{
  "data": {
    "a": {
      "slug": "stytch-connected-apps",
      "name": "Stytch Connected Apps",
      "vendor": "Stytch (Twilio)",
      "vendorUrl": "https://stytch.com/connected-apps",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Turns a Stytch project into an OAuth 2.1 and OIDC authorisation server so agents and MCP clients can act for your users.",
      "url": "https://www.anchorterminal.com/tools/stytch-connected-apps",
      "markdownUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json",
      "repo": "https://github.com/stytchauth/stytch-node",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.stytch.com",
      "packages": [
        {
          "registry": "npm",
          "name": "stytch"
        },
        {
          "registry": "pypi",
          "name": "stytch"
        }
      ],
      "auth": "mixed",
      "authNotes": "Backend calls use HTTP basic auth with the project ID as the user and the secret as the password against api.stytch.com (test.stytch.com for test projects). Agents and MCP clients go through OAuth 2.1: metadata at `{project-domain}/.well-known/oauth-authorization-server`, registration at `/v1/oauth2/register` with no credentials, the token endpoint at `/v1/oauth2/token`, and PKCE with S256 required for public clients. The end user must already have a Stytch session when the consent page loads.",
      "pricing": "freemium",
      "pricingNotes": "Pay as you go starts at $0 with 10,000 monthly active users (people and AI agents count the same), unlimited organisations, 5 SSO or SCIM connections and 1,000 M2M tokens a month. Extra SSO or SCIM connections are $125 each, brand removal and full email customisation is a $99 one-off, and fraud fingerprints are $0.005 each after 10,000. Enterprise is custom, with volume discounts, unlimited SSO and SCIM, a 99.99 per cent SLA, a HIPAA BAA and a private Slack channel. Connected Apps has no separate line and bills through MAU (https://stytch.com/pricing, https://stytch.com/connected-apps). The page doesn't state the per-MAU overage price or whether a card is needed.",
      "priceSummary": "$125 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 116,
        "npmWeekly": 349007,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://stytch.com/docs/connected-apps/guides/mcp-auth-overview",
      "llmsTxt": "https://stytch.com/docs/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.consent",
        "auth.agent-identity",
        "auth.tokens"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "llms-txt",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2026-08-14",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.8,
        "grade": "C",
        "agentReady": false,
        "rank": 444,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 62,
          "payments": 20,
          "reliability": 73,
          "schema": 64,
          "security": 66,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens.",
        "bestFor": "A team that needs an OAuth 2.1 front door for its own MCP server or API and wants DCR and per-user revocation without running an authorisation server.",
        "strengths": [
          "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box",
          "Revoke an app's access and all its tokens for a user with one API call",
          "Consent screen built from RBAC roles, so agents only see grantable scopes",
          "10,000 monthly active users free, agents counted as users",
          "No incidents on the OAuth endpoints on the status page since 1 July 2026"
        ],
        "weaknesses": [
          "No outbound token vault, so it can't hold your users' third-party tokens",
          "Node, Python, Go and Ruby SDKs last tagged 24 June 2026, and the docs changelog last moved on 14 August",
          "No published rate limits for the OAuth, registration or token endpoints",
          "No audit log of grants and revocations that we could find",
          "No security.txt, and Twilio's certifications page doesn't mention Stytch"
        ],
        "agentNotes": [
          "Fetch `{project-domain}/.well-known/oauth-authorization-server` first and use the endpoints it returns, not hard-coded paths",
          "Register with `token_endpoint_auth_method` none and PKCE S256 when the agent can't keep a secret",
          "Expect a 401 with protected resource metadata from the MCP server, then register and authorise",
          "Ask only for scopes the user's roles can grant, or the consent page will refuse them",
          "Back off exponentially on a 429, since no Retry-After header is documented"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.8
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 62,
          "payments": 20,
          "reliability": 73,
          "schema": 64,
          "security": 66,
          "transparency": 42
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install stytch",
