{
  "data": {
    "a": {
      "slug": "arcade",
      "name": "Arcade.dev",
      "vendor": "Arcade.dev",
      "vendorUrl": "https://www.arcade.dev",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "MCP runtime built around per-user authorisation.",
      "url": "https://www.anchorterminal.com/tools/arcade",
      "markdownUrl": "https://www.anchorterminal.com/tools/arcade.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/arcade.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/arcade.json",
      "repo": "https://github.com/ArcadeAI/arcade-mcp",
      "license": "MIT (arcade-mcp framework and SDKs), platform closed",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://api.arcade.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@arcadeai/arcadejs"
        },
        {
          "registry": "pypi",
          "name": "arcadepy"
        },
        {
          "registry": "pypi",
          "name": "arcade-mcp"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST calls take the project key as `Authorization: Bearer $ARCADE_API_KEY` and name the end user with `user_id`. MCP gateways sign end users in with OAuth, either Arcade Auth (project members only) or a User Source pointing at your own OIDC provider. Clients that can't run OAuth can send the API key plus an `Arcade-User-ID` header instead.",
      "pricing": "freemium",
      "pricingNotes": "Free is $0 with 2,000 auth events and 2,000 tool calls a month, no card, community support. Team is a $25 a month platform fee plus $0.10 per auth event and $0.01 per tool call, with next-business-day email support. Enterprise is custom, with annual bundles, deployment in your VPC or air-gapped, SSO, RBAC and a dedicated forward-deployed engineer (https://www.arcade.dev/pricing). The pricing page doesn't define an auth event.",
      "priceSummary": "$25 / mo",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1043,
        "npmWeekly": 124858,
        "pypiWeekly": 70222,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.arcade.dev",
      "llmsTxt": "https://docs.arcade.dev/llms.txt",
      "openapi": "https://api.arcade.dev/v1/swagger",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.audit",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "mcp",
        "llms-txt",
        "openapi",
        "oauth",
        "python",
        "typescript",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-25",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 66.9,
        "grade": "B",
        "agentReady": false,
        "rank": 221,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 79,
          "maintenance": 74,
          "payments": 40,
          "reliability": 63,
          "schema": 82,
          "security": 71,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -2,
        "negativeNotes": [
          "2025-12-02, CVE-2025-66454 (GHSA-g2jx-37x6-6438, CVSS 6.5). The HTTP worker in arcade-mcp shipped a hardcoded default worker secret, so anyone could forge a token and list or call every tool on a self-hosted worker set up by the official guide. Fixed in 1.9.1 and disclosed in public, so we deduct 2 of a possible 15 (https://github.com/ArcadeAI/arcade-mcp/security/advisories/GHSA-g2jx-37x6-6438)"
        ],
        "verdict": "Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.",
        "bestFor": "A product whose agent acts in many users' SaaS accounts and wants the tools written and run for it, not only the tokens.",
        "strengths": [
          "Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token",
          "33 built-in auth providers plus generic OAuth 2.0, and hosted MCP gateways that sign users in through your own OIDC provider",
          "OpenAPI 3.0 file with 39 paths, llms.txt and a typed tool error hierarchy with retry hints",
          "Per-call prices in public, $0.01 a tool call and $0.10 an auth event, with 2,000 of each free and no card",
          "Valid security.txt, a SOC 2 Type 2 report and a CVE fixed through a public advisory"
        ],
        "weaknesses": [
          "The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise",
          "Tool inputs and results are training data for up to 5 years unless the organisation opts out",
          "No published rate limits for the authorise or execute calls, and no 429 in the OpenAPI file",
          "The public changelog's latest entry is 26 July 2026 and arcadepy hasn't been released since 6 November 2025",
          "Hosting in the United States only outside Enterprise"
        ],
        "agentNotes": [
          "Call `POST /v1/tools/authorize` first and send the user the returned URL when the status isn't completed",
          "Pass a stable user ID from your own database as user_id, never a shared value",
          "Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again",
          "Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project",
          "Revoke a user's access with `DELETE /v1/admin/user_connections/{id}`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 66.9
          }
        ],
        "editorialScores": {
