{
  "data": {
    "a": {
      "slug": "microsoft-entra-agent-id",
      "name": "Microsoft Entra Agent ID",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Microsoft Entra Agent ID is an identity type for AI agents in Microsoft Entra ID. Agents get their own directory identity, request OAuth 2.0 tokens autonomously or on behalf of a user, and are managed through Microsoft Graph.",
      "url": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json",
      "repo": "https://github.com/AzureAD/microsoft-identity-web",
      "license": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
      "packages": [
        {
          "registry": "nuget",
          "name": "Microsoft.Identity.Web.AgentIdentities"
        }
      ],
      "auth": "oauth",
      "authNotes": "Access starts with a Microsoft Entra tenant and a person holding the Agent ID Developer or Agent ID Administrator role, who creates an agent identity blueprint. The blueprint authenticates to login.microsoftonline.com with a managed identity, a certificate or a client secret (Microsoft advises against secrets in production) and exchanges for a token as one of its agent identities. Agent identities hold no credentials. Three flows exist, which are app-only, on behalf of a signed-in user, and as the agent's own user account. Interactive `/authorize` and public clients aren't supported. Management calls on Microsoft Graph need AgentIdentity.Create.All or AgentIdentity.ReadWrite.All.",
      "pricing": "freemium",
      "pricingNotes": "Microsoft's docs say Agent ID is available to all Microsoft Entra customers, and Entra ID Free comes with any Microsoft cloud subscription. No per-agent price is published. Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15.00 a user a month on yearly billing, or Microsoft 365 E7 at $99.00. Conditional Access for agents also needs Entra P1 or Microsoft 365 E3 alongside Agent 365. No sandbox was found in the Agent ID docs (https://www.microsoft.com/en-us/microsoft-agent-365, checked 2026-10-08).",
      "priceSummary": "$15 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Agent ID docs, the Graph reference or the pricing pages (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 787,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/entra/agent-id/",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "auth.oauth",
        "auth.agent-identity",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "oauth",
        "openapi",
        "dotnet",
        "sidecar",
        "microsoft-graph",
        "mcp",
        "freemium",
        "sla"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 74.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 63,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 74
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.",
        "bestFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
        "strengths": [
          "Agent identities can't hold credentials. The blueprint authenticates with a managed identity, certificate or secret and exchanges for the agent's token",
          "Global Administrator and similar roles, and Graph permissions such as Application.ReadWrite.All, are refused for agent identities",
          "Create, list, update, delete and restore are on Microsoft Graph v1.0, with agentIdentity in the public OpenAPI file",
          "Audit and sign-in logs carry an agentType and blueprintId for agent activity",
          "Microsoft.Identity.Web 4.16.0 shipped on 30 September 2026, the eighth tagged release since 9 July"
        ],
        "weaknesses": [
          "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing",
          "Microsoft's docs call hand-written token exchange complex and error-prone and steer developers to a .NET library or a sidecar container",
          "Creating a blueprint, a principal and an identity in quick succession can fail with 400 until the directory replicates",
          "Audit and sign-in logs are kept seven days on Entra ID Free and 30 days on P1 or P2",
          "microsoft.com's security.txt passed its Expires date on 23 September 2026"
        ],
        "agentNotes": [
          "Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token",
          "Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object",
          "Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required",
          "Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page",
          "Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 74.4
          }
        ],
        "editorialScores": {
          "ergonomics": 71,
          "maintenance": 80,
          "payments": 20,
          "reliability": 91,
          "schema": 87,
          "security": 83,
          "transparency": 63
        },
        "provenanceScore": 85
      },
      "connect": {
        "install": "dotnet add package Microsoft.Identity.Web.AgentIdentities",
        "http": "curl -X POST https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity \\\n  -H \"Authorization: Bearer $BLUEPRINT_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"displayName\": \"My Agent Identity\", \"agentIdentityBlueprintId\": \"\u003cblueprint-app-id\u003e\", \"sponsors@odata.bind\": [\"https://graph.microsoft.com/v1.0/users/\u003cid\u003e\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/microsoft-entra-agent-id"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Microsoft Agent 365",
          "unit": "seat-month",
          "usd": 15,
          "note": "billed yearly, needed for Conditional Access, ID Protection and governance for agents"
        },
        {
          "item": "Microsoft 365 E7 (includes Agent 365)",
          "unit": "seat-month",
          "usd": 99,
          "note": "billed yearly"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://www.microsoft.com/en-us/privacy/privacystatement",
        "statusPage": "https://azure.status.microsoft/en-us/status/history/",
        "changelog": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.",
          "The Microsoft APIs terms of use cover the Microsoft Graph API and other APIs that reach directory data, and were last updated in October 2025. Tenant use of Entra also falls under the customer's Microsoft licensing agreement and the Product Terms, which we didn't read.",
          "The Microsoft privacy statement was last updated in September 2026.",
          "Tokens come from login.microsoftonline.com and management calls go to graph.microsoft.com, both Microsoft domains.",
          "Entra's SLA page sends readers to the Azure status history for incidents that affect Entra ID.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02."
