# New this month: Agent Auth, MCP Enterprise-Managed Authorization…

Canonical: https://brew.new/browse/templates/email/pt1_k97yaj4nk3vd2ye6117wmv0s158fgg04

Brand: workos.com
Category: general

![Preview of New this month: Agent Auth, MCP Enterprise-Managed Authorization…](https://cdn.brew.new/email-preview-e70b0d8deb181309-tracking_r57xp2vb9m8q3jwt8yxhege0g58fgy17-1790976103422.png)

## Email content

WorkOS

WorkOS

New this month

Agent Auth, MCP Enterprise-Managed Authorization (EMA), Feature Flags Custom Targeting, & more

Agent Auth

The agents you're building into your product need identities and credentials. Until now, that meant handing them a long-lived API key or letting them borrow a user's session. Agent Auth, now in early access, gives agents their own identities in AuthKit. Define blueprints for what each agent can do, and it gets short-lived, tightly scoped tokens every time it runs.

Agents can act on a user's behalf through delegated access or autonomously with scoped access within an organization. Every token identifies the agent, the user or organization it's acting for, and its permissions. You can revoke sessions instantly. Get in touch via email or Slack to try it.

View the docs →

MCP Enterprise-Managed Authorization (EMA)

MCP Auth now supports Enterprise-Managed Authorization (EMA), letting MCP clients access servers through a company's identity provider (IdP). Previously, connecting multiple applications to an agent via MCP meant approving dozens of consent screens. Once configured in the IdP, EMA lets an MCP client automatically connect to downstream MCP servers without human involvement. Get in touch via Slack or email for access.

Learn more →

Feature Flags Custom Targeting

Feature Flags now supports custom targets for rollouts beyond users and organizations. Define resources such as workspaces, plans, environments, or regions, then enable features for specific IDs. Run betas, stage releases, and roll out functionality to the right parts of a customer account. Try it in the dashboard.

Explore custom targeting →

Events

init() by WorkOS

Join the founders, engineers, and technical leaders shaping what’s next. Hear how the best teams are building with AI, shipping ambitious products, and turning new ideas into reality.

All attendees will get a free hackable ESP-32 badge!

San Francisco. October 7th. SFJAZZ Center.

Get registered →

Developers After Dark

Join fellow developers at San Francisco’s Exploratorium on October 8 for vintage tech, hands-on ESP32-S3 hacking, food, and drinks. Bring your laptop and explore the museum after hours.

Register to attend →

An Evening with The Pragmatic Engineer

Gergely Orosz joined Michael Grinich at our New York office to discuss how AI is changing engineering roles, why faster coding enables more ambitious projects, and what it takes to keep software reliable.

Read the recap →

More featured content

Set Audit Log retention from 30 days to 10 years per organization in the Dashboard.

Debug provisioning with SCIM request and response logs for each directory in the Dashboard.

Configure the WorkOS MCP server in Claude Code, Codex, and Cursor with one command.

Review your SaaS app’s agent access controls with our AI agent permissions checklist, from identity to revocation.

If you have any feedback or feature suggestions, simply reply to this email.

Unsubscribe from all WorkOS marketing emails

WorkOS

548 Market Street PMB 86125 • San Francisco, CA 94104

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97yaj4nk3vd2ye6117wmv0s158fgg04)

[Browse email designs](https://brew.new/browse/templates)
