{
  "data": {
    "a": {
      "slug": "aembit",
      "name": "Aembit",
      "vendor": "Aembit, Inc.",
      "vendorUrl": "https://aembit.io",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Aembit is a hosted identity and access platform for workloads and AI agents. Its MCP Identity Gateway and MCP Authorisation Server apply access policies and inject credentials, with a Cloud API, an Edge API, a CLI and an Edge SDK.",
      "url": "https://www.anchorterminal.com/tools/aembit",
      "markdownUrl": "https://www.anchorterminal.com/tools/aembit.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/aembit.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/aembit.json",
      "repo": "https://github.com/Aembit/edge-sdks",
      "license": "Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@aembit/edge-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every API takes a short-lived Bearer token. For the Cloud API at https://\u003ctenant\u003e.aembit.io/api/v1, a person copies an API token from the tenant's Profile page (1 hour by default), or a workload obtains an Aembit Access Token through an Access Policy and a role. The Edge API exchanges platform attestation for an access token at /edge/v1/auth. MCP clients reach the MCP Identity Gateway and MCP Authorisation Server by OAuth 2.1 with PKCE and dynamic client registration or a Client ID Metadata Document, after the user signs in through the company's identity provider. Access is self-serve for a free tenant. The managed gateway endpoint is requested through an Aembit representative.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 3 AI agents, one MCP Identity Gateway and 5 MCP authorisation policies, or 10 workloads and 10 Access Policies, with 24 hours of event log retention. The pricing FAQ says no payment information is required. Teams is $20 per AI agent a month (to 500 agents) or $20 per workload a month, with a Contact Us button. Enterprise is custom. An agent can start on the free tenant without a contract (https://aembit.io/pricing/, checked 2026-10-08).",
      "priceSummary": "$20 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI files or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 27,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.aembit.io",
      "llmsTxt": "https://docs.aembit.io/llms.txt",
      "openapi": "https://docs.aembit.io/cloud.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.agent-identity",
        "auth.tokens",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "typescript",
        "cli",
        "terraform",
        "status-page",
        "soc2",
        "iso27001",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.5,
        "grade": "BB",
        "agentReady": true,
        "rank": 127,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 40,
          "reliability": 65,
          "schema": 85,
          "security": 84,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.",
        "bestFor": "A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.",
        "strengths": [
          "Public OpenAPI 3.1.1 files for the Cloud API (171 operations) and Edge API (2), plus llms.txt, per-page Markdown and a cloneable docs bundle",
          "No long-lived API credentials. Aembit API tokens last 1 hour by default and Edge API access tokens expire in 1 hour",
          "MCP clients authenticate by OAuth 2.1 with PKCE, dynamic client registration or a Client ID Metadata Document",
          "Audit logs, access authorisation events and workload events, exported by Log Streams to S3, Google Cloud Storage, Splunk or CrowdStrike",
          "Dated changelog with RSS. MCP Identity Gateway shipped four versions between 7 August and 7 October 2026"
        ],
        "weaknesses": [
          "No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance",
          "No SLA is published. The docs send SLA questions to Aembit support",
          "The managed MCP Identity Gateway endpoint is requested through an Aembit representative, and MCP Tool Access Control is enabled by support",
          "The Python Edge SDK is in the repository at 0.1.0 but pypi.org/project/aembit-edge-sdk returned 404 on 8 October 2026",
          "No DPA, sub-processor list or security.txt found on aembit.io. The trust centre returned 403 to our reader"
        ],
        "agentNotes": [
          "Read the API Base URL and token from the tenant's Profile page. Tokens last 1 hour by default, so plan to refresh",
          "Send `X-Aembit-ResourceSet` on Cloud API, Edge API and MCP calls outside the default Resource Set, or the request runs against the default set",
          "Cache the Edge API access token from `/edge/v1/auth` until near expiry before calling `/edge/v1/credentials`. Both endpoints can answer 429",
          "Point MCP clients at `https://\u003cgateway-host\u003e/mcp`. The `/me` path is deprecated",
          "Expect tool names prefixed with the Server Workload name behind the MCP Identity Gateway, and keep `perPage` at 100 or less on the Aembit MCP Server"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.5
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 40,
          "reliability": 65,