        ],
        "score": 85
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-entra-agent-id.json",
      "live": {
        "slug": "microsoft-entra-agent-id",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
          "method": "get",
          "lastAt": "2026-10-08T19:52:56.035923923Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 30,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 32,
          "p95ms24h": 97,
          "samples24h": 27,
          "samples30d": 27,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 27,
              "ok": 27
            }
          ]
        },
        "vendorStatus": {
          "page": "https://azure.status.microsoft/en-us/status/history",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:47.070808325Z"
        },
        "pages": [
          {
            "url": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:21:36.290153566Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "bca4f93493d4"
          },
          {
            "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:21:38.182590643Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1a1ee1c20d9a"
          }
        ],
        "updatedAt": "2026-10-08T19:52:56.035923923Z"
      }
    },
    "answer": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories.",
    "b": {
      "slug": "stytch-connected-apps",
      "name": "Stytch Connected Apps",
      "vendor": "Stytch (Twilio)",
      "vendorUrl": "https://stytch.com/connected-apps",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Turns a Stytch project into an OAuth 2.1 and OIDC authorisation server so agents and MCP clients can act for your users.",
      "url": "https://www.anchorterminal.com/tools/stytch-connected-apps",
      "markdownUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json",
      "repo": "https://github.com/stytchauth/stytch-node",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.stytch.com",
      "packages": [
        {
          "registry": "npm",
          "name": "stytch"
        },
        {
          "registry": "pypi",
          "name": "stytch"
        }
      ],
      "auth": "mixed",
      "authNotes": "Backend calls use HTTP basic auth with the project ID as the user and the secret as the password against api.stytch.com (test.stytch.com for test projects). Agents and MCP clients go through OAuth 2.1: metadata at `{project-domain}/.well-known/oauth-authorization-server`, registration at `/v1/oauth2/register` with no credentials, the token endpoint at `/v1/oauth2/token`, and PKCE with S256 required for public clients. The end user must already have a Stytch session when the consent page loads.",
      "pricing": "freemium",
      "pricingNotes": "Pay as you go starts at $0 with 10,000 monthly active users (people and AI agents count the same), unlimited organisations, 5 SSO or SCIM connections and 1,000 M2M tokens a month. Extra SSO or SCIM connections are $125 each, brand removal and full email customisation is a $99 one-off, and fraud fingerprints are $0.005 each after 10,000. Enterprise is custom, with volume discounts, unlimited SSO and SCIM, a 99.99 per cent SLA, a HIPAA BAA and a private Slack channel. Connected Apps has no separate line and bills through MAU (https://stytch.com/pricing, https://stytch.com/connected-apps). The page doesn't state the per-MAU overage price or whether a card is needed.",
      "priceSummary": "$125 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 116,
        "npmWeekly": 349007,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://stytch.com/docs/connected-apps/guides/mcp-auth-overview",
      "llmsTxt": "https://stytch.com/docs/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.consent",
        "auth.agent-identity",
        "auth.tokens"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "llms-txt",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2026-08-14",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.8,
        "grade": "C",
        "agentReady": false,
        "rank": 383,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 62,
          "payments": 20,
          "reliability": 73,
          "schema": 64,
          "security": 66,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens.",
        "bestFor": "A team that needs an OAuth 2.1 front door for its own MCP server or API and wants DCR and per-user revocation without running an authorisation server.",
        "strengths": [
          "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box",
          "Revoke an app's access and all its tokens for a user with one API call",
          "Consent screen built from RBAC roles, so agents only see grantable scopes",
          "10,000 monthly active users free, agents counted as users",
          "No incidents on the OAuth endpoints on the status page since 1 July 2026"
        ],
        "weaknesses": [
          "No outbound token vault, so it can't hold your users' third-party tokens",
