{
  "data": {
    "a": {
      "slug": "keycard",
      "name": "Keycard",
      "vendor": "Keycard Labs",
      "vendorUrl": "https://www.keycard.ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Identity and access platform for AI agents.",
      "url": "https://www.anchorterminal.com/tools/keycard",
      "markdownUrl": "https://www.anchorterminal.com/tools/keycard.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keycard.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keycard.json",
      "repo": "https://github.com/keycardai/python-sdk",
      "license": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.keycard.ai",
      "packages": [
        {
          "registry": "pypi",
          "name": "keycardai-mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai-fastmcp"
        },
        {
          "registry": "npm",
          "name": "@keycardai/mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai_api"
        }
      ],
      "auth": "mixed",
      "authNotes": "The management API at api.keycard.ai takes `Authorization: Bearer $KEYCARD_API_KEY` (a service account key). Agents and MCP servers talk OAuth 2.0 to their zone at `https://\u003czone-id\u003e.keycard.cloud`, discovered from `/.well-known/oauth-authorization-server`, with PKCE, dynamic client registration and RFC 8693 token exchange against the token endpoint. Application credentials are a client secret, a web identity (OIDC) or EKS workload identity. Tokens are JWTs verified against the zone's JWKS.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 5,000 transactions a month as a hard cap, unlimited users, agents and apps, RBAC, ABAC and ReBAC policies, 7-day telemetry retention and community support. Team is $500 a month with 100,000 transactions and $1 per 1,000 after, SSO, zone policy, 90-day retention, email support and an SLA. Enterprise is custom on an annual commitment, with org and device-based policy, SCIM, Active Directory and LDAP provisioning, dedicated, BYOC or on-prem deployment, private networking, customer-managed KMS, 180-day retention, a 99.95 per cent uptime SLA and 1-hour 24/7 response on P1 issues. A transaction is recorded each time Keycard issues a credential, validates an access request or exchanges a credential (https://www.keycard.ai/pricing). The page doesn't say whether a card is needed, and its sign-up form ends with a promise to be in touch. The quickstart calls the product Early Access, with sign-up at console.keycard.ai.",
      "priceSummary": "$500 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1,
        "npmWeekly": 52,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.keycard.ai",
      "llmsTxt": "https://docs.keycard.ai/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.2,
        "grade": "C",
        "agentReady": false,
        "rank": 492,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 44
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.",
        "bestFor": "A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product.",
        "strengths": [
          "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange",
          "Delegated grants with RFC 8693 exchange for GitHub, Google, Slack, Linear and any OAuth 2.0 provider",
          "Session timeline and audit log per exchange, exported hourly to S3 in OCSF Parquet",
          "Published per-unit price ($1 per 1,000 transactions on Team) with a transaction defined",
          "Valid security.txt and SOC 2 Type 2 listed in a SafeBase trust centre"
        ],
        "weaknesses": [
          "Early Access with sign-up by request, and no terms of service page",
          "No per-token kill switch, so a revoked grant lives until the token expires, and revocation doesn't reach the provider",
          "No published rate limits, 429 guidance or public changelog",
          "keycardai-mcp went from 1.0.0 to 2.0.0 in a day in August 2026",
          "Team is $500 a month with nothing between it and the free tier"
        ],
        "agentNotes": [
          "Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone",
          "Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange",
          "Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry",
          "Keep credentials short-lived, because revocation only stops the next issuance",
          "Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.2
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 25
        },
        "provenanceScore": 62
      },
      "connect": {
        "install": "pip install keycardai-mcp",
        "http": "curl \"https://api.keycard.ai/zones/$KEYCARD_ZONE_ID/sessions\" \\\n  -H \"Authorization: Bearer $KEYCARD_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/keycard"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 500,
          "note": "100,000 transactions included"
        },
        {
          "item": "Transactions above 100,000 on Team",
          "unit": "1k-calls",
          "usd": 1,
          "note": "The pricing page doesn't define a transaction"
        }
      ],
      "provenance": {
        "legalEntity": "Keycard Labs, Inc.",
        "domain": "keycard.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://www.keycard.ai/privacy/",
        "statusPage": "https://status.keycard.ai",
        "changelog": "",
        "securityTxt": "valid",
        "checked": "2026-10-02",
        "notes": [
          "The homepage footer names Keycard Labs, Inc., 103 Foulk Road, Suite 202, Wilmington, DE 19808. The footer's legal links on 2 October were privacy, cookie policy, a vulnerability address and the trust centre at trust.keycard.ai. We found no terms of service page (keycard.ai/terms/ returns 404) and the privacy page's body didn't load for us on 30 September or 2 October.",
          "RDAP for keycard.ai returned 404 at rdap.nic.ai and 429 at Identity Digital on 2026-09-30, so the registration date is blank.",
          "status.keycard.ai answers as a status page, though its history renders client-side and its JSON and RSS feeds returned 403 to us on 2 October.",
          "The docs index (73 entries) lists no changelog. The SDK repositories' CHANGELOG.md files are the nearest thing to release notes.",
          "The trust centre lists SOC 2 Type 1 and Type 2 reports and names Resend, Google, GitHub, Cloudflare and AWS as subprocessors."
