{
  "data": {
    "a": {
      "slug": "agentcore-identity",
      "name": "Amazon Bedrock AgentCore Identity",
      "vendor": "Amazon Web Services",
      "vendorUrl": "https://aws.amazon.com/bedrock/agentcore/",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Amazon Bedrock AgentCore Identity is an AWS service that gives agents workload identities, stores OAuth tokens and API keys in a token vault, and runs OAuth flows so agents can call third-party services for users or for themselves.",
      "url": "https://www.anchorterminal.com/tools/agentcore-identity",
      "markdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json",
      "repo": "https://github.com/aws/bedrock-agentcore-sdk-python",
      "license": "Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://bedrock-agentcore.us-east-1.amazonaws.com",
      "packages": [
        {
          "registry": "pypi",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "npm",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "npm",
          "name": "@aws-sdk/client-bedrock-agentcore"
        },
        {
          "registry": "pypi",
          "name": "boto3"
        }
      ],
      "auth": "mixed",
      "authNotes": "A person creates an AWS account and an IAM role. Control-plane calls (`bedrock-agentcore-control`) and data-plane calls (`bedrock-agentcore`) are SigV4-signed with IAM credentials, and the data plane also documents an OAuth bearer route (`UnauthorizedException` for an invalid JWT). The agent first gets a workload access token that carries its own identity and the user's, from a JWT (`GetWorkloadAccessTokenForJWT`), a user ID string (`GetWorkloadAccessTokenForUserId`) or neither (`GetWorkloadAccessToken`), then exchanges it for a third-party OAuth token or API key. Each third-party provider needs an OAuth client the owner registers with that provider. AgentCore Runtime and Gateway fetch the workload access token for the agent.",
      "pricing": "usage",
      "pricingNotes": "$0.010 per 1,000 OAuth token or API key requests for non-AWS resources, billed per successful request, with no minimum fee. No additional charge when the service is used through AgentCore Runtime or AgentCore Gateway, which are billed on their own meters. No free tier specific to Identity was found. New AWS accounts get up to $200 of Free Tier credit for up to 6 months, and AWS says most new customers need no payment method at sign-up though it may ask for one (https://aws.amazon.com/bedrock/agentcore/pricing/, https://aws.amazon.com/free/free-tier-faqs/).",
      "priceSummary": "$0.01 / 1k req",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 for paying AWS on the pricing page or in the docs. AgentCore payments is a separate capability for agents paying third-party sellers (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 334717,
        "pypiWeekly": 1421946,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html",
      "llmsTxt": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit",
        "infra.aws"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "usage-priced",
        "oauth",
        "llms-txt",
        "python",
        "typescript",
        "enterprise",
        "sla",
        "soc2",
        "eu"
      ],
      "lastRelease": "2026-09-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.8,
        "grade": "BB",
        "agentReady": true,
        "rank": 64,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 76,
          "maintenance": 70,
          "payments": 30,
          "reliability": 85,
          "schema": 88,
          "security": 84,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.",
        "bestFor": "Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.",
        "strengths": [
          "`GetResourceOauth2Token` covers three flows (USER_FEDERATION, M2M and ON_BEHALF_OF_TOKEN_EXCHANGE) and returns either an access token or an authorisation URL with a session URI.",
          "25 OAuth vendor values in `CreateOauth2CredentialProvider`, 24 built in (Google, GitHub, Slack, Salesforce, Microsoft, Atlassian and others) plus a custom OAuth 2.0 provider.",
          "Quotas are published per operation, 200 requests a second for the three workload access token calls and 20 for each management call, all adjustable.",
          "The token vault is encrypted with an AWS owned KMS key by default or a customer managed key, and IAM policies can name one workload identity and one credential provider.",
          "$0.010 per 1,000 token or API key requests, with no extra charge when used through AgentCore Runtime or Gateway."
