# Best auth and delegated access for AI agents > Descope Agentic Identity Hub (A), Composio (API + MCP) (BB) and Amazon Bedrock AgentCore Identity (BB) lead the 17 ranked auth and delegated access. Picks by need, strengths, weaknesses and prices from the Anchor benchmark. - Canonical: https://www.anchorterminal.com/best/agent-auth/ - Markdown: https://www.anchorterminal.com/best/agent-auth/index.md (~6,200 tokens) - Slim: https://www.anchorterminal.com/best/agent-auth/index.min.md (~1,730 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/best/agent-auth/index.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 The 10 highest-scoring of 17 auth and delegated access on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change. - Ranked: 17 · agent-ready (BB or better): 7 · accept x402: 0 · hosted endpoints: 16 - Full ranked table: https://www.anchorterminal.com/categories/agent-auth.md - Head-to-head comparisons: https://www.anchorterminal.com/compare/agent-auth/index.md (111) - Methodology: https://www.anchorterminal.com/benchmark/index.md ## The shortlist | # | Tool | Grade | Score | Best for | Price | Where | | --- | --- | --- | --- | --- | --- | --- | | 1 | [Descope Agentic Identity Hub](https://www.anchorterminal.com/tools/descope-agentic-identity.md) | A | 78.1 | A team that wants one vendor for both directions, holding users' third-party tokens and acting as the authorisation server for its own MCP server, with policy per agent. | $249 / mo | hosted | | 2 | [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md) | BB | 75.1 | A developer whose agent acts in many apps for many end users and wants auth, tool schemas and execution handled. | $29 / mo | hosted | | 3 | [Amazon Bedrock AgentCore Identity](https://www.anchorterminal.com/tools/agentcore-identity.md) | BB | 74.8 | Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge. | $0.01 / 1k req | hosted | | 4 | [Microsoft Entra Agent ID](https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md) | BB | 74.4 | Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs. | $15 / seat-mo | hosted | | 5 | [Scalekit AgentKit](https://www.anchorterminal.com/tools/scalekit-agentkit.md) | BB | 71.9 | A team that wants per-user third-party tokens plus a hosted tool catalogue at the lowest per-call price, with a tidy virtual MCP surface for agents. | $99 / mo | hosted | | 6 | [Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/tools/auth0-ai-agents.md) | BB | 71.4 | Best when Auth0 already runs login and the agent needs a handful of the user's Google, Microsoft, Slack or GitHub tokens, or a second-device approval before a payment or delete. | Freemium | hosted and local | | 7 | [Aembit](https://www.anchorterminal.com/tools/aembit.md) | BB | 70.5 | A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent. | $20 / mo | local | | 8 | [Vercel Connect](https://www.anchorterminal.com/tools/vercel-connect.md) | B | 68.8 | Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets. | $3 / 1k req | hosted | | 9 | [Nango](https://www.anchorterminal.com/tools/nango.md) | B | 67.7 | A product that connects many users to many SaaS APIs and wants tokens, refresh, syncs and a per-tenant MCP surface in one place, with source you can read. | $50 / mo | hosted | | 10 | [Arcade.dev](https://www.anchorterminal.com/tools/arcade.md) | B | 66.9 | A product whose agent acts in many users' SaaS accounts and wants the tools written and run for it, not only the tokens. | $25 / mo | hosted and local | ## Picks by need - Highest score overall: [Descope Agentic Identity Hub](https://www.anchorterminal.com/tools/descope-agentic-identity.md), A, 78.1/100 on the benchmark. Also [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), BB, 75.1/100. - Schema & documentation: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), 89/100 on schema & documentation, against 78 for the overall leader. - Agent ergonomics: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), 90/100 on agent ergonomics, against 80 for the overall leader. - Security & auth: [Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/tools/auth0-ai-agents.md), 88/100 on security & auth, against 86 for the overall leader. - Maintenance & community: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), 93/100 on maintenance & community, against 74 for the overall leader. - Transparency & trust: [Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/tools/auth0-ai-agents.md), 84/100 on transparency & trust, against 67 for the overall leader. - Lowest paid price per call: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), $0.0003 per call, the lowest of the 5 listings here with a paid price in this unit (free allowances aside). Also [Scalekit AgentKit](https://www.anchorterminal.com/tools/scalekit-agentkit.md), $0.0005 per call. - A hosted MCP endpoint: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), remote MCP server, nothing to install. - Self-hosting under an open licence: [Scalekit AgentKit](https://www.anchorterminal.com/tools/scalekit-agentkit.md), self-hosted, MIT