          "ergonomics": 79,
          "maintenance": 74,
          "payments": 40,
          "reliability": 63,
          "schema": 82,
          "security": 71,
          "transparency": 47
        },
        "provenanceScore": 94
      },
      "connect": {
        "install": "npm install @arcadeai/arcadejs",
        "http": "curl -X POST https://api.arcade.dev/v1/tools/authorize -H \"Authorization: Bearer $ARCADE_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"tool_name\":\"Gmail.ListEmails\",\"user_id\":\"user-123\"}'",
        "claudeCode": "claude mcp add --transport http arcade https://api.arcade.dev/mcp/\u003cyour-gateway-slug\u003e",
        "config": {
          "mcpServers": {
            "arcade": {
              "url": "https://api.arcade.dev/mcp/\u003cyour-gateway-slug\u003e"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/arcade"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan platform fee",
          "unit": "month",
          "usd": 25,
          "note": "Usage billed on top"
        },
        {
          "item": "Tool call on Team",
          "unit": "call",
          "usd": 0.01,
          "note": "After the included allowance. Auth events are $0.10 each"
        }
      ],
      "provenance": {
        "legalEntity": "Arcade AI, Inc.",
        "domain": "arcade.dev",
        "domainRegistered": "2019-03-26",
        "endpointOnVendorDomain": true,
        "terms": "https://www.arcade.dev/terms-of-service",
        "privacy": "https://www.arcade.dev/privacy-policy",
        "statusPage": "https://status.arcade.dev",
        "changelog": "https://docs.arcade.dev/en/references/changelog",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "notes": [
          "The terms (effective 15 July 2025) name Arcade AI, Inc. and California law."
        ],
        "score": 94
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/arcade.json",
      "live": {
        "slug": "arcade",
        "probe": {
          "target": "https://api.arcade.dev",
          "method": "get",
          "lastAt": "2026-10-08T20:21:06.296146901Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 779,
          "authRequired": false,
          "uptime24h": 99.26,
          "uptime30d": 99.9,
          "p50ms24h": 655,
          "p95ms24h": 987,
          "samples24h": 272,
          "samples30d": 1946,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 230,
              "ok": 228
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.arcade.dev",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T20:22:19.242501287Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@arcadeai/arcadejs",
            "version": "2.4.1",
            "seenAt": "2026-10-08T15:59:15.513696677Z"
          },
          {
            "registry": "pypi",
            "name": "arcade-mcp",
            "version": "1.16.2",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T15:59:22.627373168Z"
          },
          {
            "registry": "pypi",
            "name": "arcadepy",
            "version": "1.10.0",
            "released": "2025-11-06",
            "seenAt": "2026-10-08T15:59:19.232775498Z"
          }
        ],
        "githubStars": 1047,
        "npmWeekly": 147705,
        "pypiWeekly": 125741,
        "securityTxt": {
          "url": "https://arcade.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-07-20T00:00:00Z",
          "checkedAt": "2026-10-08T15:38:31.774058954Z"
        },
        "llmsTxt": {
          "url": "https://docs.arcade.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:03.150169651Z"
        },
        "domain": {
          "domain": "arcade.dev",
          "registered": "2019-03-26",
          "source": "https://pubapi.registry.google/rdap/domain/arcade.dev",
          "checkedAt": "2026-10-04T13:09:09.815000281Z"
        },
        "pages": [
          {
            "url": "https://docs.arcade.dev/en/references/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:13.451379301Z",
            "changedAt": "2026-10-08T18:18:13.451379301Z",
            "fingerprint": "600522b8614d"
          },
          {
            "url": "https://www.arcade.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:15.201152672Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0965f63267b5"
          },
          {
            "url": "https://www.arcade.dev/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:17.307243436Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "03308f7a2c1b"
          },
          {
            "url": "https://www.arcade.dev/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:19.284606349Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "afaf24fae3e3"
          }
        ],
        "updatedAt": "2026-10-08T20:22:19.242501287Z"
      }
    },
    "answer": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 5 of 7 scored categories. Arcade.dev leads on agent ergonomics and payments \u0026 pricing.",
    "b": {
      "slug": "microsoft-entra-agent-id",
      "name": "Microsoft Entra Agent ID",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph.",
