{
  "data": {
    "a": {
      "slug": "stytch-connected-apps",
      "name": "Stytch Connected Apps",
      "vendor": "Stytch (Twilio)",
      "vendorUrl": "https://stytch.com/connected-apps",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "Turns a Stytch project into an OAuth 2.1 and OIDC authorisation server so agents and MCP clients can act for your users.",
      "url": "https://www.anchorterminal.com/tools/stytch-connected-apps",
      "markdownUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json",
      "repo": "https://github.com/stytchauth/stytch-node",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.stytch.com",
      "packages": [
        {
          "registry": "npm",
          "name": "stytch"
        },
        {
          "registry": "pypi",
          "name": "stytch"
        }
      ],
      "auth": "mixed",
      "authNotes": "Backend calls use HTTP basic auth with the project ID as the user and the secret as the password against api.stytch.com (test.stytch.com for test projects). Agents and MCP clients go through OAuth 2.1: metadata at `{project-domain}/.well-known/oauth-authorization-server`, registration at `/v1/oauth2/register` with no credentials, the token endpoint at `/v1/oauth2/token`, and PKCE with S256 required for public clients. The end user must already have a Stytch session when the consent page loads.",
      "pricing": "freemium",
      "pricingNotes": "Pay as you go starts at $0 with 10,000 monthly active users (people and AI agents count the same), unlimited organisations, 5 SSO or SCIM connections and 1,000 M2M tokens a month. Extra SSO or SCIM connections are $125 each, brand removal and full email customisation is a $99 one-off, and fraud fingerprints are $0.005 each after 10,000. Enterprise is custom, with volume discounts, unlimited SSO and SCIM, a 99.99 per cent SLA, a HIPAA BAA and a private Slack channel. Connected Apps has no separate line and bills through MAU (https://stytch.com/pricing, https://stytch.com/connected-apps). The page doesn't state the per-MAU overage price or whether a card is needed.",
      "priceSummary": "$125 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 116,
        "npmWeekly": 349007,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://stytch.com/docs/connected-apps/guides/mcp-auth-overview",
      "llmsTxt": "https://stytch.com/docs/llms.txt",
      "capabilities": [
        "auth.oauth",
        "auth.consent",
        "auth.agent-identity",
        "auth.tokens"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "llms-txt",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2026-08-14",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.8,
        "grade": "C",
        "agentReady": false,
        "rank": 241,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 6,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 62,
          "payments": 20,
          "reliability": 73,
          "schema": 64,
          "security": 66,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens.",
        "strengths": [
          "OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box",
          "Revoke an app's access and all its tokens for a user with one API call",
          "Consent screen built from RBAC roles, so agents only see grantable scopes",
          "10,000 monthly active users free, agents counted as users",
          "No incidents on the OAuth endpoints on the status page since 1 July 2026"
        ],
        "weaknesses": [
          "No outbound token vault, so it can't hold your users' third-party tokens",
          "Node, Python, Go and Ruby SDKs last tagged 24 June 2026, and the docs changelog last moved on 14 August",
          "No published rate limits for the OAuth, registration or token endpoints",
          "No audit log of grants and revocations that we could find",
          "No security.txt, and Twilio's certifications page doesn't mention Stytch"
        ],
        "agentNotes": [
          "Fetch `{project-domain}/.well-known/oauth-authorization-server` first and use the endpoints it returns, not hard-coded paths",
          "Register with `token_endpoint_auth_method` none and PKCE S256 when the agent can't keep a secret",
          "Expect a 401 with protected resource metadata from the MCP server, then register and authorise",
          "Ask only for scopes the user's roles can grant, or the consent page will refuse them",
          "Back off exponentially on a 429, since no Retry-After header is documented"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.8
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 62,
          "payments": 20,
          "reliability": 73,
          "schema": 64,
          "security": 66,
          "transparency": 42
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install stytch",
