{
  "data": {
    "a": {
      "slug": "keycard",
      "name": "Keycard",
      "vendor": "Keycard Labs",
      "vendorUrl": "https://www.keycard.ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Identity and access platform for AI agents.",
      "url": "https://www.anchorterminal.com/tools/keycard",
      "markdownUrl": "https://www.anchorterminal.com/tools/keycard.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keycard.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keycard.json",
      "repo": "https://github.com/keycardai/python-sdk",
      "license": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.keycard.ai",
      "packages": [
        {
          "registry": "pypi",
          "name": "keycardai-mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai-fastmcp"
        },
        {
          "registry": "npm",
          "name": "@keycardai/mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai_api"
        }
      ],
      "auth": "mixed",
      "authNotes": "The management API at api.keycard.ai takes `Authorization: Bearer $KEYCARD_API_KEY` (a service account key). Agents and MCP servers talk OAuth 2.0 to their zone at `https://\u003czone-id\u003e.keycard.cloud`, discovered from `/.well-known/oauth-authorization-server`, with PKCE, dynamic client registration and RFC 8693 token exchange against the token endpoint. Application credentials are a client secret, a web identity (OIDC) or EKS workload identity. Tokens are JWTs verified against the zone's JWKS.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 5,000 transactions a month as a hard cap, unlimited users, agents and apps, RBAC, ABAC and ReBAC policies, 7-day telemetry retention and community support. Team is $500 a month with 100,000 transactions and $1 per 1,000 after, SSO, zone policy, 90-day retention, email support and an SLA. Enterprise is custom on an annual commitment, with org and device-based policy, SCIM, Active Directory and LDAP provisioning, dedicated, BYOC or on-prem deployment, private networking, customer-managed KMS, 180-day retention, a 99.95 per cent uptime SLA and 1-hour 24/7 response on P1 issues. A transaction is recorded each time Keycard issues a credential, validates an access request or exchanges a credential (https://www.keycard.ai/pricing). The page doesn't say whether a card is needed, and its sign-up form ends with a promise to be in touch. The quickstart calls the product Early Access, with sign-up at console.keycard.ai.",
      "priceSummary": "$500 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1,
        "npmWeekly": 52,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.keycard.ai",
      "llmsTxt": "https://docs.keycard.ai/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.3,
        "grade": "C",
        "agentReady": false,
        "rank": 303,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 45
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.",
        "strengths": [
          "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange",
          "Delegated grants with RFC 8693 exchange for GitHub, Google, Slack, Linear and any OAuth 2.0 provider",
          "Session timeline and audit log per exchange, exported hourly to S3 in OCSF Parquet",
          "Published per-unit price ($1 per 1,000 transactions on Team) with a transaction defined",
          "Valid security.txt and SOC 2 Type 2 listed in a SafeBase trust centre"
        ],
        "weaknesses": [
          "Early Access with sign-up by request, and no terms of service page",
          "No per-token kill switch, so a revoked grant lives until the token expires, and revocation doesn't reach the provider",
          "No published rate limits, 429 guidance or public changelog",
          "keycardai-mcp went from 1.0.0 to 2.0.0 in a day in August 2026",
          "Team is $500 a month with nothing between it and the free tier"
        ],
        "agentNotes": [
          "Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone",
          "Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange",
          "Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry",
          "Keep credentials short-lived, because revocation only stops the next issuance",
          "Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.3
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 25
        },
        "provenanceScore": 65
      },
      "connect": {
        "install": "pip install keycardai-mcp",
        "http": "curl \"https://api.keycard.ai/zones/$KEYCARD_ZONE_ID/sessions\" \\\n  -H \"Authorization: Bearer $KEYCARD_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/keycard"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 500,
          "note": "100,000 transactions included"
        },
        {
          "item": "Transactions above 100,000 on Team",
          "unit": "1k-calls",
          "usd": 1,
          "note": "The pricing page doesn't define a transaction"
        }
      ],
      "provenance": {
        "legalEntity": "Keycard Labs, Inc.",
        "domain": "keycard.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://www.keycard.ai/privacy/",
        "statusPage": "https://status.keycard.ai",
        "changelog": "",
        "securityTxt": "valid",
        "checked": "2026-10-02",
        "notes": [
          "The homepage footer names Keycard Labs, Inc., 103 Foulk Road, Suite 202, Wilmington, DE 19808. The footer's legal links on 2 October were privacy, cookie policy, a vulnerability address and the trust centre at trust.keycard.ai. We found no terms of service page (keycard.ai/terms/ returns 404) and the privacy page's body didn't load for us on 30 September or 2 October.",
          "RDAP for keycard.ai returned 404 at rdap.nic.ai and 429 at Identity Digital on 2026-09-30, so the registration date is blank.",
          "status.keycard.ai answers as a status page, though its history renders client-side and its JSON and RSS feeds returned 403 to us on 2 October.",
          "The docs index (73 entries) lists no changelog. The SDK repositories' CHANGELOG.md files are the nearest thing to release notes.",
          "The trust centre lists SOC 2 Type 1 and Type 2 reports and names Resend, Google, GitHub, Cloudflare and AWS as subprocessors."