        ],
        "score": 62
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/keycard.json",
      "live": {
        "slug": "keycard",
        "probe": {
          "target": "https://api.keycard.ai",
          "method": "get",
          "lastAt": "2026-10-08T19:52:53.312782283Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 302,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 299,
          "p95ms24h": 385,
          "samples24h": 272,
          "samples30d": 1941,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 225,
              "ok": 225
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.keycard.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:43.424506056Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@keycardai/mcp",
            "version": "2.0.2",
            "seenAt": "2026-10-08T16:17:39.557981658Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-fastmcp",
            "version": "0.7.1",
            "released": "2026-09-15",
            "seenAt": "2026-10-08T16:17:37.664040081Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-mcp",
            "version": "2.3.2",
            "released": "2026-09-16",
            "seenAt": "2026-10-08T16:17:37.473812095Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai_api",
            "version": "0.18.0",
            "released": "2026-09-25",
            "seenAt": "2026-10-08T16:17:43.121407528Z"
          }
        ],
        "githubStars": 1,
        "npmWeekly": 199,
        "pypiWeekly": 164,
        "securityTxt": {
          "url": "https://keycard.ai/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-12T00:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:48.873310409Z"
        },
        "llmsTxt": {
          "url": "https://docs.keycard.ai/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:33.244940883Z"
        },
        "domain": {
          "domain": "keycard.ai",
          "registered": "2024-02-04",
          "source": "https://rdap.identitydigital.services/rdap/domain/keycard.ai",
          "checkedAt": "2026-10-04T13:06:32.92261194Z"
        },
        "pages": [
          {
            "url": "https://www.keycard.ai/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:36.483812542Z",
            "changedAt": "2026-10-08T18:28:36.483812542Z",
            "fingerprint": "ebe4ceb994c4"
          },
          {
            "url": "https://www.keycard.ai/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:38.627980953Z",
            "changedAt": "2026-10-08T18:28:38.627980953Z",
            "fingerprint": "5d00b76169d9"
          }
        ],
        "updatedAt": "2026-10-08T19:52:53.312782283Z"
      }
    },
    "answer": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 5 of 7 scored categories. Keycard leads on payments \u0026 pricing.",
    "b": {
      "slug": "microsoft-entra-agent-id",
      "name": "Microsoft Entra Agent ID",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph.",
      "url": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json",
      "repo": "https://github.com/AzureAD/microsoft-identity-web",
      "license": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
      "packages": [
        {
          "registry": "nuget",
          "name": "Microsoft.Identity.Web.AgentIdentities"
        }
      ],
      "auth": "oauth",
      "authNotes": "Access starts with a Microsoft Entra tenant and a person holding the Agent ID Developer or Agent ID Administrator role, who creates an agent identity blueprint. The blueprint authenticates to login.microsoftonline.com with a managed identity, a certificate or a client secret (Microsoft advises against secrets in production) and exchanges for a token as one of its agent identities. Agent identities hold no credentials. Three flows exist, which are app-only, on behalf of a signed-in user, and as the agent's own user account. Interactive `/authorize` and public clients aren't supported. Management calls on Microsoft Graph need AgentIdentity.Create.All or AgentIdentity.ReadWrite.All.",
      "pricing": "freemium",
      "pricingNotes": "Microsoft's docs say Agent ID is available to all Microsoft Entra customers, and Entra ID Free comes with any Microsoft cloud subscription. No per-agent price is published. Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15.00 a user a month on yearly billing, or Microsoft 365 E7 at $99.00. Conditional Access for agents also needs Entra P1 or Microsoft 365 E3 alongside Agent 365. No sandbox was found in the Agent ID docs (https://www.microsoft.com/en-us/microsoft-agent-365, checked 2026-10-08).",
      "priceSummary": "$15 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Agent ID docs, the Graph reference or the pricing pages (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 787,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.agent-identity",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "oauth",
        "openapi",
        "dotnet",
        "sidecar",
        "microsoft-graph",
        "mcp",
        "freemium",
        "sla"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 63,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 74
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.",
        "bestFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
        "strengths": [
