{
  "data": {
    "a": {
      "slug": "aembit",
      "name": "Aembit",
      "vendor": "Aembit, Inc.",
      "vendorUrl": "https://aembit.io",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Aembit is a hosted identity and access platform for workloads and AI agents. Its MCP Identity Gateway and MCP Authorisation Server apply access policies and inject credentials, with a Cloud API, an Edge API, a CLI and an Edge SDK.",
      "url": "https://www.anchorterminal.com/tools/aembit",
      "markdownUrl": "https://www.anchorterminal.com/tools/aembit.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/aembit.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/aembit.json",
      "repo": "https://github.com/Aembit/edge-sdks",
      "license": "Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@aembit/edge-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every API takes a short-lived Bearer token. For the Cloud API at https://\u003ctenant\u003e.aembit.io/api/v1, a person copies an API token from the tenant's Profile page (1 hour by default), or a workload obtains an Aembit Access Token through an Access Policy and a role. The Edge API exchanges platform attestation for an access token at /edge/v1/auth. MCP clients reach the MCP Identity Gateway and MCP Authorisation Server by OAuth 2.1 with PKCE and dynamic client registration or a Client ID Metadata Document, after the user signs in through the company's identity provider. Access is self-serve for a free tenant. The managed gateway endpoint is requested through an Aembit representative.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 3 AI agents, one MCP Identity Gateway and 5 MCP authorisation policies, or 10 workloads and 10 Access Policies, with 24 hours of event log retention. The pricing FAQ says no payment information is required. Teams is $20 per AI agent a month (to 500 agents) or $20 per workload a month, with a Contact Us button. Enterprise is custom. An agent can start on the free tenant without a contract (https://aembit.io/pricing/, checked 2026-10-08).",
      "priceSummary": "$20 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI files or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 27,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.aembit.io",
      "llmsTxt": "https://docs.aembit.io/llms.txt",
      "openapi": "https://docs.aembit.io/cloud.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.agent-identity",
        "auth.tokens",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "typescript",
        "cli",
        "terraform",
        "status-page",
        "soc2",
        "iso27001",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.5,
        "grade": "BB",
        "agentReady": true,
        "rank": 134,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 40,
          "reliability": 65,
          "schema": 85,
          "security": 84,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.",
        "bestFor": "A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.",
        "strengths": [
          "Public OpenAPI 3.1.1 files for the Cloud API (171 operations) and Edge API (2), plus llms.txt, per-page Markdown and a cloneable docs bundle",
          "No long-lived API credentials. Aembit API tokens last 1 hour by default and Edge API access tokens expire in 1 hour",
          "MCP clients authenticate by OAuth 2.1 with PKCE, dynamic client registration or a Client ID Metadata Document",
          "Audit logs, access authorisation events and workload events, exported by Log Streams to S3, Google Cloud Storage, Splunk or CrowdStrike",
          "Dated changelog with RSS. MCP Identity Gateway shipped four versions between 7 August and 7 October 2026"
        ],
        "weaknesses": [
          "No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance",
          "No SLA is published. The docs send SLA questions to Aembit support",
          "The managed MCP Identity Gateway endpoint is requested through an Aembit representative, and MCP Tool Access Control is enabled by support",
          "The Python Edge SDK is in the repository at 0.1.0 but pypi.org/project/aembit-edge-sdk returned 404 on 8 October 2026",
          "No DPA, sub-processor list or security.txt found on aembit.io. The trust centre returned 403 to our reader"
        ],
        "agentNotes": [
          "Read the API Base URL and token from the tenant's Profile page. Tokens last 1 hour by default, so plan to refresh",
          "Send `X-Aembit-ResourceSet` on Cloud API, Edge API and MCP calls outside the default Resource Set, or the request runs against the default set",
          "Cache the Edge API access token from `/edge/v1/auth` until near expiry before calling `/edge/v1/credentials`. Both endpoints can answer 429",
          "Point MCP clients at `https://\u003cgateway-host\u003e/mcp`. The `/me` path is deprecated",
          "Expect tool names prefixed with the Server Workload name behind the MCP Identity Gateway, and keep `perPage` at 100 or less on the Aembit MCP Server"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.5
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 80,
          "payments": 40,
