# Aembit (slim) > Aembit is a hosted identity and access platform for workloads and AI agents. Its MCP Identity Gateway and MCP Authorisation Server apply access policies and inject credentials, with a Cloud API, an Edge API, a CLI and an Edge SDK. - Full: https://www.anchorterminal.com/tools/aembit.md (~7,450 tokens) · this version ~1,780 tokens · JSON https://www.anchorterminal.com/tools/aembit.json · canonical https://www.anchorterminal.com/tools/aembit - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 70.5/100 · rank #134 of 722 · #5 in Agent auth & delegated access · agent-ready · confidence medium** Assessment: Agents and workloads get short-lived credentials by attestation, and MCP clients sign in through OAuth 2.1 with policy checked on every request. Both APIs have public OpenAPI files. No rate limit figures or SLA are published, the managed gateway endpoint is requested through an Aembit representative, and no DPA or sub-processor list was found. ## Facts - Kind: HTTP API · vendor: Aembit, Inc. · category: Agent auth & delegated access · legal entity: Aembit, Inc. · provenance 78/100 - Local only (HTTP, Streamable HTTP): npm `@aembit/edge-sdk` - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Aembit's terms of service. The Edge SDKs on GitHub are Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Interfaces: Cloud API (management, 171 operations), Edge API (2 operations), Aembit CLI, Edge SDK, MCP Identity Gateway, MCP Authorisation Server, Aembit MCP Server (3 read-only tools), Terraform provider - MCP Identity Gateway: Managed at https://.mcpgateway.aembit.io with MCP at /mcp, or self-hosted on Linux. Version 1.34.6034 (7 October 2026). Proxies tools, resources and prompts - MCP client sign-in: OAuth 2.1 with PKCE, dynamic client registration or a Client ID Metadata Document. Users sign in through an OIDC or SAML identity provider - Workload attestation: AWS, Azure, Google Cloud, Kubernetes, GitHub Actions, GitLab, Terraform Cloud or any OIDC ID token - Credential types: API key, username and password, OAuth token, Google Workload Identity Federation, AWS STS federation, per the Edge API - Token lifetime: Aembit API token 1 hour by default. Edge API access token 1 hour by default. Aembit Access Token Credential Provider minimum 300 seconds - Roles: No Access, Read Only or Read/Write per resource type, limited to Resource Sets. SuperAdmin and Auditor system roles - Audit: Audit logs, access authorisation events and workload events. Log Streams to AWS S3, Google Cloud Storage, Splunk and CrowdStrike - Event log retention: 24 hours on Starter, 7 days on Teams for agents, custom on Enterprise - Free plan: Starter with 3 AI agents, one MCP Identity Gateway and 5 MCP authorisation policies, or 10 workloads and 10 Access Policies - Sign-up: https://useast2.aembit.io/signup, a request form at aembit.io/request-a-free-tenant, or AWS Marketplace and Azure Marketplace - SDKs: @aembit/edge-sdk 1.34.1 on npm (7 September 2026), Apache-2.0. Python in the repository at 0.1.0, not on PyPI on 8 October 2026. Go listed as planned - Certifications: SOC 2 Type II and ISO/IEC 27001:2022, per the docs - Status: status.aembit.io on Statuspage, components Management Portal (Admin and API) and Control Plane - Prices: Teams, each AI agent $20 per month (plan); Teams, each workload $20 per month (plan) - Scores: Reliability 65, Performance pending, Schema & documentation 85, Agent ergonomics 72, Security & auth 84, Payments & pricing 40, Task success pending, Maintenance & community 80, Transparency & trust 60 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted service. · Schema & documentation, OpenAPI 3.1.1 files for the Cloud API (78 paths, 171 operations) and the Edge API (2 operations) download from docs.aembit.io without a logi… · Agent ergonomics, The Edge API is two calls that return one credential, and the Aembit MCP Server has three read-only tools (22). · Security & auth, The API accepts only Bearer access tokens and the docs say long-lived credentials aren't supported. · Payments & pricing, No x402, MPP or L402 found in the docs, the OpenAPI files or the pricing page (0). · Maintenance & community, MCP Identity Gateway 1.34.6034 on 7 October 2026 and Aembit CLI 1.34.6014 on 5 October (30). · Transparency & trust, Closed service under terms of service last reviewed 14 July 2026, with the Edge SDKs under Apache-2.0 (15). - Sources: 22, open questions: 7, both in the full twin - Capabilities: auth.oauth, auth.agent-identity, auth.tokens, auth.consent, auth.audit - JSON: https://www.anchorterminal.com/api/v1/tools/aembit.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/aembit.svg` or a link to https://www.anchorterminal.com/tools/aembit from a page on aembit.io or one of its subdomains, or the README of github.com/Aembit/edge-sdks, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Read the API Base URL and token from the tenant's Profile page. Tokens last 1 hour by default, so plan to refresh 2. Send `X-Aembit-ResourceSet` on Cloud API, Edge API and MCP calls outside the default Resource Set, or the request runs against the default set 3. Cache the Edge API access token from `/edge/v1/auth` until near expiry before calling `/edge/v1/credentials`. Both endpoints can answer 429 4. Point MCP clients at `https:///mcp`. The `/me` path is deprecated 5. Expect tool names prefixed with the Server Workload name behind the MCP Identity Gateway, and keep `perPage` at 100 or less on the Aembit MCP Server ## Connect ```bash npm install @aembit/edge-sdk ``` ```bash curl -X GET -L 'https://tenant.aembit.io/api/v1/server-workloads' -H 'Authorization: Bearer ' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/aembit ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Descope Agentic Identity Hub | A | 78.1 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/descope-agentic-identity.min.md | | WorkOS Pipes and Agents | C | 59.9 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/workos-pipes.min.md | | Keycard | C | 56.2 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/keycard.min.md | | Microsoft Entra Agent ID | BB | 74.4 | auth.oauth, auth.agent-identity, auth.consent, auth.audit | https://www.anchorterminal.com/tools/microsoft-entra-agent-id.min.md | | Scalekit AgentKit | BB | 71.9 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity | https://www.anchorterminal.com/tools/scalekit-agentkit.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)