        "http": "curl -X POST https://api.stytch.com/v1/connected_apps/clients \\\n  -u \"$STYTCH_PROJECT_ID:$STYTCH_SECRET\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"client_type\":\"third_party_public\",\"client_name\":\"My agent\",\"redirect_urls\":[\"https://example.com/callback\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/stytch-connected-apps"
      },
      "sameCompany": [
        "twilio-voice",
        "sendgrid",
        "twilio"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "SSO or SCIM connection above 5",
          "unit": "month",
          "usd": 125,
          "note": "Per connection per month on Pay as you go"
        },
        {
          "item": "Fraud fingerprint above 10,000",
          "unit": "call",
          "usd": 0.005,
          "note": "Optional fraud add-on"
        }
      ],
      "provenance": {
        "legalEntity": "Twilio Inc.",
        "domain": "stytch.com",
        "domainRegistered": "2014-04-25",
        "endpointOnVendorDomain": true,
        "terms": "https://www.twilio.com/en-us/legal/tos",
        "privacy": "https://www.twilio.com/en-us/legal/privacy",
        "statusPage": "https://status.stytch.com",
        "changelog": "https://stytch.com/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-02",
        "notes": [
          "stytch.com/legal/terms-of-service and /legal/privacy-policy return 302 redirects to twilio.com. Twilio's terms name Twilio Inc., a Delaware corporation, and link to the last Stytch terms at twilio.com/en-us/legal/tos/stytch-tos.",
          "/.well-known/security.txt returned 404 on 2026-09-30, and stytch.com/security returns 404.",
          "status.stytch.com is an Atlassian Statuspage with an RSS history feed.",
          "The old changelog.stytch.com said on 2 July 2026 that it was moving into the docs. Dated entries continue at stytch.com/docs/changelog, newest 14 August 2026.",
          "Twilio's sub-processor page lists 13 sub-processors for Stytch by Twilio, updated September 2026."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/stytch-connected-apps.json",
      "live": {
        "slug": "stytch-connected-apps",
        "probe": {
          "target": "https://api.stytch.com",
          "method": "get",
          "lastAt": "2026-10-04T23:32:54.958409765Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 450,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 441,
          "p95ms24h": 478,
          "samples24h": 272,
          "samples30d": 895,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 267,
              "ok": 267
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.stytch.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:30.119653254Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "stytchauth/stytch-node",
            "version": "v14.2.0",
            "released": "2026-06-24",
            "seenAt": "2026-10-04T16:40:57.813871092Z"
          },
          {
            "registry": "npm",
            "name": "stytch",
            "version": "14.2.0",
            "seenAt": "2026-10-04T16:40:57.134216114Z"
          },
          {
            "registry": "pypi",
            "name": "stytch",
            "version": "15.3.0",
            "released": "2026-06-24",
            "seenAt": "2026-10-04T16:40:57.623600429Z"
          }
        ],
        "githubStars": 116,
        "npmWeekly": 351245,
        "pypiWeekly": 174452,
        "securityTxt": {
          "url": "https://stytch.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:03.361419638Z"
        },
        "llmsTxt": {
          "url": "https://stytch.com/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:17.1998257Z"
        },
        "domain": {
          "domain": "stytch.com",
          "registered": "2014-04-25",
          "source": "https://rdap.verisign.com/com/v1/domain/stytch.com",
          "checkedAt": "2026-10-04T13:06:36.74420879Z"
        },
        "pages": [
          {
            "url": "https://stytch.com/docs/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:13.995093133Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "156a41d78412"
          },
          {
            "url": "https://stytch.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:17.287254331Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "61105c9b4a8b"
          }
        ],
        "updatedAt": "2026-10-04T23:32:54.958409765Z"
      }
    },
    "b": {
      "slug": "workos-pipes",
      "name": "WorkOS Pipes and Agents",
      "vendor": "WorkOS",
      "vendorUrl": "https://workos.com",
      "kind": "http-api",
      "category": "agent-auth",
      "summary": "WorkOS tools for connecting agents to third-party accounts, managing access tokens and assigning revocable agent identities.",
      "url": "https://www.anchorterminal.com/tools/workos-pipes",
      "markdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/workos-pipes.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/workos-pipes.json",
      "repo": "https://github.com/workos/workos-node",
