# Best auth and delegated access for AI agents (slim) > Descope Agentic Identity Hub (A), Composio (API + MCP) (BB) and Amazon Bedrock AgentCore Identity (BB) lead the 17 ranked auth and delegated access. Picks by need, strengths, weaknesses and prices from the Anchor benchmark. - Full: https://www.anchorterminal.com/best/agent-auth/index.md (~6,200 tokens) · this version ~1,730 tokens · JSON https://www.anchorterminal.com/best/agent-auth/index.json · canonical https://www.anchorterminal.com/best/agent-auth/ - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 The 10 highest-scoring of 17 auth and delegated access on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change. - Ranked: 17 · agent-ready (BB or better): 7 · accept x402: 0 · hosted endpoints: 16 - Full ranked table: https://www.anchorterminal.com/categories/agent-auth.md - Head-to-head comparisons: https://www.anchorterminal.com/compare/agent-auth/index.md (111) - Methodology: https://www.anchorterminal.com/benchmark/index.md ## The shortlist | # | Tool | Grade | Score | Best for | Price | Where | | --- | --- | --- | --- | --- | --- | --- | | 1 | [Descope Agentic Identity Hub](https://www.anchorterminal.com/tools/descope-agentic-identity.md) | A | 78.1 | A team that wants one vendor for both directions, holding users' third-party tokens and acting as the authorisation server for its own MCP server, with policy per agent. | $249 / mo | hosted | | 2 | [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md) | BB | 75.1 | A developer whose agent acts in many apps for many end users and wants auth, tool schemas and execution handled. | $29 / mo | hosted | | 3 | [Amazon Bedrock AgentCore Identity](https://www.anchorterminal.com/tools/agentcore-identity.md) | BB | 74.8 | Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge. | $0.01 / 1k req | hosted | | 4 | [Microsoft Entra Agent ID](https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md) | BB | 74.4 | Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs. | $15 / seat-mo | hosted | | 5 | [Scalekit AgentKit](https://www.anchorterminal.com/tools/scalekit-agentkit.md) | BB | 71.9 | A team that wants per-user third-party tokens plus a hosted tool catalogue at the lowest per-call price, with a tidy virtual MCP surface for agents. | $99 / mo | hosted | | 6 | [Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/tools/auth0-ai-agents.md) | BB | 71.4 | Best when Auth0 already runs login and the agent needs a handful of the user's Google, Microsoft, Slack or GitHub tokens, or a second-device approval before a payment or delete. | Freemium | hosted and local | | 7 | [Aembit](https://www.anchorterminal.com/tools/aembit.md) | BB | 70.5 | A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent. | $20 / mo | local | | 8 | [Vercel Connect](https://www.anchorterminal.com/tools/vercel-connect.md) | B | 68.8 | Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets. | $3 / 1k req | hosted | | 9 | [Nango](https://www.anchorterminal.com/tools/nango.md) | B | 67.7 | A product that connects many users to many SaaS APIs and wants tokens, refresh, syncs and a per-tenant MCP surface in one place, with source you can read. | $50 / mo | hosted | | 10 | [Arcade.dev](https://www.anchorterminal.com/tools/arcade.md) | B | 66.9 | A product whose agent acts in many users' SaaS accounts and wants the tools written and run for it, not only the tokens. | $25 / mo | hosted and local | ## Picks by need - Highest score overall: [Descope Agentic Identity Hub](https://www.anchorterminal.com/tools/descope-agentic-identity.md), A, 78.1/100 on the benchmark. Also [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), BB, 75.1/100. - Schema & documentation: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), 89/100 on schema & documentation, against 78 for the overall leader. - Agent ergonomics: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), 90/100 on agent ergonomics, against 80 for the overall leader. - Security & auth: [Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/tools/auth0-ai-agents.md), 88/100 on security & auth, against 86 for the overall leader. - Maintenance & community: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), 93/100 on maintenance & community, against 74 for the overall leader. - Transparency & trust: [Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/tools/auth0-ai-agents.md), 84/100 on transparency & trust, against 67 for the overall leader. - Lowest paid price per call: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), $0.0003 per call, the lowest of the 5 listings here with a paid price in this unit (free allowances aside). Also [Scalekit AgentKit](https://www.anchorterminal.com/tools/scalekit-agentkit.md), $0.0005 per call. - A hosted MCP endpoint: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), remote MCP server, nothing to install. - Self-hosting under an open licence: [Scalekit AgentKit](https://www.anchorterminal.com/tools/scalekit-agentkit.md), self-hosted, MIT licence. Also [Aembit](https://www.anchorterminal.com/tools/aembit.md), self-hosted, Proprietary service under Aembit's terms of service licence. - The review panel's favourite: [Composio (API + MCP)](https://www.anchorterminal.com/tools/composio-rube.md), 3.5/5 from 8 panel reviews. ## How to choose - Third-party apps covered: Check which third-party apps are covered and whether each one's OAuth scopes can be requested separately, since an app you need may only be reachable with broad access. - Consent screen and refused scopes: Check what the consent screen shows the user and how the agent learns that a scope was refused, since silent partial access is hard to debug. - Where tokens are stored: Check where access and refresh tokens live, whether the agent holds the raw token, and whether revocation clears every copy, since a stray copy keeps working. - Revocation and audit trail: Check how fast a revoked grant stops the agent's calls and what the audit log records for each call, because revocation that takes effect late is a security gap. - How the benchmark tests this category: An agent connects to two third-party apps for a test user, makes calls, has one scope refused and then the grant revoked. We check the consent flow, where tokens live, what the audit log shows and how revocation reaches the agent. Each listing's verdict, strengths and weaknesses: https://www.anchorterminal.com/best/agent-auth/index.md