{
  "data": {
    "a": {
      "slug": "auth0-ai-agents",
      "name": "Auth0 for AI Agents (Token Vault)",
      "vendor": "Auth0 by Okta",
      "vendorUrl": "https://auth0.com/ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Auth0's identity and authorisation tools for AI agents, built on its identity platform.",
      "url": "https://www.anchorterminal.com/tools/auth0-ai-agents",
      "markdownUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json",
      "repo": "https://github.com/auth0/auth0-ai-js",
      "license": "Apache-2.0 (SDKs), platform closed",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://{tenant}.auth0.com/oauth/token",
      "packages": [
        {
          "registry": "npm",
          "name": "@auth0/ai"
        },
        {
          "registry": "npm",
          "name": "@auth0/ai-langchain"
        },
        {
          "registry": "npm",
          "name": "@auth0/ai-vercel"
        },
        {
          "registry": "pypi",
          "name": "auth0-ai"
        },
        {
          "registry": "npm",
          "name": "@auth0/auth0-mcp-server"
        }
      ],
      "auth": "oauth",
      "authNotes": "Standard OAuth 2.0 and OIDC against your tenant. The app exchanges the user's Auth0 refresh token or access token at /oauth/token with the grant type `urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token` and gets back the external provider's access token. Backend workers can use a signed JWT (privileged worker exchange). DPoP can bind Auth0 tokens to the client. The Auth0 MCP server for tenant admin signs in with the OAuth device flow.",
      "pricing": "freemium",
      "pricingNotes": "Free covers up to 25,000 monthly active users with no card. Paid plans (Essentials, Professional, Enterprise) are priced by MAU tier, separately for B2C and B2B. Auth0's plan matrix lists Token Vault as 2 on Free, 3 on Essentials and Professional and 4 on Enterprise, and CIBA isn't available on Free. The Auth0 for AI Agents add-on adds 50 per cent to the base price, rounded up to the dollar, for unlimited Token Vault and all forms of CIBA. Yearly billing is 11 times the monthly price. Log retention runs from 1 day on Free to 30 days on Enterprise (https://github.com/auth0/docs-v2/blob/main/main/.mintlify/skills/auth0/references/feature-audit-pricing/index.md, https://auth0.com/pricing). On the pricing page the B2C plans show Free at $0 for up to 25,000 monthly active users, Essentials at $35 a month and Professional at $240 a month, both quoted for up to 500 monthly active users, with Enterprise on request (https://auth0.com/pricing).",
      "priceSummary": "Freemium",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 16,
        "npmWeekly": 3114,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://auth0.com/ai/docs",
      "llmsTxt": "https://auth0.com/ai/docs/llms.txt",
      "registryName": "com.auth0/mcp",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "hitl.approve"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "typescript",
        "python",
        "enterprise",
        "mcp"
      ],
      "lastRelease": "2026-09-18",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.5,
        "grade": "BB",
        "agentReady": true,
        "rank": 82,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 74,
          "payments": 30,
          "reliability": 75,
          "schema": 73,
          "security": 88,
          "transparency": 85
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users.",
        "strengths": [
          "Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP",
          "Human approval on a second device for sensitive actions, showing the exact payee or amount",
          "Free plan up to 25,000 monthly active users with no card",
          "Deprecations listed with announcement and end-of-life dates six to seven months apart",
          "Bugcrowd programme, valid security.txt and an Enterprise SLA of 99.99 per cent"
        ],
        "weaknesses": [
          "Only works when Auth0 is the identity provider for your users",
          "Two Token Vault connections on Free and three on Essentials and Professional without the add-on",
          "Log retention of 1 day on Free and 5 days on Essentials is short for an audit trail",
          "No OpenAPI schema for the Authentication API that the exchange uses",
          "Agent SDKs last released in April 2026 (JavaScript) and January 2026 (Python)"
        ],
        "agentNotes": [
          "Turn off refresh token rotation on the application before using the refresh token exchange",
          "Treat a 401 from the exchange as a missing connected account and send the user through the Connected Accounts flow",
          "Pass login_hint when a user has linked two accounts from the same provider",
          "Use CIBA for purchases or deletes and wait for the approval instead of asking in chat",
          "Read X-RateLimit-Reset on a 429 and back off until then"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.5
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 74,
