{
  "data": {
    "a": {
      "slug": "arcade",
      "name": "Arcade.dev",
      "vendor": "Arcade.dev",
      "vendorUrl": "https://www.arcade.dev",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "MCP runtime built around per-user authorisation.",
      "url": "https://www.anchorterminal.com/tools/arcade",
      "markdownUrl": "https://www.anchorterminal.com/tools/arcade.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/arcade.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/arcade.json",
      "repo": "https://github.com/ArcadeAI/arcade-mcp",
      "license": "MIT (arcade-mcp framework and SDKs), platform closed",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://api.arcade.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@arcadeai/arcadejs"
        },
        {
          "registry": "pypi",
          "name": "arcadepy"
        },
        {
          "registry": "pypi",
          "name": "arcade-mcp"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST calls take the project key as `Authorization: Bearer $ARCADE_API_KEY` and name the end user with `user_id`. MCP gateways sign end users in with OAuth, either Arcade Auth (project members only) or a User Source pointing at your own OIDC provider. Clients that can't run OAuth can send the API key plus an `Arcade-User-ID` header instead.",
      "pricing": "freemium",
      "pricingNotes": "Free is $0 with 2,000 auth events and 2,000 tool calls a month, no card, community support. Team is a $25 a month platform fee plus $0.10 per auth event and $0.01 per tool call, with next-business-day email support. Enterprise is custom, with annual bundles, deployment in your VPC or air-gapped, SSO, RBAC and a dedicated forward-deployed engineer (https://www.arcade.dev/pricing). The pricing page doesn't define an auth event.",
      "priceSummary": "$25 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1043,
        "npmWeekly": 124858,
        "pypiWeekly": 70222,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.arcade.dev",
      "llmsTxt": "https://docs.arcade.dev/llms.txt",
      "openapi": "https://api.arcade.dev/v1/swagger",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.audit",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "mcp",
        "llms-txt",
        "openapi",
        "oauth",
        "python",
        "typescript",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-25",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67,
        "grade": "B",
        "agentReady": false,
        "rank": 147,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 79,
          "maintenance": 74,
          "payments": 40,
          "reliability": 63,
          "schema": 82,
          "security": 71,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -2,
        "negativeNotes": [
          "2025-12-02, CVE-2025-66454 (GHSA-g2jx-37x6-6438, CVSS 6.5). The HTTP worker in arcade-mcp shipped a hardcoded default worker secret, so anyone could forge a token and list or call every tool on a self-hosted worker set up by the official guide. Fixed in 1.9.1 and disclosed in public, so we deduct 2 of a possible 15 (https://github.com/ArcadeAI/arcade-mcp/security/advisories/GHSA-g2jx-37x6-6438)"
        ],
        "verdict": "Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.",
        "strengths": [
          "Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token",
          "33 built-in auth providers plus generic OAuth 2.0, and hosted MCP gateways that sign users in through your own OIDC provider",
          "OpenAPI 3.0 file with 39 paths, llms.txt and a typed tool error hierarchy with retry hints",
          "Per-call prices in public, $0.01 a tool call and $0.10 an auth event, with 2,000 of each free and no card",
          "Valid security.txt, a SOC 2 Type 2 report and a CVE fixed through a public advisory"
        ],
        "weaknesses": [
          "The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise",
          "Tool inputs and results are training data for up to 5 years unless the organisation opts out",
          "No published rate limits for the authorise or execute calls, and no 429 in the OpenAPI file",
          "The public changelog's latest entry is 26 July 2026 and arcadepy hasn't been released since 6 November 2025",
          "Hosting in the United States only outside Enterprise"
        ],
        "agentNotes": [
          "Call `POST /v1/tools/authorize` first and send the user the returned URL when the status isn't completed",
          "Pass a stable user ID from your own database as user_id, never a shared value",
          "Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again",
          "Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project",
          "Revoke a user's access with `DELETE /v1/admin/user_connections/{id}`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67
          }
        ],
        "editorialScores": {
          "ergonomics": 79,
          "maintenance": 74,
          "payments": 40,
          "reliability": 63,
          "schema": 82,
          "security": 71,
          "transparency": 47
        },
        "provenanceScore": 96
      },
      "connect": {
        "install": "npm install @arcadeai/arcadejs",
        "http": "curl -X POST https://api.arcade.dev/v1/tools/authorize -H \"Authorization: Bearer $ARCADE_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"tool_name\":\"Gmail.ListEmails\",\"user_id\":\"user-123\"}'",
        "claudeCode": "claude mcp add --transport http arcade https://api.arcade.dev/mcp/\u003cyour-gateway-slug\u003e",
        "config": {
          "mcpServers": {
            "arcade": {
              "url": "https://api.arcade.dev/mcp/\u003cyour-gateway-slug\u003e"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/arcade"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan platform fee",
          "unit": "month",
          "usd": 25,
          "note": "Usage billed on top"
        },
        {
          "item": "Tool call on Team",
          "unit": "call",
          "usd": 0.01,
          "note": "After the included allowance. Auth events are $0.10 each"
        }
      ],
      "provenance": {
        "legalEntity": "Arcade AI, Inc.",
        "domain": "arcade.dev",
        "domainRegistered": "2019-03-26",
        "endpointOnVendorDomain": true,
        "terms": "https://www.arcade.dev/terms-of-service",
        "privacy": "https://www.arcade.dev/privacy-policy",
        "statusPage": "https://status.arcade.dev",
        "changelog": "https://docs.arcade.dev/en/references/changelog",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "notes": [
          "The terms (effective 15 July 2025) name Arcade AI, Inc. and California law."