      "license": "MIT (SDKs), platform closed",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.workos.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@workos-inc/node"
        },
        {
          "registry": "pypi",
          "name": "workos"
        }
      ],
      "auth": "mixed",
      "authNotes": "Server calls take the secret key as `Authorization: Bearer $WORKOS_API_KEY` (`sk_...`). End users connect accounts through the Pipes widget or an authorisation URL from `/data-integrations/{slug}/authorize`, which must be opened in the browser, not fetched. Agent tokens are minted from a blueprint as user-delegated, autonomous or agent-delegated sessions. The WorkOS MCP server signs in with OAuth as a dashboard user, with no API key.",
      "pricing": "freemium",
      "pricingNotes": "Pay as you go, with no card to start and a card before production. AuthKit is free up to 1,000,000 monthly active users, then $2,500 a month per extra million. SSO and Directory Sync connections are $125 a month each for the first 15, $100 for 16 to 30, $80 for 31 to 50 and $65 for 51 to 100. Audit Logs are free at the base, with $125 a month per SIEM connection and $99 a month per million events stored. Radar is free for 1,000 checks, then $100 per 50,000. A custom domain is $99 a month. Annual credits plans add volume discounts and a 99.99 per cent SLA (https://workos.com/pricing). Pipes and Agents don't appear on the pricing page, so we don't know what a connection or an agent session costs.",
      "priceSummary": "$125 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 221,
        "npmWeekly": 4041570,
        "pypiWeekly": 1697594,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://workos.com/docs/pipes",
      "registryName": "com.workos/mcp",
      "capabilities": [
        "auth.oauth",
        "auth.tokens",
        "auth.consent",
        "auth.agent-identity",
        "auth.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "typescript",
        "python",
        "enterprise",
        "webhooks"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60,
        "grade": "C",
        "agentReady": false,
        "rank": 256,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 83,
          "payments": 10,
          "reliability": 70,
          "schema": 53,
          "security": 69,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.",
        "strengths": [
          "Agent identity with per-session revocation and token lifetimes set per blueprint",
          "Pipes covers 500+ providers with user-owned and organisation-owned connections by OAuth, API key or client credentials",
          "Published rate limits of 6,000 requests a minute per key, with Retry-After on a 429",
          "Same platform for SSO, directory sync, RBAC, Audit Logs and Vault",
          "SOC 2 Type 2, a public subprocessor list and a 99.99 per cent SLA on annual plans"
        ],
        "weaknesses": [
          "21 incidents on the status page since 3 July 2026, several over an hour",
          "Pipes and Agents aren't on the pricing page",
          "Deleting a connected account doesn't revoke the grant at the provider",
          "Breaking Pipes change in SDK 11.0.0 on 28 September 2026",
          "No OpenAPI file, llms.txt or security.txt we could find"
        ],
        "agentNotes": [
          "Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token",
          "Branch on `active` in the response and send the user to reconnect on `needs_reauthorization`",
          "Wait for Retry-After on a 429, or back off with jitter when it's missing",
          "Use lower-case provider slugs such as github or slack",
          "Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 83,
          "payments": 10,
          "reliability": 70,
          "schema": 53,
          "security": 69,
          "transparency": 37
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "npm install @workos-inc/node",
        "http": "curl -X POST https://api.workos.com/data-integrations/github/token -H \"Authorization: Bearer $WORKOS_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"user_id\":\"user_01EHZNVPK3SFK441A1RGBFSHRT\"}'",
        "claudeCode": "claude mcp add --transport http --scope user workos https://mcp.workos.com/mcp",
        "config": {
          "mcpServers": {
            "workos": {
              "url": "https://mcp.workos.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/auth.oauth",
        "tool": "https://letme.dev/workos-pipes"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "SSO or Directory Sync connection (first 15)",
          "unit": "month",
          "usd": 125,
          "note": "Per connection per month, falling to $65 above 50"
        },
        {
          "item": "Audit Logs SIEM connection",
          "unit": "month",
          "usd": 125,
          "note": "Plus $99 a month per million events stored"
        },
        {
          "item": "Custom domain",
