← Back to all sparks
K

Kinde

DEVOPS
Velocity3.8

Kinde went from connecting agents to itself to helping customers ship their own MCP servers

identitymcpagent authorizationpasskeyssaml ssobilling
Current state
Kinde has been filling out the standard identity surface — passkeys via WebAuthn/FIDO2, IdP-initiated SAML SSO, WhatsApp delivery for verification codes, and organization-level invite controls — while building billing into the platform with self-serve plan management and the ability to cancel a customer. The newest release, Kinde Secure MCP, is a different kind of move: a beta that lets customers ship an MCP server for their own product so their users can reach it from Claude, Cursor and similar tools.
Where it's heading
January's Kinde MCP server let agents operate Kinde itself; Secure MCP inverts that, making Kinde the thing that authenticates someone else's agent-facing API. That places the company on the access-control layer for agent traffic rather than only human login, which is a wider surface than passkeys or SAML. The billing work running alongside it suggests Kinde intends to be the monetization-plus-identity layer for a product, not just the sign-in box.
Prediction
Secure MCP is in beta, so the near-term work is most likely general availability plus the scope, consent and token-handling controls that agent access needs. Expect the authentication method list to keep widening in parallel, since that has been the steady cadence all year.

Recent moves

  1. 12d ago

    Kinde Secure MCP lets you ship an MCP server to customers

    ⚡ SPARK

    Kinde Secure MCP, in beta, lets customers ship an MCP server for their own product so users can reach it from Claude, Cursor and other AI clients. It moves Kinde from authenticating people into a product to authenticating agents into someone else's API.

  2. 1mo ago

    Passkey sign-in (WebAuthn/FIDO2) plus flexible billing

    Passwordless sign-in with passkeys (WebAuthn/FIDO2) lands alongside further billing flexibility. Standard-surface work — passkey support is close to table stakes for an identity provider at this point.

  3. 2mo ago

    Self-serve plan management and customer cancellation

    Plan management becomes more self-serve on both sides, including the ability to cancel a customer. Continues Kinde's pattern of treating billing as part of the identity platform rather than an adjacent concern.

  4. 3mo ago

    Organization owners gain invite controls

    Organization owners gain control over whether member invitations are enabled at all and how invite emails are sent. Administrative tightening aimed at larger multi-tenant deployments.

    View source ↗
  5. 4mo ago

    WhatsApp delivery for verification codes and notifications

    Verification codes and notifications can be delivered over WhatsApp, aimed at markets where it is the primary messaging channel. A deliverability play rather than a security one.

    View source ↗
  6. 5mo ago

    IdP-initiated SAML SSO

    Users can start a login flow from their identity provider's portal rather than having to begin at the application. An enterprise SSO expectation being met.

    View source ↗