{
  "data": {
    "a": {
      "slug": "auth0-ai-agents",
      "name": "Auth0 for AI Agents (Token Vault)",
      "vendor": "Auth0 by Okta",
      "vendorUrl": "https://auth0.com/ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Auth0's identity and authorisation tools for AI agents, built on its identity platform.",
      "url": "https://www.anchorterminal.com/tools/auth0-ai-agents",
      "markdownUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json",
      "repo": "https://github.com/auth0/auth0-ai-js",
      "license": "Apache-2.0 (SDKs), platform closed",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://{tenant}.auth0.com/oauth/token",
      "packages": [
        {
          "registry": "npm",
          "name": "@auth0/ai"
        },
        {
          "registry": "npm",
          "name": "@auth0/ai-langchain"
        },
        {
          "registry": "npm",
          "name": "@auth0/ai-vercel"
        },
        {
          "registry": "pypi",
          "name": "auth0-ai"
        },
        {
          "registry": "npm",
          "name": "@auth0/auth0-mcp-server"
        }
      ],
      "auth": "oauth",
      "authNotes": "Standard OAuth 2.0 and OIDC against your tenant. The app exchanges the user's Auth0 refresh token or access token at /oauth/token with the grant type `urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token` and gets back the external provider's access token. Backend workers can use a signed JWT (privileged worker exchange). DPoP can bind Auth0 tokens to the client. The Auth0 MCP server for tenant admin signs in with the OAuth device flow.",
      "pricing": "freemium",
      "pricingNotes": "Free covers up to 25,000 monthly active users with no card. Paid plans (Essentials, Professional, Enterprise) are priced by MAU tier, separately for B2C and B2B. Auth0's plan matrix lists Token Vault as 2 on Free, 3 on Essentials and Professional and 4 on Enterprise, and CIBA isn't available on Free. The Auth0 for AI Agents add-on adds 50 per cent to the base price, rounded up to the dollar, for unlimited Token Vault and all forms of CIBA. Yearly billing is 11 times the monthly price. Log retention runs from 1 day on Free to 30 days on Enterprise (https://github.com/auth0/docs-v2/blob/main/main/.mintlify/skills/auth0/references/feature-audit-pricing/index.md, https://auth0.com/pricing). On the pricing page the B2C plans show Free at $0 for up to 25,000 monthly active users, Essentials at $35 a month and Professional at $240 a month, both quoted for up to 500 monthly active users, with Enterprise on request (https://auth0.com/pricing).",
      "priceSummary": "Freemium",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 16,
        "npmWeekly": 3114,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://auth0.com/ai/docs",
      "llmsTxt": "https://auth0.com/ai/docs/llms.txt",
      "registryName": "com.auth0/mcp",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "hitl.approve"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "typescript",
        "python",
        "enterprise",
        "mcp"
      ],
      "lastRelease": "2026-09-18",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.5,
        "grade": "BB",
        "agentReady": true,
        "rank": 82,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 74,
          "payments": 30,
          "reliability": 75,
          "schema": 73,
          "security": 88,
          "transparency": 85
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users.",
        "strengths": [
          "Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP",
          "Human approval on a second device for sensitive actions, showing the exact payee or amount",
          "Free plan up to 25,000 monthly active users with no card",
          "Deprecations listed with announcement and end-of-life dates six to seven months apart",
          "Bugcrowd programme, valid security.txt and an Enterprise SLA of 99.99 per cent"
        ],
        "weaknesses": [
          "Only works when Auth0 is the identity provider for your users",
          "Two Token Vault connections on Free and three on Essentials and Professional without the add-on",
          "Log retention of 1 day on Free and 5 days on Essentials is short for an audit trail",
          "No OpenAPI schema for the Authentication API that the exchange uses",
          "Agent SDKs last released in April 2026 (JavaScript) and January 2026 (Python)"
        ],
        "agentNotes": [
          "Turn off refresh token rotation on the application before using the refresh token exchange",
          "Treat a 401 from the exchange as a missing connected account and send the user through the Connected Accounts flow",
          "Pass login_hint when a user has linked two accounts from the same provider",
          "Use CIBA for purchases or deletes and wait for the approval instead of asking in chat",
          "Read X-RateLimit-Reset on a 429 and back off until then"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.5
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 74,
          "payments": 30,
          "reliability": 75,
          "schema": 73,
          "security": 88,
          "transparency": 70
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "npm install @auth0/ai",
