{
  "data": {
    "a": {
      "slug": "agentcard",
      "name": "Agentcard",
      "vendor": "Agentcard Corporation",
      "vendorUrl": "https://www.agentcard.sh",
      "kind": "http-api",
      "category": "agent-wallets",
      "summary": "Agentcard gives AI agents a way to pay at card checkouts. Its Vault stores a user's own cards for approved purchases, and Issuing creates single-use or multi-use virtual Visa cards. Access is by REST API, MCP server and CLI.",
      "url": "https://www.anchorterminal.com/tools/agentcard",
      "markdownUrl": "https://www.anchorterminal.com/tools/agentcard.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agentcard.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agentcard.json",
      "license": "Proprietary service under Agentcard's terms of use. The `agent-cards` CLI on npm declares no licence, `@agent-cards/checkout` is marked as having none, and the repository they name is private",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.agentcard.sh",
      "packages": [
        {
          "registry": "npm",
          "name": "agent-cards"
        },
        {
          "registry": "npm",
          "name": "@agent-cards/checkout"
        }
      ],
      "auth": "oauth",
      "authNotes": "Self-serve. A person signs in to the dashboard or the CLI with an emailed code and creates an OAuth client. `POST /api/v2/oauth/token` exchanges `client_id` and `client_secret` for a platform token that lasts one hour, with the single scope `api`. A user connects by a one-time code, which returns a connection token limited to that user's cards and purchases, refreshed with the platform token. Sandbox and production use separate clients on one host.",
      "pricing": "freemium",
      "pricingNotes": "Vault is free up to 5,000 users, with Enterprise by quote. Issuing is $5,000 a month with $0 per card. The Purchase Agent is listed at $0.15 a request and free in beta. A sandbox with test cards needs no contract or card. Prices for the personal plans named in the MCP tools (free, basic, pro) were not found (https://www.agentcard.sh/pricing, checked 2026-10-09).",
      "priceSummary": "$0.15 / call",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "The home page FAQ asks whether Agentcard supports x402, AP2 or other agent payment protocols and answers Not yet. No x402, MPP or L402 in the docs or the OpenAPI file (https://www.agentcard.sh/, checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 33018,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.agentcard.sh",
      "llmsTxt": "https://docs.agentcard.sh/llms.txt",
      "openapi": "https://docs.agentcard.sh/openapi.json",
      "capabilities": [
        "payments.card",
        "wallet.spend-limits",
        "wallet.custody"
      ],
      "tags": [
        "hosted",
        "freemium",
        "closed-source",
        "openapi",
        "llms-txt",
        "mcp",
        "cli",
        "oauth",
        "typescript",
        "sandbox",
        "webhooks",
        "virtual-cards",
        "cards",
        "approvals",
        "usdc"
      ],
      "lastRelease": "2026-10-09",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.5,
        "grade": "C",
        "agentReady": false,
        "rank": 632,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 74,
          "payments": 42,
          "reliability": 29,
          "schema": 80,
          "security": 68,
          "transparency": 44
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "Purchases need the user's passkey approval by default, cards carry spending rules, and card creation takes an idempotency key. No status page, published rate limits beyond the token endpoint, or privacy policy of Agentcard's own was found, and the Trust Centre could not be read. Issuing costs $5,000 a month.",
        "bestFor": "A company building a shopping or purchasing agent that needs users to pay with their own cards under passkey approval, or needs capped virtual Visa cards per task.",
        "strengths": [
          "Vault purchases pause for the user's passkey or master password approval by default, and production card creation returns `approval_pending` with an approval link",
          "Presets cap spend in total and per rolling day, week and month, and restrict merchants, categories, countries, currencies, days and hours, in `strict` or `watch` mode",
          "`POST /api/v2/cards` requires an `Idempotency-Key`, and `buy_checkout` re-checks the confirmed total and address before paying",
          "Errors share one envelope with a stable `code`, and each endpoint page lists the codes it can return",
          "llms.txt indexes 379 Markdown pages, among them one page for each of 117 MCP tools and 116 CLI commands",
          "Changelog entries are dated almost daily to 28 September 2026, and `@agent-cards/checkout` 0.23.6 was published on 9 October 2026"
        ],
        "weaknesses": [
          "No status page or incident history was found on the site or in the docs. An SLA is listed for Enterprise plans only, with no published text",
          "The only rate limit with numbers is 30 requests per 5 minutes per IP on the token endpoint",
          "The site's Privacy Policy link opens the policy of Rain, the card issuing partner. No privacy policy of Agentcard's own was found",
