{
  "data": {
    "a": {
      "slug": "aembit",
      "name": "Aembit",
      "vendor": "Aembit, Inc.",
      "vendorUrl": "https://aembit.io",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Aembit is a hosted identity and access platform for workloads and AI agents. Its MCP Identity Gateway and MCP Authorisation Server apply access policies and inject credentials, with a Cloud API, an Edge API, a CLI and an Edge SDK.",
      "url": "https://www.anchorterminal.com/tools/aembit",
      "markdownUrl": "https://www.anchorterminal.com/tools/aembit.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/aembit.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/aembit.json",
      "repo": "https://github.com/Aembit/edge-sdks",
      "license": "Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@aembit/edge-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every API takes a short-lived Bearer token. For the Cloud API at https://\u003ctenant\u003e.aembit.io/api/v1, a person copies an API token from the tenant's Profile page (1 hour by default), or a workload obtains an Aembit Access Token through an Access Policy and a role. The Edge API exchanges platform attestation for an access token at /edge/v1/auth. MCP clients reach the MCP Identity Gateway and MCP Authorisation Server by OAuth 2.1 with PKCE and dynamic client registration or a Client ID Metadata Document, after the user signs in through the company's identity provider. Access is self-serve for a free tenant. The managed gateway endpoint is requested through an Aembit representative.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 3 AI agents, one MCP Identity Gateway and 5 MCP authorisation policies, or 10 workloads and 10 Access Policies, with 24 hours of event log retention. The pricing FAQ says no payment information is required. Teams is $20 per AI agent a month (to 500 agents) or $20 per workload a month, with a Contact Us button. Enterprise is custom. An agent can start on the free tenant without a contract (https://aembit.io/pricing/, checked 2026-10-08).",
      "priceSummary": "$20 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI files or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 27,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.aembit.io",
      "llmsTxt": "https://docs.aembit.io/llms.txt",
      "openapi": "https://docs.aembit.io/cloud.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.agent-identity",
        "auth.tokens",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "typescript",
        "cli",
        "terraform",
        "status-page",
        "soc2",
        "iso27001",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.5,
        "grade": "BB",
        "agentReady": true,
        "rank": 147,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 40,
          "reliability": 65,
          "schema": 85,
          "security": 84,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.",
        "bestFor": "A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.",
        "strengths": [
          "Public OpenAPI 3.1.1 files for the Cloud API (171 operations) and Edge API (2), plus llms.txt, per-page Markdown and a cloneable docs bundle",
          "No long-lived API credentials. Aembit API tokens last 1 hour by default and Edge API access tokens expire in 1 hour",
          "MCP clients authenticate by OAuth 2.1 with PKCE, dynamic client registration or a Client ID Metadata Document",
          "Audit logs, access authorisation events and workload events, exported by Log Streams to S3, Google Cloud Storage, Splunk or CrowdStrike",
          "Dated changelog with RSS. MCP Identity Gateway shipped four versions between 7 August and 7 October 2026"
        ],
        "weaknesses": [
          "No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance",
          "No SLA is published. The docs send SLA questions to Aembit support",
          "The managed MCP Identity Gateway endpoint is requested through an Aembit representative, and MCP Tool Access Control is enabled by support",
          "The Python Edge SDK is in the repository at 0.1.0 but pypi.org/project/aembit-edge-sdk returned 404 on 8 October 2026",
          "No DPA, sub-processor list or security.txt found on aembit.io. The trust centre returned 403 to our reader"
        ],
        "agentNotes": [
          "Read the API Base URL and token from the tenant's Profile page. Tokens last 1 hour by default, so plan to refresh",
          "Send `X-Aembit-ResourceSet` on Cloud API, Edge API and MCP calls outside the default Resource Set, or the request runs against the default set",
