{
  "data": {
    "a": {
      "slug": "microsoft-entra-agent-id",
      "name": "Microsoft Entra Agent ID",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph.",
      "url": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json",
      "repo": "https://github.com/AzureAD/microsoft-identity-web",
      "license": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
      "packages": [
        {
          "registry": "nuget",
          "name": "Microsoft.Identity.Web.AgentIdentities"
        }
      ],
      "auth": "oauth",
      "authNotes": "Access starts with a Microsoft Entra tenant and a person holding the Agent ID Developer or Agent ID Administrator role, who creates an agent identity blueprint. The blueprint authenticates to login.microsoftonline.com with a managed identity, a certificate or a client secret (Microsoft advises against secrets in production) and exchanges for a token as one of its agent identities. Agent identities hold no credentials. Three flows exist, which are app-only, on behalf of a signed-in user, and as the agent's own user account. Interactive `/authorize` and public clients aren't supported. Management calls on Microsoft Graph need AgentIdentity.Create.All or AgentIdentity.ReadWrite.All.",
      "pricing": "freemium",
      "pricingNotes": "Microsoft's docs say Agent ID is available to all Microsoft Entra customers, and Entra ID Free comes with any Microsoft cloud subscription. No per-agent price is published. Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15.00 a user a month on yearly billing, or Microsoft 365 E7 at $99.00. Conditional Access for agents also needs Entra P1 or Microsoft 365 E3 alongside Agent 365. No sandbox was found in the Agent ID docs (https://www.microsoft.com/en-us/microsoft-agent-365, checked 2026-10-08).",
      "priceSummary": "$15 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Agent ID docs, the Graph reference or the pricing pages (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 787,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.agent-identity",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "oauth",
        "openapi",
        "dotnet",
        "sidecar",
        "microsoft-graph",
        "mcp",
        "freemium",
        "sla"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 63,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 74
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.",
        "bestFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
        "strengths": [
          "Agent identities can't hold credentials. The blueprint authenticates with a managed identity, certificate or secret and exchanges for the agent's token",
          "Global Administrator and similar roles, and Graph permissions such as Application.ReadWrite.All, are refused for agent identities",
          "Create, list, update, delete and restore are on Microsoft Graph v1.0, with agentIdentity in the public OpenAPI file",
          "Audit and sign-in logs carry an agentType and blueprintId for agent activity",
          "Microsoft.Identity.Web 4.16.0 shipped on 30 September 2026, the eighth tagged release since 9 July"
        ],
        "weaknesses": [
          "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing",
          "Microsoft's docs call hand-written token exchange complex and error-prone and steer developers to a .NET library or a sidecar container",
          "Creating a blueprint, a principal and an identity in quick succession can fail with 400 until the directory replicates",
          "Audit and sign-in logs are kept seven days on Entra ID Free and 30 days on P1 or P2",
          "microsoft.com's security.txt passed its Expires date on 23 September 2026"
        ],
        "agentNotes": [
          "Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token",
          "Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object",
          "Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required",
          "Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page",
          "Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.4
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 63
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "dotnet add package Microsoft.Identity.Web.AgentIdentities",
        "http": "curl -X POST https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity \\\n  -H \"Authorization: Bearer $BLUEPRINT_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"displayName\": \"My Agent Identity\", \"agentIdentityBlueprintId\": \"\u003cblueprint-app-id\u003e\", \"sponsors@odata.bind\": [\"https://graph.microsoft.com/v1.0/users/\u003cid\u003e\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/microsoft-entra-agent-id"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Microsoft Agent 365",
          "unit": "seat-month",