        ],
        "score": 96
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/arcade.json",
      "live": {
        "slug": "arcade",
        "probe": {
          "target": "https://api.arcade.dev",
          "method": "get",
          "lastAt": "2026-10-05T00:57:15.815572883Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 579,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 600,
          "p95ms24h": 921,
          "samples24h": 272,
          "samples30d": 911,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 11,
              "ok": 11
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.arcade.dev",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T00:53:42.950101517Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@arcadeai/arcadejs",
            "version": "2.4.1",
            "seenAt": "2026-10-04T16:20:45.579808808Z"
          },
          {
            "registry": "pypi",
            "name": "arcade-mcp",
            "version": "1.16.1",
            "released": "2026-09-25",
            "seenAt": "2026-10-04T16:20:46.731244096Z"
          },
          {
            "registry": "pypi",
            "name": "arcadepy",
            "version": "1.10.0",
            "released": "2025-11-06",
            "seenAt": "2026-10-04T16:20:46.538925772Z"
          }
        ],
        "githubStars": 1044,
        "npmWeekly": 147047,
        "pypiWeekly": 89070,
        "securityTxt": {
          "url": "https://arcade.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-07-20T00:00:00Z",
          "checkedAt": "2026-10-04T15:15:42.588411925Z"
        },
        "llmsTxt": {
          "url": "https://docs.arcade.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:15.279748511Z"
        },
        "domain": {
          "domain": "arcade.dev",
          "registered": "2019-03-26",
          "source": "https://pubapi.registry.google/rdap/domain/arcade.dev",
          "checkedAt": "2026-10-04T13:09:09.815000281Z"
        },
        "pages": [
          {
            "url": "https://docs.arcade.dev/en/references/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:12.967090689Z",
            "changedAt": "2026-10-03T15:31:20.862139392Z",
            "fingerprint": "fed6349730bd"
          },
          {
            "url": "https://www.arcade.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:49:11.688685765Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0965f63267b5"
          },
          {
            "url": "https://www.arcade.dev/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:49:13.767168196Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "03308f7a2c1b"
          },
          {
            "url": "https://www.arcade.dev/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:49:15.77318424Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "afaf24fae3e3"
          }
        ],
        "updatedAt": "2026-10-05T00:57:15.815572883Z"
      }
    },
    "b": {
      "slug": "keycard",
      "name": "Keycard",
      "vendor": "Keycard Labs",
      "vendorUrl": "https://www.keycard.ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Identity and access platform for AI agents.",
      "url": "https://www.anchorterminal.com/tools/keycard",
      "markdownUrl": "https://www.anchorterminal.com/tools/keycard.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keycard.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keycard.json",
      "repo": "https://github.com/keycardai/python-sdk",
      "license": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.keycard.ai",
      "packages": [
        {
          "registry": "pypi",
          "name": "keycardai-mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai-fastmcp"
        },
        {
          "registry": "npm",
          "name": "@keycardai/mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai_api"
        }
      ],
      "auth": "mixed",
      "authNotes": "The management API at api.keycard.ai takes `Authorization: Bearer $KEYCARD_API_KEY` (a service account key). Agents and MCP servers talk OAuth 2.0 to their zone at `https://\u003czone-id\u003e.keycard.cloud`, discovered from `/.well-known/oauth-authorization-server`, with PKCE, dynamic client registration and RFC 8693 token exchange against the token endpoint. Application credentials are a client secret, a web identity (OIDC) or EKS workload identity. Tokens are JWTs verified against the zone's JWKS.