          "reliability": 65,
          "schema": 85,
          "security": 84,
          "transparency": 42
        },
        "provenanceScore": 78
      },
      "connect": {
        "install": "npm install @aembit/edge-sdk",
        "http": "curl -X GET -L 'https://tenant.aembit.io/api/v1/server-workloads' -H 'Authorization: Bearer \u003cTOKEN\u003e'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/aembit"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Teams, each AI agent",
          "unit": "month",
          "usd": 20,
          "note": "Priced per agent a month, up to 500 agents"
        },
        {
          "item": "Teams, each workload",
          "unit": "month",
          "usd": 20,
          "note": "Priced per workload a month"
        }
      ],
      "provenance": {
        "legalEntity": "Aembit, Inc.",
        "domain": "aembit.io",
        "domainRegistered": "2021-03-14",
        "endpointOnVendorDomain": true,
        "terms": "https://aembit.io/terms-of-service/",
        "privacy": "https://aembit.io/privacy-policy/",
        "statusPage": "https://status.aembit.io",
        "changelog": "https://docs.aembit.io/changelog/",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last reviewed 14 July 2026) are between the customer and Aembit, Inc., define the Services as the website and the web-based and downloadable workload identity and access management services, and choose Delaware law.",
          "The privacy policy (last updated 5 May 2026) names Aembit, Inc. and covers the platform, websites and related services.",
          "aembit.io/.well-known/security.txt and docs.aembit.io/.well-known/security.txt both returned 404. The docs give security@aembit.io as the security contact.",
          "RDAP at Identity Digital gives a registration date of 2021-03-14 for aembit.io.",
          "Tenant APIs answer at https://\u003ctenant\u003e.aembit.io and the managed gateway at https://\u003ctenantId\u003e.mcpgateway.aembit.io, both on the vendor's domain.",
          "No DPA, sub-processor or SLA page was found at the obvious aembit.io paths, and trust.aembit.io returned 403 to our reader."
        ],
        "score": 78
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/aembit.json",
      "live": {
        "slug": "aembit",
        "vendorStatus": {
          "page": "https://status.aembit.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:50:23.849353023Z"
        },
        "pages": [
          {
            "url": "https://docs.aembit.io/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:07.775115006Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4e930f2cc1ec"
          },
          {
            "url": "https://aembit.io/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:14:59.808222145Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "781c90a65067"
          },
          {
            "url": "https://aembit.io/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:01.881687653Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "753e7b8821e4"
          },
          {
            "url": "https://aembit.io/terms-of-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:03.860763085Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ad42c0fa0432"
          }
        ],
        "updatedAt": "2026-10-08T19:50:23.849353023Z"
      }
    },
    "answer": "Aembit scores 70.5 (BB) on agent readiness against WorkOS Pipes and Agents's 59.9 (C), and leads in 4 of 7 scored categories. WorkOS Pipes and Agents leads on reliability.",
    "b": {
      "slug": "workos-pipes",
      "name": "WorkOS Pipes and Agents",
      "vendor": "WorkOS",
      "vendorUrl": "https://workos.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "WorkOS tools for connecting agents to third-party accounts, managing access tokens and assigning revocable agent identities.",
      "url": "https://www.anchorterminal.com/tools/workos-pipes",
      "markdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/workos-pipes.json",
      "repo": "https://github.com/workos/workos-node",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.workos.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@workos-inc/node"
        },
        {
          "registry": "pypi",
          "name": "workos"
        }
      ],
      "auth": "mixed",
      "authNotes": "Server calls take the secret key as `Authorization: Bearer $WORKOS_API_KEY` (`sk_...`). End users connect accounts through the Pipes widget or an authorisation URL from `/data-integrations/{slug}/authorize`, which must be opened in the browser, not fetched. Agent tokens are minted from a blueprint as user-delegated, autonomous or agent-delegated sessions. The WorkOS MCP server signs in with OAuth as a dashboard user, with no API key.",
      "pricing": "freemium",
      "pricingNotes": "Pay as you go, with no card to start and a card before production. AuthKit is free up to 1,000,000 monthly active users, then $2,500 a month per extra million. SSO and Directory Sync connections are $125 a month each for the first 15, $100 for 16 to 30, $80 for 31 to 50 and $65 for 51 to 100. Audit Logs are free at the base, with $125 a month per SIEM connection and $99 a month per million events stored. Radar is free for 1,000 checks, then $100 per 50,000. A custom domain is $99 a month. Annual credits plans add volume discounts and a 99.99 per cent SLA (https://workos.com/pricing). Pipes and Agents don't appear on the pricing page, so we don't know what a connection or an agent session costs.",