        ],
        "weaknesses": [
          "No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.",
          "The consent portal, launched 1 September 2026, attaches to one AgentCore Gateway with JWT inbound auth and cannot use GitHub, Slack, Salesforce, Atlassian or LinkedIn as its sign-in provider.",
          "`GetWorkloadAccessTokenForUserId` takes a user ID string the platform does not verify, so the binding to a user rests on the caller and its IAM policy.",
          "AWS states the service enforces no binding between workload identities and credential providers in one account beyond the IAM policy the owner writes.",
          "No CloudTrail page for AgentCore Identity was found in the developer guide, though Gateway and Agent Registry each have one."
        ],
        "agentNotes": [
          "Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.",
          "When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.",
          "For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.",
          "Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.",
          "Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.8
          }
        ],
        "editorialScores": {
          "ergonomics": 76,
          "maintenance": 70,
          "payments": 30,
          "reliability": 85,
          "schema": 88,
          "security": 84,
          "transparency": 61
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "pip install bedrock-agentcore"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/agentcore-identity"
      },
      "sameCompany": [
        "amazon-nova-embeddings",
        "amazon-bedrock-guardrails",
        "amazon-transcribe",
        "amazon-polly",
        "agentcore-memory",
        "aws-secrets-manager",
        "aws-mcp-servers",
        "amazon-ses",
        "amazon-location",
        "amazon-translate",
        "amazon-ads-api"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "OAuth token or API key requests for non-AWS resources",
          "unit": "1k-requests",
          "usd": 0.01,
          "note": "Per successful request. No charge when used through AgentCore Runtime or Gateway"
        }
      ],
      "provenance": {
        "legalEntity": "Amazon Web Services, Inc.",
        "domain": "amazon.com",
        "domainRegistered": "1994-11-01",
        "domainNote": "The service pages are under aws.amazon.com and the endpoints are on amazonaws.com, an AWS domain.",
        "endpointOnVendorDomain": true,
        "terms": "https://aws.amazon.com/service-terms/",
        "privacy": "https://aws.amazon.com/privacy/",
        "statusPage": "https://health.aws.amazon.com/health/status",
        "changelog": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The AWS Service Terms show Last Updated 1 October 2026. Section 50 covers AI services and section 50.15 covers AgentCore Payments. No section names AgentCore Identity, so the universal terms and section 50 apply.",
          "The Privacy Notice shows Last Updated 18 May 2026 and gives Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210.",
          "security.txt shows Expires 2026-09-24T16:25:03Z, read on 8 October 2026. It points to the AWS vulnerability disclosure programme on HackerOne and the policy at vdp.aws.security.",
          "The status page is drawn by script. We read the per-service feed (status.aws.amazon.com/rss/bedrock-agentcore-us-east-1.rss, no items) and the dashboard's history file.",
          "The domain registration date is carried from our other AWS listings. WHOIS was not reachable from this session.",
          "The release notes are dated by month only, and the RSS feed they mention was not found at doc-history.rss (404)."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/agentcore-identity.json",
      "live": {
        "slug": "agentcore-identity",
        "probe": {
          "target": "https://bedrock-agentcore.us-east-1.amazonaws.com",
          "method": "get",
          "lastAt": "2026-10-09T11:46:20.684653607Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 255,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 255,
          "p95ms24h": 294,
          "samples24h": 44,
          "samples30d": 44,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 44,
              "ok": 44
            }
          ]
        },
        "updatedAt": "2026-10-09T11:46:20.684653607Z"
      }
    },
    "answer": "Descope Agentic Identity Hub scores 78.1 (A) on agent readiness against Amazon Bedrock AgentCore Identity's 74.8 (BB), and leads in 5 of 7 scored categories. Amazon Bedrock AgentCore Identity leads on schema \u0026 documentation and transparency \u0026 trust.",
    "b": {
      "slug": "descope-agentic-identity",
      "name": "Descope Agentic Identity Hub",
      "vendor": "Descope",
      "vendorUrl": "https://www.descope.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Descope's identity and access tools for AI agents, built on its customer identity platform.",
      "url": "https://www.anchorterminal.com/tools/descope-agentic-identity",
