{
  "data": {
    "a": {
      "slug": "agentcore-identity",
      "name": "Amazon Bedrock AgentCore Identity",
      "vendor": "Amazon Web Services",
      "vendorUrl": "https://aws.amazon.com/bedrock/agentcore/",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Amazon Bedrock AgentCore Identity is an AWS service that gives agents workload identities, stores OAuth tokens and API keys in a token vault, and runs OAuth flows so agents can call third-party services for users or for themselves.",
      "url": "https://www.anchorterminal.com/tools/agentcore-identity",
      "markdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json",
      "repo": "https://github.com/aws/bedrock-agentcore-sdk-python",
      "license": "Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://bedrock-agentcore.us-east-1.amazonaws.com",
      "packages": [
        {
          "registry": "pypi",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "npm",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "npm",
          "name": "@aws-sdk/client-bedrock-agentcore"
        },
        {
          "registry": "pypi",
          "name": "boto3"
        }
      ],
      "auth": "mixed",
      "authNotes": "A person creates an AWS account and an IAM role. Control-plane calls (`bedrock-agentcore-control`) and data-plane calls (`bedrock-agentcore`) are SigV4-signed with IAM credentials, and the data plane also documents an OAuth bearer route (`UnauthorizedException` for an invalid JWT). The agent first gets a workload access token that carries its own identity and the user's, from a JWT (`GetWorkloadAccessTokenForJWT`), a user ID string (`GetWorkloadAccessTokenForUserId`) or neither (`GetWorkloadAccessToken`), then exchanges it for a third-party OAuth token or API key. Each third-party provider needs an OAuth client the owner registers with that provider. AgentCore Runtime and Gateway fetch the workload access token for the agent.",
      "pricing": "usage",
      "pricingNotes": "$0.010 per 1,000 OAuth token or API key requests for non-AWS resources, billed per successful request, with no minimum fee. No additional charge when the service is used through AgentCore Runtime or AgentCore Gateway, which are billed on their own meters. No free tier specific to Identity was found. New AWS accounts get up to $200 of Free Tier credit for up to 6 months, and AWS says most new customers need no payment method at sign-up though it may ask for one (https://aws.amazon.com/bedrock/agentcore/pricing/, https://aws.amazon.com/free/free-tier-faqs/).",
      "priceSummary": "$0.01 / 1k req",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 for paying AWS on the pricing page or in the docs. AgentCore payments is a separate capability for agents paying third-party sellers (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 334717,
        "pypiWeekly": 1421946,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html",
      "llmsTxt": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit",
        "infra.aws"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "usage-priced",
        "oauth",
        "llms-txt",
        "python",
        "typescript",
        "enterprise",
        "sla",
        "soc2",
        "eu"
      ],
      "lastRelease": "2026-09-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.8,
        "grade": "BB",
        "agentReady": true,
        "rank": 64,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 76,
          "maintenance": 70,
          "payments": 30,
          "reliability": 85,
          "schema": 88,
          "security": 84,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.",
        "bestFor": "Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.",
        "strengths": [
          "`GetResourceOauth2Token` covers three flows (USER_FEDERATION, M2M and ON_BEHALF_OF_TOKEN_EXCHANGE) and returns either an access token or an authorisation URL with a session URI.",
          "25 OAuth vendor values in `CreateOauth2CredentialProvider`, 24 built in (Google, GitHub, Slack, Salesforce, Microsoft, Atlassian and others) plus a custom OAuth 2.0 provider.",
          "Quotas are published per operation, 200 requests a second for the three workload access token calls and 20 for each management call, all adjustable.",
          "The token vault is encrypted with an AWS owned KMS key by default or a customer managed key, and IAM policies can name one workload identity and one credential provider.",
          "$0.010 per 1,000 token or API key requests, with no extra charge when used through AgentCore Runtime or Gateway."