          "The OpenAPI file covers 21 operations and leaves out the Vault, preset and webhook endpoint routes documented in the API reference",
          "The home page FAQ answers Not yet on x402, AP2 and other agent payment protocols",
          "An app's auto-approval permission on a saved card has no spending limit or end date, per the Vault docs",
          "Platform access tokens carry one scope, `api`, and the MCP guide sends the client secret itself as the bearer"
        ],
        "agentNotes": [
          "Mint a platform token with `POST /api/v2/oauth/token` and cache it for its one hour. The endpoint allows 30 requests per 5 minutes per IP",
          "Send the same `Idempotency-Key` on every retry of `POST /api/v2/cards`, and the same `idempotency_key` on every retry of `buy_checkout`",
          "Pass `source: \"issued\"` to the MCP `create_card` tool for a card number. Without it the tool may start Vault setup and return a link",
          "Call `get_card_details` only at the payment form and never log the result. Each read notifies the member and may return `approval_required`",
          "Treat `transaction.authorized` and `order.*` webhooks as the record of a payment, and deduplicate deliveries on the event `id`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.5
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 74,
          "payments": 42,
          "reliability": 29,
          "schema": 80,
          "security": 68,
          "transparency": 36
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "npm install -g agent-cards",
        "http": "curl -X POST https://api.agentcard.sh/api/v2/oauth/token -d grant_type=client_credentials -d client_id=$AGENTCARD_CLIENT_ID -d client_secret=$AGENTCARD_CLIENT_SECRET",
        "claudeCode": "claude mcp add agentcard --transport http https://mcp.agentcard.sh/mcp --header \"Authorization: Bearer YOUR_CLIENT_SECRET\""
      },
      "letme": {
        "capability": "https://letme.dev/payments.card",
        "tool": "https://letme.dev/agentcard"
      },
      "area": "payments",
      "unitPrices": [
        {
          "item": "Purchase Agent request (listed price, free in beta)",
          "unit": "call",
          "usd": 0.15,
          "note": "https://www.agentcard.sh/pricing"
        },
        {
          "item": "Issuing plan",
          "unit": "month",
          "usd": 5000,
          "note": "$0 per card, 1 per cent revenue share to the customer"
        },
        {
          "item": "Vault Free plan, up to 5,000 users",
          "unit": "month",
          "usd": 0,
          "note": "Enterprise by quote"
        },
        {
          "item": "Issued card international transaction",
          "unit": "pct",
          "usd": 1,
          "note": "no annual fee, 0 per cent APR"
        }
      ],
      "provenance": {
        "legalEntity": "Agentcard Corporation",
        "domain": "agentcard.sh",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://www.agentcard.sh/terms",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://www.agentcard.sh/updates",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms of use (updated 10 July 2026) name Agentcard Corporation, a Delaware corporation (File No. 10619012), registered office 131 Continental Dr, Suite 305, Newark, DE 19713, and cover the MCP server, CLI, dashboard and API.",
          "No privacy policy of Agentcard's own was found, so `privacy` is left out. The footer's Privacy Policy link and the link in the terms open Rain's privacy policy at legal.raincards.xyz, and www.agentcard.sh/privacy redirects to Rain's account opening privacy notice for Third National.",
          "Cards are issued by Third National, a Rain company, under a cardholder agreement at https://www.agentcard.sh/card-terms.",
          "The API answers at api.agentcard.sh, the MCP server at mcp.agentcard.sh and the Vault at vault.agentcard.sh per the docs. We sent no request to those hosts.",
          "www.agentcard.sh/.well-known/security.txt returned a 404 page. No status page was found.",
          "rdap.org returned 404 for agentcard.sh, so the registration date is unknown. The first `agent-cards` package was published on 23 February 2026.",
          "The npm packages name the private repository github.com/tiny-agent-company/tiny-agent-company."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/agentcard.json",
      "live": {
        "slug": "agentcard",
        "probe": {
          "target": "https://api.agentcard.sh",
          "method": "get",
          "lastAt": "2026-10-10T02:06:58.768255278Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 249,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 199,
          "p95ms24h": 505,
          "samples24h": 107,
          "samples30d": 107,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 22,
              "ok": 22
            }
          ]
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@agent-cards/checkout",
            "version": "0.23.6",
            "seenAt": "2026-10-09T16:37:14.192195816Z"
          },
          {
            "registry": "npm",
            "name": "agent-cards",
            "version": "0.8.2",
            "seenAt": "2026-10-09T16:37:13.385313375Z"
          }
        ],
        "npmWeekly": 8954,
        "pages": [
          {
