{
  "data": {
    "a": {
      "slug": "agentcore-identity",
      "name": "Amazon Bedrock AgentCore Identity",
      "vendor": "Amazon Web Services",
      "vendorUrl": "https://aws.amazon.com/bedrock/agentcore/",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Amazon Bedrock AgentCore Identity is an AWS service that gives agents workload identities, stores OAuth tokens and API keys in a token vault, and runs OAuth flows so agents can call third-party services for users or for themselves.",
      "url": "https://www.anchorterminal.com/tools/agentcore-identity",
      "markdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agentcore-identity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json",
      "repo": "https://github.com/aws/bedrock-agentcore-sdk-python",
      "license": "Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://bedrock-agentcore.us-east-1.amazonaws.com",
      "packages": [
        {
          "registry": "pypi",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "npm",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "npm",
          "name": "@aws-sdk/client-bedrock-agentcore"
        },
        {
          "registry": "pypi",
          "name": "boto3"
        }
      ],
      "auth": "mixed",
      "authNotes": "A person creates an AWS account and an IAM role. Control-plane calls (`bedrock-agentcore-control`) and data-plane calls (`bedrock-agentcore`) are SigV4-signed with IAM credentials, and the data plane also documents an OAuth bearer route (`UnauthorizedException` for an invalid JWT). The agent first gets a workload access token that carries its own identity and the user's, from a JWT (`GetWorkloadAccessTokenForJWT`), a user ID string (`GetWorkloadAccessTokenForUserId`) or neither (`GetWorkloadAccessToken`), then exchanges it for a third-party OAuth token or API key. Each third-party provider needs an OAuth client the owner registers with that provider. AgentCore Runtime and Gateway fetch the workload access token for the agent.",
      "pricing": "usage",
      "pricingNotes": "$0.010 per 1,000 OAuth token or API key requests for non-AWS resources, billed per successful request, with no minimum fee. No additional charge when the service is used through AgentCore Runtime or AgentCore Gateway, which are billed on their own meters. No free tier specific to Identity was found. New AWS accounts get up to $200 of Free Tier credit for up to 6 months, and AWS says most new customers need no payment method at sign-up though it may ask for one (https://aws.amazon.com/bedrock/agentcore/pricing/, https://aws.amazon.com/free/free-tier-faqs/).",
      "priceSummary": "$0.01 / 1k req",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 for paying AWS on the pricing page or in the docs. AgentCore payments is a separate capability for agents paying third-party sellers (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 334717,
        "pypiWeekly": 1421946,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html",
      "llmsTxt": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit",
        "infra.aws"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "usage-priced",
        "oauth",
        "llms-txt",
        "python",
        "typescript",
        "enterprise",
        "sla",
        "soc2",
        "eu"
      ],
      "lastRelease": "2026-09-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.8,
        "grade": "BB",
        "agentReady": true,
        "rank": 64,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 76,
          "maintenance": 70,
          "payments": 30,
          "reliability": 85,
          "schema": 88,
          "security": 84,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.",
        "bestFor": "Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.",
        "strengths": [
          "`GetResourceOauth2Token` covers three flows (USER_FEDERATION, M2M and ON_BEHALF_OF_TOKEN_EXCHANGE) and returns either an access token or an authorisation URL with a session URI.",
          "25 OAuth vendor values in `CreateOauth2CredentialProvider`, 24 built in (Google, GitHub, Slack, Salesforce, Microsoft, Atlassian and others) plus a custom OAuth 2.0 provider.",
          "Quotas are published per operation, 200 requests a second for the three workload access token calls and 20 for each management call, all adjustable.",
          "The token vault is encrypted with an AWS owned KMS key by default or a customer managed key, and IAM policies can name one workload identity and one credential provider.",
          "$0.010 per 1,000 token or API key requests, with no extra charge when used through AgentCore Runtime or Gateway."