          "schema": 85,
          "security": 84,
          "transparency": 42
        },
        "provenanceScore": 78
      },
      "connect": {
        "install": "npm install @aembit/edge-sdk",
        "http": "curl -X GET -L 'https://tenant.aembit.io/api/v1/server-workloads' -H 'Authorization: Bearer \u003cTOKEN\u003e'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/aembit"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Teams, each AI agent",
          "unit": "month",
          "usd": 20,
          "note": "Priced per agent a month, up to 500 agents"
        },
        {
          "item": "Teams, each workload",
          "unit": "month",
          "usd": 20,
          "note": "Priced per workload a month"
        }
      ],
      "provenance": {
        "legalEntity": "Aembit, Inc.",
        "domain": "aembit.io",
        "domainRegistered": "2021-03-14",
        "endpointOnVendorDomain": true,
        "terms": "https://aembit.io/terms-of-service/",
        "privacy": "https://aembit.io/privacy-policy/",
        "statusPage": "https://status.aembit.io",
        "changelog": "https://docs.aembit.io/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last reviewed 14 July 2026) are between the customer and Aembit, Inc., define the Services as the website and the web-based and downloadable workload identity and access management services, and choose Delaware law.",
          "The privacy policy (last updated 5 May 2026) names Aembit, Inc. and covers the platform, websites and related services.",
          "aembit.io/.well-known/security.txt and docs.aembit.io/.well-known/security.txt both returned 404. The docs give security@aembit.io as the security contact.",
          "RDAP at Identity Digital gives a registration date of 2021-03-14 for aembit.io.",
          "Tenant APIs answer at https://\u003ctenant\u003e.aembit.io and the managed gateway at https://\u003ctenantId\u003e.mcpgateway.aembit.io, both on the vendor's domain.",
          "No DPA, sub-processor or SLA page was found at the obvious aembit.io paths, and trust.aembit.io returned 403 to our reader."
        ],
        "score": 78
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/aembit.json",
      "live": {
        "slug": "aembit",
        "vendorStatus": {
          "page": "https://status.aembit.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:25.306023091Z"
        },
        "pages": [
          {
            "url": "https://docs.aembit.io/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:07.775115006Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4e930f2cc1ec"
          },
          {
            "url": "https://aembit.io/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:14:59.808222145Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "781c90a65067"
          },
          {
            "url": "https://aembit.io/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:01.881687653Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "753e7b8821e4"
          },
          {
            "url": "https://aembit.io/terms-of-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:03.860763085Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ad42c0fa0432"
          }
        ],
        "updatedAt": "2026-10-08T19:06:25.306023091Z"
      }
    },
    "answer": "Auth0 for AI Agents (Token Vault) and Aembit score within a point of each other on agent readiness, 71.4 (BB) and 70.5 (BB). Aembit leads on schema \u0026 documentation, payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "auth0-ai-agents",
      "name": "Auth0 for AI Agents (Token Vault)",
      "vendor": "Auth0 by Okta",
      "vendorUrl": "https://auth0.com/ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Auth0's identity and authorisation tools for AI agents, built on its identity platform.",
      "url": "https://www.anchorterminal.com/tools/auth0-ai-agents",
      "markdownUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json",
      "repo": "https://github.com/auth0/auth0-ai-js",
      "license": "Apache-2.0 (SDKs), platform closed",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://{tenant}.auth0.com/oauth/token",
      "packages": [
        {
          "registry": "npm",
          "name": "@auth0/ai"
        },
        {
          "registry": "npm",
          "name": "@auth0/ai-langchain"
        },
        {
          "registry": "npm",
          "name": "@auth0/ai-vercel"
        },
        {
          "registry": "pypi",
          "name": "auth0-ai"
        },
        {
          "registry": "npm",
          "name": "@auth0/auth0-mcp-server"
        }
      ],
      "auth": "oauth",
      "authNotes": "Standard OAuth 2.0 and OIDC against your tenant. The app exchanges the user's Auth0 refresh token or access token at /oauth/token with the grant type `urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token` and gets back the external provider's access token. Backend workers can use a signed JWT (privileged worker exchange). DPoP can bind Auth0 tokens to the client. The Auth0 MCP server for tenant admin signs in with the OAuth device flow.",
      "pricing": "freemium",
