{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "aembit",
    "name": "Aembit",
    "vendor": "Aembit, Inc.",
    "vendorUrl": "https://aembit.io",
    "kind": "http-api",
    "category": "agent-auth",
    "summary": "Aembit is a hosted identity and access platform for workloads and AI agents. Its MCP Identity Gateway and MCP Authorisation Server apply access policies and inject credentials, with a Cloud API, an Edge API, a CLI and an Edge SDK.",
    "url": "https://www.anchorterminal.com/tools/aembit",
    "markdownUrl": "https://www.anchorterminal.com/tools/aembit.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/aembit.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/aembit.json",
    "repo": "https://github.com/Aembit/edge-sdks",
    "license": "Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0",
    "transports": [
      "http",
      "streamable-http"
    ],
    "packages": [
      {
        "registry": "npm",
        "name": "@aembit/edge-sdk"
      }
    ],
    "auth": "mixed",
    "authNotes": "Every API takes a short-lived Bearer token. For the Cloud API at https://\u003ctenant\u003e.aembit.io/api/v1, a person copies an API token from the tenant's Profile page (1 hour by default), or a workload obtains an Aembit Access Token through an Access Policy and a role. The Edge API exchanges platform attestation for an access token at /edge/v1/auth. MCP clients reach the MCP Identity Gateway and MCP Authorisation Server by OAuth 2.1 with PKCE and dynamic client registration or a Client ID Metadata Document, after the user signs in through the company's identity provider. Access is self-serve for a free tenant. The managed gateway endpoint is requested through an Aembit representative.",
    "pricing": "freemium",
    "pricingNotes": "Starter is free with 3 AI agents, one MCP Identity Gateway and 5 MCP authorisation policies, or 10 workloads and 10 Access Policies, with 24 hours of event log retention. The pricing FAQ says no payment information is required. Teams is $20 per AI agent a month (to 500 agents) or $20 per workload a month, with a Contact Us button. Enterprise is custom. An agent can start on the free tenant without a contract (https://aembit.io/pricing/, checked 2026-10-08).",
    "priceSummary": "$20 / mo",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, the OpenAPI files or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 27,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.aembit.io",
    "llmsTxt": "https://docs.aembit.io/llms.txt",
    "openapi": "https://docs.aembit.io/cloud.yaml",
    "capabilities": [
      "auth.oauth",
      "auth.agent-identity",
      "auth.tokens",
      "auth.consent",
      "auth.audit"
    ],
    "tags": [
      "hosted",
      "freemium",
      "free-tier",
      "oauth",
      "mcp",
      "openapi",
      "llms-txt",
      "typescript",
      "cli",
      "terraform",
      "status-page",
      "soc2",
      "iso27001",
      "enterprise",
      "self-hosted"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 70.5,
      "grade": "BB",
      "agentReady": true,
      "rank": 127,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 72,
        "maintenance": 80,
        "payments": 40,
        "reliability": 65,
        "schema": 85,
        "security": 84,
        "transparency": 60
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 65,
          "points": 13,
          "reason": "Graded as a hosted service. Statuspage at status.aembit.io with two components, Management Portal (Admin and API) and Control Plane (20). One incident in the 90 days to 8 October 2026, the admin console unavailable for five minutes on 14 July during a service upgrade (30). No rate limit figures found. The Aembit MCP Server page says it has no application-level rate limiting and caps `perPage` at 100 (0). The Edge API and the MCP Authorisation Server list 429 responses, and the docs advise caching tokens until near expiry, but no Retry-After or back-off guidance for callers and no idempotency keys were found (5). No SLA is published, and the docs send SLA details to support (0). The Cloud API is v1 and the Edge API 1.0.0 with no beta label, though MCP Identity Gateway began as a limited beta on 28 January 2026 and the docs don't state its current status (10). Total 65."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 85,
          "points": 13.81,
