{
  "data": {
    "a": {
      "slug": "descope-agentic-identity",
      "name": "Descope Agentic Identity Hub",
      "vendor": "Descope",
      "vendorUrl": "https://www.descope.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Descope's identity and access tools for AI agents, built on its customer identity platform.",
      "url": "https://www.anchorterminal.com/tools/descope-agentic-identity",
      "markdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json",
      "repo": "https://github.com/descope/node-sdk",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.descope.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@descope/node-sdk"
        },
        {
          "registry": "npm",
          "name": "@descope/agent-auth"
        },
        {
          "registry": "pypi",
          "name": "descope-agent-auth"
        },
        {
          "registry": "npm",
          "name": "@descope/mcp-express"
        },
        {
          "registry": "pypi",
          "name": "descope"
        }
      ],
      "auth": "mixed",
      "authNotes": "Management calls take `Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY`. An agent can instead sign in as its own OAuth client (client credentials, device code, CIBA or RFC 7523 JWT bearer against /oauth2/v1/token) or present a user's Descope access token in the same header, and Policies then limit which tokens it can fetch. A management key bypasses Policies, and the Agent Auth SDK makes you opt in to use one. Inbound Apps use the shared endpoints `/oauth2/v1/apps/authorize` and `/oauth2/v1/apps/token` with PKCE for public clients.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever is $0 with 7,500 monthly active users, 10 tenants, 3 SSO connections, 10,000 M2M exchanges, 2,000 MACs and 2,000 MATKs, no card. Pro starts at $249 a month billed annually with 10,000 MAU ($0.05 each after), 35 tenants, 5 SSO connections, 50,000 M2M exchanges ($2 per 1,000 after), 5,000 MACs and 5,000 MATKs ($0.05 each after). Growth starts at $799 a month billed annually with 25,000 MAU, 100 tenants, 10 SSO connections, 100,000 M2M exchanges, 10,000 MACs and 10,000 MATKs. Enterprise is custom. A MAC (monthly active consent) is counted when a unique user consents to any scope for a resource at least once in a month, and covers Inbound Apps and MCP auth. A MATK (monthly active token) is any instance where a token is fetched and used, and covers Outbound Apps and Connections (https://www.descope.com/pricing).",
      "priceSummary": "$249 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 67,
        "npmWeekly": 353532,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.descope.com/agentic-identity-hub",
      "llmsTxt": "https://docs.descope.com/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit",
        "hitl.approve"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "llms-txt",
        "typescript",
        "python",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 79.2,
        "grade": "A",
        "agentReady": true,
        "rank": 10,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 80,
          "maintenance": 76,
          "payments": 40,
          "reliability": 100,
          "schema": 82,
          "security": 86,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.",
        "strengths": [
          "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion",
          "Descope as the OAuth authorisation server for your APIs and MCP servers, with DCR, CIBA and token exchange",
          "Policies decide which tokens an agent identity can obtain, evaluated at issuance and exchange",
          "Per-endpoint rate limits, 429 with Retry-After, and an SLA of 99.99 per cent on Pro",
          "Free Forever tier with 2,000 consents and 2,000 token fetches a month, no card"
        ],
        "weaknesses": [
          "No tool catalogue, so you write every provider call yourself",
          "The Agent Auth SDK is 0.1.0 with 18 open pull requests and no commit since 2 July 2026",
          "The docs don't say how vaulted tokens are encrypted",
          "No security.txt and no deprecation policy we could find",
          "Paid plans are billed annually, from $249 a month"
        ],
        "agentNotes": [
          "Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key",
          "Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL",
          "Back off for the full window on a 429, 60 seconds for most management endpoints",
          "Ask for a tenant token, not a user token, for organisation-wide API keys",
          "Budget monthly active tokens, since every token fetched and used counts once a month"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.1,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 79.2
          }
        ],
        "editorialScores": {
          "ergonomics": 80,
          "maintenance": 76,
          "payments": 40,
          "reliability": 100,
          "schema": 82,
          "security": 86,
          "transparency": 49
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install @descope/node-sdk",
