{
  "data": {
    "category": {
      "area": "agent-runtime",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "description": "Services that let an agent act for a user in other apps: OAuth flows and token storage for third-party APIs, scoped and revocable access, and an identity for the agent itself. Compared on the providers they cover, how consent works, token handling and audit logs.",
      "indexed": [
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/artifacta-mcp.json",
          "kind": "mcp",
          "name": "artifacta.io MCP server",
          "slug": "artifacta-mcp",
          "url": "https://www.anchorterminal.com/tools/artifacta-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/coachwatts-coach-watts.json",
          "kind": "mcp",
          "name": "Coach Watts",
          "slug": "coachwatts-coach-watts",
          "url": "https://www.anchorterminal.com/tools/coachwatts-coach-watts"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/expense-budget-tracker.json",
          "kind": "mcp",
          "name": "Expense Budget Tracker",
          "slug": "expense-budget-tracker",
          "url": "https://www.anchorterminal.com/tools/expense-budget-tracker"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/gemina.json",
          "kind": "mcp",
          "name": "Gemina",
          "slug": "gemina",
          "url": "https://www.anchorterminal.com/tools/gemina"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hit-pay-mcp.json",
          "kind": "mcp",
          "name": "HitPay MCP Server",
          "slug": "hit-pay-mcp",
          "url": "https://www.anchorterminal.com/tools/hit-pay-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/imaginevid-ai-generation.json",
          "kind": "mcp",
          "name": "imaginevid-ai-generation",
          "slug": "imaginevid-ai-generation",
          "url": "https://www.anchorterminal.com/tools/imaginevid-ai-generation"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/onkernel-kernel-mcp-server.json",
          "kind": "mcp",
          "name": "kernel-mcp-server",
          "slug": "onkernel-kernel-mcp-server",
          "url": "https://www.anchorterminal.com/tools/onkernel-kernel-mcp-server"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/dinglebear-labby.json",
          "kind": "mcp",
          "name": "Labby",
          "slug": "dinglebear-labby",
          "url": "https://www.anchorterminal.com/tools/dinglebear-labby"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/1pass-logi.json",
          "kind": "mcp",
          "name": "logi",
          "slug": "1pass-logi",
          "url": "https://www.anchorterminal.com/tools/1pass-logi"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/studiomeyer-protocol-conformance.json",
          "kind": "mcp",
          "name": "MCP Protocol Conformance",
          "slug": "studiomeyer-protocol-conformance",
          "url": "https://www.anchorterminal.com/tools/studiomeyer-protocol-conformance"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/git-mymlh-mcp-server.json",
          "kind": "mcp",
          "name": "mymlh-mcp-server",
          "slug": "git-mymlh-mcp-server",
          "url": "https://www.anchorterminal.com/tools/git-mymlh-mcp-server"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/odooconsole-odoo.json",
          "kind": "mcp",
          "name": "odoo",
          "slug": "odooconsole-odoo",
          "url": "https://www.anchorterminal.com/tools/odooconsole-odoo"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/offlinecreatorstudio-mcp.json",
          "kind": "mcp",
          "name": "OfflineCreator Studio",
          "slug": "offlinecreatorstudio-mcp",
          "url": "https://www.anchorterminal.com/tools/offlinecreatorstudio-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openworklabs-openwork.json",
          "kind": "mcp",
          "name": "OpenWork MCP Gateway",
          "slug": "openworklabs-openwork",
          "url": "https://www.anchorterminal.com/tools/openworklabs-openwork"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paichart-mcp-hub.json",
          "kind": "mcp",
          "name": "pAIchart MCP Hub",
          "slug": "paichart-mcp-hub",
          "url": "https://www.anchorterminal.com/tools/paichart-mcp-hub"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/p7n-platform7n.json",
          "kind": "mcp",
          "name": "platform7n",
          "slug": "p7n-platform7n",
          "url": "https://www.anchorterminal.com/tools/p7n-platform7n"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/prizmad-mcp-server.json",
          "kind": "mcp",
          "name": "Prizmad",
          "slug": "prizmad-mcp-server",
          "url": "https://www.anchorterminal.com/tools/prizmad-mcp-server"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/thoughtspot-mcp-server.json",
          "kind": "mcp",
          "name": "thoughtspot.app MCP server",
          "slug": "thoughtspot-mcp-server",
          "url": "https://www.anchorterminal.com/tools/thoughtspot-mcp-server"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/toll402-mcp.json",
          "kind": "mcp",
          "name": "toll402-mcp",
          "slug": "toll402-mcp",
          "url": "https://www.anchorterminal.com/tools/toll402-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/missingmcp-whoop.json",
          "kind": "mcp",
          "name": "WHOOP — MissingMCP",
          "slug": "missingmcp-whoop",
          "url": "https://www.anchorterminal.com/tools/missingmcp-whoop"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/wraps-docs.json",
          "kind": "mcp",
          "name": "Wraps",
          "slug": "wraps-docs",
          "url": "https://www.anchorterminal.com/tools/wraps-docs"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/xquik-mcp.json",
          "kind": "mcp",
          "name": "Xquik MCP Server",
          "slug": "xquik-mcp",
          "url": "https://www.anchorterminal.com/tools/xquik-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/smirnovlabs-ynab-mcp-server.json",
          "kind": "mcp",
          "name": "ynab-mcp-server",
          "slug": "smirnovlabs-ynab-mcp-server",
          "url": "https://www.anchorterminal.com/tools/smirnovlabs-ynab-mcp-server"
        }
      ],
      "indexedCount": 23,
      "json": "https://www.anchorterminal.com/categories/agent-auth.json",
      "name": "Agent auth \u0026 delegated access",
      "slug": "agent-auth",
      "test": "An agent connects to two third-party apps for a test user, makes calls, has one scope refused and then the grant revoked. We check the consent flow, where tokens live, what the audit log shows and how revocation reaches the agent.",
      "title": "Auth and delegated access for AI agents",
      "toolCount": 13,
      "tools": [
        "descope-agentic-identity",
        "composio-rube",
        "scalekit-agentkit",
        "auth0-ai-agents",
        "nango",
        "arcade",
        "pipedream",
        "stytch-connected-apps",
        "workos-pipes",
        "zapier-mcp",
        "keycard",
        "permit-mcp-gateway",
        "paragon"
      ],
      "url": "https://www.anchorterminal.com/categories/agent-auth"
    },
    "tools": [
      {
        "slug": "descope-agentic-identity",
        "name": "Descope Agentic Identity Hub",
        "vendor": "Descope",
        "vendorUrl": "https://www.descope.com",
        "kind": "http-api",
        "category": "agent-auth",
        "summary": "Descope's identity and access tools for AI agents, built on its customer identity platform.",
        "url": "https://www.anchorterminal.com/tools/descope-agentic-identity",
        "markdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json",
        "repo": "https://github.com/descope/node-sdk",
        "license": "MIT (SDKs), platform closed",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://api.descope.com",
        "packages": [
          {
            "registry": "npm",
            "name": "@descope/node-sdk"
          },
          {
            "registry": "npm",
            "name": "@descope/agent-auth"
          },
          {
            "registry": "pypi",
            "name": "descope-agent-auth"
          },
          {
            "registry": "npm",
            "name": "@descope/mcp-express"
          },
          {
            "registry": "pypi",
            "name": "descope"
          }
        ],
        "auth": "mixed",
        "authNotes": "Management calls take `Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY`. An agent can instead sign in as its own OAuth client (client credentials, device code, CIBA or RFC 7523 JWT bearer against /oauth2/v1/token) or present a user's Descope access token in the same header, and Policies then limit which tokens it can fetch. A management key bypasses Policies, and the Agent Auth SDK makes you opt in to use one. Inbound Apps use the shared endpoints `/oauth2/v1/apps/authorize` and `/oauth2/v1/apps/token` with PKCE for public clients.",
        "pricing": "freemium",
        "pricingNotes": "Free Forever is $0 with 7,500 monthly active users, 10 tenants, 3 SSO connections, 10,000 M2M exchanges, 2,000 MACs and 2,000 MATKs, no card. Pro starts at $249 a month billed annually with 10,000 MAU ($0.05 each after), 35 tenants, 5 SSO connections, 50,000 M2M exchanges ($2 per 1,000 after), 5,000 MACs and 5,000 MATKs ($0.05 each after). Growth starts at $799 a month billed annually with 25,000 MAU, 100 tenants, 10 SSO connections, 100,000 M2M exchanges, 10,000 MACs and 10,000 MATKs. Enterprise is custom. A MAC (monthly active consent) is counted when a unique user consents to any scope for a resource at least once in a month, and covers Inbound Apps and MCP auth. A MATK (monthly active token) is any instance where a token is fetched and used, and covers Outbound Apps and Connections (https://www.descope.com/pricing).",
        "priceSummary": "$249 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 67,
          "npmWeekly": 353532,
          "pypiWeekly": null,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://docs.descope.com/agentic-identity-hub",
        "llmsTxt": "https://docs.descope.com/llms.txt",
        "capabilities": [
          "auth.oauth",
          "auth.tokens",
          "auth.consent",
          "auth.agent-identity",
          "auth.audit",
          "hitl.approve"
        ],
        "tags": [
          "hosted",
          "freemium",
          "free-tier",
          "no-card",
          "oauth",
          "llms-txt",
          "typescript",
          "python",
          "enterprise",
          "eu"
        ],
        "lastRelease": "2026-09-07",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 79.2,
          "grade": "A",
          "agentReady": true,
          "rank": 10,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 1,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 80,
            "maintenance": 76,
            "payments": 40,
            "reliability": 100,
            "schema": 82,
            "security": 86,
            "transparency": 70
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.",
          "strengths": [
            "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion",
            "Descope as the OAuth authorisation server for your APIs and MCP servers, with DCR, CIBA and token exchange",
            "Policies decide which tokens an agent identity can obtain, evaluated at issuance and exchange",
            "Per-endpoint rate limits, 429 with Retry-After, and an SLA of 99.99 per cent on Pro",
            "Free Forever tier with 2,000 consents and 2,000 token fetches a month, no card"
          ],
          "weaknesses": [
            "No tool catalogue, so you write every provider call yourself",
            "The Agent Auth SDK is 0.1.0 with 18 open pull requests and no commit since 2 July 2026",
            "The docs don't say how vaulted tokens are encrypted",
            "No security.txt and no deprecation policy we could find",
            "Paid plans are billed annually, from $249 a month"
          ],
          "agentNotes": [
            "Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key",
            "Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL",
            "Back off for the full window on a 429, 60 seconds for most management endpoints",
            "Ask for a tenant token, not a user token, for organisation-wide API keys",
            "Budget monthly active tokens, since every token fetched and used counts once a month"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 8,
          "avgRating": 3.1,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "A",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 79.2
            }
          ],
          "editorialScores": {
            "ergonomics": 80,
            "maintenance": 76,
            "payments": 40,
            "reliability": 100,
            "schema": 82,
            "security": 86,
            "transparency": 49
          },
          "provenanceScore": 90
        },
        "connect": {
          "install": "npm install @descope/node-sdk",
          "http": "curl -X POST https://api.descope.com/v1/mgmt/outbound/app/user/token/latest \\\n  -H \"Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"appId\":\"github\",\"userId\":\"user-123\"}'"
        },
        "letme": {
          "capability": "https://letme.dev/auth.oauth",
          "tool": "https://letme.dev/descope-agentic-identity"
        },
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "Pro plan",
            "unit": "month",
            "usd": 249,
            "note": "Starting price, billed annually"
          },
          {
            "item": "Monthly active token (MATK) above the allowance",
            "unit": "call",
            "usd": 0.05,
            "note": "A token fetched and used, counted once a month. Pro and Growth"
          },
          {
            "item": "Monthly active consent (MAC) above the allowance",
            "unit": "account-month",
            "usd": 0.05,
            "note": "A unique user consenting to a resource at least once in a month. Pro and Growth"
          }
        ],
        "provenance": {
          "legalEntity": "Descope, Inc.",
          "domain": "descope.com",
          "domainRegistered": "2016-04-13",
          "endpointOnVendorDomain": true,
          "terms": "https://www.descope.com/legal/terms",
          "privacy": "https://www.descope.com/legal/privacy",
          "statusPage": "https://descopestatus.com",
          "changelog": "https://ideas.descope.works/changelog",
          "securityTxt": "none",
          "checked": "2026-10-01",
          "notes": [
            "The terms (updated 24 February 2026) contract with Descope, Inc. for US and Canadian customers, Descope Technologies Israel (2022) Ltd. for Israel and Descope Technologies UK (2025) Ltd. elsewhere, under Delaware law.",
            "/.well-known/security.txt returned 404 on 2026-09-30. A vulnerability disclosure policy is linked from descope.com/security-compliance.",
            "The status page is an Instatus page at descopestatus.com.",
            "The changelog lives on the ideas.descope.works portal, off the main domain, and needs JavaScript to render."
