{
  "data": {
    "a": {
      "slug": "aembit",
      "name": "Aembit",
      "vendor": "Aembit, Inc.",
      "vendorUrl": "https://aembit.io",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Aembit is a hosted identity and access platform for workloads and AI agents. Its MCP Identity Gateway and MCP Authorisation Server apply access policies and inject credentials, with a Cloud API, an Edge API, a CLI and an Edge SDK.",
      "url": "https://www.anchorterminal.com/tools/aembit",
      "markdownUrl": "https://www.anchorterminal.com/tools/aembit.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/aembit.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/aembit.json",
      "repo": "https://github.com/Aembit/edge-sdks",
      "license": "Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@aembit/edge-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every API takes a short-lived Bearer token. For the Cloud API at https://\u003ctenant\u003e.aembit.io/api/v1, a person copies an API token from the tenant's Profile page (1 hour by default), or a workload obtains an Aembit Access Token through an Access Policy and a role. The Edge API exchanges platform attestation for an access token at /edge/v1/auth. MCP clients reach the MCP Identity Gateway and MCP Authorisation Server by OAuth 2.1 with PKCE and dynamic client registration or a Client ID Metadata Document, after the user signs in through the company's identity provider. Access is self-serve for a free tenant. The managed gateway endpoint is requested through an Aembit representative.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 3 AI agents, one MCP Identity Gateway and 5 MCP authorisation policies, or 10 workloads and 10 Access Policies, with 24 hours of event log retention. The pricing FAQ says no payment information is required. Teams is $20 per AI agent a month (to 500 agents) or $20 per workload a month, with a Contact Us button. Enterprise is custom. An agent can start on the free tenant without a contract (https://aembit.io/pricing/, checked 2026-10-08).",
      "priceSummary": "$20 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI files or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 27,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.aembit.io",
      "llmsTxt": "https://docs.aembit.io/llms.txt",
      "openapi": "https://docs.aembit.io/cloud.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.agent-identity",
        "auth.tokens",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "typescript",
        "cli",
        "terraform",
        "status-page",
        "soc2",
        "iso27001",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.5,
        "grade": "BB",
        "agentReady": true,
        "rank": 134,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 40,
          "reliability": 65,
          "schema": 85,
          "security": 84,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.",
        "bestFor": "A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.",
        "strengths": [
          "Public OpenAPI 3.1.1 files for the Cloud API (171 operations) and Edge API (2), plus llms.txt, per-page Markdown and a cloneable docs bundle",
          "No long-lived API credentials. Aembit API tokens last 1 hour by default and Edge API access tokens expire in 1 hour",
          "MCP clients authenticate by OAuth 2.1 with PKCE, dynamic client registration or a Client ID Metadata Document",
          "Audit logs, access authorisation events and workload events, exported by Log Streams to S3, Google Cloud Storage, Splunk or CrowdStrike",
          "Dated changelog with RSS. MCP Identity Gateway shipped four versions between 7 August and 7 October 2026"
        ],
        "weaknesses": [
          "No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance",
          "No SLA is published. The docs send SLA questions to Aembit support",
          "The managed MCP Identity Gateway endpoint is requested through an Aembit representative, and MCP Tool Access Control is enabled by support",
          "The Python Edge SDK is in the repository at 0.1.0 but pypi.org/project/aembit-edge-sdk returned 404 on 8 October 2026",
          "No DPA, sub-processor list or security.txt found on aembit.io. The trust centre returned 403 to our reader"
        ],
        "agentNotes": [
          "Read the API Base URL and token from the tenant's Profile page. Tokens last 1 hour by default, so plan to refresh",
          "Send `X-Aembit-ResourceSet` on Cloud API, Edge API and MCP calls outside the default Resource Set, or the request runs against the default set",
          "Cache the Edge API access token from `/edge/v1/auth` until near expiry before calling `/edge/v1/credentials`. Both endpoints can answer 429",
          "Point MCP clients at `https://\u003cgateway-host\u003e/mcp`. The `/me` path is deprecated",