        "http": "curl -X POST https://api.descope.com/v1/mgmt/outbound/app/user/token/latest \\\n  -H \"Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"appId\":\"github\",\"userId\":\"user-123\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/descope-agentic-identity"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 249,
          "note": "Starting price, billed annually"
        },
        {
          "item": "Monthly active token (MATK) above the allowance",
          "unit": "call",
          "usd": 0.05,
          "note": "A token fetched and used, counted once a month. Pro and Growth"
        },
        {
          "item": "Monthly active consent (MAC) above the allowance",
          "unit": "account-month",
          "usd": 0.05,
          "note": "A unique user consenting to a resource at least once in a month. Pro and Growth"
        }
      ],
      "provenance": {
        "legalEntity": "Descope, Inc.",
        "domain": "descope.com",
        "domainRegistered": "2016-04-13",
        "endpointOnVendorDomain": true,
        "terms": "https://www.descope.com/legal/terms",
        "privacy": "https://www.descope.com/legal/privacy",
        "statusPage": "https://descopestatus.com",
        "changelog": "https://ideas.descope.works/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "The terms (updated 24 February 2026) contract with Descope, Inc. for US and Canadian customers, Descope Technologies Israel (2022) Ltd. for Israel and Descope Technologies UK (2025) Ltd. elsewhere, under Delaware law.",
          "/.well-known/security.txt returned 404 on 2026-09-30. A vulnerability disclosure policy is linked from descope.com/security-compliance.",
          "The status page is an Instatus page at descopestatus.com.",
          "The changelog lives on the ideas.descope.works portal, off the main domain, and needs JavaScript to render."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.json",
      "live": {
        "slug": "descope-agentic-identity",
        "probe": {
          "target": "https://api.descope.com",
          "method": "get",
          "lastAt": "2026-10-04T23:48:07.457844964Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 219,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 124,
          "p95ms24h": 292,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "vendorStatus": {
          "page": "https://descopestatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:39:56.414035779Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "descope/node-sdk",
            "version": "v2.17.0",
            "released": "2026-09-07",
            "seenAt": "2026-10-04T16:25:34.432882503Z"
          },
          {
            "registry": "npm",
            "name": "@descope/mcp-express",
            "version": "1.6.0",
            "seenAt": "2026-10-04T16:25:32.533673136Z"
          },
          {
            "registry": "npm",
            "name": "@descope/node-sdk",
            "version": "2.17.0",
            "seenAt": "2026-10-04T16:25:30.077963378Z"
          },
          {
            "registry": "pypi",
            "name": "descope",
            "version": "2.14.0",
            "released": "2026-09-07",
            "seenAt": "2026-10-04T16:25:34.348420573Z"
          }
        ],
        "githubStars": 68,
        "npmWeekly": 347658,
        "securityTxt": {
          "url": "https://descope.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:50.5505058Z"
        },
        "llmsTxt": {
          "url": "https://docs.descope.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:30.527628191Z"
        },
        "domain": {
          "domain": "descope.com",
          "registered": "2016-04-13",
          "source": "https://rdap.verisign.com/com/v1/domain/descope.com",
          "checkedAt": "2026-10-04T13:09:53.916089274Z"
        },
        "pages": [
          {
            "url": "https://ideas.descope.works/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:04.44252976Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "df9dfc56ddd7"
          },
          {
            "url": "https://www.descope.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:06.059286057Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a45e89c271ce"
          },
          {
            "url": "https://www.descope.com/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:01.803096328Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b2b659c6dcc"
          },
          {
            "url": "https://www.descope.com/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:04.020978892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d6f39b94f5db"
          }
        ],
        "updatedAt": "2026-10-04T23:48:07.457844964Z"
      }
    },
    "b": {
      "slug": "nango",
      "name": "Nango",
      "vendor": "Nango",
      "vendorUrl": "https://www.nango.dev",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Source-available integration platform that handles OAuth, API keys and token refresh for 1,000+ APIs on behalf of your users.",
      "url": "https://www.anchorterminal.com/tools/nango",