          "unit": "month",
          "usd": 99,
          "note": "AuthKit, Admin Portal and email sender"
        }
      ],
      "provenance": {
        "legalEntity": "WorkOS, Inc.",
        "domain": "workos.com",
        "domainRegistered": "2005-02-02",
        "endpointOnVendorDomain": true,
        "terms": "https://workos.com/legal/terms",
        "privacy": "https://workos.com/legal/privacy",
        "statusPage": "https://status.workos.com",
        "changelog": "https://github.com/workos/workos-node/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The website terms (effective 29 October 2020) name WorkOS, Inc. and California law. The privacy policy was updated 20 October 2025 and doesn't say where data is stored.",
          "RDAP shows workos.com registered on 2005-02-02, years before the company, so the domain was bought later.",
          "/.well-known/security.txt returned 404 on 2026-09-30."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/workos-pipes.json",
      "live": {
        "slug": "workos-pipes",
        "probe": {
          "target": "https://api.workos.com",
          "method": "get",
          "lastAt": "2026-10-04T23:32:56.84607093Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 117,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 128,
          "p95ms24h": 187,
          "samples24h": 272,
          "samples30d": 895,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 267,
              "ok": 267
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.workos.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:28:05.691657187Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "workos/workos-node",
            "version": "v11.0.0",
            "released": "2026-09-28",
            "seenAt": "2026-10-04T16:44:14.997893727Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.workos/mcp",
            "version": "1.0.0",
            "seenAt": "2026-10-03T23:29:28.630222764Z"
          },
          {
            "registry": "npm",
            "name": "@workos-inc/node",
            "version": "11.0.0",
            "seenAt": "2026-10-04T16:44:14.113290354Z"
          },
          {
            "registry": "pypi",
            "name": "workos",
            "version": "10.5.0",
            "released": "2026-09-24",
            "seenAt": "2026-10-04T16:44:14.80123694Z"
          }
        ],
        "githubStars": 223,
        "npmWeekly": 4341866,
        "pypiWeekly": 1819216,
        "securityTxt": {
          "url": "https://workos.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:42.791540879Z"
        },
        "domain": {
          "domain": "workos.com",
          "registered": "2005-02-02",
          "source": "https://rdap.verisign.com/com/v1/domain/workos.com",
          "checkedAt": "2026-10-04T13:09:49.925296041Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/workos/workos-node/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:01.225770024Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "57d8be278609"
          },
          {
            "url": "https://workos.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:58.671443903Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0cdd6961c090"
          },
          {
            "url": "https://workos.com/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:54.606253176Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5fc970fc9d08"
          },
          {
            "url": "https://workos.com/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:56.692868313Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b3130dd8035"
          }
        ],
        "updatedAt": "2026-10-04T23:32:56.84607093Z"
      }
    },
    "summary": "Stytch Connected Apps has a score of 60.8 (C) against WorkOS Pipes and Agents's 60 (C). Both do auth oauth. The largest gap is maintenance \u0026 community, 21 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes",
    "json": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.md",
    "slim": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes.min.md"
  },
  "markdown": "Stytch Connected Apps has a score of 60.8 (C) against WorkOS Pipes and Agents's 60 (C). Both do auth oauth. The largest gap is maintenance \u0026 community, 21 points.\n\n- Stytch Connected Apps: grade C, 60.8/100, rank #241 of 452. Markdown https://www.anchorterminal.com/tools/stytch-connected-apps.md · JSON https://www.anchorterminal.com/api/v1/tools/stytch-connected-apps.json\n- WorkOS Pipes and Agents: grade C, 60/100, rank #256 of 452. Markdown https://www.anchorterminal.com/tools/workos-pipes.md · JSON https://www.anchorterminal.com/api/v1/tools/workos-pipes.json\n\n## Which one, for what\n\nPick Stytch Connected Apps for schema \u0026 documentation (+11), payments \u0026 pricing (+10).\n\nPick WorkOS Pipes and Agents for maintenance \u0026 community (+21).