          ],
          "score": 90
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.json",
        "live": {
          "slug": "descope-agentic-identity",
          "probe": {
            "target": "https://api.descope.com",
            "method": "get",
            "lastAt": "2026-10-04T22:35:22.468592784Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 315,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 124,
            "p95ms24h": 296,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 109
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://descopestatus.com",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-04T21:39:56.414035779Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "descope/node-sdk",
              "version": "v2.17.0",
              "released": "2026-09-07",
              "seenAt": "2026-10-04T16:25:34.432882503Z"
            },
            {
              "registry": "npm",
              "name": "@descope/mcp-express",
              "version": "1.6.0",
              "seenAt": "2026-10-04T16:25:32.533673136Z"
            },
            {
              "registry": "npm",
              "name": "@descope/node-sdk",
              "version": "2.17.0",
              "seenAt": "2026-10-04T16:25:30.077963378Z"
            },
            {
              "registry": "pypi",
              "name": "descope",
              "version": "2.14.0",
              "released": "2026-09-07",
              "seenAt": "2026-10-04T16:25:34.348420573Z"
            }
          ],
          "githubStars": 68,
          "npmWeekly": 347658,
          "securityTxt": {
            "url": "https://descope.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:50.5505058Z"
          },
          "llmsTxt": {
            "url": "https://docs.descope.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:30.527628191Z"
          },
          "domain": {
            "domain": "descope.com",
            "registered": "2016-04-13",
            "source": "https://rdap.verisign.com/com/v1/domain/descope.com",
            "checkedAt": "2026-10-04T13:09:53.916089274Z"
          },
          "pages": [
            {
              "url": "https://ideas.descope.works/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:45:04.44252976Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "df9dfc56ddd7"
            },
            {
              "url": "https://www.descope.com/pricing",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:50:06.059286057Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "a45e89c271ce"
            },
            {
              "url": "https://www.descope.com/legal/privacy",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:50:01.803096328Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "8b2b659c6dcc"
            },
            {
              "url": "https://www.descope.com/legal/terms",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-04T15:50:04.020978892Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "d6f39b94f5db"
            }
          ],
          "updatedAt": "2026-10-04T22:35:22.468592784Z"
        }
      },
      {
        "slug": "composio-rube",
        "name": "Composio (API + MCP)",
        "vendor": "Composio",
        "vendorUrl": "https://composio.dev",
        "kind": "http-api",
        "category": "aggregator",
        "summary": "Tool access and per-user authentication for agents across 1,000+ apps.",
        "url": "https://www.anchorterminal.com/tools/composio-rube",
        "markdownUrl": "https://www.anchorterminal.com/tools/composio-rube.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/composio-rube.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/composio-rube.json",
        "repo": "https://github.com/ComposioHQ/composio",
        "license": "MIT",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://backend.composio.dev/api/v3.1",
        "packages": [
          {
            "registry": "npm",
            "name": "@composio/core"
          },
          {
            "registry": "pypi",
            "name": "composio"
          }
        ],
        "auth": "mixed",
        "authNotes": "REST calls take a project key in 'x-api-key' (or an org key in 'x-org-api-key'). End users authorise each app through a hosted Connect Link, and Composio stores the tokens under your user ID, so they never pass through your app or the model. Composio Connect MCP uses an OAuth sign-in in the client. Bring your own OAuth app via a custom auth config for your own branding or scopes.",
        "pricing": "freemium",
        "pricingNotes": "Hobby is free with 100,000 tool calls and 50,000 trigger events a month and pauses at the cap, no card. Pro is $29 a month including $29 of usage, then $0.0003 a tool call and $0.003 a trigger event, or $0.0005 and $0.005 through Composio-managed apps, and $3.75 per million LLM tokens after 1 million free. Premium tools (search, maps, browser, media) are billed at provider prices. Enterprise is custom. The new prices apply to sign-ups from 2026-08-15, and earlier customers keep their plan to 2026-12-31 (https://composio.dev/pricing).",
        "priceSummary": "$29 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402 support in Composio docs or pricing (checked 2026-09-30).",
          "endpoints": []
        },
        "toolCount": 7,
        "popularity": {
          "githubStars": 30370,
          "npmWeekly": 1139190,
          "pypiWeekly": null,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://docs.composio.dev/",
        "llmsTxt": "https://docs.composio.dev/llms.txt",
        "openapi": "https://backend.composio.dev/api/v3.1/openapi.json",
        "registryName": "io.github.ComposioHQ/composio",
        "capabilities": [
          "automation.apps",
          "automation.auth",
          "automation.actions",
          "agent.tools",
          "automation.webhooks"
        ],
        "tags": [
          "aggregator",
          "meta-tools",
          "hosted",
          "freemium",
          "no-card",
          "mcp",
          "llms-txt",
          "openapi",
          "python",
          "typescript",
          "open-source"
        ],
        "lastRelease": "2026-09-29",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 75.3,
          "grade": "BB",
          "agentReady": true,
          "rank": 36,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 1,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 90,
            "maintenance": 93,
            "payments": 40,
            "reliability": 70,
            "schema": 89,
            "security": 70,
            "transparency": 78
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "Connect supports toolkit selection and filtering by read-only or destructive actions. Rube closed on 16 May 2026, so existing rube.app configurations need migration.",
          "strengths": [
            "Seven Connect meta-tools, and sessions that load chosen toolkits or filter by read-only and destructive tags",
            "Per-call prices in public and 100,000 free tool calls a month with no card",
            "OpenAPI 3.0 with 62 paths, llms.txt and an error reference",
            "Published rate limits with Retry-After, and SDKs that don't retry non-idempotent tools",
            "Retention and ZDR documented in detail, including what ZDR doesn't cover"
          ],
          "weaknesses": [
            "Rube shut down on 16 May 2026, so old rube.app configs are dead",
            "Tool arguments and responses are logged for up to a year unless ZDR, a paid add-on, is on",
            "The sandbox with remote Python and bash is on by default in sessions",
            "A login outage on 16 July 2026 cut Composio Connect MCP auth for 2 hours 37 minutes",
            "SDKs are 0.x and ship breaking changes most months"
          ],
          "agentNotes": [
            "Create one session per end user with a stable database ID, never an email or `default`",
            "Pass the Connect Link from COMPOSIO_MANAGE_CONNECTIONS to the user and call COMPOSIO_WAIT_FOR_CONNECTIONS rather than asking for credentials",
            "Filter the session to `readOnlyHint` tools when the task only reads",
            "Don't retry a timed-out send or create call blind, check the app first, since the SDKs won't retry it either",
            "Replace any rube.app/mcp entry with connect.composio.dev/mcp or a session MCP URL"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 8,
          "avgRating": 3.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 75.3
            }
          ],
          "editorialScores": {
            "ergonomics": 90,
            "maintenance": 93,
            "payments": 40,
            "reliability": 70,
            "schema": 89,
            "security": 70,
            "transparency": 74
          },
          "provenanceScore": 82
        },
        "connect": {
          "install": "pip install composio",
          "http": "curl https://backend.composio.dev/api/v3.1/toolkits -H \"x-api-key: $COMPOSIO_API_KEY\"",
          "claudeCode": "claude mcp add --transport http composio https://connect.composio.dev/mcp",
          "config": {
            "mcpServers": {
              "composio": {
                "url": "https://connect.composio.dev/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/automation.apps",
          "tool": "https://letme.dev/composio-rube"
        },
        "alsoIn": [
          "agent-auth"
        ],
        "area": "business",
        "unitPrices": [
          {
            "item": "Pro",
            "unit": "month",
            "usd": 29,
            "note": "includes $29 of usage"
          },
          {
            "item": "Tool call on Pro",
            "unit": "call",
            "usd": 0.0003
          },
          {
            "item": "Trigger event on Pro",
            "unit": "call",
            "usd": 0.003
          }
        ],
        "provenance": {
          "legalEntity": "Sampark Inc (d/b/a Composio)",
          "domain": "composio.dev",
          "domainRegistered": "2023-04-02",
          "domainNote": "The slug dates from Rube. www.rube.app now shows only Composio's discontinuation notice. The listing covers Composio's platform on composio.dev.",
          "endpointOnVendorDomain": true,
          "terms": "https://composio.dev/terms",
          "privacy": "https://composio.dev/privacy",
          "statusPage": "https://status.composio.dev",
          "changelog": "https://docs.composio.dev/docs/changelog",
          "securityTxt": "none",
          "checked": "2026-10-01",
          "score": 82
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/composio-rube.json",
        "live": {
          "slug": "composio-rube",
          "probe": {
            "target": "https://backend.composio.dev/api/v3.1",
            "method": "get",
            "lastAt": "2026-10-04T22:35:21.380545648Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 198,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 202,
            "p95ms24h": 280,
            "samples24h": 272,
            "samples30d": 1086,
            "days": [
              {
                "date": "2026-09-30",
                "probes": 35,
                "ok": 35
              },
              {
                "date": "2026-10-01",
                "probes": 276,
                "ok": 276
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.composio.dev",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-04T21:39:55.439866911Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "ComposioHQ/composio",
              "version": "@composio/openai@0.13.0",
              "released": "2026-09-29",
              "seenAt": "2026-10-04T16:24:30.810064913Z"
            },
            {
              "registry": "mcp-registry",
              "name": "io.github.ComposioHQ/composio",
              "version": "1.0.5",
              "seenAt": "2026-10-03T23:29:28.630222764Z"
            },
            {
              "registry": "npm",
              "name": "@composio/core",
              "version": "0.22.0",
              "seenAt": "2026-10-04T16:24:28.681796505Z"
            },
            {
              "registry": "pypi",
              "name": "composio",
              "version": "0.25.0",
              "released": "2026-09-29",
              "seenAt": "2026-10-04T16:24:30.701523487Z"
            }
          ],
          "githubStars": 30436,
          "npmWeekly": 1248122,
          "pypiWeekly": 449642,
          "securityTxt": {
            "url": "https://composio.dev/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:56.992199833Z"
          },
          "llmsTxt": {
            "url": "https://docs.composio.dev/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:27.941146986Z"
          },
          "domain": {
            "domain": "composio.dev",
            "registered": "2023-04-02",
            "source": "https://pubapi.registry.google/rdap/domain/composio.dev",
            "checkedAt": "2026-10-04T13:03:43.269953405Z"
          },
          "pages": [
            {
              "url": "https://docs.composio.dev/docs/changelog",
              "kind": "changelog",
              "status": 404,
              "checkedAt": "2026-10-04T15:43:28.411469457Z",
              "changedAt": "0001-01-01T00:00:00Z"
            },
            {
              "url": "https://composio.dev/pricing",
              "kind": "deprecations",
              "status": 200,
              "checkedAt": "2026-10-04T15:42:08.360650759Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "a0b799c2566b"
            },
            {
              "url": "https://www.rube.app",
              "kind": "deprecations",
              "status": 304,
              "checkedAt": "2026-10-04T15:52:00.602901035Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "30124a52bb40"
            },
            {
              "url": "https://composio.dev/privacy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:42:10.445091393Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "2acd021f9d37"
            },
            {
              "url": "https://composio.dev/terms",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-04T15:42:12.588466325Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "48d7e56a73d0"
            }
          ],
          "updatedAt": "2026-10-04T22:35:21.380545648Z"
        }
      },
      {
        "slug": "scalekit-agentkit",
        "name": "Scalekit AgentKit",
        "vendor": "Scalekit",
        "vendorUrl": "https://www.scalekit.com",
        "kind": "http-api",
        "category": "agent-auth",
        "summary": "Authentication and integration platform for agents, with per-user account connections, scoped MCP servers and managed tool calls.",
        "url": "https://www.anchorterminal.com/tools/scalekit-agentkit",
        "markdownUrl": "https://www.anchorterminal.com/tools/scalekit-agentkit.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/scalekit-agentkit.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/scalekit-agentkit.json",
        "repo": "https://github.com/scalekit-inc/scalekit-sdk-node",
        "license": "MIT (SDKs), platform closed, self-hosted on Enterprise",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://{env}.scalekit.com",
        "packages": [
          {
            "registry": "npm",
            "name": "@scalekit-sdk/node"
          },
          {
            "registry": "pypi",
            "name": "scalekit-sdk-python"
          },
          {
            "registry": "npm",
            "name": "@scalekit-inc/cli"
          }
        ],
        "auth": "mixed",
        "authNotes": "Your backend gets a bearer token from `POST $SCALEKIT_ENVIRONMENT_URL/oauth/token` with `grant_type=client_credentials` and the client ID and secret from the dashboard, then calls the REST API under /api/v1 on the same environment URL (dev environments end in .scalekit.dev, production in .scalekit.com). End users authorise a connection through a time-limited magic link that Scalekit hosts. Virtual MCP servers take a short-lived session token minted per user, about one hour by default. The management MCP server at mcp.scalekit.com needs no extra credentials.",
        "pricing": "freemium",
        "pricingNotes": "AgentKit Free is $0 with 5,000 tool calls a month, unlimited connected accounts, 500+ connectors and community and email support, no card. Growth is $99 a month with 100,000 tool calls and $0.0005 per extra call, custom connectors, an API proxy and private Slack support, with an EU data residency add-on at $99 a month. Enterprise is custom, with negotiated call volume, a 99.99 per cent uptime SLA, VPC or on-prem deployment, a HIPAA BAA, SIEM integrations and a forward-deployed engineer (https://www.scalekit.com/pricing). The page doesn't say whether a plain token fetch counts as a tool call.",
        "priceSummary": "$99 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 6,
          "npmWeekly": 10642,
          "pypiWeekly": null,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://docs.scalekit.com/agentkit/overview",
        "llmsTxt": "https://docs.scalekit.com/llms.txt",
        "openapi": "https://docs.scalekit.com/api/agentkit.scalar.json",
        "capabilities": [
          "auth.oauth",
          "auth.tokens",
          "auth.consent",
          "auth.agent-identity",
          "agent.tools"
        ],
        "tags": [
          "hosted",
          "freemium",
          "free-tier",
          "no-card",
          "oauth",
          "mcp",
          "llms-txt",
          "openapi",
          "typescript",
          "python",
          "enterprise",
          "self-hosted"
        ],
        "lastRelease": "2026-09-29",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 72.1,
          "grade": "BB",
          "agentReady": true,
          "rank": 74,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 2,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 83,
            "maintenance": 80,
            "payments": 40,
            "reliability": 75,
            "schema": 87,
            "security": 66,
            "transparency": 68
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "500+ connectors, including remote MCP servers over OAuth 2.1 with DCR. No rate limits or idempotency documented for Scalekit's own API.",
          "strengths": [
            "500+ connectors, including remote MCP servers over OAuth 2.1 with DCR",
            "OpenAPI files, llms.txt and a Markdown twin for every docs page",
            "Tool search, scoped tool lists and virtual MCP servers keep an agent's context small",
            "Atlassian status page with an Agent Kit Tool Execution component, 100.0 per cent over 90 days",
            "Free tier of 5,000 tool calls a month with no card, then $0.0005 a call on Growth"
          ],
          "weaknesses": [
            "No rate limits or idempotency documented for Scalekit's own API",
            "Any holder of the API credential can read a user's full OAuth tokens",
            "No approval step for destructive tools and no prompt-injection guidance",
            "The privacy policy says the United States and India, the trust centre says Frankfurt and Los Angeles",
            "No security.txt, no bug bounty and no deprecation notices"
          ],
          "agentNotes": [
            "Use the exact dashboard Connection Name, not the connector slug, in every call",
            "Call `POST /api/v1/tools:search` with top_k instead of listing every tool",
            "When a connected account isn't ACTIVE, send the user the magic link and stop until they finish",
            "On ScalekitToolRateLimitException, back off before retrying, and log the executionId",
            "Mint a fresh virtual MCP session token per user per run and let it expire"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 72.1
            }
          ],
          "editorialScores": {
            "ergonomics": 83,
            "maintenance": 80,
            "payments": 40,
            "reliability": 75,
            "schema": 87,
            "security": 66,
            "transparency": 45
          },
          "provenanceScore": 90
        },
        "connect": {
          "install": "npm install @scalekit-sdk/node",
          "http": "TOKEN=$(curl -s -X POST \"$SCALEKIT_ENVIRONMENT_URL/oauth/token\" \\\n  -d client_id=\"$SCALEKIT_CLIENT_ID\" -d client_secret=\"$SCALEKIT_CLIENT_SECRET\" \\\n  -d grant_type=client_credentials | jq -r .access_token)\ncurl -X POST \"$SCALEKIT_ENVIRONMENT_URL/api/v1/connected_accounts/magic_link\" \\\n  -H \"Authorization: Bearer $TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"connection_name\":\"gmail\",\"identifier\":\"user-123\"}'",
          "claudeCode": "claude mcp add --transport http --scope user scalekit https://mcp.scalekit.com",
          "config": {
            "mcpServers": {
              "scalekit": {
                "url": "https://mcp.scalekit.com"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/auth.oauth",
          "tool": "https://letme.dev/scalekit-agentkit"
        },
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "Growth plan",
            "unit": "month",
            "usd": 99,
            "note": "100,000 tool calls included"
          },
          {
            "item": "Tool call above 100,000 on Growth",
            "unit": "call",
            "usd": 0.0005,
            "note": "$0.50 per 1,000"
          },
          {
            "item": "EU data residency add-on",
            "unit": "month",
            "usd": 99,
            "note": "Growth plan"
          }
        ],
        "provenance": {
          "legalEntity": "ScaleKit, Inc.",
          "domain": "scalekit.com",
          "domainRegistered": "2003-04-24",
          "endpointOnVendorDomain": true,
          "terms": "https://www.scalekit.com/legal/terms-of-service",
          "privacy": "https://www.scalekit.com/legal/privacy-policy",
          "statusPage": "https://scalekit.statuspage.io/",
          "changelog": "https://www.scalekit.com/product-updates",
          "securityTxt": "none",
          "checked": "2026-10-02",
          "notes": [
            "The terms and privacy policy (both effective 1 January 2026) name ScaleKit, Inc., with addresses in Redmond, WA and Lewes, DE, under Delaware law.",
            "RDAP shows scalekit.com registered on 2003-04-24, long before the company, so the domain was bought later.",
            "/.well-known/security.txt returned 404 on 2026-09-30. The status page is scalekit.statuspage.io, linked from the site footer. status.scalekit.com serves the dashboard app.",
            "The trust page at https://www.scalekit.com/trust-center states SOC 2 Type 2 and ISO 27001 certification and gives security@scalekit.com for reports."