        ],
        "weaknesses": [
          "No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.",
          "The consent portal, launched 1 September 2026, attaches to one AgentCore Gateway with JWT inbound auth and cannot use GitHub, Slack, Salesforce, Atlassian or LinkedIn as its sign-in provider.",
          "`GetWorkloadAccessTokenForUserId` takes a user ID string the platform does not verify, so the binding to a user rests on the caller and its IAM policy.",
          "AWS states the service enforces no binding between workload identities and credential providers in one account beyond the IAM policy the owner writes.",
          "No CloudTrail page for AgentCore Identity was found in the developer guide, though Gateway and Agent Registry each have one."
        ],
        "agentNotes": [
          "Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.",
          "When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.",
          "For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.",
          "Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.",
          "Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.8
          }
        ],
        "editorialScores": {
          "ergonomics": 76,
          "maintenance": 70,
          "payments": 30,
          "reliability": 85,
          "schema": 88,
          "security": 84,
          "transparency": 61
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "pip install bedrock-agentcore"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/agentcore-identity"
      },
      "sameCompany": [
        "amazon-nova-embeddings",
        "amazon-bedrock-guardrails",
        "amazon-transcribe",
        "amazon-polly",
        "agentcore-memory",
        "aws-secrets-manager",
        "aws-mcp-servers",
        "amazon-ses",
        "amazon-location",
        "amazon-translate",
        "amazon-ads-api"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "OAuth token or API key requests for non-AWS resources",
          "unit": "1k-requests",
          "usd": 0.01,
          "note": "Per successful request. No charge when used through AgentCore Runtime or Gateway"
        }
      ],
      "provenance": {
        "legalEntity": "Amazon Web Services, Inc.",
        "domain": "amazon.com",
        "domainRegistered": "1994-11-01",
        "domainNote": "The service pages are under aws.amazon.com and the endpoints are on amazonaws.com, an AWS domain.",
        "endpointOnVendorDomain": true,
        "terms": "https://aws.amazon.com/service-terms/",
        "privacy": "https://aws.amazon.com/privacy/",
        "statusPage": "https://health.aws.amazon.com/health/status",
        "changelog": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The AWS Service Terms show Last Updated 1 October 2026. Section 50 covers AI services and section 50.15 covers AgentCore Payments. No section names AgentCore Identity, so the universal terms and section 50 apply.",
          "The Privacy Notice shows Last Updated 18 May 2026 and gives Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210.",
          "security.txt shows Expires 2026-09-24T16:25:03Z, read on 8 October 2026. It points to the AWS vulnerability disclosure programme on HackerOne and the policy at vdp.aws.security.",
          "The status page is drawn by script. We read the per-service feed (status.aws.amazon.com/rss/bedrock-agentcore-us-east-1.rss, no items) and the dashboard's history file.",
          "The domain registration date is carried from our other AWS listings. WHOIS was not reachable from this session.",
          "The release notes are dated by month only, and the RSS feed they mention was not found at doc-history.rss (404)."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/agentcore-identity.json",
      "live": {
        "slug": "agentcore-identity",
        "probe": {
          "target": "https://bedrock-agentcore.us-east-1.amazonaws.com",
          "method": "get",
          "lastAt": "2026-10-09T11:46:20.684653607Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 255,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 255,
          "p95ms24h": 294,
          "samples24h": 44,
          "samples30d": 44,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 44,
              "ok": 44
            }
          ]
        },
        "updatedAt": "2026-10-09T11:46:20.684653607Z"
      }
    },
    "answer": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 4 of 7 scored categories. Keycard leads on maintenance \u0026 community.",
    "b": {
      "slug": "keycard",
      "name": "Keycard",
      "vendor": "Keycard Labs",
      "vendorUrl": "https://www.keycard.ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Identity and access platform for AI agents.",
      "url": "https://www.anchorterminal.com/tools/keycard",
      "markdownUrl": "https://www.anchorterminal.com/tools/keycard.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keycard.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keycard.json",
      "repo": "https://github.com/keycardai/python-sdk",
      "license": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.keycard.ai",
      "packages": [
        {
          "registry": "pypi",
          "name": "keycardai-mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai-fastmcp"
        },
        {
          "registry": "npm",
          "name": "@keycardai/mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai_api"