        ],
        "weaknesses": [
          "No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.",
          "The consent portal, launched 1 September 2026, attaches to one AgentCore Gateway with JWT inbound auth and cannot use GitHub, Slack, Salesforce, Atlassian or LinkedIn as its sign-in provider.",
          "`GetWorkloadAccessTokenForUserId` takes a user ID string the platform does not verify, so the binding to a user rests on the caller and its IAM policy.",
          "AWS states the service enforces no binding between workload identities and credential providers in one account beyond the IAM policy the owner writes.",
          "No CloudTrail page for AgentCore Identity was found in the developer guide, though Gateway and Agent Registry each have one."
        ],
        "agentNotes": [
          "Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.",
          "When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.",
          "For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.",
          "Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.",
          "Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.8
          }
        ],
        "editorialScores": {
          "ergonomics": 76,
          "maintenance": 70,
          "payments": 30,
          "reliability": 85,
          "schema": 88,
          "security": 84,
          "transparency": 61
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "pip install bedrock-agentcore"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/agentcore-identity"
      },
      "sameCompany": [
        "amazon-nova-embeddings",
        "amazon-bedrock-guardrails",
        "amazon-transcribe",
        "amazon-polly",
        "agentcore-memory",
        "aws-secrets-manager",
        "aws-mcp-servers",
        "amazon-ses",
        "amazon-location",
        "amazon-translate",
        "amazon-ads-api"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "OAuth token or API key requests for non-AWS resources",
          "unit": "1k-requests",
          "usd": 0.01,
          "note": "Per successful request. No charge when used through AgentCore Runtime or Gateway"
        }
      ],
      "provenance": {
        "legalEntity": "Amazon Web Services, Inc.",
        "domain": "amazon.com",
        "domainRegistered": "1994-11-01",
        "domainNote": "The service pages are under aws.amazon.com and the endpoints are on amazonaws.com, an AWS domain.",
        "endpointOnVendorDomain": true,
        "terms": "https://aws.amazon.com/service-terms/",
        "privacy": "https://aws.amazon.com/privacy/",
        "statusPage": "https://health.aws.amazon.com/health/status",
        "changelog": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The AWS Service Terms show Last Updated 1 October 2026. Section 50 covers AI services and section 50.15 covers AgentCore Payments. No section names AgentCore Identity, so the universal terms and section 50 apply.",
          "The Privacy Notice shows Last Updated 18 May 2026 and gives Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210.",
          "security.txt shows Expires 2026-09-24T16:25:03Z, read on 8 October 2026. It points to the AWS vulnerability disclosure programme on HackerOne and the policy at vdp.aws.security.",
          "The status page is drawn by script. We read the per-service feed (status.aws.amazon.com/rss/bedrock-agentcore-us-east-1.rss, no items) and the dashboard's history file.",
          "The domain registration date is carried from our other AWS listings. WHOIS was not reachable from this session.",
          "The release notes are dated by month only, and the RSS feed they mention was not found at doc-history.rss (404)."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/agentcore-identity.json",
      "live": {
        "slug": "agentcore-identity",
        "probe": {
          "target": "https://bedrock-agentcore.us-east-1.amazonaws.com",
          "method": "get",
          "lastAt": "2026-10-09T10:42:34.563053327Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 271,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 259,
          "p95ms24h": 300,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "updatedAt": "2026-10-09T10:42:34.563053327Z"
      }
    },
    "answer": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Vercel Connect's 68.8 (B), and leads in 4 of 7 scored categories. Vercel Connect leads on payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "vercel-connect",
      "name": "Vercel Connect",
      "vendor": "Vercel Inc.",
      "vendorUrl": "https://vercel.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Vercel Connect is a credential broker for apps and agents. Code asks it for a short-lived, scoped token for Slack, GitHub, Microsoft, Linear, Snowflake or any OAuth, API-key or MCP service, as the app or for a user.",
      "url": "https://www.anchorterminal.com/tools/vercel-connect",
      "markdownUrl": "https://www.anchorterminal.com/tools/vercel-connect.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vercel-connect.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vercel-connect.json",
      "repo": "https://github.com/vercel/vercel",