          "usd": 15,
          "note": "billed yearly, needed for Conditional Access, ID Protection and governance for agents"
        },
        {
          "item": "Microsoft 365 E7 (includes Agent 365)",
          "unit": "seat-month",
          "usd": 99,
          "note": "billed yearly"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://www.microsoft.com/en-us/privacy/privacystatement",
        "statusPage": "https://azure.status.microsoft/en-us/status/history/",
        "changelog": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.",
          "The Microsoft APIs terms of use cover the Microsoft Graph API and other APIs that reach directory data, and were last updated in October 2025. Tenant use of Entra also falls under the customer's Microsoft licensing agreement and the Product Terms, which we didn't read.",
          "The Microsoft privacy statement was last updated in September 2026.",
          "Tokens come from login.microsoftonline.com and management calls go to graph.microsoft.com, both Microsoft domains.",
          "Entra's SLA page sends readers to the Azure status history for incidents that affect Entra ID.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.json",
      "live": {
        "slug": "microsoft-entra-agent-id",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
          "method": "get",
          "lastAt": "2026-10-08T20:21:20.147544694Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 57,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 32,
          "p95ms24h": 172,
          "samples24h": 32,
          "samples30d": 32,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 32,
              "ok": 32
            }
          ]
        },
        "vendorStatus": {
          "page": "https://azure.status.microsoft/en-us/status/history",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:47.070808325Z"
        },
        "pages": [
          {
            "url": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:21:36.290153566Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "bca4f93493d4"
          },
          {
            "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:21:38.182590643Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1a1ee1c20d9a"
          }
        ],
        "updatedAt": "2026-10-08T20:21:20.147544694Z"
      }
    },
    "answer": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Nango's 67.7 (B), and leads in 3 of 7 scored categories. Nango leads on payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "nango",
      "name": "Nango",
      "vendor": "Nango",
      "vendorUrl": "https://www.nango.dev",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Source-available integration platform that handles OAuth, API keys and token refresh for 1,000+ APIs on behalf of your users.",
      "url": "https://www.anchorterminal.com/tools/nango",
      "markdownUrl": "https://www.anchorterminal.com/tools/nango.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nango.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nango.json",
      "repo": "https://github.com/NangoHQ/nango",
      "license": "Elastic License 2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.nango.dev",
      "packages": [
        {
          "registry": "npm",
          "name": "@nangohq/node"
        },
        {
          "registry": "npm",
          "name": "@nangohq/frontend"
        }
      ],
      "auth": "mixed",
      "authNotes": "Backend calls take an environment secret key as `Authorization: Bearer $NANGO_SECRET_KEY`, and API keys can be scoped (agent sessions need `environment:agent_sessions:write`). End users connect through a short-lived connect session token in the Connect UI. An agent session returns its own MCP URL and `session_token`, sent as a Bearer token. The Management MCP at mcp.nango.dev signs in with OAuth.",
      "pricing": "freemium",
      "pricingNotes": "Three plans since 2 September 2026. Free is $0 with 10 connections, 10 compute hours and 10 GB of data transfer a month and no card. Pay-as-you-go is $50 a month returned as $50 of usage credits, then $0.29 per connection a month, $0.72 per compute hour and $0.50 per GB. The Growth add-on is $450 a month and adds faster integration delivery (5 days instead of 20) and a private Slack channel, and the changelog of 2 September also puts RBAC, OpenTelemetry export, Connect UI branding, SAML SSO for your team and a HIPAA BAA under it. Enterprise is custom, with connections from $0.01 at volume, 2-day integration delivery, BYOC and self-hosting, dedicated SLAs, and the pricing page lists HIPAA, SAML SSO, SCIM and the audit trail there (https://www.nango.dev/pricing, https://nango.dev/docs/updates/changelog). Free self-hosting covers auth and proxy only, with no MCP server, syncs or webhooks (https://nango.dev/docs/guides/platform/free-self-hosting).",