        ],
        "score": 65
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/keycard.json",
      "live": {
        "slug": "keycard",
        "probe": {
          "target": "https://api.keycard.ai",
          "method": "get",
          "lastAt": "2026-10-05T00:57:22.208548648Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 278,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 280,
          "p95ms24h": 367,
          "samples24h": 272,
          "samples30d": 911,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 11,
              "ok": 11
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.keycard.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:10.814751767Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@keycardai/mcp",
            "version": "2.0.2",
            "seenAt": "2026-10-04T16:30:47.44448777Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-fastmcp",
            "version": "0.7.1",
            "released": "2026-09-15",
            "seenAt": "2026-10-04T16:30:45.543960623Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-mcp",
            "version": "2.3.2",
            "released": "2026-09-16",
            "seenAt": "2026-10-04T16:30:45.360722519Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai_api",
            "version": "0.18.0",
            "released": "2026-09-25",
            "seenAt": "2026-10-04T16:30:48.363651419Z"
          }
        ],
        "githubStars": 1,
        "npmWeekly": 211,
        "pypiWeekly": 179,
        "securityTxt": {
          "url": "https://keycard.ai/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-12T00:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:49.895852699Z"
        },
        "llmsTxt": {
          "url": "https://docs.keycard.ai/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:54.842330743Z"
        },
        "domain": {
          "domain": "keycard.ai",
          "registered": "2024-02-04",
          "source": "https://rdap.identitydigital.services/rdap/domain/keycard.ai",
          "checkedAt": "2026-10-04T13:06:32.92261194Z"
        },
        "pages": [
          {
            "url": "https://www.keycard.ai/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:56.738789549Z",
            "changedAt": "2026-10-03T15:38:49.492444489Z",
            "fingerprint": "7d745cb5c53f"
          },
          {
            "url": "https://www.keycard.ai/privacy/",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:58.814741157Z",
            "changedAt": "2026-10-03T15:38:51.566729092Z",
            "fingerprint": "596ae9dc1660"
          }
        ],
        "updatedAt": "2026-10-05T00:57:22.208548648Z"
      }
    },
    "b": {
      "slug": "nango",
      "name": "Nango",
      "vendor": "Nango",
      "vendorUrl": "https://www.nango.dev",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Source-available integration platform that handles OAuth, API keys and token refresh for 1,000+ APIs on behalf of your users.",
      "url": "https://www.anchorterminal.com/tools/nango",
      "markdownUrl": "https://www.anchorterminal.com/tools/nango.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nango.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nango.json",
      "repo": "https://github.com/NangoHQ/nango",
      "license": "Elastic License 2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.nango.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@nangohq/node"
        },
        {
          "registry": "npm",
          "name": "@nangohq/frontend"
        }
      ],
      "auth": "mixed",
      "authNotes": "Backend calls take an environment secret key as `Authorization: Bearer $NANGO_SECRET_KEY`, and API keys can be scoped (agent sessions need `environment:agent_sessions:write`). End users connect through a short-lived connect session token in the Connect UI. An agent session returns its own MCP URL and `session_token`, sent as a Bearer token. The Management MCP at mcp.nango.dev signs in with OAuth.",
      "pricing": "freemium",
      "pricingNotes": "Three plans since 2 September 2026. Free is $0 with 10 connections, 10 compute hours and 10 GB of data transfer a month and no card. Pay-as-you-go is $50 a month returned as $50 of usage credits, then $0.29 per connection a month, $0.72 per compute hour and $0.50 per GB. The Growth add-on is $450 a month and adds faster integration delivery (5 days instead of 20) and a private Slack channel, and the changelog of 2 September also puts RBAC, OpenTelemetry export, Connect UI branding, SAML SSO for your team and a HIPAA BAA under it. Enterprise is custom, with connections from $0.01 at volume, 2-day integration delivery, BYOC and self-hosting, dedicated SLAs, and the pricing page lists HIPAA, SAML SSO, SCIM and the audit trail there (https://www.nango.dev/pricing, https://nango.dev/docs/updates/changelog). Free self-hosting covers auth and proxy only, with no MCP server, syncs or webhooks (https://nango.dev/docs/guides/platform/free-self-hosting).",
