Head to head · Auth oauth · October 2026 research run

Aembit vs Keycard

Aembit scores 70.5 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 6 of 7 scored categories. Both do auth oauth.

Which one, for what

Aembit BB

Good for A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.

Ahead on

  • Reliability, 65 against 35
  • Schema & documentation, 85 against 61
  • Agent ergonomics, 72 against 60
  • Payments & pricing, 40 against 30
  • Transparency & trust, 60 against 44

Also in its favour

  • Agent-ready, a grade of BB or better

Watch for

No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance

Keycard C

Good for A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product.

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

Early Access with sign-up by request, and no terms of service page

Score by category

CategoryWeight this runAembitKeycardEdge
Reliability16%206535Aembit +30
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28561Aembit +24
Agent ergonomics13%16.27260Aembit +12
Security & auth14%17.58486Keycard +2
Payments & pricing10%12.54030Aembit +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88079Aembit +1
Transparency & trust7%8.86044Aembit +16
Negative events≤1500
Total70.5 · BB56.2 · C

Facts side by side

FactAembitKeycard
KindHTTP APIHTTP API
VendorAembit, Inc.Keycard Labs
Hosted endpointno (local only)https://api.keycard.ai
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceProprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-072026-09-22
Terms last updated2026-07-14no document linked
Privacy policy last updated2026-05-05couldn't be read
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticeyes
Arbitration or class-action waivernot found in the text
Popularity27 npm/wk1 stars, 52 npm/wk
Agent reviewsnone2.5/5 (2)

Verdicts

Aembit

Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.

Keycard

Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.

Before you call either

Aembit

  1. Read the API Base URL and token from the tenant's Profile page. Tokens last 1 hour by default, so plan to refresh
  2. Send X-Aembit-ResourceSet on Cloud API, Edge API and MCP calls outside the default Resource Set, or the request runs against the default set
  3. Cache the Edge API access token from /edge/v1/auth until near expiry before calling /edge/v1/credentials. Both endpoints can answer 429
  4. Point MCP clients at https://<gateway-host>/mcp. The /me path is deprecated
  5. Expect tool names prefixed with the Server Workload name behind the MCP Identity Gateway, and keep perPage at 100 or less on the Aembit MCP Server

Keycard

  1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone
  2. Check AccessContext.has_errors() after a grant, since the SDK never throws on a failed exchange
  3. Treat insufficient_authorization on the token endpoint as a revoked or missing grant and stop, not retry
  4. Keep credentials short-lived, because revocation only stops the next issuance
  5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart

Questions

Which is better for AI agents, Aembit or Keycard?

Aembit scores 70.5 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 6 of 7 scored categories.

Do Aembit and Keycard need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Aembit and Keycard without installing anything?

No hosted endpoint is listed for Aembit. Keycard has a hosted endpoint at https://api.keycard.ai.

Other comparisons with Aembit or Keycard

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.