            "url": "https://www.agentcard.sh/updates",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:47:49.410862389Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4cb2a788f3c9"
          },
          {
            "url": "https://www.agentcard.sh/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:47:45.256033021Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5286901862a9"
          },
          {
            "url": "https://www.agentcard.sh/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:47:47.562806747Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f5a295e149ce"
          }
        ],
        "updatedAt": "2026-10-10T02:06:58.768255278Z"
      }
    },
    "answer": "Openfort scores 70.1 (BB) on agent readiness against Agentcard's 56.5 (C), and leads in 6 of 7 scored categories.",
    "b": {
      "slug": "openfort",
      "name": "Openfort",
      "vendor": "Openfort (Alamas Labs Inc.)",
      "vendorUrl": "https://www.openfort.io",
      "kind": "http-api",
      "category": "agent-wallets",
      "summary": "Openfort is wallet infrastructure from Alamas Labs. Its REST API, Node SDK and CLI create backend wallets held in a trusted execution environment, with signing policies, session keys and gas sponsorship. It also sells embedded wallets for apps.",
      "url": "https://www.anchorterminal.com/tools/openfort",
      "markdownUrl": "https://www.anchorterminal.com/tools/openfort.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openfort.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openfort.json",
      "repo": "https://github.com/openfort-xyz/openfort-node",
      "license": "Proprietary service under the Openfort Developer Terms of Service. The Node SDK and OpenSigner are MIT. The CLI repository and package state no licence",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.openfort.io",
      "packages": [
        {
          "registry": "npm",
          "name": "@openfort/openfort-node"
        },
        {
          "registry": "npm",
          "name": "@openfort/cli"
        }
      ],
      "auth": "api-key",
      "authNotes": "A secret key (`sk_test_` or `sk_live_`) from the self-serve dashboard goes in `Authorization: Bearer`. Secret keys carry scopes (26 named, such as `accounts:sign`, `policies:write` and `accounts:export`), and a key made without a scope list gets all but four. Backend wallet signing also needs an `x-wallet-auth` ES256 JWT signed with a separate wallet secret, with a nonce and a request hash. Test and live keys are isolated. No OAuth (https://www.openfort.io/docs/api-reference/authentication).",
      "pricing": "freemium",
      "pricingNotes": "Free plan with 2,000 operations a month and no card, then $0.01 an operation. Growth $99 a month (25,000 operations, $0.008 extra), Pro $249 (100,000, $0.006), Scale $599 (500,000, $0.004). An operation is a wallet creation, signature, broadcast, policy evaluation, webhook or key import or export. Sponsored gas carries a 10 per cent surcharge, 5 per cent on Pro and Scale. Enterprise is priced by sales (https://www.openfort.io/pricing.md, checked 2026-10-09).",
      "priceSummary": "$99 / mo",
      "where": "both",
      "x402": {
        "level": "partial",
        "evidence": "Openfort wallets pay as a buyer. The docs carry an x402 recipe for USDC payments from embedded and backend wallets and an MPP recipe for an agent paying HTTP services on Tempo. Openfort's own API is not paid over x402. Its 402 status means the plan's operations are used up with no payment method (https://www.openfort.io/docs/llms.txt; https://www.openfort.io/docs/api-reference/errors, checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 10,
        "npmWeekly": 7647,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://www.openfort.io/docs/products/server/workflows/agentic-wallets",
      "llmsTxt": "https://www.openfort.io/llms.txt",
      "openapi": "https://www.openfort.io/docs/openapi.json",
      "capabilities": [
        "wallet.onchain",
        "wallet.spend-limits",
        "wallet.custody",
        "payments.x402"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "api-key",
        "openapi",
        "llms-txt",
        "mcp",
        "cli",
        "typescript",
        "wallet",
        "stablecoin",
        "x402",
        "tee",
        "status-page",
        "webhooks"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.1,
        "grade": "BB",
        "agentReady": true,
        "rank": 163,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 60,
          "reliability": 88,
          "schema": 89,
          "security": 65,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "9 October 2026. The agent wallets page says a signing policy is evaluated server-side on every operation against value caps and allowlists and that caps are enforced at signing time. The policies docs say an EVM backend send is evaluated only as `signEvmHash`, so those rules cannot block one. The docs disclose this plainly, so 3 points (https://www.openfort.io/agent-wallets; https://www.openfort.io/docs/configuration/policies).",
          "28 September 2026. The changelog says tokens from a third-party login provider were still accepted after the provider was disabled. Fixed and documented in the changelog, with no advisory found, so 2 points (https://www.openfort.io/changelog)."
