{
  "data": {
    "a": {
      "slug": "keycard",
      "name": "Keycard",
      "vendor": "Keycard Labs",
      "vendorUrl": "https://www.keycard.ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Identity and access platform for AI agents.",
      "url": "https://www.anchorterminal.com/tools/keycard",
      "markdownUrl": "https://www.anchorterminal.com/tools/keycard.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keycard.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keycard.json",
      "repo": "https://github.com/keycardai/python-sdk",
      "license": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.keycard.ai",
      "packages": [
        {
          "registry": "pypi",
          "name": "keycardai-mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai-fastmcp"
        },
        {
          "registry": "npm",
          "name": "@keycardai/mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai_api"
        }
      ],
      "auth": "mixed",
      "authNotes": "The management API at api.keycard.ai takes `Authorization: Bearer $KEYCARD_API_KEY` (a service account key). Agents and MCP servers talk OAuth 2.0 to their zone at `https://\u003czone-id\u003e.keycard.cloud`, discovered from `/.well-known/oauth-authorization-server`, with PKCE, dynamic client registration and RFC 8693 token exchange against the token endpoint. Application credentials are a client secret, a web identity (OIDC) or EKS workload identity. Tokens are JWTs verified against the zone's JWKS.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 5,000 transactions a month as a hard cap, unlimited users, agents and apps, RBAC, ABAC and ReBAC policies, 7-day telemetry retention and community support. Team is $500 a month with 100,000 transactions and $1 per 1,000 after, SSO, zone policy, 90-day retention, email support and an SLA. Enterprise is custom on an annual commitment, with org and device-based policy, SCIM, Active Directory and LDAP provisioning, dedicated, BYOC or on-prem deployment, private networking, customer-managed KMS, 180-day retention, a 99.95 per cent uptime SLA and 1-hour 24/7 response on P1 issues. A transaction is recorded each time Keycard issues a credential, validates an access request or exchanges a credential (https://www.keycard.ai/pricing). The page doesn't say whether a card is needed, and its sign-up form ends with a promise to be in touch. The quickstart calls the product Early Access, with sign-up at console.keycard.ai.",
      "priceSummary": "$500 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1,
        "npmWeekly": 52,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.keycard.ai",
      "llmsTxt": "https://docs.keycard.ai/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.3,
        "grade": "C",
        "agentReady": false,
        "rank": 303,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 45
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.",
        "strengths": [
          "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange",
          "Delegated grants with RFC 8693 exchange for GitHub, Google, Slack, Linear and any OAuth 2.0 provider",
          "Session timeline and audit log per exchange, exported hourly to S3 in OCSF Parquet",
          "Published per-unit price ($1 per 1,000 transactions on Team) with a transaction defined",
          "Valid security.txt and SOC 2 Type 2 listed in a SafeBase trust centre"
        ],
        "weaknesses": [
          "Early Access with sign-up by request, and no terms of service page",
          "No per-token kill switch, so a revoked grant lives until the token expires, and revocation doesn't reach the provider",
          "No published rate limits, 429 guidance or public changelog",
          "keycardai-mcp went from 1.0.0 to 2.0.0 in a day in August 2026",
          "Team is $500 a month with nothing between it and the free tier"
        ],
        "agentNotes": [
          "Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone",
          "Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange",
          "Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry",
          "Keep credentials short-lived, because revocation only stops the next issuance",
          "Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.3
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 25
        },
        "provenanceScore": 65
      },
      "connect": {
        "install": "pip install keycardai-mcp",
        "http": "curl \"https://api.keycard.ai/zones/$KEYCARD_ZONE_ID/sessions\" \\\n  -H \"Authorization: Bearer $KEYCARD_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/keycard"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 500,
          "note": "100,000 transactions included"
        },
        {
          "item": "Transactions above 100,000 on Team",
          "unit": "1k-calls",
          "usd": 1,
          "note": "The pricing page doesn't define a transaction"
        }
      ],
      "provenance": {
        "legalEntity": "Keycard Labs, Inc.",
        "domain": "keycard.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://www.keycard.ai/privacy/",
        "statusPage": "https://status.keycard.ai",
        "changelog": "",
        "securityTxt": "valid",
        "checked": "2026-10-02",
        "notes": [
          "The homepage footer names Keycard Labs, Inc., 103 Foulk Road, Suite 202, Wilmington, DE 19808. The footer's legal links on 2 October were privacy, cookie policy, a vulnerability address and the trust centre at trust.keycard.ai. We found no terms of service page (keycard.ai/terms/ returns 404) and the privacy page's body didn't load for us on 30 September or 2 October.",
          "RDAP for keycard.ai returned 404 at rdap.nic.ai and 429 at Identity Digital on 2026-09-30, so the registration date is blank.",
          "status.keycard.ai answers as a status page, though its history renders client-side and its JSON and RSS feeds returned 403 to us on 2 October.",
          "The docs index (73 entries) lists no changelog. The SDK repositories' CHANGELOG.md files are the nearest thing to release notes.",
          "The trust centre lists SOC 2 Type 1 and Type 2 reports and names Resend, Google, GitHub, Cloudflare and AWS as subprocessors."
