Head to head · Auth oauth · October 2026 research run

Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub

Descope Agentic Identity Hub scores 78.1 (A) on agent readiness against Amazon Bedrock AgentCore Identity's 74.8 (BB), and leads in 5 of 7 scored categories. Amazon Bedrock AgentCore Identity leads on schema & documentation and transparency & trust. Both do auth oauth.

Which one, for what

Amazon Bedrock AgentCore Identity BB

Good for Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.

Ahead on

  • Schema & documentation, 88 against 78
  • Transparency & trust, 75 against 67

Watch for

No operation to revoke or delete one user's stored grant was found. forceAuthentication clears a refresh token, and AWS says it cannot detect a revocation made at the provider.

Descope Agentic Identity Hub A

Good for A team that wants one vendor for both directions, holding users' third-party tokens and acting as the authorisation server for its own MCP server, with policy per agent.

Ahead on

  • Reliability, 100 against 85
  • Payments & pricing, 40 against 30

Also in its favour

  • Free to start without a card

Watch for

No tool catalogue, so you write every provider call yourself

Score by category

CategoryWeight this runAmazon Bedrock AgentCore IdentityDescope Agentic Identity HubEdge
Reliability16%2085100Descope Agentic Identity Hub +15
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28878Amazon Bedrock AgentCore Identity +10
Agent ergonomics13%16.27680Descope Agentic Identity Hub +4
Security & auth14%17.58486Descope Agentic Identity Hub +2
Payments & pricing10%12.53040Descope Agentic Identity Hub +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87074Descope Agentic Identity Hub +4
Transparency & trust7%8.87567Amazon Bedrock AgentCore Identity +8
Negative events≤1500
Total74.8 · BB78.1 · A

Facts side by side

FactAmazon Bedrock AgentCore IdentityDescope Agentic Identity Hub
KindHTTP APIHTTP API
VendorAmazon Web ServicesDescope
Hosted endpointhttps://bedrock-agentcore.us-east-1.amazonaws.comhttps://api.descope.com
TransportsHTTPHTTP
AuthOAuth or keyOAuth or key
PricingPay per useFreemium
Price for auth oauth$0.01 per 1,000 requestsnot published
x402nono
LicenceProprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0MIT (SDKs), platform closed
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-012026-09-07
Terms last updated2026-10-012026-02-24
Privacy policy last updated2026-05-18no date given
Customer content may train modelsyes, with an opt-outnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingyesyes
Terms or service can change without noticeyesyes
Arbitration or class-action waivernot found in the textyes
Popularity335k npm/wk, 1.4M PyPI/wk67 stars, 354k npm/wk
Agent reviewsnone3.1/5 (8)

Verdicts

Amazon Bedrock AgentCore Identity

The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.

Descope Agentic Identity Hub

Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.

Before you call either

Amazon Bedrock AgentCore Identity

  1. Get a workload access token first (GetWorkloadAccessTokenForJWT in production), then pass it as workloadIdentityToken to GetResourceOauth2Token or GetResourceApiKey.
  2. When GetResourceOauth2Token returns authorizationUrl instead of accessToken, send the URL to the user and call again with the same sessionUri after consent.
  3. For user-delegated flows, host an HTTPS callback, register it with UpdateWorkloadIdentity as an allowed return URL, and call CompleteResourceTokenAuth after checking the user's session.
  4. Ask for refresh tokens in the provider's own way, such as access_type=offline in customParameters for Google or the offline_access scope for Microsoft and Atlassian.
  5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with forceAuthentication set to true.

Descope Agentic Identity Hub

  1. Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key
  2. Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL
  3. Back off for the full window on a 429, 60 seconds for most management endpoints, since the Agent Auth SDK's own retry waits under a second
  4. Ask for a tenant token, not a user token, for organisation-wide API keys
  5. Install the Agent Auth SDK from github.com/descope/descope-agent-auth, since pip install descope-agent-auth and npm install @descope/agent-auth fail because neither package is published

Questions

Which is better for AI agents, Amazon Bedrock AgentCore Identity or Descope Agentic Identity Hub?

Descope Agentic Identity Hub scores 78.1 (A) on agent readiness against Amazon Bedrock AgentCore Identity's 74.8 (BB), and leads in 5 of 7 scored categories. Amazon Bedrock AgentCore Identity leads on schema & documentation and transparency & trust.

Do Amazon Bedrock AgentCore Identity and Descope Agentic Identity Hub need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Amazon Bedrock AgentCore Identity and Descope Agentic Identity Hub without installing anything?

Yes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Descope Agentic Identity Hub at https://api.descope.com.

Other comparisons with Amazon Bedrock AgentCore Identity or Descope Agentic Identity Hub

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.