      "url": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json",
      "repo": "https://github.com/AzureAD/microsoft-identity-web",
      "license": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
      "packages": [
        {
          "registry": "nuget",
          "name": "Microsoft.Identity.Web.AgentIdentities"
        }
      ],
      "auth": "oauth",
      "authNotes": "Access starts with a Microsoft Entra tenant and a person holding the Agent ID Developer or Agent ID Administrator role, who creates an agent identity blueprint. The blueprint authenticates to login.microsoftonline.com with a managed identity, a certificate or a client secret (Microsoft advises against secrets in production) and exchanges for a token as one of its agent identities. Agent identities hold no credentials. Three flows exist, which are app-only, on behalf of a signed-in user, and as the agent's own user account. Interactive `/authorize` and public clients aren't supported. Management calls on Microsoft Graph need AgentIdentity.Create.All or AgentIdentity.ReadWrite.All.",
      "pricing": "freemium",
      "pricingNotes": "Microsoft's docs say Agent ID is available to all Microsoft Entra customers, and Entra ID Free comes with any Microsoft cloud subscription. No per-agent price is published. Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15.00 a user a month on yearly billing, or Microsoft 365 E7 at $99.00. Conditional Access for agents also needs Entra P1 or Microsoft 365 E3 alongside Agent 365. No sandbox was found in the Agent ID docs (https://www.microsoft.com/en-us/microsoft-agent-365, checked 2026-10-08).",
      "priceSummary": "$15 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Agent ID docs, the Graph reference or the pricing pages (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 787,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.agent-identity",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "oauth",
        "openapi",
        "dotnet",
        "sidecar",
        "microsoft-graph",
        "mcp",
        "freemium",
        "sla"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 63,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 74
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.",
        "bestFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
        "strengths": [
          "Agent identities can't hold credentials. The blueprint authenticates with a managed identity, certificate or secret and exchanges for the agent's token",
          "Global Administrator and similar roles, and Graph permissions such as Application.ReadWrite.All, are refused for agent identities",
          "Create, list, update, delete and restore are on Microsoft Graph v1.0, with agentIdentity in the public OpenAPI file",
          "Audit and sign-in logs carry an agentType and blueprintId for agent activity",
          "Microsoft.Identity.Web 4.16.0 shipped on 30 September 2026, the eighth tagged release since 9 July"
        ],
        "weaknesses": [
          "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing",
          "Microsoft's docs call hand-written token exchange complex and error-prone and steer developers to a .NET library or a sidecar container",
          "Creating a blueprint, a principal and an identity in quick succession can fail with 400 until the directory replicates",
          "Audit and sign-in logs are kept seven days on Entra ID Free and 30 days on P1 or P2",
          "microsoft.com's security.txt passed its Expires date on 23 September 2026"
        ],
        "agentNotes": [
          "Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token",
          "Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object",
          "Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required",
          "Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page",
          "Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.4
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 63
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "dotnet add package Microsoft.Identity.Web.AgentIdentities",
        "http": "curl -X POST https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity \\\n  -H \"Authorization: Bearer $BLUEPRINT_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"displayName\": \"My Agent Identity\", \"agentIdentityBlueprintId\": \"\u003cblueprint-app-id\u003e\", \"sponsors@odata.bind\": [\"https://graph.microsoft.com/v1.0/users/\u003cid\u003e\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/microsoft-entra-agent-id"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Microsoft Agent 365",
          "unit": "seat-month",
          "usd": 15,
          "note": "billed yearly, needed for Conditional Access, ID Protection and governance for agents"
        },
        {
          "item": "Microsoft 365 E7 (includes Agent 365)",
          "unit": "seat-month",
          "usd": 99,
          "note": "billed yearly"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://www.microsoft.com/en-us/privacy/privacystatement",