        }
      ],
      "auth": "mixed",
      "authNotes": "The management API at api.keycard.ai takes `Authorization: Bearer $KEYCARD_API_KEY` (a service account key). Agents and MCP servers talk OAuth 2.0 to their zone at `https://\u003czone-id\u003e.keycard.cloud`, discovered from `/.well-known/oauth-authorization-server`, with PKCE, dynamic client registration and RFC 8693 token exchange against the token endpoint. Application credentials are a client secret, a web identity (OIDC) or EKS workload identity. Tokens are JWTs verified against the zone's JWKS.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 5,000 transactions a month as a hard cap, unlimited users, agents and apps, RBAC, ABAC and ReBAC policies, 7-day telemetry retention and community support. Team is $500 a month with 100,000 transactions and $1 per 1,000 after, SSO, zone policy, 90-day retention, email support and an SLA. Enterprise is custom on an annual commitment, with org and device-based policy, SCIM, Active Directory and LDAP provisioning, dedicated, BYOC or on-prem deployment, private networking, customer-managed KMS, 180-day retention, a 99.95 per cent uptime SLA and 1-hour 24/7 response on P1 issues. A transaction is recorded each time Keycard issues a credential, validates an access request or exchanges a credential (https://www.keycard.ai/pricing). The page doesn't say whether a card is needed, and its sign-up form ends with a promise to be in touch. The quickstart calls the product Early Access, with sign-up at console.keycard.ai.",
      "priceSummary": "$500 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1,
        "npmWeekly": 52,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.keycard.ai",
      "llmsTxt": "https://docs.keycard.ai/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.2,
        "grade": "C",
        "agentReady": false,
        "rank": 572,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 44
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.",
        "bestFor": "A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product.",
        "strengths": [
          "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange",
          "Delegated grants with RFC 8693 exchange for GitHub, Google, Slack, Linear and any OAuth 2.0 provider",
          "Session timeline and audit log per exchange, exported hourly to S3 in OCSF Parquet",
          "Published per-unit price ($1 per 1,000 transactions on Team) with a transaction defined",
          "Valid security.txt and SOC 2 Type 2 listed in a SafeBase trust centre"
        ],
        "weaknesses": [
          "Early Access with sign-up by request, and no terms of service page",
          "No per-token kill switch, so a revoked grant lives until the token expires, and revocation doesn't reach the provider",
          "No published rate limits, 429 guidance or public changelog",
          "keycardai-mcp went from 1.0.0 to 2.0.0 in a day in August 2026",
          "Team is $500 a month with nothing between it and the free tier"
        ],
        "agentNotes": [
          "Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone",
          "Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange",
          "Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry",
          "Keep credentials short-lived, because revocation only stops the next issuance",
          "Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.2
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 25
        },
        "provenanceScore": 62
      },
      "connect": {
        "install": "pip install keycardai-mcp",
        "http": "curl \"https://api.keycard.ai/zones/$KEYCARD_ZONE_ID/sessions\" \\\n  -H \"Authorization: Bearer $KEYCARD_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/keycard"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 500,
          "note": "100,000 transactions included"
        },
        {
          "item": "Transactions above 100,000 on Team",
          "unit": "1k-calls",
          "usd": 1,
          "note": "The pricing page doesn't define a transaction"
        }
      ],
      "provenance": {
        "legalEntity": "Keycard Labs, Inc.",
        "domain": "keycard.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://www.keycard.ai/privacy/",
        "statusPage": "https://status.keycard.ai",
        "changelog": "",
        "securityTxt": "valid",
        "checked": "2026-10-02",
        "notes": [
          "The homepage footer names Keycard Labs, Inc., 103 Foulk Road, Suite 202, Wilmington, DE 19808. The footer's legal links on 2 October were privacy, cookie policy, a vulnerability address and the trust centre at trust.keycard.ai. We found no terms of service page (keycard.ai/terms/ returns 404) and the privacy page's body didn't load for us on 30 September or 2 October.",
          "RDAP for keycard.ai returned 404 at rdap.nic.ai and 429 at Identity Digital on 2026-09-30, so the registration date is blank.",
          "status.keycard.ai answers as a status page, though its history renders client-side and its JSON and RSS feeds returned 403 to us on 2 October.",
          "The docs index (73 entries) lists no changelog. The SDK repositories' CHANGELOG.md files are the nearest thing to release notes.",
          "The trust centre lists SOC 2 Type 1 and Type 2 reports and names Resend, Google, GitHub, Cloudflare and AWS as subprocessors."