          "reason": "OpenAPI 3.1.1 files for the Cloud API (78 paths, 171 operations) and the Edge API (2 operations) download from docs.aembit.io without a login (25). llms.txt, per-page Markdown, split API reference files and a docs bundle on GitHub (10). The guides say when to pick the MCP Identity Gateway over the MCP Authorisation Server, and an SDK over Agent Proxy, and 170 of 171 Cloud operations carry a summary or description (16). 188 Cloud schemas, 44 with required fields, and enums on the Edge API credential type, but most Edge fields are nullable strings (9). curl examples and status code tables, with the MCP Authorisation Server's table described as not exhaustive and no Cloud API error catalogue (10). `/api/v1` in the path and a dated changelog with RSS (15). Total 85."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 72,
          "points": 11.7,
          "reason": "The Edge API is two calls that return one credential, and the Aembit MCP Server has three read-only tools (22). Cloud API lists take `page`, `per-page`, `order`, `filter` and `group-by`, and event queries take time spans and severity (20). Standard HTTP status codes with per-endpoint tables for the Edge API, and JSON-RPC errors from the gateway, but no catalogue of Cloud API error bodies (12). No idempotency keys found. Credential requests are repeatable and the MCP server is read-only, and the gateway passes tool annotations through (8). TypeScript SDK on npm, a CLI and a Terraform provider. The Python SDK is in the repository at 0.1.0 and was not on PyPI on 8 October 2026 (10). Total 72."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 84,
          "points": 14.7,
          "reason": "The API accepts only Bearer access tokens and the docs say long-lived credentials aren't supported. Aembit API tokens last 1 hour by default, workloads authenticate by attestation through Trust Providers, and MCP clients use OAuth 2.1 with PKCE and dynamic client registration or a Client ID Metadata Document (30). Roles set No Access, Read Only or Read/Write per resource type and can be limited to Resource Sets, an Auditor system role exists, and MCP Tool Access Control can hide or block tools, though it is off until support enables it. No confirmation step for destructive API calls was found (16). The gateway relays MCP server content, and a Content Security Provider can send tool traffic to CrowdStrike AIDR for inspection (11). Audit logs, access authorisation events and workload events with export by Log Streams (15). SOC 2 Type II and ISO/IEC 27001:2022 stated in the docs, with reports under NDA. No security.txt, bug bounty or public advisories found, and the trust centre returned 403 to our reader (12). Total 84."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 found in the docs, the OpenAPI files or the pricing page (0). Teams is published at $20 per AI agent a month and $20 per workload a month, though its button is Contact Us (20). Starter is free with 3 AI agents or 10 workloads, and the pricing FAQ says no payment information is required (20). A person signs up in a browser at useast2.aembit.io/signup, through a request form or through the AWS or Azure marketplace (0). Total 40."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 80,
          "points": 7,
          "reason": "MCP Identity Gateway 1.34.6034 on 7 October 2026 and Aembit CLI 1.34.6014 on 5 October (30). Gateway versions on 7 and 18 August, 15 September and 7 October 2026 (20). Closed service with a public changelog and RSS, a knowledge base and ticket support, with community support only on the free plan (11 of 15). @aembit/edge-sdk 1.34.1 on 7 September 2026 is current, and the Python SDK is unpublished (12). The SDK repository has CI, release and Renovate workflows. We couldn't see their run status (7). Total 80."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 60,
          "points": 5.25,
          "note": "editorial 42, provenance 78",
          "reason": "Closed service under terms of service last reviewed 14 July 2026, with the Edge SDKs under Apache-2.0 (15). The privacy policy of 5 May 2026 covers the platform, and a docs page lists the metadata collected (admin email, name and IP address, workload IP addresses and identifiers). Event log retention is 24 hours on Starter and 7 days on Teams for agents. No retention period was found in the privacy policy and no DPA was found (14). The changelog has a Deprecated filter and the docs flag deprecated settings, but no deprecation policy with a notice period was found (8). Status posts name us-east-2 and us-west-2. No sub-processor list was found, and the trust centre returned 403 to our reader (5). Total 42."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The Edge API is two calls that return one credential, and the Aembit MCP Server has three read-only tools (22). Cloud API lists take `page`, `per-page`, `order`, `filter` and `group-by`, and event queries take time spans and severity (20). Standard HTTP status codes with per-endpoint tables for the Edge API, and JSON-RPC errors from the gateway, but no catalogue of Cloud API error bodies (12). No idempotency keys found. Credential requests are repeatable and the MCP server is read-only, and the gateway passes tool annotations through (8). TypeScript SDK on npm, a CLI and a Terraform provider. The Python SDK is in the repository at 0.1.0 and was not on PyPI on 8 October 2026 (10). Total 72.",