      "license": "Proprietary service under Vercel's Terms of Service and the Vercel Connect product terms. The `@vercel/connect` SDK and the Vercel CLI are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.vercel.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@vercel/connect"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access is self-serve with a Vercel account, on every plan. A deployment calls Connect with its project OIDC token (`VERCEL_OIDC_TOKEN`), which Connect checks against the connector's project links and their environments. Locally, `vercel env pull` writes a development OIDC token that lasts about 12 hours. Outside Vercel, a Vercel access token goes in `vercelToken`, and it can request only the app subject or its own user. Connect then holds the provider side. Vercel registers the OAuth client for managed connectors (Slack, GitHub, Linear, Microsoft, Snowflake, Salesforce), and the customer supplies a client or an API key for the others. End users consent in a browser at a URL from `startAuthorization`.",
      "pricing": "freemium",
      "pricingNotes": "Billed per token request and per trigger. Hobby includes 500 token requests and 1,000 triggers a month at no extra charge, and Vercel's fair use guidelines limit Hobby to non-commercial, personal use. Pro is $3.00 per 1,000 token requests and $0.95 per 1,000 triggers on top of the plan. Enterprise is negotiated. A trigger is counted once per destination, and once per event when no destination is set. The SDK's in-process cache means many provider calls in one invocation cost one token request (https://vercel.com/docs/connect/pricing, checked 2026-10-08).",
      "priceSummary": "$3 / 1k req",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Connect docs, the pricing page or the Connect operations of the OpenAPI document (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 16354,
        "npmWeekly": 738165,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://vercel.com/docs/connect",
      "llmsTxt": "https://vercel.com/llms.txt",
      "openapi": "https://openapi.vercel.sh/",
      "capabilities": [
        "auth.tokens",
        "auth.oauth",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "oidc",
        "openapi",
        "llms-txt",
        "typescript",
        "cli",
        "webhooks",
        "status-page",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.8,
        "grade": "B",
        "agentReady": false,
        "rank": 195,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 81,
          "payments": 40,
          "reliability": 63,
          "schema": 84,
          "security": 83,
          "transparency": 77
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "April 2026. Vercel's security bulletin says an attacker took over an employee's account through a compromised third-party AI tool, reached internal systems and decrypted non-sensitive environment variables of a limited subset of customers. It predates Connect's general availability on 25 August 2026 and is documented with remediation, so 3 of a possible 15 is taken, because Connect now keeps customers' provider refresh tokens on the same platform (https://vercel.com/kb/bulletin/vercel-april-2026-security-incident)."
        ],
        "verdict": "Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript.",
        "bestFor": "Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets.",
        "strengths": [
          "Refresh tokens stay on Vercel's infrastructure. Code receives only short-lived access tokens, as the app or for a named user",
          "A deployment authenticates with its project OIDC token, checked against per-environment project links, so no provider secret sits in environment variables",
          "Public OpenAPI 3.0.3 document covers 13 Connect paths, including `/v1/connect/token/{connector}` and `/v1/connect/authorize/{connector}`",
          "Token requests, completed authorisations and revocations are logged with `tokenId` and `authorizationId`, and can be sent to a drain on Pro and Enterprise",
          "Rate limits are published with numbers, 200 reads and 50 writes a minute per team"
        ],
        "weaknesses": [
          "Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment",
          "Elevated Connect errors for 94 minutes on 10 September 2026, marked major, and again on 18 September, per the status page",
          "Event history is kept 12 hours on Hobby and 3 days on Pro. Connector audit logs and 30 days need Enterprise",
          "Revocation depends on the provider. Without a revocation endpoint the provider credential can work until it expires",
          "The SDK is TypeScript only, and the public repository's copy stops at 2.0.2 while npm has 2.4.1"
        ],
        "agentNotes": [
          "Call `getToken` at request time and don't store the result. The SDK caches up to 100 tokens in process and refreshes them 30 seconds before expiry",
          "Pass `scopes` on every request. Since SDK 1.0.0 an omitted `scopes` defaults to `['*']`, the connector's default scopes",
          "Catch `UserAuthorizationRequiredError`, call `startAuthorization` and send the user to the returned URL. Consent needs a person in a browser",
          "Outside Vercel, pass a Vercel access token as `vercelToken`. It can request only the app subject or its own user, not another user",