        ],
        "score": 62
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/keycard.json",
      "live": {
        "slug": "keycard",
        "probe": {
          "target": "https://api.keycard.ai",
          "method": "get",
          "lastAt": "2026-10-09T11:46:31.475578625Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 295,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 298,
          "p95ms24h": 375,
          "samples24h": 259,
          "samples30d": 2109,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 125,
              "ok": 125
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.keycard.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:05.925286139Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@keycardai/mcp",
            "version": "2.0.2",
            "seenAt": "2026-10-08T16:17:39.557981658Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-fastmcp",
            "version": "0.7.1",
            "released": "2026-09-15",
            "seenAt": "2026-10-08T16:17:37.664040081Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-mcp",
            "version": "2.3.2",
            "released": "2026-09-16",
            "seenAt": "2026-10-08T16:17:37.473812095Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai_api",
            "version": "0.18.0",
            "released": "2026-09-25",
            "seenAt": "2026-10-08T16:17:43.121407528Z"
          }
        ],
        "githubStars": 1,
        "npmWeekly": 199,
        "pypiWeekly": 164,
        "securityTxt": {
          "url": "https://keycard.ai/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-12T00:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:48.873310409Z"
        },
        "llmsTxt": {
          "url": "https://docs.keycard.ai/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:33.244940883Z"
        },
        "domain": {
          "domain": "keycard.ai",
          "registered": "2024-02-04",
          "source": "https://rdap.identitydigital.services/rdap/domain/keycard.ai",
          "checkedAt": "2026-10-04T13:06:32.92261194Z"
        },
        "pages": [
          {
            "url": "https://www.keycard.ai/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:36.483812542Z",
            "changedAt": "2026-10-08T18:28:36.483812542Z",
            "fingerprint": "ebe4ceb994c4"
          },
          {
            "url": "https://www.keycard.ai/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:38.627980953Z",
            "changedAt": "2026-10-08T18:28:38.627980953Z",
            "fingerprint": "5d00b76169d9"
          }
        ],
        "updatedAt": "2026-10-09T11:46:31.475578625Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Amazon Web Services",
        "b": "Keycard Labs",
        "name": "Vendor"
      },
      {
        "a": "https://bedrock-agentcore.us-east-1.amazonaws.com",
        "b": "https://api.keycard.ai",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Pay per use",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "$0.01 per 1,000 requests",
        "b": "not published",
        "name": "Price for auth oauth"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0",
        "b": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-01",
        "b": "2026-09-22",
        "name": "Last release"
      },
      {
        "a": "2026-10-01",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-18",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes, with an opt-out",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "335k npm/wk, 1.4M PyPI/wk",
        "b": "1 stars, 52 npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 4 of 7 scored categories. Keycard leads on maintenance \u0026 community.",
        "question": "Which is better for AI agents, Amazon Bedrock AgentCore Identity or Keycard?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Amazon Bedrock AgentCore Identity and Keycard need an API key?"
      },
      {
        "answer": "Yes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Keycard at https://api.keycard.ai.",
        "question": "Can an agent call Amazon Bedrock AgentCore Identity and Keycard without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 85 against 35",
          "Schema \u0026 documentation, 88 against 61",
          "Agent ergonomics, 76 against 60",
          "Transparency \u0026 trust, 75 against 44"
        ],
        "also": [
          "Agent-ready, a grade of BB or better"
        ],
        "goodFor": "Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.",
        "slug": "agentcore-identity",
        "watchFor": "No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider."
