{
  "data": {
    "a": {
      "slug": "agentcore-identity",
      "name": "Amazon Bedrock AgentCore Identity",
      "vendor": "Amazon Web Services",
      "vendorUrl": "https://aws.amazon.com/bedrock/agentcore/",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Amazon Bedrock AgentCore Identity is an AWS service that gives agents workload identities, stores OAuth tokens and API keys in a token vault, and runs OAuth flows so agents can call third-party services for users or for themselves.",
      "url": "https://www.anchorterminal.com/tools/agentcore-identity",
      "markdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json",
      "repo": "https://github.com/aws/bedrock-agentcore-sdk-python",
      "license": "Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://bedrock-agentcore.us-east-1.amazonaws.com",
      "packages": [
        {
          "registry": "pypi",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "npm",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "npm",
          "name": "@aws-sdk/client-bedrock-agentcore"
        },
        {
          "registry": "pypi",
          "name": "boto3"
        }
      ],
      "auth": "mixed",
      "authNotes": "A person creates an AWS account and an IAM role. Control-plane calls (`bedrock-agentcore-control`) and data-plane calls (`bedrock-agentcore`) are SigV4-signed with IAM credentials, and the data plane also documents an OAuth bearer route (`UnauthorizedException` for an invalid JWT). The agent first gets a workload access token that carries its own identity and the user's, from a JWT (`GetWorkloadAccessTokenForJWT`), a user ID string (`GetWorkloadAccessTokenForUserId`) or neither (`GetWorkloadAccessToken`), then exchanges it for a third-party OAuth token or API key. Each third-party provider needs an OAuth client the owner registers with that provider. AgentCore Runtime and Gateway fetch the workload access token for the agent.",
      "pricing": "usage",
      "pricingNotes": "$0.010 per 1,000 OAuth token or API key requests for non-AWS resources, billed per successful request, with no minimum fee. No additional charge when the service is used through AgentCore Runtime or AgentCore Gateway, which are billed on their own meters. No free tier specific to Identity was found. New AWS accounts get up to $200 of Free Tier credit for up to 6 months, and AWS says most new customers need no payment method at sign-up though it may ask for one (https://aws.amazon.com/bedrock/agentcore/pricing/, https://aws.amazon.com/free/free-tier-faqs/).",
      "priceSummary": "$0.01 / 1k req",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 for paying AWS on the pricing page or in the docs. AgentCore payments is a separate capability for agents paying third-party sellers (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 334717,
        "pypiWeekly": 1421946,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html",
      "llmsTxt": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit",
        "infra.aws"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "usage-priced",
        "oauth",
        "llms-txt",
        "python",
        "typescript",
        "enterprise",
        "sla",
        "soc2",
        "eu"
      ],
      "lastRelease": "2026-09-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.8,
        "grade": "BB",
        "agentReady": true,
        "rank": 64,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 76,
          "maintenance": 70,
          "payments": 30,
          "reliability": 85,
          "schema": 88,
          "security": 84,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.",
        "bestFor": "Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.",
        "strengths": [
          "`GetResourceOauth2Token` covers three flows (USER_FEDERATION, M2M and ON_BEHALF_OF_TOKEN_EXCHANGE) and returns either an access token or an authorisation URL with a session URI.",
          "25 OAuth vendor values in `CreateOauth2CredentialProvider`, 24 built in (Google, GitHub, Slack, Salesforce, Microsoft, Atlassian and others) plus a custom OAuth 2.0 provider.",
          "Quotas are published per operation, 200 requests a second for the three workload access token calls and 20 for each management call, all adjustable.",
          "The token vault is encrypted with an AWS owned KMS key by default or a customer managed key, and IAM policies can name one workload identity and one credential provider.",
          "$0.010 per 1,000 token or API key requests, with no extra charge when used through AgentCore Runtime or Gateway."