      "priceSummary": "$125 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 221,
        "npmWeekly": 4041570,
        "pypiWeekly": 1697594,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://workos.com/docs/pipes",
      "registryName": "com.workos/mcp",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "typescript",
        "python",
        "enterprise",
        "webhooks"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.9,
        "grade": "C",
        "agentReady": false,
        "rank": 418,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 83,
          "payments": 10,
          "reliability": 70,
          "schema": 53,
          "security": 69,
          "transparency": 63
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.",
        "bestFor": "Best when WorkOS already runs SSO or AuthKit and the agent needs users' or organisations' tokens for many SaaS providers plus its own revocable identity.",
        "strengths": [
          "Agent identity with per-session revocation and token lifetimes set per blueprint",
          "Pipes covers 500+ providers with user-owned and organisation-owned connections by OAuth, API key or client credentials",
          "Published rate limits of 6,000 requests a minute per key, with Retry-After on a 429",
          "Same platform for SSO, directory sync, RBAC, Audit Logs and Vault",
          "SOC 2 Type 2, a public subprocessor list and a 99.99 per cent SLA on annual plans"
        ],
        "weaknesses": [
          "21 incidents on the status page since 3 July 2026, several over an hour",
          "Pipes and Agents aren't on the pricing page",
          "Deleting a connected account doesn't revoke the grant at the provider",
          "Breaking Pipes change in SDK 11.0.0 on 28 September 2026",
          "No OpenAPI file, llms.txt or security.txt we could find"
        ],
        "agentNotes": [
          "Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token",
          "Branch on `active` in the response and send the user to reconnect on `needs_reauthorization`",
          "Wait for Retry-After on a 429, or back off with jitter when it's missing",
          "Use lower-case provider slugs such as github or slack",
          "Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.9
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 83,
          "payments": 10,
          "reliability": 70,
          "schema": 53,
          "security": 69,
          "transparency": 37
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "npm install @workos-inc/node",
        "http": "curl -X POST https://api.workos.com/data-integrations/github/token -H \"Authorization: Bearer $WORKOS_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"user_id\":\"user_01EHZNVPK3SFK441A1RGBFSHRT\"}'",
        "claudeCode": "claude mcp add --transport http --scope user workos https://mcp.workos.com/mcp",
        "config": {
          "mcpServers": {
            "workos": {
              "url": "https://mcp.workos.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/workos-pipes"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "SSO or Directory Sync connection (first 15)",
          "unit": "month",
          "usd": 125,
          "note": "Per connection per month, falling to $65 above 50"
        },
        {
          "item": "Audit Logs SIEM connection",
          "unit": "month",
          "usd": 125,
          "note": "Plus $99 a month per million events stored"
        },
        {
          "item": "Custom domain",
          "unit": "month",
          "usd": 99,
          "note": "AuthKit, Admin Portal and email sender"
        }
      ],
      "provenance": {
        "legalEntity": "WorkOS, Inc.",
        "domain": "workos.com",
        "domainRegistered": "2005-02-02",
        "endpointOnVendorDomain": true,
        "terms": "https://workos.com/legal/terms",
        "privacy": "https://workos.com/legal/privacy",
        "statusPage": "https://status.workos.com",
        "changelog": "https://github.com/workos/workos-node/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The website terms (effective 29 October 2020) name WorkOS, Inc. and California law. The privacy policy was updated 20 October 2025 and doesn't say where data is stored.",
          "RDAP shows workos.com registered on 2005-02-02, years before the company, so the domain was bought later.",
          "/.well-known/security.txt returned 404 on 2026-09-30."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/workos-pipes.json",
      "live": {
        "slug": "workos-pipes",
        "probe": {
          "target": "https://api.workos.com",
          "method": "get",
          "lastAt": "2026-10-08T19:53:06.858923356Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 134,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 136,
          "p95ms24h": 192,
          "samples24h": 272,