      },
      {
        "aheadOn": [
          "Maintenance \u0026 community, 79 against 70"
        ],
        "also": null,
        "goodFor": "A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product.",
        "slug": "keycard",
        "watchFor": "Early Access with sign-up by request, and no terms of service page"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.json",
        "title": "Aembit vs Amazon Bedrock AgentCore Identity",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-keycard.json",
        "title": "Aembit vs Keycard",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.json",
        "title": "Amazon Bedrock AgentCore Identity vs Arcade.dev",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.json",
        "title": "Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.json",
        "title": "Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.json",
        "title": "Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.json",
        "title": "Amazon Bedrock AgentCore Identity vs Nango",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.json",
        "title": "Amazon Bedrock AgentCore Identity vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.json",
        "title": "Amazon Bedrock AgentCore Identity vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.json",
        "title": "Amazon Bedrock AgentCore Identity vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.json",
        "title": "Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-keycard.json",
        "title": "Arcade.dev vs Keycard",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Keycard",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.json",
        "title": "Descope Agentic Identity Hub vs Keycard",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.json",
        "title": "Keycard vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-nango.json",
        "title": "Keycard vs Nango",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.json",
        "title": "Keycard vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.json",
        "title": "Keycard vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-vercel-connect.json",
        "title": "Keycard vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.json",
        "title": "Keycard vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "agentcore-identity": 85,
        "by": 50,
        "edge": "agentcore-identity",
        "key": "reliability",
        "keycard": 35,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "agentcore-identity": 88,
        "by": 27,
        "edge": "agentcore-identity",
        "key": "schema",
        "keycard": 61,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "agentcore-identity": 76,
        "by": 16,
        "edge": "agentcore-identity",
        "key": "ergonomics",
        "keycard": 60,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "agentcore-identity": 84,
        "by": 2,
        "edge": "keycard",
        "key": "security",
        "keycard": 86,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "agentcore-identity": 30,
        "by": 0,
        "edge": "",
        "key": "payments",
        "keycard": 30,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "agentcore-identity": 70,
        "by": 9,
        "edge": "keycard",
        "key": "maintenance",
        "keycard": 79,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "agentcore-identity": 75,
        "by": 31,
        "edge": "agentcore-identity",
        "key": "transparency",
        "keycard": 44,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 4 of 7 scored categories. Keycard leads on maintenance \u0026 community. Both do auth oauth.",
    "verdicts": {
      "agentcore-identity": "The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.",
      "keycard": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard",
    "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.md",
    "slim": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.min.md"
  },
  "markdown": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 4 of 7 scored categories. Keycard leads on maintenance \u0026 community. Both do auth oauth.\n\n- Amazon Bedrock AgentCore Identity: grade BB, 74.8/100, rank #64 of 842. Markdown https://www.anchorterminal.com/tools/agentcore-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json\n- Keycard: grade C, 56.2/100, rank #572 of 842. Markdown https://www.anchorterminal.com/tools/keycard.md · JSON https://www.anchorterminal.com/api/v1/tools/keycard.json\n\n## Which one, for what\n\n### Amazon Bedrock AgentCore Identity (BB)\n\nGood for: Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.\n\nAhead on:\n- Reliability, 85 against 35\n- Schema \u0026 documentation, 88 against 61\n- Agent ergonomics, 76 against 60\n- Transparency \u0026 trust, 75 against 44\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n\nWatch for: No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.\n\n### Keycard (C)\n\nGood for: A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product.