        "http": "curl -X POST https://api.stytch.com/v1/connected_apps/clients \\\n  -u \"$STYTCH_PROJECT_ID:$STYTCH_SECRET\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"client_type\":\"third_party_public\",\"client_name\":\"My agent\",\"redirect_urls\":[\"https://example.com/callback\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/stytch-connected-apps"
      },
      "sameCompany": [
        "twilio-voice",
        "sendgrid",
        "twilio"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "SSO or SCIM connection above 5",
          "unit": "month",
          "usd": 125,
          "note": "Per connection per month on Pay as you go"
        },
        {
          "item": "Fraud fingerprint above 10,000",
          "unit": "call",
          "usd": 0.005,
          "note": "Optional fraud add-on"
        }
      ],
      "provenance": {
        "legalEntity": "Twilio Inc.",
        "domain": "stytch.com",
        "domainRegistered": "2014-04-25",
        "endpointOnVendorDomain": true,
        "terms": "https://www.twilio.com/en-us/legal/tos",
        "privacy": "https://www.twilio.com/en-us/legal/privacy",
        "statusPage": "https://status.stytch.com",
        "changelog": "https://stytch.com/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-02",
        "notes": [
          "stytch.com/legal/terms-of-service and /legal/privacy-policy return 302 redirects to twilio.com. Twilio's terms name Twilio Inc., a Delaware corporation, and link to the last Stytch terms at twilio.com/en-us/legal/tos/stytch-tos.",
          "/.well-known/security.txt returned 404 on 2026-09-30, and stytch.com/security returns 404.",
          "status.stytch.com is an Atlassian Statuspage with an RSS history feed.",
          "The old changelog.stytch.com said on 2 July 2026 that it was moving into the docs. Dated entries continue at stytch.com/docs/changelog, newest 14 August 2026.",
          "Twilio's sub-processor page lists 13 sub-processors for Stytch by Twilio, updated September 2026."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.json",
      "live": {
        "slug": "stytch-connected-apps",
        "probe": {
          "target": "https://api.stytch.com",
          "method": "get",
          "lastAt": "2026-10-09T11:46:41.98865437Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 442,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 443,
          "p95ms24h": 469,
          "samples24h": 259,
          "samples30d": 2109,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 125,
              "ok": 125
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.stytch.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:34.193016237Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "stytchauth/stytch-node",
            "version": "v14.2.0",
            "released": "2026-06-24",
            "seenAt": "2026-10-08T16:30:57.426532857Z"
          },
          {
            "registry": "npm",
            "name": "stytch",
            "version": "14.2.0",
            "seenAt": "2026-10-08T16:30:56.378979925Z"
          },
          {
            "registry": "pypi",
            "name": "stytch",
            "version": "15.3.0",
            "released": "2026-06-24",
            "seenAt": "2026-10-08T16:30:57.237287044Z"
          }
        ],
        "githubStars": 116,
        "npmWeekly": 347506,
        "pypiWeekly": 163040,
        "securityTxt": {
          "url": "https://stytch.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:00.951923238Z"
        },
        "llmsTxt": {
          "url": "https://stytch.com/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:55.872785638Z"
        },
        "domain": {
          "domain": "stytch.com",
          "registered": "2014-04-25",
          "source": "https://rdap.verisign.com/com/v1/domain/stytch.com",
          "checkedAt": "2026-10-04T13:06:36.74420879Z"
        },
        "pages": [
          {
            "url": "https://stytch.com/docs/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:55.724389268Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "156a41d78412"
          },
          {
            "url": "https://stytch.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:00.722528976Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "61105c9b4a8b"
          }
        ],
        "updatedAt": "2026-10-09T11:46:41.98865437Z"
      }
    },
    "answer": "Vercel Connect scores 68.8 (B) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories. Stytch Connected Apps leads on reliability.",
    "b": {
      "slug": "vercel-connect",
      "name": "Vercel Connect",
      "vendor": "Vercel Inc.",
      "vendorUrl": "https://vercel.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Vercel Connect is a credential broker for apps and agents. Code asks it for a short-lived, scoped token for Slack, GitHub, Microsoft, Linear, Snowflake or any OAuth, API-key or MCP service, as the app or for a user.",
      "url": "https://www.anchorterminal.com/tools/vercel-connect",
      "markdownUrl": "https://www.anchorterminal.com/tools/vercel-connect.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vercel-connect.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vercel-connect.json",