      "pricingNotes": "Free covers up to 25,000 monthly active users with no card. Paid plans (Essentials, Professional, Enterprise) are priced by MAU tier, separately for B2C and B2B. Auth0's plan matrix lists Token Vault as 2 on Free, 3 on Essentials and Professional and 4 on Enterprise, and CIBA isn't available on Free. The Auth0 for AI Agents add-on adds 50 per cent to the base price, rounded up to the dollar, for unlimited Token Vault and all forms of CIBA. Yearly billing is 11 times the monthly price. Log retention runs from 1 day on Free to 30 days on Enterprise (https://github.com/auth0/docs-v2/blob/main/main/.mintlify/skills/auth0/references/feature-audit-pricing/index.md, https://auth0.com/pricing). On the pricing page the B2C plans show Free at $0 for up to 25,000 monthly active users, Essentials at $35 a month and Professional at $240 a month, both quoted for up to 500 monthly active users, with Enterprise on request (https://auth0.com/pricing).",
      "priceSummary": "Freemium",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 16,
        "npmWeekly": 3114,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://auth0.com/ai/docs",
      "llmsTxt": "https://auth0.com/ai/docs/llms.txt",
      "registryName": "com.auth0/mcp",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "hitl.approve"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "typescript",
        "python",
        "enterprise",
        "mcp"
      ],
      "lastRelease": "2026-09-18",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 103,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 74,
          "payments": 30,
          "reliability": 75,
          "schema": 73,
          "security": 88,
          "transparency": 84
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users.",
        "bestFor": "Best when Auth0 already runs login and the agent needs a handful of the user's Google, Microsoft, Slack or GitHub tokens, or a second-device approval before a payment or delete.",
        "strengths": [
          "Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP",
          "Human approval on a second device for sensitive actions, showing the exact payee or amount",
          "Free plan up to 25,000 monthly active users with no card",
          "Deprecations listed with announcement and end-of-life dates six to seven months apart",
          "Bugcrowd programme, valid security.txt and an Enterprise SLA of 99.99 per cent"
        ],
        "weaknesses": [
          "Only works when Auth0 is the identity provider for your users",
          "Two Token Vault connections on Free and three on Essentials and Professional without the add-on",
          "Log retention of 1 day on Free and 5 days on Essentials is short for an audit trail",
          "No OpenAPI schema for the Authentication API that the exchange uses",
          "Agent SDKs last released in April 2026 (JavaScript) and January 2026 (Python)"
        ],
        "agentNotes": [
          "Turn off refresh token rotation on the application before using the refresh token exchange",
          "Treat a 401 from the exchange as a missing connected account and send the user through the Connected Accounts flow",
          "Pass login_hint when a user has linked two accounts from the same provider",
          "Use CIBA for purchases or deletes and wait for the approval instead of asking in chat",
          "Read X-RateLimit-Reset on a 429 and back off until then"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.4
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 74,
          "payments": 30,
          "reliability": 75,
          "schema": 73,
          "security": 88,
          "transparency": 70
        },
        "provenanceScore": 97
      },
      "connect": {
        "install": "npm install @auth0/ai",
        "http": "curl -X POST \"https://$AUTH0_DOMAIN/oauth/token\" \\\n  -d grant_type=urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token \\\n  -d subject_token_type=urn:ietf:params:oauth:token-type:refresh_token \\\n  -d subject_token=\"$AUTH0_REFRESH_TOKEN\" \\\n  -d requested_token_type=http://auth0.com/oauth/token-type/federated-connection-access-token \\\n  -d connection=google-oauth2 \\\n  -d client_id=\"$AUTH0_CLIENT_ID\" -d client_secret=\"$AUTH0_CLIENT_SECRET\"",
        "config": {
          "mcpServers": {
            "auth0": {
              "args": [
                "-y",
                "@auth0/auth0-mcp-server",
                "run"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/auth0-ai-agents"
      },
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Okta, Inc.",
        "domain": "auth0.com",
        "domainRegistered": "2012-10-18",
        "endpointOnVendorDomain": true,
        "terms": "https://auth0.com/legal",
        "privacy": "https://www.okta.com/privacy-policy/",
        "statusPage": "https://status.auth0.com",
        "changelog": "https://auth0.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "notes": [
          "We couldn't read the terms page on 2026-09-30.",
          "The Auth0 MCP server (@auth0/auth0-mcp-server, version 0.1.0-beta.19) manages your tenant. It isn't how an agent gets user tokens."
