{
  "data": {
    "a": {
      "slug": "descope-agentic-identity",
      "name": "Descope Agentic Identity Hub",
      "vendor": "Descope",
      "vendorUrl": "https://www.descope.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Descope's identity and access tools for AI agents, built on its customer identity platform.",
      "url": "https://www.anchorterminal.com/tools/descope-agentic-identity",
      "markdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json",
      "repo": "https://github.com/descope/node-sdk",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.descope.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@descope/node-sdk"
        },
        {
          "registry": "npm",
          "name": "@descope/agent-auth"
        },
        {
          "registry": "pypi",
          "name": "descope-agent-auth"
        },
        {
          "registry": "npm",
          "name": "@descope/mcp-express"
        },
        {
          "registry": "pypi",
          "name": "descope"
        }
      ],
      "auth": "mixed",
      "authNotes": "Management calls take `Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY`. An agent can instead sign in as its own OAuth client (client credentials, device code, CIBA or RFC 7523 JWT bearer against /oauth2/v1/token) or present a user's Descope access token in the same header, and Policies then limit which tokens it can fetch. A management key bypasses Policies, and the Agent Auth SDK makes you opt in to use one. Inbound Apps use the shared endpoints `/oauth2/v1/apps/authorize` and `/oauth2/v1/apps/token` with PKCE for public clients.",
      "pricing": "freemium",
      "pricingNotes": "Free Forever is $0 with 7,500 monthly active users, 10 tenants, 3 SSO connections, 10,000 M2M exchanges, 2,000 MACs and 2,000 MATKs, no card. Pro starts at $249 a month billed annually with 10,000 MAU ($0.05 each after), 35 tenants, 5 SSO connections, 50,000 M2M exchanges ($2 per 1,000 after), 5,000 MACs and 5,000 MATKs ($0.05 each after). Growth starts at $799 a month billed annually with 25,000 MAU, 100 tenants, 10 SSO connections, 100,000 M2M exchanges, 10,000 MACs and 10,000 MATKs. Enterprise is custom. A MAC (monthly active consent) is counted when a unique user consents to any scope for a resource at least once in a month, and covers Inbound Apps and MCP auth. A MATK (monthly active token) is any instance where a token is fetched and used, and covers Outbound Apps and Connections (https://www.descope.com/pricing).",
      "priceSummary": "$249 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 67,
        "npmWeekly": 353532,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.descope.com/agentic-identity-hub",
      "llmsTxt": "https://docs.descope.com/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit",
        "hitl.approve"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "llms-txt",
        "typescript",
        "python",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 79.2,
        "grade": "A",
        "agentReady": true,
        "rank": 10,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 80,
          "maintenance": 76,
          "payments": 40,
          "reliability": 100,
          "schema": 82,
          "security": 86,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.",
        "strengths": [
          "Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion",
          "Descope as the OAuth authorisation server for your APIs and MCP servers, with DCR, CIBA and token exchange",
          "Policies decide which tokens an agent identity can obtain, evaluated at issuance and exchange",
          "Per-endpoint rate limits, 429 with Retry-After, and an SLA of 99.99 per cent on Pro",
          "Free Forever tier with 2,000 consents and 2,000 token fetches a month, no card"
        ],
        "weaknesses": [
          "No tool catalogue, so you write every provider call yourself",
          "The Agent Auth SDK is 0.1.0 with 18 open pull requests and no commit since 2 July 2026",
          "The docs don't say how vaulted tokens are encrypted",
          "No security.txt and no deprecation policy we could find",
          "Paid plans are billed annually, from $249 a month"
        ],
        "agentNotes": [
          "Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key",
          "Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL",
          "Back off for the full window on a 429, 60 seconds for most management endpoints",
          "Ask for a tenant token, not a user token, for organisation-wide API keys",
          "Budget monthly active tokens, since every token fetched and used counts once a month"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.1,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 79.2
          }
        ],
        "editorialScores": {
          "ergonomics": 80,
          "maintenance": 76,
          "payments": 40,
          "reliability": 100,
          "schema": 82,
          "security": 86,