          "maintenance": "MCP Identity Gateway 1.34.6034 on 7 October 2026 and Aembit CLI 1.34.6014 on 5 October (30). Gateway versions on 7 and 18 August, 15 September and 7 October 2026 (20). Closed service with a public changelog and RSS, a knowledge base and ticket support, with community support only on the free plan (11 of 15). @aembit/edge-sdk 1.34.1 on 7 September 2026 is current, and the Python SDK is unpublished (12). The SDK repository has CI, release and Renovate workflows. We couldn't see their run status (7). Total 80.",
          "payments": "No x402, MPP or L402 found in the docs, the OpenAPI files or the pricing page (0). Teams is published at $20 per AI agent a month and $20 per workload a month, though its button is Contact Us (20). Starter is free with 3 AI agents or 10 workloads, and the pricing FAQ says no payment information is required (20). A person signs up in a browser at useast2.aembit.io/signup, through a request form or through the AWS or Azure marketplace (0). Total 40.",
          "reliability": "Graded as a hosted service. Statuspage at status.aembit.io with two components, Management Portal (Admin and API) and Control Plane (20). One incident in the 90 days to 8 October 2026, the admin console unavailable for five minutes on 14 July during a service upgrade (30). No rate limit figures found. The Aembit MCP Server page says it has no application-level rate limiting and caps `perPage` at 100 (0). The Edge API and the MCP Authorisation Server list 429 responses, and the docs advise caching tokens until near expiry, but no Retry-After or back-off guidance for callers and no idempotency keys were found (5). No SLA is published, and the docs send SLA details to support (0). The Cloud API is v1 and the Edge API 1.0.0 with no beta label, though MCP Identity Gateway began as a limited beta on 28 January 2026 and the docs don't state its current status (10). Total 65.",
          "schema": "OpenAPI 3.1.1 files for the Cloud API (78 paths, 171 operations) and the Edge API (2 operations) download from docs.aembit.io without a login (25). llms.txt, per-page Markdown, split API reference files and a docs bundle on GitHub (10). The guides say when to pick the MCP Identity Gateway over the MCP Authorisation Server, and an SDK over Agent Proxy, and 170 of 171 Cloud operations carry a summary or description (16). 188 Cloud schemas, 44 with required fields, and enums on the Edge API credential type, but most Edge fields are nullable strings (9). curl examples and status code tables, with the MCP Authorisation Server's table described as not exhaustive and no Cloud API error catalogue (10). `/api/v1` in the path and a dated changelog with RSS (15). Total 85.",
          "security": "The API accepts only Bearer access tokens and the docs say long-lived credentials aren't supported. Aembit API tokens last 1 hour by default, workloads authenticate by attestation through Trust Providers, and MCP clients use OAuth 2.1 with PKCE and dynamic client registration or a Client ID Metadata Document (30). Roles set No Access, Read Only or Read/Write per resource type and can be limited to Resource Sets, an Auditor system role exists, and MCP Tool Access Control can hide or block tools, though it is off until support enables it. No confirmation step for destructive API calls was found (16). The gateway relays MCP server content, and a Content Security Provider can send tool traffic to CrowdStrike AIDR for inspection (11). Audit logs, access authorisation events and workload events with export by Log Streams (15). SOC 2 Type II and ISO/IEC 27001:2022 stated in the docs, with reports under NDA. No security.txt, bug bounty or public advisories found, and the trust centre returned 403 to our reader (12). Total 84.",
          "transparency": "Closed service under terms of service last reviewed 14 July 2026, with the Edge SDKs under Apache-2.0 (15). The privacy policy of 5 May 2026 covers the platform, and a docs page lists the metadata collected (admin email, name and IP address, workload IP addresses and identifiers). Event log retention is 24 hours on Starter and 7 days on Teams for agents. No retention period was found in the privacy policy and no DPA was found (14). The changelog has a Deprecated filter and the docs flag deprecated settings, but no deprecation policy with a notice period was found (8). Status posts name us-east-2 and us-west-2. No sub-processor list was found, and the trust centre returned 403 to our reader (5). Total 42."