        ],
        "score": 65
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/keycard.json",
      "live": {
        "slug": "keycard",
        "probe": {
          "target": "https://api.keycard.ai",
          "method": "get",
          "lastAt": "2026-10-04T23:32:49.146895618Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 266,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 280,
          "p95ms24h": 367,
          "samples24h": 272,
          "samples30d": 895,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 267,
              "ok": 267
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.keycard.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:10.814751767Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@keycardai/mcp",
            "version": "2.0.2",
            "seenAt": "2026-10-04T16:30:47.44448777Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-fastmcp",
            "version": "0.7.1",
            "released": "2026-09-15",
            "seenAt": "2026-10-04T16:30:45.543960623Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-mcp",
            "version": "2.3.2",
            "released": "2026-09-16",
            "seenAt": "2026-10-04T16:30:45.360722519Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai_api",
            "version": "0.18.0",
            "released": "2026-09-25",
            "seenAt": "2026-10-04T16:30:48.363651419Z"
          }
        ],
        "githubStars": 1,
        "npmWeekly": 211,
        "pypiWeekly": 179,
        "securityTxt": {
          "url": "https://keycard.ai/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-12T00:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:49.895852699Z"
        },
        "llmsTxt": {
          "url": "https://docs.keycard.ai/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:54.842330743Z"
        },
        "domain": {
          "domain": "keycard.ai",
          "registered": "2024-02-04",
          "source": "https://rdap.identitydigital.services/rdap/domain/keycard.ai",
          "checkedAt": "2026-10-04T13:06:32.92261194Z"
        },
        "pages": [
          {
            "url": "https://www.keycard.ai/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:56.738789549Z",
            "changedAt": "2026-10-03T15:38:49.492444489Z",
            "fingerprint": "7d745cb5c53f"
          },
          {
            "url": "https://www.keycard.ai/privacy/",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:58.814741157Z",
            "changedAt": "2026-10-03T15:38:51.566729092Z",
            "fingerprint": "596ae9dc1660"
          }
        ],
        "updatedAt": "2026-10-04T23:32:49.146895618Z"
      }
    },
    "b": {
      "slug": "scalekit-agentkit",
      "name": "Scalekit AgentKit",
      "vendor": "Scalekit",
      "vendorUrl": "https://www.scalekit.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Authentication and integration platform for agents, with per-user account connections, scoped MCP servers and managed tool calls.",
      "url": "https://www.anchorterminal.com/tools/scalekit-agentkit",
      "markdownUrl": "https://www.anchorterminal.com/tools/scalekit-agentkit.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/scalekit-agentkit.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/scalekit-agentkit.json",
      "repo": "https://github.com/scalekit-inc/scalekit-sdk-node",
      "license": "MIT (SDKs), platform closed, self-hosted on Enterprise",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://{env}.scalekit.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@scalekit-sdk/node"
        },
        {
          "registry": "pypi",
          "name": "scalekit-sdk-python"
        },
        {
          "registry": "npm",
          "name": "@scalekit-inc/cli"
        }
      ],
      "auth": "mixed",
      "authNotes": "Your backend gets a bearer token from `POST $SCALEKIT_ENVIRONMENT_URL/oauth/token` with `grant_type=client_credentials` and the client ID and secret from the dashboard, then calls the REST API under /api/v1 on the same environment URL (dev environments end in .scalekit.dev, production in .scalekit.com). End users authorise a connection through a time-limited magic link that Scalekit hosts. Virtual MCP servers take a short-lived session token minted per user, about one hour by default. The management MCP server at mcp.scalekit.com needs no extra credentials.",
      "pricing": "freemium",