        ],
        "score": 97
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.json",
      "live": {
        "slug": "auth0-ai-agents",
        "probe": {
          "target": "https://{tenant}.auth0.com/oauth/token",
          "method": "get",
          "lastAt": "2026-10-08T19:08:39.846630227Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 272,
          "samples30d": 1933,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 0
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 0
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 0
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 0
            },
            {
              "date": "2026-10-08",
              "probes": 217,
              "ok": 0
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.auth0.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T17:50:22.90546805Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "auth0/auth0-ai-js",
            "version": "@auth0/ai-vercel-v5.1.1",
            "released": "2026-04-22",
            "seenAt": "2026-10-08T16:00:16.881579068Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.auth0/mcp",
            "version": "0.1.0-beta.10",
            "seenAt": "2026-10-08T02:42:52.272076636Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai",
            "version": "6.0.2",
            "seenAt": "2026-10-08T16:00:07.151271236Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai-langchain",
            "version": "5.0.2",
            "seenAt": "2026-10-08T16:00:11.11785045Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai-vercel",
            "version": "5.1.1",
            "seenAt": "2026-10-08T16:00:11.491195505Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/auth0-mcp-server",
            "version": "0.1.0-beta.19",
            "seenAt": "2026-10-08T16:00:16.635027644Z"
          },
          {
            "registry": "pypi",
            "name": "auth0-ai",
            "version": "1.0.2",
            "released": "2026-01-20",
            "seenAt": "2026-10-08T16:00:13.354695893Z"
          }
        ],
        "githubStars": 16,
        "npmWeekly": 5756,
        "pypiWeekly": 204,
        "securityTxt": {
          "url": "https://auth0.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-01-01T08:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:39.123462908Z"
        },
        "llmsTxt": {
          "url": "https://auth0.com/ai/docs/llms.txt",
          "ok": false,
          "status": 404,
          "checkedAt": "2026-10-08T14:00:04.745442501Z"
        },
        "domain": {
          "domain": "auth0.com",
          "registered": "2012-10-18",
          "source": "https://rdap.verisign.com/com/v1/domain/auth0.com",
          "checkedAt": "2026-10-04T13:06:20.951498912Z"
        },
        "pages": [
          {
            "url": "https://auth0.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:26.779773705Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2ecd4d6660eb"
          },
          {
            "url": "https://auth0.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-08T18:15:29.251984813Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8730de5a8d15"
          },
          {
            "url": "https://raw.githubusercontent.com/auth0/docs-v2/main/main/.mintlify/skills/auth0/references/feature-audit-pricing/index.md",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-08T18:23:59.779721296Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d3bbfc00df65"
          },
          {
            "url": "https://www.okta.com/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:25.460956149Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "be09b03a3016"
          },
          {
            "url": "https://auth0.com/legal",
            "kind": "terms",
            "status": 0,
            "checkedAt": "2026-10-08T18:15:29.251971584Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-08T19:08:39.846630227Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Aembit, Inc.",
        "b": "Auth0 by Okta",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://{tenant}.auth0.com/oauth/token",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0",
        "b": "Apache-2.0 (SDKs), platform closed",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "com.auth0/mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-07",
        "b": "2026-09-18",
        "name": "Last release"
      },
      {
        "a": "2026-07-14",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-05",
        "b": "2026-06-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "27 npm/wk",
        "b": "16 stars, 3.1k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Auth0 for AI Agents (Token Vault) and Aembit score within a point of each other on agent readiness, 71.4 (BB) and 70.5 (BB). Aembit leads on schema \u0026 documentation, payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Aembit or Auth0 for AI Agents (Token Vault)?"
      },
      {
        "answer": "Aembit takes an API key or an OAuth sign-in. Auth0 for AI Agents (Token Vault) uses an OAuth sign-in.",
        "question": "Do Aembit and Auth0 for AI Agents (Token Vault) need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Aembit. Auth0 for AI Agents (Token Vault) has a hosted endpoint at https://{tenant}.auth0.com/oauth/token.",
        "question": "Can an agent call Aembit and Auth0 for AI Agents (Token Vault) without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 85 against 73",
          "Payments \u0026 pricing, 40 against 30",
          "Maintenance \u0026 community, 80 against 74"
        ],
        "also": null,
        "goodFor": "A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.",
        "slug": "aembit",