      "repo": "https://github.com/vercel/vercel",
      "license": "Proprietary service under Vercel's Terms of Service and the Vercel Connect product terms. The `@vercel/connect` SDK and the Vercel CLI are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.vercel.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@vercel/connect"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access is self-serve with a Vercel account, on every plan. A deployment calls Connect with its project OIDC token (`VERCEL_OIDC_TOKEN`), which Connect checks against the connector's project links and their environments. Locally, `vercel env pull` writes a development OIDC token that lasts about 12 hours. Outside Vercel, a Vercel access token goes in `vercelToken`, and it can request only the app subject or its own user. Connect then holds the provider side. Vercel registers the OAuth client for managed connectors (Slack, GitHub, Linear, Microsoft, Snowflake, Salesforce), and the customer supplies a client or an API key for the others. End users consent in a browser at a URL from `startAuthorization`.",
      "pricing": "freemium",
      "pricingNotes": "Billed per token request and per trigger. Hobby includes 500 token requests and 1,000 triggers a month at no extra charge, and Vercel's fair use guidelines limit Hobby to non-commercial, personal use. Pro is $3.00 per 1,000 token requests and $0.95 per 1,000 triggers on top of the plan. Enterprise is negotiated. A trigger is counted once per destination, and once per event when no destination is set. The SDK's in-process cache means many provider calls in one invocation cost one token request (https://vercel.com/docs/connect/pricing, checked 2026-10-08).",
      "priceSummary": "$3 / 1k req",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Connect docs, the pricing page or the Connect operations of the OpenAPI document (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 16354,
        "npmWeekly": 738165,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://vercel.com/docs/connect",
      "llmsTxt": "https://vercel.com/llms.txt",
      "openapi": "https://openapi.vercel.sh/",
      "capabilities": [
        "auth.tokens",
        "auth.oauth",
        "auth.consent",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "oidc",
        "openapi",
        "llms-txt",
        "typescript",
        "cli",
        "webhooks",
        "status-page",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.8,
        "grade": "B",
        "agentReady": false,
        "rank": 195,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 81,
          "payments": 40,
          "reliability": 63,
          "schema": 84,
          "security": 83,
          "transparency": 77
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "April 2026. Vercel's security bulletin says an attacker took over an employee's account through a compromised third-party AI tool, reached internal systems and decrypted non-sensitive environment variables of a limited subset of customers. It predates Connect's general availability on 25 August 2026 and is documented with remediation, so 3 of a possible 15 is taken, because Connect now keeps customers' provider refresh tokens on the same platform (https://vercel.com/kb/bulletin/vercel-april-2026-security-incident)."
        ],
        "verdict": "Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript.",
        "bestFor": "Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets.",
        "strengths": [
          "Refresh tokens stay on Vercel's infrastructure. Code receives only short-lived access tokens, as the app or for a named user",
          "A deployment authenticates with its project OIDC token, checked against per-environment project links, so no provider secret sits in environment variables",
          "Public OpenAPI 3.0.3 document covers 13 Connect paths, including `/v1/connect/token/{connector}` and `/v1/connect/authorize/{connector}`",
          "Token requests, completed authorisations and revocations are logged with `tokenId` and `authorizationId`, and can be sent to a drain on Pro and Enterprise",
          "Rate limits are published with numbers, 200 reads and 50 writes a minute per team"
        ],
        "weaknesses": [
          "Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment",
          "Elevated Connect errors for 94 minutes on 10 September 2026, marked major, and again on 18 September, per the status page",
          "Event history is kept 12 hours on Hobby and 3 days on Pro. Connector audit logs and 30 days need Enterprise",
          "Revocation depends on the provider. Without a revocation endpoint the provider credential can work until it expires",
          "The SDK is TypeScript only, and the public repository's copy stops at 2.0.2 while npm has 2.4.1"
        ],
        "agentNotes": [
          "Call `getToken` at request time and don't store the result. The SDK caches up to 100 tokens in process and refreshes them 30 seconds before expiry",
