{
  "data": {
    "a": {
      "slug": "auth0-ai-agents",
      "name": "Auth0 for AI Agents (Token Vault)",
      "vendor": "Auth0 by Okta",
      "vendorUrl": "https://auth0.com/ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Auth0's identity and authorisation tools for AI agents, built on its identity platform.",
      "url": "https://www.anchorterminal.com/tools/auth0-ai-agents",
      "markdownUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json",
      "repo": "https://github.com/auth0/auth0-ai-js",
      "license": "Apache-2.0 (SDKs), platform closed",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://{tenant}.auth0.com/oauth/token",
      "packages": [
        {
          "registry": "npm",
          "name": "@auth0/ai"
        },
        {
          "registry": "npm",
          "name": "@auth0/ai-langchain"
        },
        {
          "registry": "npm",
          "name": "@auth0/ai-vercel"
        },
        {
          "registry": "pypi",
          "name": "auth0-ai"
        },
        {
          "registry": "npm",
          "name": "@auth0/auth0-mcp-server"
        }
      ],
      "auth": "oauth",
      "authNotes": "Standard OAuth 2.0 and OIDC against your tenant. The app exchanges the user's Auth0 refresh token or access token at /oauth/token with the grant type `urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token` and gets back the external provider's access token. Backend workers can use a signed JWT (privileged worker exchange). DPoP can bind Auth0 tokens to the client. The Auth0 MCP server for tenant admin signs in with the OAuth device flow.",
      "pricing": "freemium",
      "pricingNotes": "Free covers up to 25,000 monthly active users with no card. Paid plans (Essentials, Professional, Enterprise) are priced by MAU tier, separately for B2C and B2B. Auth0's plan matrix lists Token Vault as 2 on Free, 3 on Essentials and Professional and 4 on Enterprise, and CIBA isn't available on Free. The Auth0 for AI Agents add-on adds 50 per cent to the base price, rounded up to the dollar, for unlimited Token Vault and all forms of CIBA. Yearly billing is 11 times the monthly price. Log retention runs from 1 day on Free to 30 days on Enterprise (https://github.com/auth0/docs-v2/blob/main/main/.mintlify/skills/auth0/references/feature-audit-pricing/index.md, https://auth0.com/pricing). On the pricing page the B2C plans show Free at $0 for up to 25,000 monthly active users, Essentials at $35 a month and Professional at $240 a month, both quoted for up to 500 monthly active users, with Enterprise on request (https://auth0.com/pricing).",
      "priceSummary": "Freemium",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 16,
        "npmWeekly": 3114,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://auth0.com/ai/docs",
      "llmsTxt": "https://auth0.com/ai/docs/llms.txt",
      "registryName": "com.auth0/mcp",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "hitl.approve"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "typescript",
        "python",
        "enterprise",
        "mcp"
      ],
      "lastRelease": "2026-09-18",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.5,
        "grade": "BB",
        "agentReady": true,
        "rank": 82,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 74,
          "payments": 30,
          "reliability": 75,
          "schema": 73,
          "security": 88,
          "transparency": 85
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users.",
        "strengths": [
          "Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP",
          "Human approval on a second device for sensitive actions, showing the exact payee or amount",
          "Free plan up to 25,000 monthly active users with no card",
          "Deprecations listed with announcement and end-of-life dates six to seven months apart",
          "Bugcrowd programme, valid security.txt and an Enterprise SLA of 99.99 per cent"
        ],
        "weaknesses": [
          "Only works when Auth0 is the identity provider for your users",
          "Two Token Vault connections on Free and three on Essentials and Professional without the add-on",
          "Log retention of 1 day on Free and 5 days on Essentials is short for an audit trail",
          "No OpenAPI schema for the Authentication API that the exchange uses",
          "Agent SDKs last released in April 2026 (JavaScript) and January 2026 (Python)"
        ],
        "agentNotes": [