          "On a 429 wait one minute for the window to reset. Limits are 200 token requests a minute per team"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.8
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 81,
          "payments": 40,
          "reliability": 63,
          "schema": 84,
          "security": 83,
          "transparency": 55
        },
        "provenanceScore": 99
      },
      "connect": {
        "install": "pnpm add @vercel/connect",
        "http": "curl -X POST https://api.vercel.com/v1/connect/token/slack%2Facme-slack \\\n  -H \"Authorization: Bearer $VERCEL_OIDC_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"subject\":{\"type\":\"app\"},\"scopes\":[\"chat:write\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.tokens",
        "tool": "https://letme.dev/vercel-connect"
      },
      "sameCompany": [
        "vercel-sandbox"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Token request (Pro)",
          "unit": "1k-requests",
          "usd": 3,
          "note": "Hobby includes 500 a month. Enterprise negotiated"
        },
        {
          "item": "Trigger, a forwarded provider webhook (Pro)",
          "unit": "1k-requests",
          "usd": 0.95,
          "note": "Counted per destination. Hobby includes 1,000 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Vercel Inc.",
        "domain": "vercel.com",
        "domainRegistered": "1999-10-04",
        "endpointOnVendorDomain": true,
        "terms": "https://vercel.com/legal/terms",
        "privacy": "https://vercel.com/legal/privacy-policy",
        "statusPage": "https://www.vercel-status.com",
        "changelog": "https://vercel.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service (last updated 1 June 2026) name Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, and California law. The DPA calls Vercel Inc. a Delaware corporation.",
          "Connect also has its own product terms at https://vercel.com/docs/connect/legal. The Terms of Service text we read does not mention Connect by name.",
          "The Privacy Notice (effective 1 June 2026) says it does not apply to personal information Vercel processes as a processor for customers, which the DPA covers. The DPA (effective 31 March 2026) applies to Pro and Enterprise plans.",
          "https://vercel.com/.well-known/security.txt points to HackerOne and responsible.disclosure@vercel.com and expires 2027-09-28.",
          "RDAP gives vercel.com a registration date of 1999-10-04, long before Vercel, so the domain was bought later.",
          "The API answers at api.vercel.com and the OpenAPI document at openapi.vercel.sh."
        ],
        "score": 99
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vercel-connect.json",
      "live": {
        "slug": "vercel-connect",
        "probe": {
          "target": "https://api.vercel.com",
          "method": "get",
          "lastAt": "2026-10-09T10:43:00.826005623Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 550,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 570,
          "p95ms24h": 1136,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.vercel-status.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T10:42:07.466379649Z"
        },
        "updatedAt": "2026-10-09T10:43:00.826005623Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Amazon Web Services",
        "b": "Vercel Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://bedrock-agentcore.us-east-1.amazonaws.com",
        "b": "https://api.vercel.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Pay per use",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "$0.01 per 1,000 requests",
        "b": "not published",
        "name": "Price for auth oauth"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0",
        "b": "Proprietary service under Vercel's Terms of Service and the Vercel Connect product terms. The `@vercel/connect` SDK and the Vercel CLI are Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-01",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "2026-10-01",
        "b": "2026-06-01",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-18",
        "b": "2026-06-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes, with an opt-out",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "335k npm/wk, 1.4M PyPI/wk",
        "b": "16k stars, 738k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Vercel Connect's 68.8 (B), and leads in 4 of 7 scored categories. Vercel Connect leads on payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Amazon Bedrock AgentCore Identity or Vercel Connect?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Amazon Bedrock AgentCore Identity and Vercel Connect need an API key?"
      },
      {
        "answer": "Yes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Vercel Connect at https://api.vercel.com.",
        "question": "Can an agent call Amazon Bedrock AgentCore Identity and Vercel Connect without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 85 against 63"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "No incidents deducted, where Vercel Connect loses 3 points for them"
        ],
        "goodFor": "Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.",
        "slug": "agentcore-identity",
        "watchFor": "No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider."