          "Pass `scopes` on every request. Since SDK 1.0.0 an omitted `scopes` defaults to `['*']`, the connector's default scopes",
          "Catch `UserAuthorizationRequiredError`, call `startAuthorization` and send the user to the returned URL. Consent needs a person in a browser",
          "Outside Vercel, pass a Vercel access token as `vercelToken`. It can request only the app subject or its own user, not another user",
          "On a 429 wait one minute for the window to reset. Limits are 200 token requests a minute per team"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.8
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 81,
          "payments": 40,
          "reliability": 63,
          "schema": 84,
          "security": 83,
          "transparency": 55
        },
        "provenanceScore": 99
      },
      "connect": {
        "install": "pnpm add @vercel/connect",
        "http": "curl -X POST https://api.vercel.com/v1/connect/token/slack%2Facme-slack \\\n  -H \"Authorization: Bearer $VERCEL_OIDC_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"subject\":{\"type\":\"app\"},\"scopes\":[\"chat:write\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.tokens",
        "tool": "https://letme.dev/vercel-connect"
      },
      "sameCompany": [
        "vercel-sandbox"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Token request (Pro)",
          "unit": "1k-requests",
          "usd": 3,
          "note": "Hobby includes 500 a month. Enterprise negotiated"
        },
        {
          "item": "Trigger, a forwarded provider webhook (Pro)",
          "unit": "1k-requests",
          "usd": 0.95,
          "note": "Counted per destination. Hobby includes 1,000 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Vercel Inc.",
        "domain": "vercel.com",
        "domainRegistered": "1999-10-04",
        "endpointOnVendorDomain": true,
        "terms": "https://vercel.com/legal/terms",
        "privacy": "https://vercel.com/legal/privacy-policy",
        "statusPage": "https://www.vercel-status.com",
        "changelog": "https://vercel.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service (last updated 1 June 2026) name Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, and California law. The DPA calls Vercel Inc. a Delaware corporation.",
          "Connect also has its own product terms at https://vercel.com/docs/connect/legal. The Terms of Service text we read does not mention Connect by name.",
          "The Privacy Notice (effective 1 June 2026) says it does not apply to personal information Vercel processes as a processor for customers, which the DPA covers. The DPA (effective 31 March 2026) applies to Pro and Enterprise plans.",
          "https://vercel.com/.well-known/security.txt points to HackerOne and responsible.disclosure@vercel.com and expires 2027-09-28.",
          "RDAP gives vercel.com a registration date of 1999-10-04, long before Vercel, so the domain was bought later.",
          "The API answers at api.vercel.com and the OpenAPI document at openapi.vercel.sh."
        ],
        "score": 99
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vercel-connect.json",
      "live": {
        "slug": "vercel-connect",
        "probe": {
          "target": "https://api.vercel.com",
          "method": "get",
          "lastAt": "2026-10-09T11:46:44.766209061Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 598,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 570,
          "p95ms24h": 973,
          "samples24h": 44,
          "samples30d": 44,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 44,
              "ok": 44
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.vercel-status.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T11:41:11.405145015Z"
        },
        "updatedAt": "2026-10-09T11:46:44.766209061Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Stytch (Twilio)",
        "b": "Vercel Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://api.stytch.com",
        "b": "https://api.vercel.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT (SDKs), platform closed",
        "b": "Proprietary service under Vercel's Terms of Service and the Vercel Connect product terms. The `@vercel/connect` SDK and the Vercel CLI are Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-08-14",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "2026-07-16",
        "b": "2026-06-01",
        "name": "Terms last updated"
      },
      {
        "a": "2026-04-09",
        "b": "2026-06-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "116 stars, 349k npm/wk",
        "b": "16k stars, 738k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Vercel Connect scores 68.8 (B) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories. Stytch Connected Apps leads on reliability.",
        "question": "Which is better for AI agents, Stytch Connected Apps or Vercel Connect?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Stytch Connected Apps and Vercel Connect need an API key?"