        ],
        "verdict": "Backend wallets sign inside a GCP Confidential Space enclave, secret keys carry 26 scopes, and rate limits, errors and prices are published. On EVM, a backend send reaches the policy engine only as a hash, so address and value rules bind only when the caller runs the pre-flight check first.",
        "bestFor": "A team that wants server-held wallets for agents on EVM chains and Solana with enclave signing, a free start and a CLI an agent can drive.",
        "strengths": [
          "Backend wallet keys are generated and used inside a GCP Confidential Space enclave with AMD SEV-SNP, wrapped by an HSM-backed Cloud KMS key",
          "Secret keys carry 26 named scopes, and backend signing also needs an ES256 JWT from a separate wallet secret that can be rotated",
          "Policy engine rejects any operation no rule matches, with account and project scopes and a pre-flight `POST /v2/policies/evaluate`",
          "Rate limits are published per plan (100 to 1,200 requests a minute) and a 429 carries `Retry-After`",
          "Free plan of 2,000 operations a month with no card, and per-operation overage prices on every plan"
        ],
        "weaknesses": [
          "An EVM backend send is evaluated only as `signEvmHash`, so address, value and calldata rules do not block it unless the caller pre-flights",
          "Signing policies cap value per transaction. No daily or rolling cap was found in the reviewed policy pages",
          "The CLI MCP server exposes 72 commands as tools, among them `accounts_evm_export`, which returns a private key",
          "A default secret key includes `accounts:export` and `accounts:sign`",
          "No SOC 2 report (the vendor says so), no security.txt and no bug bounty found"
        ],
        "agentNotes": [
          "Call `policies.evaluate` with operation `signEvmTransaction` before every EVM backend send. The send itself is checked only as `signEvmHash`",
          "Keep the signing policy and the gas sponsorship policy separate. Linking a signing policy to a fee sponsorship stops it working as a guardrail",
          "Pass a fee sponsorship on EVM sends. Without one the transaction stays pending with no error",
          "Give an agent a secret key without `accounts:export`, and limit the CLI MCP server to the tools it needs",
          "On a 5xx after a write, read the resource before retrying. On a 429, wait the full `Retry-After`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.1
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 60,
          "reliability": 88,
          "schema": 89,
          "security": 65,
          "transparency": 64
        },
        "provenanceScore": 73
      },
      "connect": {
        "install": "npm install @openfort/openfort-node",
        "http": "curl https://api.openfort.io/v2/transactions -H \"Authorization: Bearer sk_test_...\"",
        "claudeCode": "claude mcp add --transport http openfort-docs https://www.openfort.io/api/mcp",
        "config": {
          "mcpServers": {
            "openfort": {
              "args": [
                "@openfort/cli",
                "--mcp"
              ],
              "command": "npx",
              "env": {
                "OPENFORT_API_KEY": "${OPENFORT_API_KEY}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/wallet.onchain",
        "tool": "https://letme.dev/openfort"
      },
      "area": "payments",
      "unitPrices": [
        {
          "item": "Growth plan",
          "unit": "month",
          "usd": 99,
          "note": "25,000 operations included"
        },
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 249,
          "note": "100,000 operations included"
        },
        {
          "item": "Scale plan",
          "unit": "month",
          "usd": 599,
          "note": "500,000 operations included"
        },
        {
          "item": "Extra operation, Free plan",
          "unit": "call",
          "usd": 0.01,
          "note": "per operation above 2,000 a month"
        },
        {
          "item": "Extra operation, Growth plan",
          "unit": "call",
          "usd": 0.008,
          "note": "per operation above 25,000 a month"
        },
        {
          "item": "Extra operation, Scale plan",
          "unit": "call",
          "usd": 0.004,
          "note": "per operation above 500,000 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Alamas Labs Inc.",
        "domain": "openfort.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://www.openfort.io/developer-terms",
        "privacy": "https://www.openfort.io/privacy",
        "statusPage": "https://status.openfort.io",
        "changelog": "https://www.openfort.io/changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Developer Terms of Service (last updated 16 January 2026) and the privacy policy (last updated 4 September 2026) both name Alamas Labs Inc. doing business as Openfort. The terms are governed by Delaware law.",
          "The API answers at https://api.openfort.io and the docs, OpenAPI file and docs MCP server at www.openfort.io.",
          "https://www.openfort.io/.well-known/security.txt answered 404. The security page gives security@openfort.io for reports.",
          "rdap.org answered that no RDAP service is available for openfort.io, so the registration date is not recorded.",
          "robots.txt on www.openfort.io allows every path and carries `Content-Signal: search=yes, ai-input=yes, ai-train=no`."