        "statusPage": "https://azure.status.microsoft/en-us/status/history/",
        "changelog": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.",
          "The Microsoft APIs terms of use cover the Microsoft Graph API and other APIs that reach directory data, and were last updated in October 2025. Tenant use of Entra also falls under the customer's Microsoft licensing agreement and the Product Terms, which we didn't read.",
          "The Microsoft privacy statement was last updated in September 2026.",
          "Tokens come from login.microsoftonline.com and management calls go to graph.microsoft.com, both Microsoft domains.",
          "Entra's SLA page sends readers to the Azure status history for incidents that affect Entra ID.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.json",
      "live": {
        "slug": "microsoft-entra-agent-id",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
          "method": "get",
          "lastAt": "2026-10-08T20:21:20.147544694Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 57,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 32,
          "p95ms24h": 172,
          "samples24h": 32,
          "samples30d": 32,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 32,
              "ok": 32
            }
          ]
        },
        "vendorStatus": {
          "page": "https://azure.status.microsoft/en-us/status/history",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:47.070808325Z"
        },
        "pages": [
          {
            "url": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:21:36.290153566Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "bca4f93493d4"
          },
          {
            "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:21:38.182590643Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1a1ee1c20d9a"
          }
        ],
        "updatedAt": "2026-10-08T20:21:20.147544694Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Arcade.dev",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "https://api.arcade.dev",
        "b": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP, stdio",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT (arcade-mcp framework and SDKs), platform closed",
        "b": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-25",
        "b": "2026-09-30",
        "name": "Last release"
      },
      {
        "a": "2025-07-15",
        "b": "2025-10-01",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-10",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1k stars, 125k npm/wk, 70k PyPI/wk",
        "b": "787 stars",
        "name": "Popularity"
      },
      {
        "a": "2.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 5 of 7 scored categories. Arcade.dev leads on agent ergonomics and payments \u0026 pricing.",
        "question": "Which is better for AI agents, Arcade.dev or Microsoft Entra Agent ID?"
      },
      {
        "answer": "Arcade.dev takes an API key or an OAuth sign-in. Microsoft Entra Agent ID uses an OAuth sign-in.",
        "question": "Do Arcade.dev and Microsoft Entra Agent ID need an API key?"
      },
      {
        "answer": "Yes. Arcade.dev has a hosted endpoint at https://api.arcade.dev and Microsoft Entra Agent ID at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity.",
        "question": "Can an agent call Arcade.dev and Microsoft Entra Agent ID without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 79 against 71",
          "Payments \u0026 pricing, 40 against 20"
        ],
        "also": [
          "Runs on your own machine",
          "Free to start without a card"
        ],
        "goodFor": "A product whose agent acts in many users' SaaS accounts and wants the tools written and run for it, not only the tokens.",
        "slug": "arcade",
        "watchFor": "The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise"
      },
      {
        "aheadOn": [
          "Reliability, 91 against 63",
          "Schema \u0026 documentation, 87 against 82",
          "Security \u0026 auth, 83 against 71",
          "Maintenance \u0026 community, 80 against 74"
        ],
        "also": [
          "Agent-ready, a grade of BB or better"
        ],
        "goodFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
        "slug": "microsoft-entra-agent-id",
        "watchFor": "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-arcade.json",
        "title": "Aembit vs Arcade.dev",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-arcade"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.json",
        "title": "Aembit vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents.json",
        "title": "Arcade.dev vs Auth0 for AI Agents (Token Vault)",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.json",
        "title": "Arcade.dev vs Descope Agentic Identity Hub",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-keycard.json",
        "title": "Arcade.dev vs Keycard",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-nango.json",
        "title": "Arcade.dev vs Nango",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-scalekit-agentkit.json",