          "Expect tool names prefixed with the Server Workload name behind the MCP Identity Gateway, and keep `perPage` at 100 or less on the Aembit MCP Server"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.5
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 40,
          "reliability": 65,
          "schema": 85,
          "security": 84,
          "transparency": 42
        },
        "provenanceScore": 78
      },
      "connect": {
        "install": "npm install @aembit/edge-sdk",
        "http": "curl -X GET -L 'https://tenant.aembit.io/api/v1/server-workloads' -H 'Authorization: Bearer \u003cTOKEN\u003e'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/aembit"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Teams, each AI agent",
          "unit": "month",
          "usd": 20,
          "note": "Priced per agent a month, up to 500 agents"
        },
        {
          "item": "Teams, each workload",
          "unit": "month",
          "usd": 20,
          "note": "Priced per workload a month"
        }
      ],
      "provenance": {
        "legalEntity": "Aembit, Inc.",
        "domain": "aembit.io",
        "domainRegistered": "2021-03-14",
        "endpointOnVendorDomain": true,
        "terms": "https://aembit.io/terms-of-service/",
        "privacy": "https://aembit.io/privacy-policy/",
        "statusPage": "https://status.aembit.io",
        "changelog": "https://docs.aembit.io/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last reviewed 14 July 2026) are between the customer and Aembit, Inc., define the Services as the website and the web-based and downloadable workload identity and access management services, and choose Delaware law.",
          "The privacy policy (last updated 5 May 2026) names Aembit, Inc. and covers the platform, websites and related services.",
          "aembit.io/.well-known/security.txt and docs.aembit.io/.well-known/security.txt both returned 404. The docs give security@aembit.io as the security contact.",
          "RDAP at Identity Digital gives a registration date of 2021-03-14 for aembit.io.",
          "Tenant APIs answer at https://\u003ctenant\u003e.aembit.io and the managed gateway at https://\u003ctenantId\u003e.mcpgateway.aembit.io, both on the vendor's domain.",
          "No DPA, sub-processor or SLA page was found at the obvious aembit.io paths, and trust.aembit.io returned 403 to our reader."
        ],
        "score": 78
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/aembit.json",
      "live": {
        "slug": "aembit",
        "vendorStatus": {
          "page": "https://status.aembit.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T20:22:18.582119143Z"
        },
        "pages": [
          {
            "url": "https://docs.aembit.io/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:07.775115006Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4e930f2cc1ec"
          },
          {
            "url": "https://aembit.io/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:14:59.808222145Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "781c90a65067"
          },
          {
            "url": "https://aembit.io/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:01.881687653Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "753e7b8821e4"
          },
          {
            "url": "https://aembit.io/terms-of-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:03.860763085Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ad42c0fa0432"
          }
        ],
        "updatedAt": "2026-10-08T20:22:18.582119143Z"
      }
    },
    "answer": "Aembit scores 70.5 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 6 of 7 scored categories.",
    "b": {
      "slug": "keycard",
      "name": "Keycard",
      "vendor": "Keycard Labs",
      "vendorUrl": "https://www.keycard.ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Identity and access platform for AI agents.",
      "url": "https://www.anchorterminal.com/tools/keycard",
      "markdownUrl": "https://www.anchorterminal.com/tools/keycard.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keycard.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keycard.json",
      "repo": "https://github.com/keycardai/python-sdk",
      "license": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.keycard.ai",
      "packages": [
        {
          "registry": "pypi",
          "name": "keycardai-mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai-fastmcp"
        },
        {
          "registry": "npm",
          "name": "@keycardai/mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai_api"
        }
      ],
      "auth": "mixed",