          "samples30d": 1941,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 225,
              "ok": 225
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.workos.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:51:08.460891847Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "workos/workos-node",
            "version": "v11.0.0",
            "released": "2026-09-28",
            "seenAt": "2026-10-08T16:35:06.66310113Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.workos/mcp",
            "version": "1.0.0",
            "seenAt": "2026-10-08T02:42:52.272076636Z"
          },
          {
            "registry": "npm",
            "name": "@workos-inc/node",
            "version": "11.0.0",
            "seenAt": "2026-10-08T16:35:05.630586961Z"
          },
          {
            "registry": "pypi",
            "name": "workos",
            "version": "10.5.0",
            "released": "2026-09-24",
            "seenAt": "2026-10-08T16:35:06.473084485Z"
          }
        ],
        "githubStars": 224,
        "npmWeekly": 4251277,
        "pypiWeekly": 1715183,
        "securityTxt": {
          "url": "https://workos.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:57.279092605Z"
        },
        "domain": {
          "domain": "workos.com",
          "registered": "2005-02-02",
          "source": "https://rdap.verisign.com/com/v1/domain/workos.com",
          "checkedAt": "2026-10-04T13:09:49.925296041Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/workos/workos-node/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:51.718491233Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "57d8be278609"
          },
          {
            "url": "https://workos.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-08T18:25:55.816742057Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0cdd6961c090"
          },
          {
            "url": "https://workos.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:50.548963085Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5fc970fc9d08"
          },
          {
            "url": "https://workos.com/legal/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:52.624391607Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b3130dd8035"
          }
        ],
        "updatedAt": "2026-10-08T19:53:06.858923356Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Aembit, Inc.",
        "b": "WorkOS",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.workos.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0",
        "b": "MIT (SDKs), platform closed",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "com.workos/mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-07",
        "b": "2026-09-28",
        "name": "Last release"
      },
      {
        "a": "2026-07-14",
        "b": "2020-10-29",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-05",
        "b": "2025-10-20",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "27 npm/wk",
        "b": "221 stars, 4M npm/wk, 1.7M PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Aembit scores 70.5 (BB) on agent readiness against WorkOS Pipes and Agents's 59.9 (C), and leads in 4 of 7 scored categories. WorkOS Pipes and Agents leads on reliability.",
        "question": "Which is better for AI agents, Aembit or WorkOS Pipes and Agents?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Aembit and WorkOS Pipes and Agents need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Aembit. WorkOS Pipes and Agents has a hosted endpoint at https://api.workos.com.",
        "question": "Can an agent call Aembit and WorkOS Pipes and Agents without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 85 against 53",
          "Security \u0026 auth, 84 against 69",
          "Payments \u0026 pricing, 40 against 10"
        ],
        "also": [
          "Agent-ready, a grade of BB or better"
        ],
        "goodFor": "A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.",
        "slug": "aembit",
        "watchFor": "No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance"
      },
      {
        "aheadOn": [
          "Reliability, 70 against 65"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Best when WorkOS already runs SSO or AuthKit and the agent needs users' or organisations' tokens for many SaaS providers plus its own revocable identity.",
        "slug": "workos-pipes",
        "watchFor": "21 incidents on the status page since 3 July 2026, several over an hour"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-arcade.json",
        "title": "Aembit vs Arcade.dev",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-arcade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents.json",
        "title": "Aembit vs Auth0 for AI Agents (Token Vault)",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity.json",
        "title": "Aembit vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-keycard.json",
        "title": "Aembit vs Keycard",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.json",
        "title": "Aembit vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-nango.json",