          ],
          "score": 90
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/scalekit-agentkit.json",
        "live": {
          "slug": "scalekit-agentkit",
          "probe": {
            "target": "https://{env}.scalekit.com",
            "method": "get",
            "lastAt": "2026-10-04T22:35:30.833802529Z",
            "lastOk": false,
            "lastStatus": 0,
            "lastMs": 0,
            "lastNote": "invalid character \"{\" in host name",
            "authRequired": false,
            "uptime24h": 0,
            "uptime30d": 0,
            "p50ms24h": 0,
            "p95ms24h": 0,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 0
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 0
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 0
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 0
              }
            ]
          },
          "vendorStatus": {
            "page": "https://scalekit.statuspage.io",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T22:34:08.265283219Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "scalekit-inc/scalekit-sdk-node",
              "version": "v2.18.0",
              "released": "2026-09-29",
              "seenAt": "2026-10-04T16:39:02.534913139Z"
            },
            {
              "registry": "npm",
              "name": "@scalekit-inc/cli",
              "version": "0.3.23",
              "seenAt": "2026-10-04T16:39:01.342000489Z"
            },
            {
              "registry": "npm",
              "name": "@scalekit-sdk/node",
              "version": "2.18.0",
              "seenAt": "2026-10-04T16:39:00.30736538Z"
            },
            {
              "registry": "pypi",
              "name": "scalekit-sdk-python",
              "version": "2.19.1",
              "released": "2026-09-11",
              "seenAt": "2026-10-04T16:39:01.154420887Z"
            }
          ],
          "githubStars": 8,
          "npmWeekly": 10677,
          "pypiWeekly": 10097,
          "securityTxt": {
            "url": "https://scalekit.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:57.375101166Z"
          },
          "llmsTxt": {
            "url": "https://docs.scalekit.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:18:13.064059136Z"
          },
          "domain": {
            "domain": "scalekit.com",
            "registered": "2003-04-24",
            "source": "https://rdap.verisign.com/com/v1/domain/scalekit.com",
            "checkedAt": "2026-10-04T13:09:01.703612585Z"
          },
          "pages": [
            {
              "url": "https://www.scalekit.com/product-updates",
              "kind": "changelog",
              "status": 304,
              "checkedAt": "2026-10-04T15:52:10.80505162Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "0bfb89bd8ec3"
            },
            {
              "url": "https://www.scalekit.com/pricing",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:52:08.787466407Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "cdf7adf96094"
            },
            {
              "url": "https://www.scalekit.com/legal/privacy-policy",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:52:04.7487051Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "455fdfe20694"
            },
            {
              "url": "https://www.scalekit.com/legal/terms-of-service",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-04T15:52:06.776239407Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "c8437cad75b0"
            }
          ],
          "updatedAt": "2026-10-04T22:35:30.833802529Z"
        }
      },
      {
        "slug": "auth0-ai-agents",
        "name": "Auth0 for AI Agents (Token Vault)",
        "vendor": "Auth0 by Okta",
        "vendorUrl": "https://auth0.com/ai",
        "kind": "http-api",
        "category": "agent-auth",
        "summary": "Auth0's identity and authorisation tools for AI agents, built on its identity platform.",
        "url": "https://www.anchorterminal.com/tools/auth0-ai-agents",
        "markdownUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json",
        "repo": "https://github.com/auth0/auth0-ai-js",
        "license": "Apache-2.0 (SDKs), platform closed",
        "transports": [
          "http",
          "stdio"
        ],
        "remoteUrl": "https://{tenant}.auth0.com/oauth/token",
        "packages": [
          {
            "registry": "npm",
            "name": "@auth0/ai"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai-langchain"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai-vercel"
          },
          {
            "registry": "pypi",
            "name": "auth0-ai"
          },
          {
            "registry": "npm",
            "name": "@auth0/auth0-mcp-server"
          }
        ],
        "auth": "oauth",
        "authNotes": "Standard OAuth 2.0 and OIDC against your tenant. The app exchanges the user's Auth0 refresh token or access token at /oauth/token with the grant type `urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token` and gets back the external provider's access token. Backend workers can use a signed JWT (privileged worker exchange). DPoP can bind Auth0 tokens to the client. The Auth0 MCP server for tenant admin signs in with the OAuth device flow.",
        "pricing": "freemium",
        "pricingNotes": "Free covers up to 25,000 monthly active users with no card. Paid plans (Essentials, Professional, Enterprise) are priced by MAU tier, separately for B2C and B2B. Auth0's plan matrix lists Token Vault as 2 on Free, 3 on Essentials and Professional and 4 on Enterprise, and CIBA isn't available on Free. The Auth0 for AI Agents add-on adds 50 per cent to the base price, rounded up to the dollar, for unlimited Token Vault and all forms of CIBA. Yearly billing is 11 times the monthly price. Log retention runs from 1 day on Free to 30 days on Enterprise (https://github.com/auth0/docs-v2/blob/main/main/.mintlify/skills/auth0/references/feature-audit-pricing/index.md, https://auth0.com/pricing). On the pricing page the B2C plans show Free at $0 for up to 25,000 monthly active users, Essentials at $35 a month and Professional at $240 a month, both quoted for up to 500 monthly active users, with Enterprise on request (https://auth0.com/pricing).",
        "priceSummary": "Freemium",
        "where": "both",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 16,
          "npmWeekly": 3114,
          "pypiWeekly": null,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://auth0.com/ai/docs",
        "llmsTxt": "https://auth0.com/ai/docs/llms.txt",
        "registryName": "com.auth0/mcp",
        "capabilities": [
          "auth.oauth",
          "auth.tokens",
          "auth.consent",
          "auth.agent-identity",
          "hitl.approve"
        ],
        "tags": [
          "hosted",
          "freemium",
          "free-tier",
          "no-card",
          "oauth",
          "typescript",
          "python",
          "enterprise",
          "mcp"
        ],
        "lastRelease": "2026-09-18",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 71.5,
          "grade": "BB",
          "agentReady": true,
          "rank": 82,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 3,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 71,
            "maintenance": 74,
            "payments": 30,
            "reliability": 75,
            "schema": 73,
            "security": 88,
            "transparency": 85
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users.",
          "strengths": [
            "Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP",
            "Human approval on a second device for sensitive actions, showing the exact payee or amount",
            "Free plan up to 25,000 monthly active users with no card",
            "Deprecations listed with announcement and end-of-life dates six to seven months apart",
            "Bugcrowd programme, valid security.txt and an Enterprise SLA of 99.99 per cent"
          ],
          "weaknesses": [
            "Only works when Auth0 is the identity provider for your users",
            "Two Token Vault connections on Free and three on Essentials and Professional without the add-on",
            "Log retention of 1 day on Free and 5 days on Essentials is short for an audit trail",
            "No OpenAPI schema for the Authentication API that the exchange uses",
            "Agent SDKs last released in April 2026 (JavaScript) and January 2026 (Python)"
          ],
          "agentNotes": [
            "Turn off refresh token rotation on the application before using the refresh token exchange",
            "Treat a 401 from the exchange as a missing connected account and send the user through the Connected Accounts flow",
            "Pass login_hint when a user has linked two accounts from the same provider",
            "Use CIBA for purchases or deletes and wait for the approval instead of asking in chat",
            "Read X-RateLimit-Reset on a 429 and back off until then"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 3.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 71.5
            }
          ],
          "editorialScores": {
            "ergonomics": 71,
            "maintenance": 74,
            "payments": 30,
            "reliability": 75,
            "schema": 73,
            "security": 88,
            "transparency": 70
          },
          "provenanceScore": 100
        },
        "connect": {
          "install": "npm install @auth0/ai",
          "http": "curl -X POST \"https://$AUTH0_DOMAIN/oauth/token\" \\\n  -d grant_type=urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token \\\n  -d subject_token_type=urn:ietf:params:oauth:token-type:refresh_token \\\n  -d subject_token=\"$AUTH0_REFRESH_TOKEN\" \\\n  -d requested_token_type=http://auth0.com/oauth/token-type/federated-connection-access-token \\\n  -d connection=google-oauth2 \\\n  -d client_id=\"$AUTH0_CLIENT_ID\" -d client_secret=\"$AUTH0_CLIENT_SECRET\"",
          "config": {
            "mcpServers": {
              "auth0": {
                "args": [
                  "-y",
                  "@auth0/auth0-mcp-server",
                  "run"
                ],
                "command": "npx"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/auth.oauth",
          "tool": "https://letme.dev/auth0-ai-agents"
        },
        "area": "agent-runtime",
        "provenance": {
          "legalEntity": "Okta, Inc.",
          "domain": "auth0.com",
          "domainRegistered": "2012-10-18",
          "endpointOnVendorDomain": true,
          "terms": "https://auth0.com/legal",
          "privacy": "https://www.okta.com/privacy-policy/",
          "statusPage": "https://status.auth0.com",
          "changelog": "https://auth0.com/changelog",
          "securityTxt": "valid",
          "checked": "2026-09-30",
          "notes": [
            "We couldn't read the terms page on 2026-09-30.",
            "The Auth0 MCP server (@auth0/auth0-mcp-server, version 0.1.0-beta.19) manages your tenant. It isn't how an agent gets user tokens."
          ],
          "score": 100
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.json",
        "live": {
          "slug": "auth0-ai-agents",
          "probe": {
            "target": "https://{tenant}.auth0.com/oauth/token",
            "method": "get",
            "lastAt": "2026-10-04T22:35:19.072174881Z",
            "lastOk": false,
            "lastStatus": 0,
            "lastMs": 0,
            "lastNote": "invalid character \"{\" in host name",
            "authRequired": false,
            "uptime24h": 0,
            "uptime30d": 0,
            "p50ms24h": 0,
            "p95ms24h": 0,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 0
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 0
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 0
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 0
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.auth0.com",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-04T21:39:49.238514327Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "auth0/auth0-ai-js",
              "version": "@auth0/ai-vercel-v5.1.1",
              "released": "2026-04-22",
              "seenAt": "2026-10-04T16:21:15.912325367Z"
            },
            {
              "registry": "mcp-registry",
              "name": "com.auth0/mcp",
              "version": "0.1.0-beta.10",
              "seenAt": "2026-10-03T23:29:28.630222764Z"
            },
            {
              "registry": "npm",
              "name": "@auth0/ai",
              "version": "6.0.2",
              "seenAt": "2026-10-04T16:21:08.539398106Z"
            },
            {
              "registry": "npm",
              "name": "@auth0/ai-langchain",
              "version": "5.0.2",
              "seenAt": "2026-10-04T16:21:10.728760999Z"
            },
            {
              "registry": "npm",
              "name": "@auth0/ai-vercel",
              "version": "5.1.1",
              "seenAt": "2026-10-04T16:21:11.90752887Z"
            },
            {
              "registry": "npm",
              "name": "@auth0/auth0-mcp-server",
              "version": "0.1.0-beta.19",
              "seenAt": "2026-10-04T16:21:14.12298902Z"
            },
            {
              "registry": "pypi",
              "name": "auth0-ai",
              "version": "1.0.2",
              "released": "2026-01-20",
              "seenAt": "2026-10-04T16:21:13.941984722Z"
            }
          ],
          "githubStars": 16,
          "npmWeekly": 2628,
          "pypiWeekly": 281,
          "securityTxt": {
            "url": "https://auth0.com/.well-known/security.txt",
            "state": "valid",
            "expires": "2027-01-01T08:00:00.000Z",
            "checkedAt": "2026-10-04T15:15:55.13396602Z"
          },
          "llmsTxt": {
            "url": "https://auth0.com/ai/docs/llms.txt",
            "ok": false,
            "status": 404,
            "checkedAt": "2026-10-04T15:17:16.736611989Z"
          },
          "domain": {
            "domain": "auth0.com",
            "registered": "2012-10-18",
            "source": "https://rdap.verisign.com/com/v1/domain/auth0.com",
            "checkedAt": "2026-10-04T13:06:20.951498912Z"
          },
          "pages": [
            {
              "url": "https://auth0.com/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:41:20.178814118Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "2ecd4d6660eb"
            },
            {
              "url": "https://auth0.com/pricing",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:41:22.566960863Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "8730de5a8d15"
            },
            {
              "url": "https://raw.githubusercontent.com/auth0/docs-v2/main/main/.mintlify/skills/auth0/references/feature-audit-pricing/index.md",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:47:29.254754697Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "d3bbfc00df65"
            },
            {
              "url": "https://www.okta.com/privacy-policy/",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:51:31.687421551Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "be09b03a3016"
            },
            {
              "url": "https://auth0.com/legal",
              "kind": "terms",
              "status": 0,
              "checkedAt": "2026-10-04T15:41:22.56694968Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "blockedByRobots": true
            }
          ],
          "updatedAt": "2026-10-04T22:35:19.072174881Z"
        }
      },
      {
        "slug": "nango",
        "name": "Nango",
        "vendor": "Nango",
        "vendorUrl": "https://www.nango.dev",
        "kind": "http-api",
        "category": "agent-auth",
        "summary": "Source-available integration platform that handles OAuth, API keys and token refresh for 1,000+ APIs on behalf of your users.",
        "url": "https://www.anchorterminal.com/tools/nango",
        "markdownUrl": "https://www.anchorterminal.com/tools/nango.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nango.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nango.json",
        "repo": "https://github.com/NangoHQ/nango",
        "license": "Elastic License 2.0",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://api.nango.dev",
        "packages": [
          {
            "registry": "npm",
            "name": "@nangohq/node"
          },
          {
            "registry": "npm",
            "name": "@nangohq/frontend"
          }
        ],
        "auth": "mixed",
        "authNotes": "Backend calls take an environment secret key as `Authorization: Bearer $NANGO_SECRET_KEY`, and API keys can be scoped (agent sessions need `environment:agent_sessions:write`). End users connect through a short-lived connect session token in the Connect UI. An agent session returns its own MCP URL and `session_token`, sent as a Bearer token. The Management MCP at mcp.nango.dev signs in with OAuth.",
        "pricing": "freemium",
        "pricingNotes": "Three plans since 2 September 2026. Free is $0 with 10 connections, 10 compute hours and 10 GB of data transfer a month and no card. Pay-as-you-go is $50 a month returned as $50 of usage credits, then $0.29 per connection a month, $0.72 per compute hour and $0.50 per GB. The Growth add-on is $450 a month and adds faster integration delivery (5 days instead of 20) and a private Slack channel, and the changelog of 2 September also puts RBAC, OpenTelemetry export, Connect UI branding, SAML SSO for your team and a HIPAA BAA under it. Enterprise is custom, with connections from $0.01 at volume, 2-day integration delivery, BYOC and self-hosting, dedicated SLAs, and the pricing page lists HIPAA, SAML SSO, SCIM and the audit trail there (https://www.nango.dev/pricing, https://nango.dev/docs/updates/changelog). Free self-hosting covers auth and proxy only, with no MCP server, syncs or webhooks (https://nango.dev/docs/guides/platform/free-self-hosting).",
        "priceSummary": "$50 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": null,
          "npmWeekly": 469086,
          "pypiWeekly": null,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://nango.dev/docs",
        "llmsTxt": "https://nango.dev/docs/llms.txt",
        "openapi": "https://raw.githubusercontent.com/NangoHQ/nango/master/docs/spec.yaml",
        "capabilities": [
          "auth.oauth",
          "auth.tokens",
          "auth.consent",
          "auth.audit",
          "agent.tools",
          "automation.embedded"
        ],
        "tags": [
          "hosted",
          "self-hosted",
          "freemium",
          "free-tier",
          "mcp",
          "llms-txt",
          "openapi",
          "oauth",
          "typescript",
          "webhooks",
          "source-available",
          "enterprise"
        ],
        "lastRelease": "2026-09-30",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 67.9,
          "grade": "B",
          "agentReady": false,
          "rank": 135,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 4,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 74,
            "maintenance": 90,
            "payments": 40,
            "reliability": 78,
            "schema": 85,
            "security": 67,
            "transparency": 78
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": -5,
          "negativeNotes": [
            "2026-09-04, CVE-2026-9317 (CVSS 9.2). The runner's tRPC server in Nango before 0.71.6 didn't enforce RUNNER_SECRET_KEY, so anyone who could reach the runner port could run arbitrary JavaScript. Fixed in 0.71.6. Recent and critical, though it needs network access to the runner (https://github.com/advisories/GHSA-9cph-w8mv-q56r)",
            "2026-09-16, CVE-2026-92804 (high). Nango through 0.70.4 didn't validate caller-supplied connection configuration values. Fixed in later releases. Together with the runner flaw we deduct 5, less than the maximum because both are fixed and disclosed (https://github.com/advisories/GHSA-29mm-6vmq-g8cg)"
          ],
          "verdict": "1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.",
          "strengths": [
            "1,000+ APIs with OAuth, API key and client-credentials auth handled",
            "Per-tenant agent sessions served as an MCP server, credentials never shown to the agent",
            "Encryption, retention and deletion rules published in the docs",
            "Per-unit prices in public ($0.29 a connection a month) and a free plan with no card",
            "Source on GitHub under ELv2, 31 open issues against more than 7,000 filed"
          ],
          "weaknesses": [
            "Audit trail only on Enterprise, and logs kept 15 days on every plan",
            "Two CVEs fixed in September 2026, one critical, neither on Nango's own advisory page",
            "Status page tracks a single component",
            "No prompt-injection guidance for content agent sessions pass through",
            "ELv2 bars offering Nango itself as a hosted service"
          ],
          "agentNotes": [
            "Create one agent session per tenant from your backend and pass only the mcp_url and session_token to the agent",
            "Tag connections with your own user and organisation IDs so sessions can select them",
            "Listen for the refresh-failure webhook and send the user a reconnect link instead of retrying",
            "Read the rate-limit headers on a 429 and wait for the reset before resuming",
            "Run 0.71.6 or later when self-hosting, and keep the runner port off the network"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 3.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 67.9
            }
          ],
          "editorialScores": {
            "ergonomics": 74,
            "maintenance": 90,
            "payments": 40,
            "reliability": 78,
            "schema": 85,
            "security": 67,
            "transparency": 63
          },
          "provenanceScore": 92
        },
        "connect": {
          "install": "npm install @nangohq/node",
          "http": "curl -X POST https://api.nango.dev/connect/sessions -H \"Authorization: Bearer $NANGO_SECRET_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"tags\":{\"end_user_id\":\"user-123\"}}'",
          "claudeCode": "claude mcp add --transport http nango-management --scope user https://mcp.nango.dev/mcp",
          "config": {
            "mcpServers": {
              "nango-management": {
                "url": "https://mcp.nango.dev/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/auth.oauth",
          "tool": "https://letme.dev/nango"
        },
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "Pay-as-you-go subscription",
            "unit": "month",
            "usd": 50,
            "note": "Returned as $50 of usage credits each month"
          },
          {
            "item": "Connection on Pay-as-you-go",
            "unit": "account-month",
            "usd": 0.29,
            "note": "Per connected end-user account per month"
          },
          {
            "item": "Data transfer on Pay-as-you-go",
            "unit": "gb",
            "usd": 0.5,
            "note": "10 GB a month free. Compute is $0.72 an hour"
          },
          {
            "item": "Growth add-on",
            "unit": "month",
            "usd": 450,
            "note": "Faster integration delivery, private Slack, RBAC, branding, SAML SSO, HIPAA BAA"
          }
        ],
        "provenance": {
          "legalEntity": "Nango Inc",
          "domain": "nango.dev",
          "domainRegistered": "2022-05-31",
          "endpointOnVendorDomain": true,
          "terms": "https://www.nango.dev/terms",
          "privacy": "https://www.nango.dev/privacy-policy",
          "statusPage": "https://status.nango.dev",
          "changelog": "https://nango.dev/docs/updates/changelog",
          "securityTxt": "valid",
          "checked": "2026-10-01",
          "notes": [
            "The legal entity comes from the copyright line in the repository's LICENSE_SHORT, because we couldn't read the terms page on 2026-09-30.",
            "SECURITY.md asks for reports to security@nango.dev or a private GitHub advisory. The Trust Center at trust.nango.dev holds the SOC 2 report.",
            "status.nango.dev is a Better Stack page with one component, Nango Cloud Health."
