{
  "data": {
    "a": {
      "slug": "arcade",
      "name": "Arcade.dev",
      "vendor": "Arcade.dev",
      "vendorUrl": "https://www.arcade.dev",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "MCP runtime built around per-user authorisation.",
      "url": "https://www.anchorterminal.com/tools/arcade",
      "markdownUrl": "https://www.anchorterminal.com/tools/arcade.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/arcade.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/arcade.json",
      "repo": "https://github.com/ArcadeAI/arcade-mcp",
      "license": "MIT (arcade-mcp framework and SDKs), platform closed",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://api.arcade.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@arcadeai/arcadejs"
        },
        {
          "registry": "pypi",
          "name": "arcadepy"
        },
        {
          "registry": "pypi",
          "name": "arcade-mcp"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST calls take the project key as `Authorization: Bearer $ARCADE_API_KEY` and name the end user with `user_id`. MCP gateways sign end users in with OAuth, either Arcade Auth (project members only) or a User Source pointing at your own OIDC provider. Clients that can't run OAuth can send the API key plus an `Arcade-User-ID` header instead.",
      "pricing": "freemium",
      "pricingNotes": "Free is $0 with 2,000 auth events and 2,000 tool calls a month, no card, community support. Team is a $25 a month platform fee plus $0.10 per auth event and $0.01 per tool call, with next-business-day email support. Enterprise is custom, with annual bundles, deployment in your VPC or air-gapped, SSO, RBAC and a dedicated forward-deployed engineer (https://www.arcade.dev/pricing). The pricing page doesn't define an auth event.",
      "priceSummary": "$25 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1043,
        "npmWeekly": 124858,
        "pypiWeekly": 70222,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.arcade.dev",
      "llmsTxt": "https://docs.arcade.dev/llms.txt",
      "openapi": "https://api.arcade.dev/v1/swagger",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.audit",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "mcp",
        "llms-txt",
        "openapi",
        "oauth",
        "python",
        "typescript",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-25",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67,
        "grade": "B",
        "agentReady": false,
        "rank": 147,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 79,
          "maintenance": 74,
          "payments": 40,
          "reliability": 63,
          "schema": 82,
          "security": 71,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -2,
        "negativeNotes": [
          "2025-12-02, CVE-2025-66454 (GHSA-g2jx-37x6-6438, CVSS 6.5). The HTTP worker in arcade-mcp shipped a hardcoded default worker secret, so anyone could forge a token and list or call every tool on a self-hosted worker set up by the official guide. Fixed in 1.9.1 and disclosed in public, so we deduct 2 of a possible 15 (https://github.com/ArcadeAI/arcade-mcp/security/advisories/GHSA-g2jx-37x6-6438)"
        ],
        "verdict": "Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.",
        "strengths": [
          "Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token",
          "33 built-in auth providers plus generic OAuth 2.0, and hosted MCP gateways that sign users in through your own OIDC provider",
          "OpenAPI 3.0 file with 39 paths, llms.txt and a typed tool error hierarchy with retry hints",
          "Per-call prices in public, $0.01 a tool call and $0.10 an auth event, with 2,000 of each free and no card",
          "Valid security.txt, a SOC 2 Type 2 report and a CVE fixed through a public advisory"
        ],
        "weaknesses": [
          "The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise",
          "Tool inputs and results are training data for up to 5 years unless the organisation opts out",
          "No published rate limits for the authorise or execute calls, and no 429 in the OpenAPI file",
          "The public changelog's latest entry is 26 July 2026 and arcadepy hasn't been released since 6 November 2025",
          "Hosting in the United States only outside Enterprise"
        ],
        "agentNotes": [
          "Call `POST /v1/tools/authorize` first and send the user the returned URL when the status isn't completed",
          "Pass a stable user ID from your own database as user_id, never a shared value",
          "Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again",
          "Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project",
          "Revoke a user's access with `DELETE /v1/admin/user_connections/{id}`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67
          }
        ],
        "editorialScores": {