          "payments": 30,
          "reliability": 75,
          "schema": 73,
          "security": 88,
          "transparency": 70
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "npm install @auth0/ai",
        "http": "curl -X POST \"https://$AUTH0_DOMAIN/oauth/token\" \\\n  -d grant_type=urn:auth0:params:oauth:grant-type:token-exchange:federated-connection-access-token \\\n  -d subject_token_type=urn:ietf:params:oauth:token-type:refresh_token \\\n  -d subject_token=\"$AUTH0_REFRESH_TOKEN\" \\\n  -d requested_token_type=http://auth0.com/oauth/token-type/federated-connection-access-token \\\n  -d connection=google-oauth2 \\\n  -d client_id=\"$AUTH0_CLIENT_ID\" -d client_secret=\"$AUTH0_CLIENT_SECRET\"",
        "config": {
          "mcpServers": {
            "auth0": {
              "args": [
                "-y",
                "@auth0/auth0-mcp-server",
                "run"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/auth0-ai-agents"
      },
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Okta, Inc.",
        "domain": "auth0.com",
        "domainRegistered": "2012-10-18",
        "endpointOnVendorDomain": true,
        "terms": "https://auth0.com/legal",
        "privacy": "https://www.okta.com/privacy-policy/",
        "statusPage": "https://status.auth0.com",
        "changelog": "https://auth0.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "notes": [
          "We couldn't read the terms page on 2026-09-30.",
          "The Auth0 MCP server (@auth0/auth0-mcp-server, version 0.1.0-beta.19) manages your tenant. It isn't how an agent gets user tokens."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/auth0-ai-agents.json",
      "live": {
        "slug": "auth0-ai-agents",
        "probe": {
          "target": "https://{tenant}.auth0.com/oauth/token",
          "method": "get",
          "lastAt": "2026-10-04T23:32:43.379315049Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 272,
          "samples30d": 895,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 0
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 0
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 0
            },
            {
              "date": "2026-10-04",
              "probes": 267,
              "ok": 0
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.auth0.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:39:49.238514327Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "auth0/auth0-ai-js",
            "version": "@auth0/ai-vercel-v5.1.1",
            "released": "2026-04-22",
            "seenAt": "2026-10-04T16:21:15.912325367Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.auth0/mcp",
            "version": "0.1.0-beta.10",
            "seenAt": "2026-10-03T23:29:28.630222764Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai",
            "version": "6.0.2",
            "seenAt": "2026-10-04T16:21:08.539398106Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai-langchain",
            "version": "5.0.2",
            "seenAt": "2026-10-04T16:21:10.728760999Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/ai-vercel",
            "version": "5.1.1",
            "seenAt": "2026-10-04T16:21:11.90752887Z"
          },
          {
            "registry": "npm",
            "name": "@auth0/auth0-mcp-server",
            "version": "0.1.0-beta.19",
            "seenAt": "2026-10-04T16:21:14.12298902Z"
          },
          {
            "registry": "pypi",
            "name": "auth0-ai",
            "version": "1.0.2",
            "released": "2026-01-20",
            "seenAt": "2026-10-04T16:21:13.941984722Z"
          }
        ],
        "githubStars": 16,
        "npmWeekly": 2628,
        "pypiWeekly": 281,
        "securityTxt": {
          "url": "https://auth0.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-01-01T08:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:55.13396602Z"
        },
        "llmsTxt": {
          "url": "https://auth0.com/ai/docs/llms.txt",
          "ok": false,
          "status": 404,
          "checkedAt": "2026-10-04T15:17:16.736611989Z"
        },
        "domain": {
          "domain": "auth0.com",
          "registered": "2012-10-18",
          "source": "https://rdap.verisign.com/com/v1/domain/auth0.com",
          "checkedAt": "2026-10-04T13:06:20.951498912Z"
        },
        "pages": [
          {
            "url": "https://auth0.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:41:20.178814118Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2ecd4d6660eb"
          },
          {
            "url": "https://auth0.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:41:22.566960863Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8730de5a8d15"
          },
          {
            "url": "https://raw.githubusercontent.com/auth0/docs-v2/main/main/.mintlify/skills/auth0/references/feature-audit-pricing/index.md",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:29.254754697Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d3bbfc00df65"
          },
          {