          "Agent identities can't hold credentials. The blueprint authenticates with a managed identity, certificate or secret and exchanges for the agent's token",
          "Global Administrator and similar roles, and Graph permissions such as Application.ReadWrite.All, are refused for agent identities",
          "Create, list, update, delete and restore are on Microsoft Graph v1.0, with agentIdentity in the public OpenAPI file",
          "Audit and sign-in logs carry an agentType and blueprintId for agent activity",
          "Microsoft.Identity.Web 4.16.0 shipped on 30 September 2026, the eighth tagged release since 9 July"
        ],
        "weaknesses": [
          "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing",
          "Microsoft's docs call hand-written token exchange complex and error-prone and steer developers to a .NET library or a sidecar container",
          "Creating a blueprint, a principal and an identity in quick succession can fail with 400 until the directory replicates",
          "Audit and sign-in logs are kept seven days on Entra ID Free and 30 days on P1 or P2",
          "microsoft.com's security.txt passed its Expires date on 23 September 2026"
        ],
        "agentNotes": [
          "Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token",
          "Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object",
          "Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required",
          "Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page",
          "Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.4
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 63
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "dotnet add package Microsoft.Identity.Web.AgentIdentities",
        "http": "curl -X POST https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity \\\n  -H \"Authorization: Bearer $BLUEPRINT_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"displayName\": \"My Agent Identity\", \"agentIdentityBlueprintId\": \"\u003cblueprint-app-id\u003e\", \"sponsors@odata.bind\": [\"https://graph.microsoft.com/v1.0/users/\u003cid\u003e\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/microsoft-entra-agent-id"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Microsoft Agent 365",
          "unit": "seat-month",
          "usd": 15,
          "note": "billed yearly, needed for Conditional Access, ID Protection and governance for agents"
        },
        {
          "item": "Microsoft 365 E7 (includes Agent 365)",
          "unit": "seat-month",
          "usd": 99,
          "note": "billed yearly"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://www.microsoft.com/en-us/privacy/privacystatement",
        "statusPage": "https://azure.status.microsoft/en-us/status/history/",
        "changelog": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.",
          "The Microsoft APIs terms of use cover the Microsoft Graph API and other APIs that reach directory data, and were last updated in October 2025. Tenant use of Entra also falls under the customer's Microsoft licensing agreement and the Product Terms, which we didn't read.",
          "The Microsoft privacy statement was last updated in September 2026.",
          "Tokens come from login.microsoftonline.com and management calls go to graph.microsoft.com, both Microsoft domains.",
          "Entra's SLA page sends readers to the Azure status history for incidents that affect Entra ID.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.json",
      "live": {
        "slug": "microsoft-entra-agent-id",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
          "method": "get",
          "lastAt": "2026-10-08T19:52:56.035923923Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 30,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 32,
          "p95ms24h": 97,
          "samples24h": 27,
          "samples30d": 27,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 27,
              "ok": 27
            }
          ]
        },
        "vendorStatus": {
          "page": "https://azure.status.microsoft/en-us/status/history",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:47.070808325Z"
        },
        "pages": [
          {
            "url": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:21:36.290153566Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "bca4f93493d4"
          },
          {
            "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:21:38.182590643Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1a1ee1c20d9a"
          }
        ],
        "updatedAt": "2026-10-08T19:52:56.035923923Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Keycard Labs",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "https://api.keycard.ai",
        "b": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
        "b": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-22",
        "b": "2026-09-30",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2025-10-01",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1 stars, 52 npm/wk",
        "b": "787 stars",
        "name": "Popularity"
      },
      {
        "a": "2.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 5 of 7 scored categories. Keycard leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Keycard or Microsoft Entra Agent ID?"
