Head to head · Auth oauth · October 2026 research run

Keycard vs WorkOS Pipes and Agents

WorkOS Pipes and Agents has a score of 60 (C) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 35 points.

Which one, for what

Pick Keycard for

  • schema & documentation (+8)
  • security & auth (+17)
  • payments & pricing (+20)

Pick WorkOS Pipes and Agents for

  • reliability (+35)
  • agent ergonomics (+9)
  • transparency & trust (+19)

Score by category

CategoryWeight this runKeycardWorkOS Pipes and AgentsEdge
Reliability16%203570WorkOS Pipes and Agents +35
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26153Keycard +8
Agent ergonomics13%16.26069WorkOS Pipes and Agents +9
Security & auth14%17.58669Keycard +17
Payments & pricing10%12.53010Keycard +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87983WorkOS Pipes and Agents +4
Transparency & trust7%8.84564WorkOS Pipes and Agents +19
Negative events≤1500
Total56.3 · C60 · C

Facts side by side

FactKeycardWorkOS Pipes and Agents
KindHTTP APIHTTP API
VendorKeycard LabsWorkOS
Hosted endpointhttps://api.keycard.aihttps://api.workos.com
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on EnterpriseMIT (SDKs), platform closed
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesno
MCP registrynot listedcom.workos/mcp
Last release2026-09-222026-09-28
Popularity1 stars, 52 npm/wk221 stars, 4M npm/wk, 1.7M PyPI/wk
Agent reviews2.5/5 (2)2.5/5 (2)

Verdicts

Keycard

Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.

WorkOS Pipes and Agents

Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.

Before you call either

Keycard

  1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone
  2. Check AccessContext.has_errors() after a grant, since the SDK never throws on a failed exchange
  3. Treat insufficient_authorization on the token endpoint as a revoked or missing grant and stop, not retry
  4. Keep credentials short-lived, because revocation only stops the next issuance
  5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart

WorkOS Pipes and Agents

  1. Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token
  2. Branch on active in the response and send the user to reconnect on needs_reauthorization
  3. Wait for Retry-After on a 429, or back off with jitter when it's missing
  4. Use lower-case provider slugs such as github or slack
  5. Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry

Other comparisons with Keycard or WorkOS Pipes and Agents

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.