          ],
          "score": 92
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/nango.json",
        "live": {
          "slug": "nango",
          "probe": {
            "target": "https://api.nango.dev",
            "method": "get",
            "lastAt": "2026-10-04T22:35:27.249237971Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 454,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 448,
            "p95ms24h": 527,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 109
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.nango.dev",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-04T21:40:15.983421149Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "NangoHQ/nango",
              "version": "v0.71.12",
              "released": "2026-10-02",
              "seenAt": "2026-10-04T16:34:17.295643211Z"
            },
            {
              "registry": "npm",
              "name": "@nangohq/frontend",
              "version": "0.71.12",
              "seenAt": "2026-10-04T16:34:15.84943577Z"
            },
            {
              "registry": "npm",
              "name": "@nangohq/node",
              "version": "0.71.12",
              "seenAt": "2026-10-04T16:34:15.032017504Z"
            }
          ],
          "githubStars": 12512,
          "npmWeekly": 605062,
          "securityTxt": {
            "url": "https://nango.dev/.well-known/security.txt",
            "state": "valid",
            "expires": "2027-12-31T23:59:59.000Z",
            "checkedAt": "2026-10-04T15:15:47.082341179Z"
          },
          "llmsTxt": {
            "url": "https://nango.dev/docs/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:18:02.723630139Z"
          },
          "domain": {
            "domain": "nango.dev",
            "registered": "2022-05-31",
            "source": "https://pubapi.registry.google/rdap/domain/nango.dev",
            "checkedAt": "2026-10-04T13:09:24.044829714Z"
          },
          "pages": [
            {
              "url": "https://nango.dev/docs/updates/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:46:08.862094314Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "5d603945f9f6"
            },
            {
              "url": "https://www.nango.dev/pricing",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:51:25.76214842Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "de303d4e1a64"
            },
            {
              "url": "https://www.nango.dev/privacy-policy",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:51:28.18451084Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "2b1d4741bc37"
            },
            {
              "url": "https://www.nango.dev/terms",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-04T15:51:30.200662946Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "b8fadd3f9456"
            }
          ],
          "updatedAt": "2026-10-04T22:35:27.249237971Z"
        }
      },
      {
        "slug": "arcade",
        "name": "Arcade.dev",
        "vendor": "Arcade.dev",
        "vendorUrl": "https://www.arcade.dev",
        "kind": "http-api",
        "category": "agent-auth",
        "summary": "MCP runtime built around per-user authorisation.",
        "url": "https://www.anchorterminal.com/tools/arcade",
        "markdownUrl": "https://www.anchorterminal.com/tools/arcade.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/arcade.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/arcade.json",
        "repo": "https://github.com/ArcadeAI/arcade-mcp",
        "license": "MIT (arcade-mcp framework and SDKs), platform closed",
        "transports": [
          "http",
          "streamable-http",
          "stdio"
        ],
        "remoteUrl": "https://api.arcade.dev",
        "packages": [
          {
            "registry": "npm",
            "name": "@arcadeai/arcadejs"
          },
          {
            "registry": "pypi",
            "name": "arcadepy"
          },
          {
            "registry": "pypi",
            "name": "arcade-mcp"
          }
        ],
        "auth": "mixed",
        "authNotes": "REST calls take the project key as `Authorization: Bearer $ARCADE_API_KEY` and name the end user with `user_id`. MCP gateways sign end users in with OAuth, either Arcade Auth (project members only) or a User Source pointing at your own OIDC provider. Clients that can't run OAuth can send the API key plus an `Arcade-User-ID` header instead.",
        "pricing": "freemium",
        "pricingNotes": "Free is $0 with 2,000 auth events and 2,000 tool calls a month, no card, community support. Team is a $25 a month platform fee plus $0.10 per auth event and $0.01 per tool call, with next-business-day email support. Enterprise is custom, with annual bundles, deployment in your VPC or air-gapped, SSO, RBAC and a dedicated forward-deployed engineer (https://www.arcade.dev/pricing). The pricing page doesn't define an auth event.",
        "priceSummary": "$25 / mo",
        "where": "both",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 1043,
          "npmWeekly": 124858,
          "pypiWeekly": 70222,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://docs.arcade.dev",
        "llmsTxt": "https://docs.arcade.dev/llms.txt",
        "openapi": "https://api.arcade.dev/v1/swagger",
        "capabilities": [
          "auth.oauth",
          "auth.tokens",
          "auth.consent",
          "auth.audit",
          "agent.tools"
        ],
        "tags": [
          "hosted",
          "freemium",
          "free-tier",
          "no-card",
          "mcp",
          "llms-txt",
          "openapi",
          "oauth",
          "python",
          "typescript",
          "enterprise",
          "self-hosted"
        ],
        "lastRelease": "2026-09-25",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 67,
          "grade": "B",
          "agentReady": false,
          "rank": 147,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 5,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 79,
            "maintenance": 74,
            "payments": 40,
            "reliability": 63,
            "schema": 82,
            "security": 71,
            "transparency": 72
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": -2,
          "negativeNotes": [
            "2025-12-02, CVE-2025-66454 (GHSA-g2jx-37x6-6438, CVSS 6.5). The HTTP worker in arcade-mcp shipped a hardcoded default worker secret, so anyone could forge a token and list or call every tool on a self-hosted worker set up by the official guide. Fixed in 1.9.1 and disclosed in public, so we deduct 2 of a possible 15 (https://github.com/ArcadeAI/arcade-mcp/security/advisories/GHSA-g2jx-37x6-6438)"
          ],
          "verdict": "Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.",
          "strengths": [
            "Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token",
            "33 built-in auth providers plus generic OAuth 2.0, and hosted MCP gateways that sign users in through your own OIDC provider",
            "OpenAPI 3.0 file with 39 paths, llms.txt and a typed tool error hierarchy with retry hints",
            "Per-call prices in public, $0.01 a tool call and $0.10 an auth event, with 2,000 of each free and no card",
            "Valid security.txt, a SOC 2 Type 2 report and a CVE fixed through a public advisory"
          ],
          "weaknesses": [
            "The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise",
            "Tool inputs and results are training data for up to 5 years unless the organisation opts out",
            "No published rate limits for the authorise or execute calls, and no 429 in the OpenAPI file",
            "The public changelog's latest entry is 26 July 2026 and arcadepy hasn't been released since 6 November 2025",
            "Hosting in the United States only outside Enterprise"
          ],
          "agentNotes": [
            "Call `POST /v1/tools/authorize` first and send the user the returned URL when the status isn't completed",
            "Pass a stable user ID from your own database as user_id, never a shared value",
            "Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again",
            "Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project",
            "Revoke a user's access with `DELETE /v1/admin/user_connections/{id}`"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 67
            }
          ],
          "editorialScores": {
            "ergonomics": 79,
            "maintenance": 74,
            "payments": 40,
            "reliability": 63,
            "schema": 82,
            "security": 71,
            "transparency": 47
          },
          "provenanceScore": 96
        },
        "connect": {
          "install": "npm install @arcadeai/arcadejs",
          "http": "curl -X POST https://api.arcade.dev/v1/tools/authorize -H \"Authorization: Bearer $ARCADE_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"tool_name\":\"Gmail.ListEmails\",\"user_id\":\"user-123\"}'",
          "claudeCode": "claude mcp add --transport http arcade https://api.arcade.dev/mcp/\u003cyour-gateway-slug\u003e",
          "config": {
            "mcpServers": {
              "arcade": {
                "url": "https://api.arcade.dev/mcp/\u003cyour-gateway-slug\u003e"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/auth.oauth",
          "tool": "https://letme.dev/arcade"
        },
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "Team plan platform fee",
            "unit": "month",
            "usd": 25,
            "note": "Usage billed on top"
          },
          {
            "item": "Tool call on Team",
            "unit": "call",
            "usd": 0.01,
            "note": "After the included allowance. Auth events are $0.10 each"
          }
        ],
        "provenance": {
          "legalEntity": "Arcade AI, Inc.",
          "domain": "arcade.dev",
          "domainRegistered": "2019-03-26",
          "endpointOnVendorDomain": true,
          "terms": "https://www.arcade.dev/terms-of-service",
          "privacy": "https://www.arcade.dev/privacy-policy",
          "statusPage": "https://status.arcade.dev",
          "changelog": "https://docs.arcade.dev/en/references/changelog",
          "securityTxt": "valid",
          "checked": "2026-09-30",
          "notes": [
            "The terms (effective 15 July 2025) name Arcade AI, Inc. and California law."
          ],
          "score": 96
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/arcade.json",
        "live": {
          "slug": "arcade",
          "probe": {
            "target": "https://api.arcade.dev",
            "method": "get",
            "lastAt": "2026-10-04T22:35:18.85887346Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 631,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 601,
            "p95ms24h": 928,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 109
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.arcade.dev",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T22:33:46.700569213Z"
          },
          "versions": [
            {
              "registry": "npm",
              "name": "@arcadeai/arcadejs",
              "version": "2.4.1",
              "seenAt": "2026-10-04T16:20:45.579808808Z"
            },
            {
              "registry": "pypi",
              "name": "arcade-mcp",
              "version": "1.16.1",
              "released": "2026-09-25",
              "seenAt": "2026-10-04T16:20:46.731244096Z"
            },
            {
              "registry": "pypi",
              "name": "arcadepy",
              "version": "1.10.0",
              "released": "2025-11-06",
              "seenAt": "2026-10-04T16:20:46.538925772Z"
            }
          ],
          "githubStars": 1044,
          "npmWeekly": 147047,
          "pypiWeekly": 89070,
          "securityTxt": {
            "url": "https://arcade.dev/.well-known/security.txt",
            "state": "valid",
            "expires": "2027-07-20T00:00:00Z",
            "checkedAt": "2026-10-04T15:15:42.588411925Z"
          },
          "llmsTxt": {
            "url": "https://docs.arcade.dev/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:15.279748511Z"
          },
          "domain": {
            "domain": "arcade.dev",
            "registered": "2019-03-26",
            "source": "https://pubapi.registry.google/rdap/domain/arcade.dev",
            "checkedAt": "2026-10-04T13:09:09.815000281Z"
          },
          "pages": [
            {
              "url": "https://docs.arcade.dev/en/references/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:43:12.967090689Z",
              "changedAt": "2026-10-03T15:31:20.862139392Z",
              "fingerprint": "fed6349730bd"
            },
            {
              "url": "https://www.arcade.dev/pricing",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-04T15:49:11.688685765Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "0965f63267b5"
            },
            {
              "url": "https://www.arcade.dev/privacy-policy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:49:13.767168196Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "03308f7a2c1b"
            },
            {
              "url": "https://www.arcade.dev/terms-of-service",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-04T15:49:15.77318424Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "afaf24fae3e3"
            }
          ],
          "updatedAt": "2026-10-04T22:35:18.85887346Z"
        }
      },
      {
        "slug": "pipedream",
        "name": "Pipedream API + MCP",
        "vendor": "Pipedream (Workday)",
        "vendorUrl": "https://pipedream.com",
        "kind": "http-api",
        "category": "workflow-automation",
        "summary": "Code-first workflows in Node.js, Python, Go and Bash, plus Connect, an API and SDK that runs 10,000+ prebuilt actions across 3,000+ apps on behalf of your own users with managed OAuth.",
        "url": "https://www.anchorterminal.com/tools/pipedream",
        "markdownUrl": "https://www.anchorterminal.com/tools/pipedream.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/pipedream.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/pipedream.json",
        "repo": "https://github.com/PipedreamHQ/pipedream",
        "license": "Pipedream Source Available License (components)",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://api.pipedream.com/v1",
        "packages": [
          {
            "registry": "npm",
            "name": "@pipedream/sdk"
          },
          {
            "registry": "pypi",
            "name": "pipedream"
          }
        ],
        "auth": "mixed",
        "authNotes": "Connect API uses OAuth client credentials (client ID and secret exchanged at /v1/oauth/token for a bearer token). End users connect their accounts through short-lived Connect tokens. The developer MCP server at https://remote.mcp.pipedream.net/v3 takes the bearer token plus `x-pd-project-id`, `x-pd-environment` and `x-pd-external-user-id` headers. The end-user server at https://mcp.pipedream.net/v2 signs in with OAuth.",
        "pricing": "freemium",
        "pricingNotes": "Billed in credits, one credit per 30 seconds of compute at 256 MB (more memory costs more). Tool calls through MCP, action runs, deployed trigger emissions and proxy requests cost credits, listing apps and tools doesn't. Free $0 with a daily credit limit and Connect in development only, no card. Startup $150 a month or $99 a month billed yearly, 10,000 credits a month, extra credits $0.012 each, production Connect with 100 end users included and $2 per extra end user. Business is custom, annual contract only (https://pipedream.com/pricing).",
        "priceSummary": "$150 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 11719,
          "npmWeekly": 587447,
          "pypiWeekly": 327799,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://pipedream.com/docs",
        "llmsTxt": "https://pipedream.com/docs/llms.txt",
        "openapi": "https://pipedream.com/docs/pipedream_openapi_swagger.json",
        "capabilities": [
          "automation.workflows",
          "automation.apps",
          "automation.embedded",
          "automation.code",
          "automation.webhooks",
          "automation.auth",
          "agent.tools"
        ],
        "tags": [
          "hosted",
          "freemium",
          "mcp",
          "llms-txt",
          "openapi",
          "typescript",
          "python",
          "webhooks",
          "enterprise"
        ],
        "lastRelease": "2026-09-02",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 65.8,
          "grade": "B",
          "agentReady": false,
          "rank": 167,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 1,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 73,
            "maintenance": 79,
            "payments": 40,
            "reliability": 65,
            "schema": 74,
            "security": 58,
            "transparency": 78
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "Managed OAuth per end user across 3,000+ apps, through API, SDK or MCP. Public changelog's last entry is 1 October 2025.",
          "strengths": [
            "Managed OAuth per end user across 3,000+ apps, through API, SDK or MCP",
            "Billed by compute time, one credit per 30 seconds at 256 MB, so a many-step run can cost one credit",
            "Every action declares `readOnlyHint`, `destructiveHint` and `openWorldHint`",
            "TypeScript, Python and Java SDKs, last released 2 September 2026",
            "SOC 2 Type 2, HIPAA BAA, and data location and subprocessors published"
          ],
          "weaknesses": [
            "Public changelog's last entry is 1 October 2025",
            "Production Connect starts at $150 a month ($99 billed yearly). Free is development only",
            "No published limit or 429 behaviour for action runs and tool calls",
            "No security.txt, no bug bounty and no prompt-injection guidance",
            "Cloud only, in AWS us-east-1"
          ],
          "agentNotes": [
            "Pass your own user ID as `x-pd-external-user-id` so each user's accounts stay separate",
            "Send `x-pd-app-slug` to load one app's tools rather than 10,000",
            "Use a Connect rate-limit token (`x-pd-rate-limit`) to cap runaway loops per user",
            "Check `isError` on tool results before treating a call as done",
            "Stay on `x-pd-environment: development` until billing is set, since production needs a paid plan"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 65.8
            }
          ],
          "editorialScores": {
            "ergonomics": 73,
            "maintenance": 79,
            "payments": 40,
            "reliability": 65,
            "schema": 74,
            "security": 58,
            "transparency": 65
          },
          "provenanceScore": 90
        },
        "connect": {
          "http": "curl -X POST https://api.pipedream.com/v1/oauth/token -H \"Content-Type: application/json\" \\\n  -d \"{\\\"grant_type\\\":\\\"client_credentials\\\",\\\"client_id\\\":\\\"$PIPEDREAM_CLIENT_ID\\\",\\\"client_secret\\\":\\\"$PIPEDREAM_CLIENT_SECRET\\\"}\"\ncurl \"https://api.pipedream.com/v1/connect/apps?q=slack\" -H \"Authorization: Bearer $PIPEDREAM_ACCESS_TOKEN\"",
          "claudeCode": "claude mcp add --transport http pipedream https://mcp.pipedream.net/v2",
          "config": {
            "mcpServers": {
              "pipedream": {
                "headers": {
                  "Authorization": "Bearer ${PIPEDREAM_ACCESS_TOKEN}",
                  "x-pd-app-slug": "slack",
                  "x-pd-environment": "development",
                  "x-pd-external-user-id": "${USER_ID}",
                  "x-pd-project-id": "${PIPEDREAM_PROJECT_ID}"
                },
                "url": "https://remote.mcp.pipedream.net/v3"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/automation.workflows",
          "tool": "https://letme.dev/pipedream"
        },
        "alsoIn": [
          "agent-auth"
        ],
        "area": "business",
        "unitPrices": [
          {
            "item": "Startup plan",
            "unit": "month",
            "usd": 150,
            "note": "$99 a month billed yearly. 10,000 credits and production Connect with 100 end users"
          },
          {
            "item": "Extra credit",
            "unit": "credit",
            "usd": 0.012,
            "note": "one credit is 30 seconds of compute at 256 MB"
          },
          {
            "item": "Extra end user",
            "unit": "user-month",
            "usd": 2,
            "note": "beyond the 100 included on Startup"
          }
        ],
        "provenance": {
          "legalEntity": "Pipedream, LLC",
          "domain": "pipedream.com",
          "domainRegistered": "1998-06-01",
          "domainNote": "pipedream.com was registered in 1998, well before the company was founded.",
          "endpointOnVendorDomain": true,
          "terms": "https://pipedream.com/terms",
          "privacy": "https://pipedream.com/privacy",
          "statusPage": "https://status.pipedream.com",
          "changelog": "https://pipedream.com/docs/changelog",
          "securityTxt": "none",
          "checked": "2026-10-01",
          "notes": [
            "The terms, last updated 30 September 2026, name Pipedream, LLC, a Delaware limited liability company, and point Workday customers to Workday's early access scheme. Workday agreed to buy Pipedream in November 2025."
