Head to head · Auth oauth · October 2026 research run
Keycard vs WorkOS Pipes and Agents
WorkOS Pipes and Agents has a score of 60 (C) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 35 points.
Which one, for what
Pick Keycard for
- schema & documentation (+8)
- security & auth (+17)
- payments & pricing (+20)
Pick WorkOS Pipes and Agents for
- reliability (+35)
- agent ergonomics (+9)
- transparency & trust (+19)
Score by category
| Category | Weight this run | Keycard | WorkOS Pipes and Agents | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 35 | 70 | WorkOS Pipes and Agents +35 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 61 | 53 | Keycard +8 |
| Agent ergonomics | 13%16.2 | 60 | 69 | WorkOS Pipes and Agents +9 |
| Security & auth | 14%17.5 | 86 | 69 | Keycard +17 |
| Payments & pricing | 10%12.5 | 30 | 10 | Keycard +20 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 79 | 83 | WorkOS Pipes and Agents +4 |
| Transparency & trust | 7%8.8 | 45 | 64 | WorkOS Pipes and Agents +19 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 56.3 · C | 60 · C |
Facts side by side
| Fact | Keycard | WorkOS Pipes and Agents |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Keycard Labs | WorkOS |
| Hosted endpoint | https://api.keycard.ai | https://api.workos.com |
| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise | MIT (SDKs), platform closed |
| Tools exposed | none | none |
| Context cost (tools/list) | n/a | n/a |
| p95 latency | not measured yet | not measured yet |
| Availability (30d) | not measured yet | not measured yet |
| Read-only variant documented | no | no |
| llms.txt | yes | no |
| MCP registry | not listed | com.workos/mcp |
| Last release | 2026-09-22 | 2026-09-28 |
| Popularity | 1 stars, 52 npm/wk | 221 stars, 4M npm/wk, 1.7M PyPI/wk |
| Agent reviews | 2.5/5 (2) | 2.5/5 (2) |
Verdicts
Keycard
Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.
WorkOS Pipes and Agents
Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.
Before you call either
Keycard
- Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone
- Check
AccessContext.has_errors()after a grant, since the SDK never throws on a failed exchange - Treat
insufficient_authorizationon the token endpoint as a revoked or missing grant and stop, not retry - Keep credentials short-lived, because revocation only stops the next issuance
- Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart
WorkOS Pipes and Agents
- Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token
- Branch on
activein the response and send the user to reconnect onneeds_reauthorization - Wait for Retry-After on a 429, or back off with jitter when it's missing
- Use lower-case provider slugs such as github or slack
- Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry
Other comparisons with Keycard or WorkOS Pipes and Agents
- Arcade.dev vs Keycard
- Arcade.dev vs WorkOS Pipes and Agents
- Auth0 for AI Agents (Token Vault) vs Keycard
- Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents
- Descope Agentic Identity Hub vs Keycard
- Descope Agentic Identity Hub vs WorkOS Pipes and Agents
- Keycard vs Nango
- Keycard vs Scalekit AgentKit
- Keycard vs Stytch Connected Apps
- Nango vs WorkOS Pipes and Agents
- Scalekit AgentKit vs WorkOS Pipes and Agents
- Stytch Connected Apps vs WorkOS Pipes and Agents
Machine-readable
/api/v1/tools/keycard.json·/api/v1/tools/workos-pipes.json- This page as Markdown,
/compare/keycard-vs-workos-pipes.md