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 5,000 transactions a month as a hard cap, unlimited users, agents and apps, RBAC, ABAC and ReBAC policies, 7-day telemetry retention and community support. Team is $500 a month with 100,000 transactions and $1 per 1,000 after, SSO, zone policy, 90-day retention, email support and an SLA. Enterprise is custom on an annual commitment, with org and device-based policy, SCIM, Active Directory and LDAP provisioning, dedicated, BYOC or on-prem deployment, private networking, customer-managed KMS, 180-day retention, a 99.95 per cent uptime SLA and 1-hour 24/7 response on P1 issues. A transaction is recorded each time Keycard issues a credential, validates an access request or exchanges a credential (https://www.keycard.ai/pricing). The page doesn't say whether a card is needed, and its sign-up form ends with a promise to be in touch. The quickstart calls the product Early Access, with sign-up at console.keycard.ai.",
      "priceSummary": "$500 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1,
        "npmWeekly": 52,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.keycard.ai",
      "llmsTxt": "https://docs.keycard.ai/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.3,
        "grade": "C",
        "agentReady": false,
        "rank": 303,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 45
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.",
        "strengths": [
          "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange",
          "Delegated grants with RFC 8693 exchange for GitHub, Google, Slack, Linear and any OAuth 2.0 provider",
          "Session timeline and audit log per exchange, exported hourly to S3 in OCSF Parquet",
          "Published per-unit price ($1 per 1,000 transactions on Team) with a transaction defined",
          "Valid security.txt and SOC 2 Type 2 listed in a SafeBase trust centre"
        ],
        "weaknesses": [
          "Early Access with sign-up by request, and no terms of service page",
          "No per-token kill switch, so a revoked grant lives until the token expires, and revocation doesn't reach the provider",
          "No published rate limits, 429 guidance or public changelog",
          "keycardai-mcp went from 1.0.0 to 2.0.0 in a day in August 2026",
          "Team is $500 a month with nothing between it and the free tier"
        ],
        "agentNotes": [
          "Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone",
          "Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange",
          "Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry",
          "Keep credentials short-lived, because revocation only stops the next issuance",
          "Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.3
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 25
        },
        "provenanceScore": 65
      },
      "connect": {
        "install": "pip install keycardai-mcp",
        "http": "curl \"https://api.keycard.ai/zones/$KEYCARD_ZONE_ID/sessions\" \\\n  -H \"Authorization: Bearer $KEYCARD_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/keycard"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 500,
          "note": "100,000 transactions included"
        },
        {
          "item": "Transactions above 100,000 on Team",
          "unit": "1k-calls",
          "usd": 1,
          "note": "The pricing page doesn't define a transaction"
        }
      ],
      "provenance": {
        "legalEntity": "Keycard Labs, Inc.",
        "domain": "keycard.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://www.keycard.ai/privacy/",
        "statusPage": "https://status.keycard.ai",
        "changelog": "",
        "securityTxt": "valid",
        "checked": "2026-10-02",
        "notes": [
          "The homepage footer names Keycard Labs, Inc., 103 Foulk Road, Suite 202, Wilmington, DE 19808. The footer's legal links on 2 October were privacy, cookie policy, a vulnerability address and the trust centre at trust.keycard.ai. We found no terms of service page (keycard.ai/terms/ returns 404) and the privacy page's body didn't load for us on 30 September or 2 October.",
          "RDAP for keycard.ai returned 404 at rdap.nic.ai and 429 at Identity Digital on 2026-09-30, so the registration date is blank.",
          "status.keycard.ai answers as a status page, though its history renders client-side and its JSON and RSS feeds returned 403 to us on 2 October.",
          "The docs index (73 entries) lists no changelog. The SDK repositories' CHANGELOG.md files are the nearest thing to release notes.",
          "The trust centre lists SOC 2 Type 1 and Type 2 reports and names Resend, Google, GitHub, Cloudflare and AWS as subprocessors."