      "authNotes": "The management API at api.keycard.ai takes `Authorization: Bearer $KEYCARD_API_KEY` (a service account key). Agents and MCP servers talk OAuth 2.0 to their zone at `https://\u003czone-id\u003e.keycard.cloud`, discovered from `/.well-known/oauth-authorization-server`, with PKCE, dynamic client registration and RFC 8693 token exchange against the token endpoint. Application credentials are a client secret, a web identity (OIDC) or EKS workload identity. Tokens are JWTs verified against the zone's JWKS.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 5,000 transactions a month as a hard cap, unlimited users, agents and apps, RBAC, ABAC and ReBAC policies, 7-day telemetry retention and community support. Team is $500 a month with 100,000 transactions and $1 per 1,000 after, SSO, zone policy, 90-day retention, email support and an SLA. Enterprise is custom on an annual commitment, with org and device-based policy, SCIM, Active Directory and LDAP provisioning, dedicated, BYOC or on-prem deployment, private networking, customer-managed KMS, 180-day retention, a 99.95 per cent uptime SLA and 1-hour 24/7 response on P1 issues. A transaction is recorded each time Keycard issues a credential, validates an access request or exchanges a credential (https://www.keycard.ai/pricing). The page doesn't say whether a card is needed, and its sign-up form ends with a promise to be in touch. The quickstart calls the product Early Access, with sign-up at console.keycard.ai.",
      "priceSummary": "$500 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1,
        "npmWeekly": 52,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.keycard.ai",
      "llmsTxt": "https://docs.keycard.ai/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.2,
        "grade": "C",
        "agentReady": false,
        "rank": 492,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 44
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.",
        "bestFor": "A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product.",
        "strengths": [
          "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange",
          "Delegated grants with RFC 8693 exchange for GitHub, Google, Slack, Linear and any OAuth 2.0 provider",
          "Session timeline and audit log per exchange, exported hourly to S3 in OCSF Parquet",
          "Published per-unit price ($1 per 1,000 transactions on Team) with a transaction defined",
          "Valid security.txt and SOC 2 Type 2 listed in a SafeBase trust centre"
        ],
        "weaknesses": [
          "Early Access with sign-up by request, and no terms of service page",
          "No per-token kill switch, so a revoked grant lives until the token expires, and revocation doesn't reach the provider",
          "No published rate limits, 429 guidance or public changelog",
          "keycardai-mcp went from 1.0.0 to 2.0.0 in a day in August 2026",
          "Team is $500 a month with nothing between it and the free tier"
        ],
        "agentNotes": [
          "Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone",
          "Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange",
          "Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry",
          "Keep credentials short-lived, because revocation only stops the next issuance",
          "Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.2
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 25
        },
        "provenanceScore": 62
      },
      "connect": {
        "install": "pip install keycardai-mcp",
        "http": "curl \"https://api.keycard.ai/zones/$KEYCARD_ZONE_ID/sessions\" \\\n  -H \"Authorization: Bearer $KEYCARD_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/keycard"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 500,
          "note": "100,000 transactions included"
        },
        {
          "item": "Transactions above 100,000 on Team",
          "unit": "1k-calls",
          "usd": 1,
          "note": "The pricing page doesn't define a transaction"
        }
      ],
      "provenance": {
        "legalEntity": "Keycard Labs, Inc.",
        "domain": "keycard.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://www.keycard.ai/privacy/",
        "statusPage": "https://status.keycard.ai",
        "changelog": "",
        "securityTxt": "valid",
        "checked": "2026-10-02",
        "notes": [
          "The homepage footer names Keycard Labs, Inc., 103 Foulk Road, Suite 202, Wilmington, DE 19808. The footer's legal links on 2 October were privacy, cookie policy, a vulnerability address and the trust centre at trust.keycard.ai. We found no terms of service page (keycard.ai/terms/ returns 404) and the privacy page's body didn't load for us on 30 September or 2 October.",
          "RDAP for keycard.ai returned 404 at rdap.nic.ai and 429 at Identity Digital on 2026-09-30, so the registration date is blank.",
          "status.keycard.ai answers as a status page, though its history renders client-side and its JSON and RSS feeds returned 403 to us on 2 October.",
          "The docs index (73 entries) lists no changelog. The SDK repositories' CHANGELOG.md files are the nearest thing to release notes.",
          "The trust centre lists SOC 2 Type 1 and Type 2 reports and names Resend, Google, GitHub, Cloudflare and AWS as subprocessors."