        "title": "Arcade.dev vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps.json",
        "title": "Arcade.dev vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.json",
        "title": "Arcade.dev vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.json",
        "title": "Descope Agentic Identity Hub vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.json",
        "title": "Keycard vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.json",
        "title": "Microsoft Entra Agent ID vs Nango",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.json",
        "title": "Microsoft Entra Agent ID vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.json",
        "title": "Microsoft Entra Agent ID vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.json",
        "title": "Microsoft Entra Agent ID vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "arcade": 63,
        "by": 28,
        "edge": "microsoft-entra-agent-id",
        "key": "reliability",
        "microsoft-entra-agent-id": 91,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "arcade": 82,
        "by": 5,
        "edge": "microsoft-entra-agent-id",
        "key": "schema",
        "microsoft-entra-agent-id": 87,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "arcade": 79,
        "by": 8,
        "edge": "arcade",
        "key": "ergonomics",
        "microsoft-entra-agent-id": 71,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "arcade": 71,
        "by": 12,
        "edge": "microsoft-entra-agent-id",
        "key": "security",
        "microsoft-entra-agent-id": 83,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "arcade": 40,
        "by": 20,
        "edge": "arcade",
        "key": "payments",
        "microsoft-entra-agent-id": 20,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "arcade": 74,
        "by": 6,
        "edge": "microsoft-entra-agent-id",
        "key": "maintenance",
        "microsoft-entra-agent-id": 80,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "arcade": 71,
        "by": 3,
        "edge": "microsoft-entra-agent-id",
        "key": "transparency",
        "microsoft-entra-agent-id": 74,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 5 of 7 scored categories. Arcade.dev leads on agent ergonomics and payments \u0026 pricing. Both do auth oauth.",
    "verdicts": {
      "arcade": "Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.",
      "microsoft-entra-agent-id": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id",
    "json": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.md",
    "slim": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.min.md"
  },
  "markdown": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 5 of 7 scored categories. Arcade.dev leads on agent ergonomics and payments \u0026 pricing. Both do auth oauth.\n\n- Arcade.dev: grade B, 66.9/100, rank #221 of 722. Markdown https://www.anchorterminal.com/tools/arcade.md · JSON https://www.anchorterminal.com/api/v1/tools/arcade.json\n- Microsoft Entra Agent ID: grade BB, 74.4/100, rank #63 of 722. Markdown https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json\n\n## Which one, for what\n\n### Arcade.dev (B)\n\nGood for: A product whose agent acts in many users' SaaS accounts and wants the tools written and run for it, not only the tokens.\n\nAhead on:\n- Agent ergonomics, 79 against 71\n- Payments \u0026 pricing, 40 against 20\n\nAlso in its favour:\n- Runs on your own machine\n- Free to start without a card\n\nWatch for: The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise\n\n### Microsoft Entra Agent ID (BB)\n\nGood for: Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.\n\nAhead on:\n- Reliability, 91 against 63\n- Schema \u0026 documentation, 87 against 82\n- Security \u0026 auth, 83 against 71\n- Maintenance \u0026 community, 80 against 74\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n\nWatch for: Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing\n\n\n## Score by category\n\n| Category | Weight | Arcade.dev | Microsoft Entra Agent ID | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 63 | 91 | Microsoft Entra Agent ID +28 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 87 | Microsoft Entra Agent ID +5 |\n| Agent ergonomics | 13% (16.2 this run) | 79 | 71 | Arcade.dev +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 71 | 83 | Microsoft Entra Agent ID +12 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 20 | Arcade.dev +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 80 | Microsoft Entra Agent ID +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 71 | 74 | Microsoft Entra Agent ID +3 |\n| Negative events | ≤15 | -2 | 0 | |\n| **Total** | | **66.9 · B** | **74.4 · BB** | |\n\n## Facts side by side\n\n| Fact | Arcade.dev | Microsoft Entra Agent ID |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Arcade.dev | Microsoft |\n| Hosted endpoint | `https://api.arcade.dev` | `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity` |\n| Transports | HTTP, Streamable HTTP, stdio | HTTP |\n| Auth | OAuth or key | OAuth |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (arcade-mcp framework and SDKs), platform closed | Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-09-25 | 2026-09-30 |\n| Terms last updated | 2025-07-15 | 2025-10-01 |\n| Privacy policy last updated | 2026-09-10 | 2026-09-01 |\n| Customer content may train models | not found in the text | yes |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 1k stars, 125k npm/wk, 70k PyPI/wk | 787 stars |\n| Agent reviews | 2.5/5 (2) | none |\n\n## Verdicts\n\n**Arcade.dev.