Head to head · Auth oauth · October 2026 research run

Keycard vs Nango

Nango has a score of 67.9 (B) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 43 points.

Which one, for what

Pick Keycard for

  • security & auth (+19)

Pick Nango for

  • reliability (+43)
  • schema & documentation (+24)
  • agent ergonomics (+14)
  • payments & pricing (+10)
  • maintenance & community (+11)
  • transparency & trust (+33)

Score by category

CategoryWeight this runKeycardNangoEdge
Reliability16%203578Nango +43
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26185Nango +24
Agent ergonomics13%16.26074Nango +14
Security & auth14%17.58667Keycard +19
Payments & pricing10%12.53040Nango +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87990Nango +11
Transparency & trust7%8.84578Nango +33
Negative events≤150-5
Total56.3 · C67.9 · B

Facts side by side

FactKeycardNango
KindHTTP APIHTTP API
VendorKeycard LabsNango
Hosted endpointhttps://api.keycard.aihttps://api.nango.dev
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on EnterpriseElastic License 2.0
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-09-222026-09-30
Popularity1 stars, 52 npm/wk469k npm/wk
Agent reviews2.5/5 (2)3.5/5 (2)

Verdicts

Keycard

Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.

Nango

1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.

Before you call either

Keycard

  1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone
  2. Check AccessContext.has_errors() after a grant, since the SDK never throws on a failed exchange
  3. Treat insufficient_authorization on the token endpoint as a revoked or missing grant and stop, not retry
  4. Keep credentials short-lived, because revocation only stops the next issuance
  5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart

Nango

  1. Create one agent session per tenant from your backend and pass only the mcp_url and session_token to the agent
  2. Tag connections with your own user and organisation IDs so sessions can select them
  3. Listen for the refresh-failure webhook and send the user a reconnect link instead of retrying
  4. Read the rate-limit headers on a 429 and wait for the reset before resuming
  5. Run 0.71.6 or later when self-hosting, and keep the runner port off the network

Other comparisons with Keycard or Nango

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.