          "Node, Python, Go and Ruby SDKs last tagged 24 June 2026, and the docs changelog last moved on 14 August",
          "No published rate limits for the OAuth, registration or token endpoints",
          "No audit log of grants and revocations that we could find",
          "No security.txt, and Twilio's certifications page doesn't mention Stytch"
        ],
        "agentNotes": [
          "Fetch `{project-domain}/.well-known/oauth-authorization-server` first and use the endpoints it returns, not hard-coded paths",
          "Register with `token_endpoint_auth_method` none and PKCE S256 when the agent can't keep a secret",
          "Expect a 401 with protected resource metadata from the MCP server, then register and authorise",
          "Ask only for scopes the user's roles can grant, or the consent page will refuse them",
          "Back off exponentially on a 429, since no Retry-After header is documented"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.8
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 62,
          "payments": 20,
          "reliability": 73,
          "schema": 64,
          "security": 66,
          "transparency": 42
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install stytch",
        "http": "curl -X POST https://api.stytch.com/v1/connected_apps/clients \\\n  -u \"$STYTCH_PROJECT_ID:$STYTCH_SECRET\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"client_type\":\"third_party_public\",\"client_name\":\"My agent\",\"redirect_urls\":[\"https://example.com/callback\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/stytch-connected-apps"
      },
      "sameCompany": [
        "twilio-voice",
        "sendgrid",
        "twilio"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "SSO or SCIM connection above 5",
          "unit": "month",
          "usd": 125,
          "note": "Per connection per month on Pay as you go"
        },
        {
          "item": "Fraud fingerprint above 10,000",
          "unit": "call",
          "usd": 0.005,
          "note": "Optional fraud add-on"
        }
      ],
      "provenance": {
        "legalEntity": "Twilio Inc.",
        "domain": "stytch.com",
        "domainRegistered": "2014-04-25",
        "endpointOnVendorDomain": true,
        "terms": "https://www.twilio.com/en-us/legal/tos",
        "privacy": "https://www.twilio.com/en-us/legal/privacy",
        "statusPage": "https://status.stytch.com",
        "changelog": "https://stytch.com/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-02",
        "notes": [
          "stytch.com/legal/terms-of-service and /legal/privacy-policy return 302 redirects to twilio.com. Twilio's terms name Twilio Inc., a Delaware corporation, and link to the last Stytch terms at twilio.com/en-us/legal/tos/stytch-tos.",
          "/.well-known/security.txt returned 404 on 2026-09-30, and stytch.com/security returns 404.",
          "status.stytch.com is an Atlassian Statuspage with an RSS history feed.",
          "The old changelog.stytch.com said on 2 July 2026 that it was moving into the docs. Dated entries continue at stytch.com/docs/changelog, newest 14 August 2026.",
          "Twilio's sub-processor page lists 13 sub-processors for Stytch by Twilio, updated September 2026."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.json",
      "live": {
        "slug": "stytch-connected-apps",
        "probe": {
          "target": "https://api.stytch.com",
          "method": "get",
          "lastAt": "2026-10-08T19:53:03.241644802Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 449,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 445,
          "p95ms24h": 483,
          "samples24h": 272,
          "samples30d": 1941,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 225,
              "ok": 225
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.stytch.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:14.702520002Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "stytchauth/stytch-node",
            "version": "v14.2.0",
            "released": "2026-06-24",
            "seenAt": "2026-10-08T16:30:57.426532857Z"
          },
          {
            "registry": "npm",
            "name": "stytch",
            "version": "14.2.0",
            "seenAt": "2026-10-08T16:30:56.378979925Z"
          },
          {
            "registry": "pypi",
            "name": "stytch",
            "version": "15.3.0",
            "released": "2026-06-24",
            "seenAt": "2026-10-08T16:30:57.237287044Z"
          }
        ],
        "githubStars": 116,
        "npmWeekly": 347506,
        "pypiWeekly": 163040,
        "securityTxt": {
          "url": "https://stytch.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:00.951923238Z"
        },
        "llmsTxt": {
          "url": "https://stytch.com/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:55.872785638Z"
        },
        "domain": {
          "domain": "stytch.com",
          "registered": "2014-04-25",
