{
  "data": {
    "a": {
      "slug": "descope-agentic-identity",
      "name": "Descope Agentic Identity Hub",
      "vendor": "Descope",
      "vendorUrl": "https://www.descope.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Descope's identity and access tools for AI agents, built on its customer identity platform.",
      "url": "https://www.anchorterminal.com/tools/descope-agentic-identity",
      "markdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json",
      "repo": "https://github.com/descope/node-sdk",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.descope.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@descope/node-sdk"
        },
        {
          "registry": "npm",
          "name": "@descope/agent-auth"
        },
        {
          "registry": "pypi",
          "name": "descope-agent-auth"
        },
        {
          "registry": "npm",
          "name": "@descope/mcp-express"
        },
        {
          "registry": "pypi",
          "name": "descope"
        }
      ],
      "auth": "mixed",
      "authNotes": "Management calls take `Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY`. An agent can instead sign in as its own OAuth client (client credentials, device code, CIBA or RFC 7523 JWT bearer against /oauth2/v1/token) or present a user's Descope access token in the same header, and Policies then limit which tokens it can fetch. A management key bypasses Policies, and the Agent Auth SDK makes you opt in to use one. Inbound Apps use the shared endpoints `/oauth2/v1/apps/authorize` and `/oauth2/v1/apps/token` with PKCE for public clients.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever is $0 with 7,500 monthly active users, 10 tenants, 3 SSO connections, 10,000 M2M exchanges, 2,000 MACs and 2,000 MATKs, no card. Pro starts at $249 a month billed annually with 10,000 MAU ($0.05 each after), 35 tenants, 5 SSO connections, 50,000 M2M exchanges ($2 per 1,000 after), 5,000 MACs and 5,000 MATKs ($0.05 each after). Growth starts at $799 a month billed annually with 25,000 MAU, 100 tenants, 10 SSO connections, 100,000 M2M exchanges, 10,000 MACs and 10,000 MATKs. Enterprise is custom. A MAC (monthly active consent) is counted when a unique user consents to any scope for a resource at least once in a month, and covers Inbound Apps and MCP auth. A MATK (monthly active token) is any instance where a token is fetched and used, and covers Outbound Apps and Connections (https://www.descope.com/pricing).",
      "priceSummary": "$249 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 67,
        "npmWeekly": 353532,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.descope.com/agentic-identity-hub",
      "llmsTxt": "https://docs.descope.com/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit",
        "hitl.approve"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "llms-txt",
        "typescript",
        "python",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 79.2,
        "grade": "A",
        "agentReady": true,
        "rank": 10,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 80,
          "maintenance": 76,
          "payments": 40,
          "reliability": 100,
          "schema": 82,
          "security": 86,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.",
        "strengths": [
          "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion",
          "Descope as the OAuth authorisation server for your APIs and MCP servers, with DCR, CIBA and token exchange",
          "Policies decide which tokens an agent identity can obtain, evaluated at issuance and exchange",
          "Per-endpoint rate limits, 429 with Retry-After, and an SLA of 99.99 per cent on Pro",
          "Free Forever tier with 2,000 consents and 2,000 token fetches a month, no card"
        ],
        "weaknesses": [
          "No tool catalogue, so you write every provider call yourself",
          "The Agent Auth SDK is 0.1.0 with 18 open pull requests and no commit since 2 July 2026",
          "The docs don't say how vaulted tokens are encrypted",
          "No security.txt and no deprecation policy we could find",
          "Paid plans are billed annually, from $249 a month"
        ],
        "agentNotes": [
          "Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key",
          "Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL",
          "Back off for the full window on a 429, 60 seconds for most management endpoints",
          "Ask for a tenant token, not a user token, for organisation-wide API keys",
          "Budget monthly active tokens, since every token fetched and used counts once a month"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.1,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 79.2
          }
        ],
        "editorialScores": {
          "ergonomics": 80,
          "maintenance": 76,
          "payments": 40,
          "reliability": 100,
          "schema": 82,
          "security": 86,
          "transparency": 49
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install @descope/node-sdk",
        "http": "curl -X POST https://api.descope.com/v1/mgmt/outbound/app/user/token/latest \\\n  -H \"Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"appId\":\"github\",\"userId\":\"user-123\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/descope-agentic-identity"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 249,