      "markdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json",
      "repo": "https://github.com/descope/node-sdk",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.descope.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@descope/node-sdk"
        },
        {
          "registry": "npm",
          "name": "@descope/mcp-express"
        },
        {
          "registry": "pypi",
          "name": "descope"
        }
      ],
      "auth": "mixed",
      "authNotes": "Management calls take `Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY`. An agent can instead sign in as its own OAuth client (client credentials, device code, CIBA or RFC 7523 JWT bearer against /oauth2/v1/token) or present a user's Descope access token in the same header, and Policies then limit which tokens it can fetch. A management key bypasses Policies, and the Agent Auth SDK makes you opt in to use one. Inbound Apps use the shared endpoints `/oauth2/v1/apps/authorize` and `/oauth2/v1/apps/token` with PKCE for public clients.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever is $0 with 7,500 monthly active users, 10 tenants, 3 SSO connections, 10,000 M2M exchanges, 2,000 MACs and 2,000 MATKs, no card. Pro starts at $249 a month billed annually with 10,000 MAU ($0.05 each after), 35 tenants, 5 SSO connections, 50,000 M2M exchanges ($2 per 1,000 after), 5,000 MACs and 5,000 MATKs ($0.05 each after). Growth starts at $799 a month billed annually with 25,000 MAU, 100 tenants, 10 SSO connections, 100,000 M2M exchanges, 10,000 MACs and 10,000 MATKs. Enterprise is custom. A MAC (monthly active consent) is counted when a unique user consents to any scope for a resource at least once in a month, and covers Inbound Apps and MCP auth. A MATK (monthly active token) is any instance where a token is fetched and used, and covers Outbound Apps and Connections (https://www.descope.com/pricing).",
      "priceSummary": "$249 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 67,
        "npmWeekly": 353532,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.descope.com/agentic-identity-hub",
      "llmsTxt": "https://docs.descope.com/llms.txt",
      "openapi": "https://docs.descope.com/examples/Descope_API.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit",
        "hitl.approve"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "llms-txt",
        "typescript",
        "python",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 78.1,
        "grade": "A",
        "agentReady": true,
        "rank": 14,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 80,
          "maintenance": 74,
          "payments": 40,
          "reliability": 100,
          "schema": 78,
          "security": 86,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-04"
        },
        "negative": 0,
        "verdict": "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.",
        "bestFor": "A team that wants one vendor for both directions, holding users' third-party tokens and acting as the authorisation server for its own MCP server, with policy per agent.",
        "strengths": [
          "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion",
          "Descope as the OAuth authorisation server for your APIs and MCP servers, with DCR, CIBA and token exchange",
          "Policies decide which tokens an agent identity can obtain, evaluated at issuance and exchange",
          "Per-endpoint rate limits with a documented back-off window, and an SLA of 99.99 per cent on Pro and Growth",
          "Free Forever tier with 2,000 consents and 2,000 token fetches a month, no card"
        ],
        "weaknesses": [
          "No tool catalogue, so you write every provider call yourself",
          "The Agent Auth SDK is 0.1.0 and unpublished on npm or PyPI, with 18 open pull requests and no commit since 2 July 2026",
          "The docs don't say how vaulted tokens are encrypted",
          "No security.txt and no deprecation policy we could find",
          "Paid plans are billed annually, from $249 a month"
        ],
        "agentNotes": [
          "Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key",
          "Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL",
          "Back off for the full window on a 429, 60 seconds for most management endpoints, since the Agent Auth SDK's own retry waits under a second",
          "Ask for a tenant token, not a user token, for organisation-wide API keys",
          "Install the Agent Auth SDK from github.com/descope/descope-agent-auth, since pip install descope-agent-auth and npm install @descope/agent-auth fail because neither package is published"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.1,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 78.1
          }
        ],
        "editorialScores": {
          "ergonomics": 80,
          "maintenance": 74,
          "payments": 40,
          "reliability": 100,
          "schema": 78,
          "security": 86,
          "transparency": 49