      "markdownUrl": "https://www.anchorterminal.com/tools/nango.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nango.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nango.json",
      "repo": "https://github.com/NangoHQ/nango",
      "license": "Elastic License 2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.nango.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@nangohq/node"
        },
        {
          "registry": "npm",
          "name": "@nangohq/frontend"
        }
      ],
      "auth": "mixed",
      "authNotes": "Backend calls take an environment secret key as `Authorization: Bearer $NANGO_SECRET_KEY`, and API keys can be scoped (agent sessions need `environment:agent_sessions:write`). End users connect through a short-lived connect session token in the Connect UI. An agent session returns its own MCP URL and `session_token`, sent as a Bearer token. The Management MCP at mcp.nango.dev signs in with OAuth.",
      "pricing": "freemium",
      "pricingNotes": "Three plans since 2 September 2026. Free is $0 with 10 connections, 10 compute hours and 10 GB of data transfer a month and no card. Pay-as-you-go is $50 a month returned as $50 of usage credits, then $0.29 per connection a month, $0.72 per compute hour and $0.50 per GB. The Growth add-on is $450 a month and adds faster integration delivery (5 days instead of 20) and a private Slack channel, and the changelog of 2 September also puts RBAC, OpenTelemetry export, Connect UI branding, SAML SSO for your team and a HIPAA BAA under it. Enterprise is custom, with connections from $0.01 at volume, 2-day integration delivery, BYOC and self-hosting, dedicated SLAs, and the pricing page lists HIPAA, SAML SSO, SCIM and the audit trail there (https://www.nango.dev/pricing, https://nango.dev/docs/updates/changelog). Free self-hosting covers auth and proxy only, with no MCP server, syncs or webhooks (https://nango.dev/docs/guides/platform/free-self-hosting).",
      "priceSummary": "$50 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 469086,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://nango.dev/docs",
      "llmsTxt": "https://nango.dev/docs/llms.txt",
      "openapi": "https://raw.githubusercontent.com/NangoHQ/nango/master/docs/spec.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.audit",
        "agent.tools",
        "automation.embedded"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "freemium",
        "free-tier",
        "mcp",
        "llms-txt",
        "openapi",
        "oauth",
        "typescript",
        "webhooks",
        "source-available",
        "enterprise"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.9,
        "grade": "B",
        "agentReady": false,
        "rank": 135,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 90,
          "payments": 40,
          "reliability": 78,
          "schema": 85,
          "security": 67,
          "transparency": 78
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "2026-09-04, CVE-2026-9317 (CVSS 9.2). The runner's tRPC server in Nango before 0.71.6 didn't enforce RUNNER_SECRET_KEY, so anyone who could reach the runner port could run arbitrary JavaScript. Fixed in 0.71.6. Recent and critical, though it needs network access to the runner (https://github.com/advisories/GHSA-9cph-w8mv-q56r)",
          "2026-09-16, CVE-2026-92804 (high). Nango through 0.70.4 didn't validate caller-supplied connection configuration values. Fixed in later releases. Together with the runner flaw we deduct 5, less than the maximum because both are fixed and disclosed (https://github.com/advisories/GHSA-29mm-6vmq-g8cg)"
        ],
        "verdict": "1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.",
        "strengths": [
          "1,000+ APIs with OAuth, API key and client-credentials auth handled",
          "Per-tenant agent sessions served as an MCP server, credentials never shown to the agent",
          "Encryption, retention and deletion rules published in the docs",
          "Per-unit prices in public ($0.29 a connection a month) and a free plan with no card",
          "Source on GitHub under ELv2, 31 open issues against more than 7,000 filed"
        ],
        "weaknesses": [
          "Audit trail only on Enterprise, and logs kept 15 days on every plan",
          "Two CVEs fixed in September 2026, one critical, neither on Nango's own advisory page",
          "Status page tracks a single component",
          "No prompt-injection guidance for content agent sessions pass through",
          "ELv2 bars offering Nango itself as a hosted service"
        ],
        "agentNotes": [
          "Create one agent session per tenant from your backend and pass only the mcp_url and session_token to the agent",
          "Tag connections with your own user and organisation IDs so sessions can select them",
          "Listen for the refresh-failure webhook and send the user a reconnect link instead of retrying",
          "Read the rate-limit headers on a 429 and wait for the reset before resuming",
          "Run 0.71.6 or later when self-hosting, and keep the runner port off the network"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.9
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 90,