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 40 against 30",
          "Maintenance \u0026 community, 81 against 70"
        ],
        "also": null,
        "goodFor": "Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets.",
        "slug": "vercel-connect",
        "watchFor": "Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.json",
        "title": "Aembit vs Amazon Bedrock AgentCore Identity",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-vercel-connect.json",
        "title": "Aembit vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.json",
        "title": "Amazon Bedrock AgentCore Identity vs Arcade.dev",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.json",
        "title": "Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.json",
        "title": "Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.json",
        "title": "Amazon Bedrock AgentCore Identity vs Keycard",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.json",
        "title": "Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.json",
        "title": "Amazon Bedrock AgentCore Identity vs Nango",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.json",
        "title": "Amazon Bedrock AgentCore Identity vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.json",
        "title": "Amazon Bedrock AgentCore Identity vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.json",
        "title": "Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-vercel-connect.json",
        "title": "Arcade.dev vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-vercel-connect.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-vercel-connect.json",
        "title": "Descope Agentic Identity Hub vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-vercel-connect.json",
        "title": "Keycard vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-vercel-connect.json",
        "title": "Microsoft Entra Agent ID vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nango-vs-vercel-connect.json",
        "title": "Nango vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/nango-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/scalekit-agentkit-vs-vercel-connect.json",
        "title": "Scalekit AgentKit vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/scalekit-agentkit-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-vercel-connect.json",
        "title": "Stytch Connected Apps vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/vercel-connect-vs-workos-pipes.json",
        "title": "Vercel Connect vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/vercel-connect-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "agentcore-identity": 85,
        "by": 22,
        "edge": "agentcore-identity",
        "key": "reliability",
        "name": "Reliability",
        "vercel-connect": 63,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "agentcore-identity": 88,
        "by": 4,
        "edge": "agentcore-identity",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "vercel-connect": 84,
        "weight": 13
      },
      {
        "agentcore-identity": 76,
        "by": 1,
        "edge": "agentcore-identity",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "vercel-connect": 75,
        "weight": 13
      },
      {
        "agentcore-identity": 84,
        "by": 1,
        "edge": "agentcore-identity",
        "key": "security",
        "name": "Security \u0026 auth",
        "vercel-connect": 83,
        "weight": 14
      },
      {
        "agentcore-identity": 30,
        "by": 10,
        "edge": "vercel-connect",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "vercel-connect": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "agentcore-identity": 70,
        "by": 11,
        "edge": "vercel-connect",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "vercel-connect": 81,
        "weight": 7
      },
      {
        "agentcore-identity": 75,
        "by": 2,
        "edge": "vercel-connect",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "vercel-connect": 77,
        "weight": 7
      }
    ],
    "summary": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Vercel Connect's 68.8 (B), and leads in 4 of 7 scored categories. Vercel Connect leads on payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth.",
    "verdicts": {
      "agentcore-identity": "The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.",
      "vercel-connect": "Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect",
    "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.md",
    "slim": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.min.md"
  },