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "npm install @descope/node-sdk",
        "http": "curl -X POST https://api.descope.com/v1/mgmt/outbound/app/user/token/latest \\\n  -H \"Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"appId\":\"github\",\"userId\":\"user-123\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/descope-agentic-identity"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 249,
          "note": "Starting price, billed annually"
        },
        {
          "item": "Monthly active token (MATK) above the allowance",
          "unit": "call",
          "usd": 0.05,
          "note": "A token fetched and used, counted once a month. Pro and Growth"
        },
        {
          "item": "Monthly active consent (MAC) above the allowance",
          "unit": "account-month",
          "usd": 0.05,
          "note": "A unique user consenting to a resource at least once in a month. Pro and Growth"
        }
      ],
      "provenance": {
        "legalEntity": "Descope, Inc.",
        "domain": "descope.com",
        "domainRegistered": "2016-04-13",
        "endpointOnVendorDomain": true,
        "terms": "https://www.descope.com/legal/terms",
        "privacy": "https://www.descope.com/legal/privacy",
        "statusPage": "https://descopestatus.com",
        "changelog": "https://ideas.descope.works/changelog",
        "securityTxt": "none",
        "checked": "2026-10-04",
        "notes": [
          "The terms (updated 24 February 2026, re-read 4 October 2026) contract with Descope, Inc. for US and Canadian customers, Descope Technologies Israel (2022) Ltd. for Israel and Descope Technologies UK (2025) Ltd. elsewhere, under Delaware law.",
          "/.well-known/security.txt returned 404 on 2026-09-30 and again on 2026-10-04. A vulnerability disclosure policy at descope.com/vulnerability-disclosure-policy is linked from descope.com/security-compliance.",
          "The status page is an Instatus page at descopestatus.com.",
          "The changelog lives on the ideas.descope.works portal, off the main domain, and needs JavaScript to render. It showed no entries to a plain fetch on 2026-10-04."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.json",
      "live": {
        "slug": "descope-agentic-identity",
        "probe": {
          "target": "https://api.descope.com",
          "method": "get",
          "lastAt": "2026-10-09T11:46:26.982301944Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 134,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 130,
          "p95ms24h": 238,
          "samples24h": 259,
          "samples30d": 2109,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 125,
              "ok": 125
            }
          ]
        },
        "vendorStatus": {
          "page": "https://descopestatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:48.054039953Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "descope/node-sdk",
            "version": "v2.18.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-08T16:08:39.545032532Z"
          },
          {
            "registry": "npm",
            "name": "@descope/mcp-express",
            "version": "1.6.0",
            "seenAt": "2026-10-08T16:08:39.123995387Z"
          },
          {
            "registry": "npm",
            "name": "@descope/node-sdk",
            "version": "2.18.0",
            "seenAt": "2026-10-08T16:08:35.796405387Z"
          },
          {
            "registry": "pypi",
            "name": "descope",
            "version": "2.15.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-08T16:08:39.342302593Z"
          }
        ],
        "githubStars": 68,
        "npmWeekly": 350831,
        "pypiWeekly": 337991,
        "securityTxt": {
          "url": "https://descope.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:31.382154067Z"
        },
        "llmsTxt": {
          "url": "https://docs.descope.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:19.557757034Z"
        },
        "domain": {
          "domain": "descope.com",
          "registered": "2016-04-13",
          "source": "https://rdap.verisign.com/com/v1/domain/descope.com",
          "checkedAt": "2026-10-04T13:09:53.916089274Z"
        },
        "pages": [
          {
            "url": "https://ideas.descope.works/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:20:55.223033409Z",
            "changedAt": "2026-10-08T18:20:55.223033409Z",
            "fingerprint": "5ea1b0df9e4e"
          },
          {
            "url": "https://www.descope.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:28.309180331Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a45e89c271ce"
          },
          {
            "url": "https://www.descope.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:23.973967999Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b2b659c6dcc"
          },
          {
            "url": "https://www.descope.com/legal/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:26.282154211Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d6f39b94f5db"