            "url": "https://www.okta.com/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:51:31.687421551Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "be09b03a3016"
          },
          {
            "url": "https://auth0.com/legal",
            "kind": "terms",
            "status": 0,
            "checkedAt": "2026-10-04T15:41:22.56694968Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-04T23:32:43.379315049Z"
      }
    },
    "b": {
      "slug": "workos-pipes",
      "name": "WorkOS Pipes and Agents",
      "vendor": "WorkOS",
      "vendorUrl": "https://workos.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "WorkOS tools for connecting agents to third-party accounts, managing access tokens and assigning revocable agent identities.",
      "url": "https://www.anchorterminal.com/tools/workos-pipes",
      "markdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/workos-pipes.json",
      "repo": "https://github.com/workos/workos-node",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.workos.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@workos-inc/node"
        },
        {
          "registry": "pypi",
          "name": "workos"
        }
      ],
      "auth": "mixed",
      "authNotes": "Server calls take the secret key as `Authorization: Bearer $WORKOS_API_KEY` (`sk_...`). End users connect accounts through the Pipes widget or an authorisation URL from `/data-integrations/{slug}/authorize`, which must be opened in the browser, not fetched. Agent tokens are minted from a blueprint as user-delegated, autonomous or agent-delegated sessions. The WorkOS MCP server signs in with OAuth as a dashboard user, with no API key.",
      "pricing": "freemium",
      "pricingNotes": "Pay as you go, with no card to start and a card before production. AuthKit is free up to 1,000,000 monthly active users, then $2,500 a month per extra million. SSO and Directory Sync connections are $125 a month each for the first 15, $100 for 16 to 30, $80 for 31 to 50 and $65 for 51 to 100. Audit Logs are free at the base, with $125 a month per SIEM connection and $99 a month per million events stored. Radar is free for 1,000 checks, then $100 per 50,000. A custom domain is $99 a month. Annual credits plans add volume discounts and a 99.99 per cent SLA (https://workos.com/pricing). Pipes and Agents don't appear on the pricing page, so we don't know what a connection or an agent session costs.",
      "priceSummary": "$125 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 221,
        "npmWeekly": 4041570,
        "pypiWeekly": 1697594,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://workos.com/docs/pipes",
      "registryName": "com.workos/mcp",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "typescript",
        "python",
        "enterprise",
        "webhooks"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60,
        "grade": "C",
        "agentReady": false,
        "rank": 256,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 83,
          "payments": 10,
          "reliability": 70,
          "schema": 53,
          "security": 69,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.",
        "strengths": [
          "Agent identity with per-session revocation and token lifetimes set per blueprint",
          "Pipes covers 500+ providers with user-owned and organisation-owned connections by OAuth, API key or client credentials",
          "Published rate limits of 6,000 requests a minute per key, with Retry-After on a 429",
          "Same platform for SSO, directory sync, RBAC, Audit Logs and Vault",
          "SOC 2 Type 2, a public subprocessor list and a 99.99 per cent SLA on annual plans"
        ],
        "weaknesses": [
          "21 incidents on the status page since 3 July 2026, several over an hour",
          "Pipes and Agents aren't on the pricing page",
          "Deleting a connected account doesn't revoke the grant at the provider",
          "Breaking Pipes change in SDK 11.0.0 on 28 September 2026",
          "No OpenAPI file, llms.txt or security.txt we could find"
        ],
        "agentNotes": [
          "Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token",
          "Branch on `active` in the response and send the user to reconnect on `needs_reauthorization`",
          "Wait for Retry-After on a 429, or back off with jitter when it's missing",
          "Use lower-case provider slugs such as github or slack",
          "Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 83,
          "payments": 10,
          "reliability": 70,
          "schema": 53,
          "security": 69,
          "transparency": 37
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install @workos-inc/node",
        "http": "curl -X POST https://api.workos.com/data-integrations/github/token -H \"Authorization: Bearer $WORKOS_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"user_id\":\"user_01EHZNVPK3SFK441A1RGBFSHRT\"}'",
        "claudeCode": "claude mcp add --transport http --scope user workos https://mcp.workos.com/mcp",
        "config": {
          "mcpServers": {
