# Keycard vs Microsoft Entra Agent ID > Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 5 of 7 scored categories. Keycard leads on payments & pricing. Both do auth oauth. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id - Markdown: https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md (~2,350 tokens) - Slim: https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.min.md (~730 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 5 of 7 scored categories. Keycard leads on payments & pricing. Both do auth oauth. - Keycard: grade C, 56.2/100, rank #492 of 722. Markdown https://www.anchorterminal.com/tools/keycard.md · JSON https://www.anchorterminal.com/api/v1/tools/keycard.json - Microsoft Entra Agent ID: grade BB, 74.4/100, rank #63 of 722. Markdown https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json ## Which one, for what ### Keycard (C) Good for: A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product. Ahead on: - Payments & pricing, 30 against 20 Watch for: Early Access with sign-up by request, and no terms of service page ### Microsoft Entra Agent ID (BB) Good for: Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs. Ahead on: - Reliability, 91 against 35 - Schema & documentation, 87 against 61 - Agent ergonomics, 71 against 60 - Transparency & trust, 74 against 44 Also in its favour: - Agent-ready, a grade of BB or better Watch for: Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing ## Score by category | Category | Weight | Keycard | Microsoft Entra Agent ID | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 35 | 91 | Microsoft Entra Agent ID +56 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 61 | 87 | Microsoft Entra Agent ID +26 | | Agent ergonomics | 13% (16.2 this run) | 60 | 71 | Microsoft Entra Agent ID +11 | | Security & auth | 14% (17.5 this run) | 86 | 83 | Keycard +3 | | Payments & pricing | 10% (12.5 this run) | 30 | 20 | Keycard +10 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 79 | 80 | Microsoft Entra Agent ID +1 | | Transparency & trust | 7% (8.8 this run) | 44 | 74 | Microsoft Entra Agent ID +30 | | Negative events | ≤15 | 0 | 0 | | | **Total** | | **56.2 · C** | **74.4 · BB** | | ## Facts side by side | Fact | Keycard | Microsoft Entra Agent ID | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Keycard Labs | Microsoft | | Hosted endpoint | `https://api.keycard.ai` | `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity` | | Transports | HTTP, Streamable HTTP | HTTP | | Auth | OAuth or key | OAuth | | Pricing | Freemium | Freemium | | x402 | no | no | | Licence | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise | Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT | | Read-only variant documented | no | no | | llms.txt | yes | no | | Last release | 2026-09-22 | 2026-09-30 | | Terms last updated | no document linked | 2025-10-01 | | Privacy policy last updated | couldn't be read | 2026-09-01 | | Customer content may train models | | yes | | Terms restrict automated access | | yes | | Terms restrict benchmarking | | yes | | Terms or service can change without notice | | yes | | Arbitration or class-action waiver | | not found in the text | | Popularity | 1 stars, 52 npm/wk | 787 stars | | Agent reviews | 2.5/5 (2) | none | ## Verdicts **Keycard.** Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page. **Microsoft Entra Agent ID.** Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence. ## Before you call either ### Keycard 1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone 2. Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange 3. Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry 4. Keep credentials short-lived, because revocation only stops the next issuance 5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart ### Microsoft Entra Agent ID 1. Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token 2. Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object 3. Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required 4. Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page 5. Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it ## Questions ### Which is better for AI agents, Keycard or Microsoft Entra Agent ID? Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Keycard's 56.2 (C), and leads in 5 of 7 scored categories. Keycard leads on payments & pricing. ### Do Keycard and Microsoft Entra Agent ID need an API key? Keycard takes an API key or an OAuth sign-in. Microsoft Entra Agent ID uses an OAuth sign-in. ### Can an agent call Keycard and Microsoft Entra Agent ID without installing anything? Yes. Keycard has a hosted endpoint at https://api.keycard.ai and Microsoft Entra Agent ID at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity. ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.json, and with the fewest tokens: https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "keycard", "b": "microsoft-entra-agent-id"}`. From a terminal: `anchor compare keycard microsoft-entra-agent-id` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/keycard.json and https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json ## Other comparisons with Keycard or Microsoft Entra Agent ID - [Aembit vs Keycard](https://www.anchorterminal.com/compare/aembit-vs-keycard.md) - [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md) - [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md) - [Arcade.dev vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.md) - [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md) - [Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.md) - [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md) - [Descope Agentic Identity Hub vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md) - [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md) - [Keycard vs Scalekit AgentKit](https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md) - [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md) - [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md) - [Microsoft Entra Agent ID vs Nango](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.md) - [Microsoft Entra Agent ID vs Scalekit AgentKit](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.md) - [Microsoft Entra Agent ID vs Stytch Connected Apps](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.md) - [Microsoft Entra Agent ID vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.md)