{
  "data": {
    "a": {
      "slug": "keycard",
      "name": "Keycard",
      "vendor": "Keycard Labs",
      "vendorUrl": "https://www.keycard.ai",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Identity and access platform for AI agents.",
      "url": "https://www.anchorterminal.com/tools/keycard",
      "markdownUrl": "https://www.anchorterminal.com/tools/keycard.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/keycard.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/keycard.json",
      "repo": "https://github.com/keycardai/python-sdk",
      "license": "MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.keycard.ai",
      "packages": [
        {
          "registry": "pypi",
          "name": "keycardai-mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai-fastmcp"
        },
        {
          "registry": "npm",
          "name": "@keycardai/mcp"
        },
        {
          "registry": "pypi",
          "name": "keycardai_api"
        }
      ],
      "auth": "mixed",
      "authNotes": "The management API at api.keycard.ai takes `Authorization: Bearer $KEYCARD_API_KEY` (a service account key). Agents and MCP servers talk OAuth 2.0 to their zone at `https://\u003czone-id\u003e.keycard.cloud`, discovered from `/.well-known/oauth-authorization-server`, with PKCE, dynamic client registration and RFC 8693 token exchange against the token endpoint. Application credentials are a client secret, a web identity (OIDC) or EKS workload identity. Tokens are JWTs verified against the zone's JWKS.",
      "pricing": "freemium",
      "pricingNotes": "Starter is free with 5,000 transactions a month as a hard cap, unlimited users, agents and apps, RBAC, ABAC and ReBAC policies, 7-day telemetry retention and community support. Team is $500 a month with 100,000 transactions and $1 per 1,000 after, SSO, zone policy, 90-day retention, email support and an SLA. Enterprise is custom on an annual commitment, with org and device-based policy, SCIM, Active Directory and LDAP provisioning, dedicated, BYOC or on-prem deployment, private networking, customer-managed KMS, 180-day retention, a 99.95 per cent uptime SLA and 1-hour 24/7 response on P1 issues. A transaction is recorded each time Keycard issues a credential, validates an access request or exchanges a credential (https://www.keycard.ai/pricing). The page doesn't say whether a card is needed, and its sign-up form ends with a promise to be in touch. The quickstart calls the product Early Access, with sign-up at console.keycard.ai.",
      "priceSummary": "$500 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1,
        "npmWeekly": 52,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.keycard.ai",
      "llmsTxt": "https://docs.keycard.ai/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "enterprise",
        "self-hosted"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.3,
        "grade": "C",
        "agentReady": false,
        "rank": 303,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 45
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.",
        "strengths": [
          "Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange",
          "Delegated grants with RFC 8693 exchange for GitHub, Google, Slack, Linear and any OAuth 2.0 provider",
          "Session timeline and audit log per exchange, exported hourly to S3 in OCSF Parquet",
          "Published per-unit price ($1 per 1,000 transactions on Team) with a transaction defined",
          "Valid security.txt and SOC 2 Type 2 listed in a SafeBase trust centre"
        ],
        "weaknesses": [
          "Early Access with sign-up by request, and no terms of service page",
          "No per-token kill switch, so a revoked grant lives until the token expires, and revocation doesn't reach the provider",
          "No published rate limits, 429 guidance or public changelog",
          "keycardai-mcp went from 1.0.0 to 2.0.0 in a day in August 2026",
          "Team is $500 a month with nothing between it and the free tier"
        ],
        "agentNotes": [
          "Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone",
          "Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange",
          "Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry",
          "Keep credentials short-lived, because revocation only stops the next issuance",
          "Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.3
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 79,
          "payments": 30,
          "reliability": 35,
          "schema": 61,
          "security": 86,
          "transparency": 25
        },
        "provenanceScore": 65
      },
      "connect": {
        "install": "pip install keycardai-mcp",
        "http": "curl \"https://api.keycard.ai/zones/$KEYCARD_ZONE_ID/sessions\" \\\n  -H \"Authorization: Bearer $KEYCARD_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/keycard"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 500,
          "note": "100,000 transactions included"
        },
        {
          "item": "Transactions above 100,000 on Team",
          "unit": "1k-calls",
          "usd": 1,
          "note": "The pricing page doesn't define a transaction"
        }
      ],
      "provenance": {
        "legalEntity": "Keycard Labs, Inc.",
        "domain": "keycard.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://www.keycard.ai/privacy/",
        "statusPage": "https://status.keycard.ai",
        "changelog": "",
        "securityTxt": "valid",
        "checked": "2026-10-02",
        "notes": [
          "The homepage footer names Keycard Labs, Inc., 103 Foulk Road, Suite 202, Wilmington, DE 19808. The footer's legal links on 2 October were privacy, cookie policy, a vulnerability address and the trust centre at trust.keycard.ai. We found no terms of service page (keycard.ai/terms/ returns 404) and the privacy page's body didn't load for us on 30 September or 2 October.",
          "RDAP for keycard.ai returned 404 at rdap.nic.ai and 429 at Identity Digital on 2026-09-30, so the registration date is blank.",
          "status.keycard.ai answers as a status page, though its history renders client-side and its JSON and RSS feeds returned 403 to us on 2 October.",
          "The docs index (73 entries) lists no changelog. The SDK repositories' CHANGELOG.md files are the nearest thing to release notes.",
          "The trust centre lists SOC 2 Type 1 and Type 2 reports and names Resend, Google, GitHub, Cloudflare and AWS as subprocessors."