      "priceSummary": "$50 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 469086,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://nango.dev/docs",
      "llmsTxt": "https://nango.dev/docs/llms.txt",
      "openapi": "https://raw.githubusercontent.com/NangoHQ/nango/master/docs/spec.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.audit",
        "agent.tools",
        "automation.embedded"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "freemium",
        "free-tier",
        "mcp",
        "llms-txt",
        "openapi",
        "oauth",
        "typescript",
        "webhooks",
        "source-available",
        "enterprise"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.7,
        "grade": "B",
        "agentReady": false,
        "rank": 199,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 90,
          "payments": 40,
          "reliability": 78,
          "schema": 85,
          "security": 67,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "2026-09-04, CVE-2026-9317 (CVSS 9.2). The runner's tRPC server in Nango before 0.71.6 didn't enforce RUNNER_SECRET_KEY, so anyone who could reach the runner port could run arbitrary JavaScript. Fixed in 0.71.6. Recent and critical, though it needs network access to the runner (https://github.com/advisories/GHSA-9cph-w8mv-q56r)",
          "2026-09-16, CVE-2026-92804 (high). Nango through 0.70.4 didn't validate caller-supplied connection configuration values. Fixed in later releases. Together with the runner flaw we deduct 5, less than the maximum because both are fixed and disclosed (https://github.com/advisories/GHSA-29mm-6vmq-g8cg)"
        ],
        "verdict": "1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.",
        "bestFor": "A product that connects many users to many SaaS APIs and wants tokens, refresh, syncs and a per-tenant MCP surface in one place, with source you can read.",
        "strengths": [
          "1,000+ APIs with OAuth, API key and client-credentials auth handled",
          "Per-tenant agent sessions served as an MCP server, credentials never shown to the agent",
          "Encryption, retention and deletion rules published in the docs",
          "Per-unit prices in public ($0.29 a connection a month) and a free plan with no card",
          "Source on GitHub under ELv2, 31 open issues against more than 7,000 filed"
        ],
        "weaknesses": [
          "Audit trail only on Enterprise, and logs kept 15 days on every plan",
          "Two CVEs fixed in September 2026, one critical, neither on Nango's own advisory page",
          "Status page tracks a single component",
          "No prompt-injection guidance for content agent sessions pass through",
          "ELv2 bars offering Nango itself as a hosted service"
        ],
        "agentNotes": [
          "Create one agent session per tenant from your backend and pass only the mcp_url and session_token to the agent",
          "Tag connections with your own user and organisation IDs so sessions can select them",
          "Listen for the refresh-failure webhook and send the user a reconnect link instead of retrying",
          "Read the rate-limit headers on a 429 and wait for the reset before resuming",
          "Run 0.71.6 or later when self-hosting, and keep the runner port off the network"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.7
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 90,
          "payments": 40,
          "reliability": 78,
          "schema": 85,
          "security": 67,
          "transparency": 63
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "npm install @nangohq/node",
        "http": "curl -X POST https://api.nango.dev/connect/sessions -H \"Authorization: Bearer $NANGO_SECRET_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"tags\":{\"end_user_id\":\"user-123\"}}'",
        "claudeCode": "claude mcp add --transport http nango-management --scope user https://mcp.nango.dev/mcp",
        "config": {
          "mcpServers": {
            "nango-management": {
              "url": "https://mcp.nango.dev/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/nango"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Pay-as-you-go subscription",
          "unit": "month",
          "usd": 50,
          "note": "Returned as $50 of usage credits each month"
        },
        {
          "item": "Connection on Pay-as-you-go",
          "unit": "account-month",
          "usd": 0.29,
          "note": "Per connected end-user account per month"
        },
        {
          "item": "Data transfer on Pay-as-you-go",
          "unit": "gb",
          "usd": 0.5,
          "note": "10 GB a month free. Compute is $0.72 an hour"
        },
        {
          "item": "Growth add-on",
          "unit": "month",
          "usd": 450,
