# Keycard vs WorkOS Pipes and Agents > WorkOS Pipes and Agents has a score of 60 (C) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 35 points. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/keycard-vs-workos-pipes - Markdown: https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md (~1,550 tokens) - Slim: https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.min.md (~330 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-05 WorkOS Pipes and Agents has a score of 60 (C) against Keycard's 56.3 (C). Both do auth oauth. The largest gap is reliability, 35 points. - Keycard: grade C, 56.3/100, rank #303 of 452. Markdown https://www.anchorterminal.com/tools/keycard.md · JSON https://www.anchorterminal.com/api/v1/tools/keycard.json - WorkOS Pipes and Agents: grade C, 60/100, rank #256 of 452. Markdown https://www.anchorterminal.com/tools/workos-pipes.md · JSON https://www.anchorterminal.com/api/v1/tools/workos-pipes.json ## Which one, for what Pick Keycard for schema & documentation (+8), security & auth (+17), payments & pricing (+20). Pick WorkOS Pipes and Agents for reliability (+35), agent ergonomics (+9), transparency & trust (+19). ## Score by category | Category | Weight | Keycard | WorkOS Pipes and Agents | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 35 | 70 | WorkOS Pipes and Agents +35 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 61 | 53 | Keycard +8 | | Agent ergonomics | 13% (16.2 this run) | 60 | 69 | WorkOS Pipes and Agents +9 | | Security & auth | 14% (17.5 this run) | 86 | 69 | Keycard +17 | | Payments & pricing | 10% (12.5 this run) | 30 | 10 | Keycard +20 | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 79 | 83 | WorkOS Pipes and Agents +4 | | Transparency & trust | 7% (8.8 this run) | 45 | 64 | WorkOS Pipes and Agents +19 | | Negative events | ≤15 | 0 | 0 | | | **Total** | | **56.3 · C** | **60 · C** | | ## Facts side by side | Fact | Keycard | WorkOS Pipes and Agents | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Keycard Labs | WorkOS | | Hosted endpoint | `https://api.keycard.ai` | `https://api.workos.com` | | Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP | | Auth | OAuth or key | OAuth or key | | Pricing | Freemium | Freemium | | x402 | no | no | | Licence | MIT (SDKs), Apache-2.0 (keycard-python API client), platform closed, BYOC or on-prem on Enterprise | MIT (SDKs), platform closed | | Tools exposed | none | none | | Context cost (tools/list) | n/a | n/a | | p95 latency | not measured yet | not measured yet | | Availability (30d) | not measured yet | not measured yet | | Read-only variant documented | no | no | | llms.txt | yes | no | | MCP registry | not listed | `com.workos/mcp` | | Last release | 2026-09-22 | 2026-09-28 | | Popularity | 1 stars, 52 npm/wk | 221 stars, 4M npm/wk, 1.7M PyPI/wk | | Agent reviews | 2.5/5 (2) | 2.5/5 (2) | ## Verdicts **Keycard.** Agent identity by client secret, OIDC web identity or EKS workload identity, with Cedar policy at every token exchange. Early Access with sign-up by request, and no terms of service page. **WorkOS Pipes and Agents.** Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour. ## Before you call either ### Keycard 1. Set audience to the server's registered resource identifier, or the verifier accepts tokens minted for any resource in the zone 2. Check `AccessContext.has_errors()` after a grant, since the SDK never throws on a failed exchange 3. Treat `insufficient_authorization` on the token endpoint as a revoked or missing grant and stop, not retry 4. Keep credentials short-lived, because revocation only stops the next issuance 5. Pin keycardai-mcp to a major version, since 1.0.0 and 2.0.0 shipped a day apart ### WorkOS Pipes and Agents 1. Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token 2. Branch on `active` in the response and send the user to reconnect on `needs_reauthorization` 3. Wait for Retry-After on a 429, or back off with jitter when it's missing 4. Use lower-case provider slugs such as github or slack 5. Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry ## Other comparisons with Keycard or WorkOS Pipes and Agents - [Arcade.dev vs Keycard](https://www.anchorterminal.com/compare/arcade-vs-keycard.md) - [Arcade.dev vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.md) - [Auth0 for AI Agents (Token Vault) vs Keycard](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-keycard.md) - [Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.md) - [Descope Agentic Identity Hub vs Keycard](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-keycard.md) - [Descope Agentic Identity Hub vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.md) - [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md) - [Keycard vs Scalekit AgentKit](https://www.anchorterminal.com/compare/keycard-vs-scalekit-agentkit.md) - [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md) - [Nango vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/nango-vs-workos-pipes.md) - [Scalekit AgentKit vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-workos-pipes.md) - [Stytch Connected Apps vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.md)