        ],
        "score": 65
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/keycard.json",
      "live": {
        "slug": "keycard",
        "probe": {
          "target": "https://api.keycard.ai",
          "method": "get",
          "lastAt": "2026-10-05T02:29:57.507317513Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 273,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 280,
          "p95ms24h": 367,
          "samples24h": 273,
          "samples30d": 929,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 29,
              "ok": 29
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.keycard.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:10.814751767Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@keycardai/mcp",
            "version": "2.0.2",
            "seenAt": "2026-10-04T16:30:47.44448777Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-fastmcp",
            "version": "0.7.1",
            "released": "2026-09-15",
            "seenAt": "2026-10-04T16:30:45.543960623Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai-mcp",
            "version": "2.3.2",
            "released": "2026-09-16",
            "seenAt": "2026-10-04T16:30:45.360722519Z"
          },
          {
            "registry": "pypi",
            "name": "keycardai_api",
            "version": "0.18.0",
            "released": "2026-09-25",
            "seenAt": "2026-10-04T16:30:48.363651419Z"
          }
        ],
        "githubStars": 1,
        "npmWeekly": 211,
        "pypiWeekly": 179,
        "securityTxt": {
          "url": "https://keycard.ai/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-12T00:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:49.895852699Z"
        },
        "llmsTxt": {
          "url": "https://docs.keycard.ai/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:54.842330743Z"
        },
        "domain": {
          "domain": "keycard.ai",
          "registered": "2024-02-04",
          "source": "https://rdap.identitydigital.services/rdap/domain/keycard.ai",
          "checkedAt": "2026-10-04T13:06:32.92261194Z"
        },
        "pages": [
          {
            "url": "https://www.keycard.ai/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:56.738789549Z",
            "changedAt": "2026-10-03T15:38:49.492444489Z",
            "fingerprint": "7d745cb5c53f"
          },
          {
            "url": "https://www.keycard.ai/privacy/",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:58.814741157Z",
            "changedAt": "2026-10-03T15:38:51.566729092Z",
            "fingerprint": "596ae9dc1660"
          }
        ],
        "updatedAt": "2026-10-05T02:29:57.507317513Z"
      }
    },
    "b": {
      "slug": "workos-pipes",
      "name": "WorkOS Pipes and Agents",
      "vendor": "WorkOS",
      "vendorUrl": "https://workos.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "WorkOS tools for connecting agents to third-party accounts, managing access tokens and assigning revocable agent identities.",
      "url": "https://www.anchorterminal.com/tools/workos-pipes",
      "markdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/workos-pipes.json",
      "repo": "https://github.com/workos/workos-node",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.workos.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@workos-inc/node"
        },
        {
          "registry": "pypi",
          "name": "workos"
        }
      ],
      "auth": "mixed",
      "authNotes": "Server calls take the secret key as `Authorization: Bearer $WORKOS_API_KEY` (`sk_...`). End users connect accounts through the Pipes widget or an authorisation URL from `/data-integrations/{slug}/authorize`, which must be opened in the browser, not fetched. Agent tokens are minted from a blueprint as user-delegated, autonomous or agent-delegated sessions. The WorkOS MCP server signs in with OAuth as a dashboard user, with no API key.",
      "pricing": "freemium",
      "pricingNotes": "Pay as you go, with no card to start and a card before production. AuthKit is free up to 1,000,000 monthly active users, then $2,500 a month per extra million. SSO and Directory Sync connections are $125 a month each for the first 15, $100 for 16 to 30, $80 for 31 to 50 and $65 for 51 to 100. Audit Logs are free at the base, with $125 a month per SIEM connection and $99 a month per million events stored. Radar is free for 1,000 checks, then $100 per 50,000. A custom domain is $99 a month. Annual credits plans add volume discounts and a 99.99 per cent SLA (https://workos.com/pricing). Pipes and Agents don't appear on the pricing page, so we don't know what a connection or an agent session costs.",
      "priceSummary": "$125 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 221,
        "npmWeekly": 4041570,
        "pypiWeekly": 1697594,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://workos.com/docs/pipes",
      "registryName": "com.workos/mcp",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "typescript",
        "python",
        "enterprise",
        "webhooks"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60,
        "grade": "C",
        "agentReady": false,
        "rank": 256,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 83,
          "payments": 10,
          "reliability": 70,
          "schema": 53,
          "security": 69,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.",
        "strengths": [
          "Agent identity with per-session revocation and token lifetimes set per blueprint",
