# Vercel Connect > Vercel Connect is a credential broker for apps and agents. Code asks it for a short-lived, scoped token for Slack, GitHub, Microsoft, Linear, Snowflake or any OAuth, API-key or MCP service, as the app or for a user. - Canonical: https://www.anchorterminal.com/tools/vercel-connect - Markdown: https://www.anchorterminal.com/tools/vercel-connect.md (~8,200 tokens) - Slim: https://www.anchorterminal.com/tools/vercel-connect.min.md (~1,930 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/vercel-connect.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade B · 68.8/100 · rank #195 of 842 · #7 in Agent auth & delegated access · not agent-ready · confidence medium** More from Vercel Inc., listed separately because each is its own product: [Vercel Sandbox](https://www.anchorterminal.com/tools/vercel-sandbox.md) (Code execution sandboxes). ## Assessment Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript. ## Facts | Field | Value | | --- | --- | | Vendor | Vercel Inc. (https://vercel.com) | | Kind | HTTP API | | Category | Agent auth & delegated access (https://www.anchorterminal.com/categories/agent-auth) | | Transport | HTTP | | Endpoint | `https://api.vercel.com` | | Auth | OAuth or key · Access is self-serve with a Vercel account, on every plan. A deployment calls Connect with its project OIDC token (`VERCEL_OIDC_TOKEN`), which Connect checks against the connector's project links and their environments. Locally, `vercel env pull` writes a development OIDC token that lasts about 12 hours. Outside Vercel, a Vercel access token goes in `vercelToken`, and it can request only the app subject or its own user. Connect then holds the provider side. Vercel registers the OAuth client for managed connectors (Slack, GitHub, Linear, Microsoft, Snowflake, Salesforce), and the customer supplies a client or an API key for the others. End users consent in a browser at a URL from `startAuthorization`. | | Pricing | Freemium ($3 / 1k req) · Billed per token request and per trigger. Hobby includes 500 token requests and 1,000 triggers a month at no extra charge, and Vercel's fair use guidelines limit Hobby to non-commercial, personal use. Pro is $3.00 per 1,000 token requests and $0.95 per 1,000 triggers on top of the plan. Enterprise is negotiated. A trigger is counted once per destination, and once per event when no destination is set. The SDK's in-process cache means many provider calls in one invocation cost one token request (https://vercel.com/docs/connect/pricing, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the Connect docs, the pricing page or the Connect operations of the OpenAPI document (checked 2026-10-08). | | Licence | Proprietary service under Vercel's Terms of Service and the Vercel Connect product terms. The `@vercel/connect` SDK and the Vercel CLI are Apache-2.0 | | Packages | npm: `@vercel/connect` | | Source | https://github.com/vercel/vercel | | Docs | https://vercel.com/docs/connect | | llms.txt | https://vercel.com/llms.txt | | Last release | 2026-10-06 | | GitHub stars | 16,354 (as of 2026-10-08) | | npm downloads / week | 738,165 | | Surface graded | The hosted Connect API at https://api.vercel.com (`/v1/connect/token/{connector}`, `/v1/connect/authorize/{connector}` and the connector management paths), reached through the `@vercel/connect` TypeScript SDK, the `vercel connect` CLI or plain HTTP | | Token subjects | `app` (the service or bot), `user` (a named user, after consent), `jwt-bearer` (a federated subject from the customer's own identity provider) and `token` (exchange of an existing subject token) | | Scoping | `scopes`, `resources`, `authorizationDetails` and `audience` are forwarded to the provider per request. `installationId` picks the tenant, and `'*'` asks for a cross-installation token where the connector supports it | | Connectors | Managed by Vercel: Slack, GitHub, Linear, Microsoft, Microsoft Teams, Snowflake, Salesforce (beta) and Linq (beta). Customer managed: custom OAuth with the authorisation code flow with PKCE or client credentials, static API keys, and MCP servers discovered from their OAuth metadata | | Rate limits | 200 reads a minute per team (`getToken`, `getTokenResponse`, `getConnectorMetadata`, list), 50 writes a minute per team (`revokeToken`, create, attach, detach, update, remove), 6,000 a minute on the OAuth gateway and trigger endpoints. A 429 means waiting one minute | | Errors | Typed SDK classes: `UserAuthorizationRequiredError`, `ConnectorInstallationRequiredError`, `NoValidTokenError`, `ConnectorNotFoundError`, `ClientNotLinkedToProjectError`, `ClientNotEnabledForEnvironmentError` | | Audit | Observability tab per connector with five event types and correlation IDs. Retention 12 hours on Hobby, 3 days on Pro, 30 days on Enterprise. Drains on Pro and Enterprise. Connector changes appear in the team Activity Log | | Triggers | Connect verifies provider webhook signatures, re-attests each event with an OIDC identity and forwards it to up to 3 project destinations per connector | | Access control | Project links per environment, including Custom Environments. On Pro and Enterprise an owner can restrict connector management to Owners and the Connector Manager permission | | SDK | `@vercel/connect` 2.4.1 (6 October 2026), Apache-2.0, one runtime dependency (`@vercel/oidc`), with adapters for AI SDK, MCP clients, eve, Chat SDK, Better Auth and Auth.js | | Certifications | Vercel states SOC 2 Type 2 (Security, Confidentiality, Availability) and ISO 27001:2022. security.txt points to HackerOne and expires 28 September 2027 | | Status | Connect has been a component on www.vercel-status.com since 18 September 2026 | | Capabilities | auth.tokens, auth.oauth, auth.consent, auth.audit | | Tags | hosted, freemium, free-tier, oauth, oidc, openapi, llms-txt, typescript, cli, webhooks, status-page, soc2, iso27001 | | JSON | https://www.anchorterminal.com/api/v1/tools/vercel-connect.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 63 | 12.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 84 | 13.7 | | Agent ergonomics | 13% | 16.2 | 75 | 12.2 | | Security & auth | 14% | 17.5 | 83 | 14.5 | | Payments & pricing | 10% | 12.5 | 40 | 5.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 81 | 7.1 | | Transparency & trust (editorial 55, provenance 99) | 7% | 8.8 | 77 | 6.7 | | Negative events | up to −15 | up to −15 | April 2026. Vercel's security bulletin says an attacker took over an employee's account through a compromised third-party AI tool, reached internal systems and decrypted non-sensitive environment variables of a limited subset of customers. It predates Connect's general availability on 25 August 2026 and is documented with remediation, so 3 of a possible 15 is taken, because Connect now keeps customers' provider refresh tokens on the same platform (https://vercel.com/kb/bulletin/vercel-april-2026-security-incident). | -3 | | **Total** | | | | **68.8 → B** | ### Why each score - Reliability 63: Graded on the hosted lines. Connect is a component on www.vercel-status.com with an incident feed (20). The feed has elevated error rates on Connect and Passport for 1 hour 34 minutes on 10 September 2026, marked major, and elevated KMS and Connect errors posted for 18 September, which we read as one major (10). Rate limits published with numbers, 200 reads and 50 writes a minute per team and 6,000 a minute on the OAuth gateway and trigger endpoints (15). A 429 is documented with a one-minute wait and token requests are safe to repeat, but we found no Retry-After header or idempotency keys for writes (8). Vercel's SLA says it does not apply to the APIs or CLI (0). Generally available since 25 August 2026, with Salesforce and Linq connectors still beta (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 84: Vercel's public OpenAPI 3.0.3 document has 13 Connect paths, the token and authorise calls among them (25). Docs are served as Markdown on request and vercel.com/llms.txt exists (10). The docs say when to use Connect and when a Vercel Integration fits better, and give a use-when line for each subject type (16). The token body types the subject as a union with enums, but most variants allow extra properties, `authorizationDetails` is open and scopes are provider strings (10). Examples are plentiful and six SDK error classes are documented with fixes, while the OpenAPI error responses for the token call have empty descriptions (11). Paths are versioned and the SDK follows semver with a dated product changelog, though the package changelog in the public repository stops at 2.0.2 (12). - Agent ergonomics 75: A token call returns one token with its expiry and identifiers, so there is little to size (22). Listing connectors takes `limit`, `cursor`, `search`, `projectId` and `type` (18). Errors are typed and each maps to a next step, such as starting consent or attaching the project, but the 429 carries no documented wait header (17). Token requests are cached and safe to repeat, and we found no idempotency keys for create, attach or revoke (10). Only