          ],
          "score": 90
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/pipedream.json",
        "live": {
          "slug": "pipedream",
          "probe": {
            "target": "https://api.pipedream.com/v1",
            "method": "get",
            "lastAt": "2026-10-04T22:35:28.845258092Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 333,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 337,
            "p95ms24h": 398,
            "samples24h": 272,
            "samples30d": 1086,
            "days": [
              {
                "date": "2026-09-30",
                "probes": 35,
                "ok": 35
              },
              {
                "date": "2026-10-01",
                "probes": 276,
                "ok": 276
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.pipedream.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T22:34:05.751119055Z"
          },
          "versions": [
            {
              "registry": "npm",
              "name": "@pipedream/sdk",
              "version": "3.1.6",
              "seenAt": "2026-10-04T16:36:35.684775925Z"
            },
            {
              "registry": "pypi",
              "name": "pipedream",
              "version": "2.1.20",
              "released": "2026-09-02",
              "seenAt": "2026-10-04T16:36:36.554973153Z"
            }
          ],
          "githubStars": 11724,
          "npmWeekly": 628729,
          "pypiWeekly": 423275,
          "securityTxt": {
            "url": "https://pipedream.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:41.429747478Z"
          },
          "llmsTxt": {
            "url": "https://pipedream.com/docs/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:18:06.906170195Z"
          },
          "domain": {
            "domain": "pipedream.com",
            "registered": "1998-06-01",
            "source": "https://rdap.verisign.com/com/v1/domain/pipedream.com",
            "checkedAt": "2026-10-04T13:06:14.75079587Z"
          },
          "pages": [
            {
              "url": "https://pipedream.com/docs/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:46:40.0311865Z",
              "changedAt": "2026-10-02T15:22:54.204376413Z",
              "fingerprint": "85598021dd17"
            },
            {
              "url": "https://pipedream.com/pricing",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:46:42.503230545Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "d35da09334d8"
            },
            {
              "url": "https://pipedream.com/privacy",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:46:44.304778654Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "333facaf775d"
            },
            {
              "url": "https://pipedream.com/terms",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-04T15:46:46.316335344Z",
              "changedAt": "2026-10-02T15:23:00.580870679Z",
              "fingerprint": "b8807ffb4738"
            }
          ],
          "updatedAt": "2026-10-04T22:35:28.845258092Z"
        }
      },
      {
        "slug": "stytch-connected-apps",
        "name": "Stytch Connected Apps",
        "vendor": "Stytch (Twilio)",
        "vendorUrl": "https://stytch.com/connected-apps",
        "kind": "http-api",
        "category": "agent-auth",
        "summary": "Turns a Stytch project into an OAuth 2.1 and OIDC authorisation server so agents and MCP clients can act for your users.",
        "url": "https://www.anchorterminal.com/tools/stytch-connected-apps",
        "markdownUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json",
        "repo": "https://github.com/stytchauth/stytch-node",
        "license": "MIT (SDKs), platform closed",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://api.stytch.com",
        "packages": [
          {
            "registry": "npm",
            "name": "stytch"
          },
          {
            "registry": "pypi",
            "name": "stytch"
          }
        ],
        "auth": "mixed",
        "authNotes": "Backend calls use HTTP basic auth with the project ID as the user and the secret as the password against api.stytch.com (test.stytch.com for test projects). Agents and MCP clients go through OAuth 2.1: metadata at `{project-domain}/.well-known/oauth-authorization-server`, registration at `/v1/oauth2/register` with no credentials, the token endpoint at `/v1/oauth2/token`, and PKCE with S256 required for public clients. The end user must already have a Stytch session when the consent page loads.",
        "pricing": "freemium",
        "pricingNotes": "Pay as you go starts at $0 with 10,000 monthly active users (people and AI agents count the same), unlimited organisations, 5 SSO or SCIM connections and 1,000 M2M tokens a month. Extra SSO or SCIM connections are $125 each, brand removal and full email customisation is a $99 one-off, and fraud fingerprints are $0.005 each after 10,000. Enterprise is custom, with volume discounts, unlimited SSO and SCIM, a 99.99 per cent SLA, a HIPAA BAA and a private Slack channel. Connected Apps has no separate line and bills through MAU (https://stytch.com/pricing, https://stytch.com/connected-apps). The page doesn't state the per-MAU overage price or whether a card is needed.",
        "priceSummary": "$125 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 116,
          "npmWeekly": 349007,
          "pypiWeekly": null,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://stytch.com/docs/connected-apps/guides/mcp-auth-overview",
        "llmsTxt": "https://stytch.com/docs/llms.txt",
        "capabilities": [
          "auth.oauth",
          "auth.consent",
          "auth.agent-identity",
          "auth.tokens"
        ],
        "tags": [
          "hosted",
          "freemium",
          "free-tier",
          "oauth",
          "llms-txt",
          "typescript",
          "python",
          "enterprise"
        ],
        "lastRelease": "2026-08-14",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 60.8,
          "grade": "C",
          "agentReady": false,
          "rank": 241,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 6,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 65,
            "maintenance": 62,
            "payments": 20,
            "reliability": 73,
            "schema": 64,
            "security": 66,
            "transparency": 66
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens.",
          "strengths": [
            "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box",
            "Revoke an app's access and all its tokens for a user with one API call",
            "Consent screen built from RBAC roles, so agents only see grantable scopes",
            "10,000 monthly active users free, agents counted as users",
            "No incidents on the OAuth endpoints on the status page since 1 July 2026"
          ],
          "weaknesses": [
            "No outbound token vault, so it can't hold your users' third-party tokens",
            "Node, Python, Go and Ruby SDKs last tagged 24 June 2026, and the docs changelog last moved on 14 August",
            "No published rate limits for the OAuth, registration or token endpoints",
            "No audit log of grants and revocations that we could find",
            "No security.txt, and Twilio's certifications page doesn't mention Stytch"
          ],
          "agentNotes": [
            "Fetch `{project-domain}/.well-known/oauth-authorization-server` first and use the endpoints it returns, not hard-coded paths",
            "Register with `token_endpoint_auth_method` none and PKCE S256 when the agent can't keep a secret",
            "Expect a 401 with protected resource metadata from the MCP server, then register and authorise",
            "Ask only for scopes the user's roles can grant, or the consent page will refuse them",
            "Back off exponentially on a 429, since no Retry-After header is documented"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 3,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 60.8
            }
          ],
          "editorialScores": {
            "ergonomics": 65,
            "maintenance": 62,
            "payments": 20,
            "reliability": 73,
            "schema": 64,
            "security": 66,
            "transparency": 42
          },
          "provenanceScore": 90
        },
        "connect": {
          "install": "npm install stytch",
          "http": "curl -X POST https://api.stytch.com/v1/connected_apps/clients \\\n  -u \"$STYTCH_PROJECT_ID:$STYTCH_SECRET\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"client_type\":\"third_party_public\",\"client_name\":\"My agent\",\"redirect_urls\":[\"https://example.com/callback\"]}'"
        },
        "letme": {
          "capability": "https://letme.dev/auth.oauth",
          "tool": "https://letme.dev/stytch-connected-apps"
        },
        "sameCompany": [
          "twilio-voice",
          "sendgrid",
          "twilio"
        ],
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "SSO or SCIM connection above 5",
            "unit": "month",
            "usd": 125,
            "note": "Per connection per month on Pay as you go"
          },
          {
            "item": "Fraud fingerprint above 10,000",
            "unit": "call",
            "usd": 0.005,
            "note": "Optional fraud add-on"
          }
        ],
        "provenance": {
          "legalEntity": "Twilio Inc.",
          "domain": "stytch.com",
          "domainRegistered": "2014-04-25",
          "endpointOnVendorDomain": true,
          "terms": "https://www.twilio.com/en-us/legal/tos",
          "privacy": "https://www.twilio.com/en-us/legal/privacy",
          "statusPage": "https://status.stytch.com",
          "changelog": "https://stytch.com/docs/changelog",
          "securityTxt": "none",
          "checked": "2026-10-02",
          "notes": [
            "stytch.com/legal/terms-of-service and /legal/privacy-policy return 302 redirects to twilio.com. Twilio's terms name Twilio Inc., a Delaware corporation, and link to the last Stytch terms at twilio.com/en-us/legal/tos/stytch-tos.",
            "/.well-known/security.txt returned 404 on 2026-09-30, and stytch.com/security returns 404.",
            "status.stytch.com is an Atlassian Statuspage with an RSS history feed.",
            "The old changelog.stytch.com said on 2 July 2026 that it was moving into the docs. Dated entries continue at stytch.com/docs/changelog, newest 14 August 2026.",
            "Twilio's sub-processor page lists 13 sub-processors for Stytch by Twilio, updated September 2026."
          ],
          "score": 90
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.json",
        "live": {
          "slug": "stytch-connected-apps",
          "probe": {
            "target": "https://api.stytch.com",
            "method": "get",
            "lastAt": "2026-10-04T22:35:31.930773381Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 442,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 441,
            "p95ms24h": 471,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 109
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.stytch.com",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-04T21:40:30.119653254Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "stytchauth/stytch-node",
              "version": "v14.2.0",
              "released": "2026-06-24",
              "seenAt": "2026-10-04T16:40:57.813871092Z"
            },
            {
              "registry": "npm",
              "name": "stytch",
              "version": "14.2.0",
              "seenAt": "2026-10-04T16:40:57.134216114Z"
            },
            {
              "registry": "pypi",
              "name": "stytch",
              "version": "15.3.0",
              "released": "2026-06-24",
              "seenAt": "2026-10-04T16:40:57.623600429Z"
            }
          ],
          "githubStars": 116,
          "npmWeekly": 351245,
          "pypiWeekly": 174452,
          "securityTxt": {
            "url": "https://stytch.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:16:03.361419638Z"
          },
          "llmsTxt": {
            "url": "https://stytch.com/docs/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:18:17.1998257Z"
          },
          "domain": {
            "domain": "stytch.com",
            "registered": "2014-04-25",
            "source": "https://rdap.verisign.com/com/v1/domain/stytch.com",
            "checkedAt": "2026-10-04T13:06:36.74420879Z"
          },
          "pages": [
            {
              "url": "https://stytch.com/docs/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:48:13.995093133Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "156a41d78412"
            },
            {
              "url": "https://stytch.com/pricing",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-04T15:48:17.287254331Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "61105c9b4a8b"
            }
          ],
          "updatedAt": "2026-10-04T22:35:31.930773381Z"
        }
      },
      {
        "slug": "workos-pipes",
        "name": "WorkOS Pipes and Agents",
        "vendor": "WorkOS",
        "vendorUrl": "https://workos.com",
        "kind": "http-api",
        "category": "agent-auth",
        "summary": "WorkOS tools for connecting agents to third-party accounts, managing access tokens and assigning revocable agent identities.",
        "url": "https://www.anchorterminal.com/tools/workos-pipes",
        "markdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/workos-pipes.json",
        "repo": "https://github.com/workos/workos-node",
        "license": "MIT (SDKs), platform closed",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://api.workos.com",
        "packages": [
          {
            "registry": "npm",
            "name": "@workos-inc/node"
          },
          {
            "registry": "pypi",
            "name": "workos"
          }
        ],
        "auth": "mixed",
        "authNotes": "Server calls take the secret key as `Authorization: Bearer $WORKOS_API_KEY` (`sk_...`). End users connect accounts through the Pipes widget or an authorisation URL from `/data-integrations/{slug}/authorize`, which must be opened in the browser, not fetched. Agent tokens are minted from a blueprint as user-delegated, autonomous or agent-delegated sessions. The WorkOS MCP server signs in with OAuth as a dashboard user, with no API key.",
        "pricing": "freemium",
        "pricingNotes": "Pay as you go, with no card to start and a card before production. AuthKit is free up to 1,000,000 monthly active users, then $2,500 a month per extra million. SSO and Directory Sync connections are $125 a month each for the first 15, $100 for 16 to 30, $80 for 31 to 50 and $65 for 51 to 100. Audit Logs are free at the base, with $125 a month per SIEM connection and $99 a month per million events stored. Radar is free for 1,000 checks, then $100 per 50,000. A custom domain is $99 a month. Annual credits plans add volume discounts and a 99.99 per cent SLA (https://workos.com/pricing). Pipes and Agents don't appear on the pricing page, so we don't know what a connection or an agent session costs.",
        "priceSummary": "$125 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 221,
          "npmWeekly": 4041570,
          "pypiWeekly": 1697594,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://workos.com/docs/pipes",
        "registryName": "com.workos/mcp",
        "capabilities": [
          "auth.oauth",
          "auth.tokens",
          "auth.consent",
          "auth.agent-identity",
          "auth.audit"
        ],
        "tags": [
          "hosted",
          "freemium",
          "free-tier",
          "oauth",
          "mcp",
          "typescript",
          "python",
          "enterprise",
          "webhooks"
        ],
        "lastRelease": "2026-09-28",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 60,
          "grade": "C",
          "agentReady": false,
          "rank": 256,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 7,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 69,
            "maintenance": 83,
            "payments": 10,
            "reliability": 70,
            "schema": 53,
            "security": 69,
            "transparency": 64
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.",
          "strengths": [
            "Agent identity with per-session revocation and token lifetimes set per blueprint",
            "Pipes covers 500+ providers with user-owned and organisation-owned connections by OAuth, API key or client credentials",
            "Published rate limits of 6,000 requests a minute per key, with Retry-After on a 429",
            "Same platform for SSO, directory sync, RBAC, Audit Logs and Vault",
            "SOC 2 Type 2, a public subprocessor list and a 99.99 per cent SLA on annual plans"
          ],
          "weaknesses": [
            "21 incidents on the status page since 3 July 2026, several over an hour",
            "Pipes and Agents aren't on the pricing page",
            "Deleting a connected account doesn't revoke the grant at the provider",
            "Breaking Pipes change in SDK 11.0.0 on 28 September 2026",
            "No OpenAPI file, llms.txt or security.txt we could find"
          ],
          "agentNotes": [
            "Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token",
            "Branch on `active` in the response and send the user to reconnect on `needs_reauthorization`",
            "Wait for Retry-After on a 429, or back off with jitter when it's missing",
            "Use lower-case provider slugs such as github or slack",
            "Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 60
            }
          ],
          "editorialScores": {
            "ergonomics": 69,
            "maintenance": 83,
            "payments": 10,
            "reliability": 70,
            "schema": 53,
            "security": 69,
            "transparency": 37
          },
          "provenanceScore": 90
        },
        "connect": {
          "install": "npm install @workos-inc/node",
          "http": "curl -X POST https://api.workos.com/data-integrations/github/token -H \"Authorization: Bearer $WORKOS_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"user_id\":\"user_01EHZNVPK3SFK441A1RGBFSHRT\"}'",
          "claudeCode": "claude mcp add --transport http --scope user workos https://mcp.workos.com/mcp",
          "config": {
            "mcpServers": {
              "workos": {
                "url": "https://mcp.workos.com/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/auth.oauth",
          "tool": "https://letme.dev/workos-pipes"
        },
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "SSO or Directory Sync connection (first 15)",
            "unit": "month",
            "usd": 125,
            "note": "Per connection per month, falling to $65 above 50"
          },
          {
            "item": "Audit Logs SIEM connection",
            "unit": "month",
            "usd": 125,
            "note": "Plus $99 a month per million events stored"
          },
          {
            "item": "Custom domain",
            "unit": "month",
            "usd": 99,
            "note": "AuthKit, Admin Portal and email sender"
          }
        ],
        "provenance": {
          "legalEntity": "WorkOS, Inc.",
          "domain": "workos.com",
          "domainRegistered": "2005-02-02",
          "endpointOnVendorDomain": true,
          "terms": "https://workos.com/legal/terms",
          "privacy": "https://workos.com/legal/privacy",
          "statusPage": "https://status.workos.com",
          "changelog": "https://github.com/workos/workos-node/blob/main/CHANGELOG.md",
          "securityTxt": "none",
          "checked": "2026-09-30",
          "notes": [
            "The website terms (effective 29 October 2020) name WorkOS, Inc. and California law. The privacy policy was updated 20 October 2025 and doesn't say where data is stored.",
            "RDAP shows workos.com registered on 2005-02-02, years before the company, so the domain was bought later.",
            "/.well-known/security.txt returned 404 on 2026-09-30."
