scanned Jul 4, 2026

WorkOS

workos.com

WorkOS provides a set of building blocks for quickly adding enterprise features to applications

76/100

Tier 4 · Agent-Ready

Content answers81/100
Protocol plumbing63/10010 of 16 checks pass

Scored by asking 15 questions a buyer of a saas product asks, then grading this site’s own pages: answered, hedged (partial or vague), or silent (no page answers it). How scoring works

This report is public. Own workos.com? Claiming is free: crawl every page, re-audit as you fix, and track your score over time.

Sign in to claim

The fix queue

24 points sit between workos.com and 100: 8 open questions and 6 missing protocol checks, ordered by estimated payoff.

Point estimates are per fix under scoring v2. They are not additive to a promised total.

Hedged · 8 of 15 questions

A buyer gets something, then has to guess the rest. Expand any row for the evidence and the fix.

01If our MAU count exceeds the purchased tier limit mid-month, does WorkOS charge prorated overages immediately or force an automatic tier upgrade?pricingHedges+2 pts est.

If our MAU count exceeds the purchased tier limit mid-month, does WorkOS charge prorated overages immediately or force an automatic tier upgrade?

What the pages say

WorkOS charges $2,500 per month for each additional million MAUs beyond the first 1 million free MAUs, but the retrieved chunks do not specify whether exceeding an MAU limit mid-month results in prorated overage charges or an automatic tier upgrade.

The fix

Add a billing FAQ or pricing page section explaining how mid-month MAU overages are handled—specifically whether customers are prorated immediately, automatically upgraded to the next tier, or billed retrospectively at month-end.

Where we looked: /compare/auth0, /compare/frontegg, /blog/auth0-pricing-how-it-works-and-compares-to-workos, /blog/clerk-pricing

confidence high · grounding synthesized · weight 0.70 · Vague

02When migrating from a standalone SSO implementation to WorkOS, will existing user sessions remain valid or will all users be forced to re-authenticate?migrationHedges+2 pts est.

When migrating from a standalone SSO implementation to WorkOS, will existing user sessions remain valid or will all users be forced to re-authenticate?

What the pages say

The WorkOS migration guide explains that when switching from the standalone SSO API to AuthKit, your application will receive User objects instead of Profiles, and the User IDs will differ from previous Profile IDs. However, the retrieved chunks do not state whether existing user sessions remain valid during the migration or if users will be forced to re-authenticate.

The fix

Add a section to the standalone SSO migration guide explaining whether existing application sessions remain valid during the migration or if users must re-authenticate.

Where we looked: /docs/migrate-standalone-sso.md, /docs/migrate-standalone-sso.md

confidence medium · grounding synthesized · weight 0.65 · Vague

03For on-premise deployments, does WorkOS require a Kubernetes cluster, or can it run on standard virtual machines with Docker Compose?technicalHedges+2 pts est.

For on-premise deployments, does WorkOS require a Kubernetes cluster, or can it run on standard virtual machines with Docker Compose?

What the pages say

The chunks describe WorkOS as a cloud-hosted API service that integrates with on-prem customer applications via static API keys and HTTPS firewall rules, but they do not specify whether WorkOS itself can be self-hosted on-premise or whether such a deployment would require a Kubernetes cluster versus Docker Compose on standard virtual machines.

The fix

Clarify in the on-prem deployment documentation whether WorkOS offers a self-hosted on-premise option and, if so, specify the infrastructure requirements such as Kubernetes, Docker Compose, or standard VMs.

Where we looked: /blog/air-gapped-authentication-with-workos, /docs/on-prem-deployment.md, /docs/on-prem-deployment.md

confidence medium · grounding synthesized · weight 0.65 · Vague

04What is the guaranteed support response time SLA for production-impacting issues under WorkOS's enterprise plan?supportHedges+2 pts est.

What is the guaranteed support response time SLA for production-impacting issues under WorkOS's enterprise plan?