          "ergonomics": 79,
          "maintenance": 74,
          "payments": 40,
          "reliability": 63,
          "schema": 82,
          "security": 71,
          "transparency": 47
        },
        "provenanceScore": 96
      },
      "connect": {
        "install": "npm install @arcadeai/arcadejs",
        "http": "curl -X POST https://api.arcade.dev/v1/tools/authorize -H \"Authorization: Bearer $ARCADE_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"tool_name\":\"Gmail.ListEmails\",\"user_id\":\"user-123\"}'",
        "claudeCode": "claude mcp add --transport http arcade https://api.arcade.dev/mcp/\u003cyour-gateway-slug\u003e",
        "config": {
          "mcpServers": {
            "arcade": {
              "url": "https://api.arcade.dev/mcp/\u003cyour-gateway-slug\u003e"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/arcade"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan platform fee",
          "unit": "month",
          "usd": 25,
          "note": "Usage billed on top"
        },
        {
          "item": "Tool call on Team",
          "unit": "call",
          "usd": 0.01,
          "note": "After the included allowance. Auth events are $0.10 each"
        }
      ],
      "provenance": {
        "legalEntity": "Arcade AI, Inc.",
        "domain": "arcade.dev",
        "domainRegistered": "2019-03-26",
        "endpointOnVendorDomain": true,
        "terms": "https://www.arcade.dev/terms-of-service",
        "privacy": "https://www.arcade.dev/privacy-policy",
        "statusPage": "https://status.arcade.dev",
        "changelog": "https://docs.arcade.dev/en/references/changelog",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "notes": [
          "The terms (effective 15 July 2025) name Arcade AI, Inc. and California law."
        ],
        "score": 96
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/arcade.json",
      "live": {
        "slug": "arcade",
        "probe": {
          "target": "https://api.arcade.dev",
          "method": "get",
          "lastAt": "2026-10-04T23:48:04.273774371Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 582,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 600,
          "p95ms24h": 921,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.arcade.dev",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:49:05.979745844Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@arcadeai/arcadejs",
            "version": "2.4.1",
            "seenAt": "2026-10-04T16:20:45.579808808Z"
          },
          {
            "registry": "pypi",
            "name": "arcade-mcp",
            "version": "1.16.1",
            "released": "2026-09-25",
            "seenAt": "2026-10-04T16:20:46.731244096Z"
          },
          {
            "registry": "pypi",
            "name": "arcadepy",
            "version": "1.10.0",
            "released": "2025-11-06",
            "seenAt": "2026-10-04T16:20:46.538925772Z"
          }
        ],
        "githubStars": 1044,
        "npmWeekly": 147047,
        "pypiWeekly": 89070,
        "securityTxt": {
          "url": "https://arcade.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-07-20T00:00:00Z",
          "checkedAt": "2026-10-04T15:15:42.588411925Z"
        },
        "llmsTxt": {
          "url": "https://docs.arcade.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:15.279748511Z"
        },
        "domain": {
          "domain": "arcade.dev",
          "registered": "2019-03-26",
          "source": "https://pubapi.registry.google/rdap/domain/arcade.dev",
          "checkedAt": "2026-10-04T13:09:09.815000281Z"
        },
        "pages": [
          {
            "url": "https://docs.arcade.dev/en/references/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:12.967090689Z",
            "changedAt": "2026-10-03T15:31:20.862139392Z",
            "fingerprint": "fed6349730bd"
          },
          {
            "url": "https://www.arcade.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:49:11.688685765Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0965f63267b5"
          },
          {
            "url": "https://www.arcade.dev/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:49:13.767168196Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "03308f7a2c1b"
          },
          {
            "url": "https://www.arcade.dev/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:49:15.77318424Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "afaf24fae3e3"
          }
        ],
        "updatedAt": "2026-10-04T23:49:05.979745844Z"
      }
    },
    "b": {
      "slug": "descope-agentic-identity",
      "name": "Descope Agentic Identity Hub",
      "vendor": "Descope",
      "vendorUrl": "https://www.descope.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Descope's identity and access tools for AI agents, built on its customer identity platform.",