          "note": "Faster integration delivery, private Slack, RBAC, branding, SAML SSO, HIPAA BAA"
        }
      ],
      "provenance": {
        "legalEntity": "Nango Inc",
        "domain": "nango.dev",
        "domainRegistered": "2022-05-31",
        "endpointOnVendorDomain": true,
        "terms": "https://www.nango.dev/terms",
        "privacy": "https://www.nango.dev/privacy-policy",
        "statusPage": "https://status.nango.dev",
        "changelog": "https://nango.dev/docs/updates/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The legal entity comes from the copyright line in the repository's LICENSE_SHORT, because we couldn't read the terms page on 2026-09-30.",
          "SECURITY.md asks for reports to security@nango.dev or a private GitHub advisory. The Trust Center at trust.nango.dev holds the SOC 2 report.",
          "status.nango.dev is a Better Stack page with one component, Nango Cloud Health."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/nango.json",
      "live": {
        "slug": "nango",
        "probe": {
          "target": "https://api.nango.dev",
          "method": "get",
          "lastAt": "2026-10-08T20:21:20.911297136Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 460,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 451,
          "p95ms24h": 600,
          "samples24h": 272,
          "samples30d": 1946,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 230,
              "ok": 230
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.nango.dev",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:49.851036321Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "NangoHQ/nango",
            "version": "v0.71.12",
            "released": "2026-10-02",
            "seenAt": "2026-10-08T16:22:20.7927292Z"
          },
          {
            "registry": "npm",
            "name": "@nangohq/frontend",
            "version": "0.71.12",
            "seenAt": "2026-10-08T16:22:19.220575591Z"
          },
          {
            "registry": "npm",
            "name": "@nangohq/node",
            "version": "0.71.12",
            "seenAt": "2026-10-08T16:22:18.408405571Z"
          }
        ],
        "githubStars": 12565,
        "npmWeekly": 574885,
        "securityTxt": {
          "url": "https://nango.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-12-31T23:59:59.000Z",
          "checkedAt": "2026-10-08T15:38:54.043924869Z"
        },
        "llmsTxt": {
          "url": "https://nango.dev/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:41.879573019Z"
        },
        "domain": {
          "domain": "nango.dev",
          "registered": "2022-05-31",
          "source": "https://pubapi.registry.google/rdap/domain/nango.dev",
          "checkedAt": "2026-10-04T13:09:24.044829714Z"
        },
        "pages": [
          {
            "url": "https://nango.dev/docs/updates/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:17.802547108Z",
            "changedAt": "2026-10-08T18:22:17.802547108Z",
            "fingerprint": "7434beb81e90"
          },
          {
            "url": "https://www.nango.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:29:19.012567466Z",
            "changedAt": "2026-10-07T18:13:03.16074757Z",
            "fingerprint": "adec6a07286e"
          },
          {
            "url": "https://www.nango.dev/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-08T18:29:21.716296026Z",
            "changedAt": "2026-10-05T16:03:46.071317875Z",
            "fingerprint": "45daea61757a"
          },
          {
            "url": "https://www.nango.dev/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:29:23.439595351Z",
            "changedAt": "2026-10-05T16:03:48.100151405Z",
            "fingerprint": "f40a407279cf"
          }
        ],
        "updatedAt": "2026-10-08T20:21:20.911297136Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Microsoft",
        "b": "Nango",
        "name": "Vendor"
      },
      {
        "a": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
        "b": "https://api.nango.dev",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
        "b": "Elastic License 2.0",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-09-30",
        "name": "Last release"
      },
      {
        "a": "2025-10-01",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-01",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "787 stars",
        "b": "469k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Nango's 67.7 (B), and leads in 3 of 7 scored categories. Nango leads on payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Microsoft Entra Agent ID or Nango?"
      },
      {
        "answer": "Microsoft Entra Agent ID uses an OAuth sign-in. Nango takes an API key or an OAuth sign-in.",
        "question": "Do Microsoft Entra Agent ID and Nango need an API key?"
