Head to head · Auth oauth · October 2026 research run

Arcade.dev vs Keycard

Arcade.dev has a score of 67 (B) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 28 points.

Which one, for what

Pick Arcade.dev for

  • reliability (+28)
  • schema & documentation (+21)
  • agent ergonomics (+19)
  • payments & pricing (+10)
  • transparency & trust (+27)

Pick Keycard for

  • security & auth (+15)
  • maintenance & community (+5)

Score by category

CategoryWeight this runArcade.devKeycardEdge
Reliability16%206335Arcade.dev +28
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28261Arcade.dev +21
Agent ergonomics13%16.27960Arcade.dev +19
Security & auth14%17.57186Keycard +15
Payments & pricing10%12.54030Arcade.dev +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87479Keycard +5
Transparency & trust7%8.87245Arcade.dev +27
Negative events≤15-20
Total67 · B56.3 · C

Facts side by side

FactArcade.devKeycard
KindHTTP APIHTTP API
VendorArcade.devKeycard Labs
Hosted endpointhttps://api.arcade.devhttps://api.keycard.ai
TransportsHTTP, Streamable HTTP, stdioHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMIT (arcade-mcp framework and SDKs), platform closedMIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-09-252026-09-22
Popularity1k stars, 125k npm/wk, 70k PyPI/wk1 stars, 52 npm/wk
Agent reviews2.5/5 (2)2.5/5 (2)

Verdicts

Arcade.dev

Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.

Keycard

Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.

Before you call either

Arcade.dev

  1. Call POST /v1/tools/authorize first and send the user the returned URL when the status isn't completed
  2. Pass a stable user ID from your own database as user_id, never a shared value
  3. Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again
  4. Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project
  5. Revoke a user's access with DELETE /v1/admin/user_connections/{id}

Keycard

  1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone
  2. Check AccessContext.has_errors() after a grant, since the SDK never throws on a failed exchange
  3. Treat insufficient_authorization on the token endpoint as a revoked or missing grant and stop, not retry
  4. Keep credentials short-lived, because revocation only stops the next issuance
  5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart

Other comparisons with Arcade.dev or Keycard

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.