        },
        "sources": [
          {
            "what": "docs index (llms.txt)",
            "url": "https://docs.aembit.io/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "full docs as Markdown",
            "url": "https://docs.aembit.io/llms-full.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://aembit.io/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "sign-up options and plans",
            "url": "https://docs.aembit.io/get-started/signup-options/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Cloud API overview",
            "url": "https://docs.aembit.io/dev-guide/api/cloud/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Cloud API OpenAPI file",
            "url": "https://docs.aembit.io/cloud.yaml",
            "seen": "2026-10-08"
          },
          {
            "what": "Edge API overview",
            "url": "https://docs.aembit.io/dev-guide/api/edge/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Edge API OpenAPI file",
            "url": "https://docs.aembit.io/edge.yaml",
            "seen": "2026-10-08"
          },
          {
            "what": "Edge API reference",
            "url": "https://docs.aembit.io/llms-api-edge-full.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP Identity Gateway use case",
            "url": "https://docs.aembit.io/get-started/use-cases/mcp-server-access/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP Identity Gateway set-up",
            "url": "https://docs.aembit.io/user-guide/access-policies/mcp-identity-gateway/setup-mcp-gateway/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Edge component versions",
            "url": "https://docs.aembit.io/reference/edge-components/edge-component-supported-versions/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://docs.aembit.io/changelog/",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents feed",
            "url": "https://status.aembit.io/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "security compliance",
            "url": "https://docs.aembit.io/get-started/security-posture/security-compliance/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "metadata collection",
            "url": "https://docs.aembit.io/get-started/security-posture/metadata-collection/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://aembit.io/terms-of-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://aembit.io/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry, @aembit/edge-sdk",
            "url": "https://registry.npmjs.org/@aembit/edge-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "Edge SDK repository (cloned)",
            "url": "https://github.com/Aembit/edge-sdks",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt (404)",
            "url": "https://aembit.io/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for aembit.io",
            "url": "https://rdap.identitydigital.services/rdap/domain/aembit.io",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the trust centre at trust.aembit.io returned 403 to our reader, so any sub-processor list, DPA or report index there is unread. Transparency and Security score those items as not found.",
          "unchecked: GitHub stars and CI run status for Aembit/edge-sdks. The GitHub API refused us for its rate limit.",
          "Whether MCP Identity Gateway is generally available. The version table calls 1.28.4136 (28 January 2026) an initial limited beta and no later statement was found.",
          "No rate limit figures, SLA, deprecation policy, DPA or security.txt were found in the reviewed pages.",
          "The Edge API OpenAPI file gives https://aembit.io/terms as its terms of service, which returned 404. The governing terms are at https://aembit.io/terms-of-service/.",
          "The docs say the Edge SDKs are available for TypeScript and Python, but pypi.org/project/aembit-edge-sdk returned 404 and the repository's pyproject.toml is at 0.1.0.",
          "Whether the Teams plan can be bought without talking to sales. Its button on the pricing page is Contact Us."