      },
      {
        "answer": "Yes. Microsoft Entra Agent ID has a hosted endpoint at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity and Nango at https://api.nango.dev.",
        "question": "Can an agent call Microsoft Entra Agent ID and Nango without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 91 against 78",
          "Security \u0026 auth, 83 against 67"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "No incidents deducted, where Nango loses 5 points for them"
        ],
        "goodFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
        "slug": "microsoft-entra-agent-id",
        "watchFor": "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 40 against 20",
          "Maintenance \u0026 community, 90 against 80"
        ],
        "also": null,
        "goodFor": "A product that connects many users to many SaaS APIs and wants tokens, refresh, syncs and a per-tenant MCP surface in one place, with source you can read.",
        "slug": "nango",
        "watchFor": "Audit trail only on Enterprise, and logs kept 15 days on every plan"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.json",
        "title": "Aembit vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-nango.json",
        "title": "Aembit vs Nango",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.json",
        "title": "Arcade.dev vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-nango.json",
        "title": "Arcade.dev vs Nango",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Nango",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.json",
        "title": "Descope Agentic Identity Hub vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.json",
        "title": "Descope Agentic Identity Hub vs Nango",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.json",
        "title": "Keycard vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-nango.json",
        "title": "Keycard vs Nango",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.json",
        "title": "Microsoft Entra Agent ID vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.json",
        "title": "Microsoft Entra Agent ID vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.json",
        "title": "Microsoft Entra Agent ID vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nango-vs-scalekit-agentkit.json",
        "title": "Nango vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/nango-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps.json",
        "title": "Nango vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nango-vs-workos-pipes.json",
        "title": "Nango vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/nango-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "by": 13,
        "edge": "microsoft-entra-agent-id",
        "key": "reliability",
        "microsoft-entra-agent-id": 91,
        "name": "Reliability",
        "nango": 78,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "microsoft-entra-agent-id",
        "key": "schema",
        "microsoft-entra-agent-id": 87,
        "name": "Schema \u0026 documentation",
        "nango": 85,
        "weight": 13
      },
      {
        "by": 3,
        "edge": "nango",
        "key": "ergonomics",
        "microsoft-entra-agent-id": 71,
        "name": "Agent ergonomics",
        "nango": 74,
        "weight": 13
      },
      {
        "by": 16,
        "edge": "microsoft-entra-agent-id",
        "key": "security",
        "microsoft-entra-agent-id": 83,
        "name": "Security \u0026 auth",
        "nango": 67,
        "weight": 14
      },
      {
        "by": 20,
        "edge": "nango",
        "key": "payments",
        "microsoft-entra-agent-id": 20,
        "name": "Payments \u0026 pricing",
        "nango": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 10,
        "edge": "nango",
        "key": "maintenance",
        "microsoft-entra-agent-id": 80,
        "name": "Maintenance \u0026 community",
        "nango": 90,
        "weight": 7
      },
      {
        "by": 2,
        "edge": "nango",
        "key": "transparency",
        "microsoft-entra-agent-id": 74,
        "name": "Transparency \u0026 trust",
        "nango": 76,
        "weight": 7
      }
    ],
    "summary": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Nango's 67.7 (B), and leads in 3 of 7 scored categories. Nango leads on payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth.",
    "verdicts": {
      "microsoft-entra-agent-id": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.",
      "nango": "1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango",
    "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.md",
    "slim": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.min.md"
  },
  "markdown": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Nango's 67.7 (B), and leads in 3 of 7 scored categories. Nango leads on payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth.\n\n- Microsoft Entra Agent ID: grade BB, 74.4/100, rank #63 of 722. Markdown https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json\n- Nango: grade B, 67.7/100, rank #199 of 722. Markdown https://www.anchorterminal.com/tools/nango.md · JSON https://www.anchorterminal.com/api/v1/tools/nango.json\n\n## Which one, for what\n\n### Microsoft Entra Agent ID (BB)\n\nGood for: Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.\n\nAhead on:\n- Reliability, 91 against 78\n- Security \u0026 auth, 83 against 67\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- No incidents deducted, where Nango loses 5 points for them\n\nWatch for: Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing\n\n### Nango (B)\n\nGood for: A product that connects many users to many SaaS APIs and wants tokens, refresh, syncs and a per-tenant MCP surface in one place, with source you can read.