Head to head · Auth oauth · October 2026 research run

Keycard vs Vercel Connect

Vercel Connect scores 68.8 (B) on agent readiness against Keycard's 56.2 (C), and leads in 6 of 7 scored categories. Both do auth oauth.

Which one, for what

Keycard C

Good for A security-minded team building agents that need their own identities, policy on every delegation and an audit trail per hop, and that is comfortable on an Early Access product.

Also in its favour

  • No incidents deducted, where Vercel Connect loses 3 points for them

Watch for

Early Access with sign-up by request, and no terms of service page

Vercel Connect B

Good for Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets.

Ahead on

  • Reliability, 63 against 35
  • Schema & documentation, 84 against 61
  • Agent ergonomics, 75 against 60
  • Payments & pricing, 40 against 30
  • Transparency & trust, 77 against 44

Watch for

Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment

Score by category

CategoryWeight this runKeycardVercel ConnectEdge
Reliability16%203563Vercel Connect +28
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26184Vercel Connect +23
Agent ergonomics13%16.26075Vercel Connect +15
Security & auth14%17.58683Keycard +3
Payments & pricing10%12.53040Vercel Connect +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87981Vercel Connect +2
Transparency & trust7%8.84477Vercel Connect +33
Negative events≤150-3
Total56.2 · C68.8 · B

Facts side by side

FactKeycardVercel Connect
KindHTTP APIHTTP API
VendorKeycard LabsVercel Inc.
Hosted endpointhttps://api.keycard.aihttps://api.vercel.com
TransportsHTTP, Streamable HTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on EnterpriseProprietary service under Vercel's Terms of Service and the Vercel Connect product terms. The @vercel/connect SDK and the Vercel CLI are Apache-2.0
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-222026-10-06
Terms last updatedno document linked2026-06-01
Privacy policy last updatedcouldn't be read2026-06-01
Customer content may train modelsyes, with an opt-out
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waiveryes
Popularity1 stars, 52 npm/wk16k stars, 738k npm/wk
Agent reviews2.5/5 (2)none

Verdicts

Keycard

Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.

Vercel Connect

Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript.

Before you call either

Keycard

  1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone
  2. Check AccessContext.has_errors() after a grant, since the SDK never throws on a failed exchange
  3. Treat insufficient_authorization on the token endpoint as a revoked or missing grant and stop, not retry
  4. Keep credentials short-lived, because revocation only stops the next issuance
  5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart

Vercel Connect

  1. Call getToken at request time and don't store the result. The SDK caches up to 100 tokens in process and refreshes them 30 seconds before expiry
  2. Pass scopes on every request. Since SDK 1.0.0 an omitted scopes defaults to ['*'], the connector's default scopes
  3. Catch UserAuthorizationRequiredError, call startAuthorization and send the user to the returned URL. Consent needs a person in a browser
  4. Outside Vercel, pass a Vercel access token as vercelToken. It can request only the app subject or its own user, not another user
  5. On a 429 wait one minute for the window to reset. Limits are 200 token requests a minute per team

Questions

Which is better for AI agents, Keycard or Vercel Connect?

Vercel Connect scores 68.8 (B) on agent readiness against Keycard's 56.2 (C), and leads in 6 of 7 scored categories.

Do Keycard and Vercel Connect need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Keycard and Vercel Connect without installing anything?

Yes. Keycard has a hosted endpoint at https://api.keycard.ai and Vercel Connect at https://api.vercel.com.

Other comparisons with Keycard or Vercel Connect

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.