          "note": "Starting price, billed annually"
        },
        {
          "item": "Monthly active token (MATK) above the allowance",
          "unit": "call",
          "usd": 0.05,
          "note": "A token fetched and used, counted once a month. Pro and Growth"
        },
        {
          "item": "Monthly active consent (MAC) above the allowance",
          "unit": "account-month",
          "usd": 0.05,
          "note": "A unique user consenting to a resource at least once in a month. Pro and Growth"
        }
      ],
      "provenance": {
        "legalEntity": "Descope, Inc.",
        "domain": "descope.com",
        "domainRegistered": "2016-04-13",
        "endpointOnVendorDomain": true,
        "terms": "https://www.descope.com/legal/terms",
        "privacy": "https://www.descope.com/legal/privacy",
        "statusPage": "https://descopestatus.com",
        "changelog": "https://ideas.descope.works/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "The terms (updated 24 February 2026) contract with Descope, Inc. for US and Canadian customers, Descope Technologies Israel (2022) Ltd. for Israel and Descope Technologies UK (2025) Ltd. elsewhere, under Delaware law.",
          "/.well-known/security.txt returned 404 on 2026-09-30. A vulnerability disclosure policy is linked from descope.com/security-compliance.",
          "The status page is an Instatus page at descopestatus.com.",
          "The changelog lives on the ideas.descope.works portal, off the main domain, and needs JavaScript to render."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.json",
      "live": {
        "slug": "descope-agentic-identity",
        "probe": {
          "target": "https://api.descope.com",
          "method": "get",
          "lastAt": "2026-10-04T22:50:31.656026121Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 113,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 124,
          "p95ms24h": 296,
          "samples24h": 272,
          "samples30d": 887,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 259,
              "ok": 259
            }
          ]
        },
        "vendorStatus": {
          "page": "https://descopestatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:39:56.414035779Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "descope/node-sdk",
            "version": "v2.17.0",
            "released": "2026-09-07",
            "seenAt": "2026-10-04T16:25:34.432882503Z"
          },
          {
            "registry": "npm",
            "name": "@descope/mcp-express",
            "version": "1.6.0",
            "seenAt": "2026-10-04T16:25:32.533673136Z"
          },
          {
            "registry": "npm",
            "name": "@descope/node-sdk",
            "version": "2.17.0",
            "seenAt": "2026-10-04T16:25:30.077963378Z"
          },
          {
            "registry": "pypi",
            "name": "descope",
            "version": "2.14.0",
            "released": "2026-09-07",
            "seenAt": "2026-10-04T16:25:34.348420573Z"
          }
        ],
        "githubStars": 68,
        "npmWeekly": 347658,
        "securityTxt": {
          "url": "https://descope.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:50.5505058Z"
        },
        "llmsTxt": {
          "url": "https://docs.descope.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:30.527628191Z"
        },
        "domain": {
          "domain": "descope.com",
          "registered": "2016-04-13",
          "source": "https://rdap.verisign.com/com/v1/domain/descope.com",
          "checkedAt": "2026-10-04T13:09:53.916089274Z"
        },
        "pages": [
          {
            "url": "https://ideas.descope.works/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:04.44252976Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "df9dfc56ddd7"
          },
          {
            "url": "https://www.descope.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:06.059286057Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a45e89c271ce"
          },
          {
            "url": "https://www.descope.com/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:01.803096328Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b2b659c6dcc"
          },
          {
            "url": "https://www.descope.com/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:04.020978892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d6f39b94f5db"
          }
        ],
        "updatedAt": "2026-10-04T22:50:31.656026121Z"
      }
    },
    "b": {
      "slug": "keycard",
      "name": "Keycard",
      "vendor": "Keycard Labs",
      "vendorUrl": "https://www.keycard.ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Identity and access platform for AI agents.",
      "url": "https://www.anchorterminal.com/tools/keycard",
      "markdownUrl": "https://www.anchorterminal.com/tools/keycard.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keycard.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keycard.json",
      "repo": "https://github.com/keycardai/python-sdk",
      "license": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.keycard.ai",
      "packages": [
        {
          "registry": "pypi",
          "name": "keycardai-mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai-fastmcp"
        },
        {
          "registry": "npm",
