Head to head · Wallet spend limits · October 2026 research run

Agentcard vs Openfort

Openfort scores 70.1 (BB) on agent readiness against Agentcard's 56.5 (C), and leads in 6 of 7 scored categories. Both do wallet spend limits.

Best agent wallets and spending controls · All 23 wallets comparisons

Which one, for what

Agentcard C

Good for A company building a shopping or purchasing agent that needs users to pay with their own cards under passkey approval, or needs capped virtual Visa cards per task.

Also in its favour

  • No incidents deducted, where Openfort loses 5 points for them

Watch for

No status page or incident history was found on the site or in the docs. An SLA is listed for Enterprise plans only, with no published text

Openfort BB

Good for A team that wants server-held wallets for agents on EVM chains and Solana with enclave signing, a free start and a CLI an agent can drive.

Ahead on

  • Reliability, 88 against 29
  • Schema & documentation, 89 against 80
  • Payments & pricing, 60 against 42
  • Maintenance & community, 87 against 74
  • Transparency & trust, 69 against 44

Also in its favour

  • Agent-ready, a grade of BB or better
  • Runs on your own machine

Watch for

An EVM backend send is evaluated only as signEvmHash, so address, value and calldata rules do not block it unless the caller pre-flights

Score by category

CategoryWeight this runAgentcardOpenfortEdge
Reliability16%202988Openfort +59
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28089Openfort +9
Agent ergonomics13%16.26365Openfort +2
Security & auth14%17.56865Agentcard +3
Payments & pricing10%12.54260Openfort +18
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87487Openfort +13
Transparency & trust7%8.84469Openfort +25
Negative events≤150-5
Total56.5 · C70.1 · BB

Facts side by side

FactAgentcardOpenfort
KindHTTP APIHTTP API
VendorAgentcard CorporationOpenfort (Alamas Labs Inc.)
Hosted endpointhttps://api.agentcard.shhttps://api.openfort.io
TransportsHTTPHTTP, stdio
AuthOAuthAPI key
PricingFreemiumFreemium
x402nopayer tooling only
LicenceProprietary service under Agentcard's terms of use. The agent-cards CLI on npm declares no licence, @agent-cards/checkout is marked as having none, and the repository they name is privateProprietary service under the Openfort Developer Terms of Service. The Node SDK and OpenSigner are MIT. The CLI repository and package state no licence
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-092026-09-28
Terms last updated2026-07-102026-01-16
Privacy policy last updatedno document linked2026-09-04
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waiveryesyes
Popularity33k npm/wk10 stars, 7.6k npm/wk

Verdicts

Agentcard

Purchases need the user's passkey approval by default, cards carry spending rules, and card creation takes an idempotency key. No status page, published rate limits beyond the token endpoint, or privacy policy of Agentcard's own was found, and the Trust Centre could not be read. Issuing costs $5,000 a month.

Openfort

Backend wallets sign inside a GCP Confidential Space enclave, secret keys carry 26 scopes, and rate limits, errors and prices are published. On EVM, a backend send reaches the policy engine only as a hash, so address and value rules bind only when the caller runs the pre-flight check first.

Before you call either

Agentcard

  1. Mint a platform token with POST /api/v2/oauth/token and cache it for its one hour. The endpoint allows 30 requests per 5 minutes per IP
  2. Send the same Idempotency-Key on every retry of POST /api/v2/cards, and the same idempotency_key on every retry of buy_checkout
  3. Pass source: "issued" to the MCP create_card tool for a card number. Without it the tool may start Vault setup and return a link
  4. Call get_card_details only at the payment form and never log the result. Each read notifies the member and may return approval_required
  5. Treat transaction.authorized and order.* webhooks as the record of a payment, and deduplicate deliveries on the event id

Openfort

  1. Call policies.evaluate with operation signEvmTransaction before every EVM backend send. The send itself is checked only as signEvmHash
  2. Keep the signing policy and the gas sponsorship policy separate. Linking a signing policy to a fee sponsorship stops it working as a guardrail
  3. Pass a fee sponsorship on EVM sends. Without one the transaction stays pending with no error
  4. Give an agent a secret key without accounts:export, and limit the CLI MCP server to the tools it needs
  5. On a 5xx after a write, read the resource before retrying. On a 429, wait the full Retry-After

Questions

Which is better for AI agents, Agentcard or Openfort?

Openfort scores 70.1 (BB) on agent readiness against Agentcard's 56.5 (C), and leads in 6 of 7 scored categories.

Do Agentcard and Openfort need an API key?

Agentcard uses an OAuth sign-in. Openfort needs an API key.

Can an agent call Agentcard and Openfort without installing anything?

Yes. Agentcard has a hosted endpoint at https://api.agentcard.sh and Openfort at https://api.openfort.io.

Other comparisons with Agentcard or Openfort

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.