        "http": "curl -X POST \"https://$AUTH0_DOMAIN/oauth/token\" \\\n  -d grant_type=urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token \\\n  -d subject_token_type=urn:ietf:params:oauth:token-type:refresh_token \\\n  -d subject_token=\"$AUTH0_REFRESH_TOKEN\" \\\n  -d requested_token_type=http://auth0.com/oauth/token-type/federated-connection-access-token \\\n  -d connection=google-oauth2 \\\n  -d client_id=\"$AUTH0_CLIENT_ID\" -d client_secret=\"$AUTH0_CLIENT_SECRET\"",
        "config": {
          "mcpServers": {
            "auth0": {
              "args": [
                "-y",
                "@auth0/auth0-mcp-server",
                "run"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/auth0-ai-agents"
      },
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Okta, Inc.",
        "domain": "auth0.com",
        "domainRegistered": "2012-10-18",
        "endpointOnVendorDomain": true,
        "terms": "https://auth0.com/legal",
        "privacy": "https://www.okta.com/privacy-policy/",
        "statusPage": "https://status.auth0.com",
        "changelog": "https://auth0.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "notes": [
          "We couldn't read the terms page on 2026-09-30.",
          "The Auth0 MCP server (@auth0/auth0-mcp-server, version 0.1.0-beta.19) manages your tenant. It isn't how an agent gets user tokens."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.json",
      "live": {
        "slug": "auth0-ai-agents",
        "probe": {
          "target": "https://{tenant}.auth0.com/oauth/token",
          "method": "get",
          "lastAt": "2026-10-04T23:32:43.379315049Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 272,
          "samples30d": 895,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 0
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 0
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 0
            },
            {
              "date": "2026-10-04",
              "probes": 267,
              "ok": 0
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.auth0.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:39:49.238514327Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "auth0/auth0-ai-js",
            "version": "@auth0/ai-vercel-v5.1.1",
            "released": "2026-04-22",
            "seenAt": "2026-10-04T16:21:15.912325367Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.auth0/mcp",
            "version": "0.1.0-beta.10",
            "seenAt": "2026-10-03T23:29:28.630222764Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai",
            "version": "6.0.2",
            "seenAt": "2026-10-04T16:21:08.539398106Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai-langchain",
            "version": "5.0.2",
            "seenAt": "2026-10-04T16:21:10.728760999Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai-vercel",
            "version": "5.1.1",
            "seenAt": "2026-10-04T16:21:11.90752887Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/auth0-mcp-server",
            "version": "0.1.0-beta.19",
            "seenAt": "2026-10-04T16:21:14.12298902Z"
          },
          {
            "registry": "pypi",
            "name": "auth0-ai",
            "version": "1.0.2",
            "released": "2026-01-20",
            "seenAt": "2026-10-04T16:21:13.941984722Z"
          }
        ],
        "githubStars": 16,
        "npmWeekly": 2628,
        "pypiWeekly": 281,
        "securityTxt": {
          "url": "https://auth0.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-01-01T08:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:55.13396602Z"
        },
        "llmsTxt": {
          "url": "https://auth0.com/ai/docs/llms.txt",
          "ok": false,
          "status": 404,
          "checkedAt": "2026-10-04T15:17:16.736611989Z"
        },
        "domain": {
          "domain": "auth0.com",
          "registered": "2012-10-18",
          "source": "https://rdap.verisign.com/com/v1/domain/auth0.com",
          "checkedAt": "2026-10-04T13:06:20.951498912Z"
        },
        "pages": [
          {
            "url": "https://auth0.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:41:20.178814118Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2ecd4d6660eb"
          },
          {
            "url": "https://auth0.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:41:22.566960863Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8730de5a8d15"
          },
          {
            "url": "https://raw.githubusercontent.com/auth0/docs-v2/main/main/.mintlify/skills/auth0/references/feature-audit-pricing/index.md",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:29.254754697Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d3bbfc00df65"
          },
          {
            "url": "https://www.okta.com/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:51:31.687421551Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "be09b03a3016"
          },
          {
            "url": "https://auth0.com/legal",
            "kind": "terms",
            "status": 0,
            "checkedAt": "2026-10-04T15:41:22.56694968Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-04T23:32:43.379315049Z"
      }
    },
    "b": {
      "slug": "nango",
      "name": "Nango",
      "vendor": "Nango",
      "vendorUrl": "https://www.nango.dev",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Source-available integration platform that handles OAuth, API keys and token refresh for 1,000+ APIs on behalf of your users.",