          "name": "@keycardai/mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai_api"
        }
      ],
      "auth": "mixed",
      "authNotes": "The management API at api.keycard.ai takes `Authorization: Bearer $KEYCARD_API_KEY` (a service account key). Agents and MCP servers talk OAuth 2.0 to their zone at `https://\u003czone-id\u003e.keycard.cloud`, discovered from `/.well-known/oauth-authorization-server`, with PKCE, dynamic client registration and RFC 8693 token exchange against the token endpoint. Application credentials are a client secret, a web identity (OIDC) or EKS workload identity. Tokens are JWTs verified against the zone's JWKS.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 5,000 transactions a month as a hard cap, unlimited users, agents and apps, RBAC, ABAC and ReBAC policies, 7-day telemetry retention and community support. Team is $500 a month with 100,000 transactions and $1 per 1,000 after, SSO, zone policy, 90-day retention, email support and an SLA. Enterprise is custom on an annual commitment, with org and device-based policy, SCIM, Active Directory and LDAP provisioning, dedicated, BYOC or on-prem deployment, private networking, customer-managed KMS, 180-day retention, a 99.95 per cent uptime SLA and 1-hour 24/7 response on P1 issues. A transaction is recorded each time Keycard issues a credential, validates an access request or exchanges a credential (https://www.keycard.ai/pricing). The page doesn't say whether a card is needed, and its sign-up form ends with a promise to be in touch. The quickstart calls the product Early Access, with sign-up at console.keycard.ai.",
      "priceSummary": "$500 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1,
        "npmWeekly": 52,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.keycard.ai",
      "llmsTxt": "https://docs.keycard.ai/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.3,
        "grade": "C",
        "agentReady": false,
        "rank": 303,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 45
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.",
        "strengths": [
          "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange",
          "Delegated grants with RFC 8693 exchange for GitHub, Google, Slack, Linear and any OAuth 2.0 provider",
          "Session timeline and audit log per exchange, exported hourly to S3 in OCSF Parquet",
          "Published per-unit price ($1 per 1,000 transactions on Team) with a transaction defined",
          "Valid security.txt and SOC 2 Type 2 listed in a SafeBase trust centre"
        ],
        "weaknesses": [
          "Early Access with sign-up by request, and no terms of service page",
          "No per-token kill switch, so a revoked grant lives until the token expires, and revocation doesn't reach the provider",
          "No published rate limits, 429 guidance or public changelog",
          "keycardai-mcp went from 1.0.0 to 2.0.0 in a day in August 2026",
          "Team is $500 a month with nothing between it and the free tier"
        ],
        "agentNotes": [
          "Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone",
          "Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange",
          "Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry",
          "Keep credentials short-lived, because revocation only stops the next issuance",
          "Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.3
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 25
        },
        "provenanceScore": 65
      },
      "connect": {
        "install": "pip install keycardai-mcp",
        "http": "curl \"https://api.keycard.ai/zones/$KEYCARD_ZONE_ID/sessions\" \\\n  -H \"Authorization: Bearer $KEYCARD_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/keycard"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 500,
          "note": "100,000 transactions included"
        },
        {
          "item": "Transactions above 100,000 on Team",
          "unit": "1k-calls",
          "usd": 1,
          "note": "The pricing page doesn't define a transaction"
        }
      ],
      "provenance": {
        "legalEntity": "Keycard Labs, Inc.",
        "domain": "keycard.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://www.keycard.ai/privacy/",
        "statusPage": "https://status.keycard.ai",
        "changelog": "",
        "securityTxt": "valid",
        "checked": "2026-10-02",
        "notes": [
          "The homepage footer names Keycard Labs, Inc., 103 Foulk Road, Suite 202, Wilmington, DE 19808. The footer's legal links on 2 October were privacy, cookie policy, a vulnerability address and the trust centre at trust.keycard.ai. We found no terms of service page (keycard.ai/terms/ returns 404) and the privacy page's body didn't load for us on 30 September or 2 October.",
          "RDAP for keycard.ai returned 404 at rdap.nic.ai and 429 at Identity Digital on 2026-09-30, so the registration date is blank.",
          "status.keycard.ai answers as a status page, though its history renders client-side and its JSON and RSS feeds returned 403 to us on 2 October.",
          "The docs index (73 entries) lists no changelog. The SDK repositories' CHANGELOG.md files are the nearest thing to release notes.",
          "The trust centre lists SOC 2 Type 1 and Type 2 reports and names Resend, Google, GitHub, Cloudflare and AWS as subprocessors."
