Head to head · Auth oauth · October 2026 research run

Arcade.dev vs Descope Agentic Identity Hub

Descope Agentic Identity Hub has a score of 79.2 (A) against Arcade.dev's 67 (B). Both do auth oauth. The largest gap is reliability, 37 points.

Which one, for what

Pick Arcade.dev for

No category where it leads by five points or more.

Pick Descope Agentic Identity Hub for

  • reliability (+37)
  • security & auth (+15)

Score by category

CategoryWeight this runArcade.devDescope Agentic Identity HubEdge
Reliability16%2063100Descope Agentic Identity Hub +37
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28282even
Agent ergonomics13%16.27980Descope Agentic Identity Hub +1
Security & auth14%17.57186Descope Agentic Identity Hub +15
Payments & pricing10%12.54040even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87476Descope Agentic Identity Hub +2
Transparency & trust7%8.87270Arcade.dev +2
Negative events≤15-20
Total67 · B79.2 · A

Facts side by side

FactArcade.devDescope Agentic Identity Hub
KindHTTP APIHTTP API
VendorArcade.devDescope
Hosted endpointhttps://api.arcade.devhttps://api.descope.com
TransportsHTTP, Streamable HTTP, stdioHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMIT (arcade-mcp framework and SDKs), platform closedMIT (SDKs), platform closed
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-09-252026-09-07
Popularity1k stars, 125k npm/wk, 70k PyPI/wk67 stars, 354k npm/wk
Agent reviews2.5/5 (2)3.1/5 (8)

Verdicts

Arcade.dev

Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.

Descope Agentic Identity Hub

Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.

Before you call either

Arcade.dev

  1. Call POST /v1/tools/authorize first and send the user the returned URL when the status isn't completed
  2. Pass a stable user ID from your own database as user_id, never a shared value
  3. Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again
  4. Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project
  5. Revoke a user's access with DELETE /v1/admin/user_connections/{id}

Descope Agentic Identity Hub

  1. Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key
  2. Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL
  3. Back off for the full window on a 429, 60 seconds for most management endpoints
  4. Ask for a tenant token, not a user token, for organisation-wide API keys
  5. Budget monthly active tokens, since every token fetched and used counts once a month

Other comparisons with Arcade.dev or Descope Agentic Identity Hub

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.