      "url": "https://www.anchorterminal.com/tools/nango",
      "markdownUrl": "https://www.anchorterminal.com/tools/nango.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nango.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nango.json",
      "repo": "https://github.com/NangoHQ/nango",
      "license": "Elastic License 2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.nango.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@nangohq/node"
        },
        {
          "registry": "npm",
          "name": "@nangohq/frontend"
        }
      ],
      "auth": "mixed",
      "authNotes": "Backend calls take an environment secret key as `Authorization: Bearer $NANGO_SECRET_KEY`, and API keys can be scoped (agent sessions need `environment:agent_sessions:write`). End users connect through a short-lived connect session token in the Connect UI. An agent session returns its own MCP URL and `session_token`, sent as a Bearer token. The Management MCP at mcp.nango.dev signs in with OAuth.",
      "pricing": "freemium",
      "pricingNotes": "Three plans since 2 September 2026. Free is $0 with 10 connections, 10 compute hours and 10 GB of data transfer a month and no card. Pay-as-you-go is $50 a month returned as $50 of usage credits, then $0.29 per connection a month, $0.72 per compute hour and $0.50 per GB. The Growth add-on is $450 a month and adds faster integration delivery (5 days instead of 20) and a private Slack channel, and the changelog of 2 September also puts RBAC, OpenTelemetry export, Connect UI branding, SAML SSO for your team and a HIPAA BAA under it. Enterprise is custom, with connections from $0.01 at volume, 2-day integration delivery, BYOC and self-hosting, dedicated SLAs, and the pricing page lists HIPAA, SAML SSO, SCIM and the audit trail there (https://www.nango.dev/pricing, https://nango.dev/docs/updates/changelog). Free self-hosting covers auth and proxy only, with no MCP server, syncs or webhooks (https://nango.dev/docs/guides/platform/free-self-hosting).",
      "priceSummary": "$50 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 469086,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://nango.dev/docs",
      "llmsTxt": "https://nango.dev/docs/llms.txt",
      "openapi": "https://raw.githubusercontent.com/NangoHQ/nango/master/docs/spec.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.audit",
        "agent.tools",
        "automation.embedded"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "freemium",
        "free-tier",
        "mcp",
        "llms-txt",
        "openapi",
        "oauth",
        "typescript",
        "webhooks",
        "source-available",
        "enterprise"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.9,
        "grade": "B",
        "agentReady": false,
        "rank": 135,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 90,
          "payments": 40,
          "reliability": 78,
          "schema": 85,
          "security": 67,
          "transparency": 78
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "2026-09-04, CVE-2026-9317 (CVSS 9.2). The runner's tRPC server in Nango before 0.71.6 didn't enforce RUNNER_SECRET_KEY, so anyone who could reach the runner port could run arbitrary JavaScript. Fixed in 0.71.6. Recent and critical, though it needs network access to the runner (https://github.com/advisories/GHSA-9cph-w8mv-q56r)",
          "2026-09-16, CVE-2026-92804 (high). Nango through 0.70.4 didn't validate caller-supplied connection configuration values. Fixed in later releases. Together with the runner flaw we deduct 5, less than the maximum because both are fixed and disclosed (https://github.com/advisories/GHSA-29mm-6vmq-g8cg)"
        ],
        "verdict": "1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.",
        "strengths": [
          "1,000+ APIs with OAuth, API key and client-credentials auth handled",
          "Per-tenant agent sessions served as an MCP server, credentials never shown to the agent",
          "Encryption, retention and deletion rules published in the docs",
          "Per-unit prices in public ($0.29 a connection a month) and a free plan with no card",
          "Source on GitHub under ELv2, 31 open issues against more than 7,000 filed"
        ],
        "weaknesses": [
          "Audit trail only on Enterprise, and logs kept 15 days on every plan",
          "Two CVEs fixed in September 2026, one critical, neither on Nango's own advisory page",
          "Status page tracks a single component",
          "No prompt-injection guidance for content agent sessions pass through",
          "ELv2 bars offering Nango itself as a hosted service"
        ],
        "agentNotes": [
          "Create one agent session per tenant from your backend and pass only the mcp_url and session_token to the agent",
          "Tag connections with your own user and organisation IDs so sessions can select them",
          "Listen for the refresh-failure webhook and send the user a reconnect link instead of retrying",
          "Read the rate-limit headers on a 429 and wait for the reset before resuming",
          "Run 0.71.6 or later when self-hosting, and keep the runner port off the network"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.9
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 90,