        ],
        "score": 65
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/keycard.json",
      "live": {
        "slug": "keycard",
        "probe": {
          "target": "https://api.keycard.ai",
          "method": "get",
          "lastAt": "2026-10-04T22:50:34.53518687Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 265,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 280,
          "p95ms24h": 360,
          "samples24h": 272,
          "samples30d": 887,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 259,
              "ok": 259
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.keycard.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:10.814751767Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@keycardai/mcp",
            "version": "2.0.2",
            "seenAt": "2026-10-04T16:30:47.44448777Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-fastmcp",
            "version": "0.7.1",
            "released": "2026-09-15",
            "seenAt": "2026-10-04T16:30:45.543960623Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-mcp",
            "version": "2.3.2",
            "released": "2026-09-16",
            "seenAt": "2026-10-04T16:30:45.360722519Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai_api",
            "version": "0.18.0",
            "released": "2026-09-25",
            "seenAt": "2026-10-04T16:30:48.363651419Z"
          }
        ],
        "githubStars": 1,
        "npmWeekly": 211,
        "pypiWeekly": 179,
        "securityTxt": {
          "url": "https://keycard.ai/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-12T00:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:49.895852699Z"
        },
        "llmsTxt": {
          "url": "https://docs.keycard.ai/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:54.842330743Z"
        },
        "domain": {
          "domain": "keycard.ai",
          "registered": "2024-02-04",
          "source": "https://rdap.identitydigital.services/rdap/domain/keycard.ai",
          "checkedAt": "2026-10-04T13:06:32.92261194Z"
        },
        "pages": [
          {
            "url": "https://www.keycard.ai/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:56.738789549Z",
            "changedAt": "2026-10-03T15:38:49.492444489Z",
            "fingerprint": "7d745cb5c53f"
          },
          {
            "url": "https://www.keycard.ai/privacy/",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:58.814741157Z",
            "changedAt": "2026-10-03T15:38:51.566729092Z",
            "fingerprint": "596ae9dc1660"
          }
        ],
        "updatedAt": "2026-10-04T22:50:34.53518687Z"
      }
    },
    "summary": "Descope Agentic Identity Hub has a score of 79.2 (A) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 65 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard",
    "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md",
    "slim": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.min.md"
  },
  "markdown": "Descope Agentic Identity Hub has a score of 79.2 (A) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 65 points.\n\n- Descope Agentic Identity Hub: grade A, 79.2/100, rank #10 of 452. Markdown https://www.anchorterminal.com/tools/descope-agentic-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json\n- Keycard: grade C, 56.3/100, rank #303 of 452. Markdown https://www.anchorterminal.com/tools/keycard.md · JSON https://www.anchorterminal.com/api/v1/tools/keycard.json\n\n## Which one, for what\n\nPick Descope Agentic Identity Hub for reliability (+65), schema \u0026 documentation (+21), agent ergonomics (+20), payments \u0026 pricing (+10), transparency \u0026 trust (+25).\n\nPick Keycard for nothing in particular (no category where it leads by five points or more).\n\n## Score by category\n\n| Category | Weight | Descope Agentic Identity Hub | Keycard | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 100 | 35 | Descope Agentic Identity Hub +65 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 61 | Descope Agentic Identity Hub +21 |\n| Agent ergonomics | 13% (16.2 this run) | 80 | 60 | Descope Agentic Identity Hub +20 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 86 | even |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 30 | Descope Agentic Identity Hub +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 76 | 79 | Keycard +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 70 | 45 | Descope Agentic Identity Hub +25 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **79.2 · A** | **56.3 · C** | |\n\n## Facts side by side\n\n| Fact | Descope Agentic Identity Hub | Keycard |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Descope | Keycard Labs |\n| Hosted endpoint | `https://api.descope.com` | `https://api.keycard.ai` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (SDKs), platform closed | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-07 | 2026-09-22 |\n| Popularity | 67 stars, 354k npm/wk | 1 stars, 52 npm/wk |\n| Agent reviews | 3.1/5 (8) | 2.5/5 (2) |\n\n## Verdicts\n\n**Descope Agentic Identity Hub.** Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.\n\n**Keycard.** Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.\n\n## Before you call either\n\n### Descope Agentic Identity Hub\n\n1. Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key\n2. Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL\n3. Back off for the full window on a 429, 60 seconds for most management endpoints\n4. Ask for a tenant token, not a user token, for organisation-wide API keys\n5. Budget monthly active tokens, since every token fetched and used counts once a month\n\n### Keycard\n\n1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone\n2. Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange\n3. Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry\n4. Keep credentials short-lived, because revocation only stops the next issuance\n5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart\n\n## Other comparisons with Descope Agentic Identity Hub or Keycard\n\n- [Arcade.dev vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.md)\n- [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md)\n- [Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Nango](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.md)\n- [Descope Agentic Identity Hub vs Scalekit AgentKit](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit.md)\n- [Descope Agentic Identity Hub vs Stytch Connected Apps](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.md)\n- [Descope Agentic Identity Hub vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.md)\n- [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md)\n- [Keycard vs Scalekit AgentKit](https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Descope Agentic Identity Hub vs Keycard",
        "url": ""
      }
    ],
    "description": "Descope Agentic Identity Hub has a score of 79.2 (A) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 65 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Descope Agentic Identity Hub A 79.2",
      "Keycard C 56.3",
      "scores"
    ],
    "h1": "Descope Agentic Identity Hub vs Keycard",
    "image": "https://www.anchorterminal.com/assets/og/compare-descope-agentic-identity-vs-keycard.png",
    "path": "/compare/descope-agentic-identity-vs-keycard",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Descope Agentic Identity Hub vs Keycard for AI agents",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard"
  },
  "tokens": {
    "markdown": 1600,
    "slim": 380
  },
  "version": 1
}