        ],
        "weaknesses": [
          "No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.",
          "The consent portal, launched 1 September 2026, attaches to one AgentCore Gateway with JWT inbound auth and cannot use GitHub, Slack, Salesforce, Atlassian or LinkedIn as its sign-in provider.",
          "`GetWorkloadAccessTokenForUserId` takes a user ID string the platform does not verify, so the binding to a user rests on the caller and its IAM policy.",
          "AWS states the service enforces no binding between workload identities and credential providers in one account beyond the IAM policy the owner writes.",
          "No CloudTrail page for AgentCore Identity was found in the developer guide, though Gateway and Agent Registry each have one."
        ],
        "agentNotes": [
          "Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.",
          "When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.",
          "For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.",
          "Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.",
          "Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.8
          }
        ],
        "editorialScores": {
          "ergonomics": 76,
          "maintenance": 70,
          "payments": 30,
          "reliability": 85,
          "schema": 88,
          "security": 84,
          "transparency": 61
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "pip install bedrock-agentcore"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/agentcore-identity"
      },
      "sameCompany": [
        "amazon-nova-embeddings",
        "amazon-bedrock-guardrails",
        "amazon-transcribe",
        "amazon-polly",
        "agentcore-memory",
        "aws-secrets-manager",
        "aws-mcp-servers",
        "amazon-ses",
        "amazon-location",
        "amazon-translate",
        "amazon-ads-api"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "OAuth token or API key requests for non-AWS resources",
          "unit": "1k-requests",
          "usd": 0.01,
          "note": "Per successful request. No charge when used through AgentCore Runtime or Gateway"
        }
      ],
      "provenance": {
        "legalEntity": "Amazon Web Services, Inc.",
        "domain": "amazon.com",
        "domainRegistered": "1994-11-01",
        "domainNote": "The service pages are under aws.amazon.com and the endpoints are on amazonaws.com, an AWS domain.",
        "endpointOnVendorDomain": true,
        "terms": "https://aws.amazon.com/service-terms/",
        "privacy": "https://aws.amazon.com/privacy/",
        "statusPage": "https://health.aws.amazon.com/health/status",
        "changelog": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The AWS Service Terms show Last Updated 1 October 2026. Section 50 covers AI services and section 50.15 covers AgentCore Payments. No section names AgentCore Identity, so the universal terms and section 50 apply.",
          "The Privacy Notice shows Last Updated 18 May 2026 and gives Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210.",
          "security.txt shows Expires 2026-09-24T16:25:03Z, read on 8 October 2026. It points to the AWS vulnerability disclosure programme on HackerOne and the policy at vdp.aws.security.",
          "The status page is drawn by script. We read the per-service feed (status.aws.amazon.com/rss/bedrock-agentcore-us-east-1.rss, no items) and the dashboard's history file.",
          "The domain registration date is carried from our other AWS listings. WHOIS was not reachable from this session.",
          "The release notes are dated by month only, and the RSS feed they mention was not found at doc-history.rss (404)."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/agentcore-identity.json",
      "live": {
        "slug": "agentcore-identity",
        "probe": {
          "target": "https://bedrock-agentcore.us-east-1.amazonaws.com",
          "method": "get",
          "lastAt": "2026-10-09T11:46:20.684653607Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 255,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 255,
          "p95ms24h": 294,
          "samples24h": 44,
          "samples30d": 44,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 44,
              "ok": 44
            }
          ]
        },
        "updatedAt": "2026-10-09T11:46:20.684653607Z"
      }
    },
    "answer": "Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID score within a point of each other on agent readiness, 74.8 (BB) and 74.4 (BB). Microsoft Entra Agent ID leads on reliability and maintenance \u0026 community.",
    "b": {
      "slug": "microsoft-entra-agent-id",
      "name": "Microsoft Entra Agent ID",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph.",
      "url": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json",
      "repo": "https://github.com/AzureAD/microsoft-identity-web",
      "license": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
      "packages": [
        {
          "registry": "nuget",
          "name": "Microsoft.Identity.Web.AgentIdentities"
        }
      ],
      "auth": "oauth",