      },
      {
        "answer": "Yes. Stytch Connected Apps has a hosted endpoint at https://api.stytch.com and Vercel Connect at https://api.vercel.com.",
        "question": "Can an agent call Stytch Connected Apps and Vercel Connect without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 73 against 63"
        ],
        "also": [
          "No incidents deducted, where Vercel Connect loses 3 points for them"
        ],
        "goodFor": "A team that needs an OAuth 2.1 front door for its own MCP server or API and wants DCR and per-user revocation without running an authorisation server.",
        "slug": "stytch-connected-apps",
        "watchFor": "No outbound token vault, so it can't hold your users' third-party tokens"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 84 against 64",
          "Agent ergonomics, 75 against 65",
          "Security \u0026 auth, 83 against 66",
          "Payments \u0026 pricing, 40 against 20",
          "Maintenance \u0026 community, 81 against 62",
          "Transparency \u0026 trust, 77 against 66"
        ],
        "also": null,
        "goodFor": "Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets.",
        "slug": "vercel-connect",
        "watchFor": "Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment"
      }
    ],
    "job": {
      "capability": "auth.oauth",
      "name": "Auth oauth"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.json",
        "title": "Aembit vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aembit-vs-vercel-connect.json",
        "title": "Aembit vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/aembit-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.json",
        "title": "Amazon Bedrock AgentCore Identity vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.json",
        "title": "Amazon Bedrock AgentCore Identity vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps.json",
        "title": "Arcade.dev vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/arcade-vs-vercel-connect.json",
        "title": "Arcade.dev vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/arcade-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-vercel-connect.json",
        "title": "Auth0 for AI Agents (Token Vault) vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/auth0-ai-agents-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.json",
        "title": "Descope Agentic Identity Hub vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-vercel-connect.json",
        "title": "Descope Agentic Identity Hub vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/descope-agentic-identity-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.json",
        "title": "Keycard vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/keycard-vs-vercel-connect.json",
        "title": "Keycard vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/keycard-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.json",
        "title": "Microsoft Entra Agent ID vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-vercel-connect.json",
        "title": "Microsoft Entra Agent ID vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps.json",
        "title": "Nango vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nango-vs-vercel-connect.json",
        "title": "Nango vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/nango-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/scalekit-agentkit-vs-stytch-connected-apps.json",
        "title": "Scalekit AgentKit vs Stytch Connected Apps",
        "url": "https://www.anchorterminal.com/compare/scalekit-agentkit-vs-stytch-connected-apps"
      },
      {
        "json": "https://www.anchorterminal.com/compare/scalekit-agentkit-vs-vercel-connect.json",
        "title": "Scalekit AgentKit vs Vercel Connect",
        "url": "https://www.anchorterminal.com/compare/scalekit-agentkit-vs-vercel-connect"
      },
      {
        "json": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.json",
        "title": "Stytch Connected Apps vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/vercel-connect-vs-workos-pipes.json",
        "title": "Vercel Connect vs WorkOS Pipes and Agents",
        "url": "https://www.anchorterminal.com/compare/vercel-connect-vs-workos-pipes"
      }
    ],
    "scores": [
      {
        "by": 10,
        "edge": "stytch-connected-apps",
        "key": "reliability",
        "name": "Reliability",
        "stytch-connected-apps": 73,
        "vercel-connect": 63,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 20,
        "edge": "vercel-connect",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "stytch-connected-apps": 64,
        "vercel-connect": 84,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "vercel-connect",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "stytch-connected-apps": 65,
        "vercel-connect": 75,
        "weight": 13
      },
      {
        "by": 17,
        "edge": "vercel-connect",
        "key": "security",
        "name": "Security \u0026 auth",
