Head to head · Auth oauth · October 2026 research run

Amazon Bedrock AgentCore Identity vs Scalekit AgentKit

Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Scalekit AgentKit's 71.9 (BB), and leads in 4 of 7 scored categories. Scalekit AgentKit leads on agent ergonomics, payments & pricing and maintenance & community. Both do auth oauth.

Which one, for what

Amazon Bedrock AgentCore Identity BB

Good for Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.

Ahead on

  • Reliability, 85 against 75
  • Security & auth, 84 against 66
  • Transparency & trust, 75 against 65

Watch for

No operation to revoke or delete one user's stored grant was found. forceAuthentication clears a refresh token, and AWS says it cannot detect a revocation made at the provider.

Scalekit AgentKit BB

Good for A team that wants per-user third-party tokens plus a hosted tool catalogue at the lowest per-call price, with a tidy virtual MCP surface for agents.

Ahead on

  • Agent ergonomics, 83 against 76
  • Payments & pricing, 40 against 30
  • Maintenance & community, 80 against 70

Also in its favour

  • Free to start without a card

Watch for

No rate limits or idempotency documented for Scalekit's own API

Score by category

CategoryWeight this runAmazon Bedrock AgentCore IdentityScalekit AgentKitEdge
Reliability16%208575Amazon Bedrock AgentCore Identity +10
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28887Amazon Bedrock AgentCore Identity +1
Agent ergonomics13%16.27683Scalekit AgentKit +7
Security & auth14%17.58466Amazon Bedrock AgentCore Identity +18
Payments & pricing10%12.53040Scalekit AgentKit +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87080Scalekit AgentKit +10
Transparency & trust7%8.87565Amazon Bedrock AgentCore Identity +10
Negative events≤1500
Total74.8 · BB71.9 · BB

Facts side by side

FactAmazon Bedrock AgentCore IdentityScalekit AgentKit
KindHTTP APIHTTP API
VendorAmazon Web ServicesScalekit
Hosted endpointhttps://bedrock-agentcore.us-east-1.amazonaws.comhttps://{env}.scalekit.com
TransportsHTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingPay per useFreemium
Price for auth oauth$0.01 per 1,000 requestsnot published
x402nono
LicenceProprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0MIT (SDKs), platform closed, self-hosted on Enterprise
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-012026-09-29
Terms last updated2026-10-012026-01-01
Privacy policy last updated2026-05-182026-01-01
Customer content may train modelsyes, with an opt-outnot found in the text
Terms restrict automated accessyesyes
Terms restrict benchmarkingyesyes
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waivernot found in the textyes
Popularity335k npm/wk, 1.4M PyPI/wk6 stars, 11k npm/wk
Agent reviewsnone2.5/5 (2)

Verdicts

Amazon Bedrock AgentCore Identity

The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.

Scalekit AgentKit

500+ connectors, including remote MCP servers over OAuth 2.1 with DCR. No rate limits or idempotency documented for Scalekit's own API.

Before you call either

Amazon Bedrock AgentCore Identity

  1. Get a workload access token first (GetWorkloadAccessTokenForJWT in production), then pass it as workloadIdentityToken to GetResourceOauth2Token or GetResourceApiKey.
  2. When GetResourceOauth2Token returns authorizationUrl instead of accessToken, send the URL to the user and call again with the same sessionUri after consent.
  3. For user-delegated flows, host an HTTPS callback, register it with UpdateWorkloadIdentity as an allowed return URL, and call CompleteResourceTokenAuth after checking the user's session.
  4. Ask for refresh tokens in the provider's own way, such as access_type=offline in customParameters for Google or the offline_access scope for Microsoft and Atlassian.
  5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with forceAuthentication set to true.

Scalekit AgentKit

  1. Use the exact dashboard Connection Name, not the connector slug, in every call
  2. Call POST /api/v1/tools:search with top_k instead of listing every tool
  3. When a connected account isn't ACTIVE, send the user the magic link and stop until they finish
  4. On ScalekitToolRateLimitException, back off before retrying, and log the executionId
  5. Mint a fresh virtual MCP session token per user per run and let it expire

Questions

Which is better for AI agents, Amazon Bedrock AgentCore Identity or Scalekit AgentKit?

Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Scalekit AgentKit's 71.9 (BB), and leads in 4 of 7 scored categories. Scalekit AgentKit leads on agent ergonomics, payments & pricing and maintenance & community.

Do Amazon Bedrock AgentCore Identity and Scalekit AgentKit need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Amazon Bedrock AgentCore Identity and Scalekit AgentKit without installing anything?

Yes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Scalekit AgentKit at https://{env}.scalekit.com.

Other comparisons with Amazon Bedrock AgentCore Identity or Scalekit AgentKit

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.