the connector and subject are required and scopes default to the connector's own, but the one official SDK is TypeScript, with a CLI and plain HTTP for everything else (8). - Security & auth 83: Callers present a project-bound OIDC token or a Vercel access token, provider tokens are short-lived and scoped per request, refresh tokens stay with Vercel, and grants can be revoked from the SDK, CLI or dashboard (28). Project links limit which environments may ask, requests can narrow scopes and resources, and Pro and Enterprise can restrict who manages connectors. There is no approval step before a token is issued, omitted scopes default to `['*']`, and revocation depends on the provider (14). The API returns tokens, not untrusted content (10). Token requests, authorisations and revocations are logged with correlation IDs, kept 12 hours on Hobby, 3 days on Pro and 30 days on Enterprise, with drains on paid plans (13). Valid security.txt, HackerOne, SOC 2 Type 2 and ISO 27001:2022 as Vercel states them, and a public bulletin for the April 2026 incident (18). - Payments & pricing 40: No x402, MPP or L402 (0). Unit prices are public without a login, $3.00 per 1,000 token requests and $0.95 per 1,000 triggers on Pro (20). Hobby includes 500 token requests and 1,000 triggers a month at no charge, for non-commercial use, and the Hobby plan page names no card (20). A person signs up in a browser, and connectors and user consent also pass through a browser (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 81: `@vercel/connect` 2.4.1 was published on 6 October 2026 (30). npm shows 30 versions since 2 July 2026, and the changelog has Connect entries on 11 and 25 August and 11 and 21 September (20). Closed service with a dated public changelog. The public copy of the SDK in vercel/vercel was last synced on 8 September 2026 and stops at 2.0.2, and we didn't read issue replies (10). One current official SDK, with 738,165 npm downloads in the week to 4 October 2026 (15). One runtime dependency and 13 test files in the package. We didn't confirm CI status on the default branch (6). - Transparency & trust 77: Closed service under the Terms of Service of 1 June 2026 plus short Connect product terms, with an Apache-2.0 SDK and CLI (20). A privacy notice and a DPA exist, and the docs say refresh tokens are stored on Vercel's infrastructure and give event retention by plan. We found no retention period or encryption statement for stored provider credentials, and the DPA covers Pro and Enterprise only (18). No deprecation policy found. The product terms let Vercel remove third-party platforms without notice, though the beta price change was announced with a date of 25 September 2026 (5). The DPA points to a subprocessor list on security.vercel.com and says primary processing is in the United States. We saw the list's page but could not read its entries (12). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/vercel-connect.md (JSON https://www.anchorterminal.com/fixes/vercel-connect.json) ### What we couldn't check - unchecked: the entries of the subprocessor list on security.vercel.com, which is drawn by script. We saw only that the page has a Subprocessors section. - unchecked: whether Hobby signup asks for a card. The Hobby plan page names none, and we did not open the signup flow. - unchecked: CI status for packages/connect on the default branch of vercel/vercel, and issue replies there. - Whether failed or cached token requests are billed. The pricing page defines a token request as a call that returns a provider token. - How stored provider refresh tokens and API keys are encrypted and how long they are kept after a connector is deleted. Not found in the reviewed documentation. - Whether a REST path for revocation is public. The docs say tokens can be revoked through the REST API, and the OpenAPI document has no Connect revoke path. - The deduction of 3 for the April 2026 incident is a judgement call. The existing vercel-sandbox listing took none for the same bulletin. - The 18 September 2026 status entry for KMS and Connect errors has no duration, so its length is unknown. - The count of 1,083 catalogue services is ours, from the Markdown of /connect/browse. Vercel's own figure at launch was 100+ preset connectors. ### Sources - Connect docs overview: (seen 2026-10-08) - authentication and the HTTP token call: (seen 2026-10-08) - tokens, scoping, revocation and errors: (seen 2026-10-08) - rate limits: (seen 2026-10-08) - pricing: (seen 2026-10-08) - observability events and