      "pricingNotes": "AgentKit Free is $0 with 5,000 tool calls a month, unlimited connected accounts, 500+ connectors and community and email support, no card. Growth is $99 a month with 100,000 tool calls and $0.0005 per extra call, custom connectors, an API proxy and private Slack support, with an EU data residency add-on at $99 a month. Enterprise is custom, with negotiated call volume, a 99.99 per cent uptime SLA, VPC or on-prem deployment, a HIPAA BAA, SIEM integrations and a forward-deployed engineer (https://www.scalekit.com/pricing). The page doesn't say whether a plain token fetch counts as a tool call.",
      "priceSummary": "$99 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6,
        "npmWeekly": 10642,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.scalekit.com/agentkit/overview",
      "llmsTxt": "https://docs.scalekit.com/llms.txt",
      "openapi": "https://docs.scalekit.com/api/agentkit.scalar.json",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "no-card",
        "oauth",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "python",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 72.1,
        "grade": "BB",
        "agentReady": true,
        "rank": 74,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 80,
          "payments": 40,
          "reliability": 75,
          "schema": 87,
          "security": 66,
          "transparency": 68
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "500+ connectors, including remote MCP servers over OAuth 2.1 with DCR. No rate limits or idempotency documented for Scalekit's own API.",
        "strengths": [
          "500+ connectors, including remote MCP servers over OAuth 2.1 with DCR",
          "OpenAPI files, llms.txt and a Markdown twin for every docs page",
          "Tool search, scoped tool lists and virtual MCP servers keep an agent's context small",
          "Atlassian status page with an Agent Kit Tool Execution component, 100.0 per cent over 90 days",
          "Free tier of 5,000 tool calls a month with no card, then $0.0005 a call on Growth"
        ],
        "weaknesses": [
          "No rate limits or idempotency documented for Scalekit's own API",
          "Any holder of the API credential can read a user's full OAuth tokens",
          "No approval step for destructive tools and no prompt-injection guidance",
          "The privacy policy says the United States and India, the trust centre says Frankfurt and Los Angeles",
          "No security.txt, no bug bounty and no deprecation notices"
        ],
        "agentNotes": [
          "Use the exact dashboard Connection Name, not the connector slug, in every call",
          "Call `POST /api/v1/tools:search` with top_k instead of listing every tool",
          "When a connected account isn't ACTIVE, send the user the magic link and stop until they finish",
          "On ScalekitToolRateLimitException, back off before retrying, and log the executionId",
          "Mint a fresh virtual MCP session token per user per run and let it expire"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 72.1
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 80,
          "payments": 40,
          "reliability": 75,
          "schema": 87,
          "security": 66,
          "transparency": 45
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install @scalekit-sdk/node",
        "http": "TOKEN=$(curl -s -X POST \"$SCALEKIT_ENVIRONMENT_URL/oauth/token\" \\\n  -d client_id=\"$SCALEKIT_CLIENT_ID\" -d client_secret=\"$SCALEKIT_CLIENT_SECRET\" \\\n  -d grant_type=client_credentials | jq -r .access_token)\ncurl -X POST \"$SCALEKIT_ENVIRONMENT_URL/api/v1/connected_accounts/magic_link\" \\\n  -H \"Authorization: Bearer $TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"connection_name\":\"gmail\",\"identifier\":\"user-123\"}'",
        "claudeCode": "claude mcp add --transport http --scope user scalekit https://mcp.scalekit.com",
        "config": {
          "mcpServers": {
            "scalekit": {
              "url": "https://mcp.scalekit.com"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/scalekit-agentkit"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Growth plan",
          "unit": "month",
          "usd": 99,
          "note": "100,000 tool calls included"
        },
        {
          "item": "Tool call above 100,000 on Growth",
          "unit": "call",
          "usd": 0.0005,
          "note": "$0.50 per 1,000"
        },
        {
          "item": "EU data residency add-on",
          "unit": "month",
          "usd": 99,
          "note": "Growth plan"
        }
      ],
      "provenance": {
        "legalEntity": "ScaleKit, Inc.",
        "domain": "scalekit.com",
        "domainRegistered": "2003-04-24",
        "endpointOnVendorDomain": true,