What the pages say

WorkOS enterprise plans include “response time SLAs,” but the retrieved chunks do not specify the guaranteed response time for production-impacting issues. The Enterprise SLA page only details a 99.99% uptime guarantee and service credits, with no support response time commitments listed.

The fix

Publish the specific support response time commitments (e.g., 1 hour for production-impacting issues) on the /support-plans or /legal/sla page rather than only referencing that response time SLAs exist.

Where we looked: /audit-logs, /legal/sla

confidence high · grounding synthesized · weight 0.70 · Vague

05Does WorkOS Vault support automated encryption key rotation, and if so, what is the default rotation interval for customer-managed keys?securityHedges+2 pts est.

Does WorkOS Vault support automated encryption key rotation, and if so, what is the default rotation interval for customer-managed keys?

What the pages say

WorkOS Vault supports rotating keys on demand, and when a customer rotates a key in their own KMS, Vault automatically uses the latest active key for new encryption requests while previous key versions remain available to decrypt existing data. However, the chunks do not state whether Vault initiates automated key rotation on a schedule, nor do they specify a default rotation interval for customer-managed keys.

The fix

Add explicit documentation on whether Vault supports automated (scheduled) key rotation for customer-managed keys and state the default rotation interval, if any.

Where we looked: /blog/enterprise-infrastructure-for-ai-apps, /blog/byok-with-vault

confidence medium · grounding synthesized · weight 0.65 · Vague

06What are the per-minute rate limits and burst quotas for MCP tool invocations through the WorkOS API?limitsPage missing+2 pts est.

What are the per-minute rate limits and burst quotas for MCP tool invocations through the WorkOS API?

What the pages say

The WorkOS API has a general rate limit of 6,000 requests per 60 seconds per IP address for all requests. However, the retrieved chunks do not specify any per-minute rate limits or burst quotas specific to MCP tool invocations.

The fix

Add an MCP-specific section to the rate limits documentation that lists per-minute rate limits and burst quotas for MCP tool invocations.

Where we looked: /llms-full.txt, /docs/mcp.md

confidence high · grounding synthesized · weight 0.70 · Page missing

07When audit log streaming to our SIEM endpoint experiences backpressure or timeout, does WorkOS buffer events locally and for how long before dropping them?operationsHedges+2 pts est.

When audit log streaming to our SIEM endpoint experiences backpressure or timeout, does WorkOS buffer events locally and for how long before dropping them?

What the pages say

WorkOS supports streaming Audit Logs to generic HTTP POST endpoints and specific SIEM providers, but the retrieved documentation does not specify whether events are buffered locally when the destination experiences backpressure or timeout, nor how long they would be retained before dropping.

The fix

Add a reliability or operations section to the Log Streams documentation that explains behavior during destination failures: whether events are buffered locally, maximum buffer duration/size, retry policies, and drop behavior under backpressure or timeout.

Where we looked: /llms-full.txt, /docs/audit-logs/log-streams.md, /docs/audit-logs/log-streams.md

confidence high · grounding synthesized · weight 0.70 · Vague

08In the Pipes Admin portal, can we restrict operator access to specific organization tenants, or does admin access apply globally across all connected directories?securityHedges+2 pts est.

In the Pipes Admin portal, can we restrict operator access to specific organization tenants, or does admin access apply globally across all connected directories?

What the pages say

The chunks indicate that the Pipes Admin widget is designed for organization administrators to manage their own organization's Pipes connections, requiring the `widgets:pipes:manage` permission, which implies a per-organization scope rather than a global view. However, the chunks do not explicitly state whether vendor operators can be restricted to specific organization tenants or if admin access applies globally across all connected directories.

The fix

Add explicit documentation clarifying whether Pipes Admin portal/operator access can be scoped to specific organization tenants or if it applies globally across all connected directories.

Where we looked: /llms-full.txt, /llms-full.txt, /docs/pipes/organization-scoped-providers.md

confidence medium · grounding synthesized · weight 0.65 · Vague

What the pages already answer cleanly

7 of 15. Answered with enough specificity for a buyer to act on. This is the bar the queue above is chasing.

securityAnswered

Which specific compliance certifications and attestations—such as SOC 2 Type II or ISO 27001—does WorkOS currently maintain?