            "workos": {
              "url": "https://mcp.workos.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/workos-pipes"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "SSO or Directory Sync connection (first 15)",
          "unit": "month",
          "usd": 125,
          "note": "Per connection per month, falling to $65 above 50"
        },
        {
          "item": "Audit Logs SIEM connection",
          "unit": "month",
          "usd": 125,
          "note": "Plus $99 a month per million events stored"
        },
        {
          "item": "Custom domain",
          "unit": "month",
          "usd": 99,
          "note": "AuthKit, Admin Portal and email sender"
        }
      ],
      "provenance": {
        "legalEntity": "WorkOS, Inc.",
        "domain": "workos.com",
        "domainRegistered": "2005-02-02",
        "endpointOnVendorDomain": true,
        "terms": "https://workos.com/legal/terms",
        "privacy": "https://workos.com/legal/privacy",
        "statusPage": "https://status.workos.com",
        "changelog": "https://github.com/workos/workos-node/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The website terms (effective 29 October 2020) name WorkOS, Inc. and California law. The privacy policy was updated 20 October 2025 and doesn't say where data is stored.",
          "RDAP shows workos.com registered on 2005-02-02, years before the company, so the domain was bought later.",
          "/.well-known/security.txt returned 404 on 2026-09-30."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/workos-pipes.json",
      "live": {
        "slug": "workos-pipes",
        "probe": {
          "target": "https://api.workos.com",
          "method": "get",
          "lastAt": "2026-10-04T23:32:56.84607093Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 117,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 128,
          "p95ms24h": 187,
          "samples24h": 272,
          "samples30d": 895,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 267,
              "ok": 267
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.workos.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:28:05.691657187Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "workos/workos-node",
            "version": "v11.0.0",
            "released": "2026-09-28",
            "seenAt": "2026-10-04T16:44:14.997893727Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.workos/mcp",
            "version": "1.0.0",
            "seenAt": "2026-10-03T23:29:28.630222764Z"
          },
          {
            "registry": "npm",
            "name": "@workos-inc/node",
            "version": "11.0.0",
            "seenAt": "2026-10-04T16:44:14.113290354Z"
          },
          {
            "registry": "pypi",
            "name": "workos",
            "version": "10.5.0",
            "released": "2026-09-24",
            "seenAt": "2026-10-04T16:44:14.80123694Z"
          }
        ],
        "githubStars": 223,
        "npmWeekly": 4341866,
        "pypiWeekly": 1819216,
        "securityTxt": {
          "url": "https://workos.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:42.791540879Z"
        },
        "domain": {
          "domain": "workos.com",
          "registered": "2005-02-02",
          "source": "https://rdap.verisign.com/com/v1/domain/workos.com",
          "checkedAt": "2026-10-04T13:09:49.925296041Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/workos/workos-node/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:01.225770024Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "57d8be278609"
          },
          {
            "url": "https://workos.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:58.671443903Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0cdd6961c090"
          },
          {
            "url": "https://workos.com/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:54.606253176Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5fc970fc9d08"
          },
          {
            "url": "https://workos.com/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:56.692868313Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b3130dd8035"
          }
        ],
        "updatedAt": "2026-10-04T23:32:56.84607093Z"
      }
    },
    "summary": "Auth0 for AI Agents (Token Vault) has a score of 71.5 (BB) against WorkOS Pipes and Agents's 60 (C). Both do auth oauth. The largest gap is transparency \u0026 trust, 21 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes",
    "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.md",
    "slim": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.min.md"
  },