retention: (seen 2026-10-08) - SDK reference: (seen 2026-10-08) - Connect product terms: (seen 2026-10-08) - project links: (seen 2026-10-08) - general availability changelog entry: (seen 2026-10-08) - connector permissions changelog entry: (seen 2026-10-08) - connector catalogue: (seen 2026-10-08) - OpenAPI document: (seen 2026-10-08) - status page incidents feed: (seen 2026-10-08) - status page components: (seen 2026-10-08) - npm registry, versions and dates: (seen 2026-10-08) - npm weekly downloads: (seen 2026-10-08) - SDK source in the public repository (shallow clone): (seen 2026-10-08) - Terms of Service: (seen 2026-10-08) - Privacy Notice: (seen 2026-10-08) - Data Processing Addendum: (seen 2026-10-08) - SLA: (seen 2026-10-08) - compliance page: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - April 2026 security bulletin: (seen 2026-10-08) - Hobby plan: (seen 2026-10-08) - RDAP for vercel.com: (seen 2026-10-08) ## Who's behind it (provenance 99/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Vercel Inc. | 20/20 | | Domain age | vercel.com, registered 1999-10-04 (27 years) | 15/15 | | Endpoint on the vendor's domain | api.vercel.com | 15/15 | | Terms of service | read, states 7 of the 7 things a reader expects | 10/10 | | Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 | | Status page | www.vercel-status.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The Terms of Service (last updated 1 June 2026) name Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, and California law. The DPA calls Vercel Inc. a Delaware corporation. Connect also has its own product terms at https://vercel.com/docs/connect/legal. The Terms of Service text we read does not mention Connect by name. The Privacy Notice (effective 1 June 2026) says it does not apply to personal information Vercel processes as a processor for customers, which the DPA covers. The DPA (effective 31 March 2026) applies to Pro and Enterprise plans. https://vercel.com/.well-known/security.txt points to HackerOne and responsible.disclosure@vercel.com and expires 2027-09-28. RDAP gives vercel.com a registration date of 1999-10-04, long before Vercel, so the domain was bought later. The API answers at api.vercel.com and the OpenAPI document at openapi.vercel.sh. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://vercel.com/legal/terms), read 2026-10-08, dated 2026-06-01, states 7 of the 7 things a reader expects. - To know. Says it may use customer content to train or improve models, and gives an opt-out. "In addition, if you are on a Hobby plan or trial Pro plan, you agree that we may use Your Content to train our artificial intelligence ("AI") and machine learning models, and we may share Your Content with third parties for the purpose of developing and improving their products, including training and improving their…" - To know. Says access can be ended without notice or for any reason. "We may shut down and terminate projects or deployments using the Hobby plan without notice for any reason or no reason." - To know. Requires arbitration or waives class actions. "You and Vercel agree that any Claim will be settled by final and binding arbitration, using the English language, administered by JAMS under its Streamlined Arbitration Rules and Procedures (the "JAMS Rules")." - Gives the date it was last updated. Last updated 2026-06-01. - Names the governing law or courts. The law of the State of California. - Says how changes to the terms are announced. Says it gives notice of a change. - Also in the text (2026-10-08). A customer that lets its own or a third party's AI tools or agents access the service agrees to be legally bound by the actions those tools take on its behalf. "you authorize and agree to be legally bound by the actions taken on your behalf by those Third Party Tools" - Also in the text (2026-10-08). During the agreement Vercel may use the customer's trademarks, trade names and logos in its marketing materials and websites and name it as a customer. "During the term of this Agreement, you grant Vercel a non-exclusive, royalty-free, fully-paid up license to use and reproduce your trademarks, trade names and logos in Vercel's marketing materials and website(s) and to indicate that you are a Vercel customer." - Also in the text (2026-10-08). The licence over customer content is sublicensable and transferable and covers improving the services and developing new products and services. "a worldwide, non-exclusive, royalty-free, fully paid, sublicensable and transferable license to