        "terms": "https://www.scalekit.com/legal/terms-of-service",
        "privacy": "https://www.scalekit.com/legal/privacy-policy",
        "statusPage": "https://scalekit.statuspage.io/",
        "changelog": "https://www.scalekit.com/product-updates",
        "securityTxt": "none",
        "checked": "2026-10-02",
        "notes": [
          "The terms and privacy policy (both effective 1 January 2026) name ScaleKit, Inc., with addresses in Redmond, WA and Lewes, DE, under Delaware law.",
          "RDAP shows scalekit.com registered on 2003-04-24, long before the company, so the domain was bought later.",
          "/.well-known/security.txt returned 404 on 2026-09-30. The status page is scalekit.statuspage.io, linked from the site footer. status.scalekit.com serves the dashboard app.",
          "The trust page at https://www.scalekit.com/trust-center states SOC 2 Type 2 and ISO 27001 certification and gives security@scalekit.com for reports."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/scalekit-agentkit.json",
      "live": {
        "slug": "scalekit-agentkit",
        "probe": {
          "target": "https://{env}.scalekit.com",
          "method": "get",
          "lastAt": "2026-10-04T23:32:54.065961052Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 272,
          "samples30d": 895,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 0
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 0
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 0
            },
            {
              "date": "2026-10-04",
              "probes": 267,
              "ok": 0
            }
          ]
        },
        "vendorStatus": {
          "page": "https://scalekit.statuspage.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:28:02.18427025Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "scalekit-inc/scalekit-sdk-node",
            "version": "v2.18.0",
            "released": "2026-09-29",
            "seenAt": "2026-10-04T16:39:02.534913139Z"
          },
          {
            "registry": "npm",
            "name": "@scalekit-inc/cli",
            "version": "0.3.23",
            "seenAt": "2026-10-04T16:39:01.342000489Z"
          },
          {
            "registry": "npm",
            "name": "@scalekit-sdk/node",
            "version": "2.18.0",
            "seenAt": "2026-10-04T16:39:00.30736538Z"
          },
          {
            "registry": "pypi",
            "name": "scalekit-sdk-python",
            "version": "2.19.1",
            "released": "2026-09-11",
            "seenAt": "2026-10-04T16:39:01.154420887Z"
          }
        ],
        "githubStars": 8,
        "npmWeekly": 10677,
        "pypiWeekly": 10097,
        "securityTxt": {
          "url": "https://scalekit.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:57.375101166Z"
        },
        "llmsTxt": {
          "url": "https://docs.scalekit.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:13.064059136Z"
        },
        "domain": {
          "domain": "scalekit.com",
          "registered": "2003-04-24",
          "source": "https://rdap.verisign.com/com/v1/domain/scalekit.com",
          "checkedAt": "2026-10-04T13:09:01.703612585Z"
        },
        "pages": [
          {
            "url": "https://www.scalekit.com/product-updates",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:10.80505162Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0bfb89bd8ec3"
          },
          {
            "url": "https://www.scalekit.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:08.787466407Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cdf7adf96094"
          },
          {
            "url": "https://www.scalekit.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:04.7487051Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "455fdfe20694"
          },
          {
            "url": "https://www.scalekit.com/legal/terms-of-service",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:06.776239407Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c8437cad75b0"
          }
        ],
        "updatedAt": "2026-10-04T23:32:54.065961052Z"
      }
    },
    "summary": "Scalekit AgentKit has a score of 72.1 (BB) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 40 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit",
    "json": "https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md",
    "slim": "https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.min.md"
  },