        "watchFor": "No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance"
      },
      {
        "aheadOn": [
          "Reliability, 75 against 65",
          "Transparency \u0026 trust, 84 against 60"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Runs on your own machine",
          "Free to start without a card"
        ],
        "goodFor": "Best when Auth0 already runs login and the agent needs a handful of the user's Google, Microsoft, Slack or GitHub tokens, or a second-device approval before a payment or delete.",
        "slug": "auth0-ai-agents",
        "watchFor": "Only works when Auth0 is the identity provider for your users"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-arcade.json",
        "title": "Aembit vs Arcade.dev",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-arcade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity.json",
        "title": "Aembit vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-keycard.json",
        "title": "Aembit vs Keycard",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.json",
        "title": "Aembit vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-nango.json",
        "title": "Aembit vs Nango",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit.json",
        "title": "Aembit vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.json",
        "title": "Aembit vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-workos-pipes.json",
        "title": "Aembit vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents.json",
        "title": "Arcade.dev vs Auth0 for AI Agents (Token Vault)",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Keycard",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Nango",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-scalekit-agentkit.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.json",
        "title": "Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "aembit": 65,
        "auth0-ai-agents": 75,
        "by": 10,
        "edge": "auth0-ai-agents",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "aembit": 85,
        "auth0-ai-agents": 73,
        "by": 12,
        "edge": "aembit",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "aembit": 72,
        "auth0-ai-agents": 71,
        "by": 1,
        "edge": "aembit",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "aembit": 84,
        "auth0-ai-agents": 88,
        "by": 4,
        "edge": "auth0-ai-agents",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "aembit": 40,
        "auth0-ai-agents": 30,
        "by": 10,
        "edge": "aembit",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "aembit": 80,
        "auth0-ai-agents": 74,
        "by": 6,
        "edge": "aembit",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "aembit": 60,
        "auth0-ai-agents": 84,
        "by": 24,
        "edge": "auth0-ai-agents",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Auth0 for AI Agents (Token Vault) and Aembit score within a point of each other on agent readiness, 71.4 (BB) and 70.5 (BB). Aembit leads on schema \u0026 documentation, payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth.",
    "verdicts": {
      "aembit": "Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.",
      "auth0-ai-agents": "Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents",
    "json": "https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents.md",
    "slim": "https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents.min.md"
  },
  "markdown": "Auth0 for AI Agents (Token Vault) and Aembit score within a point of each other on agent readiness, 71.4 (BB) and 70.5 (BB). Aembit leads on schema \u0026 documentation, payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth.\n\n- Aembit: grade BB, 70.5/100, rank #127 of 629. Markdown https://www.anchorterminal.com/tools/aembit.md · JSON https://www.anchorterminal.com/api/v1/tools/aembit.json\n- Auth0 for AI Agents (Token Vault): grade BB, 71.4/100, rank #103 of 629. Markdown https://www.anchorterminal.com/tools/auth0-ai-agents.md · JSON https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json\n\n## Which one, for what\n\n### Aembit (BB)\n\nGood for: A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.\n\nAhead on:\n- Schema \u0026 documentation, 85 against 73\n- Payments \u0026 pricing, 40 against 30\n- Maintenance \u0026 community, 80 against 74\n\nWatch for: No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance\n\n### Auth0 for AI Agents (Token Vault) (BB)\n\nGood for: Best when Auth0 already runs login and the agent needs a handful of the user's Google, Microsoft, Slack or GitHub tokens, or a second-device approval before a payment or delete.\n\nAhead on:\n- Reliability, 75 against 65\n- Transparency \u0026 trust, 84 against 60\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Runs on your own machine\n- Free to start without a card\n\nWatch for: Only works when Auth0 is the identity provider for your users\n\n\n## Score by category\n\n| Category | Weight | Aembit | Auth0 for AI Agents (Token Vault) | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 75 | Auth0 for AI Agents (Token Vault) +10 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 85 | 73 | Aembit +12 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 71 | Aembit +1 |\n| Security \u0026 auth | 14% (17.5 this run) | 84 | 88 | Auth0 for AI Agents (Token Vault) +4 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 30 | Aembit +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 74 | Aembit +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 60 | 84 | Auth0 for AI Agents (Token Vault) +24 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **70.5 · BB** | **71.4 · BB** | |\n\n## Facts side by