          "Pipes covers 500+ providers with user-owned and organisation-owned connections by OAuth, API key or client credentials",
          "Published rate limits of 6,000 requests a minute per key, with Retry-After on a 429",
          "Same platform for SSO, directory sync, RBAC, Audit Logs and Vault",
          "SOC 2 Type 2, a public subprocessor list and a 99.99 per cent SLA on annual plans"
        ],
        "weaknesses": [
          "21 incidents on the status page since 3 July 2026, several over an hour",
          "Pipes and Agents aren't on the pricing page",
          "Deleting a connected account doesn't revoke the grant at the provider",
          "Breaking Pipes change in SDK 11.0.0 on 28 September 2026",
          "No OpenAPI file, llms.txt or security.txt we could find"
        ],
        "agentNotes": [
          "Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token",
          "Branch on `active` in the response and send the user to reconnect on `needs_reauthorization`",
          "Wait for Retry-After on a 429, or back off with jitter when it's missing",
          "Use lower-case provider slugs such as github or slack",
          "Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 83,
          "payments": 10,
          "reliability": 70,
          "schema": 53,
          "security": 69,
          "transparency": 37
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install @workos-inc/node",
        "http": "curl -X POST https://api.workos.com/data-integrations/github/token -H \"Authorization: Bearer $WORKOS_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"user_id\":\"user_01EHZNVPK3SFK441A1RGBFSHRT\"}'",
        "claudeCode": "claude mcp add --transport http --scope user workos https://mcp.workos.com/mcp",
        "config": {
          "mcpServers": {
            "workos": {
              "url": "https://mcp.workos.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/workos-pipes"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "SSO or Directory Sync connection (first 15)",
          "unit": "month",
          "usd": 125,
          "note": "Per connection per month, falling to $65 above 50"
        },
        {
          "item": "Audit Logs SIEM connection",
          "unit": "month",
          "usd": 125,
          "note": "Plus $99 a month per million events stored"
        },
        {
          "item": "Custom domain",
          "unit": "month",
          "usd": 99,
          "note": "AuthKit, Admin Portal and email sender"
        }
      ],
      "provenance": {
        "legalEntity": "WorkOS, Inc.",
        "domain": "workos.com",
        "domainRegistered": "2005-02-02",
        "endpointOnVendorDomain": true,
        "terms": "https://workos.com/legal/terms",
        "privacy": "https://workos.com/legal/privacy",
        "statusPage": "https://status.workos.com",
        "changelog": "https://github.com/workos/workos-node/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The website terms (effective 29 October 2020) name WorkOS, Inc. and California law. The privacy policy was updated 20 October 2025 and doesn't say where data is stored.",
          "RDAP shows workos.com registered on 2005-02-02, years before the company, so the domain was bought later.",
          "/.well-known/security.txt returned 404 on 2026-09-30."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/workos-pipes.json",
      "live": {
        "slug": "workos-pipes",
        "probe": {
          "target": "https://api.workos.com",
          "method": "get",
          "lastAt": "2026-10-05T02:30:05.302891189Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 111,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 128,
          "p95ms24h": 188,
          "samples24h": 273,
          "samples30d": 929,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 29,
              "ok": 29
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.workos.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T02:29:16.64443803Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "workos/workos-node",
            "version": "v11.0.0",
            "released": "2026-09-28",
            "seenAt": "2026-10-04T16:44:14.997893727Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.workos/mcp",
            "version": "1.0.0",
            "seenAt": "2026-10-04T23:42:40.113054682Z"
          },
          {
            "registry": "npm",
            "name": "@workos-inc/node",
            "version": "11.0.0",
            "seenAt": "2026-10-04T16:44:14.113290354Z"
          },
          {
            "registry": "pypi",
            "name": "workos",
            "version": "10.5.0",
            "released": "2026-09-24",
            "seenAt": "2026-10-04T16:44:14.80123694Z"
          }
        ],
        "githubStars": 223,
        "npmWeekly": 4341866,
        "pypiWeekly": 1819216,
        "securityTxt": {
          "url": "https://workos.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:42.791540879Z"
        },
        "domain": {
          "domain": "workos.com",
          "registered": "2005-02-02",
          "source": "https://rdap.verisign.com/com/v1/domain/workos.com",
          "checkedAt": "2026-10-04T13:09:49.925296041Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/workos/workos-node/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:01.225770024Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "57d8be278609"
          },
          {
