Best of · Agent runtime
Best auth and delegated access for AI agents
The 10 highest-scoring of 17 auth and delegated access on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.
- 17 ranked
- 7 agent-ready
- 16 hosted endpoints
- Updated 8 October 2026
Top three
Picks by need
Worked out from the scores, prices and facts, so they change when the research does.
Highest score overall
Descope Agentic Identity Hub A
A, 78.1/100 on the benchmark.
Also Composio (API + MCP), BB, 75.1/100.
Schema & documentation
89/100 on schema & documentation, against 78 for the overall leader.
Agent ergonomics
90/100 on agent ergonomics, against 80 for the overall leader.
Security & auth
Auth0 for AI Agents (Token Vault) BB
88/100 on security & auth, against 86 for the overall leader.
Maintenance & community
93/100 on maintenance & community, against 74 for the overall leader.
Transparency & trust
Auth0 for AI Agents (Token Vault) BB
84/100 on transparency & trust, against 67 for the overall leader.
Lowest paid price per call
$0.0003 per call, the lowest of the 5 listings here with a paid price in this unit (free allowances aside).
Also Scalekit AgentKit, $0.0005 per call.
Self-hosting under an open licence
self-hosted, MIT licence.
Also Aembit, self-hosted, Proprietary service under Aembit's terms of service licence.
The shortlist
| # | Tool | Grade | Best for | Price | Where |
|---|---|---|---|---|---|
| 1 | Descope Agentic Identity Hub Descope |
A 78.1 | A team that wants one vendor for both directions, holding users' third-party tokens and acting as the authorisation server for its own MCP server, with policy per agent. | $249 / mo | hosted |
| 2 | Composio (API + MCP) Composio |
BB 75.1 | A developer whose agent acts in many apps for many end users and wants auth, tool schemas and execution handled. | $29 / mo | hosted |
| 3 | Amazon Bedrock AgentCore Identity Amazon Web Services |
BB 74.8 | Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge. | $0.01 / 1k req | hosted |
| 4 | Microsoft Entra Agent ID Microsoft |
BB 74.4 | Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs. | $15 / seat-mo | hosted |
| 5 | Scalekit AgentKit Scalekit |
BB 71.9 | A team that wants per-user third-party tokens plus a hosted tool catalogue at the lowest per-call price, with a tidy virtual MCP surface for agents. | $99 / mo | hosted |
| 6 | Auth0 for AI Agents (Token Vault) Auth0 by Okta |
BB 71.4 | Best when Auth0 already runs login and the agent needs a handful of the user's Google, Microsoft, Slack or GitHub tokens, or a second-device approval before a payment or delete. | Freemium | hosted and local |
| 7 | Aembit Aembit, Inc. |
BB 70.5 | A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent. | $20 / mo | local |
| 8 | Vercel Connect Vercel Inc. |
B 68.8 | Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets. | $3 / 1k req | hosted |
| 9 | Nango Nango |
B 67.7 | A product that connects many users to many SaaS APIs and wants tokens, refresh, syncs and a per-tenant MCP surface in one place, with source you can read. | $50 / mo | hosted |
| 10 | Arcade.dev Arcade.dev |
B 66.9 | A product whose agent acts in many users' SaaS accounts and wants the tools written and run for it, not only the tokens. | $25 / mo | hosted and local |
7 more are ranked in the full table.
How to choose
- Third-party apps coveredCheck which third-party apps are covered and whether each one's OAuth scopes can be requested separately, since an app you need may only be reachable with broad access.
- Consent screen and refused scopesCheck what the consent screen shows the user and how the agent learns that a scope was refused, since silent partial access is hard to debug.
- Where tokens are storedCheck where access and refresh tokens live, whether the agent holds the raw token, and whether revocation clears every copy, since a stray copy keeps working.
- Revocation and audit trailCheck how fast a revoked grant stops the agent's calls and what the audit log records for each call, because revocation that takes effect late is a security gap.
How the benchmark tests this category. An agent connects to two third-party apps for a test user, makes calls, has one scope refused and then the grant revoked. We check the consent flow, where tokens live, what the audit log shows and how revocation reaches the agent.
Each one in detail
Descope Agentic Identity Hub
A 78.1/100Descope's identity and access tools for AI agents, built on its customer identity platform.
Verdict Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.
Choose it for A team that wants one vendor for both directions, holding users' third-party tokens and acting as the authorisation server for its own MCP server, with policy per agent.
Strengths
- Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion
- Descope as the OAuth authorisation server for your APIs and MCP servers, with DCR, CIBA and token exchange
- Policies decide which tokens an agent identity can obtain, evaluated at issuance and exchange
Weaknesses
- No tool catalogue, so you write every provider call yourself
- The Agent Auth SDK is 0.1.0 and unpublished on npm or PyPI, with 18 open pull requests and no commit since 2 July 2026
- The docs don't say how vaulted tokens are encrypted
Price $249 / moAuth OAuth or keyx402 nohosted
Composio (API + MCP)
BB 75.1/100Tool access and per-user authentication for agents across 1,000+ apps.