side\n\n| Fact | Aembit | Auth0 for AI Agents (Token Vault) |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Aembit, Inc. | Auth0 by Okta |\n| Hosted endpoint | no (local only) | `https://{tenant}.auth0.com/oauth/token` |\n| Transports | HTTP, Streamable HTTP | HTTP, stdio |\n| Auth | OAuth or key | OAuth |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0 | Apache-2.0 (SDKs), platform closed |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | `com.auth0/mcp` |\n| Last release | 2026-10-07 | 2026-09-18 |\n| Terms last updated | 2026-07-14 | couldn't be read |\n| Privacy policy last updated | 2026-05-05 | 2026-06-01 |\n| Customer content may train models | not found in the text | couldn't be read |\n| Terms restrict automated access | not found in the text | couldn't be read |\n| Terms restrict benchmarking | yes | couldn't be read |\n| Terms or service can change without notice | yes | couldn't be read |\n| Arbitration or class-action waiver | not found in the text | couldn't be read |\n| Popularity | 27 npm/wk | 16 stars, 3.1k npm/wk |\n| Agent reviews | none | 3.5/5 (2) |\n\n## Verdicts\n\n**Aembit.** Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.\n\n**Auth0 for AI Agents (Token Vault).** Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users.\n\n## Before you call either\n\n### Aembit\n\n1. Read the API Base URL and token from the tenant's Profile page. Tokens last 1 hour by default, so plan to refresh\n2. Send `X-Aembit-ResourceSet` on Cloud API, Edge API and MCP calls outside the default Resource Set, or the request runs against the default set\n3. Cache the Edge API access token from `/edge/v1/auth` until near expiry before calling `/edge/v1/credentials`. Both endpoints can answer 429\n4. Point MCP clients at `https://\u003cgateway-host\u003e/mcp`. The `/me` path is deprecated\n5. Expect tool names prefixed with the Server Workload name behind the MCP Identity Gateway, and keep `perPage` at 100 or less on the Aembit MCP Server\n\n### Auth0 for AI Agents (Token Vault)\n\n1. Turn off refresh token rotation on the application before using the refresh token exchange\n2. Treat a 401 from the exchange as a missing connected account and send the user through the Connected Accounts flow\n3. Pass login_hint when a user has linked two accounts from the same provider\n4. Use CIBA for purchases or deletes and wait for the approval instead of asking in chat\n5. Read X-RateLimit-Reset on a 429 and back off until then\n\n## Questions\n\n### Which is better for AI agents, Aembit or Auth0 for AI Agents (Token Vault)?\n\nAuth0 for AI Agents (Token Vault) and Aembit score within a point of each other on agent readiness, 71.4 (BB) and 70.5 (BB). Aembit leads on schema \u0026 documentation, payments \u0026 pricing and maintenance \u0026 community.\n\n### Do Aembit and Auth0 for AI Agents (Token Vault) need an API key?\n\nAembit takes an API key or an OAuth sign-in. Auth0 for AI Agents (Token Vault) uses an OAuth sign-in.\n\n### Can an agent call Aembit and Auth0 for AI Agents (Token Vault) without installing anything?\n\nNo hosted endpoint is listed for Aembit. Auth0 for AI Agents (Token Vault) has a hosted endpoint at https://{tenant}.auth0.com/oauth/token.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents.json, and with the fewest tokens: https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"aembit\", \"b\": \"auth0-ai-agents\"}`. From a terminal: `anchor compare aembit auth0-ai-agents`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/aembit.json and https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json\n\n## Other comparisons with Aembit or Auth0 for AI Agents (Token Vault)\n\n- [Aembit vs Arcade.dev](https://www.anchorterminal.com/compare/aembit-vs-arcade.md)\n- [Aembit vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity.md)\n- [Aembit vs Keycard](https://www.anchorterminal.com/compare/aembit-vs-keycard.md)\n- [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md)\n- [Aembit vs Nango](https://www.anchorterminal.com/compare/aembit-vs-nango.md)\n- [Aembit vs Scalekit AgentKit](https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit.md)\n- [Aembit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.md)\n- [Aembit vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/aembit-vs-workos-pipes.md)\n- [Arcade.dev vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents.md)\n- [Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.md)\n- [Auth0 for AI Agents (Token Vault) vs Nango](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango.md)\n- [Auth0 for AI Agents (Token Vault) vs Scalekit AgentKit](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-scalekit-agentkit.md)\n- [Auth0 for AI Agents (Token Vault) vs Stytch Connected Apps](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps.md)\n- [Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Aembit vs Auth0 for AI Agents (Token Vault)",
        "url": ""
      }
    ],
    "description": "Auth0 for AI Agents (Token Vault) and Aembit score within a point of each other on agent readiness, 71.4 (BB) and 70.5 (BB). Aembit leads on schema \u0026 documentation, payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth. Category scores, facts, verdicts and agent…",
    "facts": [
      "Aembit BB 70.5",
      "Auth0 for AI Agents (Token Vault) BB 71.4",
      "scores"
    ],
    "h1": "Aembit vs Auth0 for AI Agents (Token Vault)",
    "image": "https://www.anchorterminal.com/assets/og/compare-aembit-vs-auth0-ai-agents.png",
    "path": "/compare/aembit-vs-auth0-ai-agents",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Aembit vs Auth0 for AI Agents (Token Vault) for AI agents",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 780
  },
  "version": 1
}