        ]
      },
      "negative": 0,
      "verdict": "Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.",
      "bestFor": "A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.",
      "strengths": [
        "Public OpenAPI 3.1.1 files for the Cloud API (171 operations) and Edge API (2), plus llms.txt, per-page Markdown and a cloneable docs bundle",
        "No long-lived API credentials. Aembit API tokens last 1 hour by default and Edge API access tokens expire in 1 hour",
        "MCP clients authenticate by OAuth 2.1 with PKCE, dynamic client registration or a Client ID Metadata Document",
        "Audit logs, access authorisation events and workload events, exported by Log Streams to S3, Google Cloud Storage, Splunk or CrowdStrike",
        "Dated changelog with RSS. MCP Identity Gateway shipped four versions between 7 August and 7 October 2026"
      ],
      "weaknesses": [
        "No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance",
        "No SLA is published. The docs send SLA questions to Aembit support",
        "The managed MCP Identity Gateway endpoint is requested through an Aembit representative, and MCP Tool Access Control is enabled by support",
        "The Python Edge SDK is in the repository at 0.1.0 but pypi.org/project/aembit-edge-sdk returned 404 on 8 October 2026",
        "No DPA, sub-processor list or security.txt found on aembit.io. The trust centre returned 403 to our reader"
      ],
      "agentNotes": [
        "Read the API Base URL and token from the tenant's Profile page. Tokens last 1 hour by default, so plan to refresh",
        "Send `X-Aembit-ResourceSet` on Cloud API, Edge API and MCP calls outside the default Resource Set, or the request runs against the default set",
        "Cache the Edge API access token from `/edge/v1/auth` until near expiry before calling `/edge/v1/credentials`. Both endpoints can answer 429",
        "Point MCP clients at `https://\u003cgateway-host\u003e/mcp`. The `/me` path is deprecated",
        "Expect tool names prefixed with the Server Workload name behind the MCP Identity Gateway, and keep `perPage` at 100 or less on the Aembit MCP Server"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 70.5
        }
      ],
      "editorialScores": {
        "ergonomics": 72,
        "maintenance": 80,
        "payments": 40,
        "reliability": 65,
        "schema": 85,
        "security": 84,
        "transparency": 42
      },
      "provenanceScore": 78
    },
    "connect": {
      "install": "npm install @aembit/edge-sdk",
      "http": "curl -X GET -L 'https://tenant.aembit.io/api/v1/server-workloads' -H 'Authorization: Bearer \u003cTOKEN\u003e'"
    },
    "letme": {
      "capability": "https://letme.dev/auth.oauth",
      "tool": "https://letme.dev/aembit"
    },
    "notable": [
      "MCP Identity Gateway is a managed proxy at https://\u003ctenantId\u003e.mcpgateway.aembit.io that checks a Client-to-Gateway and a Gateway-to-Server Access Policy and injects per-user credentials, so the agent holds none. A self-hosted Linux build also exists (https://docs.aembit.io/get-started/use-cases/mcp-server-access/index.md)",
      "The docs say to contact an Aembit representative to request the managed gateway endpoint, and that MCP Tool Access Control isn't enabled by default (https://docs.aembit.io/llms-full.txt)",
      "The Aembit MCP Server at https://\u003ctenantId\u003e.mcp.useast2.aembit.io/mcp is read-only with three tools, get_audit_logs, get_auth_events and get_workload_events, and an administrator has to enable it for the tenant (https://docs.aembit.io/llms-full.txt)",
      "The Edge API is two calls, POST /edge/v1/auth with platform attestation (AWS, Azure, Google Cloud, Kubernetes, GitHub Actions, GitLab, Terraform Cloud or any OIDC token) and POST /edge/v1/credentials. Access tokens expire in 1 hour by default (https://docs.aembit.io/dev-guide/api/edge/index.md)",
      "The Cloud API takes only Bearer access tokens. The docs say it doesn't support long-lived credentials, and the default API token lifetime is 1 hour (https://docs.aembit.io/dev-guide/api/cloud/index.md)",
      "MCP Identity Gateway 1.34.6034 of 7 October 2026 serves the 2026-07-28 MCP specification and earlier revisions, and validates ES256 and RS256 access tokens (https://docs.aembit.io/changelog/)",
      "status.aembit.io lists one incident in the 90 days to 8 October 2026, a five-minute admin console outage on 14 July. A 61-minute us-west-2 disruption on 10 February 2026 has a published post-mortem (https://status.aembit.io/history)",
      "The terms of service bar use of the Services for any benchmarking activity or in connection with the development of any competitive product (https://aembit.io/terms-of-service/)",