        "title": "Aembit vs Nango",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit.json",
        "title": "Aembit vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.json",
        "title": "Aembit vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.json",
        "title": "Arcade.dev vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.json",
        "title": "Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.json",
        "title": "Descope Agentic Identity Hub vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.json",
        "title": "Keycard vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.json",
        "title": "Microsoft Entra Agent ID vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nango-vs-workos-pipes.json",
        "title": "Nango vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/nango-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/scalekit-agentkit-vs-workos-pipes.json",
        "title": "Scalekit AgentKit vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/scalekit-agentkit-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.json",
        "title": "Stytch Connected Apps vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "aembit": 65,
        "by": 5,
        "edge": "workos-pipes",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16,
        "workos-pipes": 70
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "aembit": 85,
        "by": 32,
        "edge": "aembit",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13,
        "workos-pipes": 53
      },
      {
        "aembit": 72,
        "by": 3,
        "edge": "aembit",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13,
        "workos-pipes": 69
      },
      {
        "aembit": 84,
        "by": 15,
        "edge": "aembit",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14,
        "workos-pipes": 69
      },
      {
        "aembit": 40,
        "by": 30,
        "edge": "aembit",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10,
        "workos-pipes": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "aembit": 80,
        "by": 3,
        "edge": "workos-pipes",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7,
        "workos-pipes": 83
      },
      {
        "aembit": 60,
        "by": 3,
        "edge": "workos-pipes",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7,
        "workos-pipes": 63
      }
    ],
    "summary": "Aembit scores 70.5 (BB) on agent readiness against WorkOS Pipes and Agents's 59.9 (C), and leads in 4 of 7 scored categories. WorkOS Pipes and Agents leads on reliability. Both do auth oauth.",
    "verdicts": {
      "aembit": "Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.",
      "workos-pipes": "Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/aembit-vs-workos-pipes",
    "json": "https://www.anchorterminal.com/compare/aembit-vs-workos-pipes.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/aembit-vs-workos-pipes.md",
    "slim": "https://www.anchorterminal.com/compare/aembit-vs-workos-pipes.min.md"
  },
  "markdown": "Aembit scores 70.5 (BB) on agent readiness against WorkOS Pipes and Agents's 59.9 (C), and leads in 4 of 7 scored categories. WorkOS Pipes and Agents leads on reliability. Both do auth oauth.\n\n- Aembit: grade BB, 70.5/100, rank #134 of 722. Markdown https://www.anchorterminal.com/tools/aembit.md · JSON https://www.anchorterminal.com/api/v1/tools/aembit.json\n- WorkOS Pipes and Agents: grade C, 59.9/100, rank #418 of 722. Markdown https://www.anchorterminal.com/tools/workos-pipes.md · JSON https://www.anchorterminal.com/api/v1/tools/workos-pipes.json\n\n## Which one, for what\n\n### Aembit (BB)\n\nGood for: A security team that wants one policy and audit point between AI agents or workloads and the services they call, with credentials kept away from the agent.\n\nAhead on:\n- Schema \u0026 documentation, 85 against 53\n- Security \u0026 auth, 84 against 69\n- Payments \u0026 pricing, 40 against 10\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n\nWatch for: No rate limit figures in the reviewed documentation. The Edge API lists 429 responses without limits or Retry-After guidance\n\n### WorkOS Pipes and Agents (C)\n\nGood for: Best when WorkOS already runs SSO or AuthKit and the agent needs users' or organisations' tokens for many SaaS providers plus its own revocable identity.\n\nAhead on:\n- Reliability, 70 against 65\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: 21 incidents on the status page since 3 July 2026, several over an hour\n\n\n## Score by category\n\n| Category | Weight | Aembit | WorkOS Pipes and Agents | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 65 | 70 | WorkOS Pipes and Agents +5 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 85 | 53 | Aembit +32 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 69 | Aembit +3 |\n| Security \u0026 auth | 14% (17.5 this run) | 84 | 69 | Aembit +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 10 | Aembit +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 83 | WorkOS Pipes and Agents +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 60 | 63 | WorkOS Pipes and Agents +3 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **70.5 · BB** | **59.9 · C** | |\n\n## Facts side by side\n\n| Fact | Aembit | WorkOS Pipes and Agents |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Aembit, Inc. | WorkOS |\n| Hosted endpoint | no (local only) | `https://api.workos.com` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0 | MIT (SDKs), platform closed |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | not listed | `com.workos/mcp` |\n| Last release | 2026-10-07 | 2026-09-28 |\n| Terms last updated | 2026-07-14 | 2020-10-29 |\n| Privacy policy last updated | 2026-05-05 | 2025-10-20 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 27 npm/wk | 221 stars, 4M npm/wk, 1.7M PyPI/wk |\n| Agent reviews | none | 2.5/5 (2) |\n\n## Verdicts\n\n**Aembit.** Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found.\n\n**WorkOS Pipes and Agents.** Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.\n\n## Before you call either\n\n### Aembit\n\n1. Read the API Base URL and token from the tenant's Profile page. Tokens last 1 hour by default, so plan to refresh\n2. Send `X-Aembit-ResourceSet` on Cloud API, Edge API and MCP calls outside the default Resource Set, or the request runs against the default set\n3. Cache the Edge API access token from `/edge/v1/auth` until near expiry before calling `/edge/v1/credentials`. Both endpoints can answer 429\n4. Point MCP clients at `https://\u003cgateway-host\u003e/mcp`. The `/me` path is deprecated\n5. Expect tool names prefixed with the Server Workload name behind the MCP Identity Gateway, and keep `perPage` at 100 or less on the Aembit MCP Server\n\n### WorkOS Pipes and Agents\n\n1. Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token\n2. Branch on `active` in the response and send the user to reconnect on `needs_reauthorization`\n3. Wait for Retry-After on a 429, or back off with jitter when it's missing\n4. Use lower-case provider slugs such as github or slack\n5. Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry\n\n## Questions\n\n### Which is better for AI agents, Aembit or WorkOS Pipes and Agents?\n\nAembit scores 70.5 (BB) on agent readiness against WorkOS Pipes and Agents's 59.9 (C), and leads in 4 of 7 scored categories. WorkOS Pipes and Agents leads on reliability.\n\n### Do Aembit and WorkOS Pipes and Agents need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Aembit and WorkOS Pipes and Agents without installing anything?\n\nNo hosted endpoint is listed for Aembit. WorkOS Pipes and Agents has a hosted endpoint at https://api.workos.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/aembit-vs-workos-pipes.json, and with the fewest tokens: https://www.anchorterminal.com/compare/aembit-vs-workos-pipes.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"aembit\", \"b\": \"workos-pipes\"}`. From a terminal: `anchor compare aembit workos-pipes`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/aembit.json and https://www.anchorterminal.com/api/v1/tools/workos-pipes.json\n\n## Other comparisons with Aembit or WorkOS Pipes and Agents\n\n- [Aembit vs Arcade.dev](https://www.anchorterminal.com/compare/aembit-vs-arcade.md)\n- [Aembit vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/aembit-vs-auth0-ai-agents.md)\n- [Aembit vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity.md)\n- [Aembit vs Keycard](https://www.anchorterminal.com/compare/aembit-vs-keycard.md)\n- [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md)\n- [Aembit vs Nango](https://www.anchorterminal.com/compare/aembit-vs-nango.md)\n- [Aembit vs Scalekit AgentKit](https://www.anchorterminal.com/compare/aembit-vs-scalekit-agentkit.md)\n- [Aembit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.md)\n- [Arcade.dev vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.md)\n- [Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.md)\n- [Descope Agentic Identity Hub vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.md)\n- [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)\n- [Microsoft Entra Agent ID vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.md)\n- [Nango vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/nango-vs-workos-pipes.md)\n- [Scalekit AgentKit vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-workos-pipes.md)\n- [Stytch Connected Apps vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Aembit vs WorkOS Pipes and Agents",
        "url": ""
      }
    ],
    "description": "Aembit scores 70.5 (BB) on agent readiness against WorkOS Pipes and Agents's 59.9 (C), and leads in 4 of 7 scored categories. WorkOS Pipes and Agents leads on reliability. Both do auth oauth. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Aembit BB 70.5",
      "WorkOS Pipes and Agents C 59.9",
      "scores"
    ],
    "h1": "Aembit vs WorkOS Pipes and Agents",
    "image": "https://www.anchorterminal.com/assets/og/compare-aembit-vs-workos-pipes.png",
    "path": "/compare/aembit-vs-workos-pipes",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Aembit vs WorkOS Pipes and Agents for AI agents, BB 70.5 vs C 59.9",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/aembit-vs-workos-pipes"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 680
  },
  "version": 1
}
