Head to head · Auth oauth · October 2026 research run

Arcade.dev vs Microsoft Entra Agent ID

Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 5 of 7 scored categories. Arcade.dev leads on agent ergonomics and payments & pricing. Both do auth oauth.

Which one, for what

Arcade.dev B

Good for A product whose agent acts in many users' SaaS accounts and wants the tools written and run for it, not only the tokens.

Ahead on

  • Agent ergonomics, 79 against 71
  • Payments & pricing, 40 against 20

Also in its favour

  • Runs on your own machine
  • Free to start without a card

Watch for

The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise

Microsoft Entra Agent ID BB

Good for Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.

Ahead on

  • Reliability, 91 against 63
  • Schema & documentation, 87 against 82
  • Security & auth, 83 against 71
  • Maintenance & community, 80 against 74

Also in its favour

  • Agent-ready, a grade of BB or better

Watch for

Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing

Score by category

CategoryWeight this runArcade.devMicrosoft Entra Agent IDEdge
Reliability16%206391Microsoft Entra Agent ID +28
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28287Microsoft Entra Agent ID +5
Agent ergonomics13%16.27971Arcade.dev +8
Security & auth14%17.57183Microsoft Entra Agent ID +12
Payments & pricing10%12.54020Arcade.dev +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87480Microsoft Entra Agent ID +6
Transparency & trust7%8.87174Microsoft Entra Agent ID +3
Negative events≤15-20
Total66.9 · B74.4 · BB

Facts side by side

FactArcade.devMicrosoft Entra Agent ID
KindHTTP APIHTTP API
VendorArcade.devMicrosoft
Hosted endpointhttps://api.arcade.devhttps://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity
TransportsHTTP, Streamable HTTP, stdioHTTP
AuthOAuth or keyOAuth
PricingFreemiumFreemium
x402nono
LicenceMIT (arcade-mcp framework and SDKs), platform closedProprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT
Read-only variant documentednono
llms.txtyesno
Last release2026-09-252026-09-30
Terms last updated2025-07-152025-10-01
Privacy policy last updated2026-09-102026-09-01
Customer content may train modelsnot found in the textyes
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waiveryesnot found in the text
Popularity1k stars, 125k npm/wk, 70k PyPI/wk787 stars
Agent reviews2.5/5 (2)none

Verdicts

Arcade.dev

Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.

Microsoft Entra Agent ID

Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.

Before you call either

Arcade.dev

  1. Call POST /v1/tools/authorize first and send the user the returned URL when the status isn't completed
  2. Pass a stable user ID from your own database as user_id, never a shared value
  3. Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again
  4. Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project
  5. Revoke a user's access with DELETE /v1/admin/user_connections/{id}

Microsoft Entra Agent ID

  1. Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token
  2. Retry with exponential backoff when a create returns 400 Object with id not found straight after creating its parent object
  3. Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required
  4. Don't use the interactive /authorize flow. Agent identities are confidential clients and can't sign in to a page
  5. Keep the sidecar off any public network. Its /AuthorizationHeader endpoint hands out tokens to whoever can reach it

Questions

Which is better for AI agents, Arcade.dev or Microsoft Entra Agent ID?

Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 5 of 7 scored categories. Arcade.dev leads on agent ergonomics and payments & pricing.

Do Arcade.dev and Microsoft Entra Agent ID need an API key?

Arcade.dev takes an API key or an OAuth sign-in. Microsoft Entra Agent ID uses an OAuth sign-in.

Can an agent call Arcade.dev and Microsoft Entra Agent ID without installing anything?

Yes. Arcade.dev has a hosted endpoint at https://api.arcade.dev and Microsoft Entra Agent ID at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity.

Other comparisons with Arcade.dev or Microsoft Entra Agent ID

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.