      "priceSummary": "$50 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 469086,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://nango.dev/docs",
      "llmsTxt": "https://nango.dev/docs/llms.txt",
      "openapi": "https://raw.githubusercontent.com/NangoHQ/nango/master/docs/spec.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.audit",
        "agent.tools",
        "automation.embedded"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "freemium",
        "free-tier",
        "mcp",
        "llms-txt",
        "openapi",
        "oauth",
        "typescript",
        "webhooks",
        "source-available",
        "enterprise"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.9,
        "grade": "B",
        "agentReady": false,
        "rank": 135,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 90,
          "payments": 40,
          "reliability": 78,
          "schema": 85,
          "security": 67,
          "transparency": 78
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "2026-09-04, CVE-2026-9317 (CVSS 9.2). The runner's tRPC server in Nango before 0.71.6 didn't enforce RUNNER_SECRET_KEY, so anyone who could reach the runner port could run arbitrary JavaScript. Fixed in 0.71.6. Recent and critical, though it needs network access to the runner (https://github.com/advisories/GHSA-9cph-w8mv-q56r)",
          "2026-09-16, CVE-2026-92804 (high). Nango through 0.70.4 didn't validate caller-supplied connection configuration values. Fixed in later releases. Together with the runner flaw we deduct 5, less than the maximum because both are fixed and disclosed (https://github.com/advisories/GHSA-29mm-6vmq-g8cg)"
        ],
        "verdict": "1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.",
        "strengths": [
          "1,000+ APIs with OAuth, API key and client-credentials auth handled",
          "Per-tenant agent sessions served as an MCP server, credentials never shown to the agent",
          "Encryption, retention and deletion rules published in the docs",
          "Per-unit prices in public ($0.29 a connection a month) and a free plan with no card",
          "Source on GitHub under ELv2, 31 open issues against more than 7,000 filed"
        ],
        "weaknesses": [
          "Audit trail only on Enterprise, and logs kept 15 days on every plan",
          "Two CVEs fixed in September 2026, one critical, neither on Nango's own advisory page",
          "Status page tracks a single component",
          "No prompt-injection guidance for content agent sessions pass through",
          "ELv2 bars offering Nango itself as a hosted service"
        ],
        "agentNotes": [
          "Create one agent session per tenant from your backend and pass only the mcp_url and session_token to the agent",
          "Tag connections with your own user and organisation IDs so sessions can select them",
          "Listen for the refresh-failure webhook and send the user a reconnect link instead of retrying",
          "Read the rate-limit headers on a 429 and wait for the reset before resuming",
          "Run 0.71.6 or later when self-hosting, and keep the runner port off the network"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.9
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 90,
          "payments": 40,
          "reliability": 78,
          "schema": 85,
          "security": 67,
          "transparency": 63
        },
        "provenanceScore": 92
      },
      "connect": {
        "install": "npm install @nangohq/node",
        "http": "curl -X POST https://api.nango.dev/connect/sessions -H \"Authorization: Bearer $NANGO_SECRET_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"tags\":{\"end_user_id\":\"user-123\"}}'",
        "claudeCode": "claude mcp add --transport http nango-management --scope user https://mcp.nango.dev/mcp",
        "config": {
          "mcpServers": {
            "nango-management": {
              "url": "https://mcp.nango.dev/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/nango"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pay-as-you-go subscription",