        ],
        "score": 62
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/keycard.json",
      "live": {
        "slug": "keycard",
        "probe": {
          "target": "https://api.keycard.ai",
          "method": "get",
          "lastAt": "2026-10-08T20:21:16.694766433Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 290,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 299,
          "p95ms24h": 381,
          "samples24h": 272,
          "samples30d": 1946,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 230,
              "ok": 230
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.keycard.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:43.424506056Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@keycardai/mcp",
            "version": "2.0.2",
            "seenAt": "2026-10-08T16:17:39.557981658Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-fastmcp",
            "version": "0.7.1",
            "released": "2026-09-15",
            "seenAt": "2026-10-08T16:17:37.664040081Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-mcp",
            "version": "2.3.2",
            "released": "2026-09-16",
            "seenAt": "2026-10-08T16:17:37.473812095Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai_api",
            "version": "0.18.0",
            "released": "2026-09-25",
            "seenAt": "2026-10-08T16:17:43.121407528Z"
          }
        ],
        "githubStars": 1,
        "npmWeekly": 199,
        "pypiWeekly": 164,
        "securityTxt": {
          "url": "https://keycard.ai/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-12T00:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:48.873310409Z"
        },
        "llmsTxt": {
          "url": "https://docs.keycard.ai/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:33.244940883Z"
        },
        "domain": {
          "domain": "keycard.ai",
          "registered": "2024-02-04",
          "source": "https://rdap.identitydigital.services/rdap/domain/keycard.ai",
          "checkedAt": "2026-10-04T13:06:32.92261194Z"
        },
        "pages": [
          {
            "url": "https://www.keycard.ai/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:36.483812542Z",
            "changedAt": "2026-10-08T18:28:36.483812542Z",
            "fingerprint": "ebe4ceb994c4"
          },
          {
            "url": "https://www.keycard.ai/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:38.627980953Z",
            "changedAt": "2026-10-08T18:28:38.627980953Z",
            "fingerprint": "5d00b76169d9"
          }
        ],
        "updatedAt": "2026-10-08T20:21:16.694766433Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Aembit, Inc.",
        "b": "Keycard Labs",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.keycard.ai",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0",
        "b": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-09-22",
        "name": "Last release"
      },
      {
        "a": "2026-07-14",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-05",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "27 npm/wk",
        "b": "1 stars, 52 npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Aembit scores 70.5 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 6 of 7 scored categories.",
        "question": "Which is better for AI agents, Aembit or Keycard?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Aembit and Keycard need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Aembit. Keycard has a hosted endpoint at https://api.keycard.ai.",
        "question": "Can an agent call Aembit and Keycard without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 65 against 35",
          "Schema \u0026 documentation, 85 against 61",
          "Agent ergonomics, 72 against 60",
          "Payments \u0026 pricing, 40 against 30",
          "Transparency \u0026 trust, 60 against 44"
        ],
        "also": [
          "Agent-ready, a grade of BB or better"
        ],
        "goodFor": "A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.",
        "slug": "aembit",
        "watchFor": "No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance"
      },
      {
        "aheadOn": null,
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product.",
        "slug": "keycard",
        "watchFor": "Early Access with sign-up by request, and no terms of service page"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-arcade.json",
        "title": "Aembit vs Arcade.dev",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-arcade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents.json",
        "title": "Aembit vs Auth0 for AI Agents (Token Vault)",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity.json",
        "title": "Aembit vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.json",
        "title": "Aembit vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-nango.json",
        "title": "Aembit vs Nango",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit.json",
        "title": "Aembit vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.json",
        "title": "Aembit vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-workos-pipes.json",
        "title": "Aembit vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-keycard.json",
        "title": "Arcade.dev vs Keycard",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Keycard",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.json",
        "title": "Descope Agentic Identity Hub vs Keycard",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.json",
        "title": "Keycard vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-nango.json",
        "title": "Keycard vs Nango",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.json",
        "title": "Keycard vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.json",
        "title": "Keycard vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.json",
        "title": "Keycard vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "aembit": 65,
        "by": 30,
        "edge": "aembit",
        "key": "reliability",
        "keycard": 35,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "aembit": 85,
        "by": 24,
        "edge": "aembit",
        "key": "schema",
        "keycard": 61,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "aembit": 72,
        "by": 12,
        "edge": "aembit",
        "key": "ergonomics",
        "keycard": 60,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "aembit": 84,
        "by": 2,
        "edge": "keycard",
        "key": "security",
        "keycard": 86,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "aembit": 40,
        "by": 10,
        "edge": "aembit",
        "key": "payments",
        "keycard": 30,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "aembit": 80,
