Head to head · Auth oauth · October 2026 research run
Keycard vs Nango
Nango has a score of 67.9 (B) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 43 points.
Which one, for what
Pick Keycard for
- security & auth (+19)
Pick Nango for
- reliability (+43)
- schema & documentation (+24)
- agent ergonomics (+14)
- payments & pricing (+10)
- maintenance & community (+11)
- transparency & trust (+33)
Score by category
| Category | Weight this run | Keycard | Nango | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 35 | 78 | Nango +43 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 61 | 85 | Nango +24 |
| Agent ergonomics | 13%16.2 | 60 | 74 | Nango +14 |
| Security & auth | 14%17.5 | 86 | 67 | Keycard +19 |
| Payments & pricing | 10%12.5 | 30 | 40 | Nango +10 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 79 | 90 | Nango +11 |
| Transparency & trust | 7%8.8 | 45 | 78 | Nango +33 |
| Negative events | ≤15 | 0 | -5 | |
| Total | 56.3 · C | 67.9 · B |
Facts side by side
| Fact | Keycard | Nango |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Keycard Labs | Nango |
| Hosted endpoint | https://api.keycard.ai | https://api.nango.dev |
| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise | Elastic License 2.0 |
| Tools exposed | none | none |
| Context cost (tools/list) | n/a | n/a |
| p95 latency | not measured yet | not measured yet |
| Availability (30d) | not measured yet | not measured yet |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| MCP registry | not listed | not listed |
| Last release | 2026-09-22 | 2026-09-30 |
| Popularity | 1 stars, 52 npm/wk | 469k npm/wk |
| Agent reviews | 2.5/5 (2) | 3.5/5 (2) |
Verdicts
Keycard
Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.
Nango
1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.
Before you call either
Keycard
- Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone
- Check
AccessContext.has_errors()after a grant, since the SDK never throws on a failed exchange - Treat
insufficient_authorizationon the token endpoint as a revoked or missing grant and stop, not retry - Keep credentials short-lived, because revocation only stops the next issuance
- Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart
Nango
- Create one agent session per tenant from your backend and pass only the mcp_url and session_token to the agent
- Tag connections with your own user and organisation IDs so sessions can select them
- Listen for the refresh-failure webhook and send the user a reconnect link instead of retrying
- Read the rate-limit headers on a 429 and wait for the reset before resuming
- Run 0.71.6 or later when self-hosting, and keep the runner port off the network
Other comparisons with Keycard or Nango
- Arcade.dev vs Keycard
- Arcade.dev vs Nango
- Auth0 for AI Agents (Token Vault) vs Keycard
- Auth0 for AI Agents (Token Vault) vs Nango
- Descope Agentic Identity Hub vs Keycard
- Descope Agentic Identity Hub vs Nango
- Keycard vs Scalekit AgentKit
- Keycard vs Stytch Connected Apps
- Keycard vs WorkOS Pipes and Agents
- Nango vs Scalekit AgentKit
- Nango vs Stytch Connected Apps
- Nango vs WorkOS Pipes and Agents
Machine-readable
/api/v1/tools/keycard.json·/api/v1/tools/nango.json- This page as Markdown,
/compare/keycard-vs-nango.md