      "url": "https://www.anchorterminal.com/tools/descope-agentic-identity",
      "markdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json",
      "repo": "https://github.com/descope/node-sdk",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.descope.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@descope/node-sdk"
        },
        {
          "registry": "npm",
          "name": "@descope/agent-auth"
        },
        {
          "registry": "pypi",
          "name": "descope-agent-auth"
        },
        {
          "registry": "npm",
          "name": "@descope/mcp-express"
        },
        {
          "registry": "pypi",
          "name": "descope"
        }
      ],
      "auth": "mixed",
      "authNotes": "Management calls take `Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY`. An agent can instead sign in as its own OAuth client (client credentials, device code, CIBA or RFC 7523 JWT bearer against /oauth2/v1/token) or present a user's Descope access token in the same header, and Policies then limit which tokens it can fetch. A management key bypasses Policies, and the Agent Auth SDK makes you opt in to use one. Inbound Apps use the shared endpoints `/oauth2/v1/apps/authorize` and `/oauth2/v1/apps/token` with PKCE for public clients.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever is $0 with 7,500 monthly active users, 10 tenants, 3 SSO connections, 10,000 M2M exchanges, 2,000 MACs and 2,000 MATKs, no card. Pro starts at $249 a month billed annually with 10,000 MAU ($0.05 each after), 35 tenants, 5 SSO connections, 50,000 M2M exchanges ($2 per 1,000 after), 5,000 MACs and 5,000 MATKs ($0.05 each after). Growth starts at $799 a month billed annually with 25,000 MAU, 100 tenants, 10 SSO connections, 100,000 M2M exchanges, 10,000 MACs and 10,000 MATKs. Enterprise is custom. A MAC (monthly active consent) is counted when a unique user consents to any scope for a resource at least once in a month, and covers Inbound Apps and MCP auth. A MATK (monthly active token) is any instance where a token is fetched and used, and covers Outbound Apps and Connections (https://www.descope.com/pricing).",
      "priceSummary": "$249 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 67,
        "npmWeekly": 353532,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.descope.com/agentic-identity-hub",
      "llmsTxt": "https://docs.descope.com/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit",
        "hitl.approve"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "llms-txt",
        "typescript",
        "python",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 79.2,
        "grade": "A",
        "agentReady": true,
        "rank": 10,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 80,
          "maintenance": 76,
          "payments": 40,
          "reliability": 100,
          "schema": 82,
          "security": 86,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.",
        "strengths": [
          "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion",
          "Descope as the OAuth authorisation server for your APIs and MCP servers, with DCR, CIBA and token exchange",
          "Policies decide which tokens an agent identity can obtain, evaluated at issuance and exchange",
          "Per-endpoint rate limits, 429 with Retry-After, and an SLA of 99.99 per cent on Pro",
          "Free Forever tier with 2,000 consents and 2,000 token fetches a month, no card"
        ],
        "weaknesses": [
          "No tool catalogue, so you write every provider call yourself",
          "The Agent Auth SDK is 0.1.0 with 18 open pull requests and no commit since 2 July 2026",
          "The docs don't say how vaulted tokens are encrypted",
          "No security.txt and no deprecation policy we could find",
          "Paid plans are billed annually, from $249 a month"
        ],
        "agentNotes": [
          "Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key",
          "Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL",
          "Back off for the full window on a 429, 60 seconds for most management endpoints",
          "Ask for a tenant token, not a user token, for organisation-wide API keys",
          "Budget monthly active tokens, since every token fetched and used counts once a month"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.1,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 79.2
          }
        ],
        "editorialScores": {
          "ergonomics": 80,
          "maintenance": 76,
          "payments": 40,
          "reliability": 100,
          "schema": 82,
          "security": 86,
          "transparency": 49
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install @descope/node-sdk",
        "http": "curl -X POST https://api.descope.com/v1/mgmt/outbound/app/user/token/latest \\\n  -H \"Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"appId\":\"github\",\"userId\":\"user-123\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/descope-agentic-identity"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 249,