        "by": 1,
        "edge": "aembit",
        "key": "maintenance",
        "keycard": 79,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "aembit": 60,
        "by": 16,
        "edge": "aembit",
        "key": "transparency",
        "keycard": 44,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Aembit scores 70.5 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 6 of 7 scored categories. Both do auth oauth.",
    "verdicts": {
      "aembit": "Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.",
      "keycard": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/aembit-vs-keycard",
    "json": "https://www.anchorterminal.com/compare/aembit-vs-keycard.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/aembit-vs-keycard.md",
    "slim": "https://www.anchorterminal.com/compare/aembit-vs-keycard.min.md"
  },
  "markdown": "Aembit scores 70.5 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 6 of 7 scored categories. Both do auth oauth.\n\n- Aembit: grade BB, 70.5/100, rank #134 of 722. Markdown https://www.anchorterminal.com/tools/aembit.md · JSON https://www.anchorterminal.com/api/v1/tools/aembit.json\n- Keycard: grade C, 56.2/100, rank #492 of 722. Markdown https://www.anchorterminal.com/tools/keycard.md · JSON https://www.anchorterminal.com/api/v1/tools/keycard.json\n\n## Which one, for what\n\n### Aembit (BB)\n\nGood for: A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.\n\nAhead on:\n- Reliability, 65 against 35\n- Schema \u0026 documentation, 85 against 61\n- Agent ergonomics, 72 against 60\n- Payments \u0026 pricing, 40 against 30\n- Transparency \u0026 trust, 60 against 44\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n\nWatch for: No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance\n\n### Keycard (C)\n\nGood for: A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product.\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: Early Access with sign-up by request, and no terms of service page\n\n\n## Score by category\n\n| Category | Weight | Aembit | Keycard | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 35 | Aembit +30 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 85 | 61 | Aembit +24 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 60 | Aembit +12 |\n| Security \u0026 auth | 14% (17.5 this run) | 84 | 86 | Keycard +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 30 | Aembit +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 79 | Aembit +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 60 | 44 | Aembit +16 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **70.5 · BB** | **56.2 · C** | |\n\n## Facts side by side\n\n| Fact | Aembit | Keycard |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Aembit, Inc. | Keycard Labs |\n| Hosted endpoint | no (local only) | `https://api.keycard.ai` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0 | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-09-22 |\n| Terms last updated | 2026-07-14 | no document linked |\n| Privacy policy last updated | 2026-05-05 | couldn't be read |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 27 npm/wk | 1 stars, 52 npm/wk |\n| Agent reviews | none | 2.5/5 (2) |\n\n## Verdicts\n\n**Aembit.** Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.\n\n**Keycard.** Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.\n\n## Before you call either\n\n### Aembit\n\n1. Read the API Base URL and token from the tenant's Profile page. Tokens last 1 hour by default, so plan to refresh\n2. Send `X-Aembit-ResourceSet` on Cloud API, Edge API and MCP calls outside the default Resource Set, or the request runs against the default set\n3. Cache the Edge API access token from `/edge/v1/auth` until near expiry before calling `/edge/v1/credentials`. Both endpoints can answer 429\n4. Point MCP clients at `https://\u003cgateway-host\u003e/mcp`. The `/me` path is deprecated\n5. Expect tool names prefixed with the Server Workload name behind the MCP Identity Gateway, and keep `perPage` at 100 or less on the Aembit MCP Server\n\n### Keycard\n\n1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone\n2. Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange\n3. Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry\n4. Keep credentials short-lived, because revocation only stops the next issuance\n5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart\n\n## Questions\n\n### Which is better for AI agents, Aembit or Keycard?\n\nAembit scores 70.5 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 6 of 7 scored categories.\n\n### Do Aembit and Keycard need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Aembit and Keycard without installing anything?\n\nNo hosted endpoint is listed for Aembit. Keycard has a hosted endpoint at https://api.keycard.ai.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/aembit-vs-keycard.json, and with the fewest tokens: https://www.anchorterminal.com/compare/aembit-vs-keycard.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"aembit\", \"b\": \"keycard\"}`. From a terminal: `anchor compare aembit keycard`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/aembit.json and https://www.anchorterminal.com/api/v1/tools/keycard.json\n\n## Other comparisons with Aembit or Keycard\n\n- [Aembit vs Arcade.dev](https://www.anchorterminal.com/compare/aembit-vs-arcade.md)\n- [Aembit vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents.md)\n- [Aembit vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity.md)\n- [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md)\n- [Aembit vs Nango](https://www.anchorterminal.com/compare/aembit-vs-nango.md)\n- [Aembit vs Scalekit AgentKit](https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit.md)\n- [Aembit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.md)\n- [Aembit vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/aembit-vs-workos-pipes.md)\n- [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Keycard vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md)\n- [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md)\n- [Keycard vs Scalekit AgentKit](https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Aembit vs Keycard",
        "url": ""
      }
    ],
    "description": "Aembit scores 70.5 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 6 of 7 scored categories. Both do auth oauth. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Aembit BB 70.5",
      "Keycard C 56.2",
      "scores"
    ],
    "h1": "Aembit vs Keycard",
    "image": "https://www.anchorterminal.com/assets/og/compare-aembit-vs-keycard.png",
    "path": "/compare/aembit-vs-keycard",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Aembit vs Keycard for AI agents, BB 70.5 vs C 56.2 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/aembit-vs-keycard"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 680
  },
  "version": 1
}