            "url": "https://workos.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:58.671443903Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0cdd6961c090"
          },
          {
            "url": "https://workos.com/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:54.606253176Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5fc970fc9d08"
          },
          {
            "url": "https://workos.com/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:56.692868313Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b3130dd8035"
          }
        ],
        "updatedAt": "2026-10-05T02:30:05.302891189Z"
      }
    },
    "summary": "WorkOS Pipes and Agents has a score of 60 (C) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 35 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes",
    "json": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md",
    "slim": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.min.md"
  },
  "markdown": "WorkOS Pipes and Agents has a score of 60 (C) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 35 points.\n\n- Keycard: grade C, 56.3/100, rank #303 of 452. Markdown https://www.anchorterminal.com/tools/keycard.md · JSON https://www.anchorterminal.com/api/v1/tools/keycard.json\n- WorkOS Pipes and Agents: grade C, 60/100, rank #256 of 452. Markdown https://www.anchorterminal.com/tools/workos-pipes.md · JSON https://www.anchorterminal.com/api/v1/tools/workos-pipes.json\n\n## Which one, for what\n\nPick Keycard for schema \u0026 documentation (+8), security \u0026 auth (+17), payments \u0026 pricing (+20).\n\nPick WorkOS Pipes and Agents for reliability (+35), agent ergonomics (+9), transparency \u0026 trust (+19).\n\n## Score by category\n\n| Category | Weight | Keycard | WorkOS Pipes and Agents | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 35 | 70 | WorkOS Pipes and Agents +35 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 61 | 53 | Keycard +8 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 69 | WorkOS Pipes and Agents +9 |\n| Security \u0026 auth | 14% (17.5 this run) | 86 | 69 | Keycard +17 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 10 | Keycard +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 79 | 83 | WorkOS Pipes and Agents +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 45 | 64 | WorkOS Pipes and Agents +19 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **56.3 · C** | **60 · C** | |\n\n## Facts side by side\n\n| Fact | Keycard | WorkOS Pipes and Agents |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Keycard Labs | WorkOS |\n| Hosted endpoint | `https://api.keycard.ai` | `https://api.workos.com` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise | MIT (SDKs), platform closed |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | not listed | `com.workos/mcp` |\n| Last release | 2026-09-22 | 2026-09-28 |\n| Popularity | 1 stars, 52 npm/wk | 221 stars, 4M npm/wk, 1.7M PyPI/wk |\n| Agent reviews | 2.5/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Keycard.** Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page.\n\n**WorkOS Pipes and Agents.** Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.\n\n## Before you call either\n\n### Keycard\n\n1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone\n2. Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange\n3. Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry\n4. Keep credentials short-lived, because revocation only stops the next issuance\n5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart\n\n### WorkOS Pipes and Agents\n\n1. Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token\n2. Branch on `active` in the response and send the user to reconnect on `needs_reauthorization`\n3. Wait for Retry-After on a 429, or back off with jitter when it's missing\n4. Use lower-case provider slugs such as github or slack\n5. Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry\n\n## Other comparisons with Keycard or WorkOS Pipes and Agents\n\n- [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md)\n- [Arcade.dev vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.md)\n- [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md)\n- [Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.md)\n- [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md)\n- [Descope Agentic Identity Hub vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.md)\n- [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md)\n- [Keycard vs Scalekit AgentKit](https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Nango vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/nango-vs-workos-pipes.md)\n- [Scalekit AgentKit vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-workos-pipes.md)\n- [Stytch Connected Apps vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Keycard vs WorkOS Pipes and Agents",
        "url": ""
      }
    ],
    "description": "WorkOS Pipes and Agents has a score of 60 (C) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 35 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Keycard C 56.3",
      "WorkOS Pipes and Agents C 60",
      "scores"
    ],
    "h1": "Keycard vs WorkOS Pipes and Agents",
    "image": "https://www.anchorterminal.com/assets/og/compare-keycard-vs-workos-pipes.png",
    "path": "/compare/keycard-vs-workos-pipes",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Keycard vs WorkOS Pipes and Agents for AI agents, C 56.3 vs C 60",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/keycard-vs-workos-pipes"
  },
  "tokens": {
    "markdown": 1550,
    "slim": 330
  },
  "version": 1
}