      "authNotes": "Access starts with a Microsoft Entra tenant and a person holding the Agent ID Developer or Agent ID Administrator role, who creates an agent identity blueprint. The blueprint authenticates to login.microsoftonline.com with a managed identity, a certificate or a client secret (Microsoft advises against secrets in production) and exchanges for a token as one of its agent identities. Agent identities hold no credentials. Three flows exist, which are app-only, on behalf of a signed-in user, and as the agent's own user account. Interactive `/authorize` and public clients aren't supported. Management calls on Microsoft Graph need AgentIdentity.Create.All or AgentIdentity.ReadWrite.All.",
      "pricing": "freemium",
      "pricingNotes": "Microsoft's docs say Agent ID is available to all Microsoft Entra customers, and Entra ID Free comes with any Microsoft cloud subscription. No per-agent price is published. Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15.00 a user a month on yearly billing, or Microsoft 365 E7 at $99.00. Conditional Access for agents also needs Entra P1 or Microsoft 365 E3 alongside Agent 365. No sandbox was found in the Agent ID docs (https://www.microsoft.com/en-us/microsoft-agent-365, checked 2026-10-08).",
      "priceSummary": "$15 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Agent ID docs, the Graph reference or the pricing pages (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 787,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.agent-identity",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "oauth",
        "openapi",
        "dotnet",
        "sidecar",
        "microsoft-graph",
        "mcp",
        "freemium",
        "sla"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 71,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 74
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.",
        "bestFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
        "strengths": [
          "Agent identities can't hold credentials. The blueprint authenticates with a managed identity, certificate or secret and exchanges for the agent's token",
          "Global Administrator and similar roles, and Graph permissions such as Application.ReadWrite.All, are refused for agent identities",
          "Create, list, update, delete and restore are on Microsoft Graph v1.0, with agentIdentity in the public OpenAPI file",
          "Audit and sign-in logs carry an agentType and blueprintId for agent activity",
          "Microsoft.Identity.Web 4.16.0 shipped on 30 September 2026, the eighth tagged release since 9 July"
        ],
        "weaknesses": [
          "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing",
          "Microsoft's docs call hand-written token exchange complex and error-prone and steer developers to a .NET library or a sidecar container",
          "Creating a blueprint, a principal and an identity in quick succession can fail with 400 until the directory replicates",
          "Audit and sign-in logs are kept seven days on Entra ID Free and 30 days on P1 or P2",
          "microsoft.com's security.txt passed its Expires date on 23 September 2026"
        ],
        "agentNotes": [
          "Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token",
          "Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object",
          "Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required",
          "Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page",
          "Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.4
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 63
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "dotnet add package Microsoft.Identity.Web.AgentIdentities",
        "http": "curl -X POST https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity \\\n  -H \"Authorization: Bearer $BLUEPRINT_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"displayName\": \"My Agent Identity\", \"agentIdentityBlueprintId\": \"\u003cblueprint-app-id\u003e\", \"sponsors@odata.bind\": [\"https://graph.microsoft.com/v1.0/users/\u003cid\u003e\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/microsoft-entra-agent-id"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "onedrive-sharepoint",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Microsoft Agent 365",
          "unit": "seat-month",
          "usd": 15,
          "note": "billed yearly, needed for Conditional Access, ID Protection and governance for agents"
        },
        {
          "item": "Microsoft 365 E7 (includes Agent 365)",
          "unit": "seat-month",
          "usd": 99,
          "note": "billed yearly"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://www.microsoft.com/en-us/privacy/privacystatement",
        "statusPage": "https://azure.status.microsoft/en-us/status/history/",
        "changelog": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.",
          "The Microsoft APIs terms of use cover the Microsoft Graph API and other APIs that reach directory data, and were last updated in October 2025. Tenant use of Entra also falls under the customer's Microsoft licensing agreement and the Product Terms, which we didn't read.",
          "The Microsoft privacy statement was last updated in September 2026.",