** Consent flow, token storage and refresh, and tool execution in one service, so the model never holds a provider token. The terms of 15 July 2025 call the service an early version provided as is, with no uptime commitment below Enterprise.\n\n**Microsoft Entra Agent ID.** Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.\n\n## Before you call either\n\n### Arcade.dev\n\n1. Call `POST /v1/tools/authorize` first and send the user the returned URL when the status isn't completed\n2. Pass a stable user ID from your own database as user_id, never a shared value\n3. Read retry_after_ms on an UpstreamRateLimitError and wait that long before calling again\n4. Register your own OAuth app and a custom user verifier before real users sign in, because the default apps only accept members of your Arcade project\n5. Revoke a user's access with `DELETE /v1/admin/user_connections/{id}`\n\n### Microsoft Entra Agent ID\n\n1. Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token\n2. Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object\n3. Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required\n4. Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page\n5. Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it\n\n## Questions\n\n### Which is better for AI agents, Arcade.dev or Microsoft Entra Agent ID?\n\nMicrosoft Entra Agent ID scores 74.4 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 5 of 7 scored categories. Arcade.dev leads on agent ergonomics and payments \u0026 pricing.\n\n### Do Arcade.dev and Microsoft Entra Agent ID need an API key?\n\nArcade.dev takes an API key or an OAuth sign-in. Microsoft Entra Agent ID uses an OAuth sign-in.\n\n### Can an agent call Arcade.dev and Microsoft Entra Agent ID without installing anything?\n\nYes. Arcade.dev has a hosted endpoint at https://api.arcade.dev and Microsoft Entra Agent ID at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.json, and with the fewest tokens: https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"arcade\", \"b\": \"microsoft-entra-agent-id\"}`. From a terminal: `anchor compare arcade microsoft-entra-agent-id`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/arcade.json and https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json\n\n## Other comparisons with Arcade.dev or Microsoft Entra Agent ID\n\n- [Aembit vs Arcade.dev](https://www.anchorterminal.com/compare/aembit-vs-arcade.md)\n- [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md)\n- [Arcade.dev vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents.md)\n- [Arcade.dev vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.md)\n- [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md)\n- [Arcade.dev vs Nango](https://www.anchorterminal.com/compare/arcade-vs-nango.md)\n- [Arcade.dev vs Scalekit AgentKit](https://www.anchorterminal.com/compare/arcade-vs-scalekit-agentkit.md)\n- [Arcade.dev vs Stytch Connected Apps](https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps.md)\n- [Arcade.dev vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.md)\n- [Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.md)\n- [Descope Agentic Identity Hub vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md)\n- [Keycard vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md)\n- [Microsoft Entra Agent ID vs Nango](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.md)\n- [Microsoft Entra Agent ID vs Scalekit AgentKit](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.md)\n- [Microsoft Entra Agent ID vs Stytch Connected Apps](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.md)\n- [Microsoft Entra Agent ID vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Arcade.dev vs Microsoft Entra Agent ID",
        "url": ""
      }
    ],
    "description": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Arcade.dev's 66.9 (B), and leads in 5 of 7 scored categories. Arcade.dev leads on agent ergonomics and payments \u0026 pricing. Both do auth oauth. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Arcade.dev B 66.9",
      "Microsoft Entra Agent ID BB 74.4",
      "scores"
    ],
    "h1": "Arcade.dev vs Microsoft Entra Agent ID",
    "image": "https://www.anchorterminal.com/assets/og/compare-arcade-vs-microsoft-entra-agent-id.png",
    "path": "/compare/arcade-vs-microsoft-entra-agent-id",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Arcade.dev vs Microsoft Entra Agent ID for AI agents | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 780
  },
  "version": 1
}