  "markdown": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Vercel Connect's 68.8 (B), and leads in 4 of 7 scored categories. Vercel Connect leads on payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth.\n\n- Amazon Bedrock AgentCore Identity: grade BB, 74.8/100, rank #64 of 842. Markdown https://www.anchorterminal.com/tools/agentcore-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json\n- Vercel Connect: grade B, 68.8/100, rank #195 of 842. Markdown https://www.anchorterminal.com/tools/vercel-connect.md · JSON https://www.anchorterminal.com/api/v1/tools/vercel-connect.json\n\n## Which one, for what\n\n### Amazon Bedrock AgentCore Identity (BB)\n\nGood for: Agents already built on AWS, above all those on AgentCore Runtime or Gateway, where token retrieval is automatic and free of extra charge.\n\nAhead on:\n- Reliability, 85 against 63\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- No incidents deducted, where Vercel Connect loses 3 points for them\n\nWatch for: No operation to revoke or delete one user's stored grant was found. `forceAuthentication` clears a refresh token, and AWS says it cannot detect a revocation made at the provider.\n\n### Vercel Connect (B)\n\nGood for: Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets.\n\nAhead on:\n- Payments \u0026 pricing, 40 against 30\n- Maintenance \u0026 community, 81 against 70\n\nWatch for: Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment\n\n\n## Score by category\n\n| Category | Weight | Amazon Bedrock AgentCore Identity | Vercel Connect | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 85 | 63 | Amazon Bedrock AgentCore Identity +22 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 88 | 84 | Amazon Bedrock AgentCore Identity +4 |\n| Agent ergonomics | 13% (16.2 this run) | 76 | 75 | Amazon Bedrock AgentCore Identity +1 |\n| Security \u0026 auth | 14% (17.5 this run) | 84 | 83 | Amazon Bedrock AgentCore Identity +1 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 40 | Vercel Connect +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 70 | 81 | Vercel Connect +11 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 75 | 77 | Vercel Connect +2 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **74.8 · BB** | **68.8 · B** | |\n\n## Facts side by side\n\n| Fact | Amazon Bedrock AgentCore Identity | Vercel Connect |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Amazon Web Services | Vercel Inc. |\n| Hosted endpoint | `https://bedrock-agentcore.us-east-1.amazonaws.com` | `https://api.vercel.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Pay per use | Freemium |\n| Price for auth oauth | $0.01 per 1,000 requests | not published |\n| x402 | no | no |\n| Licence | Proprietary service under the AWS Customer Agreement and AWS Service Terms. The AgentCore SDKs for Python and TypeScript are Apache-2.0 | Proprietary service under Vercel's Terms of Service and the Vercel Connect product terms. The `@vercel/connect` SDK and the Vercel CLI are Apache-2.0 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-01 | 2026-10-06 |\n| Terms last updated | 2026-10-01 | 2026-06-01 |\n| Privacy policy last updated | 2026-05-18 | 2026-06-01 |\n| Customer content may train models | yes, with an opt-out | yes, with an opt-out |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 335k npm/wk, 1.4M PyPI/wk | 16k stars, 738k npm/wk |\n\n## Verdicts\n\n**Amazon Bedrock AgentCore Identity.** The service handles user-delegated, machine-to-machine and on-behalf-of token flows through one call, with IAM scoping, KMS encryption and published quotas. It only works inside an AWS account a person creates, the hosted consent portal needs an AgentCore Gateway, and no call to revoke one user's stored grant was found in the API reference.\n\n**Vercel Connect.** Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript.\n\n## Before you call either\n\n### Amazon Bedrock AgentCore Identity\n\n1. Get a workload access token first (`GetWorkloadAccessTokenForJWT` in production), then pass it as `workloadIdentityToken` to `GetResourceOauth2Token` or `GetResourceApiKey`.\n2. When `GetResourceOauth2Token` returns `authorizationUrl` instead of `accessToken`, send the URL to the user and call again with the same `sessionUri` after consent.\n3. For user-delegated flows, host an HTTPS callback, register it with `UpdateWorkloadIdentity` as an allowed return URL, and call `CompleteResourceTokenAuth` after checking the user's session.\n4. Ask for refresh tokens in the provider's own way, such as `access_type=offline` in `customParameters` for Google or the `offline_access` scope for Microsoft and Atlassian.\n5. Treat a returned token as possibly revoked. On a 401 from the resource server, retry with `forceAuthentication` set to true.