          "Tokens come from login.microsoftonline.com and management calls go to graph.microsoft.com, both Microsoft domains.",
          "Entra's SLA page sends readers to the Azure status history for incidents that affect Entra ID.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.json",
      "live": {
        "slug": "microsoft-entra-agent-id",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
          "method": "get",
          "lastAt": "2026-10-09T11:46:34.298468406Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 30,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 32,
          "p95ms24h": 69,
          "samples24h": 195,
          "samples30d": 195,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 70,
              "ok": 70
            },
            {
              "date": "2026-10-09",
              "probes": 125,
              "ok": 125
            }
          ]
        },
        "vendorStatus": {
          "page": "https://azure.status.microsoft/en-us/status/history",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:09.711979485Z"
        },
        "pages": [
          {
            "url": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:21:36.290153566Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "bca4f93493d4"
          },
          {
            "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:21:38.182590643Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1a1ee1c20d9a"
          }
        ],
        "updatedAt": "2026-10-09T11:46:34.298468406Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Amazon Web Services",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "https://bedrock-agentcore.us-east-1.amazonaws.com",
        "b": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Pay per use",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "$0.01 per 1,000 requests",
        "b": "not published",
        "name": "Price for auth oauth"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0",
        "b": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-01",
        "b": "2026-09-30",
        "name": "Last release"
      },
      {
        "a": "2026-10-01",
        "b": "2025-10-01",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-18",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes, with an opt-out",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "335k npm/wk, 1.4M PyPI/wk",
        "b": "787 stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID score within a point of each other on agent readiness, 74.8 (BB) and 74.4 (BB). Microsoft Entra Agent ID leads on reliability and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Amazon Bedrock AgentCore Identity or Microsoft Entra Agent ID?"
      },
      {
        "answer": "Amazon Bedrock AgentCore Identity takes an API key or an OAuth sign-in. Microsoft Entra Agent ID uses an OAuth sign-in.",
        "question": "Do Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID need an API key?"
      },
      {
        "answer": "Yes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Microsoft Entra Agent ID at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity.",
        "question": "Can an agent call Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 76 against 71",
          "Payments \u0026 pricing, 30 against 20"
        ],
        "also": null,
        "goodFor": "Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.",
        "slug": "agentcore-identity",
        "watchFor": "No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider."
      },
      {
        "aheadOn": [
          "Reliability, 91 against 85",
          "Maintenance \u0026 community, 80 against 70"
        ],
        "also": null,
        "goodFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
        "slug": "microsoft-entra-agent-id",
        "watchFor": "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.json",
        "title": "Aembit vs Amazon Bedrock AgentCore Identity",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.json",
        "title": "Aembit vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.json",
        "title": "Amazon Bedrock AgentCore Identity vs Arcade.dev",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.json",
        "title": "Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.json",
        "title": "Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.json",
        "title": "Amazon Bedrock AgentCore Identity vs Keycard",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.json",
        "title": "Amazon Bedrock AgentCore Identity vs Nango",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.json",
        "title": "Amazon Bedrock AgentCore Identity vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.json",
        "title": "Amazon Bedrock AgentCore Identity vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.json",
        "title": "Amazon Bedrock AgentCore Identity vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.json",
        "title": "Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.json",
        "title": "Arcade.dev vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.json",
        "title": "Descope Agentic Identity Hub vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.json",