Verdict Connect supports toolkit selection and filtering by read-only or destructive actions. Rube closed on 16 May 2026, so existing rube.app configurations need migration.
Choose it for A developer whose agent acts in many apps for many end users and wants auth, tool schemas and execution handled.
Strengths
- Seven Connect meta-tools, and sessions that load chosen toolkits or filter by read-only and destructive tags
- Per-call prices in public and 100,000 free tool calls a month with no card
- OpenAPI 3.0 with 62 paths, llms.txt and an error reference
Weaknesses
- Rube shut down on 16 May 2026, so old rube.app configs are dead
- Tool arguments and responses are logged for up to a year unless ZDR, a paid add-on, is on
- The sandbox with remote Python and bash is on by default in sessions
Price $29 / moAuth OAuth or keyx402 nohosted
Amazon Bedrock AgentCore Identity
BB 74.8/100Amazon Bedrock AgentCore Identity is an AWS service that gives agents workload identities, stores OAuth tokens and API keys in a token vault, and runs OAuth flows so agents can call third-party services for users or for themselves.
Verdict The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.
Choose it for Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.
Strengths
GetResourceOauth2Tokencovers three flows (USER_FEDERATION, M2M and ON_BEHALF_OF_TOKEN_EXCHANGE) and returns either an access token or an authorisation URL with a session URI.- 25 OAuth vendor values in
CreateOauth2CredentialProvider, 24 built in (Google, GitHub, Slack, Salesforce, Microsoft, Atlassian and others) plus a custom OAuth 2.0 provider. - Quotas are published per operation, 200 requests a second for the three workload access token calls and 20 for each management call, all adjustable.
Weaknesses
- No operation to revoke or delete one user's stored grant was found.
forceAuthenticationclears a refresh token, and AWS says it cannot detect a revocation made at the provider. - The consent portal, launched 1 September 2026, attaches to one AgentCore Gateway with JWT inbound auth and cannot use GitHub, Slack, Salesforce, Atlassian or LinkedIn as its sign-in provider.
GetWorkloadAccessTokenForUserIdtakes a user ID string the platform does not verify, so the binding to a user rests on the caller and its IAM policy.
Price $0.01 / 1k reqAuth OAuth or keyx402 nohosted
Microsoft Entra Agent ID
BB 74.4/100Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph.
Verdict Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.
Choose it for Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.
Strengths
- Agent identities can't hold credentials. The blueprint authenticates with a managed identity, certificate or secret and exchanges for the agent's token
- Global Administrator and similar roles, and Graph permissions such as Application.ReadWrite.All, are refused for agent identities
- Create, list, update, delete and restore are on Microsoft Graph v1.0, with agentIdentity in the public OpenAPI file
Weaknesses
- Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing
- Microsoft's docs call hand-written token exchange complex and error-prone and steer developers to a .NET library or a sidecar container
- Creating a blueprint, a principal and an identity in quick succession can fail with 400 until the directory replicates
Price $15 / seat-moAuth OAuthx402 nohosted
Scalekit AgentKit
BB 71.9/100Authentication and integration platform for agents, with per-user account connections, scoped MCP servers and managed tool calls.
Verdict 500+ connectors, including remote MCP servers over OAuth 2.1 with DCR. No rate limits or idempotency documented for Scalekit's own API.
Choose it for A team that wants per-user third-party tokens plus a hosted tool catalogue at the lowest per-call price, with a tidy virtual MCP surface for agents.
Strengths
- 500+ connectors, including remote MCP servers over OAuth 2.1 with DCR
- OpenAPI files, llms.txt and a Markdown twin for every docs page
- Tool search, scoped tool lists and virtual MCP servers keep an agent's context small
Weaknesses
- No rate limits or idempotency documented for Scalekit's own API
- Any holder of the API credential can read a user's full OAuth tokens
- No approval step for destructive tools and no prompt-injection guidance
Price $99 / moAuth OAuth or keyx402 nohosted
Auth0 for AI Agents (Token Vault)
BB 71.4/100Auth0's identity and authorisation tools for AI agents, built on its identity platform.
Verdict Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users.
Choose it for Best when Auth0 already runs login and the agent needs a handful of the user's Google, Microsoft, Slack or GitHub tokens, or a second-device approval before a payment or delete.
Strengths
- Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP
- Human approval on a second device for sensitive actions, showing the exact payee or amount
- Free plan up to 25,000 monthly active users with no card
Weaknesses
- Only works when Auth0 is the identity provider for your users
- Two Token Vault connections on Free and three on Essentials and Professional without the add-on
- Log retention of 1 day on Free and 5 days on Essentials is short for an audit trail
Price FreemiumAuth OAuthx402 nohosted and local
Aembit
BB 70.5/100Aembit is a hosted identity and access platform for workloads and AI agents. Its MCP Identity Gateway and MCP Authorisation Server apply access policies and inject credentials, with a Cloud API, an Edge API, a CLI and an Edge SDK.