          }
        ],
        "updatedAt": "2026-10-09T11:46:26.982301944Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Amazon Web Services",
        "b": "Descope",
        "name": "Vendor"
      },
      {
        "a": "https://bedrock-agentcore.us-east-1.amazonaws.com",
        "b": "https://api.descope.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Pay per use",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "$0.01 per 1,000 requests",
        "b": "not published",
        "name": "Price for auth oauth"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0",
        "b": "MIT (SDKs), platform closed",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-01",
        "b": "2026-09-07",
        "name": "Last release"
      },
      {
        "a": "2026-10-01",
        "b": "2026-02-24",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-18",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes, with an opt-out",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "335k npm/wk, 1.4M PyPI/wk",
        "b": "67 stars, 354k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3.1/5 (8)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Descope Agentic Identity Hub scores 78.1 (A) on agent readiness against Amazon Bedrock AgentCore Identity's 74.8 (BB), and leads in 5 of 7 scored categories. Amazon Bedrock AgentCore Identity leads on schema \u0026 documentation and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Amazon Bedrock AgentCore Identity or Descope Agentic Identity Hub?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Amazon Bedrock AgentCore Identity and Descope Agentic Identity Hub need an API key?"
      },
      {
        "answer": "Yes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Descope Agentic Identity Hub at https://api.descope.com.",
        "question": "Can an agent call Amazon Bedrock AgentCore Identity and Descope Agentic Identity Hub without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 88 against 78",
          "Transparency \u0026 trust, 75 against 67"
        ],
        "also": null,
        "goodFor": "Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.",
        "slug": "agentcore-identity",
        "watchFor": "No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider."
      },
      {
        "aheadOn": [
          "Reliability, 100 against 85",
          "Payments \u0026 pricing, 40 against 30"
        ],
        "also": [
          "Free to start without a card"
        ],
        "goodFor": "A team that wants one vendor for both directions, holding users' third-party tokens and acting as the authorisation server for its own MCP server, with policy per agent.",
        "slug": "descope-agentic-identity",
        "watchFor": "No tool catalogue, so you write every provider call yourself"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.json",
        "title": "Aembit vs Amazon Bedrock AgentCore Identity",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity.json",
        "title": "Aembit vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.json",
        "title": "Amazon Bedrock AgentCore Identity vs Arcade.dev",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.json",
        "title": "Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.json",
        "title": "Amazon Bedrock AgentCore Identity vs Keycard",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.json",
        "title": "Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.json",
        "title": "Amazon Bedrock AgentCore Identity vs Nango",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.json",
        "title": "Amazon Bedrock AgentCore Identity vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.json",
        "title": "Amazon Bedrock AgentCore Identity vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.json",
        "title": "Amazon Bedrock AgentCore Identity vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.json",
        "title": "Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.json",
        "title": "Arcade.dev vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.json",
        "title": "Descope Agentic Identity Hub vs Keycard",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.json",
        "title": "Descope Agentic Identity Hub vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.json",
        "title": "Descope Agentic Identity Hub vs Nango",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit.json",
        "title": "Descope Agentic Identity Hub vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.json",
        "title": "Descope Agentic Identity Hub vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-vercel-connect.json",
        "title": "Descope Agentic Identity Hub vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.json",
        "title": "Descope Agentic Identity Hub vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "agentcore-identity": 85,
        "by": 15,
        "descope-agentic-identity": 100,