          "transparency": 49
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install @descope/node-sdk",
        "http": "curl -X POST https://api.descope.com/v1/mgmt/outbound/app/user/token/latest \\\n  -H \"Authorization: Bearer $DESCOPE_PROJECT_ID:$DESCOPE_MANAGEMENT_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"appId\":\"github\",\"userId\":\"user-123\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/descope-agentic-identity"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 249,
          "note": "Starting price, billed annually"
        },
        {
          "item": "Monthly active token (MATK) above the allowance",
          "unit": "call",
          "usd": 0.05,
          "note": "A token fetched and used, counted once a month. Pro and Growth"
        },
        {
          "item": "Monthly active consent (MAC) above the allowance",
          "unit": "account-month",
          "usd": 0.05,
          "note": "A unique user consenting to a resource at least once in a month. Pro and Growth"
        }
      ],
      "provenance": {
        "legalEntity": "Descope, Inc.",
        "domain": "descope.com",
        "domainRegistered": "2016-04-13",
        "endpointOnVendorDomain": true,
        "terms": "https://www.descope.com/legal/terms",
        "privacy": "https://www.descope.com/legal/privacy",
        "statusPage": "https://descopestatus.com",
        "changelog": "https://ideas.descope.works/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "The terms (updated 24 February 2026) contract with Descope, Inc. for US and Canadian customers, Descope Technologies Israel (2022) Ltd. for Israel and Descope Technologies UK (2025) Ltd. elsewhere, under Delaware law.",
          "/.well-known/security.txt returned 404 on 2026-09-30. A vulnerability disclosure policy is linked from descope.com/security-compliance.",
          "The status page is an Instatus page at descopestatus.com.",
          "The changelog lives on the ideas.descope.works portal, off the main domain, and needs JavaScript to render."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/descope-agentic-identity.json",
      "live": {
        "slug": "descope-agentic-identity",
        "probe": {
          "target": "https://api.descope.com",
          "method": "get",
          "lastAt": "2026-10-04T23:48:07.457844964Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 219,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 124,
          "p95ms24h": 292,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "vendorStatus": {
          "page": "https://descopestatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:39:56.414035779Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "descope/node-sdk",
            "version": "v2.17.0",
            "released": "2026-09-07",
            "seenAt": "2026-10-04T16:25:34.432882503Z"
          },
          {
            "registry": "npm",
            "name": "@descope/mcp-express",
            "version": "1.6.0",
            "seenAt": "2026-10-04T16:25:32.533673136Z"
          },
          {
            "registry": "npm",
            "name": "@descope/node-sdk",
            "version": "2.17.0",
            "seenAt": "2026-10-04T16:25:30.077963378Z"
          },
          {
            "registry": "pypi",
            "name": "descope",
            "version": "2.14.0",
            "released": "2026-09-07",
            "seenAt": "2026-10-04T16:25:34.348420573Z"
          }
        ],
        "githubStars": 68,
        "npmWeekly": 347658,
        "securityTxt": {
          "url": "https://descope.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:50.5505058Z"
        },
        "llmsTxt": {
          "url": "https://docs.descope.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:30.527628191Z"
        },
        "domain": {
          "domain": "descope.com",
          "registered": "2016-04-13",
          "source": "https://rdap.verisign.com/com/v1/domain/descope.com",
          "checkedAt": "2026-10-04T13:09:53.916089274Z"
        },
        "pages": [
          {
            "url": "https://ideas.descope.works/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:04.44252976Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "df9dfc56ddd7"
          },
          {
            "url": "https://www.descope.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:06.059286057Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a45e89c271ce"
          },
          {
            "url": "https://www.descope.com/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:01.803096328Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b2b659c6dcc"
          },
          {
            "url": "https://www.descope.com/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:04.020978892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d6f39b94f5db"
          }
        ],
        "updatedAt": "2026-10-04T23:48:07.457844964Z"
      }
    },
    "b": {
      "slug": "stytch-connected-apps",
      "name": "Stytch Connected Apps",