licence. Also [Aembit](https://www.anchorterminal.com/tools/aembit.md), self-hosted, Proprietary service under Aembit's terms of service licence. - The review panel's favourite: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), 3.5/5 from 8 panel reviews. ## How to choose - Third-party apps covered: Check which third-party apps are covered and whether each one's OAuth scopes can be requested separately, since an app you need may only be reachable with broad access. - Consent screen and refused scopes: Check what the consent screen shows the user and how the agent learns that a scope was refused, since silent partial access is hard to debug. - Where tokens are stored: Check where access and refresh tokens live, whether the agent holds the raw token, and whether revocation clears every copy, since a stray copy keeps working. - Revocation and audit trail: Check how fast a revoked grant stops the agent's calls and what the audit log records for each call, because revocation that takes effect late is a security gap. - How the benchmark tests this category: An agent connects to two third-party apps for a test user, makes calls, has one scope refused and then the grant revoked. We check the consent flow, where tokens live, what the audit log shows and how revocation reaches the agent. ## Each one in detail ### 1. Descope Agentic Identity Hub, A 78.1/100 Descope's identity and access tools for AI agents, built on its customer identity platform. - Verdict: Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself. - Choose it for: A team that wants one vendor for both directions, holding users' third-party tokens and acting as the authorisation server for its own MCP server, with policy per agent. - Strength: Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion - Strength: Descope as the OAuth authorisation server for your APIs and MCP servers, with DCR, CIBA and token exchange - Strength: Policies decide which tokens an agent identity can obtain, evaluated at issuance and exchange - Weakness: No tool catalogue, so you write every provider call yourself - Weakness: The Agent Auth SDK is 0.1.0 and unpublished on npm or PyPI, with 18 open pull requests and no commit since 2 July 2026 - Weakness: The docs don't say how vaulted tokens are encrypted - Price: $249 / mo · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/descope-agentic-identity.md ### 2. Composio (API + MCP), BB 75.1/100 Tool access and per-user authentication for agents across 1,000+ apps. - Verdict: Connect supports toolkit selection and filtering by read-only or destructive actions. Rube closed on 16 May 2026, so existing rube.app configurations need migration. - Choose it for: A developer whose agent acts in many apps for many end users and wants auth, tool schemas and execution handled. - Strength: Seven Connect meta-tools, and sessions that load chosen toolkits or filter by read-only and destructive tags - Strength: Per-call prices in public and 100,000 free tool calls a month with no card - Strength: OpenAPI 3.0 with 62 paths, llms.txt and an error reference - Weakness: Rube shut down on 16 May 2026, so old rube.app configs are dead - Weakness: Tool arguments and responses are logged for up to a year unless ZDR, a paid add-on, is on - Weakness: The sandbox with remote Python and bash is on by default in sessions - Price: $29 / mo · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/composio-rube.md ### 3. Amazon Bedrock AgentCore Identity, BB 74.8/100 Amazon Bedrock AgentCore Identity is an AWS service that gives agents workload identities, stores OAuth tokens and API keys in a token vault, and runs OAuth flows so agents can call third-party services for users or for themselves. - Verdict: The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference. - Choose it for: Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge. - Strength: `GetResourceOauth2Token` covers three flows (USER_FEDERATION, M2M and ON_BEHALF_OF_TOKEN_EXCHANGE) and returns either an access token or an authorisation URL with a session URI. - Strength: 25 OAuth vendor values in `CreateOauth2CredentialProvider`, 24 built in (Google, GitHub, Slack, Salesforce, Microsoft, Atlassian and others) plus a custom OAuth 2.0 provider. - Strength: Quotas are published per operation, 200 requests a second for the three workload access token calls and 20 for each management call, all adjustable. - Weakness: No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider. - Weakness: The consent portal, launched 1 September 2026, attaches to one AgentCore Gateway with JWT inbound auth and cannot use GitHub, Slack, Salesforce, Atlassian or LinkedIn as its sign-in provider. - Weakness: `GetWorkloadAccessTokenForUserId` takes a user ID string the platform does not verify, so the binding to a user rests on the caller and its IAM policy. - Price: $0.01 / 1k req · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/agentcore-identity.md - Against #1: https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.md ### 