Verdict Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.
Choose it for A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.
Strengths
- Public OpenAPI 3.1.1 files for the Cloud API (171 operations) and Edge API (2), plus llms.txt, per-page Markdown and a cloneable docs bundle
- No long-lived API credentials. Aembit API tokens last 1 hour by default and Edge API access tokens expire in 1 hour
- MCP clients authenticate by OAuth 2.1 with PKCE, dynamic client registration or a Client ID Metadata Document
Weaknesses
- No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance
- No SLA is published. The docs send SLA questions to Aembit support
- The managed MCP Identity Gateway endpoint is requested through an Aembit representative, and MCP Tool Access Control is enabled by support
Price $20 / moAuth OAuth or keyx402 nolocal
Vercel Connect
B 68.8/100Vercel Connect is a credential broker for apps and agents. Code asks it for a short-lived, scoped token for Slack, GitHub, Microsoft, Linear, Snowflake or any OAuth, API-key or MCP service, as the app or for a user.
Verdict Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript.
Choose it for Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets.
Strengths
- Refresh tokens stay on Vercel's infrastructure. Code receives only short-lived access tokens, as the app or for a named user
- A deployment authenticates with its project OIDC token, checked against per-environment project links, so no provider secret sits in environment variables
- Public OpenAPI 3.0.3 document covers 13 Connect paths, including
/v1/connect/token/{connector}and/v1/connect/authorize/{connector}
Weaknesses
- Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment
- Elevated Connect errors for 94 minutes on 10 September 2026, marked major, and again on 18 September, per the status page
- Event history is kept 12 hours on Hobby and 3 days on Pro. Connector audit logs and 30 days need Enterprise
Price $3 / 1k reqAuth OAuth or keyx402 nohosted
Nango
B 67.7/100Source-available integration platform that handles OAuth, API keys and token refresh for 1,000+ APIs on behalf of your users.
Verdict 1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.
Choose it for A product that connects many users to many SaaS APIs and wants tokens, refresh, syncs and a per-tenant MCP surface in one place, with source you can read.
Strengths
- 1,000+ APIs with OAuth, API key and client-credentials auth handled
- Per-tenant agent sessions served as an MCP server, credentials never shown to the agent
- Encryption, retention and deletion rules published in the docs
Weaknesses
- Audit trail only on Enterprise, and logs kept 15 days on every plan
- Two CVEs fixed in September 2026, one critical, neither on Nango's own advisory page
- Status page tracks a single component
Price $50 / moAuth OAuth or keyx402 nohosted
Arcade.dev
B 66.9/100MCP runtime built around per-user authorisation.
Verdict Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.
Choose it for A product whose agent acts in many users' SaaS accounts and wants the tools written and run for it, not only the tokens.
Strengths
- Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token
- 33 built-in auth providers plus generic OAuth 2.0, and hosted MCP gateways that sign users in through your own OIDC provider
- OpenAPI 3.0 file with 39 paths, llms.txt and a typed tool error hierarchy with retry hints
Weaknesses
- The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise
- Tool inputs and results are training data for up to 5 years unless the organisation opts out
- No published rate limits for the authorise or execute calls, and no 429 in the OpenAPI file
Price $25 / moAuth OAuth or keyx402 nohosted and local
Head to head
- Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub BB 74.8 vs A 78.1
- Descope Agentic Identity Hub vs Microsoft Entra Agent ID A 78.1 vs BB 74.4
- Descope Agentic Identity Hub vs Scalekit AgentKit A 78.1 vs BB 71.9
- Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID BB 74.8 vs BB 74.4
- Amazon Bedrock AgentCore Identity vs Scalekit AgentKit BB 74.8 vs BB 71.9
- Microsoft Entra Agent ID vs Scalekit AgentKit BB 74.4 vs BB 71.9
Questions
What are the highest-rated auth and delegated access for AI agents?
Descope Agentic Identity Hub has the highest benchmark score of the 17 ranked auth and delegated access, 78.1 (A). Composio (API + MCP) is second with 75.1 (BB).
How many auth and delegated access are agent-ready?
7 of the 17 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.
Which auth and delegated access accept x402 payments?
None of the ranked listings here accepts x402 for its main call yet.
Which of these auth and delegated access is cheapest?
By published paid prices, Composio (API + MCP), at $0.0003 per call, the lowest of the 5 listings here with a paid price in this unit (free allowances aside). Plans, volume tiers and free allowances change the sum, so check the listing's price table.
How is this list ranked?
By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 8 October 2026.
How this list is made
The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.
Full ranked table · 111 head-to-head comparisons · Best tools in every category