint or rotate API keys, change its own MCP admin controls, impersonate users, or delete the team. AuthKit for MCP, which secures other people's MCP servers, is outside this product boundary. The official CLI is a standalone binary with --json output and commands that manage organizations, users, connections, and the MCP install. Webhook endpoints are created at /webhook_endpoints and include a signing secret. This record excludes Auth0, Okta, Stytch, and FusionAuth. Connector catalogs were not opened. Computer-use viability is unassessed. API, MCP, and CLI all score 8; API is the best path because it is not subject to the MCP admin kill-switch or CLI login session.\n"
 }
}