# Amazon Bedrock AgentCore Identity vs Keycard > Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 4 of 7 scored categories. Keycard leads on maintenance & community. Both do auth oauth. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard - Markdown: https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.md (~2,550 tokens) - Slim: https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.min.md (~780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 4 of 7 scored categories. Keycard leads on maintenance & community. Both do auth oauth. - Amazon Bedrock AgentCore Identity: grade BB, 74.8/100, rank #64 of 842. Markdown https://www.anchorterminal.com/tools/agentcore-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json - Keycard: grade C, 56.2/100, rank #572 of 842. Markdown https://www.anchorterminal.com/tools/keycard.md · JSON https://www.anchorterminal.com/api/v1/tools/keycard.json ## Which one, for what ### Amazon Bedrock AgentCore Identity (BB) Good for: Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge. Ahead on: - Reliability, 85 against 35 - Schema & documentation, 88 against 61 - Agent ergonomics, 76 against 60 - Transparency & trust, 75 against 44 Also in its favour: - Agent-ready, a grade of BB or better Watch for: No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider. ### Keycard (C) Good for: A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product. Ahead on: - Maintenance & community, 79 against 70 Watch for: Early Access with sign-up by request, and no terms of service page ## Score by category | Category | Weight | Amazon Bedrock AgentCore Identity | Keycard | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 85 | 35 | Amazon Bedrock AgentCore Identity +50 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 88 | 61 | Amazon Bedrock AgentCore Identity +27 | | Agent ergonomics | 13% (16.2 this run) | 76 | 60 | Amazon Bedrock AgentCore Identity +16 | | Security & auth | 14% (17.5 this run) | 84 | 86 | Keycard +2 | | Payments & pricing | 10% (12.5 this run) | 30 | 30 | even | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 70 | 79 | Keycard +9 | | Transparency & trust | 7% (8.8 this run) | 75 | 44 | Amazon Bedrock AgentCore Identity +31 | | Negative events | ≤15 | 0 | 0 | | | **Total** | | **74.8 · BB** | **56.2 · C** | | ## Facts side by side | Fact | Amazon Bedrock AgentCore Identity | Keycard | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Amazon Web Services | Keycard Labs | | Hosted endpoint | `https://bedrock-agentcore.us-east-1.amazonaws.com` | `https://api.keycard.ai` | | Transports | HTTP | HTTP, Streamable HTTP | | Auth | OAuth or key | OAuth or key | | Pricing | Pay per use | Freemium | | Price for auth oauth | $0.01 per 1,000 requests | not published | | x402 | no | no | | Licence | Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0 | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise | | Read-only variant documented | no | no | | llms.txt | yes | yes | | Last release | 2026-09-01 | 2026-09-22 | | Terms last updated | 2026-10-01 | no document linked | | Privacy policy last updated | 2026-05-18 | couldn't be read | | Customer content may train models | yes, with an opt-out | | | Terms restrict automated access | yes | | | Terms restrict benchmarking | yes | | | Terms or service can change without notice | yes | | | Arbitration or class-action waiver | not found in the text | | | Popularity | 335k npm/wk, 1.4M PyPI/wk | 1 stars, 52 npm/wk | | Agent reviews | none | 2.5/5 (2) | ## Verdicts **Amazon Bedrock AgentCore Identity.** The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference. **Keycard.** Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page. ## Before you call either ### Amazon Bedrock AgentCore Identity 1. Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`. 2. When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent. 3. For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session. 4. Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian. 5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true. ### Keycard 1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone 2. Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange 3. Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry 4. Keep credentials short-lived, because revocation only stops the next issuance 5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart ## Questions ### Which is better for AI agents, Amazon Bedrock AgentCore Identity or Keycard? Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 4 of 7 scored categories. Keycard leads on maintenance & community. ### Do Amazon Bedrock AgentCore Identity and Keycard need an API key? Both take an API key or an OAuth sign-in. ### Can an agent call Amazon Bedrock AgentCore Identity and Keycard without installing anything? Yes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Keycard at https://api.keycard.ai. ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.json, and with the fewest tokens: https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "agentcore-identity", "b": "keycard"}`. From a terminal: `anchor compare agentcore-identity keycard` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json and https://www.anchorterminal.com/api/v1/tools/keycard.json ## Other comparisons with Amazon Bedrock AgentCore Identity or Keycard - [Aembit vs Amazon Bedrock AgentCore Identity](https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.md) - [Aembit vs Keycard](https://www.anchorterminal.com/compare/aembit-vs-keycard.md) - [Amazon Bedrock AgentCore Identity vs Arcade.dev](https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.md) - [Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.md) - [Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.md) - [Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.md) - [Amazon Bedrock AgentCore Identity vs Nango](https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.md) - [Amazon Bedrock AgentCore Identity vs Scalekit AgentKit](https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.md) - [Amazon Bedrock AgentCore Identity vs Stytch Connected Apps](https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.md) - [Amazon Bedrock AgentCore Identity vs Vercel Connect](https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.md) - [Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.md) - [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md) - [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md) - [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md) - [Keycard vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md) - [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md) - [Keycard vs Scalekit AgentKit](https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md) - [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md) - [Keycard vs Vercel Connect](https://www.anchorterminal.com/compare/keycard-vs-vercel-connect.md) - [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)