\n\n### Vercel Connect\n\n1. Call `getToken` at request time and don't store the result. The SDK caches up to 100 tokens in process and refreshes them 30 seconds before expiry\n2. Pass `scopes` on every request. Since SDK 1.0.0 an omitted `scopes` defaults to `['*']`, the connector's default scopes\n3. Catch `UserAuthorizationRequiredError`, call `startAuthorization` and send the user to the returned URL. Consent needs a person in a browser\n4. Outside Vercel, pass a Vercel access token as `vercelToken`. It can request only the app subject or its own user, not another user\n5. On a 429 wait one minute for the window to reset. Limits are 200 token requests a minute per team\n\n## Questions\n\n### Which is better for AI agents, Amazon Bedrock AgentCore Identity or Vercel Connect?\n\nAmazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Vercel Connect's 68.8 (B), and leads in 4 of 7 scored categories. Vercel Connect leads on payments \u0026 pricing and maintenance \u0026 community.\n\n### Do Amazon Bedrock AgentCore Identity and Vercel Connect need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Amazon Bedrock AgentCore Identity and Vercel Connect without installing anything?\n\nYes. Amazon Bedrock AgentCore Identity has a hosted endpoint at https://bedrock-agentcore.us-east-1.amazonaws.com and Vercel Connect at https://api.vercel.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.json, and with the fewest tokens: https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"agentcore-identity\", \"b\": \"vercel-connect\"}`. From a terminal: `anchor compare agentcore-identity vercel-connect`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/agentcore-identity.json and https://www.anchorterminal.com/api/v1/tools/vercel-connect.json\n\n## Other comparisons with Amazon Bedrock AgentCore Identity or Vercel Connect\n\n- [Aembit vs Amazon Bedrock AgentCore Identity](https://www.anchorterminal.com/compare/aembit-vs-agentcore-identity.md)\n- [Aembit vs Vercel Connect](https://www.anchorterminal.com/compare/aembit-vs-vercel-connect.md)\n- [Amazon Bedrock AgentCore Identity vs Arcade.dev](https://www.anchorterminal.com/compare/agentcore-identity-vs-arcade.md)\n- [Amazon Bedrock AgentCore Identity vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/agentcore-identity-vs-auth0-ai-agents.md)\n- [Amazon Bedrock AgentCore Identity vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/agentcore-identity-vs-descope-agentic-identity.md)\n- [Amazon Bedrock AgentCore Identity vs Keycard](https://www.anchorterminal.com/compare/agentcore-identity-vs-keycard.md)\n- [Amazon Bedrock AgentCore Identity vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/agentcore-identity-vs-microsoft-entra-agent-id.md)\n- [Amazon Bedrock AgentCore Identity vs Nango](https://www.anchorterminal.com/compare/agentcore-identity-vs-nango.md)\n- [Amazon Bedrock AgentCore Identity vs Scalekit AgentKit](https://www.anchorterminal.com/compare/agentcore-identity-vs-scalekit-agentkit.md)\n- [Amazon Bedrock AgentCore Identity vs Stytch Connected Apps](https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.md)\n- [Amazon Bedrock AgentCore Identity vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/agentcore-identity-vs-workos-pipes.md)\n- [Arcade.dev vs Vercel Connect](https://www.anchorterminal.com/compare/arcade-vs-vercel-connect.md)\n- [Auth0 for AI Agents (Token Vault) vs Vercel Connect](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-vercel-connect.md)\n- [Descope Agentic Identity Hub vs Vercel Connect](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-vercel-connect.md)\n- [Keycard vs Vercel Connect](https://www.anchorterminal.com/compare/keycard-vs-vercel-connect.md)\n- [Microsoft Entra Agent ID vs Vercel Connect](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-vercel-connect.md)\n- [Nango vs Vercel Connect](https://www.anchorterminal.com/compare/nango-vs-vercel-connect.md)\n- [Scalekit AgentKit vs Vercel Connect](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-vercel-connect.md)\n- [Stytch Connected Apps vs Vercel Connect](https://www.anchorterminal.com/compare/stytch-connected-apps-vs-vercel-connect.md)\n- [Vercel Connect vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/vercel-connect-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Amazon Bedrock AgentCore Identity vs Vercel Connect",
        "url": ""
      }
    ],
    "description": "Amazon Bedrock AgentCore Identity scores 74.8 (BB) on agent readiness against Vercel Connect's 68.8 (B), and leads in 4 of 7 scored categories. Vercel Connect leads on payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth. Category scores, facts, verdicts and agent…",
    "facts": [
      "Amazon Bedrock AgentCore Identity BB 74.8",
      "Vercel Connect B 68.8",
      "scores"
    ],
    "h1": "Amazon Bedrock AgentCore Identity vs Vercel Connect",
    "image": "https://www.anchorterminal.com/assets/og/compare-agentcore-identity-vs-vercel-connect.png",
    "path": "/compare/agentcore-identity-vs-vercel-connect",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Amazon Bedrock AgentCore Identity vs Vercel Connect for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect"
  },
  "tokens": {
    "markdown": 2750,
    "slim": 780
  },
  "version": 1
}