        ],
        "score": 73
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/openfort.json",
      "live": {
        "slug": "openfort",
        "probe": {
          "target": "https://api.openfort.io",
          "method": "get",
          "lastAt": "2026-10-10T02:07:19.161241064Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 135,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 124,
          "p95ms24h": 218,
          "samples24h": 107,
          "samples30d": 107,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 22,
              "ok": 22
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.openfort.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:51:06.10917188Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "openfort-xyz/openfort-node",
            "version": "v0.13.1",
            "released": "2026-09-26",
            "seenAt": "2026-10-09T17:10:51.27158188Z"
          },
          {
            "registry": "npm",
            "name": "@openfort/cli",
            "version": "0.2.2",
            "seenAt": "2026-10-09T17:10:50.094981492Z"
          },
          {
            "registry": "npm",
            "name": "@openfort/openfort-node",
            "version": "0.13.1",
            "seenAt": "2026-10-09T17:10:49.071091624Z"
          }
        ],
        "githubStars": 10,
        "npmWeekly": 7647,
        "pages": [
          {
            "url": "https://www.openfort.io/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:45.881124774Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f46241d68d76"
          },
          {
            "url": "https://www.openfort.io/pricing.md",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:49.918241068Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "85d4cce5d750"
          },
          {
            "url": "https://www.openfort.io/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:51.997983732Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "92d5a24cf4eb"
          },
          {
            "url": "https://www.openfort.io/developer-terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:48.217259445Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c5c4280eac9f"
          }
        ],
        "updatedAt": "2026-10-10T02:07:19.161241064Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Agentcard Corporation",
        "b": "Openfort (Alamas Labs Inc.)",
        "name": "Vendor"
      },
      {
        "a": "https://api.agentcard.sh",
        "b": "https://api.openfort.io",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "payer tooling only",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Agentcard's terms of use. The `agent-cards` CLI on npm declares no licence, `@agent-cards/checkout` is marked as having none, and the repository they name is private",
        "b": "Proprietary service under the Openfort Developer Terms of Service. The Node SDK and OpenSigner are MIT. The CLI repository and package state no licence",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-09",
        "b": "2026-09-28",
        "name": "Last release"
      },
      {
        "a": "2026-07-10",
        "b": "2026-01-16",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "2026-09-04",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "33k npm/wk",
        "b": "10 stars, 7.6k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Openfort scores 70.1 (BB) on agent readiness against Agentcard's 56.5 (C), and leads in 6 of 7 scored categories.",
        "question": "Which is better for AI agents, Agentcard or Openfort?"
      },
      {
        "answer": "Agentcard uses an OAuth sign-in. Openfort needs an API key.",
        "question": "Do Agentcard and Openfort need an API key?"