4. Microsoft Entra Agent ID, BB 74.4/100 Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph. - Verdict: Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence. - Choose it for: Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs. - Strength: Agent identities can't hold credentials. The blueprint authenticates with a managed identity, certificate or secret and exchanges for the agent's token - Strength: Global Administrator and similar roles, and Graph permissions such as Application.ReadWrite.All, are refused for agent identities - Strength: Create, list, update, delete and restore are on Microsoft Graph v1.0, with agentIdentity in the public OpenAPI file - Weakness: Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing - Weakness: Microsoft's docs call hand-written token exchange complex and error-prone and steer developers to a .NET library or a sidecar container - Weakness: Creating a blueprint, a principal and an identity in quick succession can fail with 400 until the directory replicates - Price: $15 / seat-mo · Auth: OAuth · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md - Against #1: https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md ### 5. Scalekit AgentKit, BB 71.9/100 Authentication and integration platform for agents, with per-user account connections, scoped MCP servers and managed tool calls. - Verdict: 500+ connectors, including remote MCP servers over OAuth 2.1 with DCR. No rate limits or idempotency documented for Scalekit's own API. - Choose it for: A team that wants per-user third-party tokens plus a hosted tool catalogue at the lowest per-call price, with a tidy virtual MCP surface for agents. - Strength: 500+ connectors, including remote MCP servers over OAuth 2.1 with DCR - Strength: OpenAPI files, llms.txt and a Markdown twin for every docs page - Strength: Tool search, scoped tool lists and virtual MCP servers keep an agent's context small - Weakness: No rate limits or idempotency documented for Scalekit's own API - Weakness: Any holder of the API credential can read a user's full OAuth tokens - Weakness: No approval step for destructive tools and no prompt-injection guidance - Price: $99 / mo · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/scalekit-agentkit.md - Against #1: https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit.md ### 6. Auth0 for AI Agents (Token Vault), BB 71.4/100 Auth0's identity and authorisation tools for AI agents, built on its identity platform. - Verdict: Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users. - Choose it for: Best when Auth0 already runs login and the agent needs a handful of the user's Google, Microsoft, Slack or GitHub tokens, or a second-device approval before a payment or delete. - Strength: Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP - Strength: Human approval on a second device for sensitive actions, showing the exact payee or amount - Strength: Free plan up to 25,000 monthly active users with no card - Weakness: Only works when Auth0 is the identity provider for your users - Weakness: Two Token Vault connections on Free and three on Essentials and Professional without the add-on - Weakness: Log retention of 1 day on Free and 5 days on Essentials is short for an audit trail - Price: Freemium · Auth: OAuth · x402: no · Where: hosted and local - Full assessment: https://www.anchorterminal.com/tools/auth0-ai-agents.md - Against #1: https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.md ### 7. Aembit, BB 70.5/100 Aembit is a hosted identity and access platform for workloads and AI agents. Its MCP Identity Gateway and MCP Authorisation Server apply access policies and inject credentials, with a Cloud API, an Edge API, a CLI and an Edge SDK. - Verdict: Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found. - Choose it for: A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent. - Strength: Public OpenAPI 3.1.1 files for the Cloud API (171 operations) and Edge API (2), plus llms.txt, per-page Markdown and a cloneable docs bundle - Strength: No long-lived API credentials. Aembit API tokens last 1 hour by default and Edge API access tokens expire in 1 hour - Strength: MCP clients authenticate by OAuth 2.1 with PKCE, dynamic client registration or a Client ID Metadata Document - Weakness: No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance - Weakness: No SLA is published. The docs send SLA questions to Aembit support - Weakness: The managed MCP Identity Gateway endpoint is requested through an Aembit representative, and MCP Tool Access Control is enabled by support - Price: $20 / mo · Auth: OAuth or key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/aembit.md - Against #1: https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity.md ### 8. Vercel Connect, B 68.8/100 Vercel Connect is a credential broker for apps and agents. Code asks it for a short-lived, scoped token for Slack, GitHub, Microsoft, Linear, Snowflake or any OAuth, API-key or MCP service, as the app or for a