        "stytch-connected-apps": 66,
        "vercel-connect": 83,
        "weight": 14
      },
      {
        "by": 20,
        "edge": "vercel-connect",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "stytch-connected-apps": 20,
        "vercel-connect": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 19,
        "edge": "vercel-connect",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "stytch-connected-apps": 62,
        "vercel-connect": 81,
        "weight": 7
      },
      {
        "by": 11,
        "edge": "vercel-connect",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "stytch-connected-apps": 66,
        "vercel-connect": 77,
        "weight": 7
      }
    ],
    "summary": "Vercel Connect scores 68.8 (B) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories. Stytch Connected Apps leads on reliability. Both do auth oauth.",
    "verdicts": {
      "stytch-connected-apps": "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens.",
      "vercel-connect": "Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-vercel-connect",
    "json": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-vercel-connect.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-vercel-connect.md",
    "slim": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-vercel-connect.min.md"
  },
  "markdown": "Vercel Connect scores 68.8 (B) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories. Stytch Connected Apps leads on reliability. Both do auth oauth.\n\n- Stytch Connected Apps: grade C, 60.8/100, rank #444 of 842. Markdown https://www.anchorterminal.com/tools/stytch-connected-apps.md · JSON https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json\n- Vercel Connect: grade B, 68.8/100, rank #195 of 842. Markdown https://www.anchorterminal.com/tools/vercel-connect.md · JSON https://www.anchorterminal.com/api/v1/tools/vercel-connect.json\n\n## Which one, for what\n\n### Stytch Connected Apps (C)\n\nGood for: A team that needs an OAuth 2.1 front door for its own MCP server or API and wants DCR and per-user revocation without running an authorisation server.\n\nAhead on:\n- Reliability, 73 against 63\n\nAlso in its favour:\n- No incidents deducted, where Vercel Connect loses 3 points for them\n\nWatch for: No outbound token vault, so it can't hold your users' third-party tokens\n\n### Vercel Connect (B)\n\nGood for: Teams already deploying on Vercel whose agents need user or app tokens for Slack, GitHub, Microsoft, Linear, Snowflake or an MCP server without storing provider secrets.\n\nAhead on:\n- Schema \u0026 documentation, 84 against 64\n- Agent ergonomics, 75 against 65\n- Security \u0026 auth, 83 against 66\n- Payments \u0026 pricing, 40 against 20\n- Maintenance \u0026 community, 81 against 62\n- Transparency \u0026 trust, 77 against 66\n\nWatch for: Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment\n\n\n## Score by category\n\n| Category | Weight | Stytch Connected Apps | Vercel Connect | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 73 | 63 | Stytch Connected Apps +10 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 64 | 84 | Vercel Connect +20 |\n| Agent ergonomics | 13% (16.2 this run) | 65 | 75 | Vercel Connect +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 66 | 83 | Vercel Connect +17 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 40 | Vercel Connect +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 62 | 81 | Vercel Connect +19 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 66 | 77 | Vercel Connect +11 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **60.8 · C** | **68.8 · B** | |\n\n## Facts side by side\n\n| Fact | Stytch Connected Apps | Vercel Connect |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Stytch (Twilio) | Vercel Inc. |\n| Hosted endpoint | `https://api.stytch.com` | `https://api.vercel.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (SDKs), platform closed | Proprietary service under Vercel's Terms of Service and the Vercel Connect product terms. The `@vercel/connect` SDK and the Vercel CLI are Apache-2.0 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-08-14 | 2026-10-06 |\n| Terms last updated | 2026-07-16 | 2026-06-01 |\n| Privacy policy last updated | 2026-04-09 | 2026-06-01 |\n| Customer content may train models | not found in the text | yes, with an opt-out |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | yes |\n| Popularity | 116 stars, 349k npm/wk | 16k stars, 738k npm/wk |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**Stytch Connected Apps.** OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens.\n\n**Vercel Connect.** Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript.\n\n## Before you call either\n\n### Stytch Connected Apps\n\n1. Fetch `{project-domain}/.well-known/oauth-authorization-server` first and use the endpoints it returns, not hard-coded paths\n2. Register with `token_endpoint_auth_method` none and PKCE S256 when the agent can't keep a secret\n3. Expect a 401 with protected resource metadata from the MCP server, then register and authorise\n4. Ask only for scopes the user's roles can grant, or the consent page will refuse them\n5. Back off exponentially on a 429, since no Retry-After header is documented\n\n### Vercel Connect\n\n1. Call `getToken` at request time and don't store the result. The SDK caches up to 100 tokens in process and refreshes them 30 seconds before expiry\n2. Pass `scopes` on every request. Since SDK 1.0.0 an omitted `scopes` defaults to `['*']`, the connector's default scopes\n3. Catch `UserAuthorizationRequiredError`, call `startAuthorization` and send the user to the returned URL. Consent needs a person in a browser\n4. Outside Vercel, pass a Vercel access token as `vercelToken`. It can request only the app subject or its own user, not another user\n5. On a 429 wait one minute for the window to reset. Limits are 200 token requests a minute per team\n\n## Questions\n\n### Which is better for AI agents, Stytch Connected Apps or Vercel Connect?\n\nVercel Connect scores 68.8 (B) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories. Stytch Connected Apps leads on reliability.\n\n### Do Stytch Connected Apps and Vercel Connect need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Stytch Connected Apps and Vercel Connect without installing anything?\n\nYes. Stytch Connected Apps has a hosted endpoint at https://api.stytch.com and Vercel Connect at https://api.vercel.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/stytch-connected-apps-vs-vercel-connect.json, and with the fewest tokens: https://www.anchorterminal.com/compare/stytch-connected-apps-vs-vercel-connect.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"stytch-connected-apps\", \"b\": \"vercel-connect\"}`. From a terminal: `anchor compare stytch-connected-apps vercel-connect`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json and https://www.anchorterminal.com/api/v1/tools/vercel-connect.json\n\n## Other comparisons with Stytch Connected Apps or Vercel Connect\n\n- [Aembit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/aembit-vs-stytch-connected-apps.md)\n- [Aembit vs Vercel Connect](https://www.anchorterminal.com/compare/aembit-vs-vercel-connect.md)\n- [Amazon Bedrock AgentCore Identity vs Stytch Connected Apps](https://www.anchorterminal.com/compare/agentcore-identity-vs-stytch-connected-apps.md)\n- [Amazon Bedrock AgentCore Identity vs Vercel Connect](https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.md)\n- [Arcade.dev vs Stytch Connected Apps](https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps.md)\n- [Arcade.dev vs Vercel Connect](https://www.anchorterminal.com/compare/arcade-vs-vercel-connect.md)\n- [Auth0 for AI Agents (Token Vault) vs Stytch Connected Apps](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps.md)\n- [Auth0 for AI Agents (Token Vault) vs Vercel Connect](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-vercel-connect.md)\n- [Descope Agentic Identity Hub vs Stytch Connected Apps](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.md)\n- [Descope Agentic Identity Hub vs Vercel Connect](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-vercel-connect.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Keycard vs Vercel Connect](https://www.anchorterminal.com/compare/keycard-vs-vercel-connect.md)\n- [Microsoft Entra Agent ID vs Stytch Connected Apps](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-stytch-connected-apps.md)\n- [Microsoft Entra Agent ID vs Vercel Connect](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-vercel-connect.md)\n- [Nango vs Stytch Connected Apps](https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps.md)\n- [Nango vs Vercel Connect](https://www.anchorterminal.com/compare/nango-vs-vercel-connect.md)\n- [Scalekit AgentKit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-stytch-connected-apps.md)\n- [Scalekit AgentKit vs Vercel Connect](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-vercel-connect.md)\n- [Stytch Connected Apps vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.md)\n- [Vercel Connect vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/vercel-connect-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Stytch Connected Apps vs Vercel Connect",
        "url": ""
      }
    ],
    "description": "Vercel Connect scores 68.8 (B) on agent readiness against Stytch Connected Apps's 60.8 (C), and leads in 6 of 7 scored categories. Stytch Connected Apps leads on reliability. Both do auth oauth. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Stytch Connected Apps C 60.8",
      "Vercel Connect B 68.8",
      "scores"
    ],
    "h1": "Stytch Connected Apps vs Vercel Connect",
    "image": "https://www.anchorterminal.com/assets/og/compare-stytch-connected-apps-vs-vercel-connect.png",
    "path": "/compare/stytch-connected-apps-vs-vercel-connect",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Stytch Connected Apps vs Vercel Connect for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-vercel-connect"
  },
  "tokens": {
    "markdown": 2500,
    "slim": 680
  },
  "version": 1
}