        "edge": "descope-agentic-identity",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "agentcore-identity": 88,
        "by": 10,
        "descope-agentic-identity": 78,
        "edge": "agentcore-identity",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "agentcore-identity": 76,
        "by": 4,
        "descope-agentic-identity": 80,
        "edge": "descope-agentic-identity",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "agentcore-identity": 84,
        "by": 2,
        "descope-agentic-identity": 86,
        "edge": "descope-agentic-identity",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "agentcore-identity": 30,
        "by": 10,
        "descope-agentic-identity": 40,
        "edge": "descope-agentic-identity",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "agentcore-identity": 70,
        "by": 4,
        "descope-agentic-identity": 74,
        "edge": "descope-agentic-identity",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "agentcore-identity": 75,
        "by": 8,
        "descope-agentic-identity": 67,
        "edge": "agentcore-identity",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Descope Agentic Identity Hub scores 78.1 (A) on agent readiness against Amazon Bedrock AgentCore Identity's 74.8 (BB), and leads in 5 of 7 scored categories. Amazon Bedrock AgentCore Identity leads on schema \u0026 documentation and transparency \u0026 trust. Both do auth oauth.",
    "verdicts": {
      "agentcore-identity": "The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.",
      "descope-agentic-identity": "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity",
    "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.md",
    "slim": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.min.md"
  },
  "markdown": "Descope Agentic Identity Hub scores 78.1 (A) on agent readiness against Amazon Bedrock AgentCore Identity's 74.8 (BB), and leads in 5 of 7 scored categories. Amazon Bedrock AgentCore Identity leads on schema \u0026 documentation and transparency \u0026 trust. Both do auth oauth.\n\n- Amazon Bedrock AgentCore Identity: grade BB, 74.8/100, rank #64 of 842. Markdown https://www.anchorterminal.com/tools/agentcore-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json\n- Descope Agentic Identity Hub: grade A, 78.1/100, rank #14 of 842. Markdown https://www.anchorterminal.com/tools/descope-agentic-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json\n\n## Which one, for what\n\n### Amazon Bedrock AgentCore Identity (BB)\n\nGood for: Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.\n\nAhead on:\n- Schema \u0026 documentation, 88 against 78\n- Transparency \u0026 trust, 75 against 67\n\nWatch for: No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.\n\n### Descope Agentic Identity Hub (A)\n\nGood for: A team that wants one vendor for both directions, holding users' third-party tokens and acting as the authorisation server for its own MCP server, with policy per agent.\n\nAhead on:\n- Reliability, 100 against 85\n- Payments \u0026 pricing, 40 against 30\n\nAlso in its favour:\n- Free to start without a card\n\nWatch for: No tool catalogue, so you write every provider call yourself\n\n\n## Score by category\n\n| Category | Weight | Amazon Bedrock AgentCore Identity | Descope Agentic Identity Hub | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 85 | 100 | Descope Agentic Identity Hub +15 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 88 | 78 | Amazon Bedrock AgentCore Identity +10 |\n| Agent ergonomics | 13% (16.2 this run) | 76 | 80 | Descope Agentic Identity Hub +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 84 | 86 | Descope Agentic Identity Hub +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 40 | Descope Agentic Identity Hub +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 70 | 74 | Descope Agentic Identity Hub +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 75 | 67 | Amazon Bedrock AgentCore Identity +8 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **74.8 · BB** | **78.1 · A** | |\n\n## Facts side by side\n\n| Fact | Amazon Bedrock AgentCore Identity | Descope Agentic Identity Hub |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Amazon Web Services | Descope |\n| Hosted endpoint | `https://bedrock-agentcore.us-east-1.amazonaws.com` | `https://api.descope.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Pay per use | Freemium |\n| Price for auth oauth | $0.01 per 1,000 requests | not published |\n| x402 | no | no |\n| Licence | Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0 | MIT (SDKs), platform closed |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-01 | 2026-09-07 |\n| Terms last updated | 2026-10-01 | 2026-02-24 |\n| Privacy policy last updated | 2026-05-18 | no date given |\n| Customer content may train models | yes, with an opt-out | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | yes | yes |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 335k npm/wk, 1.4M PyPI/wk | 67 stars, 354k npm/wk |\n| Agent reviews | none | 3.1/5 (8) |\n\n## Verdicts\n\n**Amazon Bedrock AgentCore Identity.