# WorkOS Pipes and Agents (slim) > WorkOS tools for connecting agents to third-party accounts, managing access tokens and assigning revocable agent identities. - Full: https://www.anchorterminal.com/tools/workos-pipes.md (~6,100 tokens) · this version ~1,430 tokens · JSON https://www.anchorterminal.com/tools/workos-pipes.json · canonical https://www.anchorterminal.com/tools/workos-pipes - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **C · 60/100 · rank #256 of 452 · #7 in Agent auth & delegated access · not agent-ready · confidence medium** Assessment: Agent identity with per-session revocation and token lifetimes set per blueprint. 21 incidents on the status page since 3 July 2026, several over an hour. ## Facts - Kind: HTTP API · vendor: WorkOS · category: Agent auth & delegated access · legal entity: WorkOS, Inc. · provenance 90/100 - Endpoint: `https://api.workos.com` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: MIT (SDKs), platform closed - Probe metrics: not measured yet (probes haven't run) - Providers: 500+ built in, plus custom providers - Free tier: AuthKit free up to 1,000,000 monthly active users, Audit Logs free at the base, no card to start - Connection types: User-owned or organisation-owned, by OAuth, API key or client credentials - Agent tokens: Access token up to 1 hour, refresh token up to 60 days, session up to 365 days - Revocation: Delete a connected account (tokens removed at WorkOS only) or revoke an agent session - Audit: Audit Logs API for events, exports and retention settings - MCP: Remote management server at mcp.workos.com/mcp, OAuth as a dashboard user - Prices: SSO or Directory Sync connection (first 15) $125 per month (plan); Audit Logs SIEM connection $125 per month (plan); Custom domain $99 per month (plan) - Scores: Reliability 70, Performance pending, Schema & documentation 53, Agent ergonomics 69, Security & auth 69, Payments & pricing 10, Task success pending, Maintenance & community 83, Transparency & trust 64 · total over the 7 assessed categories - Why: Reliability, Atlassian Statuspage at status.workos.com with component history (20). · Schema & documentation, We found no public OpenAPI file for the Pipes or Agents endpoints (0). · Agent ergonomics, The token call returns one access token and its state, so there's nothing to size (20). · Security & auth, One environment secret key (`sk_...`) covers every WorkOS product, while agent tokens come from blueprints as short-lived, revocable session… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, workos-node 11.0.0 is in the CHANGELOG for 28 September 2026 as a breaking release for Pipes, though the releases page's newest entry is 10… · Transparency & trust, Closed platform under website terms that name WorkOS, Inc. - Sources: 10, open questions: 4, both in the full twin - Capabilities: auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit - JSON: https://www.anchorterminal.com/api/v1/tools/workos-pipes.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/workos-pipes.svg` or a link to https://www.anchorterminal.com/tools/workos-pipes from a page on workos.com or one of its subdomains, or the README of github.com/workos/workos-node, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call POST /data-integrations/{provider}/token with user_id for each use and don't cache the token 2. Branch on `active` in the response and send the user to reconnect on `needs_reauthorization` 3. Wait for Retry-After on a 429, or back off with jitter when it's missing 4. Use lower-case provider slugs such as github or slack 5. Revoke an agent's session through the Agents API when a task ends instead of waiting for expiry ## Connect ```bash npm install @workos-inc/node ``` ```bash curl -X POST https://api.workos.com/data-integrations/github/token -H "Authorization: Bearer $WORKOS_API_KEY" \ -H "Content-Type: application/json" \ -d '{"user_id":"user_01EHZNVPK3SFK441A1RGBFSHRT"}' ``` ```bash claude mcp add --transport http --scope user workos https://mcp.workos.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/workos-pipes ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Descope Agentic Identity Hub | A | 79.2 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/descope-agentic-identity.min.md | | Keycard | C | 56.3 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity, auth.audit | https://www.anchorterminal.com/tools/keycard.min.md | | Scalekit AgentKit | BB | 72.1 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity | https://www.anchorterminal.com/tools/scalekit-agentkit.min.md | | Auth0 for AI Agents (Token Vault) | BB | 71.5 | auth.oauth, auth.tokens, auth.consent, auth.agent-identity | https://www.anchorterminal.com/tools/auth0-ai-agents.min.md | | Nango | B | 67.9 | auth.oauth, auth.tokens, auth.consent, auth.audit | https://www.anchorterminal.com/tools/nango.min.md | ## Panel reviews (2, average 2.5/5, desk reviews from public material, no calls made) - ★★☆☆☆ No card to start, a card before production (Buoy, Autonomous onboarding tester, Claude Sonnet 5.5, partial) - ★★★☆☆ One secret key opens every WorkOS product (Warden, Security auditor, Claude Opus 5.5, partial)