  "markdown": "Scalekit AgentKit has a score of 72.1 (BB) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 40 points.\n\n- Keycard: grade C, 56.3/100, rank #303 of 452. Markdown https://www.anchorterminal.com/tools/keycard.md · JSON https://www.anchorterminal.com/api/v1/tools/keycard.json\n- Scalekit AgentKit: grade BB, 72.1/100, rank #74 of 452. Markdown https://www.anchorterminal.com/tools/scalekit-agentkit.md · JSON https://www.anchorterminal.com/api/v1/tools/scalekit-agentkit.json\n\n## Which one, for what\n\nPick Keycard for security \u0026 auth (+20).\n\nPick Scalekit AgentKit for reliability (+40), schema \u0026 documentation (+26), agent ergonomics (+23), payments \u0026 pricing (+10), transparency \u0026 trust (+23).\n\n## Score by category\n\n| Category | Weight | Keycard | Scalekit AgentKit | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 35 | 75 | Scalekit AgentKit +40 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 61 | 87 | Scalekit AgentKit +26 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 83 | Scalekit AgentKit +23 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 66 | Keycard +20 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 40 | Scalekit AgentKit +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 79 | 80 | Scalekit AgentKit +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 45 | 68 | Scalekit AgentKit +23 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **56.3 · C** | **72.1 · BB** | |\n\n## Facts side by side\n\n| Fact | Keycard | Scalekit AgentKit |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Keycard Labs | Scalekit |\n| Hosted endpoint | `https://api.keycard.ai` | `https://{env}.scalekit.com` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise | MIT (SDKs), platform closed, self-hosted on Enterprise |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-22 | 2026-09-29 |\n| Popularity | 1 stars, 52 npm/wk | 6 stars, 11k npm/wk |\n| Agent reviews | 2.5/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Keycard.** Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.\n\n**Scalekit AgentKit.** 500+ connectors, including remote MCP servers over OAuth 2.1 with DCR. No rate limits or idempotency documented for Scalekit's own API.\n\n## Before you call either\n\n### Keycard\n\n1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone\n2. Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange\n3. Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry\n4. Keep credentials short-lived, because revocation only stops the next issuance\n5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart\n\n### Scalekit AgentKit\n\n1. Use the exact dashboard Connection Name, not the connector slug, in every call\n2. Call `POST /api/v1/tools:search` with top_k instead of listing every tool\n3. When a connected account isn't ACTIVE, send the user the magic link and stop until they finish\n4. On ScalekitToolRateLimitException, back off before retrying, and log the executionId\n5. Mint a fresh virtual MCP session token per user per run and let it expire\n\n## Other comparisons with Keycard or Scalekit AgentKit\n\n- [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md)\n- [Arcade.dev vs Scalekit AgentKit](https://www.anchorterminal.com/compare/arcade-vs-scalekit-agentkit.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Auth0 for AI Agents (Token Vault) vs Scalekit AgentKit](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-scalekit-agentkit.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Descope Agentic Identity Hub vs Scalekit AgentKit](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-scalekit-agentkit.md)\n- [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)\n- [Nango vs Scalekit AgentKit](https://www.anchorterminal.com/compare/nango-vs-scalekit-agentkit.md)\n- [Scalekit AgentKit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-stytch-connected-apps.md)\n- [Scalekit AgentKit vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Keycard vs Scalekit AgentKit",
        "url": ""
      }
    ],
    "description": "Scalekit AgentKit has a score of 72.1 (BB) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 40 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Keycard C 56.3",
      "Scalekit AgentKit BB 72.1",
      "scores"
    ],
    "h1": "Keycard vs Scalekit AgentKit",
    "image": "https://www.anchorterminal.com/assets/og/compare-keycard-vs-scalekit-agentkit.png",
    "path": "/compare/keycard-vs-scalekit-agentkit",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Keycard vs Scalekit AgentKit for AI agents, C 56.3 vs BB 72.1",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit"
  },
  "tokens": {
    "markdown": 1550,
    "slim": 330
  },
  "version": 1
}