        "title": "Keycard vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.json",
        "title": "Microsoft Entra Agent ID vs Nango",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.json",
        "title": "Microsoft Entra Agent ID vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.json",
        "title": "Microsoft Entra Agent ID vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-vercel-connect.json",
        "title": "Microsoft Entra Agent ID vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.json",
        "title": "Microsoft Entra Agent ID vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "agentcore-identity": 85,
        "by": 6,
        "edge": "microsoft-entra-agent-id",
        "key": "reliability",
        "microsoft-entra-agent-id": 91,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "agentcore-identity": 88,
        "by": 1,
        "edge": "agentcore-identity",
        "key": "schema",
        "microsoft-entra-agent-id": 87,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "agentcore-identity": 76,
        "by": 5,
        "edge": "agentcore-identity",
        "key": "ergonomics",
        "microsoft-entra-agent-id": 71,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "agentcore-identity": 84,
        "by": 1,
        "edge": "agentcore-identity",
        "key": "security",
        "microsoft-entra-agent-id": 83,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "agentcore-identity": 30,
        "by": 10,
        "edge": "agentcore-identity",
        "key": "payments",
        "microsoft-entra-agent-id": 20,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "agentcore-identity": 70,
        "by": 10,
        "edge": "microsoft-entra-agent-id",
        "key": "maintenance",
        "microsoft-entra-agent-id": 80,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "agentcore-identity": 75,
        "by": 1,
        "edge": "agentcore-identity",
        "key": "transparency",
        "microsoft-entra-agent-id": 74,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID score within a point of each other on agent readiness, 74.8 (BB) and 74.4 (BB). Microsoft Entra Agent ID leads on reliability and maintenance \u0026 community. Both do auth oauth.",
    "verdicts": {
      "agentcore-identity": "The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.",
      "microsoft-entra-agent-id": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id",
    "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.md",
    "slim": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.min.md"
  },
  "markdown": "Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID score within a point of each other on agent readiness, 74.8 (BB) and 74.4 (BB). Microsoft Entra Agent ID leads on reliability and maintenance \u0026 community. Both do auth oauth.\n\n- Amazon Bedrock AgentCore Identity: grade BB, 74.8/100, rank #64 of 842. Markdown https://www.anchorterminal.com/tools/agentcore-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json\n- Microsoft Entra Agent ID: grade BB, 74.4/100, rank #71 of 842. Markdown https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json\n\n## Which one, for what\n\n### Amazon Bedrock AgentCore Identity (BB)\n\nGood for: Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.\n\nAhead on:\n- Agent ergonomics, 76 against 71\n- Payments \u0026 pricing, 30 against 20\n\nWatch for: No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.\n\n### Microsoft Entra Agent ID (BB)\n\nGood for: Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.\n\nAhead on:\n- Reliability, 91 against 85\n- Maintenance \u0026 community, 80 against 70\n\nWatch for: Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing\n\n\n## Score by category\n\n| Category | Weight | Amazon Bedrock AgentCore Identity | Microsoft Entra Agent ID | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 85 | 91 | Microsoft Entra Agent ID +6 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 88 | 87 | Amazon Bedrock AgentCore Identity +1 |\n| Agent ergonomics | 13% (16.2 this run) | 76 | 71 | Amazon Bedrock AgentCore Identity +5 |\n| Security \u0026 auth | 14% (17.5 this run) | 84 | 83 | Amazon Bedrock AgentCore Identity +1 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 20 | Amazon Bedrock AgentCore Identity +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 70 | 80 | Microsoft Entra Agent ID +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 75 | 74 | Amazon Bedrock AgentCore Identity +1 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **74.8 · BB** | **74.4 · BB** | |\n\n## Facts side by side\n\n| Fact | Amazon Bedrock AgentCore Identity | Microsoft Entra Agent ID |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Amazon Web Services | Microsoft |\n| Hosted endpoint | `https://bedrock-agentcore.us-east-1.amazonaws.com` | `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth |\n| Pricing | Pay per use | Freemium |\n| Price for auth oauth | $0.01 per 1,000 requests | not published |\n| x402 | no | no |\n| Licence | Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0 | Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-09-01 | 2026-09-30 |\n| Terms last updated | 2026-10-01 | 2025-10-01 |\n| Privacy policy last updated | 2026-05-18 | 2026-09-01 |\n| Customer content may train models | yes, with an opt-out | yes |\n| Terms restrict automated access | yes | yes |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | yes | yes |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 335k npm/wk, 1.4M PyPI/wk | 787 stars |\n\n## Verdicts\n\n**Amazon Bedrock AgentCore Identity.