          "Turn off refresh token rotation on the application before using the refresh token exchange",
          "Treat a 401 from the exchange as a missing connected account and send the user through the Connected Accounts flow",
          "Pass login_hint when a user has linked two accounts from the same provider",
          "Use CIBA for purchases or deletes and wait for the approval instead of asking in chat",
          "Read X-RateLimit-Reset on a 429 and back off until then"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.5
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 74,
          "payments": 30,
          "reliability": 75,
          "schema": 73,
          "security": 88,
          "transparency": 70
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "npm install @auth0/ai",
        "http": "curl -X POST \"https://$AUTH0_DOMAIN/oauth/token\" \\\n  -d grant_type=urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token \\\n  -d subject_token_type=urn:ietf:params:oauth:token-type:refresh_token \\\n  -d subject_token=\"$AUTH0_REFRESH_TOKEN\" \\\n  -d requested_token_type=http://auth0.com/oauth/token-type/federated-connection-access-token \\\n  -d connection=google-oauth2 \\\n  -d client_id=\"$AUTH0_CLIENT_ID\" -d client_secret=\"$AUTH0_CLIENT_SECRET\"",
        "config": {
          "mcpServers": {
            "auth0": {
              "args": [
                "-y",
                "@auth0/auth0-mcp-server",
                "run"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/auth0-ai-agents"
      },
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Okta, Inc.",
        "domain": "auth0.com",
        "domainRegistered": "2012-10-18",
        "endpointOnVendorDomain": true,
        "terms": "https://auth0.com/legal",
        "privacy": "https://www.okta.com/privacy-policy/",
        "statusPage": "https://status.auth0.com",
        "changelog": "https://auth0.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "notes": [
          "We couldn't read the terms page on 2026-09-30.",
          "The Auth0 MCP server (@auth0/auth0-mcp-server, version 0.1.0-beta.19) manages your tenant. It isn't how an agent gets user tokens."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.json",
      "live": {
        "slug": "auth0-ai-agents",
        "probe": {
          "target": "https://{tenant}.auth0.com/oauth/token",
          "method": "get",
          "lastAt": "2026-10-04T23:48:04.49400049Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 0
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 0
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 0
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 0
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.auth0.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:39:49.238514327Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "auth0/auth0-ai-js",
            "version": "@auth0/ai-vercel-v5.1.1",
            "released": "2026-04-22",
            "seenAt": "2026-10-04T16:21:15.912325367Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.auth0/mcp",
            "version": "0.1.0-beta.10",
            "seenAt": "2026-10-04T23:42:40.113054682Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai",
            "version": "6.0.2",
            "seenAt": "2026-10-04T16:21:08.539398106Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai-langchain",
            "version": "5.0.2",
            "seenAt": "2026-10-04T16:21:10.728760999Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai-vercel",
            "version": "5.1.1",
            "seenAt": "2026-10-04T16:21:11.90752887Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/auth0-mcp-server",
            "version": "0.1.0-beta.19",
            "seenAt": "2026-10-04T16:21:14.12298902Z"
          },
          {
            "registry": "pypi",
            "name": "auth0-ai",
            "version": "1.0.2",
            "released": "2026-01-20",
            "seenAt": "2026-10-04T16:21:13.941984722Z"
          }
        ],
        "githubStars": 16,
        "npmWeekly": 2628,
        "pypiWeekly": 281,
        "securityTxt": {
          "url": "https://auth0.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-01-01T08:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:55.13396602Z"
        },
        "llmsTxt": {
          "url": "https://auth0.com/ai/docs/llms.txt",
          "ok": false,
          "status": 404,
          "checkedAt": "2026-10-04T15:17:16.736611989Z"
        },
        "domain": {