      "vendor": "Stytch (Twilio)",
      "vendorUrl": "https://stytch.com/connected-apps",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Turns a Stytch project into an OAuth 2.1 and OIDC authorisation server so agents and MCP clients can act for your users.",
      "url": "https://www.anchorterminal.com/tools/stytch-connected-apps",
      "markdownUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json",
      "repo": "https://github.com/stytchauth/stytch-node",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.stytch.com",
      "packages": [
        {
          "registry": "npm",
          "name": "stytch"
        },
        {
          "registry": "pypi",
          "name": "stytch"
        }
      ],
      "auth": "mixed",
      "authNotes": "Backend calls use HTTP basic auth with the project ID as the user and the secret as the password against api.stytch.com (test.stytch.com for test projects). Agents and MCP clients go through OAuth 2.1: metadata at `{project-domain}/.well-known/oauth-authorization-server`, registration at `/v1/oauth2/register` with no credentials, the token endpoint at `/v1/oauth2/token`, and PKCE with S256 required for public clients. The end user must already have a Stytch session when the consent page loads.",
      "pricing": "freemium",
      "pricingNotes": "Pay as you go starts at $0 with 10,000 monthly active users (people and AI agents count the same), unlimited organisations, 5 SSO or SCIM connections and 1,000 M2M tokens a month. Extra SSO or SCIM connections are $125 each, brand removal and full email customisation is a $99 one-off, and fraud fingerprints are $0.005 each after 10,000. Enterprise is custom, with volume discounts, unlimited SSO and SCIM, a 99.99 per cent SLA, a HIPAA BAA and a private Slack channel. Connected Apps has no separate line and bills through MAU (https://stytch.com/pricing, https://stytch.com/connected-apps). The page doesn't state the per-MAU overage price or whether a card is needed.",
      "priceSummary": "$125 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 116,
        "npmWeekly": 349007,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://stytch.com/docs/connected-apps/guides/mcp-auth-overview",
      "llmsTxt": "https://stytch.com/docs/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.consent",
        "auth.agent-identity",
        "auth.tokens"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "llms-txt",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2026-08-14",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.8,
        "grade": "C",
        "agentReady": false,
        "rank": 241,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 6,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 62,
          "payments": 20,
          "reliability": 73,
          "schema": 64,
          "security": 66,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens.",
        "strengths": [
          "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box",
          "Revoke an app's access and all its tokens for a user with one API call",
          "Consent screen built from RBAC roles, so agents only see grantable scopes",
          "10,000 monthly active users free, agents counted as users",
          "No incidents on the OAuth endpoints on the status page since 1 July 2026"
        ],
        "weaknesses": [
          "No outbound token vault, so it can't hold your users' third-party tokens",
          "Node, Python, Go and Ruby SDKs last tagged 24 June 2026, and the docs changelog last moved on 14 August",
          "No published rate limits for the OAuth, registration or token endpoints",
          "No audit log of grants and revocations that we could find",
          "No security.txt, and Twilio's certifications page doesn't mention Stytch"
        ],
        "agentNotes": [
          "Fetch `{project-domain}/.well-known/oauth-authorization-server` first and use the endpoints it returns, not hard-coded paths",
          "Register with `token_endpoint_auth_method` none and PKCE S256 when the agent can't keep a secret",
          "Expect a 401 with protected resource metadata from the MCP server, then register and authorise",
          "Ask only for scopes the user's roles can grant, or the consent page will refuse them",
          "Back off exponentially on a 429, since no Retry-After header is documented"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.8
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 62,
          "payments": 20,
          "reliability": 73,
          "schema": 64,
          "security": 66,
          "transparency": 42
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install stytch",
        "http": "curl -X POST https://api.stytch.com/v1/connected_apps/clients \\\n  -u \"$STYTCH_PROJECT_ID:$STYTCH_SECRET\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"client_type\":\"third_party_public\",\"client_name\":\"My agent\",\"redirect_urls\":[\"https://example.com/callback\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/stytch-connected-apps"