      "SOC 2 Type II and ISO/IEC 27001:2022 are stated in the docs, with detailed reports under NDA from the trust centre (https://docs.aembit.io/get-started/security-posture/security-compliance/index.md)"
    ],
    "area": "agent-runtime",
    "details": [
      {
        "label": "Interfaces",
        "value": "Cloud API (management, 171 operations), Edge API (2 operations), Aembit CLI, Edge SDK, MCP Identity Gateway, MCP Authorisation Server, Aembit MCP Server (3 read-only tools), Terraform provider"
      },
      {
        "label": "MCP Identity Gateway",
        "value": "Managed at https://\u003ctenantId\u003e.mcpgateway.aembit.io with MCP at /mcp, or self-hosted on Linux. Version 1.34.6034 (7 October 2026). Proxies tools, resources and prompts"
      },
      {
        "label": "MCP client sign-in",
        "value": "OAuth 2.1 with PKCE, dynamic client registration or a Client ID Metadata Document. Users sign in through an OIDC or SAML identity provider"
      },
      {
        "label": "Workload attestation",
        "value": "AWS, Azure, Google Cloud, Kubernetes, GitHub Actions, GitLab, Terraform Cloud or any OIDC ID token"
      },
      {
        "label": "Credential types",
        "value": "API key, username and password, OAuth token, Google Workload Identity Federation, AWS STS federation, per the Edge API"
      },
      {
        "label": "Token lifetime",
        "value": "Aembit API token 1 hour by default. Edge API access token 1 hour by default. Aembit Access Token Credential Provider minimum 300 seconds"
      },
      {
        "label": "Roles",
        "value": "No Access, Read Only or Read/Write per resource type, limited to Resource Sets. SuperAdmin and Auditor system roles"
      },
      {
        "label": "Audit",
        "value": "Audit logs, access authorisation events and workload events. Log Streams to AWS S3, Google Cloud Storage, Splunk and CrowdStrike"
      },
      {
        "label": "Event log retention",
        "value": "24 hours on Starter, 7 days on Teams for agents, custom on Enterprise"
      },
      {
        "label": "Free plan",
        "value": "Starter with 3 AI agents, one MCP Identity Gateway and 5 MCP authorisation policies, or 10 workloads and 10 Access Policies"
      },
      {
        "label": "Sign-up",
        "value": "https://useast2.aembit.io/signup, a request form at aembit.io/request-a-free-tenant, or AWS Marketplace and Azure Marketplace"
      },
      {
        "label": "SDKs",
        "value": "@aembit/edge-sdk 1.34.1 on npm (7 September 2026), Apache-2.0. Python in the repository at 0.1.0, not on PyPI on 8 October 2026. Go listed as planned"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II and ISO/IEC 27001:2022, per the docs"
      },
      {
        "label": "Status",
        "value": "status.aembit.io on Statuspage, components Management Portal (Admin and API) and Control Plane"
      }
    ],
    "unitPrices": [
      {
        "item": "Teams, each AI agent",
        "unit": "month",
        "usd": 20,
        "note": "Priced per agent a month, up to 500 agents"
      },
      {
        "item": "Teams, each workload",
        "unit": "month",
        "usd": 20,
        "note": "Priced per workload a month"
      }
    ],
    "provenance": {
      "legalEntity": "Aembit, Inc.",
      "domain": "aembit.io",
      "domainRegistered": "2021-03-14",
      "endpointOnVendorDomain": true,
      "terms": "https://aembit.io/terms-of-service/",
      "privacy": "https://aembit.io/privacy-policy/",
      "statusPage": "https://status.aembit.io",
      "changelog": "https://docs.aembit.io/changelog/",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The terms of service (last reviewed 14 July 2026) are between the customer and Aembit, Inc., define the Services as the website and the web-based and downloadable workload identity and access management services, and choose Delaware law.",
        "The privacy policy (last updated 5 May 2026) names Aembit, Inc. and covers the platform, websites and related services.",
        "aembit.io/.well-known/security.txt and docs.aembit.io/.well-known/security.txt both returned 404. The docs give security@aembit.io as the security contact.",
        "RDAP at Identity Digital gives a registration date of 2021-03-14 for aembit.io.",
        "Tenant APIs answer at https://\u003ctenant\u003e.aembit.io and the managed gateway at https://\u003ctenantId\u003e.mcpgateway.aembit.io, both on the vendor's domain.",
        "No DPA, sub-processor or SLA page was found at the obvious aembit.io paths, and trust.aembit.io returned 403 to our reader."