          "domain": "auth0.com",
          "registered": "2012-10-18",
          "source": "https://rdap.verisign.com/com/v1/domain/auth0.com",
          "checkedAt": "2026-10-04T13:06:20.951498912Z"
        },
        "pages": [
          {
            "url": "https://auth0.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:41:20.178814118Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2ecd4d6660eb"
          },
          {
            "url": "https://auth0.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:41:22.566960863Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8730de5a8d15"
          },
          {
            "url": "https://raw.githubusercontent.com/auth0/docs-v2/main/main/.mintlify/skills/auth0/references/feature-audit-pricing/index.md",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:29.254754697Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d3bbfc00df65"
          },
          {
            "url": "https://www.okta.com/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:51:31.687421551Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "be09b03a3016"
          },
          {
            "url": "https://auth0.com/legal",
            "kind": "terms",
            "status": 0,
            "checkedAt": "2026-10-04T15:41:22.56694968Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-04T23:48:04.49400049Z"
      }
    },
    "b": {
      "slug": "scalekit-agentkit",
      "name": "Scalekit AgentKit",
      "vendor": "Scalekit",
      "vendorUrl": "https://www.scalekit.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Authentication and integration platform for agents, with per-user account connections, scoped MCP servers and managed tool calls.",
      "url": "https://www.anchorterminal.com/tools/scalekit-agentkit",
      "markdownUrl": "https://www.anchorterminal.com/tools/scalekit-agentkit.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/scalekit-agentkit.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/scalekit-agentkit.json",
      "repo": "https://github.com/scalekit-inc/scalekit-sdk-node",
      "license": "MIT (SDKs), platform closed, self-hosted on Enterprise",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://{env}.scalekit.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@scalekit-sdk/node"
        },
        {
          "registry": "pypi",
          "name": "scalekit-sdk-python"
        },
        {
          "registry": "npm",
          "name": "@scalekit-inc/cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "Your backend gets a bearer token from `POST $SCALEKIT_ENVIRONMENT_URL/oauth/token` with `grant_type=client_credentials` and the client ID and secret from the dashboard, then calls the REST API under /api/v1 on the same environment URL (dev environments end in .scalekit.dev, production in .scalekit.com). End users authorise a connection through a time-limited magic link that Scalekit hosts. Virtual MCP servers take a short-lived session token minted per user, about one hour by default. The management MCP server at mcp.scalekit.com needs no extra credentials.",
      "pricing": "freemium",
      "pricingNotes": "AgentKit Free is $0 with 5,000 tool calls a month, unlimited connected accounts, 500+ connectors and community and email support, no card. Growth is $99 a month with 100,000 tool calls and $0.0005 per extra call, custom connectors, an API proxy and private Slack support, with an EU data residency add-on at $99 a month. Enterprise is custom, with negotiated call volume, a 99.99 per cent uptime SLA, VPC or on-prem deployment, a HIPAA BAA, SIEM integrations and a forward-deployed engineer (https://www.scalekit.com/pricing). The page doesn't say whether a plain token fetch counts as a tool call.",
      "priceSummary": "$99 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6,
        "npmWeekly": 10642,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.scalekit.com/agentkit/overview",
      "llmsTxt": "https://docs.scalekit.com/llms.txt",
      "openapi": "https://docs.scalekit.com/api/agentkit.scalar.json",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "python",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 72.1,
        "grade": "BB",
        "agentReady": true,
        "rank": 74,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 80,
          "payments": 40,
          "reliability": 75,
          "schema": 87,