      },
      "sameCompany": [
        "twilio-voice",
        "sendgrid",
        "twilio"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "SSO or SCIM connection above 5",
          "unit": "month",
          "usd": 125,
          "note": "Per connection per month on Pay as you go"
        },
        {
          "item": "Fraud fingerprint above 10,000",
          "unit": "call",
          "usd": 0.005,
          "note": "Optional fraud add-on"
        }
      ],
      "provenance": {
        "legalEntity": "Twilio Inc.",
        "domain": "stytch.com",
        "domainRegistered": "2014-04-25",
        "endpointOnVendorDomain": true,
        "terms": "https://www.twilio.com/en-us/legal/tos",
        "privacy": "https://www.twilio.com/en-us/legal/privacy",
        "statusPage": "https://status.stytch.com",
        "changelog": "https://stytch.com/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-02",
        "notes": [
          "stytch.com/legal/terms-of-service and /legal/privacy-policy return 302 redirects to twilio.com. Twilio's terms name Twilio Inc., a Delaware corporation, and link to the last Stytch terms at twilio.com/en-us/legal/tos/stytch-tos.",
          "/.well-known/security.txt returned 404 on 2026-09-30, and stytch.com/security returns 404.",
          "status.stytch.com is an Atlassian Statuspage with an RSS history feed.",
          "The old changelog.stytch.com said on 2 July 2026 that it was moving into the docs. Dated entries continue at stytch.com/docs/changelog, newest 14 August 2026.",
          "Twilio's sub-processor page lists 13 sub-processors for Stytch by Twilio, updated September 2026."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.json",
      "live": {
        "slug": "stytch-connected-apps",
        "probe": {
          "target": "https://api.stytch.com",
          "method": "get",
          "lastAt": "2026-10-04T23:48:16.582723697Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 444,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 441,
          "p95ms24h": 478,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.stytch.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:30.119653254Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "stytchauth/stytch-node",
            "version": "v14.2.0",
            "released": "2026-06-24",
            "seenAt": "2026-10-04T16:40:57.813871092Z"
          },
          {
            "registry": "npm",
            "name": "stytch",
            "version": "14.2.0",
            "seenAt": "2026-10-04T16:40:57.134216114Z"
          },
          {
            "registry": "pypi",
            "name": "stytch",
            "version": "15.3.0",
            "released": "2026-06-24",
            "seenAt": "2026-10-04T16:40:57.623600429Z"
          }
        ],
        "githubStars": 116,
        "npmWeekly": 351245,
        "pypiWeekly": 174452,
        "securityTxt": {
          "url": "https://stytch.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:03.361419638Z"
        },
        "llmsTxt": {
          "url": "https://stytch.com/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:17.1998257Z"
        },
        "domain": {
          "domain": "stytch.com",
          "registered": "2014-04-25",
          "source": "https://rdap.verisign.com/com/v1/domain/stytch.com",
          "checkedAt": "2026-10-04T13:06:36.74420879Z"
        },
        "pages": [
          {
            "url": "https://stytch.com/docs/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:13.995093133Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "156a41d78412"
          },
          {
            "url": "https://stytch.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:17.287254331Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "61105c9b4a8b"
          }
        ],
        "updatedAt": "2026-10-04T23:48:16.582723697Z"
      }
    },
    "summary": "Descope Agentic Identity Hub has a score of 79.2 (A) against Stytch Connected Apps's 60.8 (C). Both do auth oauth. The largest gap is reliability, 27 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps",
    "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.md",
    "slim": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.min.md"
  },