          "Cache the Edge API access token from `/edge/v1/auth` until near expiry before calling `/edge/v1/credentials`. Both endpoints can answer 429",
          "Point MCP clients at `https://\u003cgateway-host\u003e/mcp`. The `/me` path is deprecated",
          "Expect tool names prefixed with the Server Workload name behind the MCP Identity Gateway, and keep `perPage` at 100 or less on the Aembit MCP Server"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.5
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 40,
          "reliability": 65,
          "schema": 85,
          "security": 84,
          "transparency": 42
        },
        "provenanceScore": 78
      },
      "connect": {
        "install": "npm install @aembit/edge-sdk",
        "http": "curl -X GET -L 'https://tenant.aembit.io/api/v1/server-workloads' -H 'Authorization: Bearer \u003cTOKEN\u003e'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/aembit"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Teams, each AI agent",
          "unit": "month",
          "usd": 20,
          "note": "Priced per agent a month, up to 500 agents"
        },
        {
          "item": "Teams, each workload",
          "unit": "month",
          "usd": 20,
          "note": "Priced per workload a month"
        }
      ],
      "provenance": {
        "legalEntity": "Aembit, Inc.",
        "domain": "aembit.io",
        "domainRegistered": "2021-03-14",
        "endpointOnVendorDomain": true,
        "terms": "https://aembit.io/terms-of-service/",
        "privacy": "https://aembit.io/privacy-policy/",
        "statusPage": "https://status.aembit.io",
        "changelog": "https://docs.aembit.io/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last reviewed 14 July 2026) are between the customer and Aembit, Inc., define the Services as the website and the web-based and downloadable workload identity and access management services, and choose Delaware law.",
          "The privacy policy (last updated 5 May 2026) names Aembit, Inc. and covers the platform, websites and related services.",
          "aembit.io/.well-known/security.txt and docs.aembit.io/.well-known/security.txt both returned 404. The docs give security@aembit.io as the security contact.",
          "RDAP at Identity Digital gives a registration date of 2021-03-14 for aembit.io.",
          "Tenant APIs answer at https://\u003ctenant\u003e.aembit.io and the managed gateway at https://\u003ctenantId\u003e.mcpgateway.aembit.io, both on the vendor's domain.",
          "No DPA, sub-processor or SLA page was found at the obvious aembit.io paths, and trust.aembit.io returned 403 to our reader."
        ],
        "score": 78
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/aembit.json",
      "live": {
        "slug": "aembit",
        "vendorStatus": {
          "page": "https://status.aembit.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T11:25:57.881001941Z"
        },
        "pages": [
          {
            "url": "https://docs.aembit.io/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:07.775115006Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4e930f2cc1ec"
          },
          {
            "url": "https://aembit.io/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:14:59.808222145Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "781c90a65067"
          },
          {
            "url": "https://aembit.io/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:01.881687653Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "753e7b8821e4"
          },
          {
            "url": "https://aembit.io/terms-of-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:03.860763085Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ad42c0fa0432"
          }
        ],
        "updatedAt": "2026-10-09T11:25:57.881001941Z"
      }
    },
    "answer": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Aembit's 70.5 (BB), and leads in 4 of 7 scored categories. Aembit leads on payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "agentcore-identity",
      "name": "Amazon Bedrock AgentCore Identity",
      "vendor": "Amazon Web Services",
      "vendorUrl": "https://aws.amazon.com/bedrock/agentcore/",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Amazon Bedrock AgentCore Identity is an AWS service that gives agents workload identities, stores OAuth tokens and API keys in a token vault, and runs OAuth flows so agents can call third-party services for users or for themselves.",
      "url": "https://www.anchorterminal.com/tools/agentcore-identity",
      "markdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json",
      "repo": "https://github.com/aws/bedrock-agentcore-sdk-python",