          "security": 66,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "500+ connectors, including remote MCP servers over OAuth 2.1 with DCR. No rate limits or idempotency documented for Scalekit's own API.",
        "strengths": [
          "500+ connectors, including remote MCP servers over OAuth 2.1 with DCR",
          "OpenAPI files, llms.txt and a Markdown twin for every docs page",
          "Tool search, scoped tool lists and virtual MCP servers keep an agent's context small",
          "Atlassian status page with an Agent Kit Tool Execution component, 100.0 per cent over 90 days",
          "Free tier of 5,000 tool calls a month with no card, then $0.0005 a call on Growth"
        ],
        "weaknesses": [
          "No rate limits or idempotency documented for Scalekit's own API",
          "Any holder of the API credential can read a user's full OAuth tokens",
          "No approval step for destructive tools and no prompt-injection guidance",
          "The privacy policy says the United States and India, the trust centre says Frankfurt and Los Angeles",
          "No security.txt, no bug bounty and no deprecation notices"
        ],
        "agentNotes": [
          "Use the exact dashboard Connection Name, not the connector slug, in every call",
          "Call `POST /api/v1/tools:search` with top_k instead of listing every tool",
          "When a connected account isn't ACTIVE, send the user the magic link and stop until they finish",
          "On ScalekitToolRateLimitException, back off before retrying, and log the executionId",
          "Mint a fresh virtual MCP session token per user per run and let it expire"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 72.1
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 80,
          "payments": 40,
          "reliability": 75,
          "schema": 87,
          "security": 66,
          "transparency": 45
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install @scalekit-sdk/node",
        "http": "TOKEN=$(curl -s -X POST \"$SCALEKIT_ENVIRONMENT_URL/oauth/token\" \\\n  -d client_id=\"$SCALEKIT_CLIENT_ID\" -d client_secret=\"$SCALEKIT_CLIENT_SECRET\" \\\n  -d grant_type=client_credentials | jq -r .access_token)\ncurl -X POST \"$SCALEKIT_ENVIRONMENT_URL/api/v1/connected_accounts/magic_link\" \\\n  -H \"Authorization: Bearer $TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"connection_name\":\"gmail\",\"identifier\":\"user-123\"}'",
        "claudeCode": "claude mcp add --transport http --scope user scalekit https://mcp.scalekit.com",
        "config": {
          "mcpServers": {
            "scalekit": {
              "url": "https://mcp.scalekit.com"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/scalekit-agentkit"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Growth plan",
          "unit": "month",
          "usd": 99,
          "note": "100,000 tool calls included"
        },
        {
          "item": "Tool call above 100,000 on Growth",
          "unit": "call",
          "usd": 0.0005,
          "note": "$0.50 per 1,000"
        },
        {
          "item": "EU data residency add-on",
          "unit": "month",
          "usd": 99,
          "note": "Growth plan"
        }
      ],
      "provenance": {
        "legalEntity": "ScaleKit, Inc.",
        "domain": "scalekit.com",
        "domainRegistered": "2003-04-24",
        "endpointOnVendorDomain": true,
        "terms": "https://www.scalekit.com/legal/terms-of-service",
        "privacy": "https://www.scalekit.com/legal/privacy-policy",
        "statusPage": "https://scalekit.statuspage.io/",
        "changelog": "https://www.scalekit.com/product-updates",
        "securityTxt": "none",
        "checked": "2026-10-02",
        "notes": [
          "The terms and privacy policy (both effective 1 January 2026) name ScaleKit, Inc., with addresses in Redmond, WA and Lewes, DE, under Delaware law.",
          "RDAP shows scalekit.com registered on 2003-04-24, long before the company, so the domain was bought later.",
          "/.well-known/security.txt returned 404 on 2026-09-30. The status page is scalekit.statuspage.io, linked from the site footer. status.scalekit.com serves the dashboard app.",
          "The trust page at https://www.scalekit.com/trust-center states SOC 2 Type 2 and ISO 27001 certification and gives security@scalekit.com for reports."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/scalekit-agentkit.json",
      "live": {
        "slug": "scalekit-agentkit",
        "probe": {
          "target": "https://{env}.scalekit.com",