          "payments": 40,
          "reliability": 78,
          "schema": 85,
          "security": 67,
          "transparency": 63
        },
        "provenanceScore": 92
      },
      "connect": {
        "install": "npm install @nangohq/node",
        "http": "curl -X POST https://api.nango.dev/connect/sessions -H \"Authorization: Bearer $NANGO_SECRET_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"tags\":{\"end_user_id\":\"user-123\"}}'",
        "claudeCode": "claude mcp add --transport http nango-management --scope user https://mcp.nango.dev/mcp",
        "config": {
          "mcpServers": {
            "nango-management": {
              "url": "https://mcp.nango.dev/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/nango"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pay-as-you-go subscription",
          "unit": "month",
          "usd": 50,
          "note": "Returned as $50 of usage credits each month"
        },
        {
          "item": "Connection on Pay-as-you-go",
          "unit": "account-month",
          "usd": 0.29,
          "note": "Per connected end-user account per month"
        },
        {
          "item": "Data transfer on Pay-as-you-go",
          "unit": "gb",
          "usd": 0.5,
          "note": "10 GB a month free. Compute is $0.72 an hour"
        },
        {
          "item": "Growth add-on",
          "unit": "month",
          "usd": 450,
          "note": "Faster integration delivery, private Slack, RBAC, branding, SAML SSO, HIPAA BAA"
        }
      ],
      "provenance": {
        "legalEntity": "Nango Inc",
        "domain": "nango.dev",
        "domainRegistered": "2022-05-31",
        "endpointOnVendorDomain": true,
        "terms": "https://www.nango.dev/terms",
        "privacy": "https://www.nango.dev/privacy-policy",
        "statusPage": "https://status.nango.dev",
        "changelog": "https://nango.dev/docs/updates/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The legal entity comes from the copyright line in the repository's LICENSE_SHORT, because we couldn't read the terms page on 2026-09-30.",
          "SECURITY.md asks for reports to security@nango.dev or a private GitHub advisory. The Trust Center at trust.nango.dev holds the SOC 2 report.",
          "status.nango.dev is a Better Stack page with one component, Nango Cloud Health."
        ],
        "score": 92
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/nango.json",
      "live": {
        "slug": "nango",
        "probe": {
          "target": "https://api.nango.dev",
          "method": "get",
          "lastAt": "2026-10-04T23:48:12.335933136Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 456,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 448,
          "p95ms24h": 527,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.nango.dev",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:15.983421149Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "NangoHQ/nango",
            "version": "v0.71.12",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:34:17.295643211Z"
          },
          {
            "registry": "npm",
            "name": "@nangohq/frontend",
            "version": "0.71.12",
            "seenAt": "2026-10-04T16:34:15.84943577Z"
          },
          {
            "registry": "npm",
            "name": "@nangohq/node",
            "version": "0.71.12",
            "seenAt": "2026-10-04T16:34:15.032017504Z"
          }
        ],
        "githubStars": 12512,
        "npmWeekly": 605062,
        "securityTxt": {
          "url": "https://nango.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-12-31T23:59:59.000Z",
          "checkedAt": "2026-10-04T15:15:47.082341179Z"
        },
        "llmsTxt": {
          "url": "https://nango.dev/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:02.723630139Z"
        },
        "domain": {
          "domain": "nango.dev",
          "registered": "2022-05-31",
          "source": "https://pubapi.registry.google/rdap/domain/nango.dev",
          "checkedAt": "2026-10-04T13:09:24.044829714Z"
        },
        "pages": [
          {
            "url": "https://nango.dev/docs/updates/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:08.862094314Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5d603945f9f6"
          },
          {
            "url": "https://www.nango.dev/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:25.76214842Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "de303d4e1a64"
          },
          {
            "url": "https://www.nango.dev/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:28.18451084Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2b1d4741bc37"
          },
          {
            "url": "https://www.nango.dev/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:30.200662946Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b8fadd3f9456"
          }
        ],
        "updatedAt": "2026-10-04T23:48:12.335933136Z"
      }
    },
    "summary": "Descope Agentic Identity Hub has a score of 79.2 (A) against Nango's 67.9 (B). Both do auth oauth. The largest gap is reliability, 22 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango",