      },
      {
        "answer": "Keycard takes an API key or an OAuth sign-in. Microsoft Entra Agent ID uses an OAuth sign-in.",
        "question": "Do Keycard and Microsoft Entra Agent ID need an API key?"
      },
      {
        "answer": "Yes. Keycard has a hosted endpoint at https://api.keycard.ai and Microsoft Entra Agent ID at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity.",
        "question": "Can an agent call Keycard and Microsoft Entra Agent ID without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 30 against 20"
        ],
        "also": null,
        "goodFor": "A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product.",
        "slug": "keycard",
        "watchFor": "Early Access with sign-up by request, and no terms of service page"
      },
      {
        "aheadOn": [
          "Reliability, 91 against 35",
          "Schema \u0026 documentation, 87 against 61",
          "Agent ergonomics, 71 against 60",
          "Transparency \u0026 trust, 74 against 44"
        ],
        "also": [
          "Agent-ready, a grade of BB or better"
        ],
        "goodFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
        "slug": "microsoft-entra-agent-id",
        "watchFor": "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-keycard.json",
        "title": "Aembit vs Keycard",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.json",
        "title": "Aembit vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-keycard.json",
        "title": "Arcade.dev vs Keycard",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.json",
        "title": "Arcade.dev vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Keycard",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.json",
        "title": "Descope Agentic Identity Hub vs Keycard",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.json",
        "title": "Descope Agentic Identity Hub vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-nango.json",
        "title": "Keycard vs Nango",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.json",
        "title": "Keycard vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.json",
        "title": "Keycard vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.json",
        "title": "Keycard vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.json",
        "title": "Microsoft Entra Agent ID vs Nango",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.json",
        "title": "Microsoft Entra Agent ID vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.json",
        "title": "Microsoft Entra Agent ID vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.json",
        "title": "Microsoft Entra Agent ID vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "by": 56,
        "edge": "microsoft-entra-agent-id",
        "key": "reliability",
        "keycard": 35,
        "microsoft-entra-agent-id": 91,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 26,
        "edge": "microsoft-entra-agent-id",
        "key": "schema",
        "keycard": 61,
        "microsoft-entra-agent-id": 87,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 11,
        "edge": "microsoft-entra-agent-id",
        "key": "ergonomics",
        "keycard": 60,
        "microsoft-entra-agent-id": 71,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 3,
        "edge": "keycard",
        "key": "security",
        "keycard": 86,
        "microsoft-entra-agent-id": 83,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 10,
        "edge": "keycard",
        "key": "payments",
        "keycard": 30,
        "microsoft-entra-agent-id": 20,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "edge": "microsoft-entra-agent-id",
        "key": "maintenance",
        "keycard": 79,
        "microsoft-entra-agent-id": 80,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 30,
        "edge": "microsoft-entra-agent-id",
        "key": "transparency",
        "keycard": 44,
        "microsoft-entra-agent-id": 74,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 5 of 7 scored categories. Keycard leads on payments \u0026 pricing. Both do auth oauth.",
    "verdicts": {
      "keycard": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.",
      "microsoft-entra-agent-id": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id",
    "json": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md",
    "slim": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.min.md"
  },
  "markdown": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 5 of 7 scored categories. Keycard leads on payments \u0026 pricing. Both do auth oauth.\n\n- Keycard: grade C, 56.2/100, rank #492 of 722. Markdown https://www.anchorterminal.com/tools/keycard.md · JSON https://www.anchorterminal.com/api/v1/tools/keycard.json\n- Microsoft Entra Agent ID: grade BB, 74.4/100, rank #63 of 722. Markdown https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json\n\n## Which one, for what\n\n### Keycard (C)\n\nGood for: A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product.\n\nAhead on:\n- Payments \u0026 pricing, 30 against 20\n\nWatch for: Early Access with sign-up by request, and no terms of service page\n\n### Microsoft Entra Agent ID (BB)\n\nGood for: Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.