\n\n## Score by category\n\n| Category | Weight | Stytch Connected Apps | WorkOS Pipes and Agents | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 73 | 70 | Stytch Connected Apps +3 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 64 | 53 | Stytch Connected Apps +11 |\n| Agent ergonomics | 13% (16.2 this run) | 65 | 69 | WorkOS Pipes and Agents +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 66 | 69 | WorkOS Pipes and Agents +3 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 10 | Stytch Connected Apps +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 62 | 83 | WorkOS Pipes and Agents +21 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 66 | 64 | Stytch Connected Apps +2 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **60.8 · C** | **60 · C** | |\n\n## Facts side by side\n\n| Fact | Stytch Connected Apps | WorkOS Pipes and Agents |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Stytch (Twilio) | WorkOS |\n| Hosted endpoint | `https://api.stytch.com` | `https://api.workos.com` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (SDKs), platform closed | MIT (SDKs), platform closed |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | not listed | `com.workos/mcp` |\n| Last release | 2026-08-14 | 2026-09-28 |\n| Popularity | 116 stars, 349k npm/wk | 221 stars, 4M npm/wk, 1.7M PyPI/wk |\n| Agent reviews | 3/5 (2) | 2.5/5 (2) |\n\n## Verdicts\n\n**Stytch Connected Apps.** OAuth 2.1 authorisation server with DCR, CIMD and PKCE out of the box. No outbound token vault, so it can't hold your users' third-party tokens.\n\n**WorkOS Pipes and Agents.** Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour.\n\n## Before you call either\n\n### Stytch Connected Apps\n\n1. Fetch `{project-domain}/.well-known/oauth-authorization-server` first and use the endpoints it returns, not hard-coded paths\n2. Register with `token_endpoint_auth_method` none and PKCE S256 when the agent can't keep a secret\n3. Expect a 401 with protected resource metadata from the MCP server, then register and authorise\n4. Ask only for scopes the user's roles can grant, or the consent page will refuse them\n5. Back off exponentially on a 429, since no Retry-After header is documented\n\n### WorkOS Pipes and Agents\n\n1. Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token\n2. Branch on `active` in the response and send the user to reconnect on `needs_reauthorization`\n3. Wait for Retry-After on a 429, or back off with jitter when it's missing\n4. Use lower-case provider slugs such as github or slack\n5. Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry\n\n## Other comparisons with Stytch Connected Apps or WorkOS Pipes and Agents\n\n- [Arcade.dev vs Stytch Connected Apps](https://www.anchorterminal.com/compare/arcade-vs-stytch-connected-apps.md)\n- [Arcade.dev vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/arcade-vs-workos-pipes.md)\n- [Auth0 for AI Agents (Token Vault) vs Stytch Connected Apps](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-stytch-connected-apps.md)\n- [Auth0 for AI Agents (Token Vault) vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-workos-pipes.md)\n- [Descope Agentic Identity Hub vs Stytch Connected Apps](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-stytch-connected-apps.md)\n- [Descope Agentic Identity Hub vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-workos-pipes.md)\n- [Keycard vs Stytch Connected Apps](https://www.anchorterminal.com/compare/keycard-vs-stytch-connected-apps.md)\n- [Keycard vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/keycard-vs-workos-pipes.md)\n- [Nango vs Stytch Connected Apps](https://www.anchorterminal.com/compare/nango-vs-stytch-connected-apps.md)\n- [Nango vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/nango-vs-workos-pipes.md)\n- [Scalekit AgentKit vs Stytch Connected Apps](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-stytch-connected-apps.md)\n- [Scalekit AgentKit vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-workos-pipes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Stytch Connected Apps vs WorkOS Pipes and Agents",
        "url": ""
      }
    ],
    "description": "Stytch Connected Apps has a score of 60.8 (C) against WorkOS Pipes and Agents's 60 (C). Both do auth oauth. The largest gap is maintenance \u0026 community, 21 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Stytch Connected Apps C 60.8",
      "WorkOS Pipes and Agents C 60",
      "scores"
    ],
    "h1": "Stytch Connected Apps vs WorkOS Pipes and Agents",
    "image": "https://www.anchorterminal.com/assets/og/compare-stytch-connected-apps-vs-workos-pipes.png",
    "path": "/compare/stytch-connected-apps-vs-workos-pipes",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Stytch Connected Apps vs WorkOS Pipes and Agents for AI agents",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/stytch-connected-apps-vs-workos-pipes"
  },
  "tokens": {
    "markdown": 1550,
    "slim": 330
  },
  "version": 1
}