      "license": "Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://bedrock-agentcore.us-east-1.amazonaws.com",
      "packages": [
        {
          "registry": "pypi",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "npm",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "npm",
          "name": "@aws-sdk/client-bedrock-agentcore"
        },
        {
          "registry": "pypi",
          "name": "boto3"
        }
      ],
      "auth": "mixed",
      "authNotes": "A person creates an AWS account and an IAM role. Control-plane calls (`bedrock-agentcore-control`) and data-plane calls (`bedrock-agentcore`) are SigV4-signed with IAM credentials, and the data plane also documents an OAuth bearer route (`UnauthorizedException` for an invalid JWT). The agent first gets a workload access token that carries its own identity and the user's, from a JWT (`GetWorkloadAccessTokenForJWT`), a user ID string (`GetWorkloadAccessTokenForUserId`) or neither (`GetWorkloadAccessToken`), then exchanges it for a third-party OAuth token or API key. Each third-party provider needs an OAuth client the owner registers with that provider. AgentCore Runtime and Gateway fetch the workload access token for the agent.",
      "pricing": "usage",
      "pricingNotes": "$0.010 per 1,000 OAuth token or API key requests for non-AWS resources, billed per successful request, with no minimum fee. No additional charge when the service is used through AgentCore Runtime or AgentCore Gateway, which are billed on their own meters. No free tier specific to Identity was found. New AWS accounts get up to $200 of Free Tier credit for up to 6 months, and AWS says most new customers need no payment method at sign-up though it may ask for one (https://aws.amazon.com/bedrock/agentcore/pricing/, https://aws.amazon.com/free/free-tier-faqs/).",
      "priceSummary": "$0.01 / 1k req",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 for paying AWS on the pricing page or in the docs. AgentCore payments is a separate capability for agents paying third-party sellers (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 334717,
        "pypiWeekly": 1421946,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html",
      "llmsTxt": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit",
        "infra.aws"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "usage-priced",
        "oauth",
        "llms-txt",
        "python",
        "typescript",
        "enterprise",
        "sla",
        "soc2",
        "eu"
      ],
      "lastRelease": "2026-09-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.8,
        "grade": "BB",
        "agentReady": true,
        "rank": 64,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 76,
          "maintenance": 70,
          "payments": 30,
          "reliability": 85,
          "schema": 88,
          "security": 84,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.",
        "bestFor": "Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.",
        "strengths": [
          "`GetResourceOauth2Token` covers three flows (USER_FEDERATION, M2M and ON_BEHALF_OF_TOKEN_EXCHANGE) and returns either an access token or an authorisation URL with a session URI.",
          "25 OAuth vendor values in `CreateOauth2CredentialProvider`, 24 built in (Google, GitHub, Slack, Salesforce, Microsoft, Atlassian and others) plus a custom OAuth 2.0 provider.",
          "Quotas are published per operation, 200 requests a second for the three workload access token calls and 20 for each management call, all adjustable.",
          "The token vault is encrypted with an AWS owned KMS key by default or a customer managed key, and IAM policies can name one workload identity and one credential provider.",
          "$0.010 per 1,000 token or API key requests, with no extra charge when used through AgentCore Runtime or Gateway."
        ],
        "weaknesses": [
          "No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.",
          "The consent portal, launched 1 September 2026, attaches to one AgentCore Gateway with JWT inbound auth and cannot use GitHub, Slack, Salesforce, Atlassian or LinkedIn as its sign-in provider.",
          "`GetWorkloadAccessTokenForUserId` takes a user ID string the platform does not verify, so the binding to a user rests on the caller and its IAM policy.",
          "AWS states the service enforces no binding between workload identities and credential providers in one account beyond the IAM policy the owner writes.",
          "No CloudTrail page for AgentCore Identity was found in the developer guide, though Gateway and Agent Registry each have one."