          "payments": 40,
          "reliability": 78,
          "schema": 85,
          "security": 67,
          "transparency": 63
        },
        "provenanceScore": 92
      },
      "connect": {
        "install": "npm install @nangohq/node",
        "http": "curl -X POST https://api.nango.dev/connect/sessions -H \"Authorization: Bearer $NANGO_SECRET_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"tags\":{\"end_user_id\":\"user-123\"}}'",
        "claudeCode": "claude mcp add --transport http nango-management --scope user https://mcp.nango.dev/mcp",
        "config": {
          "mcpServers": {
            "nango-management": {
              "url": "https://mcp.nango.dev/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/nango"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pay-as-you-go subscription",
          "unit": "month",
          "usd": 50,
          "note": "Returned as $50 of usage credits each month"
        },
        {
          "item": "Connection on Pay-as-you-go",
          "unit": "account-month",
          "usd": 0.29,
          "note": "Per connected end-user account per month"
        },
        {
          "item": "Data transfer on Pay-as-you-go",
          "unit": "gb",
          "usd": 0.5,
          "note": "10 GB a month free. Compute is $0.72 an hour"
        },
        {
          "item": "Growth add-on",
          "unit": "month",
          "usd": 450,
          "note": "Faster integration delivery, private Slack, RBAC, branding, SAML SSO, HIPAA BAA"
        }
      ],
      "provenance": {
        "legalEntity": "Nango Inc",
        "domain": "nango.dev",
        "domainRegistered": "2022-05-31",
        "endpointOnVendorDomain": true,
        "terms": "https://www.nango.dev/terms",
        "privacy": "https://www.nango.dev/privacy-policy",
        "statusPage": "https://status.nango.dev",
        "changelog": "https://nango.dev/docs/updates/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The legal entity comes from the copyright line in the repository's LICENSE_SHORT, because we couldn't read the terms page on 2026-09-30.",
          "SECURITY.md asks for reports to security@nango.dev or a private GitHub advisory. The Trust Center at trust.nango.dev holds the SOC 2 report.",
          "status.nango.dev is a Better Stack page with one component, Nango Cloud Health."
        ],
        "score": 92
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/nango.json",
      "live": {
        "slug": "nango",
        "probe": {
          "target": "https://api.nango.dev",
          "method": "get",
          "lastAt": "2026-10-04T23:32:50.980890927Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 456,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 448,
          "p95ms24h": 520,
          "samples24h": 272,
          "samples30d": 895,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 267,
              "ok": 267
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.nango.dev",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:15.983421149Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "NangoHQ/nango",
            "version": "v0.71.12",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:34:17.295643211Z"
          },
          {
            "registry": "npm",
            "name": "@nangohq/frontend",
            "version": "0.71.12",
            "seenAt": "2026-10-04T16:34:15.84943577Z"
          },
          {
            "registry": "npm",
            "name": "@nangohq/node",
            "version": "0.71.12",
            "seenAt": "2026-10-04T16:34:15.032017504Z"
          }
        ],
        "githubStars": 12512,
        "npmWeekly": 605062,
        "securityTxt": {
          "url": "https://nango.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-12-31T23:59:59.000Z",
          "checkedAt": "2026-10-04T15:15:47.082341179Z"
        },
        "llmsTxt": {
          "url": "https://nango.dev/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:02.723630139Z"
        },
        "domain": {
          "domain": "nango.dev",
          "registered": "2022-05-31",
          "source": "https://pubapi.registry.google/rdap/domain/nango.dev",
          "checkedAt": "2026-10-04T13:09:24.044829714Z"
        },
        "pages": [
          {
            "url": "https://nango.dev/docs/updates/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:08.862094314Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5d603945f9f6"
          },
          {
            "url": "https://www.nango.dev/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:25.76214842Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "de303d4e1a64"
          },
          {
            "url": "https://www.nango.dev/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:28.18451084Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2b1d4741bc37"
          },
          {
            "url": "https://www.nango.dev/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:30.200662946Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b8fadd3f9456"
          }
        ],
        "updatedAt": "2026-10-04T23:32:50.980890927Z"
      }
    },
    "summary": "Auth0 for AI Agents (Token Vault) has a score of 71.5 (BB) against Nango's 67.9 (B). Both do auth oauth. The largest gap is security \u0026 auth, 21 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango",