user. - Verdict: Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript. - Choose it for: Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets. - Strength: Refresh tokens stay on Vercel's infrastructure. Code receives only short-lived access tokens, as the app or for a named user - Strength: A deployment authenticates with its project OIDC token, checked against per-environment project links, so no provider secret sits in environment variables - Strength: Public OpenAPI 3.0.3 document covers 13 Connect paths, including `/v1/connect/token/{connector}` and `/v1/connect/authorize/{connector}` - Weakness: Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment - Weakness: Elevated Connect errors for 94 minutes on 10 September 2026, marked major, and again on 18 September, per the status page - Weakness: Event history is kept 12 hours on Hobby and 3 days on Pro. Connector audit logs and 30 days need Enterprise - Price: $3 / 1k req · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/vercel-connect.md - Against #1: https://www.anchorterminal.com/compare/descope-agentic-identity-vs-vercel-connect.md ### 9. Nango, B 67.7/100 Source-available integration platform that handles OAuth, API keys and token refresh for 1,000+ APIs on behalf of your users. - Verdict: 1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan. - Choose it for: A product that connects many users to many SaaS APIs and wants tokens, refresh, syncs and a per-tenant MCP surface in one place, with source you can read. - Strength: 1,000+ APIs with OAuth, API key and client-credentials auth handled - Strength: Per-tenant agent sessions served as an MCP server, credentials never shown to the agent - Strength: Encryption, retention and deletion rules published in the docs - Weakness: Audit trail only on Enterprise, and logs kept 15 days on every plan - Weakness: Two CVEs fixed in September 2026, one critical, neither on Nango's own advisory page - Weakness: Status page tracks a single component - Price: $50 / mo · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/nango.md - Against #1: https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.md ### 10. Arcade.dev, B 66.9/100 MCP runtime built around per-user authorisation. - Verdict: Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise. - Choose it for: A product whose agent acts in many users' SaaS accounts and wants the tools written and run for it, not only the tokens. - Strength: Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token - Strength: 33 built-in auth providers plus generic OAuth 2.0, and hosted MCP gateways that sign users in through your own OIDC provider - Strength: OpenAPI 3.0 file with 39 paths, llms.txt and a typed tool error hierarchy with retry hints - Weakness: The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise - Weakness: Tool inputs and results are training data for up to 5 years unless the organisation opts out - Weakness: No published rate limits for the authorise or execute calls, and no 429 in the OpenAPI file - Price: $25 / mo · Auth: OAuth or key · x402: no · Where: hosted and local - Full assessment: https://www.anchorterminal.com/tools/arcade.md - Against #1: https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.md 7 more are ranked in the full table: https://www.anchorterminal.com/categories/agent-auth.md ## Head to head - [Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.md) - [Descope Agentic Identity Hub vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md) - [Descope Agentic Identity Hub vs Scalekit AgentKit](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit.md) - [Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.md) - [Amazon Bedrock AgentCore Identity vs Scalekit AgentKit](https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.md) - [Microsoft Entra Agent ID vs Scalekit AgentKit](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.md) ## Questions ### What are the highest-rated auth and delegated access for AI agents? Descope Agentic Identity Hub has the highest benchmark score of the 17 ranked auth and delegated access, 78.1 (A). Composio (API + MCP) is second with 75.1 (BB). ### How many auth and delegated access are agent-ready? 7 of the 17 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark. ### Which auth and delegated access accept x402 payments? None of the ranked listings here accepts x402 for its main call yet. ### Which of these auth and delegated access is cheapest? By published paid prices, Composio (API + MCP), at $0.0003 per call, the lowest of the 5 listings here with a paid price in this unit (free allowances aside). Plans, volume tiers and free allowances change the sum, so check the listing's price table. ### How is this list ranked? By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 8 October 2026. ## How this list is made The order is the Anchor benchmark score, the same number as on each listing. Each listing is graded from public evidence against the benchmark checklist, and the picks are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.