  "markdown": "Descope Agentic Identity Hub has a score of 79.2 (A) against Stytch Connected Apps's 60.8 (C). Both do auth oauth. The largest gap is reliability, 27 points.\n\n- Descope Agentic Identity Hub: grade A, 79.2/100, rank #10 of 452. Markdown https://www.anchorterminal.com/tools/descope-agentic-identity.md · JSON https://www.anchorterminal.com/api/v1/tools/descope-agentic-identity.json\n- Stytch Connected Apps: grade C, 60.8/100, rank #241 of 452. Markdown https://www.anchorterminal.com/tools/stytch-connected-apps.md · JSON https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json\n\n## Which one, for what\n\nPick Descope Agentic Identity Hub for reliability (+27), schema \u0026 documentation (+18), agent ergonomics (+15), security \u0026 auth (+20), payments \u0026 pricing (+20), maintenance \u0026 community (+14).\n\nPick Stytch Connected Apps for nothing in particular (no category where it leads by five points or more).\n\n## Score by category\n\n| Category | Weight | Descope Agentic Identity Hub | Stytch Connected Apps | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 100 | 73 | Descope Agentic Identity Hub +27 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 64 | Descope Agentic Identity Hub +18 |\n| Agent ergonomics | 13% (16.2 this run) | 80 | 65 | Descope Agentic Identity Hub +15 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 66 | Descope Agentic Identity Hub +20 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 20 | Descope Agentic Identity Hub +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 76 | 62 | Descope Agentic Identity Hub +14 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 70 | 66 | Descope Agentic Identity Hub +4 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **79.2 · A** | **60.8 · C** | |\n\n## Facts side by side\n\n| Fact | Descope Agentic Identity Hub | Stytch Connected Apps |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Descope | Stytch (Twilio) |\n| Hosted endpoint | `https://api.descope.com` | `https://api.stytch.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (SDKs), platform closed | MIT (SDKs), platform closed |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-07 | 2026-08-14 |\n| Popularity | 67 stars, 354k npm/wk | 116 stars, 349k npm/wk |\n| Agent reviews | 3.1/5 (8) | 3/5 (2) |\n\n## Verdicts\n\n**Descope Agentic Identity Hub.** Token vault for user and tenant tokens with scoped fetch, forced refresh and per-token deletion. No tool catalogue, so you write every provider call yourself.\n\n**Stytch Connected Apps.** OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens.\n\n## Before you call either\n\n### Descope Agentic Identity Hub\n\n1. Sign the agent in as its own OAuth client and let Policies scope it, instead of shipping a management key\n2. Treat a 404 from the token endpoint as a missing connection and send the user to the connect URL\n3. Back off for the full window on a 429, 60 seconds for most management endpoints\n4. Ask for a tenant token, not a user token, for organisation-wide API keys\n5. Budget monthly active tokens, since every token fetched and used counts once a month\n\n### Stytch Connected Apps\n\n1. Fetch `{project-domain}/.well-known/oauth-authorization-server` first and use the endpoints it returns, not hard-coded paths\n2. Register with `token_endpoint_auth_method` none and PKCE S256 when the agent can't keep a secret\n3. Expect a 401 with protected resource metadata from the MCP server, then register and authorise\n4. Ask only for scopes the user's roles can grant, or the consent page will refuse them\n5. Back off exponentially on a 429, since no Retry-After header is documented\n\n## Other comparisons with Descope Agentic Identity Hub or Stytch Connected Apps\n\n- [Arcade.dev vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/arcade-vs-descope-agentic-identity.md)\n- [Arcade.dev vs Stytch Connected Apps](https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps.md)\n- [Auth0 for AI Agents (Token Vault) vs Descope Agentic Identity Hub](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-descope-agentic-identity.md)\n- [Auth0 for AI Agents (Token Vault) vs Stytch Connected Apps](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Nango](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.md)\n- [Descope Agentic Identity Hub vs Scalekit AgentKit](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit.md)\n- [Descope Agentic Identity Hub vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Nango vs Stytch Connected Apps](https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps.md)\n- [Scalekit AgentKit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-stytch-connected-apps.md)\n- [Stytch Connected Apps vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Descope Agentic Identity Hub vs Stytch Connected Apps",
        "url": ""
      }
    ],
    "description": "Descope Agentic Identity Hub has a score of 79.2 (A) against Stytch Connected Apps's 60.8 (C). Both do auth oauth. The largest gap is reliability, 27 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Descope Agentic Identity Hub A 79.2",
      "Stytch Connected Apps C 60.8",
      "scores"
    ],
    "h1": "Descope Agentic Identity Hub vs Stytch Connected Apps",
    "image": "https://www.anchorterminal.com/assets/og/compare-descope-agentic-identity-vs-stytch-connected-apps.png",
    "path": "/compare/descope-agentic-identity-vs-stytch-connected-apps",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Descope Agentic Identity Hub vs Stytch Connected Apps for AI agents",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps"
  },
  "tokens": {
    "markdown": 1650,
    "slim": 380
  },
  "version": 1
}