      ],
      "score": 78,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Aembit, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "aembit.io, registered 2021-03-14 (5 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "aembit.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 4.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 5 of the 8 things a reader expects",
          "points": 7.8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.aembit.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://aembit.io/terms-of-service/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-07-14",
          "words": 3604,
          "points": 4.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Reviewed on July 14, 2026",
              "says": "Last updated 2026-07-14"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement will be interpreted, construed, and enforced in all respects in accordance with the local laws of the State of Delaware, U.S.A., without reference to its choice of law rules and not including the provisions of the 1980 U.N.",
              "says": "The law of the State of Delaware"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…AEMBIT’S TOTAL LIABILITY OF ALL KINDS ARISING OUT OF OR RELATED TO THIS AGREEMENT (INCLUDING BUT NOT LIMITED TO WARRANTY CLAIMS), REGARDLESS OF THE FORUM AND REGARDLESS OF WHETHER ANY ACTION OR CLAIM IS BASED ON CONTRACT, TORT, OR OTHERWISE, EXCEED THE TOTAL AMOUNT PAID BY CUSTOMER TO AEMBIT DURING THE 12 MONTHS IMMED…",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If there is unauthorized use by anyone who obtained access to the Services directly or indirectly through Customer, Customer will take all steps reasonably necessary to terminate the unauthorized use."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Except as otherwise explicitly provided in this Agreement or as may be expressly permitted by applicable law, Customer will not, and will not permit or authorize third parties to: (a) rent, lease, or otherwise permit third parties to use the Services or Documentation;"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "(d) use the Services for any benchmarking activity or in connection with the development of any competitive product; nor (e) circumvent or disable any security or other technological features or measures of the Services.",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "Aembit reserves the right to modify or discontinue all or any portion of the Services at any time (including by limiting or discontinuing certain features of the Services), temporarily or permanently, without notice.",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Aembit accepts no liability for changes to the service, including to paid functions, or for suspending or ending a customer's access.",
              "quote": "Aembit will have no liability for any change to the Services, including any paid-for functionalities of the Services, or any suspension or termination of Customer’s access to or use of the Services."
            },
            {
              "date": "2026-10-08",
              "text": "After termination the customer must give Aembit a signed written certification that all use of the service has stopped.",
              "quote": "Customer will provide Aembit with a written certification signed by an authorized Customer representative certifying that all use of the Services and Documentation by Customer has been discontinued."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://aembit.io/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-05-05",
          "words": 2101,
          "points": 7.8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated on May 5, 2026",
              "says": "Last updated 2026-05-05"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This privacy policy (the “Privacy Policy”) explains how we collect, use, and share information from users of our Services (“Users”)."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We do not share this information with third parties except as necessary to provide the services."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": false
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have any questions, comments, or concerns about our processing activities, please email us at privacy@aembit.io",
              "says": "privacy@aembit.io"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "law, then please note that you are transferring your personal information outside of those regions to the United States for storage and processing.",
              "says": "Data goes to the United States"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Aembit receives logs of application communication requests, IP addresses and HTTP headers from end users of its platform and uses them to operate the service and improve its product.",
              "quote": "We receive logs of application communication requests and networking information like IP address and HTTP headers from end users of our platform."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/aembit.json",
    "live": {
      "slug": "aembit",
      "vendorStatus": {
        "page": "https://status.aembit.io",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:06:25.306023091Z"
      },
      "pages": [
        {
          "url": "https://docs.aembit.io/changelog/",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:18:07.775115006Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "4e930f2cc1ec"
        },
        {
          "url": "https://aembit.io/pricing/",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:14:59.808222145Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "781c90a65067"
        },
        {
          "url": "https://aembit.io/privacy-policy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:15:01.881687653Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "753e7b8821e4"
        },
        {
          "url": "https://aembit.io/terms-of-service/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:15:03.860763085Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "ad42c0fa0432"
        }
      ],
      "updatedAt": "2026-10-08T19:06:25.306023091Z"
    }
  }
}