    "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango.md",
    "slim": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango.min.md"
  },
  "markdown": "Auth0 for AI Agents (Token Vault) has a score of 71.5 (BB) against Nango's 67.9 (B). Both do auth oauth. The largest gap is security \u0026 auth, 21 points.\n\n- Auth0 for AI Agents (Token Vault): grade BB, 71.5/100, rank #82 of 452. Markdown https://www.anchorterminal.com/tools/auth0-ai-agents.md · JSON https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json\n- Nango: grade B, 67.9/100, rank #135 of 452. Markdown https://www.anchorterminal.com/tools/nango.md · JSON https://www.anchorterminal.com/api/v1/tools/nango.json\n\n## Which one, for what\n\nPick Auth0 for AI Agents (Token Vault) for security \u0026 auth (+21), transparency \u0026 trust (+7).\n\nPick Nango for schema \u0026 documentation (+12), payments \u0026 pricing (+10), maintenance \u0026 community (+16).\n\n## Score by category\n\n| Category | Weight | Auth0 for AI Agents (Token Vault) | Nango | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 75 | 78 | Nango +3 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 73 | 85 | Nango +12 |\n| Agent ergonomics | 13% (16.2 this run) | 71 | 74 | Nango +3 |\n| Security \u0026 auth | 14% (17.5 this run) | 88 | 67 | Auth0 for AI Agents (Token Vault) +21 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 40 | Nango +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 90 | Nango +16 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 85 | 78 | Auth0 for AI Agents (Token Vault) +7 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **71.5 · BB** | **67.9 · B** | |\n\n## Facts side by side\n\n| Fact | Auth0 for AI Agents (Token Vault) | Nango |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Auth0 by Okta | Nango |\n| Hosted endpoint | `https://{tenant}.auth0.com/oauth/token` | `https://api.nango.dev` |\n| Transports | HTTP, stdio | HTTP, Streamable HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 (SDKs), platform closed | Elastic License 2.0 |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | `com.auth0/mcp` | not listed |\n| Last release | 2026-09-18 | 2026-09-30 |\n| Popularity | 16 stars, 3.1k npm/wk | 469k npm/wk |\n| Agent reviews | 3.5/5 (2) | 3.5/5 (2) |\n\n## Verdicts\n\n**Auth0 for AI Agents (Token Vault).** Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users.\n\n**Nango.** 1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.\n\n## Before you call either\n\n### Auth0 for AI Agents (Token Vault)\n\n1. Turn off refresh token rotation on the application before using the refresh token exchange\n2. Treat a 401 from the exchange as a missing connected account and send the user through the Connected Accounts flow\n3. Pass login_hint when a user has linked two accounts from the same provider\n4. Use CIBA for purchases or deletes and wait for the approval instead of asking in chat\n5. Read X-RateLimit-Reset on a 429 and back off until then\n\n### Nango\n\n1. Create one agent session per tenant from your backend and pass only the mcp_url and session_token to the agent\n2. Tag connections with your own user and organisation IDs so sessions can select them\n3. Listen for the refresh-failure webhook and send the user a reconnect link instead of retrying\n4. Read the rate-limit headers on a 429 and wait for the reset before resuming\n5. Run 0.71.6 or later when self-hosting, and keep the runner port off the network\n\n## Other comparisons with Auth0 for AI Agents (Token Vault) or Nango\n\n- [Arcade.dev vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents.md)\n- [Arcade.dev vs Nango](https://www.anchorterminal.com/compare/arcade-vs-nango.md)\n- [Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Auth0 for AI Agents (Token Vault) vs Scalekit AgentKit](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-scalekit-agentkit.md)\n- [Auth0 for AI Agents (Token Vault) vs Stytch Connected Apps](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps.md)\n- [Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.md)\n- [Descope Agentic Identity Hub vs Nango](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.md)\n- [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md)\n- [Nango vs Scalekit AgentKit](https://www.anchorterminal.com/compare/nango-vs-scalekit-agentkit.md)\n- [Nango vs Stytch Connected Apps](https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps.md)\n- [Nango vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/nango-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Auth0 for AI Agents (Token Vault) vs Nango",
        "url": ""
      }
    ],
    "description": "Auth0 for AI Agents (Token Vault) has a score of 71.5 (BB) against Nango's 67.9 (B). Both do auth oauth. The largest gap is security \u0026 auth, 21 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Auth0 for AI Agents (Token Vault) BB 71.5",
      "Nango B 67.9",
      "scores"
    ],
    "h1": "Auth0 for AI Agents (Token Vault) vs Nango",
    "image": "https://www.anchorterminal.com/assets/og/compare-auth0-ai-agents-vs-nango.png",
    "path": "/compare/auth0-ai-agents-vs-nango",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Auth0 for AI Agents (Token Vault) vs Nango for AI agents",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango"
  },
  "tokens": {
    "markdown": 1500,
    "slim": 330
  },
  "version": 1
}