        ],
        "agentNotes": [
          "Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.",
          "When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.",
          "For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.",
          "Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.",
          "Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.8
          }
        ],
        "editorialScores": {
          "ergonomics": 76,
          "maintenance": 70,
          "payments": 30,
          "reliability": 85,
          "schema": 88,
          "security": 84,
          "transparency": 61
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "pip install bedrock-agentcore"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/agentcore-identity"
      },
      "sameCompany": [
        "amazon-nova-embeddings",
        "amazon-bedrock-guardrails",
        "amazon-transcribe",
        "amazon-polly",
        "agentcore-memory",
        "aws-secrets-manager",
        "aws-mcp-servers",
        "amazon-ses",
        "amazon-location",
        "amazon-translate",
        "amazon-ads-api"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "OAuth token or API key requests for non-AWS resources",
          "unit": "1k-requests",
          "usd": 0.01,
          "note": "Per successful request. No charge when used through AgentCore Runtime or Gateway"
        }
      ],
      "provenance": {
        "legalEntity": "Amazon Web Services, Inc.",
        "domain": "amazon.com",
        "domainRegistered": "1994-11-01",
        "domainNote": "The service pages are under aws.amazon.com and the endpoints are on amazonaws.com, an AWS domain.",
        "endpointOnVendorDomain": true,
        "terms": "https://aws.amazon.com/service-terms/",
        "privacy": "https://aws.amazon.com/privacy/",
        "statusPage": "https://health.aws.amazon.com/health/status",
        "changelog": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The AWS Service Terms show Last Updated 1 October 2026. Section 50 covers AI services and section 50.15 covers AgentCore Payments. No section names AgentCore Identity, so the universal terms and section 50 apply.",
          "The Privacy Notice shows Last Updated 18 May 2026 and gives Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210.",
          "security.txt shows Expires 2026-09-24T16:25:03Z, read on 8 October 2026. It points to the AWS vulnerability disclosure programme on HackerOne and the policy at vdp.aws.security.",
          "The status page is drawn by script. We read the per-service feed (status.aws.amazon.com/rss/bedrock-agentcore-us-east-1.rss, no items) and the dashboard's history file.",
          "The domain registration date is carried from our other AWS listings. WHOIS was not reachable from this session.",
          "The release notes are dated by month only, and the RSS feed they mention was not found at doc-history.rss (404)."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/agentcore-identity.json",
      "live": {
        "slug": "agentcore-identity",
        "probe": {
          "target": "https://bedrock-agentcore.us-east-1.amazonaws.com",
          "method": "get",
          "lastAt": "2026-10-09T11:28:52.708070294Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 244,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 257,
          "p95ms24h": 294,
          "samples24h": 41,
          "samples30d": 41,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 41,
              "ok": 41
            }
          ]
        },
        "updatedAt": "2026-10-09T11:28:52.708070294Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Aembit, Inc.",
        "b": "Amazon Web Services",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://bedrock-agentcore.us-east-1.amazonaws.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "not published",
        "b": "$0.01 per 1,000 requests",
        "name": "Price for auth oauth"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0",
        "b": "Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-09-01",
        "name": "Last release"
      },
      {
        "a": "2026-07-14",
        "b": "2026-10-01",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-05",
        "b": "2026-05-18",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "27 npm/wk",
        "b": "335k npm/wk, 1.4M PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Aembit's 70.5 (BB), and leads in 4 of 7 scored categories. Aembit leads on payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Aembit or Amazon Bedrock AgentCore Identity?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Aembit and Amazon Bedrock AgentCore Identity need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Aembit. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com.",
        "question": "Can an agent call Aembit and Amazon Bedrock AgentCore Identity without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 40 against 30",
          "Maintenance \u0026 community, 80 against 70"
        ],
        "also": null,
        "goodFor": "A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.",
        "slug": "aembit",
        "watchFor": "No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance"
      },
      {
        "aheadOn": [
          "Reliability, 85 against 65",
          "Transparency \u0026 trust, 75 against 60"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.",
        "slug": "agentcore-identity",
        "watchFor": "No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider."