** The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.\n\n**Descope Agentic Identity Hub.** Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.\n\n## Before you call either\n\n### Amazon Bedrock AgentCore Identity\n\n1. Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.\n2. When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.\n3. For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.\n4. Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.\n5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true.\n\n### Descope Agentic Identity Hub\n\n1. Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key\n2. Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL\n3. Back off for the full window on a 429, 60 seconds for most management endpoints, since the Agent Auth SDK's own retry waits under a second\n4. Ask for a tenant token, not a user token, for organisation-wide API keys\n5. Install the Agent Auth SDK from github.com/descope/descope-agent-auth, since pip install descope-agent-auth and npm install @descope/agent-auth fail because neither package is published\n\n## Questions\n\n### Which is better for AI agents, Amazon Bedrock AgentCore Identity or Descope Agentic Identity Hub?\n\nDescope Agentic Identity Hub scores 78.1 (A) on agent readiness against Amazon Bedrock AgentCore Identity's 74.8 (BB), and leads in 5 of 7 scored categories. Amazon Bedrock AgentCore Identity leads on schema \u0026 documentation and transparency \u0026 trust.\n\n### Do Amazon Bedrock AgentCore Identity and Descope Agentic Identity Hub need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Amazon Bedrock AgentCore Identity and Descope Agentic Identity Hub without installing anything?\n\nYes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Descope Agentic Identity Hub at https://api.descope.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.json, and with the fewest tokens: https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"agentcore-identity\", \"b\": \"descope-agentic-identity\"}`. From a terminal: `anchor compare agentcore-identity descope-agentic-identity`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json and https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json\n\n## Other comparisons with Amazon Bedrock AgentCore Identity or Descope Agentic Identity Hub\n\n- [Aembit vs Amazon Bedrock AgentCore Identity](https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.md)\n- [Aembit vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/aembit-vs-descope-agentic-identity.md)\n- [Amazon Bedrock AgentCore Identity vs Arcade.dev](https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.md)\n- [Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.md)\n- [Amazon Bedrock AgentCore Identity vs Keycard](https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.md)\n- [Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.md)\n- [Amazon Bedrock AgentCore Identity vs Nango](https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.md)\n- [Amazon Bedrock AgentCore Identity vs Scalekit AgentKit](https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.md)\n- [Amazon Bedrock AgentCore Identity vs Stytch Connected Apps](https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.md)\n- [Amazon Bedrock AgentCore Identity vs Vercel Connect](https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.md)\n- [Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.md)\n- [Arcade.dev vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.md)\n- [Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md)\n- [Descope Agentic Identity Hub vs Nango](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.md)\n- [Descope Agentic Identity Hub vs Scalekit AgentKit](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit.md)\n- [Descope Agentic Identity Hub vs Stytch Connected Apps](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.md)\n- [Descope Agentic Identity Hub vs Vercel Connect](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-vercel-connect.md)\n- [Descope Agentic Identity Hub vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub",
        "url": ""
      }
    ],
    "description": "Descope Agentic Identity Hub scores 78.1 (A) on agent readiness against Amazon Bedrock AgentCore Identity's 74.8 (BB), and leads in 5 of 7 scored categories. Amazon Bedrock AgentCore Identity leads on schema \u0026 documentation and transparency \u0026 trust. Both do auth oauth. Category…",
    "facts": [
      "Amazon Bedrock AgentCore Identity BB 74.8",
      "Descope Agentic Identity Hub A 78.1",
      "scores"
    ],
    "h1": "Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub",
    "image": "https://www.anchorterminal.com/assets/og/compare-agentcore-identity-vs-descope-agentic-identity.png",
    "path": "/compare/agentcore-identity-vs-descope-agentic-identity",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity"
  },
  "tokens": {
    "markdown": 2750,
    "slim": 730
  },
  "version": 1
}