use, copy, modify, adapt, reproduce, distribute, display, publish, store, perform, and create derivatives of Your Content to provide and improve the Services, develop new products and services" **Privacy policy** (https://vercel.com/legal/privacy-policy), read 2026-10-08, dated 2026-06-01, states 7 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and gives an opt-out. "Services, such as when we use your information to train the AI models" - To know. Says it sells personal data or shares it for advertising. "We engage with several partners, such as third-party advertising networks, integration service partners, event sponsors, and resellers. We may share information with them to provide and support our Services, and to conduct our Advertising and Marketing Activities." - Gives the date it was last updated. Last updated 2026-06-01. - Not found in the text. Says how long data is kept. - Gives a privacy contact. privacy@vercel.com. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). For Hobby and Pro plans, subject to team settings, Vercel may disclose de-identified information to AI business partners for training and improving their models. "we may disclose de-identified information (including de-identified AI Product Information) to AI business partners for their product improvement and development, including training and improving AI and machine learning models" ## Live (updated 2026-10-09 10:14 UTC) - Right now: up, HTTP 200, 570 ms, checked 2026-10-09 10:14 UTC (get on `https://api.vercel.com`) - Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 569 ms · p95 1.1 s - Vendor status page: none, All Systems Operational - Always current: https://www.anchorterminal.com/api/v1/live/vercel-connect.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Token request (Pro) | $3 | per 1,000 requests | Hobby includes 500 a month. Enterprise negotiated | | Trigger, a forwarded provider webhook (Pro) | $0.95 | per 1,000 requests | Counted per destination. Hobby includes 1,000 a month | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Refresh tokens stay on Vercel's infrastructure. Code receives only short-lived access tokens, as the app or for a named user - A deployment authenticates with its project OIDC token, checked against per-environment project links, so no provider secret sits in environment variables - Public OpenAPI 3.0.3 document covers 13 Connect paths, including `/v1/connect/token/{connector}` and `/v1/connect/authorize/{connector}` - Token requests, completed authorisations and revocations are logged with `tokenId` and `authorizationId`, and can be sent to a drain on Pro and Enterprise - Rate limits are published with numbers, 200 reads and 50 writes a minute per team ## Weaknesses - Vercel's SLA says it does not apply to the APIs or CLI, so token requests carry no uptime commitment - Elevated Connect errors for 94 minutes on 10 September 2026, marked major, and again on 18 September, per the status page - Event history is kept 12 hours on Hobby and 3 days on Pro. Connector audit logs and 30 days need Enterprise - Revocation depends on the provider. Without a revocation endpoint the provider credential can work until it expires - The SDK is TypeScript only, and the public repository's copy stops at 2.0.2 while npm has 2.4.1 ## Before you call it (notes for agents) 1. Call `getToken` at request time and don't store the result. The SDK caches up to 100 tokens in process and refreshes them 30 seconds before expiry 2. Pass `scopes` on every request. Since SDK 1.0.0 an omitted `scopes` defaults to `['*']`, the connector's default scopes 3. Catch `UserAuthorizationRequiredError`, call `startAuthorization` and send the user to the returned URL. Consent needs a person in a browser 4. Outside Vercel, pass a Vercel access token as `vercelToken`. It can request only the app subject or its own user, not another user 5. On a 429 wait one minute for the window to reset. Limits are 200 token requests a minute per team ## Connect Install: ```bash pnpm add @vercel/connect ``` First request: ```bash curl -X POST https://api.vercel.com/v1/connect/token/slack%2Facme-slack \ -H "Authorization: Bearer $VERCEL_OIDC_TOKEN" \ -H "Content-Type: application/json" \ -d '{"subject":{"type":"app"},"scopes":["chat:write"]}' ``` Through letme (picks today, calling later): https://letme.dev/vercel-connect. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Descope Agentic Identity Hub | A | 78.1 | 14 | auth.oauth, auth.tokens, auth.consent, auth.audit | no | https://www.anchorterminal.com/tools/descope-agentic-identity.md | | Amazon Bedrock AgentCore Identity | BB | 74.8 | 64 | auth.oauth, auth.tokens, auth.consent, auth.audit | no | https://www.anchorterminal.com/tools/agentcore-identity.md | | Aembit | BB | 70.5 | 147 | auth.oauth, auth.tokens, auth.consent, auth.audit | no | https://www.anchorterminal.com/tools/aembit.md | | Nango | B | 67.7 | 222 | auth.oauth, auth.tokens, auth.consent, auth.audit | no | https://www.anchorterminal.com/tools/nango.md | | Arcade.dev | B | 66.9 | 248 | auth.oauth, auth.tokens, auth.consent, auth.audit | no | https://www.anchorterminal.com/tools/arcade.md | | WorkOS Pipes and Agents | C | 59.9 | 485 | auth.oauth, auth.tokens, auth.consent, auth.audit | no | https://www.anchorterminal.com/tools/workos-pipes.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Every token request is a POST to `https://api.vercel.com/v1/connect/token/:connector` with a Bearer OIDC or access token, and the connector uid is URL-encoded, so `slack/acme-slack` becomes `slack%2Facme-slack` (source: ) - Generally available on all plans since 25 August 2026, with RBAC for connectors, audit logs and token observability added at that release (source: ) - The catalogue page listed 1,083 services when we counted on 8 October 2026, 8 of them marked Managed, 882 with an API key method, 374 with MCP and 48 with OAuth. Salesforce and Linq are marked Beta (source: ) - The product terms forbid routing cardholder data, protected health information, GLBA non-public personal information or ITAR data through Connect without Vercel's written approval, and let Vercel add or remove third-party platforms without notice (source: ) - Revocation calls the provider's revocation endpoint where one exists. Otherwise Connect marks the token for deletion in its own store and the provider credential may keep working until it expires (source: ) - Project links decide which environments may request tokens but don't separate provider installations, so Vercel's docs advise one connector per environment for isolation (source: ) - Vercel's security bulletin for April 2026 says an attacker reached internal systems through an employee account and decrypted some customers' non-sensitive environment variables. Connect was not generally available then (source: ) ## Compare - [Aembit vs Vercel Connect](https://www.anchorterminal.com/compare/aembit-vs-vercel-connect.md): BB 70.5 vs B 68.8 - [Amazon Bedrock AgentCore Identity vs Vercel Connect](https://www.anchorterminal.com/compare/agentcore-identity-vs-vercel-connect.md): BB 74.8 vs B 68.8 - [Arcade.dev vs Vercel Connect](https://www.anchorterminal.com/compare/arcade-vs-vercel-connect.md): B 66.9 vs B 68.8 - [Auth0 for AI Agents (Token Vault) vs Vercel Connect](https://www.anchorterminal.com/compare/auth0-ai-agents-vs-vercel-connect.md): BB 71.4 vs B 68.8 - [Descope Agentic Identity Hub vs Vercel Connect](https://www.anchorterminal.com/compare/descope-agentic-identity-vs-vercel-connect.md): A 78.1 vs B 68.8 - [Keycard vs Vercel Connect](https://www.anchorterminal.com/compare/keycard-vs-vercel-connect.md): C 56.2 vs B 68.8 - [Microsoft Entra Agent ID vs Vercel Connect](https://www.anchorterminal.com/compare/microsoft-entra-agent-id-vs-vercel-connect.md): BB 74.4 vs B 68.8 - [Nango vs Vercel Connect](https://www.anchorterminal.com/compare/nango-vs-vercel-connect.md): B 67.7 vs B 68.8 - [Scalekit AgentKit vs Vercel Connect](https://www.anchorterminal.com/compare/scalekit-agentkit-vs-vercel-connect.md): BB 71.9 vs B 68.8 - [Stytch Connected Apps vs Vercel Connect](https://www.anchorterminal.com/compare/stytch-connected-apps-vs-vercel-connect.md): C 60.8 vs B 68.8 - [Vercel Connect vs WorkOS Pipes and Agents](https://www.anchorterminal.com/compare/vercel-connect-vs-workos-pipes.md): B 68.8 vs C 59.9 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on vercel.com or one of its subdomains, or the README of github.com/vercel/vercel. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "vercel-connect", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Vercel Connect on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Vercel Connect on Anchor Terminal](https://www.anchorterminal.com/badges/vercel-connect.svg)](https://www.anchorterminal.com/tools/vercel-connect) ``` Plain link: ```html Vercel Connect on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Vercel Connect is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/vercel-connect-dark.png - Light: https://www.anchorterminal.com/assets/share/vercel-connect-light.png