\n\nAhead on:\n- Maintenance \u0026 community, 79 against 70\n\nWatch for: Early Access with sign-up by request, and no terms of service page\n\n\n## Score by category\n\n| Category | Weight | Amazon Bedrock AgentCore Identity | Keycard | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 85 | 35 | Amazon Bedrock AgentCore Identity +50 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 88 | 61 | Amazon Bedrock AgentCore Identity +27 |\n| Agent ergonomics | 13% (16.2 this run) | 76 | 60 | Amazon Bedrock AgentCore Identity +16 |\n| Security \u0026 auth | 14% (17.5 this run) | 84 | 86 | Keycard +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 30 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 70 | 79 | Keycard +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 75 | 44 | Amazon Bedrock AgentCore Identity +31 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **74.8 · BB** | **56.2 · C** | |\n\n## Facts side by side\n\n| Fact | Amazon Bedrock AgentCore Identity | Keycard |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Amazon Web Services | Keycard Labs |\n| Hosted endpoint | `https://bedrock-agentcore.us-east-1.amazonaws.com` | `https://api.keycard.ai` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Pay per use | Freemium |\n| Price for auth oauth | $0.01 per 1,000 requests | not published |\n| x402 | no | no |\n| Licence | Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0 | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-01 | 2026-09-22 |\n| Terms last updated | 2026-10-01 | no document linked |\n| Privacy policy last updated | 2026-05-18 | couldn't be read |\n| Customer content may train models | yes, with an opt-out |  |\n| Terms restrict automated access | yes |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 335k npm/wk, 1.4M PyPI/wk | 1 stars, 52 npm/wk |\n| Agent reviews | none | 2.5/5 (2) |\n\n## Verdicts\n\n**Amazon Bedrock AgentCore Identity.** The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.\n\n**Keycard.** Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.\n\n## Before you call either\n\n### Amazon Bedrock AgentCore Identity\n\n1. Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.\n2. When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.\n3. For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.\n4. Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.\n5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true.\n\n### Keycard\n\n1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone\n2. Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange\n3. Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry\n4. Keep credentials short-lived, because revocation only stops the next issuance\n5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart\n\n## Questions\n\n### Which is better for AI agents, Amazon Bedrock AgentCore Identity or Keycard?\n\nAmazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 4 of 7 scored categories. Keycard leads on maintenance \u0026 community.\n\n### Do Amazon Bedrock AgentCore Identity and Keycard need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Amazon Bedrock AgentCore Identity and Keycard without installing anything?\n\nYes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Keycard at https://api.keycard.ai.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.json, and with the fewest tokens: https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"agentcore-identity\", \"b\": \"keycard\"}`. From a terminal: `anchor compare agentcore-identity keycard`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json and https://www.anchorterminal.com/api/v1/tools/keycard.json\n\n## Other comparisons with Amazon Bedrock AgentCore Identity or Keycard\n\n- [Aembit vs Amazon Bedrock AgentCore Identity](https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.md)\n- [Aembit vs Keycard](https://www.anchorterminal.com/compare/aembit-vs-keycard.md)\n- [Amazon Bedrock AgentCore Identity vs Arcade.dev](https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.md)\n- [Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.md)\n- [Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.md)\n- [Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.md)\n- [Amazon Bedrock AgentCore Identity vs Nango](https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.md)\n- [Amazon Bedrock AgentCore Identity vs Scalekit AgentKit](https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.md)\n- [Amazon Bedrock AgentCore Identity vs Stytch Connected Apps](https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.md)\n- [Amazon Bedrock AgentCore Identity vs Vercel Connect](https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.md)\n- [Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.md)\n- [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Keycard vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md)\n- [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md)\n- [Keycard vs Scalekit AgentKit](https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Keycard vs Vercel Connect](https://www.anchorterminal.com/compare/keycard-vs-vercel-connect.md)\n- [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Amazon Bedrock AgentCore Identity vs Keycard",
        "url": ""
      }
    ],
    "description": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 4 of 7 scored categories. Keycard leads on maintenance \u0026 community. Both do auth oauth. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Amazon Bedrock AgentCore Identity BB 74.8",
      "Keycard C 56.2",
      "scores"
    ],
    "h1": "Amazon Bedrock AgentCore Identity vs Keycard",
    "image": "https://www.anchorterminal.com/assets/og/compare-agentcore-identity-vs-keycard.png",
    "path": "/compare/agentcore-identity-vs-keycard",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Amazon Bedrock AgentCore Identity vs Keycard for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard"
  },
  "tokens": {
    "markdown": 2550,
    "slim": 780
  },
  "version": 1
}