\n\nAhead on:\n- Reliability, 91 against 35\n- Schema \u0026 documentation, 87 against 61\n- Agent ergonomics, 71 against 60\n- Transparency \u0026 trust, 74 against 44\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n\nWatch for: Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing\n\n\n## Score by category\n\n| Category | Weight | Keycard | Microsoft Entra Agent ID | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 35 | 91 | Microsoft Entra Agent ID +56 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 61 | 87 | Microsoft Entra Agent ID +26 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 71 | Microsoft Entra Agent ID +11 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 83 | Keycard +3 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 20 | Keycard +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 79 | 80 | Microsoft Entra Agent ID +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 44 | 74 | Microsoft Entra Agent ID +30 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **56.2 · C** | **74.4 · BB** | |\n\n## Facts side by side\n\n| Fact | Keycard | Microsoft Entra Agent ID |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Keycard Labs | Microsoft |\n| Hosted endpoint | `https://api.keycard.ai` | `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity` |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise | Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-09-22 | 2026-09-30 |\n| Terms last updated | no document linked | 2025-10-01 |\n| Privacy policy last updated | couldn't be read | 2026-09-01 |\n| Customer content may train models |  | yes |\n| Terms restrict automated access |  | yes |\n| Terms restrict benchmarking |  | yes |\n| Terms or service can change without notice |  | yes |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 1 stars, 52 npm/wk | 787 stars |\n| Agent reviews | 2.5/5 (2) | none |\n\n## Verdicts\n\n**Keycard.** Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.\n\n**Microsoft Entra Agent ID.** Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.\n\n## Before you call either\n\n### Keycard\n\n1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone\n2. Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange\n3. Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry\n4. Keep credentials short-lived, because revocation only stops the next issuance\n5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart\n\n### Microsoft Entra Agent ID\n\n1. Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token\n2. Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object\n3. Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required\n4. Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page\n5. Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it\n\n## Questions\n\n### Which is better for AI agents, Keycard or Microsoft Entra Agent ID?\n\nMicrosoft Entra Agent ID scores 74.4 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 5 of 7 scored categories. Keycard leads on payments \u0026 pricing.\n\n### Do Keycard and Microsoft Entra Agent ID need an API key?\n\nKeycard takes an API key or an OAuth sign-in. Microsoft Entra Agent ID uses an OAuth sign-in.\n\n### Can an agent call Keycard and Microsoft Entra Agent ID without installing anything?\n\nYes. Keycard has a hosted endpoint at https://api.keycard.ai and Microsoft Entra Agent ID at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.json, and with the fewest tokens: https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"keycard\", \"b\": \"microsoft-entra-agent-id\"}`. From a terminal: `anchor compare keycard microsoft-entra-agent-id`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/keycard.json and https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json\n\n## Other comparisons with Keycard or Microsoft Entra Agent ID\n\n- [Aembit vs Keycard](https://www.anchorterminal.com/compare/aembit-vs-keycard.md)\n- [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md)\n- [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md)\n- [Arcade.dev vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md)\n- [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md)\n- [Keycard vs Scalekit AgentKit](https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)\n- [Microsoft Entra Agent ID vs Nango](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.md)\n- [Microsoft Entra Agent ID vs Scalekit AgentKit](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.md)\n- [Microsoft Entra Agent ID vs Stytch Connected Apps](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.md)\n- [Microsoft Entra Agent ID vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Keycard vs Microsoft Entra Agent ID",
        "url": ""
      }
    ],
    "description": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 5 of 7 scored categories. Keycard leads on payments \u0026 pricing. Both do auth oauth. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Keycard C 56.2",
      "Microsoft Entra Agent ID BB 74.4",
      "scores"
    ],
    "h1": "Keycard vs Microsoft Entra Agent ID",
    "image": "https://www.anchorterminal.com/assets/og/compare-keycard-vs-microsoft-entra-agent-id.png",
    "path": "/compare/keycard-vs-microsoft-entra-agent-id",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Keycard vs Microsoft Entra Agent ID for AI agents, C 56.2 vs BB 74.4",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 730
  },
  "version": 1
}