          "unit": "month",
          "usd": 50,
          "note": "Returned as $50 of usage credits each month"
        },
        {
          "item": "Connection on Pay-as-you-go",
          "unit": "account-month",
          "usd": 0.29,
          "note": "Per connected end-user account per month"
        },
        {
          "item": "Data transfer on Pay-as-you-go",
          "unit": "gb",
          "usd": 0.5,
          "note": "10 GB a month free. Compute is $0.72 an hour"
        },
        {
          "item": "Growth add-on",
          "unit": "month",
          "usd": 450,
          "note": "Faster integration delivery, private Slack, RBAC, branding, SAML SSO, HIPAA BAA"
        }
      ],
      "provenance": {
        "legalEntity": "Nango Inc",
        "domain": "nango.dev",
        "domainRegistered": "2022-05-31",
        "endpointOnVendorDomain": true,
        "terms": "https://www.nango.dev/terms",
        "privacy": "https://www.nango.dev/privacy-policy",
        "statusPage": "https://status.nango.dev",
        "changelog": "https://nango.dev/docs/updates/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The legal entity comes from the copyright line in the repository's LICENSE_SHORT, because we couldn't read the terms page on 2026-09-30.",
          "SECURITY.md asks for reports to security@nango.dev or a private GitHub advisory. The Trust Center at trust.nango.dev holds the SOC 2 report.",
          "status.nango.dev is a Better Stack page with one component, Nango Cloud Health."
        ],
        "score": 92
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/nango.json",
      "live": {
        "slug": "nango",
        "probe": {
          "target": "https://api.nango.dev",
          "method": "get",
          "lastAt": "2026-10-05T00:57:24.211646307Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 434,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 448,
          "p95ms24h": 520,
          "samples24h": 272,
          "samples30d": 911,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 11,
              "ok": 11
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.nango.dev",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:15.983421149Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "NangoHQ/nango",
            "version": "v0.71.12",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:34:17.295643211Z"
          },
          {
            "registry": "npm",
            "name": "@nangohq/frontend",
            "version": "0.71.12",
            "seenAt": "2026-10-04T16:34:15.84943577Z"
          },
          {
            "registry": "npm",
            "name": "@nangohq/node",
            "version": "0.71.12",
            "seenAt": "2026-10-04T16:34:15.032017504Z"
          }
        ],
        "githubStars": 12512,
        "npmWeekly": 605062,
        "securityTxt": {
          "url": "https://nango.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-12-31T23:59:59.000Z",
          "checkedAt": "2026-10-04T15:15:47.082341179Z"
        },
        "llmsTxt": {
          "url": "https://nango.dev/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:02.723630139Z"
        },
        "domain": {
          "domain": "nango.dev",
          "registered": "2022-05-31",
          "source": "https://pubapi.registry.google/rdap/domain/nango.dev",
          "checkedAt": "2026-10-04T13:09:24.044829714Z"
        },
        "pages": [
          {
            "url": "https://nango.dev/docs/updates/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:08.862094314Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5d603945f9f6"
          },
          {
            "url": "https://www.nango.dev/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:25.76214842Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "de303d4e1a64"
          },
          {
            "url": "https://www.nango.dev/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:28.18451084Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2b1d4741bc37"
          },
          {
            "url": "https://www.nango.dev/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:51:30.200662946Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b8fadd3f9456"
          }
        ],
        "updatedAt": "2026-10-05T00:57:24.211646307Z"
      }
    },
    "summary": "Nango has a score of 67.9 (B) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 43 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/keycard-vs-nango",