          ],
          "score": 90
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/workos-pipes.json",
        "live": {
          "slug": "workos-pipes",
          "probe": {
            "target": "https://api.workos.com",
            "method": "get",
            "lastAt": "2026-10-04T22:35:34.139369409Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 120,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 128,
            "p95ms24h": 187,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 109
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.workos.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T22:34:12.083160062Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "workos/workos-node",
              "version": "v11.0.0",
              "released": "2026-09-28",
              "seenAt": "2026-10-04T16:44:14.997893727Z"
            },
            {
              "registry": "mcp-registry",
              "name": "com.workos/mcp",
              "version": "1.0.0",
              "seenAt": "2026-10-03T23:29:28.630222764Z"
            },
            {
              "registry": "npm",
              "name": "@workos-inc/node",
              "version": "11.0.0",
              "seenAt": "2026-10-04T16:44:14.113290354Z"
            },
            {
              "registry": "pypi",
              "name": "workos",
              "version": "10.5.0",
              "released": "2026-09-24",
              "seenAt": "2026-10-04T16:44:14.80123694Z"
            }
          ],
          "githubStars": 223,
          "npmWeekly": 4341866,
          "pypiWeekly": 1819216,
          "securityTxt": {
            "url": "https://workos.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:42.791540879Z"
          },
          "domain": {
            "domain": "workos.com",
            "registered": "2005-02-02",
            "source": "https://rdap.verisign.com/com/v1/domain/workos.com",
            "checkedAt": "2026-10-04T13:09:49.925296041Z"
          },
          "pages": [
            {
              "url": "https://raw.githubusercontent.com/workos/workos-node/main/CHANGELOG.md",
              "kind": "changelog",
              "status": 304,
              "checkedAt": "2026-10-04T15:48:01.225770024Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "57d8be278609"
            },
            {
              "url": "https://workos.com/pricing",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:48:58.671443903Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "0cdd6961c090"
            },
            {
              "url": "https://workos.com/legal/privacy",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:48:54.606253176Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "5fc970fc9d08"
            },
            {
              "url": "https://workos.com/legal/terms",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-04T15:48:56.692868313Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "8b3130dd8035"
            }
          ],
          "updatedAt": "2026-10-04T22:35:34.139369409Z"
        }
      },
      {
        "slug": "zapier-mcp",
        "name": "Zapier MCP (agent actions)",
        "vendor": "Zapier",
        "vendorUrl": "https://zapier.com/mcp",
        "kind": "mcp",
        "category": "aggregator",
        "summary": "Hosted MCP server that lets agents discover and run actions across apps connected to the user's Zapier account.",
        "url": "https://www.anchorterminal.com/tools/zapier-mcp",
        "markdownUrl": "https://www.anchorterminal.com/tools/zapier-mcp.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zapier-mcp.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zapier-mcp.json",
        "license": "proprietary",
        "transports": [
          "streamable-http"
        ],
        "remoteUrl": "https://mcp.zapier.com/api/v1/connect",
        "packages": [
          {
            "registry": "npm",
            "name": "@zapier/zapier-sdk"
          },
          {
            "registry": "npm",
            "name": "@zapier/zapier-sdk-mcp"
          }
        ],
        "auth": "mixed",
        "authNotes": "OAuth from inside a listed MCP client, where Zapier provisions a server per client at sign-in. Otherwise a long-lived per-server connection token as 'Authorization: Bearer' (a ?token= query form also works, and the docs prefer the header). App credentials stay in Zapier and never reach the model. Each person signs in to their own Zapier account, and MCP Embed lets a product create servers for its users behind an embed secret. Streamable HTTP only, SSE-only clients can't connect.",
        "pricing": "byo-plan",
        "pricingNotes": "No separate MCP bill. Each successful tool call uses 2 tasks from the Zapier plan and failed calls are free. Free has 100 tasks a month (50 calls). Professional starts at $19.99 a month billed annually for 750 tasks, Team at $69 for 2,000 tasks. With pay-per-task on, calls continue past the limit at 1.25x (annual) or 2.5x (monthly) the base rate, otherwise they stop until the cycle resets. The SDK is free during its open beta (https://zapier.com/pricing).",
        "priceSummary": "Your plan",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402 support in Zapier MCP docs or pricing (checked 2026-09-30).",
          "endpoints": []
        },
        "toolCount": 16,
        "popularity": {
          "githubStars": 422,
          "npmWeekly": 238672,
          "pypiWeekly": null,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://docs.zapier.com/mcp/home",
        "llmsTxt": "https://docs.zapier.com/llms.txt",
        "registryName": "com.zapier/mcp",
        "capabilities": [
          "automation.apps",
          "automation.auth",
          "automation.actions",
          "agent.tools"
        ],
        "tags": [
          "official",
          "hosted",
          "oauth",
          "closed-source",
          "aggregator",
          "mcp",
          "llms-txt",
          "freemium",
          "typescript"
        ],
        "lastRelease": "2026-09-29",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 58.4,
          "grade": "C",
          "agentReady": false,
          "rank": 280,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 2,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 67,
            "maintenance": 76,
            "payments": 35,
            "reliability": 48,
            "schema": 64,
            "security": 56,
            "transparency": 76
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "16 meta-tools in agentic mode, or managed mode with only the actions you pick. Connection tokens are long-lived and the docs allow them in the URL query string.",
          "strengths": [
            "16 meta-tools in agentic mode, or managed mode with only the actions you pick",
            "Failed calls and discovery are free, and each successful call costs two tasks",
            "An MCP component on the status page and per-call activity logs for the user",
            "Account-level app and action restrictions apply to MCP, and admins can switch it off per workspace",
            "Free plan with 100 tasks a month and no card"
          ],
          "weaknesses": [
            "Connection tokens are long-lived and the docs allow them in the URL query string",
            "No numeric rate limits and no retry guidance when the task cap is hit",
            "Only Enterprise is opted out of AI training and gets configurable retention",
            "Batch work counts per item, so five rows written is ten tasks",
            "Streamable HTTP only, SSE-only clients can't connect"
          ],
          "agentNotes": [
            "Call discover_zapier_actions and enable_zapier_action before executing, discovery is free and execution costs two tasks",
            "Use execute_zapier_read_action for lookups, keep execute_zapier_write_action for changes",
            "Send the connection token in the `Authorization` header, never in the URL",
            "Count batch writes per item before starting, five rows is ten tasks"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 58.4
            }
          ],
          "editorialScores": {
            "ergonomics": 67,
            "maintenance": 76,
            "payments": 35,
            "reliability": 48,
            "schema": 64,
            "security": 56,
            "transparency": 61
          },
          "provenanceScore": 90
        },
        "connect": {
          "install": "npm install @zapier/zapier-sdk",
          "claudeCode": "claude mcp add --transport http zapier https://mcp.zapier.com/api/v1/connect --header \"Authorization: Bearer ${ZAPIER_MCP_TOKEN}\"",
          "config": {
            "mcpServers": {
              "zapier": {
                "headers": {
                  "Authorization": "Bearer ${ZAPIER_MCP_TOKEN}"
                },
                "url": "https://mcp.zapier.com/api/v1/connect"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/automation.apps",
          "tool": "https://letme.dev/zapier-mcp"
        },
        "alsoIn": [
          "agent-auth"
        ],
        "area": "business",
        "unitPrices": [
          {
            "item": "Professional, 750 tasks",
            "unit": "month",
            "usd": 19.99,
            "note": "billed annually, 375 successful MCP calls"
          },
          {
            "item": "Team, 2,000 tasks",
            "unit": "month",
            "usd": 69,
            "note": "billed annually, 1,000 successful MCP calls"
          }
        ],
        "provenance": {
          "legalEntity": "Zapier Inc.",
          "domain": "zapier.com",
          "domainRegistered": "2011-10-30",
          "endpointOnVendorDomain": true,
          "terms": "https://zapier.com/legal/terms-of-service",
          "privacy": "https://zapier.com/privacy",
          "statusPage": "https://status.zapier.com",
          "changelog": "https://docs.zapier.com/sdk/changelog",
          "securityTxt": "none",
          "checked": "2026-09-30",
          "score": 90
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/zapier-mcp.json",
        "live": {
          "slug": "zapier-mcp",
          "probe": {
            "target": "https://mcp.zapier.com/api/v1/connect",
            "method": "mcp-initialize",
            "lastAt": "2026-10-04T22:35:34.299051458Z",
            "lastOk": true,
            "lastStatus": 401,
            "lastMs": 118,
            "lastNote": "asks for credentials",
            "authRequired": true,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 138,
            "p95ms24h": 345,
            "samples24h": 272,
            "samples30d": 2040,
            "days": [
              {
                "date": "2026-09-27",
                "probes": 132,
                "ok": 132
              },
              {
                "date": "2026-09-28",
                "probes": 285,
                "ok": 285
              },
              {
                "date": "2026-09-29",
                "probes": 286,
                "ok": 286
              },
              {
                "date": "2026-09-30",
                "probes": 286,
                "ok": 286
              },
              {
                "date": "2026-10-01",
                "probes": 276,
                "ok": 276
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.zapier.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T22:34:12.327607852Z"
          },
          "versions": [
            {
              "registry": "mcp-registry",
              "name": "com.zapier/mcp",
              "version": "1.0.1",
              "seenAt": "2026-10-03T23:29:28.630222764Z"
            },
            {
              "registry": "npm",
              "name": "@zapier/zapier-sdk",
              "version": "0.114.3",
              "seenAt": "2026-10-04T16:44:33.986733846Z"
            },
            {
              "registry": "npm",
              "name": "@zapier/zapier-sdk-mcp",
              "version": "0.27.3",
              "seenAt": "2026-10-04T16:44:36.651973579Z"
            }
          ],
          "npmWeekly": 273043,
          "securityTxt": {
            "url": "https://zapier.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:53.191389018Z"
          },
          "llmsTxt": {
            "url": "https://docs.zapier.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:18:22.966709462Z"
          },
          "domain": {
            "domain": "zapier.com",
            "registered": "2011-10-30",
            "source": "https://rdap.verisign.com/com/v1/domain/zapier.com",
            "checkedAt": "2026-10-04T13:07:30.742574303Z"
          },
          "pages": [
            {
              "url": "https://docs.zapier.com/sdk/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:44:21.95311076Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "55cf82d6b763"
            },
            {
              "url": "https://docs.zapier.com/llms.txt",
              "kind": "deprecations",
              "status": 200,
              "checkedAt": "2026-10-04T15:44:19.546133509Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "1f9800993676"
            },
            {
              "url": "https://zapier.com/pricing",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-04T15:53:09.494445283Z",
              "changedAt": "2026-10-04T15:53:09.494445283Z",
              "fingerprint": "e09f312451e5"
            },
            {
              "url": "https://zapier.com/privacy",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:53:11.313488148Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "a335cbd9bdbf"
            },
            {
              "url": "https://zapier.com/legal/terms-of-service",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-04T15:53:06.98495821Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "b01831084feb"
            }
          ],
          "mcpTools": {
            "url": "https://mcp.zapier.com/api/v1/connect",
            "checkedAt": "2026-10-04T22:20:00.991387997Z",
            "status": "auth",
            "note": "asks for credentials before listing its tools",
            "changedAt": "2026-09-28T21:55:55.261094018Z"
          },
          "updatedAt": "2026-10-04T22:35:34.299051458Z"
        }
      },
      {
        "slug": "keycard",
        "name": "Keycard",
        "vendor": "Keycard Labs",
        "vendorUrl": "https://www.keycard.ai",
        "kind": "http-api",
        "category": "agent-auth",
        "summary": "Identity and access platform for AI agents.",
        "url": "https://www.anchorterminal.com/tools/keycard",
        "markdownUrl": "https://www.anchorterminal.com/tools/keycard.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keycard.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keycard.json",
        "repo": "https://github.com/keycardai/python-sdk",
        "license": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://api.keycard.ai",
        "packages": [
          {
            "registry": "pypi",
            "name": "keycardai-mcp"
          },
          {
            "registry": "pypi",
            "name": "keycardai-fastmcp"
          },
          {
            "registry": "npm",
            "name": "@keycardai/mcp"
          },
          {
            "registry": "pypi",
            "name": "keycardai_api"
          }
        ],
        "auth": "mixed",
        "authNotes": "The management API at api.keycard.ai takes `Authorization: Bearer $KEYCARD_API_KEY` (a service account key). Agents and MCP servers talk OAuth 2.0 to their zone at `https://\u003czone-id\u003e.keycard.cloud`, discovered from `/.well-known/oauth-authorization-server`, with PKCE, dynamic client registration and RFC 8693 token exchange against the token endpoint. Application credentials are a client secret, a web identity (OIDC) or EKS workload identity. Tokens are JWTs verified against the zone's JWKS.",
        "pricing": "freemium",
        "pricingNotes": "Starter is free with 5,000 transactions a month as a hard cap, unlimited users, agents and apps, RBAC, ABAC and ReBAC policies, 7-day telemetry retention and community support. Team is $500 a month with 100,000 transactions and $1 per 1,000 after, SSO, zone policy, 90-day retention, email support and an SLA. Enterprise is custom on an annual commitment, with org and device-based policy, SCIM, Active Directory and LDAP provisioning, dedicated, BYOC or on-prem deployment, private networking, customer-managed KMS, 180-day retention, a 99.95 per cent uptime SLA and 1-hour 24/7 response on P1 issues. A transaction is recorded each time Keycard issues a credential, validates an access request or exchanges a credential (https://www.keycard.ai/pricing). The page doesn't say whether a card is needed, and its sign-up form ends with a promise to be in touch. The quickstart calls the product Early Access, with sign-up at console.keycard.ai.",
        "priceSummary": "$500 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 1,
          "npmWeekly": 52,
          "pypiWeekly": null,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://docs.keycard.ai",
        "llmsTxt": "https://docs.keycard.ai/llms.txt",
        "capabilities": [
          "auth.oauth",
          "auth.tokens",
          "auth.consent",
          "auth.agent-identity",
          "auth.audit"
        ],
        "tags": [
          "hosted",
          "freemium",
          "free-tier",
          "oauth",
          "mcp",
          "llms-txt",
          "python",
          "typescript",
          "go",
          "enterprise",
          "self-hosted"
        ],
        "lastRelease": "2026-09-22",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 56.3,
          "grade": "C",
          "agentReady": false,
          "rank": 303,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 8,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 60,
            "maintenance": 79,
            "payments": 30,
            "reliability": 35,
            "schema": 61,
            "security": 86,
            "transparency": 45
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.",
          "strengths": [
            "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange",
            "Delegated grants with RFC 8693 exchange for GitHub, Google, Slack, Linear and any OAuth 2.0 provider",
            "Session timeline and audit log per exchange, exported hourly to S3 in OCSF Parquet",
            "Published per-unit price ($1 per 1,000 transactions on Team) with a transaction defined",
            "Valid security.txt and SOC 2 Type 2 listed in a SafeBase trust centre"
          ],
          "weaknesses": [
            "Early Access with sign-up by request, and no terms of service page",
            "No per-token kill switch, so a revoked grant lives until the token expires, and revocation doesn't reach the provider",
            "No published rate limits, 429 guidance or public changelog",
            "keycardai-mcp went from 1.0.0 to 2.0.0 in a day in August 2026",
            "Team is $500 a month with nothing between it and the free tier"
          ],
          "agentNotes": [
            "Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone",
            "Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange",
            "Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry",
            "Keep credentials short-lived, because revocation only stops the next issuance",
            "Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 56.3
            }
          ],
          "editorialScores": {
            "ergonomics": 60,
            "maintenance": 79,
            "payments": 30,
            "reliability": 35,
            "schema": 61,
            "security": 86,
            "transparency": 25
          },
          "provenanceScore": 65
        },
        "connect": {
          "install": "pip install keycardai-mcp",
          "http": "curl \"https://api.keycard.ai/zones/$KEYCARD_ZONE_ID/sessions\" \\\n  -H \"Authorization: Bearer $KEYCARD_API_KEY\""
        },
        "letme": {
          "capability": "https://letme.dev/auth.oauth",
          "tool": "https://letme.dev/keycard"
        },
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "Team plan",
            "unit": "month",
            "usd": 500,
            "note": "100,000 transactions included"
          },
          {
            "item": "Transactions above 100,000 on Team",
            "unit": "1k-calls",
            "usd": 1,
            "note": "The pricing page doesn't define a transaction"
          }
        ],
        "provenance": {
          "legalEntity": "Keycard Labs, Inc.",
          "domain": "keycard.ai",
          "domainRegistered": "",
          "endpointOnVendorDomain": true,
          "terms": "",
          "privacy": "https://www.keycard.ai/privacy/",
          "statusPage": "https://status.keycard.ai",
          "changelog": "",
          "securityTxt": "valid",
          "checked": "2026-10-02",
          "notes": [
            "The homepage footer names Keycard Labs, Inc., 103 Foulk Road, Suite 202, Wilmington, DE 19808. The footer's legal links on 2 October were privacy, cookie policy, a vulnerability address and the trust centre at trust.keycard.ai. We found no terms of service page (keycard.ai/terms/ returns 404) and the privacy page's body didn't load for us on 30 September or 2 October.",
            "RDAP for keycard.ai returned 404 at rdap.nic.ai and 429 at Identity Digital on 2026-09-30, so the registration date is blank.",
            "status.keycard.ai answers as a status page, though its history renders client-side and its JSON and RSS feeds returned 403 to us on 2 October.",
            "The docs index (73 entries) lists no changelog. The SDK repositories' CHANGELOG.md files are the nearest thing to release notes.",
            "The trust centre lists SOC 2 Type 1 and Type 2 reports and names Resend, Google, GitHub, Cloudflare and AWS as subprocessors."
