# Vercel Connect (slim) > Vercel Connect is a credential broker for apps and agents. Code asks it for a short-lived, scoped token for Slack, GitHub, Microsoft, Linear, Snowflake or any OAuth, API-key or MCP service, as the app or for a user. - Full: https://www.anchorterminal.com/tools/vercel-connect.md (~8,200 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/vercel-connect.json · canonical https://www.anchorterminal.com/tools/vercel-connect - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 68.8/100 · rank #195 of 842 · #7 in Agent auth & delegated access · not agent-ready · confidence medium** Assessment: Provider refresh tokens stay with Vercel, and code receives short-lived tokens tied to a project and environment through one call with a public OpenAPI definition. Vercel's SLA excludes its APIs, the status page records 94 minutes of elevated Connect errors on 10 September 2026, and the only SDK is TypeScript. ## Facts - Kind: HTTP API · vendor: Vercel Inc. · category: Agent auth & delegated access · legal entity: Vercel Inc. · provenance 99/100 - Endpoint: `https://api.vercel.com` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Vercel's Terms of Service and the Vercel Connect product terms. The `@vercel/connect` SDK and the Vercel CLI are Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Surface graded: The hosted Connect API at https://api.vercel.com (`/v1/connect/token/{connector}`, `/v1/connect/authorize/{connector}` and the connector management paths), reached through the `@vercel/connect` TypeScript SDK, the `vercel connect` CLI or plain HTTP - Token subjects: `app` (the service or bot), `user` (a named user, after consent), `jwt-bearer` (a federated subject from the customer's own identity provider) and `token` (exchange of an existing subject token) - Scoping: `scopes`, `resources`, `authorizationDetails` and `audience` are forwarded to the provider per request. `installationId` picks the tenant, and `'*'` asks for a cross-installation token where the connector supports it - Connectors: Managed by Vercel: Slack, GitHub, Linear, Microsoft, Microsoft Teams, Snowflake, Salesforce (beta) and Linq (beta). Customer managed: custom OAuth with the authorisation code flow with PKCE or client credentials, static API keys, and MCP servers discovered from their OAuth metadata - Rate limits: 200 reads a minute per team (`getToken`, `getTokenResponse`, `getConnectorMetadata`, list), 50 writes a minute per team (`revokeToken`, create, attach, detach, update, remove), 6,000 a minute on the OAuth gateway and trigger endpoints. A 429 means waiting one minute - Errors: Typed SDK classes: `UserAuthorizationRequiredError`, `ConnectorInstallationRequiredError`, `NoValidTokenError`, `ConnectorNotFoundError`, `ClientNotLinkedToProjectError`, `ClientNotEnabledForEnvironmentError` - Audit: Observability tab per connector with five event types and correlation IDs. Retention 12 hours on Hobby, 3 days on Pro, 30 days on Enterprise. Drains on Pro and Enterprise. Connector changes appear in the team Activity Log - Triggers: Connect verifies provider webhook signatures, re-attests each event with an OIDC identity and forwards it to up to 3 project destinations per connector - Access control: Project links per environment, including Custom Environments. On Pro and Enterprise an owner can restrict connector management to Owners and the Connector Manager permission - SDK: `@vercel/connect` 2.4.1 (6 October 2026), Apache-2.0, one runtime dependency (`@vercel/oidc`), with adapters for AI SDK, MCP clients, eve, Chat SDK, Better Auth and Auth.js - Certifications: Vercel states SOC 2 Type 2 (Security, Confidentiality, Availability) and ISO 27001:2022. security.txt points to HackerOne and expires 28 September 2027 - Status: Connect has been a component on www.vercel-status.com since 18 September 2026 - Prices: Token request (Pro) $3 per 1,000 requests; Trigger, a forwarded provider webhook (Pro) $0.95 per 1,000 requests - Scores: Reliability 63, Performance pending, Schema & documentation 84, Agent ergonomics 75, Security & auth 83, Payments & pricing 40, Task success pending, Maintenance & community 81, Transparency & trust 77 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Graded on the hosted lines. · Schema & documentation, Vercel's public OpenAPI 3.0.3 document has 13 Connect paths, the token and authorise calls among them (25). · Agent ergonomics, A token call returns one token with its expiry and identifiers, so there is little to size (22). · Security & auth, Callers present a project-bound OIDC token or a Vercel access token, provider tokens are short-lived and scoped per request, refresh tokens… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, `@vercel/connect` 2.4.1 was published on 6 October 2026 (30). · Transparency & trust, Closed service under the Terms of Service of 1 June 2026 plus short Connect product terms, with an Apache-2.0 SDK and CLI (20). - Sources: 27, open questions: 9, both in the full twin - Capabilities: auth.tokens, auth.oauth, auth.consent, auth.audit - JSON: https://www.anchorterminal.com/api/v1/tools/vercel-connect.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/vercel-connect.svg` or a link to https://www.anchorterminal.com/tools/vercel-connect from a page on vercel.com or one of its subdomains, or the README of github.com/vercel/vercel, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call `getToken` at request time and don't store the result. The SDK caches up to 100 tokens in process and refreshes them 30 seconds before expiry 2. Pass `scopes` on every request. Since SDK 1.0.0 an omitted `scopes` defaults to `['*']`, the connector's default scopes 3. Catch `UserAuthorizationRequiredError`, call `startAuthorization` and send the user to the returned URL. Consent needs a person in a browser 4. Outside Vercel, pass a Vercel access token as `vercelToken`. It can request only the app subject or its own user, not another user 5. On a 429 wait one minute for the window to reset. Limits are 200 token requests a minute per team ## Connect ```bash pnpm add @vercel/connect ``` ```bash curl -X POST https://api.vercel.com/v1/connect/token/slack%2Facme-slack \ -H "Authorization: Bearer $VERCEL_OIDC_TOKEN" \ -H "Content-Type: application/json" \ -d '{"subject":{"type":"app"},"scopes":["chat:write"]}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/vercel-connect ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Descope Agentic Identity Hub | A | 78.1 | auth.oauth, auth.tokens, auth.consent, auth.audit | https://www.anchorterminal.com/tools/descope-agentic-identity.min.md | | Amazon Bedrock AgentCore Identity | BB | 74.8 | auth.oauth, auth.tokens, auth.consent, auth.audit | https://www.anchorterminal.com/tools/agentcore-identity.min.md | | Aembit | BB | 70.5 | auth.oauth, auth.tokens, auth.consent, auth.audit | https://www.anchorterminal.com/tools/aembit.min.md | | Nango | B | 67.7 | auth.oauth, auth.tokens, auth.consent, auth.audit | https://www.anchorterminal.com/tools/nango.min.md | | Arcade.dev | B | 66.9 | auth.oauth, auth.tokens, auth.consent, auth.audit | https://www.anchorterminal.com/tools/arcade.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)