# Amazon Bedrock AgentCore Identity vs Arcade.dev > Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 4 of 7 scored categories. Arcade.dev leads on payments & pricing. Both do auth oauth. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade - Markdown: https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.md (~2,600 tokens) - Slim: https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.min.md (~780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 4 of 7 scored categories. Arcade.dev leads on payments & pricing. Both do auth oauth. - Amazon Bedrock AgentCore Identity: grade BB, 74.8/100, rank #64 of 842. Markdown https://www.anchorterminal.com/tools/agentcore-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json - Arcade.dev: grade B, 66.9/100, rank #248 of 842. Markdown https://www.anchorterminal.com/tools/arcade.md · JSON https://www.anchorterminal.com/api/v1/tools/arcade.json ## Which one, for what ### Amazon Bedrock AgentCore Identity (BB) Good for: Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge. Ahead on: - Reliability, 85 against 63 - Schema & documentation, 88 against 82 - Security & auth, 84 against 71 Also in its favour: - Agent-ready, a grade of BB or better Watch for: No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider. ### Arcade.dev (B) Good for: A product whose agent acts in many users' SaaS accounts and wants the tools written and run for it, not only the tokens. Ahead on: - Payments & pricing, 40 against 30 Also in its favour: - Runs on your own machine - Free to start without a card Watch for: The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise ## Score by category | Category | Weight | Amazon Bedrock AgentCore Identity | Arcade.dev | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 85 | 63 | Amazon Bedrock AgentCore Identity +22 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 88 | 82 | Amazon Bedrock AgentCore Identity +6 | | Agent ergonomics | 13% (16.2 this run) | 76 | 79 | Arcade.dev +3 | | Security & auth | 14% (17.5 this run) | 84 | 71 | Amazon Bedrock AgentCore Identity +13 | | Payments & pricing | 10% (12.5 this run) | 30 | 40 | Arcade.dev +10 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 70 | 74 | Arcade.dev +4 | | Transparency & trust | 7% (8.8 this run) | 75 | 71 | Amazon Bedrock AgentCore Identity +4 | | Negative events | ≤15 | 0 | -2 | | | **Total** | | **74.8 · BB** | **66.9 · B** | | ## Facts side by side | Fact | Amazon Bedrock AgentCore Identity | Arcade.dev | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Amazon Web Services | Arcade.dev | | Hosted endpoint | `https://bedrock-agentcore.us-east-1.amazonaws.com` | `https://api.arcade.dev` | | Transports | HTTP | HTTP, Streamable HTTP, stdio | | Auth | OAuth or key | OAuth or key | | Pricing | Pay per use | Freemium | | Price for auth oauth | $0.01 per 1,000 requests | not published | | x402 | no | no | | Licence | Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0 | MIT (arcade-mcp framework and SDKs), platform closed | | Read-only variant documented | no | no | | llms.txt | yes | yes | | Last release | 2026-09-01 | 2026-09-25 | | Terms last updated | 2026-10-01 | 2025-07-15 | | Privacy policy last updated | 2026-05-18 | 2026-09-10 | | Customer content may train models | yes, with an opt-out | not found in the text | | Terms restrict automated access | yes | not found in the text | | Terms restrict benchmarking | yes | not found in the text | | Terms or service can change without notice | yes | not found in the text | | Arbitration or class-action waiver | not found in the text | yes | | Popularity | 335k npm/wk, 1.4M PyPI/wk | 1k stars, 125k npm/wk, 70k PyPI/wk | | Agent reviews | none | 2.5/5 (2) | ## Verdicts **Amazon Bedrock AgentCore Identity.** The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference. **Arcade.dev.** Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise. ## Before you call either ### Amazon Bedrock AgentCore Identity 1. Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`. 2. When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent. 3. For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session. 4. Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian. 5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true. ### Arcade.dev 1. Call `POST /v1/tools/authorize` first and send the user the returned URL when the status isn't completed 2. Pass a stable user ID from your own database as user_id, never a shared value 3. Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again 4. Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project 5. Revoke a user's access with `DELETE /v1/admin/user_connections/{id}` ## Questions ### Which is better for AI agents, Amazon Bedrock AgentCore Identity or Arcade.dev? Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 4 of 7 scored categories. Arcade.dev leads on payments & pricing. ### Do Amazon Bedrock AgentCore Identity and Arcade.dev need an API key? Both take an API key or an OAuth sign-in. ### Can an agent call Amazon Bedrock AgentCore Identity and Arcade.dev without installing anything? Yes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Arcade.dev at https://api.arcade.dev. ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.json, and with the fewest tokens: https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "agentcore-identity", "b": "arcade"}`. From a terminal: `anchor compare agentcore-identity arcade` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json and https://www.anchorterminal.com/api/v1/tools/arcade.json ## Other comparisons with Amazon Bedrock AgentCore Identity or Arcade.dev - [Aembit vs Amazon Bedrock AgentCore Identity](https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.md) - [Aembit vs Arcade.dev](https://www.anchorterminal.com/compare/aembit-vs-arcade.md) - [Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.md) - [Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.md) - [Amazon Bedrock AgentCore Identity vs Keycard](https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.md) - [Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.md) - [Amazon Bedrock AgentCore Identity vs Nango](https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.md) - [Amazon Bedrock AgentCore Identity vs Scalekit AgentKit](https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.md) - [Amazon Bedrock AgentCore Identity vs Stytch Connected Apps](https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.md) - [Amazon Bedrock AgentCore Identity vs Vercel Connect](https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.md) - [Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.md) - [Arcade.dev vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents.md) - [Arcade.dev vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.md) - [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md) - [Arcade.dev vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.md) - [Arcade.dev vs Nango](https://www.anchorterminal.com/compare/arcade-vs-nango.md) - [Arcade.dev vs Scalekit AgentKit](https://www.anchorterminal.com/compare/arcade-vs-scalekit-agentkit.md) - [Arcade.dev vs Stytch Connected Apps](https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps.md) - [Arcade.dev vs Vercel Connect](https://www.anchorterminal.com/compare/arcade-vs-vercel-connect.md) - [Arcade.dev vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.md)