          ],
          "score": 65
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/keycard.json",
        "live": {
          "slug": "keycard",
          "probe": {
            "target": "https://api.keycard.ai",
            "method": "get",
            "lastAt": "2026-10-04T22:35:25.347082391Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 274,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 280,
            "p95ms24h": 360,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 109
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.keycard.ai",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-04T21:40:10.814751767Z"
          },
          "versions": [
            {
              "registry": "npm",
              "name": "@keycardai/mcp",
              "version": "2.0.2",
              "seenAt": "2026-10-04T16:30:47.44448777Z"
            },
            {
              "registry": "pypi",
              "name": "keycardai-fastmcp",
              "version": "0.7.1",
              "released": "2026-09-15",
              "seenAt": "2026-10-04T16:30:45.543960623Z"
            },
            {
              "registry": "pypi",
              "name": "keycardai-mcp",
              "version": "2.3.2",
              "released": "2026-09-16",
              "seenAt": "2026-10-04T16:30:45.360722519Z"
            },
            {
              "registry": "pypi",
              "name": "keycardai_api",
              "version": "0.18.0",
              "released": "2026-09-25",
              "seenAt": "2026-10-04T16:30:48.363651419Z"
            }
          ],
          "githubStars": 1,
          "npmWeekly": 211,
          "pypiWeekly": 179,
          "securityTxt": {
            "url": "https://keycard.ai/.well-known/security.txt",
            "state": "valid",
            "expires": "2027-06-12T00:00:00.000Z",
            "checkedAt": "2026-10-04T15:15:49.895852699Z"
          },
          "llmsTxt": {
            "url": "https://docs.keycard.ai/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:54.842330743Z"
          },
          "domain": {
            "domain": "keycard.ai",
            "registered": "2024-02-04",
            "source": "https://rdap.identitydigital.services/rdap/domain/keycard.ai",
            "checkedAt": "2026-10-04T13:06:32.92261194Z"
          },
          "pages": [
            {
              "url": "https://www.keycard.ai/pricing",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:50:56.738789549Z",
              "changedAt": "2026-10-03T15:38:49.492444489Z",
              "fingerprint": "7d745cb5c53f"
            },
            {
              "url": "https://www.keycard.ai/privacy/",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:50:58.814741157Z",
              "changedAt": "2026-10-03T15:38:51.566729092Z",
              "fingerprint": "596ae9dc1660"
            }
          ],
          "updatedAt": "2026-10-04T22:35:25.347082391Z"
        }
      },
      {
        "slug": "permit-mcp-gateway",
        "name": "Permit MCP Gateway",
        "vendor": "Permit.io",
        "vendorUrl": "https://www.permit.io/mcp-gateway",
        "kind": "platform",
        "category": "human-in-the-loop",
        "summary": "Hosted proxy between MCP clients and MCP servers that signs in the human behind the agent, checks each tool call against Permit.io policy and logs it.",
        "url": "https://www.anchorterminal.com/tools/permit-mcp-gateway",
        "markdownUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json",
        "transports": [
          "streamable-http"
        ],
        "remoteUrl": "https://{subdomain}.agent.security/mcp",
        "packages": [],
        "auth": "oauth",
        "authNotes": "The gateway is an OAuth 2.1 authorisation server per host. The MCP client gets a 401, reads `/.well-known/oauth-authorization-server` and opens a browser, where the user signs in with email and password, a one-time code, a passkey, Google, GitHub or Microsoft, or SAML or OIDC single sign-on, then picks the access the agent gets. Upstream OAuth (GitHub, Linear) runs through the same consent flow. Sessions expire 90 days after the last tool call.",
        "pricing": "paid",
        "pricingNotes": "Human-in-the-loop approvals are on Enterprise plans, arranged through a demo (https://docs.permit.io/permit-mcp-gateway/human-in-the-loop), and so are the customer-controlled and fully on-premises deployments. The hosted gateway is where evaluation starts, sign-up at app.agent.security. Permit's pricing page lists a free Community plan (1,000 MAU, 20 tenants, no card, 14-day audit logs, best-effort cloud uptime) and Enterprise through sales with SOC 2 Type II, HIPAA BAA and a 99.99 per cent uptime option, but no line for the MCP gateway (https://www.permit.io/pricing).",
        "priceSummary": "Paid",
        "where": "hosted",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": null,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://docs.permit.io/permit-mcp-gateway/human-in-the-loop",
        "capabilities": [
          "hitl.approve",
          "hitl.channels",
          "hitl.audit",
          "auth.oauth",
          "auth.consent",
          "auth.agent-identity",
          "auth.audit"
        ],
        "tags": [
          "hosted",
          "self-hosted",
          "mcp",
          "oauth",
          "enterprise"
        ],
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 54.5,
          "grade": "C",
          "agentReady": false,
          "rank": 321,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 4,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 83,
            "maintenance": 43,
            "payments": 10,
            "reliability": 47,
            "schema": 53,
            "security": 80,
            "transparency": 45
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.",
          "strengths": [
            "No SDK or client change, since the client points at the gateway URL and keeps its tool list",
            "Fails closed, with timeouts that reject and disconnects that cancel",
            "OAuth 2.1 with consent, a trust ceiling per user and admin revocation",
            "Approval history with the outcome, deciding admin and decision time, plus every call in Permit audit logs",
            "Customer-controlled and on-premises deployments keep tool traffic inside your network"
          ],
          "weaknesses": [
            "Approvals are Enterprise only, through a demo, with no published price",
            "Only gateway admins approve, so routing to the right person needs admin seats",
            "5-minute default window, extendable 5 minutes at a time, suits live sessions more than overnight review",
            "No gateway changelog, and the product changelog on Canny stopped in May 2024",
            "Rate limits exist but aren't published, and the status page doesn't list the gateway"
          ],
          "agentNotes": [
            "Expect a waiting message before an approval-gated tool returns, and don't retry the call while it waits",
            "Read the rejection reason in the error and change approach instead of calling the same tool again",
            "Treat a timeout as a rejection and ask the user to have an admin online before a batch of destructive calls",
            "Stay connected while waiting, since dropping the connection cancels the request",
            "On a 429 with `rate_limited`, back off for a few seconds and grow the wait on each retry"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 54.5
            }
          ],
          "editorialScores": {
            "ergonomics": 83,
            "maintenance": 43,
            "payments": 10,
            "reliability": 47,
            "schema": 53,
            "security": 80,
            "transparency": 40
          },
          "provenanceScore": 50
        },
        "connect": {
          "claudeCode": "claude mcp add --transport http linear-gated \"https://YOUR-HOST.agent.security/mcp?upstream_mcp=https://mcp.linear.app/mcp\""
        },
        "letme": {
          "capability": "https://letme.dev/hitl.approve",
          "tool": "https://letme.dev/permit-mcp-gateway"
        },
        "alsoIn": [
          "agent-auth"
        ],
        "area": "agent-runtime",
        "provenance": {
          "legalEntity": "Permit Inc.",
          "domain": "permit.io",
          "domainRegistered": "",
          "endpointOnVendorDomain": false,
          "terms": "https://www.permit.io/legal/terms-and-conditions",
          "privacy": "https://www.permit.io/legal/privacy-policy",
          "statusPage": "https://permit-io.instatus.com/",
          "changelog": "",
          "securityTxt": "unknown",
          "checked": "2026-10-01",
          "notes": [
            "Gateway hosts and the admin dashboard run on agent.security (app.agent.security, \u003chost\u003e.agent.security), while policy and audit logs live on app.permit.io.",
            "The status page lists the backend, OPAL, frontend, website, PDP Deltas and PDP Data. It has no component for the gateway or agent.security.",
            "The docs changelog page says the Canny changelog has no entries after 2024-05-16 and points to SDK and PDP release notes instead.",
            "The gateway docs in permitio/docs were last changed on 2026-09-20. The human-in-the-loop page was added on 2026-05-11.",
            "The terms (updated 2026-07-01) name Permit Inc., a Delaware corporation with a registered office in Dover, Delaware. We couldn't read security.txt or RDAP on 2026-10-01."
          ],
          "score": 50
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/permit-mcp-gateway.json",
        "live": {
          "slug": "permit-mcp-gateway",
          "probe": {
            "target": "https://{subdomain}.agent.security/mcp",
            "method": "get",
            "lastAt": "2026-10-04T22:35:28.797082922Z",
            "lastOk": false,
            "lastStatus": 0,
            "lastMs": 0,
            "lastNote": "invalid character \"{\" in host name",
            "authRequired": false,
            "uptime24h": 0,
            "uptime30d": 0,
            "p50ms24h": 0,
            "p95ms24h": 0,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 0
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 0
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 0
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 0
              }
            ]
          },
          "vendorStatus": {
            "page": "https://permit-io.instatus.com",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-04T21:40:22.877190474Z"
          },
          "securityTxt": {
            "url": "https://permit.io/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:16:02.774068255Z"
          },
          "domain": {
            "domain": "permit.io",
            "checkedAt": "2026-10-04T13:04:38.037359139Z"
          },
          "pages": [
            {
              "url": "https://www.permit.io/pricing",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:51:41.531863438Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "c9ed914508e4"
            },
            {
              "url": "https://www.permit.io/legal/privacy-policy",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:51:37.367686321Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "2c4815352975"
            },
            {
              "url": "https://www.permit.io/legal/terms-and-conditions",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-04T15:51:39.899345922Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "7561c6093e56"
            }
          ],
          "updatedAt": "2026-10-04T22:35:28.797082922Z"
        }
      },
      {
        "slug": "paragon",
        "name": "Paragon ActionKit + MCP",
        "vendor": "Paragon",
        "vendorUrl": "https://www.useparagon.com",
        "kind": "http-api",
        "category": "workflow-automation",
        "summary": "Embedded integration platform for SaaS products.",
        "url": "https://www.anchorterminal.com/tools/paragon",
        "markdownUrl": "https://www.anchorterminal.com/tools/paragon.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paragon.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paragon.json",
        "repo": "https://github.com/useparagon/paragon-mcp",
        "license": "proprietary",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://actionkit.useparagon.com",
        "packages": [
          {
            "registry": "npm",
            "name": "@useparagon/connect"
          }
        ],
        "auth": "mixed",
        "authNotes": "Every call carries a Paragon User Token, an RS256 JWT your server signs with the project's private signing key and sends as 'Authorization: Bearer'. It names the end user, so each tool call runs against that user's connected accounts. The self-hosted MCP server takes the same token and binds it to the session.",
        "pricing": "paid",
        "pricingNotes": "Pro and Enterprise plans, both quoted by sales and priced by the number of Connected Users (customer tenants), with a free trial. Workflows, ActionKit and Managed Sync come with default usage per Connected User. Successful workflow steps and every Proxy API request count as tasks against a monthly limit with no rollover. No prices are published (https://www.useparagon.com/pricing).",
        "priceSummary": "Paid",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402 support in Paragon docs or pricing (checked 2026-09-30).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 48,
          "npmWeekly": 175443,
          "pypiWeekly": null,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://docs.useparagon.com/actionkit/overview",
        "llmsTxt": "https://docs.useparagon.com/llms.txt",
        "openapi": "https://docs.useparagon.com/actionkit/openapi.json",
        "capabilities": [
          "automation.embedded",
          "automation.workflows",
          "automation.apps",
          "automation.auth",
          "automation.webhooks",
          "agent.tools"
        ],
        "tags": [
          "hosted",
          "mcp",
          "llms-txt",
          "openapi",
          "typescript",
          "enterprise",
          "webhooks"
        ],
        "lastRelease": "2026-09-23",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 47.8,
          "grade": "D",
          "agentReady": false,
          "rank": 381,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 8,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 41,
            "maintenance": 48,
            "payments": 0,
            "reliability": 60,
            "schema": 73,
            "security": 65,
            "transparency": 65
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": -4,
          "negativeNotes": [
            "As of the 30 September 2026 commit, the self-hosted MCP server defaults `NODE_ENV` to development, and in development `/mcp` and `/sse` sign a user token for whatever ID arrives in `?user=`. The Dockerfile and the image its workflow publishes don't set `NODE_ENV`, so a server started from that image without the variable lets anyone who can reach it impersonate any end user. The README documents the behaviour and the compose file sets production, so the deduction is modest (https://github.com/useparagon/paragon-mcp/blob/main/src/index.ts, https://github.com/useparagon/paragon-mcp/blob/main/src/utils.ts)."
          ],
          "verdict": "Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth. No published prices and no self-serve paid plan.",
          "strengths": [
            "Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth",
            "ActionKit lists tools as JSON Schema and has an OpenAPI 3.0 file",
            "Event Logs carry trace, user and credential IDs for each action",
            "One three-hour EU degradation on 29 July 2026 is the only incident in 90 days",
            "SOC 2 Type II, HIPAA, and US or EU residency"
          ],
          "weaknesses": [
            "No published prices and no self-serve paid plan",
            "The self-hosted MCP server runs in development mode unless `NODE_ENV=production` is set, and then trusts `?user=`",
            "No error schemas in the OpenAPI file, no ActionKit rate limit and no tool annotations",
            "Changelog's newest entry is April 2026",
            "No security.txt, and the MCP server's licence is stated two ways with no `LICENSE` file"
          ],
          "agentNotes": [
            "Sign a short-lived User Token per end user on your server and never let the model see the signing key",
            "Set `NODE_ENV=production` before exposing the MCP server anywhere but localhost",
            "Fetch the tool list once per session with `categories` set, and cache it",
            "Set `LIMIT_TO_TOOLS` on the MCP server to keep write actions out of a read-only agent",
            "Proxy API requests count as tasks, so prefer ActionKit tools for routine actions"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "D",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 47.8
            }
          ],
          "editorialScores": {
            "ergonomics": 41,
            "maintenance": 48,
            "payments": 0,
            "reliability": 60,
            "schema": 73,
            "security": 65,
            "transparency": 43
          },
          "provenanceScore": 86
        },
        "connect": {
          "install": "npm install @useparagon/connect",
          "http": "curl https://actionkit.useparagon.com/projects/$PARAGON_PROJECT_ID/tools -H \"Authorization: Bearer $PARAGON_USER_TOKEN\"",
          "claudeCode": "claude mcp add --transport http paragon http://localhost:3001/mcp --header \"Authorization: Bearer ${PARAGON_USER_TOKEN}\"",
          "config": {
            "mcpServers": {
              "paragon": {
                "headers": {
                  "Authorization": "Bearer ${PARAGON_USER_TOKEN}"
                },
                "url": "http://localhost:3001/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/automation.embedded",
          "tool": "https://letme.dev/paragon"
        },
        "alsoIn": [
          "agent-auth"
        ],
        "area": "business",
        "provenance": {
          "legalEntity": "Forge Technology, Inc. (d/b/a Paragon)",
          "domain": "useparagon.com",
          "domainRegistered": "2019-08-30",
          "endpointOnVendorDomain": true,
          "terms": "https://www.useparagon.com/terms-of-service",
          "privacy": "https://www.useparagon.com/privacy-policy",
          "statusPage": "https://status.useparagon.com",
          "changelog": "https://docs.useparagon.com/changelog/product-updates",
          "securityTxt": "none",
          "checked": "2026-09-30",
          "score": 86
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/paragon.json",
        "live": {
          "slug": "paragon",
          "probe": {
            "target": "https://actionkit.useparagon.com",
            "method": "get",
            "lastAt": "2026-10-04T22:35:28.439844321Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 312,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 310,
            "p95ms24h": 380,
            "samples24h": 272,
            "samples30d": 1086,
            "days": [
              {
                "date": "2026-09-30",
                "probes": 35,
                "ok": 35
              },
              {
                "date": "2026-10-01",
                "probes": 276,
                "ok": 276
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.useparagon.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T22:34:05.130497679Z"
          },
          "versions": [
            {