          "source": "https://rdap.verisign.com/com/v1/domain/stytch.com",
          "checkedAt": "2026-10-04T13:06:36.74420879Z"
        },
        "pages": [
          {
            "url": "https://stytch.com/docs/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:55.724389268Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "156a41d78412"
          },
          {
            "url": "https://stytch.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:00.722528976Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "61105c9b4a8b"
          }
        ],
        "updatedAt": "2026-10-08T19:53:03.241644802Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Microsoft",
        "b": "Stytch (Twilio)",
        "name": "Vendor"
      },
      {
        "a": "https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity",
        "b": "https://api.stytch.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT",
        "b": "MIT (SDKs), platform closed",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-08-14",
        "name": "Last release"
      },
      {
        "a": "2025-10-01",
        "b": "2026-07-16",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-01",
        "b": "2026-04-09",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "787 stars",
        "b": "116 stars, 349k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories.",
        "question": "Which is better for AI agents, Microsoft Entra Agent ID or Stytch Connected Apps?"
      },
      {
        "answer": "Microsoft Entra Agent ID uses an OAuth sign-in. Stytch Connected Apps takes an API key or an OAuth sign-in.",
        "question": "Do Microsoft Entra Agent ID and Stytch Connected Apps need an API key?"
      },
      {
        "answer": "Yes. Microsoft Entra Agent ID has a hosted endpoint at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity and Stytch Connected Apps at https://api.stytch.com.",
        "question": "Can an agent call Microsoft Entra Agent ID and Stytch Connected Apps without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 91 against 73",
          "Schema \u0026 documentation, 87 against 64",
          "Agent ergonomics, 71 against 65",
          "Security \u0026 auth, 83 against 66",
          "Maintenance \u0026 community, 80 against 62",
          "Transparency \u0026 trust, 74 against 66"
        ],
        "also": [
          "Agent-ready, a grade of BB or better"
        ],
        "goodFor": "Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.",
        "slug": "microsoft-entra-agent-id",
        "watchFor": "Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing"
      },
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "A team that needs an OAuth 2.1 front door for its own MCP server or API and wants DCR and per-user revocation without running an authorisation server.",
        "slug": "stytch-connected-apps",
        "watchFor": "No outbound token vault, so it can't hold your users' third-party tokens"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.json",
        "title": "Aembit vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.json",
        "title": "Aembit vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.json",
        "title": "Arcade.dev vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps.json",
        "title": "Arcade.dev vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.json",
        "title": "Descope Agentic Identity Hub vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.json",
        "title": "Descope Agentic Identity Hub vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.json",
        "title": "Keycard vs Microsoft Entra Agent ID",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.json",
        "title": "Keycard vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.json",
        "title": "Microsoft Entra Agent ID vs Nango",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.json",
        "title": "Microsoft Entra Agent ID vs Scalekit AgentKit",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.json",
        "title": "Microsoft Entra Agent ID vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps.json",
        "title": "Nango vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/scalekit-agentkit-vs-stytch-connected-apps.json",
        "title": "Scalekit AgentKit vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/scalekit-agentkit-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.json",
        "title": "Stytch Connected Apps vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "by": 18,
        "edge": "microsoft-entra-agent-id",
        "key": "reliability",
        "microsoft-entra-agent-id": 91,
        "name": "Reliability",
        "stytch-connected-apps": 73,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 23,
        "edge": "microsoft-entra-agent-id",
        "key": "schema",
        "microsoft-entra-agent-id": 87,
        "name": "Schema \u0026 documentation",
        "stytch-connected-apps": 64,
        "weight": 13
      },
      {