    "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.md",
    "slim": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.min.md"
  },
  "markdown": "Descope Agentic Identity Hub has a score of 79.2 (A) against Nango's 67.9 (B). Both do auth oauth. The largest gap is reliability, 22 points.\n\n- Descope Agentic Identity Hub: grade A, 79.2/100, rank #10 of 452. Markdown https://www.anchorterminal.com/tools/descope-agentic-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json\n- Nango: grade B, 67.9/100, rank #135 of 452. Markdown https://www.anchorterminal.com/tools/nango.md · JSON https://www.anchorterminal.com/api/v1/tools/nango.json\n\n## Which one, for what\n\nPick Descope Agentic Identity Hub for reliability (+22), agent ergonomics (+6), security \u0026 auth (+19).\n\nPick Nango for maintenance \u0026 community (+14), transparency \u0026 trust (+8).\n\n## Score by category\n\n| Category | Weight | Descope Agentic Identity Hub | Nango | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 100 | 78 | Descope Agentic Identity Hub +22 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 85 | Nango +3 |\n| Agent ergonomics | 13% (16.2 this run) | 80 | 74 | Descope Agentic Identity Hub +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 67 | Descope Agentic Identity Hub +19 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 40 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 76 | 90 | Nango +14 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 70 | 78 | Nango +8 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **79.2 · A** | **67.9 · B** | |\n\n## Facts side by side\n\n| Fact | Descope Agentic Identity Hub | Nango |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Descope | Nango |\n| Hosted endpoint | `https://api.descope.com` | `https://api.nango.dev` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (SDKs), platform closed | Elastic License 2.0 |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-07 | 2026-09-30 |\n| Popularity | 67 stars, 354k npm/wk | 469k npm/wk |\n| Agent reviews | 3.1/5 (8) | 3.5/5 (2) |\n\n## Verdicts\n\n**Descope Agentic Identity Hub.** Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.\n\n**Nango.** 1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.\n\n## Before you call either\n\n### Descope Agentic Identity Hub\n\n1. Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key\n2. Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL\n3. Back off for the full window on a 429, 60 seconds for most management endpoints\n4. Ask for a tenant token, not a user token, for organisation-wide API keys\n5. Budget monthly active tokens, since every token fetched and used counts once a month\n\n### Nango\n\n1. Create one agent session per tenant from your backend and pass only the mcp_url and session_token to the agent\n2. Tag connections with your own user and organisation IDs so sessions can select them\n3. Listen for the refresh-failure webhook and send the user a reconnect link instead of retrying\n4. Read the rate-limit headers on a 429 and wait for the reset before resuming\n5. Run 0.71.6 or later when self-hosting, and keep the runner port off the network\n\n## Other comparisons with Descope Agentic Identity Hub or Nango\n\n- [Arcade.dev vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.md)\n- [Arcade.dev vs Nango](https://www.anchorterminal.com/compare/arcade-vs-nango.md)\n- [Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.md)\n- [Auth0 for AI Agents (Token Vault) vs Nango](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Scalekit AgentKit](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit.md)\n- [Descope Agentic Identity Hub vs Stytch Connected Apps](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.md)\n- [Descope Agentic Identity Hub vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.md)\n- [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md)\n- [Nango vs Scalekit AgentKit](https://www.anchorterminal.com/compare/nango-vs-scalekit-agentkit.md)\n- [Nango vs Stytch Connected Apps](https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps.md)\n- [Nango vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/nango-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Descope Agentic Identity Hub vs Nango",
        "url": ""
      }
    ],
    "description": "Descope Agentic Identity Hub has a score of 79.2 (A) against Nango's 67.9 (B). Both do auth oauth. The largest gap is reliability, 22 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Descope Agentic Identity Hub A 79.2",
      "Nango B 67.9",
      "scores"
    ],
    "h1": "Descope Agentic Identity Hub vs Nango",
    "image": "https://www.anchorterminal.com/assets/og/compare-descope-agentic-identity-vs-nango.png",
    "path": "/compare/descope-agentic-identity-vs-nango",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Descope Agentic Identity Hub vs Nango for AI agents, A 79.2 vs B 67.9",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango"
  },
  "tokens": {
    "markdown": 1500,
    "slim": 330
  },
  "version": 1
}