      },
      {
        "answer": "Yes. Agentcard has a hosted endpoint at https://api.agentcard.sh and Openfort at https://api.openfort.io.",
        "question": "Can an agent call Agentcard and Openfort without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": [
          "No incidents deducted, where Openfort loses 5 points for them"
        ],
        "goodFor": "A company building a shopping or purchasing agent that needs users to pay with their own cards under passkey approval, or needs capped virtual Visa cards per task.",
        "slug": "agentcard",
        "watchFor": "No status page or incident history was found on the site or in the docs. An SLA is listed for Enterprise plans only, with no published text"
      },
      {
        "aheadOn": [
          "Reliability, 88 against 29",
          "Schema \u0026 documentation, 89 against 80",
          "Payments \u0026 pricing, 60 against 42",
          "Maintenance \u0026 community, 87 against 74",
          "Transparency \u0026 trust, 69 against 44"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "Runs on your own machine"
        ],
        "goodFor": "A team that wants server-held wallets for agents on EVM chains and Solana with enclave signing, a free start and a CLI an agent can drive.",
        "slug": "openfort",
        "watchFor": "An EVM backend send is evaluated only as `signEvmHash`, so address, value and calldata rules do not block it unless the caller pre-flights"
      }
    ],
    "job": {
      "capability": "wallet.spend-limits",
      "name": "Wallet spend limits"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/agentcard-vs-crossmint.json",
        "title": "Agentcard vs Crossmint API + Docs MCP",
        "url": "https://www.anchorterminal.com/compare/agentcard-vs-crossmint"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcard-vs-sponge-wallet.json",
        "title": "Agentcard vs Sponge Wallet",
        "url": "https://www.anchorterminal.com/compare/agentcard-vs-sponge-wallet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcard-vs-stripe-mcp.json",
        "title": "Agentcard vs Stripe API + MCP",
        "url": "https://www.anchorterminal.com/compare/agentcard-vs-stripe-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/circle-wallets-vs-openfort.json",
        "title": "Circle Wallets (Agent Wallets, Programmable Wallets) vs Openfort",
        "url": "https://www.anchorterminal.com/compare/circle-wallets-vs-openfort"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-openfort.json",
        "title": "Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) vs Openfort",
        "url": "https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-openfort"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openfort-vs-privy.json",
        "title": "Openfort vs Privy Wallets (server wallets, agent wallets, policy engine)",
        "url": "https://www.anchorterminal.com/compare/openfort-vs-privy"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openfort-vs-sponge-wallet.json",
        "title": "Openfort vs Sponge Wallet",
        "url": "https://www.anchorterminal.com/compare/openfort-vs-sponge-wallet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openfort-vs-turnkey-agentic-wallets.json",
        "title": "Openfort vs Turnkey Agentic Wallets",
        "url": "https://www.anchorterminal.com/compare/openfort-vs-turnkey-agentic-wallets"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcard-vs-circle-wallets.json",
        "title": "Agentcard vs Circle Wallets (Agent Wallets, Programmable Wallets)",
        "url": "https://www.anchorterminal.com/compare/agentcard-vs-circle-wallets"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcard-vs-coinbase-cdp-agentkit.json",
        "title": "Agentcard vs Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP)",
        "url": "https://www.anchorterminal.com/compare/agentcard-vs-coinbase-cdp-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcard-vs-privy.json",
        "title": "Agentcard vs Privy Wallets (server wallets, agent wallets, policy engine)",
        "url": "https://www.anchorterminal.com/compare/agentcard-vs-privy"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcard-vs-turnkey-agentic-wallets.json",
        "title": "Agentcard vs Turnkey Agentic Wallets",
        "url": "https://www.anchorterminal.com/compare/agentcard-vs-turnkey-agentic-wallets"
      }
    ],
    "scores": [
      {
        "agentcard": 29,
        "by": 59,
        "edge": "openfort",
        "key": "reliability",
        "name": "Reliability",
        "openfort": 88,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "agentcard": 80,
        "by": 9,
        "edge": "openfort",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "openfort": 89,
        "weight": 13
      },
      {
        "agentcard": 63,
        "by": 2,
        "edge": "openfort",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "openfort": 65,
        "weight": 13
      },
      {
        "agentcard": 68,
        "by": 3,
        "edge": "agentcard",
        "key": "security",
        "name": "Security \u0026 auth",
        "openfort": 65,
        "weight": 14
      },
      {
        "agentcard": 42,