What the pages say

WorkOS is SOC 2 Type 2 certified, SOC 3 certified, and PCI DSS compliant through self-attestation (SAQ-D). It is also GDPR and CCPA compliant, and can sign HIPAA Business Associate Agreements (BAAs) on enterprise plans. Additionally, WorkOS conducts annual third-party penetration tests and external code audits.

Source: /blog/how-being-enterprise-ready-helps-slack-land-big-deals, /blog/december-2025-updates, /blog/enterprise-sso-providers-b2b-saas, /security, /security

confidence high · grounding synthesized · weight 0.95 · Answered

pricingAnswered

What is the monthly active user (MAU) limit for WorkOS's free tier, and at what MAU threshold does paid billing begin?

What the pages say

WorkOS User Management is free for up to 1,000,000 monthly active users (MAUs). Paid billing begins for MAUs beyond 1,000,000, at $2,500 per additional million MAUs.

Source: /pricing, /blog/auth0-alternatives

confidence high · grounding synthesized · weight 0.95 · Answered

integrationAnswered

Does WorkOS support both SAML 2.0 and OIDC for enterprise SSO, or is one protocol required for certain identity providers?

What the pages say

WorkOS supports both SAML 2.0 and OIDC for enterprise SSO. Neither protocol is universally required; the platform is compatible with any identity provider that supports either SAML or OIDC, and developers integrate once with the WorkOS API so enterprise customers can use whichever protocol their IdP supports. Some IdPs only support one protocol—ADP, for example, uses OIDC rather than SAML—but WorkOS accommodates both rather than forcing customers to switch.

Source: /blog/how-sso-works, /blog/enterprise-readiness-checklist-2026, /docs/authkit/sso.md, /llms-full.txt

confidence high · grounding synthesized · weight 0.95 · Answered

operationsAnswered

If a directory sync webhook fails or returns a 5xx error, how many automatic retries does WorkOS attempt before marking the sync as failed?

What the pages say

WorkOS automatically retries a failed directory sync webhook up to 6 times with exponential backoff over 3 days in production environments. If the endpoint still does not return a 2xx response after that period, the event is considered failed and WorkOS stops retrying.

Source: /docs/events/data-syncing/webhooks.md, /llms-full.txt, /llms-full.txt, /docs/events/data-syncing/webhooks.md

confidence high · grounding synthesized · weight 0.95 · Answered

technicalAnswered

For WorkOS transactional emails sent on our behalf, do we need to configure custom SPF and DKIM records for our domain, or does WorkOS handle deliverability using its own domain?

What the pages say

It depends on which sending option you use. By default, WorkOS sends transactional emails from the `workos-mail.com` domain and handles SPF, DKIM, and DMARC authentication automatically—no DNS configuration is required on your end. However, if you configure WorkOS to send emails from your own domain, you must set up DNS records with your provider, including two additional CNAME records that automatically configure SPF and DKIM authentication via SendGrid's automated security feature.

Source: /docs/email.md, /docs/email.md

confidence high · grounding synthesized · weight 0.95 · Answered

integrationAnswered

Can the pre-built Admin Portal and user management widgets be fully white-labeled with our own domain, or do they still route through WorkOS-branded URLs?

What the pages say

Yes. The Admin Portal can be fully white-labeled with your own domain via CNAME; in production it uses setup.workos.com by default or a custom domain if configured. The User Management Widgets are React components that you embed directly in your own application, so they render on your domain and can be themed to match your brand. You can also configure a custom API hostname in the SDKs so API calls do not route through WorkOS-branded URLs.

Source: /admin-portal, /llms-full.txt, /docs/custom-domains/admin-portal.md, /docs/widgets.md, /llms-full.txt, /llms-full.txt

confidence high · grounding synthesized · weight 0.95 · Answered

integrationAnswered

If a user's browser locale is set to a language not yet supported by the WorkOS widgets, what is the fallback behavior—does it default to English or return untranslated keys?