          "note": "Starting price, billed annually"
        },
        {
          "item": "Monthly active token (MATK) above the allowance",
          "unit": "call",
          "usd": 0.05,
          "note": "A token fetched and used, counted once a month. Pro and Growth"
        },
        {
          "item": "Monthly active consent (MAC) above the allowance",
          "unit": "account-month",
          "usd": 0.05,
          "note": "A unique user consenting to a resource at least once in a month. Pro and Growth"
        }
      ],
      "provenance": {
        "legalEntity": "Descope, Inc.",
        "domain": "descope.com",
        "domainRegistered": "2016-04-13",
        "endpointOnVendorDomain": true,
        "terms": "https://www.descope.com/legal/terms",
        "privacy": "https://www.descope.com/legal/privacy",
        "statusPage": "https://descopestatus.com",
        "changelog": "https://ideas.descope.works/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "The terms (updated 24 February 2026) contract with Descope, Inc. for US and Canadian customers, Descope Technologies Israel (2022) Ltd. for Israel and Descope Technologies UK (2025) Ltd. elsewhere, under Delaware law.",
          "/.well-known/security.txt returned 404 on 2026-09-30. A vulnerability disclosure policy is linked from descope.com/security-compliance.",
          "The status page is an Instatus page at descopestatus.com.",
          "The changelog lives on the ideas.descope.works portal, off the main domain, and needs JavaScript to render."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.json",
      "live": {
        "slug": "descope-agentic-identity",
        "probe": {
          "target": "https://api.descope.com",
          "method": "get",
          "lastAt": "2026-10-04T23:48:07.457844964Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 219,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 124,
          "p95ms24h": 292,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "vendorStatus": {
          "page": "https://descopestatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:39:56.414035779Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "descope/node-sdk",
            "version": "v2.17.0",
            "released": "2026-09-07",
            "seenAt": "2026-10-04T16:25:34.432882503Z"
          },
          {
            "registry": "npm",
            "name": "@descope/mcp-express",
            "version": "1.6.0",
            "seenAt": "2026-10-04T16:25:32.533673136Z"
          },
          {
            "registry": "npm",
            "name": "@descope/node-sdk",
            "version": "2.17.0",
            "seenAt": "2026-10-04T16:25:30.077963378Z"
          },
          {
            "registry": "pypi",
            "name": "descope",
            "version": "2.14.0",
            "released": "2026-09-07",
            "seenAt": "2026-10-04T16:25:34.348420573Z"
          }
        ],
        "githubStars": 68,
        "npmWeekly": 347658,
        "securityTxt": {
          "url": "https://descope.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:50.5505058Z"
        },
        "llmsTxt": {
          "url": "https://docs.descope.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:30.527628191Z"
        },
        "domain": {
          "domain": "descope.com",
          "registered": "2016-04-13",
          "source": "https://rdap.verisign.com/com/v1/domain/descope.com",
          "checkedAt": "2026-10-04T13:09:53.916089274Z"
        },
        "pages": [
          {
            "url": "https://ideas.descope.works/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:04.44252976Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "df9dfc56ddd7"
          },
          {
            "url": "https://www.descope.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:06.059286057Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a45e89c271ce"
          },
          {
            "url": "https://www.descope.com/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:01.803096328Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b2b659c6dcc"
          },
          {
            "url": "https://www.descope.com/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:04.020978892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d6f39b94f5db"
          }
        ],
        "updatedAt": "2026-10-04T23:48:07.457844964Z"
      }
    },
    "summary": "Descope Agentic Identity Hub has a score of 79.2 (A) against Arcade.dev's 67 (B). Both do auth oauth. The largest gap is reliability, 37 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity",
    "json": "https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.md",
    "slim": "https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.min.md"
  },