        "by": 18,
        "edge": "openfort",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "openfort": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "agentcard": 74,
        "by": 13,
        "edge": "openfort",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "openfort": 87,
        "weight": 7
      },
      {
        "agentcard": 44,
        "by": 25,
        "edge": "openfort",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "openfort": 69,
        "weight": 7
      }
    ],
    "summary": "Openfort scores 70.1 (BB) on agent readiness against Agentcard's 56.5 (C), and leads in 6 of 7 scored categories. Both do wallet spend limits.",
    "verdicts": {
      "agentcard": "Purchases need the user's passkey approval by default, cards carry spending rules, and card creation takes an idempotency key. No status page, published rate limits beyond the token endpoint, or privacy policy of Agentcard's own was found, and the Trust Centre could not be read. Issuing costs $5,000 a month.",
      "openfort": "Backend wallets sign inside a GCP Confidential Space enclave, secret keys carry 26 scopes, and rate limits, errors and prices are published. On EVM, a backend send reaches the policy engine only as a hash, so address and value rules bind only when the caller runs the pre-flight check first."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/agentcard-vs-openfort",
    "json": "https://www.anchorterminal.com/compare/agentcard-vs-openfort.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/agentcard-vs-openfort.md",
    "slim": "https://www.anchorterminal.com/compare/agentcard-vs-openfort.min.md"
  },
  "markdown": "Openfort scores 70.1 (BB) on agent readiness against Agentcard's 56.5 (C), and leads in 6 of 7 scored categories. Both do wallet spend limits.\n\n- Agentcard: grade C, 56.5/100, rank #632 of 950. Markdown https://www.anchorterminal.com/tools/agentcard.md · JSON https://www.anchorterminal.com/api/v1/tools/agentcard.json\n- Openfort: grade BB, 70.1/100, rank #163 of 950. Markdown https://www.anchorterminal.com/tools/openfort.md · JSON https://www.anchorterminal.com/api/v1/tools/openfort.json\n- Best agent wallets and spending controls: https://www.anchorterminal.com/best/agent-wallets/index.md\n- All 23 wallets comparisons: https://www.anchorterminal.com/compare/agent-wallets/index.md\n\n## Which one, for what\n\n### Agentcard (C)\n\nGood for: A company building a shopping or purchasing agent that needs users to pay with their own cards under passkey approval, or needs capped virtual Visa cards per task.\n\nAlso in its favour:\n- No incidents deducted, where Openfort loses 5 points for them\n\nWatch for: No status page or incident history was found on the site or in the docs. An SLA is listed for Enterprise plans only, with no published text\n\n### Openfort (BB)\n\nGood for: A team that wants server-held wallets for agents on EVM chains and Solana with enclave signing, a free start and a CLI an agent can drive.\n\nAhead on:\n- Reliability, 88 against 29\n- Schema \u0026 documentation, 89 against 80\n- Payments \u0026 pricing, 60 against 42\n- Maintenance \u0026 community, 87 against 74\n- Transparency \u0026 trust, 69 against 44\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- Runs on your own machine\n\nWatch for: An EVM backend send is evaluated only as `signEvmHash`, so address, value and calldata rules do not block it unless the caller pre-flights\n\n\n## Score by category\n\n| Category | Weight | Agentcard | Openfort | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 29 | 88 | Openfort +59 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 80 | 89 | Openfort +9 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 65 | Openfort +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 68 | 65 | Agentcard +3 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 42 | 60 | Openfort +18 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 87 | Openfort +13 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 44 | 69 | Openfort +25 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **56.5 · C** | **70.1 · BB** | |\n\n## Facts side by side\n\n| Fact | Agentcard | Openfort |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Agentcard Corporation | Openfort (Alamas Labs Inc.) |\n| Hosted endpoint | `https://api.agentcard.sh` | `https://api.openfort.io` |\n| Transports | HTTP | HTTP, stdio |\n| Auth | OAuth | API key |\n| Pricing | Freemium | Freemium |\n| x402 | no | payer tooling only |\n| Licence | Proprietary service under Agentcard's terms of use. The `agent-cards` CLI on npm declares no licence, `@agent-cards/checkout` is marked as having none, and the repository they name is private | Proprietary service under the Openfort Developer Terms of Service. The Node SDK and OpenSigner are MIT. The CLI repository and package state no licence |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-09 | 2026-09-28 |\n| Terms last updated | 2026-07-10 | 2026-01-16 |\n| Privacy policy last updated | no document linked | 2026-09-04 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | yes |\n| Popularity | 33k npm/wk | 10 stars, 7.6k npm/wk |\n\n## Verdicts\n\n**Agentcard.