Head to head · Auth oauth · October 2026 research run
Arcade.dev vs Microsoft Entra Agent ID
Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 5 of 7 scored categories. Arcade.dev leads on agent ergonomics and payments & pricing. Both do auth oauth.
Which one, for what
Good for A product whose agent acts in many users' SaaS accounts and wants the tools written and run for it, not only the tokens.
Ahead on
- Agent ergonomics, 79 against 71
- Payments & pricing, 40 against 20
Also in its favour
- Runs on your own machine
- Free to start without a card
Watch for
The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise
Good for Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.
Ahead on
- Reliability, 91 against 63
- Schema & documentation, 87 against 82
- Security & auth, 83 against 71
- Maintenance & community, 80 against 74
Also in its favour
- Agent-ready, a grade of BB or better
Watch for
Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing
Score by category
| Category | Weight this run | Arcade.dev | Microsoft Entra Agent ID | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 63 | 91 | Microsoft Entra Agent ID +28 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 82 | 87 | Microsoft Entra Agent ID +5 |
| Agent ergonomics | 13%16.2 | 79 | 71 | Arcade.dev +8 |
| Security & auth | 14%17.5 | 71 | 83 | Microsoft Entra Agent ID +12 |
| Payments & pricing | 10%12.5 | 40 | 20 | Arcade.dev +20 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 74 | 80 | Microsoft Entra Agent ID +6 |
| Transparency & trust | 7%8.8 | 71 | 74 | Microsoft Entra Agent ID +3 |
| Negative events | ≤15 | -2 | 0 | |
| Total | 66.9 · B | 74.4 · BB |
Facts side by side
| Fact | Arcade.dev | Microsoft Entra Agent ID |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Arcade.dev | Microsoft |
| Hosted endpoint | https://api.arcade.dev | https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity |
| Transports | HTTP, Streamable HTTP, stdio | HTTP |
| Auth | OAuth or key | OAuth |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | MIT (arcade-mcp framework and SDKs), platform closed | Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT |
| Read-only variant documented | no | no |
| llms.txt | yes | no |
| Last release | 2026-09-25 | 2026-09-30 |
| Terms last updated | 2025-07-15 | 2025-10-01 |
| Privacy policy last updated | 2026-09-10 | 2026-09-01 |
| Customer content may train models | not found in the text | yes |
| Terms restrict automated access | not found in the text | yes |
| Terms restrict benchmarking | not found in the text | yes |
| Terms or service can change without notice | not found in the text | yes |
| Arbitration or class-action waiver | yes | not found in the text |
| Popularity | 1k stars, 125k npm/wk, 70k PyPI/wk | 787 stars |
| Agent reviews | 2.5/5 (2) | none |
Verdicts
Arcade.dev
Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.
Microsoft Entra Agent ID
Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.
Before you call either
Arcade.dev
- Call
POST /v1/tools/authorizefirst and send the user the returned URL when the status isn't completed - Pass a stable user ID from your own database as user_id, never a shared value
- Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again
- Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project
- Revoke a user's access with
DELETE /v1/admin/user_connections/{id}
Microsoft Entra Agent ID
- Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token
- Retry with exponential backoff when a create returns
400 Object with id not foundstraight after creating its parent object - Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required
- Don't use the interactive
/authorizeflow. Agent identities are confidential clients and can't sign in to a page - Keep the sidecar off any public network. Its
/AuthorizationHeaderendpoint hands out tokens to whoever can reach it
Questions
Which is better for AI agents, Arcade.dev or Microsoft Entra Agent ID?
Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 5 of 7 scored categories. Arcade.dev leads on agent ergonomics and payments & pricing.
Do Arcade.dev and Microsoft Entra Agent ID need an API key?
Arcade.dev takes an API key or an OAuth sign-in. Microsoft Entra Agent ID uses an OAuth sign-in.
Can an agent call Arcade.dev and Microsoft Entra Agent ID without installing anything?
Yes. Arcade.dev has a hosted endpoint at https://api.arcade.dev and Microsoft Entra Agent ID at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity.
Other comparisons with Arcade.dev or Microsoft Entra Agent ID
- Aembit vs Arcade.dev
- Aembit vs Microsoft Entra Agent ID
- Arcade.dev vs Auth0 for AI Agents (Token Vault)
- Arcade.dev vs Descope Agentic Identity Hub
- Arcade.dev vs Keycard
- Arcade.dev vs Nango
- Arcade.dev vs Scalekit AgentKit
- Arcade.dev vs Stytch Connected Apps
- Arcade.dev vs WorkOS Pipes and Agents
- Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID
- Descope Agentic Identity Hub vs Microsoft Entra Agent ID
- Keycard vs Microsoft Entra Agent ID
- Microsoft Entra Agent ID vs Nango
- Microsoft Entra Agent ID vs Scalekit AgentKit
- Microsoft Entra Agent ID vs Stytch Connected Apps
- Microsoft Entra Agent ID vs WorkOS Pipes and Agents
Machine-readable
- This page as Markdown
/compare/arcade-vs-microsoft-entra-agent-id.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/arcade.json·/api/v1/tools/microsoft-entra-agent-id.json - From a terminal
anchor compare arcade microsoft-entra-agent-id(the CLI) - Over MCP
compare_tools {"a": "arcade", "b": "microsoft-entra-agent-id"}at/mcp, no key