← DescopeCONTENT HISTORY

Update to Descope

Snapshot Sep 30, 2026 · 22:52 UTC · version 1.0.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "descope-auth",
  "description": "Integrate Descope authentication into applications. Use when implementing login, signup, passwordless auth (OTP, Magic Link, Passkeys), OAuth, SSO, or MFA. Detects framework and provides targeted guidance.",
  "included_files": [
    {
      "relative_path": "references/backend.md",
      "size_in_bytes": 1329
    },
    {
      "relative_path": "references/nextjs.md",
      "size_in_bytes": 2294
    },
    {
      "relative_path": "references/react.md",
      "size_in_bytes": 2526
    }
  ],
  "skill_md_contents": "---\nname: descope-auth\ndescription: Integrate Descope authentication into applications. Use when implementing login, signup, passwordless auth (OTP, Magic Link, Passkeys), OAuth, SSO, or MFA. Detects framework and provides targeted guidance.\n---\n\n# Descope Authentication\n\nIntegrate secure, passwordless authentication using Descope Flows and SDKs.\n\n## Framework Detection\n\nDetect the user's framework and use the appropriate reference:\n\n| If project has... | Use reference |\n|-------------------|---------------|\n| `next` in package.json | `references/nextjs.md` |\n| `react` (no Next.js) | `references/react.md` |\n| Python/Node.js backend only | `references/backend.md` |\n\n## Quick Start (all frameworks)\n\n1. Get Project ID from https://app.descope.com/settings/project\n2. Set environment variable: `NEXT_PUBLIC_DESCOPE_PROJECT_ID=<your-id>`\n3. Follow framework-specific reference\n4. **Verify**: After setup, confirm the `<Descope>` component renders the login form. Check the browser console — a missing or invalid Project ID produces a clear `Could not load flows` error.\n\n### Minimal Inline Example (Next.js)\n\n```tsx\n// src/app/login/page.tsx\nimport { Descope } from '@descope/nextjs-sdk';\n\nexport default function LoginPage() {\n  return (\n    <Descope\n      flowId=\"sign-up-or-in\"\n      onSuccess={(e) => console.log('Authenticated:', e.detail.user)}\n      onError={(e) => console.error('Auth failed:', e.detail)}\n    />\n  );\n}\n```\n\nFor React SPA or backend-only setups, see the framework-specific references below.\n\n## Valid Flow IDs (CRITICAL - do not invent others)\n\n| Flow ID | Purpose |\n|---------|---------|\n| `sign-up-or-in` | Combined signup/login (RECOMMENDED) |\n| `sign-up` | Registration only |\n| `sign-in` | Login only |\n| `step-up` | MFA step-up authentication |\n| `update-user` | Profile updates, add auth methods |\n\n## Authentication Methods\n\n| Method | When to use |\n|--------|-------------|\n| OTP (Email/SMS) | Quick verification codes |\n| Magic Link | Passwordless email links |\n| Passkeys | Biometric/WebAuthn (most secure) |\n| OAuth | Social login (Google, GitHub, etc.) |\n| SSO | Enterprise SAML/OIDC |\n| Passwords | Traditional auth (not recommended) |\n\n## DO NOT (Security Guardrails)\n\n- DO NOT parse JWTs manually - always use SDK's `validateSession()`\n- DO NOT store tokens in localStorage - SDK handles this securely\n- DO NOT invent flow IDs - only use IDs from the table above\n- DO NOT skip server-side validation - always validate on backend\n- DO NOT expose DESCOPE_MANAGEMENT_KEY in client code\n\n## References\n\n- `references/nextjs.md` - Next.js App Router integration\n- `references/react.md` - React SPA integration  \n- `references/backend.md` - Backend session validation\n"
}

SHA-256: ea4ceab3fba34543c1936376c97876453b1302a857716bf716613fb4eb8d41be