              "registry": "npm",
              "name": "@useparagon/connect",
              "version": "3.1.0",
              "seenAt": "2026-10-04T16:36:14.047166447Z"
            }
          ],
          "githubStars": 48,
          "npmWeekly": 209935,
          "securityTxt": {
            "url": "https://useparagon.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:38.675956466Z"
          },
          "llmsTxt": {
            "url": "https://docs.useparagon.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:18:05.97376219Z"
          },
          "domain": {
            "domain": "useparagon.com",
            "registered": "2019-08-30",
            "source": "https://rdap.verisign.com/com/v1/domain/useparagon.com",
            "checkedAt": "2026-10-04T13:08:02.741729991Z"
          },
          "pages": [
            {
              "url": "https://docs.useparagon.com/changelog/product-updates",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:44:12.572071633Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "1f693d6387f4"
            },
            {
              "url": "https://www.useparagon.com/pricing",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:52:39.051971068Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "8c248050adff"
            },
            {
              "url": "https://www.useparagon.com/privacy-policy",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:52:41.720779341Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "63ed04f01ce4"
            },
            {
              "url": "https://www.useparagon.com/terms-of-service",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-04T15:52:43.233474446Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "c2cc0e396ab4"
            }
          ],
          "updatedAt": "2026-10-04T22:35:28.439844321Z"
        }
      }
    ]
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/categories/agent-auth",
    "json": "https://www.anchorterminal.com/categories/agent-auth.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/categories/agent-auth.md",
    "slim": "https://www.anchorterminal.com/categories/agent-auth.min.md"
  },
  "markdown": "Services that let an agent act for a user in other apps: OAuth flows and token storage for third-party APIs, scoped and revocable access, and an identity for the agent itself. Compared on the providers they cover, how consent works, token handling and audit logs.\n\n- Tools ranked: 13 · agent-ready (BB or better): 4 · accept x402: 0 · hosted endpoints: 13 · desk reviews by the panel: 38\n- JSON: https://www.anchorterminal.com/api/v1/tools.json (list) · https://www.anchorterminal.com/api/v1/rankings.json (ranked) · https://www.anchorterminal.com/api/v1/x402.json (payable) · https://www.anchorterminal.com/api/v1/capabilities.json (by capability)\n- Grades run AA, A, BB, B, C, D, E, F · methodology: https://www.anchorterminal.com/benchmark/\n\n- Capabilities in this category: auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit\n- https://letme.dev/auth.oauth picks the top-graded tool in this list and says how to call it direct; calling through letme comes later (https://www.anchorterminal.com/letme/index.md)\n\n## Ranking\n\n| # | Tool | Vendor | Kind | Category | Grade | Score | Confidence | x402 | Auth | Where | Reviews | Page |\n| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |\n| 10 | Descope Agentic Identity Hub | Descope | HTTP API | Agent auth | A | 79.2 | medium | no | OAuth or key | hosted | 3.1/5 (8) | https://www.anchorterminal.com/tools/descope-agentic-identity.md |\n| 36 | Composio (API + MCP) | Composio | HTTP API | Tool access | BB | 75.3 | medium | no | OAuth or key | hosted | 3.5/5 (8) | https://www.anchorterminal.com/tools/composio-rube.md |\n| 74 | Scalekit AgentKit | Scalekit | HTTP API | Agent auth | BB | 72.1 | medium | no | OAuth or key | hosted | 2.5/5 (2) | https://www.anchorterminal.com/tools/scalekit-agentkit.md |\n| 82 | Auth0 for AI Agents (Token Vault) | Auth0 by Okta | HTTP API | Agent auth | BB | 71.5 | medium | no | OAuth | hosted + local | 3.5/5 (2) | https://www.anchorterminal.com/tools/auth0-ai-agents.md |\n| 135 | Nango | Nango | HTTP API | Agent auth | B | 67.9 | medium | no | OAuth or key | hosted | 3.5/5 (2) | https://www.anchorterminal.com/tools/nango.md |\n| 147 | Arcade.dev | Arcade.dev | HTTP API | Agent auth | B | 67 | medium | no | OAuth or key | hosted + local | 2.5/5 (2) | https://www.anchorterminal.com/tools/arcade.md |\n| 167 | Pipedream API + MCP | Pipedream (Workday) | HTTP API | Workflows | B | 65.8 | medium | no | OAuth or key | hosted | 2.5/5 (2) | https://www.anchorterminal.com/tools/pipedream.md |\n| 241 | Stytch Connected Apps | Stytch (Twilio) | HTTP API | Agent auth | C | 60.8 | medium | no | OAuth or key | hosted | 3/5 (2) | https://www.anchorterminal.com/tools/stytch-connected-apps.md |\n| 256 | WorkOS Pipes and Agents | WorkOS | HTTP API | Agent auth | C | 60 | medium | no | OAuth or key | hosted | 2.5/5 (2) | https://www.anchorterminal.com/tools/workos-pipes.md |\n| 280 | Zapier MCP (agent actions) | Zapier | MCP server | Tool access | C | 58.4 | medium | no | OAuth or key | hosted | 2.5/5 (2) | https://www.anchorterminal.com/tools/zapier-mcp.md |\n| 303 | Keycard | Keycard Labs | HTTP API | Agent auth | C | 56.3 | medium | no | OAuth or key | hosted | 2.5/5 (2) | https://www.anchorterminal.com/tools/keycard.md |\n| 321 | Permit MCP Gateway | Permit.io | Model platform | Human approval | C | 54.5 | medium | no | OAuth | hosted | 2.5/5 (2) | https://www.anchorterminal.com/tools/permit-mcp-gateway.md |\n| 381 | Paragon ActionKit + MCP | Paragon | HTTP API | Workflows | D | 47.8 | medium | no | OAuth or key | hosted | 2/5 (2) | https://www.anchorterminal.com/tools/paragon.md |\n\nScores are from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/), with Performance and Task success pending. p95 latency and context cost come from our probes, which haven't run yet.\n\n## Summaries\n\n### 10. Descope Agentic Identity Hub, A (79.2)\n\nDescope's identity and access tools for AI agents, built on its customer identity platform. Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.\n\n- Page: https://www.anchorterminal.com/tools/descope-agentic-identity · Markdown: https://www.anchorterminal.com/tools/descope-agentic-identity.md · JSON: https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json\n- Capabilities: auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit, hitl.approve · endpoint: `https://api.descope.com`\n\n### 36. Composio (API + MCP), BB (75.3)\n\nTool access and per-user authentication for agents across 1,000+ apps. Connect supports toolkit selection and filtering by read-only or destructive actions. Rube closed on 16 May 2026, so existing rube.app configurations need migration.\n\n- Page: https://www.anchorterminal.com/tools/composio-rube · Markdown: https://www.anchorterminal.com/tools/composio-rube.md · JSON: https://www.anchorterminal.com/api/v1/tools/composio-rube.json\n- Capabilities: automation.apps, automation.auth, automation.actions, agent.tools, automation.webhooks · endpoint: `https://backend.composio.dev/api/v3.1`\n\n### 74. Scalekit AgentKit, BB (72.1)\n\nAuthentication and integration platform for agents, with per-user account connections, scoped MCP servers and managed tool calls. 500+ connectors, including remote MCP servers over OAuth 2.1 with DCR. No rate limits or idempotency documented for Scalekit's own API.\n\n- Page: https://www.anchorterminal.com/tools/scalekit-agentkit · Markdown: https://www.anchorterminal.com/tools/scalekit-agentkit.md · JSON: https://www.anchorterminal.com/api/v1/tools/scalekit-agentkit.json\n- Capabilities: auth.oauth, auth.tokens, auth.consent, auth.agent-identity, agent.tools · endpoint: `https://{env}.scalekit.com`\n\n### 82. Auth0 for AI Agents (Token Vault), BB (71.5)\n\nAuth0's identity and authorisation tools for AI agents, built on its identity platform. Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users.\n\n- Page: https://www.anchorterminal.com/tools/auth0-ai-agents · Markdown: https://www.anchorterminal.com/tools/auth0-ai-agents.md · JSON: https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json\n- Capabilities: auth.oauth, auth.tokens, auth.consent, auth.agent-identity, hitl.approve · endpoint: `https://{tenant}.auth0.com/oauth/token`\n\n### 135. Nango, B (67.9)\n\nSource-available integration platform that handles OAuth, API keys and token refresh for 1,000+ APIs on behalf of your users. 1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.\n\n- Page: https://www.anchorterminal.com/tools/nango · Markdown: https://www.anchorterminal.com/tools/nango.md · JSON: https://www.anchorterminal.com/api/v1/tools/nango.json\n- Capabilities: auth.oauth, auth.tokens, auth.consent, auth.audit, agent.tools, automation.embedded · endpoint: `https://api.nango.dev`\n\n### 147. Arcade.dev, B (67)\n\nMCP runtime built around per-user authorisation. Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.\n\n- Page: https://www.anchorterminal.com/tools/arcade · Markdown: https://www.anchorterminal.com/tools/arcade.md · JSON: https://www.anchorterminal.com/api/v1/tools/arcade.json\n- Capabilities: auth.oauth, auth.tokens, auth.consent, auth.audit, agent.tools · endpoint: `https://api.arcade.dev`\n\n### 167. Pipedream API + MCP, B (65.8)\n\nCode-first workflows in Node.js, Python, Go and Bash, plus Connect, an API and SDK that runs 10,000+ prebuilt actions across 3,000+ apps on behalf of your own users with managed OAuth. Managed OAuth per end user across 3,000+ apps, through API, SDK or MCP. Public changelog's last entry is 1 October 2025.\n\n- Page: https://www.anchorterminal.com/tools/pipedream · Markdown: https://www.anchorterminal.com/tools/pipedream.md · JSON: https://www.anchorterminal.com/api/v1/tools/pipedream.json\n- Capabilities: automation.workflows, automation.apps, automation.embedded, automation.code, automation.webhooks, automation.auth, agent.tools · endpoint: `https://api.pipedream.com/v1`\n\n### 241. Stytch Connected Apps, C (60.8)\n\nTurns a Stytch project into an OAuth 2.1 and OIDC authorisation server so agents and MCP clients can act for your users. OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens.\n\n- Page: https://www.anchorterminal.com/tools/stytch-connected-apps · Markdown: https://www.anchorterminal.com/tools/stytch-connected-apps.md · JSON: https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json\n- Capabilities: auth.oauth, auth.consent, auth.agent-identity, auth.tokens · endpoint: `https://api.stytch.com`\n\n### 256. WorkOS Pipes and Agents, C (60)\n\nWorkOS tools for connecting agents to third-party accounts, managing access tokens and assigning revocable agent identities. Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.\n\n- Page: https://www.anchorterminal.com/tools/workos-pipes · Markdown: https://www.anchorterminal.com/tools/workos-pipes.md · JSON: https://www.anchorterminal.com/api/v1/tools/workos-pipes.json\n- Capabilities: auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit · endpoint: `https://api.workos.com`\n\n### 280. Zapier MCP (agent actions), C (58.4)\n\nHosted MCP server that lets agents discover and run actions across apps connected to the user's Zapier account. 16 meta-tools in agentic mode, or managed mode with only the actions you pick. Connection tokens are long-lived and the docs allow them in the URL query string.\n\n- Page: https://www.anchorterminal.com/tools/zapier-mcp · Markdown: https://www.anchorterminal.com/tools/zapier-mcp.md · JSON: https://www.anchorterminal.com/api/v1/tools/zapier-mcp.json\n- Capabilities: automation.apps, automation.auth, automation.actions, agent.tools · endpoint: `https://mcp.zapier.com/api/v1/connect`\n\n### 303. Keycard, C (56.3)\n\nIdentity and access platform for AI agents. Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.\n\n- Page: https://www.anchorterminal.com/tools/keycard · Markdown: https://www.anchorterminal.com/tools/keycard.md · JSON: https://www.anchorterminal.com/api/v1/tools/keycard.json\n- Capabilities: auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit · endpoint: `https://api.keycard.ai`\n\n### 321. Permit MCP Gateway, C (54.5)\n\nHosted proxy between MCP clients and MCP servers that signs in the human behind the agent, checks each tool call against Permit.io policy and logs it. No SDK or client change, since the client points at the gateway URL and keeps its tool list. Approvals are Enterprise only, through a demo, with no published price.\n\n- Page: https://www.anchorterminal.com/tools/permit-mcp-gateway · Markdown: https://www.anchorterminal.com/tools/permit-mcp-gateway.md · JSON: https://www.anchorterminal.com/api/v1/tools/permit-mcp-gateway.json\n- Capabilities: hitl.approve, hitl.channels, hitl.audit, auth.oauth, auth.consent, auth.agent-identity, auth.audit · endpoint: `https://{subdomain}.agent.security/mcp`\n\n### 381. Paragon ActionKit + MCP, D (47.8)\n\nEmbedded integration platform for SaaS products. Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth. No published prices and no self-serve paid plan.\n\n- Page: https://www.anchorterminal.com/tools/paragon · Markdown: https://www.anchorterminal.com/tools/paragon.md · JSON: https://www.anchorterminal.com/api/v1/tools/paragon.json\n- Capabilities: automation.embedded, automation.workflows, automation.apps, automation.auth, automation.webhooks, agent.tools · endpoint: `https://actionkit.useparagon.com`\n\n## How we test this category\n\nAn agent connects to two third-party apps for a test user, makes calls, has one scope refused and then the grant revoked. We check the consent flow, where tokens live, what the audit log shows and how revocation reaches the agent. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence.\n\n## Indexed, not reviewed (23)\n\nSorted into this category from public catalogues, with facts and our own checks but no score, grade or rank (https://www.anchorterminal.com/indexed/index.md).\n\n| Listing | Kind | What it does | Why it's here |\n| --- | --- | --- | --- |\n| [artifacta.io MCP server](https://www.anchorterminal.com/tools/artifacta-mcp.md) | MCP server | Artifact store for AI agents. Hosted OAuth at mcp.artifacta.io/mcp; local stdio via npm/PyPI. | vendor's own |\n| [Coach Watts](https://www.anchorterminal.com/tools/coachwatts-coach-watts.md) | MCP server | Remote MCP server for training, nutrition, wellness, and performance data with OAuth 2.0. | vendor's own |\n| [Expense Budget Tracker](https://www.anchorterminal.com/tools/expense-budget-tracker.md) | MCP server | Track expenses, budgets, balances, transfers, and multi-currency reports with OAuth-secured tools. | vendor's own |\n| [Gemina](https://www.anchorterminal.com/tools/gemina.md) | MCP server | Extract, search and tag any document: invoices, receipts, contracts, templates. OAuth or API key. | vendor's own |\n| [HitPay MCP Server](https://www.anchorterminal.com/tools/hit-pay-mcp.md) | MCP server | Official HitPay MCP: sales, payouts, balances; create payment links and invoices. OAuth; no refunds. | vendor's own |\n| [imaginevid-ai-generation](https://www.anchorterminal.com/tools/imaginevid-ai-generation.md) | MCP server | OAuth-protected ImagineVid MCP for image, video, and music generation. | vendor's own |\n| [kernel-mcp-server](https://www.anchorterminal.com/tools/onkernel-kernel-mcp-server.md) | MCP server | Access Kernel's cloud-based browsers and app actions via MCP (remote HTTP + OAuth). | vendor's own |\n| [Labby](https://www.anchorterminal.com/tools/dinglebear-labby.md) | MCP server | Rust MCP gateway with Code Mode, authentication, setup, logs, CLI, HTTP API, and operator web UI. | vendor's own |\n| [logi](https://www.anchorterminal.com/tools/1pass-logi.md) | MCP server | logi (1pass) IdP — manage your OAuth apps, redirect URIs, passkeys, login history and docs. | vendor's own |\n| [MCP Protocol Conformance](https://www.anchorterminal.com/tools/studiomeyer-protocol-conformance.md) | MCP server | MCP conformance test harness. JSON-RPC, OAuth 2.1 PKCE, schemas, smoke, annotations. CLI + lib. | vendor's own |\n| [mymlh-mcp-server](https://www.anchorterminal.com/tools/git-mymlh-mcp-server.md) | MCP server | OAuth-enabled MyMLH MCP server for accessing MyMLH data. | vendor's own |\n| [odoo](https://www.anchorterminal.com/tools/odooconsole-odoo.md) | MCP server | Odoo ERP for AI agents: hosted OAuth endpoint, gated writes, one endpoint for every instance. | vendor's own |\n| [OfflineCreator Studio](https://www.anchorterminal.com/tools/offlinecreatorstudio-mcp.md) | MCP server | Create images and videos with OfflineCreator Studio through OAuth or the npm stdio server. | vendor's own |\n| [OpenWork MCP Gateway](https://www.anchorterminal.com/tools/openworklabs-openwork.md) | MCP server | Your OpenWork org's skills, plugins, workflows, and connections through one OAuth MCP URL. | vendor's own, widely used |\n| [pAIchart MCP Hub](https://www.anchorterminal.com/tools/paichart-mcp-hub.md) | MCP server | MCP Hub: AI service discovery, per-user OAuth, and multi-service workflow orchestration | vendor's own |\n| [platform7n](https://www.anchorterminal.com/tools/p7n-platform7n.md) | MCP server | Connect Claude to your Platform7n workspaces — chat, links, and tasks. One-click OAuth. | vendor's own |\n| [Prizmad](https://www.anchorterminal.com/tools/prizmad-mcp-server.md) | MCP server | Generate AI UGC video ads from any product URL — avatars, voiceover, OAuth Connect. | vendor's own |\n| [thoughtspot.app MCP server](https://www.anchorterminal.com/tools/thoughtspot-mcp-server.md) | MCP server | MCP Server for ThoughtSpot - provides OAuth authentication and tools for querying data | vendor's own |\n| [toll402-mcp](https://www.anchorterminal.com/tools/toll402-mcp.md) | MCP server | Pay-per-call tools for agents: 2,600+ APIs, OAuth connector; pay with x402 or card credits. | vendor's own |\n| [WHOOP — MissingMCP](https://www.anchorterminal.com/tools/missingmcp-whoop.md) | MCP server | WHOOP recovery, strain, sleep and workouts in Claude via official WHOOP OAuth. Free, open source. | vendor's own |\n| [Wraps](https://www.anchorterminal.com/tools/wraps-docs.md) | MCP server | Search the Wraps docs and estimate AWS SES costs. Public, read-only, no authentication. | vendor's own |\n| [Xquik MCP Server](https://www.anchorterminal.com/tools/xquik-mcp.md) | MCP server | 128 REST operations. 120 MCP routes; 119 JSON/text ops. OAuth 2.1. Not affiliated with X Corp. | vendor's own |\n| [ynab-mcp-server](https://www.anchorterminal.com/tools/smirnovlabs-ynab-mcp-server.md) | MCP server | Hosted remote MCP server for YNAB on Cloudflare Workers with OAuth | vendor's own |\n\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Agent auth \u0026 delegated access",
        "url": ""
      }
    ],
    "description": "13 agent auth \u0026 delegated access ranked by the Anchor benchmark. Leader Descope Agentic Identity Hub (A). Services that let an agent act for a user in other apps: OAuth flows and token storage for third-party APIs, scoped and revocable access, and an identity for the agent itself. Compared on the providers they cover, how consent works, token handling and audit logs.",
    "facts": [
      "Descope Agentic Identity Hub A",
      "Composio (API + MCP) BB",
      "Scalekit AgentKit BB"
    ],
    "h1": "Auth and delegated access for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/categories-agent-auth.png",
    "path": "/categories/agent-auth",
    "published": "",
    "section": "tools",
    "title": "Auth and delegated access for AI agents, ranked | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/categories/agent-auth"
  },
  "tokens": {
    "markdown": 4550,
    "slim": 680
  },
  "version": 1
}