    "json": "https://www.anchorterminal.com/compare/keycard-vs-nango.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/keycard-vs-nango.md",
    "slim": "https://www.anchorterminal.com/compare/keycard-vs-nango.min.md"
  },
  "markdown": "Nango has a score of 67.9 (B) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 43 points.\n\n- Keycard: grade C, 56.3/100, rank #303 of 452. Markdown https://www.anchorterminal.com/tools/keycard.md · JSON https://www.anchorterminal.com/api/v1/tools/keycard.json\n- Nango: grade B, 67.9/100, rank #135 of 452. Markdown https://www.anchorterminal.com/tools/nango.md · JSON https://www.anchorterminal.com/api/v1/tools/nango.json\n\n## Which one, for what\n\nPick Keycard for security \u0026 auth (+19).\n\nPick Nango for reliability (+43), schema \u0026 documentation (+24), agent ergonomics (+14), payments \u0026 pricing (+10), maintenance \u0026 community (+11), transparency \u0026 trust (+33).\n\n## Score by category\n\n| Category | Weight | Keycard | Nango | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 35 | 78 | Nango +43 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 61 | 85 | Nango +24 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 74 | Nango +14 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 67 | Keycard +19 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 40 | Nango +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 79 | 90 | Nango +11 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 45 | 78 | Nango +33 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **56.3 · C** | **67.9 · B** | |\n\n## Facts side by side\n\n| Fact | Keycard | Nango |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Keycard Labs | Nango |\n| Hosted endpoint | `https://api.keycard.ai` | `https://api.nango.dev` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise | Elastic License 2.0 |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-22 | 2026-09-30 |\n| Popularity | 1 stars, 52 npm/wk | 469k npm/wk |\n| Agent reviews | 2.5/5 (2) | 3.5/5 (2) |\n\n## Verdicts\n\n**Keycard.** Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.\n\n**Nango.** 1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.\n\n## Before you call either\n\n### Keycard\n\n1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone\n2. Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange\n3. Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry\n4. Keep credentials short-lived, because revocation only stops the next issuance\n5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart\n\n### Nango\n\n1. Create one agent session per tenant from your backend and pass only the mcp_url and session_token to the agent\n2. Tag connections with your own user and organisation IDs so sessions can select them\n3. Listen for the refresh-failure webhook and send the user a reconnect link instead of retrying\n4. Read the rate-limit headers on a 429 and wait for the reset before resuming\n5. Run 0.71.6 or later when self-hosting, and keep the runner port off the network\n\n## Other comparisons with Keycard or Nango\n\n- [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md)\n- [Arcade.dev vs Nango](https://www.anchorterminal.com/compare/arcade-vs-nango.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Auth0 for AI Agents (Token Vault) vs Nango](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Nango](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.md)\n- [Keycard vs Scalekit AgentKit](https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)\n- [Nango vs Scalekit AgentKit](https://www.anchorterminal.com/compare/nango-vs-scalekit-agentkit.md)\n- [Nango vs Stytch Connected Apps](https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps.md)\n- [Nango vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/nango-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Keycard vs Nango",
        "url": ""
      }
    ],
    "description": "Nango has a score of 67.9 (B) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 43 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Keycard C 56.3",
      "Nango B 67.9",
      "scores"
    ],
    "h1": "Keycard vs Nango",
    "image": "https://www.anchorterminal.com/assets/og/compare-keycard-vs-nango.png",
    "path": "/compare/keycard-vs-nango",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Keycard vs Nango for AI agents, C 56.3 vs B 67.9 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/keycard-vs-nango"
  },
  "tokens": {
    "markdown": 1450,
    "slim": 330
  },
  "version": 1
}