        ],
        "score": 65
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/keycard.json",
      "live": {
        "slug": "keycard",
        "probe": {
          "target": "https://api.keycard.ai",
          "method": "get",
          "lastAt": "2026-10-05T00:57:22.208548648Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 278,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 280,
          "p95ms24h": 367,
          "samples24h": 272,
          "samples30d": 911,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 11,
              "ok": 11
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.keycard.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:10.814751767Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@keycardai/mcp",
            "version": "2.0.2",
            "seenAt": "2026-10-04T16:30:47.44448777Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-fastmcp",
            "version": "0.7.1",
            "released": "2026-09-15",
            "seenAt": "2026-10-04T16:30:45.543960623Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-mcp",
            "version": "2.3.2",
            "released": "2026-09-16",
            "seenAt": "2026-10-04T16:30:45.360722519Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai_api",
            "version": "0.18.0",
            "released": "2026-09-25",
            "seenAt": "2026-10-04T16:30:48.363651419Z"
          }
        ],
        "githubStars": 1,
        "npmWeekly": 211,
        "pypiWeekly": 179,
        "securityTxt": {
          "url": "https://keycard.ai/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-12T00:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:49.895852699Z"
        },
        "llmsTxt": {
          "url": "https://docs.keycard.ai/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:54.842330743Z"
        },
        "domain": {
          "domain": "keycard.ai",
          "registered": "2024-02-04",
          "source": "https://rdap.identitydigital.services/rdap/domain/keycard.ai",
          "checkedAt": "2026-10-04T13:06:32.92261194Z"
        },
        "pages": [
          {
            "url": "https://www.keycard.ai/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:56.738789549Z",
            "changedAt": "2026-10-03T15:38:49.492444489Z",
            "fingerprint": "7d745cb5c53f"
          },
          {
            "url": "https://www.keycard.ai/privacy/",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:58.814741157Z",
            "changedAt": "2026-10-03T15:38:51.566729092Z",
            "fingerprint": "596ae9dc1660"
          }
        ],
        "updatedAt": "2026-10-05T00:57:22.208548648Z"
      }
    },
    "summary": "Arcade.dev has a score of 67 (B) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 28 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/arcade-vs-keycard",
    "json": "https://www.anchorterminal.com/compare/arcade-vs-keycard.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/arcade-vs-keycard.md",
    "slim": "https://www.anchorterminal.com/compare/arcade-vs-keycard.min.md"
  },
  "markdown": "Arcade.dev has a score of 67 (B) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 28 points.\n\n- Arcade.dev: grade B, 67/100, rank #147 of 452. Markdown https://www.anchorterminal.com/tools/arcade.md · JSON https://www.anchorterminal.com/api/v1/tools/arcade.json\n- Keycard: grade C, 56.3/100, rank #303 of 452. Markdown https://www.anchorterminal.com/tools/keycard.md · JSON https://www.anchorterminal.com/api/v1/tools/keycard.json\n\n## Which one, for what\n\nPick Arcade.dev for reliability (+28), schema \u0026 documentation (+21), agent ergonomics (+19), payments \u0026 pricing (+10), transparency \u0026 trust (+27).\n\nPick Keycard for security \u0026 auth (+15), maintenance \u0026 community (+5).\n\n## Score by category\n\n| Category | Weight | Arcade.dev | Keycard | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 63 | 35 | Arcade.dev +28 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 61 | Arcade.dev +21 |\n| Agent ergonomics | 13% (16.2 this run) | 79 | 60 | Arcade.dev +19 |\n| Security \u0026 auth | 14% (17.5 this run) | 71 | 86 | Keycard +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 30 | Arcade.dev +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 79 | Keycard +5 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 45 | Arcade.dev +27 |\n| Negative events | ≤15 | -2 | 0 | |\n| **Total** | | **67 · B** | **56.3 · C** | |\n\n## Facts side by side\n\n| Fact | Arcade.dev | Keycard |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Arcade.dev | Keycard Labs |\n| Hosted endpoint | `https://api.arcade.dev` | `https://api.keycard.ai` |\n| Transports | HTTP, Streamable HTTP, stdio | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (arcade-mcp framework and SDKs), platform closed | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-25 | 2026-09-22 |\n| Popularity | 1k stars, 125k npm/wk, 70k PyPI/wk | 1 stars, 52 npm/wk |\n| Agent reviews | 2.5/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Arcade.dev.** Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.\n\n**Keycard.** Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.\n\n## Before you call either\n\n### Arcade.dev\n\n1. Call `POST /v1/tools/authorize` first and send the user the returned URL when the status isn't completed\n2. Pass a stable user ID from your own database as user_id, never a shared value\n3. Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again\n4. Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project\n5. Revoke a user's access with `DELETE /v1/admin/user_connections/{id}`\n\n### Keycard\n\n1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone\n2. Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange\n3. Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry\n4. Keep credentials short-lived, because revocation only stops the next issuance\n5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart\n\n## Other comparisons with Arcade.dev or Keycard\n\n- [Arcade.dev vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents.md)\n- [Arcade.dev vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.md)\n- [Arcade.dev vs Nango](https://www.anchorterminal.com/compare/arcade-vs-nango.md)\n- [Arcade.dev vs Scalekit AgentKit](https://www.anchorterminal.com/compare/arcade-vs-scalekit-agentkit.md)\n- [Arcade.dev vs Stytch Connected Apps](https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps.md)\n- [Arcade.dev vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md)\n- [Keycard vs Scalekit AgentKit](https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Arcade.dev vs Keycard",
        "url": ""
      }
    ],
    "description": "Arcade.dev has a score of 67 (B) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 28 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Arcade.dev B 67",
      "Keycard C 56.3",
      "scores"
    ],
    "h1": "Arcade.dev vs Keycard",
    "image": "https://www.anchorterminal.com/assets/og/compare-arcade-vs-keycard.png",
    "path": "/compare/arcade-vs-keycard",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Arcade.dev vs Keycard for AI agents, B 67 vs C 56.3 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/arcade-vs-keycard"
  },
  "tokens": {
    "markdown": 1550,
    "slim": 330
  },
  "version": 1
}