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-arcade.json",
        "title": "Aembit vs Arcade.dev",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-arcade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents.json",
        "title": "Aembit vs Auth0 for AI Agents (Token Vault)",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity.json",
        "title": "Aembit vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-keycard.json",
        "title": "Aembit vs Keycard",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.json",
        "title": "Aembit vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-nango.json",
        "title": "Aembit vs Nango",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit.json",
        "title": "Aembit vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.json",
        "title": "Aembit vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-vercel-connect.json",
        "title": "Aembit vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-workos-pipes.json",
        "title": "Aembit vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.json",
        "title": "Amazon Bedrock AgentCore Identity vs Arcade.dev",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.json",
        "title": "Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.json",
        "title": "Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.json",
        "title": "Amazon Bedrock AgentCore Identity vs Keycard",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.json",
        "title": "Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.json",
        "title": "Amazon Bedrock AgentCore Identity vs Nango",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.json",
        "title": "Amazon Bedrock AgentCore Identity vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.json",
        "title": "Amazon Bedrock AgentCore Identity vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.json",
        "title": "Amazon Bedrock AgentCore Identity vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.json",
        "title": "Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "aembit": 65,
        "agentcore-identity": 85,
        "by": 20,
        "edge": "agentcore-identity",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "aembit": 85,
        "agentcore-identity": 88,
        "by": 3,
        "edge": "agentcore-identity",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "aembit": 72,
        "agentcore-identity": 76,
        "by": 4,
        "edge": "agentcore-identity",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "aembit": 84,
        "agentcore-identity": 84,
        "by": 0,
        "edge": "",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "aembit": 40,
        "agentcore-identity": 30,
        "by": 10,
        "edge": "aembit",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "aembit": 80,
        "agentcore-identity": 70,
        "by": 10,
        "edge": "aembit",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "aembit": 60,
        "agentcore-identity": 75,
        "by": 15,
        "edge": "agentcore-identity",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Aembit's 70.5 (BB), and leads in 4 of 7 scored categories. Aembit leads on payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth.",
    "verdicts": {
      "aembit": "Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.",
      "agentcore-identity": "The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity",
    "json": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.md",
    "slim": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.min.md"
  },
  "markdown": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Aembit's 70.5 (BB), and leads in 4 of 7 scored categories. Aembit leads on payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth.\n\n- Aembit: grade BB, 70.5/100, rank #147 of 842. Markdown https://www.anchorterminal.com/tools/aembit.md · JSON https://www.anchorterminal.com/api/v1/tools/aembit.json\n- Amazon Bedrock AgentCore Identity: grade BB, 74.8/100, rank #64 of 842. Markdown https://www.anchorterminal.com/tools/agentcore-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json\n\n## Which one, for what\n\n### Aembit (BB)\n\nGood for: A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.\n\nAhead on:\n- Payments \u0026 pricing, 40 against 30\n- Maintenance \u0026 community, 80 against 70\n\nWatch for: No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance\n\n### Amazon Bedrock AgentCore Identity (BB)\n\nGood for: Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.\n\nAhead on:\n- Reliability, 85 against 65\n- Transparency \u0026 trust, 75 against 60\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.\n\n\n## Score by category\n\n| Category | Weight | Aembit | Amazon Bedrock AgentCore Identity | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 85 | Amazon Bedrock AgentCore Identity +20 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 85 | 88 | Amazon Bedrock AgentCore Identity +3 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 76 | Amazon Bedrock AgentCore Identity +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 84 | 84 | even |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 30 | Aembit +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 70 | Aembit +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 60 | 75 | Amazon Bedrock AgentCore Identity +15 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **70.5 · BB** | **74.8 · BB** | |\n\n## Facts side by side\n\n| Fact | Aembit | Amazon Bedrock AgentCore Identity |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Aembit, Inc. | Amazon Web Services |\n| Hosted endpoint | no (local only) | `https://bedrock-agentcore.us-east-1.amazonaws.com` |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Pay per use |\n| Price for auth oauth | not published | $0.01 per 1,000 requests |\n| x402 | no | no |\n| Licence | Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0 | Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-09-01 |\n| Terms last updated | 2026-07-14 | 2026-10-01 |\n| Privacy policy last updated | 2026-05-05 | 2026-05-18 |\n| Customer content may train models | not found in the text | yes, with an opt-out |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | yes | yes |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 27 npm/wk | 335k npm/wk, 1.4M PyPI/wk |\n\n## Verdicts\n\n**Aembit.** Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.\n\n**Amazon Bedrock AgentCore Identity.** The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.\n\n## Before you call either\n\n### Aembit\n\n1. Read the API Base URL and token from the tenant's Profile page. Tokens last 1 hour by default, so plan to refresh\n2. Send `X-Aembit-ResourceSet` on Cloud API, Edge API and MCP calls outside the default Resource Set, or the request runs against the default set\n3. Cache the Edge API access token from `/edge/v1/auth` until near expiry before calling `/edge/v1/credentials`. Both endpoints can answer 429\n4. Point MCP clients at `https://\u003cgateway-host\u003e/mcp`. The `/me` path is deprecated\n5. Expect tool names prefixed with the Server Workload name behind the MCP Identity Gateway, and keep `perPage` at 100 or less on the Aembit MCP Server\n\n### Amazon Bedrock AgentCore Identity\n\n1. Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.\n2. When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.\n3. For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.\n4. Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.\n5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true.\n\n## Questions\n\n### Which is better for AI agents, Aembit or Amazon Bedrock AgentCore Identity?\n\nAmazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Aembit's 70.5 (BB), and leads in 4 of 7 scored categories. Aembit leads on payments \u0026 pricing and maintenance \u0026 community.\n\n### Do Aembit and Amazon Bedrock AgentCore Identity need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Aembit and Amazon Bedrock AgentCore Identity without installing anything?\n\nNo hosted endpoint is listed for Aembit. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.json, and with the fewest tokens: https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"aembit\", \"b\": \"agentcore-identity\"}`. From a terminal: `anchor compare aembit agentcore-identity`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/aembit.json and https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json\n\n## Other comparisons with Aembit or Amazon Bedrock AgentCore Identity\n\n- [Aembit vs Arcade.dev](https://www.anchorterminal.com/compare/aembit-vs-arcade.md)\n- [Aembit vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents.md)\n- [Aembit vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity.md)\n- [Aembit vs Keycard](https://www.anchorterminal.com/compare/aembit-vs-keycard.md)\n- [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md)\n- [Aembit vs Nango](https://www.anchorterminal.com/compare/aembit-vs-nango.md)\n- [Aembit vs Scalekit AgentKit](https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit.md)\n- [Aembit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.md)\n- [Aembit vs Vercel Connect](https://www.anchorterminal.com/compare/aembit-vs-vercel-connect.md)\n- [Aembit vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/aembit-vs-workos-pipes.md)\n- [Amazon Bedrock AgentCore Identity vs Arcade.dev](https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.md)\n- [Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.md)\n- [Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.md)\n- [Amazon Bedrock AgentCore Identity vs Keycard](https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.md)\n- [Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.md)\n- [Amazon Bedrock AgentCore Identity vs Nango](https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.md)\n- [Amazon Bedrock AgentCore Identity vs Scalekit AgentKit](https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.md)\n- [Amazon Bedrock AgentCore Identity vs Stytch Connected Apps](https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.md)\n- [Amazon Bedrock AgentCore Identity vs Vercel Connect](https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.md)\n- [Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Aembit vs Amazon Bedrock AgentCore Identity",
        "url": ""
      }
    ],
    "description": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Aembit's 70.5 (BB), and leads in 4 of 7 scored categories. Aembit leads on payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth. Category scores, facts, verdicts and agent notes side by…",
    "facts": [
      "Aembit BB 70.5",
      "Amazon Bedrock AgentCore Identity BB 74.8",
      "scores"
    ],
    "h1": "Aembit vs Amazon Bedrock AgentCore Identity",
    "image": "https://www.anchorterminal.com/assets/og/compare-aembit-vs-agentcore-identity.png",
    "path": "/compare/aembit-vs-agentcore-identity",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Aembit vs Amazon Bedrock AgentCore Identity for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity"
  },
  "tokens": {
    "markdown": 2650,
    "slim": 730
  },
  "version": 1
}