          "method": "get",
          "lastAt": "2026-10-04T23:48:15.681409196Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 0
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 0
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 0
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 0
            }
          ]
        },
        "vendorStatus": {
          "page": "https://scalekit.statuspage.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:49:27.511383519Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "scalekit-inc/scalekit-sdk-node",
            "version": "v2.18.0",
            "released": "2026-09-29",
            "seenAt": "2026-10-04T16:39:02.534913139Z"
          },
          {
            "registry": "npm",
            "name": "@scalekit-inc/cli",
            "version": "0.3.23",
            "seenAt": "2026-10-04T16:39:01.342000489Z"
          },
          {
            "registry": "npm",
            "name": "@scalekit-sdk/node",
            "version": "2.18.0",
            "seenAt": "2026-10-04T16:39:00.30736538Z"
          },
          {
            "registry": "pypi",
            "name": "scalekit-sdk-python",
            "version": "2.19.1",
            "released": "2026-09-11",
            "seenAt": "2026-10-04T16:39:01.154420887Z"
          }
        ],
        "githubStars": 8,
        "npmWeekly": 10677,
        "pypiWeekly": 10097,
        "securityTxt": {
          "url": "https://scalekit.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:57.375101166Z"
        },
        "llmsTxt": {
          "url": "https://docs.scalekit.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:13.064059136Z"
        },
        "domain": {
          "domain": "scalekit.com",
          "registered": "2003-04-24",
          "source": "https://rdap.verisign.com/com/v1/domain/scalekit.com",
          "checkedAt": "2026-10-04T13:09:01.703612585Z"
        },
        "pages": [
          {
            "url": "https://www.scalekit.com/product-updates",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:10.80505162Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0bfb89bd8ec3"
          },
          {
            "url": "https://www.scalekit.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:08.787466407Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cdf7adf96094"
          },
          {
            "url": "https://www.scalekit.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:04.7487051Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "455fdfe20694"
          },
          {
            "url": "https://www.scalekit.com/legal/terms-of-service",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:06.776239407Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c8437cad75b0"
          }
        ],
        "updatedAt": "2026-10-04T23:49:27.511383519Z"
      }
    },
    "summary": "Scalekit AgentKit has a score of 72.1 (BB) against Auth0 for AI Agents (Token Vault)'s 71.5 (BB). Both do auth oauth. The largest gap is security \u0026 auth, 22 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-scalekit-agentkit",
    "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-scalekit-agentkit.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-scalekit-agentkit.md",
    "slim": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-scalekit-agentkit.min.md"
  },
  "markdown": "Scalekit AgentKit has a score of 72.1 (BB) against Auth0 for AI Agents (Token Vault)'s 71.5 (BB). Both do auth oauth. The largest gap is security \u0026 auth, 22 points.\n\n- Auth0 for AI Agents (Token Vault): grade BB, 71.5/100, rank #82 of 452. Markdown https://www.anchorterminal.com/tools/auth0-ai-agents.md · JSON https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json\n- Scalekit AgentKit: grade BB, 72.1/100, rank #74 of 452. Markdown https://www.anchorterminal.com/tools/scalekit-agentkit.md · JSON https://www.anchorterminal.com/api/v1/tools/scalekit-agentkit.json\n\n## Which one, for what\n\nPick Auth0 for AI Agents (Token Vault) for security \u0026 auth (+22), transparency \u0026 trust (+17).\n\nPick Scalekit AgentKit for schema \u0026 documentation (+14), agent ergonomics (+12), payments \u0026 pricing (+10), maintenance \u0026 community (+6).