        "by": 6,
        "edge": "microsoft-entra-agent-id",
        "key": "ergonomics",
        "microsoft-entra-agent-id": 71,
        "name": "Agent ergonomics",
        "stytch-connected-apps": 65,
        "weight": 13
      },
      {
        "by": 17,
        "edge": "microsoft-entra-agent-id",
        "key": "security",
        "microsoft-entra-agent-id": 83,
        "name": "Security \u0026 auth",
        "stytch-connected-apps": 66,
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "key": "payments",
        "microsoft-entra-agent-id": 20,
        "name": "Payments \u0026 pricing",
        "stytch-connected-apps": 20,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 18,
        "edge": "microsoft-entra-agent-id",
        "key": "maintenance",
        "microsoft-entra-agent-id": 80,
        "name": "Maintenance \u0026 community",
        "stytch-connected-apps": 62,
        "weight": 7
      },
      {
        "by": 8,
        "edge": "microsoft-entra-agent-id",
        "key": "transparency",
        "microsoft-entra-agent-id": 74,
        "name": "Transparency \u0026 trust",
        "stytch-connected-apps": 66,
        "weight": 7
      }
    ],
    "summary": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories. Both do auth oauth.",
    "verdicts": {
      "microsoft-entra-agent-id": "Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.",
      "stytch-connected-apps": "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps",
    "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.md",
    "slim": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.min.md"
  },
  "markdown": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories. Both do auth oauth.\n\n- Microsoft Entra Agent ID: grade BB, 74.4/100, rank #63 of 722. Markdown https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json\n- Stytch Connected Apps: grade C, 60.8/100, rank #383 of 722. Markdown https://www.anchorterminal.com/tools/stytch-connected-apps.md · JSON https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json\n\n## Which one, for what\n\n### Microsoft Entra Agent ID (BB)\n\nGood for: Organisations already on Microsoft Entra that want each agent to be a governed directory identity with tokens for Microsoft Graph, Azure and their own APIs.\n\nAhead on:\n- Reliability, 91 against 73\n- Schema \u0026 documentation, 87 against 64\n- Agent ergonomics, 71 against 65\n- Security \u0026 auth, 83 against 66\n- Maintenance \u0026 community, 80 against 62\n- Transparency \u0026 trust, 74 against 66\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n\nWatch for: Conditional Access, ID Protection and governance for agents need Microsoft Agent 365, listed at $15 a user a month on yearly billing\n\n### Stytch Connected Apps (C)\n\nGood for: A team that needs an OAuth 2.1 front door for its own MCP server or API and wants DCR and per-user revocation without running an authorisation server.\n\nWatch for: No outbound token vault, so it can't hold your users' third-party tokens\n\n\n## Score by category\n\n| Category | Weight | Microsoft Entra Agent ID | Stytch Connected Apps | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 91 | 73 | Microsoft Entra Agent ID +18 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 87 | 64 | Microsoft Entra Agent ID +23 |\n| Agent ergonomics | 13% (16.2 this run) | 71 | 65 | Microsoft Entra Agent ID +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 83 | 66 | Microsoft Entra Agent ID +17 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 20 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 62 | Microsoft Entra Agent ID +18 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 74 | 66 | Microsoft Entra Agent ID +8 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **74.4 · BB** | **60.8 · C** | |\n\n## Facts side by side\n\n| Fact | Microsoft Entra Agent ID | Stytch Connected Apps |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Microsoft | Stytch (Twilio) |\n| Hosted endpoint | `https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity` | `https://api.stytch.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Microsoft's terms. Microsoft.Identity.Web and the Auth SDK sidecar source are MIT | MIT (SDKs), platform closed |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| Last release | 2026-09-30 | 2026-08-14 |\n| Terms last updated | 2025-10-01 | 2026-07-16 |\n| Privacy policy last updated | 2026-09-01 | 2026-04-09 |\n| Customer content may train models | yes | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 787 stars | 116 stars, 349k npm/wk |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Microsoft Entra Agent ID.** Agent identities hold no credentials of their own, and Entra refuses high-privilege roles and Graph permissions for them. The token flow is a two-step exchange that Microsoft's own docs call complex and error-prone to implement by hand, and Conditional Access, risk detection and governance for agents need a paid Agent 365 licence.\n\n**Stytch Connected Apps.** OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens.\n\n## Before you call either\n\n### Microsoft Entra Agent ID\n\n1. Request tokens in two steps. The blueprint gets an exchange token with fmi_path set to the agent identity's client ID, then the agent identity trades it for a resource token\n2. Retry with exponential backoff when a create returns `400 Object with id not found` straight after creating its parent object\n3. Send displayName, agentIdentityBlueprintId and a sponsor reference when creating an agent identity. All three are required\n4. Don't use the interactive `/authorize` flow. Agent identities are confidential clients and can't sign in to a page\n5. Keep the sidecar off any public network. Its `/AuthorizationHeader` endpoint hands out tokens to whoever can reach it\n\n### Stytch Connected Apps\n\n1. Fetch `{project-domain}/.well-known/oauth-authorization-server` first and use the endpoints it returns, not hard-coded paths\n2. Register with `token_endpoint_auth_method` none and PKCE S256 when the agent can't keep a secret\n3. Expect a 401 with protected resource metadata from the MCP server, then register and authorise\n4. Ask only for scopes the user's roles can grant, or the consent page will refuse them\n5. Back off exponentially on a 429, since no Retry-After header is documented\n\n## Questions\n\n### Which is better for AI agents, Microsoft Entra Agent ID or Stytch Connected Apps?\n\nMicrosoft Entra Agent ID scores 74.4 (BB) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories.\n\n### Do Microsoft Entra Agent ID and Stytch Connected Apps need an API key?\n\nMicrosoft Entra Agent ID uses an OAuth sign-in. Stytch Connected Apps takes an API key or an OAuth sign-in.\n\n### Can an agent call Microsoft Entra Agent ID and Stytch Connected Apps without installing anything?\n\nYes. Microsoft Entra Agent ID has a hosted endpoint at https://graph.microsoft.com/v1.0/servicePrincipals/microsoft.graph.agentIdentity and Stytch Connected Apps at https://api.stytch.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.json, and with the fewest tokens: https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"microsoft-entra-agent-id\", \"b\": \"stytch-connected-apps\"}`. From a terminal: `anchor compare microsoft-entra-agent-id stytch-connected-apps`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/microsoft-entra-agent-id.json and https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json\n\n## Other comparisons with Microsoft Entra Agent ID or Stytch Connected Apps\n\n- [Aembit vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/aembit-vs-microsoft-entra-agent-id.md)\n- [Aembit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.md)\n- [Arcade.dev vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/arcade-vs-microsoft-entra-agent-id.md)\n- [Arcade.dev vs Stytch Connected Apps](https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps.md)\n- [Auth0 for AI Agents (Token Vault) vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-microsoft-entra-agent-id.md)\n- [Auth0 for AI Agents (Token Vault) vs Stytch Connected Apps](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps.md)\n- [Descope Agentic Identity Hub vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-microsoft-entra-agent-id.md)\n- [Descope Agentic Identity Hub vs Stytch Connected Apps](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.md)\n- [Keycard vs Microsoft Entra Agent ID](https://www.anchorterminal.com/compare/keycard-vs-microsoft-entra-agent-id.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Microsoft Entra Agent ID vs Nango](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-nango.md)\n- [Microsoft Entra Agent ID vs Scalekit AgentKit](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-scalekit-agentkit.md)\n- [Microsoft Entra Agent ID vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-workos-pipes.md)\n- [Nango vs Stytch Connected Apps](https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps.md)\n- [Scalekit AgentKit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-stytch-connected-apps.md)\n- [Stytch Connected Apps vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Microsoft Entra Agent ID vs Stytch Connected Apps",
        "url": ""
      }
    ],
    "description": "Microsoft Entra Agent ID scores 74.4 (BB) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories. Both do auth oauth. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Microsoft Entra Agent ID BB 74.4",
      "Stytch Connected Apps C 60.8",
      "scores"
    ],
    "h1": "Microsoft Entra Agent ID vs Stytch Connected Apps",
    "image": "https://www.anchorterminal.com/assets/og/compare-microsoft-entra-agent-id-vs-stytch-connected-apps.png",
    "path": "/compare/microsoft-entra-agent-id-vs-stytch-connected-apps",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Entra Agent ID vs Stytch Connected Apps for AI agents",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 730
  },
  "version": 1
}