** Purchases need the user's passkey approval by default, cards carry spending rules, and card creation takes an idempotency key. No status page, published rate limits beyond the token endpoint, or privacy policy of Agentcard's own was found, and the Trust Centre could not be read. Issuing costs $5,000 a month.\n\n**Openfort.** Backend wallets sign inside a GCP Confidential Space enclave, secret keys carry 26 scopes, and rate limits, errors and prices are published. On EVM, a backend send reaches the policy engine only as a hash, so address and value rules bind only when the caller runs the pre-flight check first.\n\n## Before you call either\n\n### Agentcard\n\n1. Mint a platform token with `POST /api/v2/oauth/token` and cache it for its one hour. The endpoint allows 30 requests per 5 minutes per IP\n2. Send the same `Idempotency-Key` on every retry of `POST /api/v2/cards`, and the same `idempotency_key` on every retry of `buy_checkout`\n3. Pass `source: \"issued\"` to the MCP `create_card` tool for a card number. Without it the tool may start Vault setup and return a link\n4. Call `get_card_details` only at the payment form and never log the result. Each read notifies the member and may return `approval_required`\n5. Treat `transaction.authorized` and `order.*` webhooks as the record of a payment, and deduplicate deliveries on the event `id`\n\n### Openfort\n\n1. Call `policies.evaluate` with operation `signEvmTransaction` before every EVM backend send. The send itself is checked only as `signEvmHash`\n2. Keep the signing policy and the gas sponsorship policy separate. Linking a signing policy to a fee sponsorship stops it working as a guardrail\n3. Pass a fee sponsorship on EVM sends. Without one the transaction stays pending with no error\n4. Give an agent a secret key without `accounts:export`, and limit the CLI MCP server to the tools it needs\n5. On a 5xx after a write, read the resource before retrying. On a 429, wait the full `Retry-After`\n\n## Questions\n\n### Which is better for AI agents, Agentcard or Openfort?\n\nOpenfort scores 70.1 (BB) on agent readiness against Agentcard's 56.5 (C), and leads in 6 of 7 scored categories.\n\n### Do Agentcard and Openfort need an API key?\n\nAgentcard uses an OAuth sign-in. Openfort needs an API key.\n\n### Can an agent call Agentcard and Openfort without installing anything?\n\nYes. Agentcard has a hosted endpoint at https://api.agentcard.sh and Openfort at https://api.openfort.io.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/agentcard-vs-openfort.json, and with the fewest tokens: https://www.anchorterminal.com/compare/agentcard-vs-openfort.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"agentcard\", \"b\": \"openfort\"}`. From a terminal: `anchor compare agentcard openfort`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/agentcard.json and https://www.anchorterminal.com/api/v1/tools/openfort.json\n\n## Other comparisons with Agentcard or Openfort\n\n- [Agentcard vs Crossmint API + Docs MCP](https://www.anchorterminal.com/compare/agentcard-vs-crossmint.md)\n- [Agentcard vs Sponge Wallet](https://www.anchorterminal.com/compare/agentcard-vs-sponge-wallet.md)\n- [Agentcard vs Stripe API + MCP](https://www.anchorterminal.com/compare/agentcard-vs-stripe-mcp.md)\n- [Circle Wallets (Agent Wallets, Programmable Wallets) vs Openfort](https://www.anchorterminal.com/compare/circle-wallets-vs-openfort.md)\n- [Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) vs Openfort](https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-openfort.md)\n- [Openfort vs Privy Wallets (server wallets, agent wallets, policy engine)](https://www.anchorterminal.com/compare/openfort-vs-privy.md)\n- [Openfort vs Sponge Wallet](https://www.anchorterminal.com/compare/openfort-vs-sponge-wallet.md)\n- [Openfort vs Turnkey Agentic Wallets](https://www.anchorterminal.com/compare/openfort-vs-turnkey-agentic-wallets.md)\n- [Agentcard vs Circle Wallets (Agent Wallets, Programmable Wallets)](https://www.anchorterminal.com/compare/agentcard-vs-circle-wallets.md)\n- [Agentcard vs Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP)](https://www.anchorterminal.com/compare/agentcard-vs-coinbase-cdp-agentkit.md)\n- [Agentcard vs Privy Wallets (server wallets, agent wallets, policy engine)](https://www.anchorterminal.com/compare/agentcard-vs-privy.md)\n- [Agentcard vs Turnkey Agentic Wallets](https://www.anchorterminal.com/compare/agentcard-vs-turnkey-agentic-wallets.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Agentcard vs Openfort",
        "url": ""
      }
    ],
    "description": "Openfort scores 70.1 (BB) to Agentcard's 56.5 (C) for wallet spend limits. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Agentcard C 56.5",
      "Openfort BB 70.1",
      "scores"
    ],
    "h1": "Agentcard vs Openfort",
    "image": "https://www.anchorterminal.com/assets/og/compare-agentcard-vs-openfort.png",
    "path": "/compare/agentcard-vs-openfort",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Agentcard vs Openfort for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/agentcard-vs-openfort"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 730
  },
  "version": 1
}