\n\n## Score by category\n\n| Category | Weight | Auth0 for AI Agents (Token Vault) | Scalekit AgentKit | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 75 | 75 | even |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 73 | 87 | Scalekit AgentKit +14 |\n| Agent ergonomics | 13% (16.2 this run) | 71 | 83 | Scalekit AgentKit +12 |\n| Security \u0026 auth | 14% (17.5 this run) | 88 | 66 | Auth0 for AI Agents (Token Vault) +22 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 40 | Scalekit AgentKit +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 80 | Scalekit AgentKit +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 85 | 68 | Auth0 for AI Agents (Token Vault) +17 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **71.5 · BB** | **72.1 · BB** | |\n\n## Facts side by side\n\n| Fact | Auth0 for AI Agents (Token Vault) | Scalekit AgentKit |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Auth0 by Okta | Scalekit |\n| Hosted endpoint | `https://{tenant}.auth0.com/oauth/token` | `https://{env}.scalekit.com` |\n| Transports | HTTP, stdio | HTTP, Streamable HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 (SDKs), platform closed | MIT (SDKs), platform closed, self-hosted on Enterprise |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | `com.auth0/mcp` | not listed |\n| Last release | 2026-09-18 | 2026-09-29 |\n| Popularity | 16 stars, 3.1k npm/wk | 6 stars, 11k npm/wk |\n| Agent reviews | 3.5/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Auth0 for AI Agents (Token Vault).** Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users.\n\n**Scalekit AgentKit.** 500+ connectors, including remote MCP servers over OAuth 2.1 with DCR. No rate limits or idempotency documented for Scalekit's own API.\n\n## Before you call either\n\n### Auth0 for AI Agents (Token Vault)\n\n1. Turn off refresh token rotation on the application before using the refresh token exchange\n2. Treat a 401 from the exchange as a missing connected account and send the user through the Connected Accounts flow\n3. Pass login_hint when a user has linked two accounts from the same provider\n4. Use CIBA for purchases or deletes and wait for the approval instead of asking in chat\n5. Read X-RateLimit-Reset on a 429 and back off until then\n\n### Scalekit AgentKit\n\n1. Use the exact dashboard Connection Name, not the connector slug, in every call\n2. Call `POST /api/v1/tools:search` with top_k instead of listing every tool\n3. When a connected account isn't ACTIVE, send the user the magic link and stop until they finish\n4. On ScalekitToolRateLimitException, back off before retrying, and log the executionId\n5. Mint a fresh virtual MCP session token per user per run and let it expire\n\n## Other comparisons with Auth0 for AI Agents (Token Vault) or Scalekit AgentKit\n\n- [Arcade.dev vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents.md)\n- [Arcade.dev vs Scalekit AgentKit](https://www.anchorterminal.com/compare/arcade-vs-scalekit-agentkit.md)\n- [Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Auth0 for AI Agents (Token Vault) vs Nango](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango.md)\n- [Auth0 for AI Agents (Token Vault) vs Stytch Connected Apps](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps.md)\n- [Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.md)\n- [Descope Agentic Identity Hub vs Scalekit AgentKit](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit.md)\n- [Keycard vs Scalekit AgentKit](https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md)\n- [Nango vs Scalekit AgentKit](https://www.anchorterminal.com/compare/nango-vs-scalekit-agentkit.md)\n- [Scalekit AgentKit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-stytch-connected-apps.md)\n- [Scalekit AgentKit vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Auth0 for AI Agents (Token Vault) vs Scalekit AgentKit",
        "url": ""
      }
    ],
    "description": "Scalekit AgentKit has a score of 72.1 (BB) against Auth0 for AI Agents (Token Vault)'s 71.5 (BB). Both do auth oauth. The largest gap is security \u0026 auth, 22 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Auth0 for AI Agents (Token Vault) BB 71.5",
      "Scalekit AgentKit BB 72.1",
      "scores"
    ],
    "h1": "Auth0 for AI Agents (Token Vault) vs Scalekit AgentKit",
    "image": "https://www.anchorterminal.com/assets/og/compare-auth0-ai-agents-vs-scalekit-agentkit.png",
    "path": "/compare/auth0-ai-agents-vs-scalekit-agentkit",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Auth0 for AI Agents (Token Vault) vs Scalekit AgentKit for AI agents",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-scalekit-agentkit"
  },
  "tokens": {
    "markdown": 1600,
    "slim": 380
  },
  "version": 1
}