  "markdown": "Auth0 for AI Agents (Token Vault) has a score of 71.5 (BB) against WorkOS Pipes and Agents's 60 (C). Both do auth oauth. The largest gap is transparency \u0026 trust, 21 points.\n\n- Auth0 for AI Agents (Token Vault): grade BB, 71.5/100, rank #82 of 452. Markdown https://www.anchorterminal.com/tools/auth0-ai-agents.md · JSON https://www.anchorterminal.com/api/v1/tools/auth0-ai-agents.json\n- WorkOS Pipes and Agents: grade C, 60/100, rank #256 of 452. Markdown https://www.anchorterminal.com/tools/workos-pipes.md · JSON https://www.anchorterminal.com/api/v1/tools/workos-pipes.json\n\n## Which one, for what\n\nPick Auth0 for AI Agents (Token Vault) for reliability (+5), schema \u0026 documentation (+20), security \u0026 auth (+19), payments \u0026 pricing (+20), transparency \u0026 trust (+21).\n\nPick WorkOS Pipes and Agents for maintenance \u0026 community (+9).\n\n## Score by category\n\n| Category | Weight | Auth0 for AI Agents (Token Vault) | WorkOS Pipes and Agents | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 75 | 70 | Auth0 for AI Agents (Token Vault) +5 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 73 | 53 | Auth0 for AI Agents (Token Vault) +20 |\n| Agent ergonomics | 13% (16.2 this run) | 71 | 69 | Auth0 for AI Agents (Token Vault) +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 88 | 69 | Auth0 for AI Agents (Token Vault) +19 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 10 | Auth0 for AI Agents (Token Vault) +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 83 | WorkOS Pipes and Agents +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 85 | 64 | Auth0 for AI Agents (Token Vault) +21 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **71.5 · BB** | **60 · C** | |\n\n## Facts side by side\n\n| Fact | Auth0 for AI Agents (Token Vault) | WorkOS Pipes and Agents |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Auth0 by Okta | WorkOS |\n| Hosted endpoint | `https://{tenant}.auth0.com/oauth/token` | `https://api.workos.com` |\n| Transports | HTTP, stdio | HTTP, Streamable HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 (SDKs), platform closed | MIT (SDKs), platform closed |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | `com.auth0/mcp` | `com.workos/mcp` |\n| Last release | 2026-09-18 | 2026-09-28 |\n| Popularity | 16 stars, 3.1k npm/wk | 221 stars, 4M npm/wk, 1.7M PyPI/wk |\n| Agent reviews | 3.5/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Auth0 for AI Agents (Token Vault).** Standard grants throughout, RFC 8693 token exchange, CIBA with RAR and DPoP. Only works when Auth0 is the identity provider for your users.\n\n**WorkOS Pipes and Agents.** Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.\n\n## Before you call either\n\n### Auth0 for AI Agents (Token Vault)\n\n1. Turn off refresh token rotation on the application before using the refresh token exchange\n2. Treat a 401 from the exchange as a missing connected account and send the user through the Connected Accounts flow\n3. Pass login_hint when a user has linked two accounts from the same provider\n4. Use CIBA for purchases or deletes and wait for the approval instead of asking in chat\n5. Read X-RateLimit-Reset on a 429 and back off until then\n\n### WorkOS Pipes and Agents\n\n1. Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token\n2. Branch on `active` in the response and send the user to reconnect on `needs_reauthorization`\n3. Wait for Retry-After on a 429, or back off with jitter when it's missing\n4. Use lower-case provider slugs such as github or slack\n5. Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry\n\n## Other comparisons with Auth0 for AI Agents (Token Vault) or WorkOS Pipes and Agents\n\n- [Arcade.dev vs Auth0 for AI Agents (Token Vault)](https://www.anchorterminal.com/compare/arcade-vs-auth0-ai-agents.md)\n- [Arcade.dev vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.md)\n- [Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Auth0 for AI Agents (Token Vault) vs Nango](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango.md)\n- [Auth0 for AI Agents (Token Vault) vs Scalekit AgentKit](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-scalekit-agentkit.md)\n- [Auth0 for AI Agents (Token Vault) vs Stytch Connected Apps](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps.md)\n- [Descope Agentic Identity Hub vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.md)\n- [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)\n- [Nango vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/nango-vs-workos-pipes.md)\n- [Scalekit AgentKit vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-workos-pipes.md)\n- [Stytch Connected Apps vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents",
        "url": ""
      }
    ],
    "description": "Auth0 for AI Agents (Token Vault) has a score of 71.5 (BB) against WorkOS Pipes and Agents's 60 (C). Both do auth oauth. The largest gap is transparency \u0026 trust, 21 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Auth0 for AI Agents (Token Vault) BB 71.5",
      "WorkOS Pipes and Agents C 60",
      "scores"
    ],
    "h1": "Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents",
    "image": "https://www.anchorterminal.com/assets/og/compare-auth0-ai-agents-vs-workos-pipes.png",
    "path": "/compare/auth0-ai-agents-vs-workos-pipes",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes"
  },
  "tokens": {
    "markdown": 1600,
    "slim": 380
  },
  "version": 1
}