** The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.\n\n**Microsoft Entra Agent ID.** Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.\n\n## Before you call either\n\n### Amazon Bedrock AgentCore Identity\n\n1. Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.\n2. When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.\n3. For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.\n4. Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.\n5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true.\n\n### Microsoft Entra Agent ID\n\n1. Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token\n2. Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object\n3. Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required\n4. Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page\n5. Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it\n\n## Questions\n\n### Which is better for AI agents, Amazon Bedrock AgentCore Identity or Microsoft Entra Agent ID?\n\nAmazon Bedrock AgentCore Identity and Microsoft Entra Agent ID score within a point of each other on agent readiness, 74.8 (BB) and 74.4 (BB). Microsoft Entra Agent ID leads on reliability and maintenance \u0026 community.\n\n### Do Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID need an API key?\n\nAmazon Bedrock AgentCore Identity takes an API key or an OAuth sign-in. Microsoft Entra Agent ID uses an OAuth sign-in.\n\n### Can an agent call Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID without installing anything?\n\nYes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Microsoft Entra Agent ID at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.json, and with the fewest tokens: https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"agentcore-identity\", \"b\": \"microsoft-entra-agent-id\"}`. From a terminal: `anchor compare agentcore-identity microsoft-entra-agent-id`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json and https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json\n\n## Other comparisons with Amazon Bedrock AgentCore Identity or Microsoft Entra Agent ID\n\n- [Aembit vs Amazon Bedrock AgentCore Identity](https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.md)\n- [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md)\n- [Amazon Bedrock AgentCore Identity vs Arcade.dev](https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.md)\n- [Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.md)\n- [Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.md)\n- [Amazon Bedrock AgentCore Identity vs Keycard](https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.md)\n- [Amazon Bedrock AgentCore Identity vs Nango](https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.md)\n- [Amazon Bedrock AgentCore Identity vs Scalekit AgentKit](https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.md)\n- [Amazon Bedrock AgentCore Identity vs Stytch Connected Apps](https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.md)\n- [Amazon Bedrock AgentCore Identity vs Vercel Connect](https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.md)\n- [Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.md)\n- [Arcade.dev vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.md)\n- [Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.md)\n- [Descope Agentic Identity Hub vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md)\n- [Keycard vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md)\n- [Microsoft Entra Agent ID vs Nango](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.md)\n- [Microsoft Entra Agent ID vs Scalekit AgentKit](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.md)\n- [Microsoft Entra Agent ID vs Stytch Connected Apps](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.md)\n- [Microsoft Entra Agent ID vs Vercel Connect](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-vercel-connect.md)\n- [Microsoft Entra Agent ID vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID",
        "url": ""
      }
    ],
    "description": "Amazon Bedrock AgentCore Identity and Microsoft Entra Agent ID score within a point of each other on agent readiness, 74.8 (BB) and 74.4 (BB). Microsoft Entra Agent ID leads on reliability and maintenance \u0026 community. Both do auth oauth. Category scores, facts, verdicts and…",
    "facts": [
      "Amazon Bedrock AgentCore Identity BB 74.8",
      "Microsoft Entra Agent ID BB 74.4",
      "scores"
    ],
    "h1": "Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID",
    "image": "https://www.anchorterminal.com/assets/og/compare-agentcore-identity-vs-microsoft-entra-agent-id.png",
    "path": "/compare/agentcore-identity-vs-microsoft-entra-agent-id",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id"
  },
  "tokens": {
    "markdown": 2850,
    "slim": 730
  },
  "version": 1
}