  "markdown": "Descope Agentic Identity Hub has a score of 79.2 (A) against Arcade.dev's 67 (B). Both do auth oauth. The largest gap is reliability, 37 points.\n\n- Arcade.dev: grade B, 67/100, rank #147 of 452. Markdown https://www.anchorterminal.com/tools/arcade.md · JSON https://www.anchorterminal.com/api/v1/tools/arcade.json\n- Descope Agentic Identity Hub: grade A, 79.2/100, rank #10 of 452. Markdown https://www.anchorterminal.com/tools/descope-agentic-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json\n\n## Which one, for what\n\nPick Arcade.dev for nothing in particular (no category where it leads by five points or more).\n\nPick Descope Agentic Identity Hub for reliability (+37), security \u0026 auth (+15).\n\n## Score by category\n\n| Category | Weight | Arcade.dev | Descope Agentic Identity Hub | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 63 | 100 | Descope Agentic Identity Hub +37 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 82 | even |\n| Agent ergonomics | 13% (16.2 this run) | 79 | 80 | Descope Agentic Identity Hub +1 |\n| Security \u0026 auth | 14% (17.5 this run) | 71 | 86 | Descope Agentic Identity Hub +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 40 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 76 | Descope Agentic Identity Hub +2 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 70 | Arcade.dev +2 |\n| Negative events | ≤15 | -2 | 0 | |\n| **Total** | | **67 · B** | **79.2 · A** | |\n\n## Facts side by side\n\n| Fact | Arcade.dev | Descope Agentic Identity Hub |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Arcade.dev | Descope |\n| Hosted endpoint | `https://api.arcade.dev` | `https://api.descope.com` |\n| Transports | HTTP, Streamable HTTP, stdio | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (arcade-mcp framework and SDKs), platform closed | MIT (SDKs), platform closed |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-25 | 2026-09-07 |\n| Popularity | 1k stars, 125k npm/wk, 70k PyPI/wk | 67 stars, 354k npm/wk |\n| Agent reviews | 2.5/5 (2) | 3.1/5 (8) |\n\n## Verdicts\n\n**Arcade.dev.** Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.\n\n**Descope Agentic Identity Hub.** Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.\n\n## Before you call either\n\n### Arcade.dev\n\n1. Call `POST /v1/tools/authorize` first and send the user the returned URL when the status isn't completed\n2. Pass a stable user ID from your own database as user_id, never a shared value\n3. Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again\n4. Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project\n5. Revoke a user's access with `DELETE /v1/admin/user_connections/{id}`\n\n### Descope Agentic Identity Hub\n\n1. Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key\n2. Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL\n3. Back off for the full window on a 429, 60 seconds for most management endpoints\n4. Ask for a tenant token, not a user token, for organisation-wide API keys\n5. Budget monthly active tokens, since every token fetched and used counts once a month\n\n## Other comparisons with Arcade.dev or Descope Agentic Identity Hub\n\n- [Arcade.dev vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents.md)\n- [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md)\n- [Arcade.dev vs Nango](https://www.anchorterminal.com/compare/arcade-vs-nango.md)\n- [Arcade.dev vs Scalekit AgentKit](https://www.anchorterminal.com/compare/arcade-vs-scalekit-agentkit.md)\n- [Arcade.dev vs Stytch Connected Apps](https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps.md)\n- [Arcade.dev vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.md)\n- [Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Nango](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.md)\n- [Descope Agentic Identity Hub vs Scalekit AgentKit](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit.md)\n- [Descope Agentic Identity Hub vs Stytch Connected Apps](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.md)\n- [Descope Agentic Identity Hub vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Arcade.dev vs Descope Agentic Identity Hub",
        "url": ""
      }
    ],
    "description": "Descope Agentic Identity Hub has a score of 79.2 (A) against Arcade.dev's 67 (B). Both do auth oauth. The largest gap is reliability, 37 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Arcade.dev B 67",
      "Descope Agentic Identity Hub A 79.2",
      "scores"
    ],
    "h1": "Arcade.dev vs Descope Agentic Identity Hub",
    "image": "https://www.anchorterminal.com/assets/og/compare-arcade-vs-descope-agentic-identity.png",
    "path": "/compare/arcade-vs-descope-agentic-identity",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Arcade.dev vs Descope Agentic Identity Hub for AI agents",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity"
  },
  "tokens": {
    "markdown": 1600,
    "slim": 330
  },
  "version": 1
}