What the pages say

The WorkOS Widgets documentation shows that when a user's locale is not supported, the fallback is to English (`en-US`). In the official code example for detecting locale, if `isValidLocale()` returns false, the function returns `DEFAULT_LOCALE`, which is set to `'en-US'`. It does not return untranslated keys.

Source: /llms-full.txt

confidence high · grounding stated · weight 1.00 · Answered

Protocol plumbing · 63/10010 of 16 checks pass · each fix +6 protocol pts est.

The other half of the score: 16 checks for the files and headers agents look for. The 6 below are installs, not judgment calls, and most are an afternoon. Expand any for the snippet and the standard it follows. They sit after the queue because none of them changes what your pages say.

Content signalAccess+6 pts est.
Install snippet
User-agent: *
Content-Signal: search=yes, ai-input=yes, ai-train=no
Allow: /

StandardCloudflare proposalVendor proposal

Markdown negotiationRendering+6 pts est.

StandardRFC 9110 + 7763IETF RFC

MCP cardInteraction+6 pts est.

Sitedex generates this file from your crawl. Grab it in Files from this audit below.

StandardModel Context ProtocolCommunity spec

OpenAPI specInteraction+6 pts est.

StandardOpenAPI SpecIndustry standard

WebMCP widgetInteraction+6 pts est.

Sitedex generates this file from your crawl. Grab it in Files from this audit below.

StandardW3C WebMCP draftW3C / WHATWG

Sitemap lastmodDiscoverability+6 pts est.

Standardsitemaps.orgIndustry standard

Already passing 10 of 16: robots.txt, sitemap.xml, llms.txt, AI crawler access, Clean crawl, Server-rendered content, Canonical URLs, Meta descriptions, HTML lang attribute, Organization schema.

Ask this site’s index

Sitedex already serves workos.com as an MCP endpoint. Ask workos.com anything an AI agent might ask, and see what its index returns. (To score your own site, use the form below.)

Snippets & configs

For developers and the engineer-on-call: copy these into your tools or your site.

Files from this audit

Built from this crawl. Download or copy each, then install it at the path noted.

llms.txt

Built from this crawl. Install at /llms.txt so agents start here.

organization.json

Organization JSON-LD, pre-filled from this crawl. Wrap in a ld+json script.

server-card.json

MCP server card built from this crawl. Host at /.well-known/mcp/server-card.json.

webmcp.json

WebMCP discovery manifest built from this crawl. Host at /.well-known/webmcp.json.

MCP endpoint

https://mcp.sitedex.dev/s/workos-com/mcp

The URL anyone's agent points at. Read-only; safe to share.

Claude Code

claude mcp add workos --transport http https://mcp.sitedex.dev/s/workos-com/mcp

One command, then the agent has it.

Cursor / Continue

{
  "mcpServers": {
    "workos": {
      "url": "https://mcp.sitedex.dev/s/workos-com/mcp"
    }
  }
}

Drop into mcp.json.

WebMCP: two parts

WebMCP-capable browsers run the widget at runtime. Crawlers without JS rendering need the discovery manifest to find your tool surface. Install both.

1 · Widget script

<script async src="https://sitedex.dev/widget.js"></script>

Drop in <head>. WebMCP-capable browsers (Chrome 146+ Origin Trial) call navigator.modelContext.provideContext() via this script.

2 · Discovery manifest

{
  "$schema": "https://wellknownmcp.org/schemas/webmcp.json",
  "name": "workos.com",
  "tools": [
    { "name": "search", "description": "Search workos.com's indexed content." },
    { "name": "get_page", "description": "Fetch a page from workos.com as markdown." }
  ]
}

Host alongside the script at /.well-known/webmcp.json. Crawlers that don't render JS rely on this.

Your turn

See which of these questions your site goes silent on.

Free, about 5 minutes. We crawl your site, test it against the buyer questions your category asks, and name what’s vague, contradictory, or missing, plus the files AI agents look for.

ComingEmbeddable grade badgeScore history and deltasOpt-in public board