Using Descope With On-Premises B2B Customers

Using Descope With On-Premises B2B Customers

Kevin Gao Head of AI Strategy and DX

Key deployment considerations

When deploying an app to a customer’s data center or private VPC, you’ll need to:

Using a static Descope Project key

Each customer deployment should have its own dedicated Descope project and API key. This ensures:

Follow these steps to set up your Descope Project key:

Enabling network access to Descope

To enable Descope features such as SSO, MFA, hosted authentication Flows, and webhooks in an on-premises environment, the deployed application must be able to communicate with the Descope cloud platform.

Depending on your customer’s network posture, there are two primary strategies to establish this connectivity:

Strategy 1: Configure firewall rules or ACLs

This is the preferred approach for production environments where stable, direct communication is required.

Descope endpoints to allow

Endpoint Purpose
https://api.descope.com Descope APIs: authentication, user/session management
https://static.descope.com Hosted Flows, JavaScript SDK, web components

Ingress rules (incoming traffic to customer environment)

Some Descope features require initiating HTTP(S) requests from Descope to the on-premises application. These include:

To support these use cases:

Egress rules (outgoing traffic from customer environment)

The on-premises application must initiate secure requests to Descope for operations such as:

To support these:

Strategy 2: Use a reverse proxy tunnel (e.g., ngrok or Cloudflare Tunnel)

This approach is ideal when the customer cannot or does not want to modify firewall rules. A secure tunnel exposes specific local ports or paths to the internet, enabling Descope to send requests as needed.

ngrok setup guide

Step 1: Install ngrok

Download and install the ngrok CLI:

brew install ngrok/ngrok/ngrok

Step 2: Authenticate (recommended for reserved domains)

If you have a paid ngrok plan and want to use static subdomains or additional access control:

ngrok config add-authtoken <your-ngrok-token>

Step 3: Start the tunnel

Assuming your application is running locally on port 3000:

grok http 3000

This will generate a temporary HTTPS URL such as:

Forwarding https://brisk-horse.ngrok.io → http://localhost:3000

Step 4: Configure Descope

In the Descope Console:

This ensures Descope can successfully return authentication responses and deliver events to the on-premises application.

Cloudflare Tunnel setup (alternative)

If your customer already uses Cloudflare or prefers a corporate-grade tunneling service:

Step 1: Install cloudflared

Instructions: Cloudflare Tunnel Installation Guide

Step 2: Authenticate and create a tunnel

cloudflared tunnel login
cloudflared tunnel create descope-tunnel

Step 3: Configure routing and DNS

cloudflared tunnel route dns descope-tunnel login.customer-domain.com

Step 4: Start the tunnel

cloudflared tunnel run descope-tunnel

Step 5: Configure Descope

Use the public domain (e.g., https://login.customer-domain.com/callback) in your Descope SSO and webhook configuration.

Security considerations for Tunnels

Summary: Choosing between the two approaches

Feature Firewall Rules (Strategy 1) Reverse Tunnel (Strategy 2)
Best for Production Yes No (unless using paid plan)
Minimal IT Involvement No Yes
Custom Domain Support Yes Yes
Persistent URLs Yes Only with paid plans
Secure HTTPS Communication Yes Yes
Supports Webhooks & Redirects Yes Yes
Deployment Complexity Moderate Low

Connecting to on-premises identity providers (e.g., ADFS)

Descope supports IdP-initiated and SP-initiated SSO via both SAML and OIDC, making it easy to connect with common on-premises identity providers like:

To set this up, use the SSO Setup Suite in the Descope Console, which provides a step-by-step guided configuration flow to:

Securing complex enterprise environments with Descope

Descope brings flexible, modern B2B CIAM to even the most technically demanding enterprise scenarios. With built-in support for SSO, MFA, device security, and webhook-driven flows, you can confidently deploy your product into customer-owned infrastructure without sacrificing security or developer experience.