\n\nAhead on:\n- Payments \u0026 pricing, 40 against 20\n- Maintenance \u0026 community, 90 against 80\n\nWatch for: Audit trail only on Enterprise, and logs kept 15 days on every plan\n\n\n## Score by category\n\n| Category | Weight | Microsoft Entra Agent ID | Nango | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 91 | 78 | Microsoft Entra Agent ID +13 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 87 | 85 | Microsoft Entra Agent ID +2 |\n| Agent ergonomics | 13% (16.2 this run) | 71 | 74 | Nango +3 |\n| Security \u0026 auth | 14% (17.5 this run) | 83 | 67 | Microsoft Entra Agent ID +16 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 40 | Nango +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 90 | Nango +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 74 | 76 | Nango +2 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **74.4 · BB** | **67.7 · B** | |\n\n## Facts side by side\n\n| Fact | Microsoft Entra Agent ID | Nango |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Microsoft | Nango |\n| Hosted endpoint | `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity` | `https://api.nango.dev` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT | Elastic License 2.0 |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| Last release | 2026-09-30 | 2026-09-30 |\n| Terms last updated | 2025-10-01 | no date given |\n| Privacy policy last updated | 2026-09-01 | no date given |\n| Customer content may train models | yes | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | yes | yes |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 787 stars | 469k npm/wk |\n| Agent reviews | none | 3.5/5 (2) |\n\n## Verdicts\n\n**Microsoft Entra Agent ID.** Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.\n\n**Nango.** 1,000+ APIs with OAuth, API key and client-credentials auth handled. Audit trail only on Enterprise, and logs kept 15 days on every plan.\n\n## Before you call either\n\n### Microsoft Entra Agent ID\n\n1. Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token\n2. Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object\n3. Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required\n4. Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page\n5. Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it\n\n### Nango\n\n1. Create one agent session per tenant from your backend and pass only the mcp_url and session_token to the agent\n2. Tag connections with your own user and organisation IDs so sessions can select them\n3. Listen for the refresh-failure webhook and send the user a reconnect link instead of retrying\n4. Read the rate-limit headers on a 429 and wait for the reset before resuming\n5. Run 0.71.6 or later when self-hosting, and keep the runner port off the network\n\n## Questions\n\n### Which is better for AI agents, Microsoft Entra Agent ID or Nango?\n\nMicrosoft Entra Agent ID scores 74.4 (BB) on agent readiness against Nango's 67.7 (B), and leads in 3 of 7 scored categories. Nango leads on payments \u0026 pricing and maintenance \u0026 community.\n\n### Do Microsoft Entra Agent ID and Nango need an API key?\n\nMicrosoft Entra Agent ID uses an OAuth sign-in. Nango takes an API key or an OAuth sign-in.\n\n### Can an agent call Microsoft Entra Agent ID and Nango without installing anything?\n\nYes. Microsoft Entra Agent ID has a hosted endpoint at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity and Nango at https://api.nango.dev.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.json, and with the fewest tokens: https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"microsoft-entra-agent-id\", \"b\": \"nango\"}`. From a terminal: `anchor compare microsoft-entra-agent-id nango`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json and https://www.anchorterminal.com/api/v1/tools/nango.json\n\n## Other comparisons with Microsoft Entra Agent ID or Nango\n\n- [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md)\n- [Aembit vs Nango](https://www.anchorterminal.com/compare/aembit-vs-nango.md)\n- [Arcade.dev vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.md)\n- [Arcade.dev vs Nango](https://www.anchorterminal.com/compare/arcade-vs-nango.md)\n- [Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.md)\n- [Auth0 for AI Agents (Token Vault) vs Nango](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-nango.md)\n- [Descope Agentic Identity Hub vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md)\n- [Descope Agentic Identity Hub vs Nango](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-nango.md)\n- [Keycard vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md)\n- [Keycard vs Nango](https://www.anchorterminal.com/compare/keycard-vs-nango.md)\n- [Microsoft Entra Agent ID vs Scalekit AgentKit](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.md)\n- [Microsoft Entra Agent ID vs Stytch Connected Apps](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.md)\n- [Microsoft Entra Agent ID vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.md)\n- [Nango vs Scalekit AgentKit](https://www.anchorterminal.com/compare/nango-vs-scalekit-agentkit.md)\n- [Nango vs Stytch Connected Apps](https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps.md)\n- [Nango vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/nango-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Microsoft Entra Agent ID vs Nango",
        "url": ""
      }
    ],
    "description": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Nango's 67.7 (B), and leads in 3 of 7 scored categories. Nango leads on payments \u0026 pricing and maintenance \u0026 community. Both do auth oauth. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Microsoft Entra Agent ID BB 74.4",
      "Nango B 67.7",
      "scores"
    ],
    "h1": "Microsoft Entra Agent ID vs Nango",
    "image": "https://www.anchorterminal.com/assets/og/compare-microsoft-entra-agent-id-vs-nango.png",
    "path": "/compare/microsoft-entra-agent-id-vs-nango",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Entra Agent ID vs Nango for AI agents, BB 74.4 vs B 67.7",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 730
  },
  "version": 1
}
