SCALEKIT vs. the alternatives

Comparing Agent auth &
tool-calling platforms

Here's what actually separates one platform from another:
01
Catalog & extensibility

Can it reach the tools you actually need, and let you add the ones it doesn't have?

02
Auth & governance

Who owns the credentials, and what stops an agent from overstepping?

03
Choose the right infrastructure

Cloud, VPC, self-hosted, air-gapped — does it run where your data has to live?

The comparison

See where each platform actually differs.

Six platforms. Sixteen criteria.
How to read this
Leading
Strong
Basic
Not offered
Capability
Catalog & extensibility
Managed Connectors
Pre-built catalog size
350+ connectors
1,000+,largest catalog
~80 toolkits
900+ APIs
Uncounted, likely modest
~130, smallest catalog
Enterprise Connectors
RSA, service accounts,tenant Azure AD, DWD
RSA, service accounts, DWD, Azure AD
Service accounts only
OAuth only, no tenant scoping
Service accounts + DWD
API keys only
None found
Build-Your-Own
Custom connectors & tools
Inherits vault + audit; scoping is manual
Yes, marked experimental
Open-source, most mature
Open-source, core to product
AI-assisted builder
Proxy API + OpenAPI import
Tool Bundles
Scoped, Virtual-MCP-style
Persistent config + session-token identity
Persistent config (allowed_tools) + per-user URLs
MCP Gateways, mature
No bundling concept
Tool Packs
No bundling primitive
Triggers / Webhook Events
Agent reacts to external events
In beta
Real-time for some, polling for others
Not offered
Inbound webhooks trigger agent runs
Not offered, pull-based only
Mature, 130+ pre-built triggers
Auth & authorization
Vault Isolation
One key per secret, or
one key for many?
Unique key per credential
One key covers many credentials
One key covers many credentials
Centrally managed, shared keys
Isolated per user, shared keys
Isolated per tenant, shared keys
OAuth Ownership
Who owns the app/client ID
Default, yours from day one
Opt-in, shared by default
Yes, standard
Opt-in, recommended
Unclear, conflicting docs
No, one shared app for all
Call-Time Verification
Who owns the app/client ID
Every call, not just connect
Connect-time only at base tier
Every call
No re-check documented
Every call
Every call
Trust & governance
White-Label UX
Who owns the app/client ID
Branding + custom domain
Brandable consent flow
Branded, implied
No branding on hosted widget
Wrapper only, consent isn't
Fully whitelabeled, most polished
Audit & SIEM
Logging + external streaming
SIEM streaming at Enterprise
None in core product
OTel export to SIEM
SIEM export is a paid add-on
Webhook + SIEM streaming
Audit yes, SIEM not yet
ISO 27001
Fewer clear this one
Certified
Certified
Not yet, in progress
Not claimed anywhere
Certified
Inconsistent on their own site
HIPAA & GDPR
Healthcare & EU privacy coverage
Both covered
Both covered, HIPAA BAA is paid
Neither yet, in progress
Both covered
Both covered
Both covered
Governance Depth
RBAC, DLP, approvals
Per-tool scoping + role ceiling
None in core product
RBAC new in 2026, growing
Basic, API keys bypass RBAC
RBAC + policy-based DLP
Basic, internal users only
Deployment
VPC
Runs inside your own cloud account
Yes, Enterprise
Reads as VPC-style
Yes, marketplace + Helm
Yes, enterprise self-host
Yes, VPC peering
Yes, network-segmented
Self-Hosted / On-Premise
Runs on infrastructure you control
Yes, Enterprise, explicit on-prem
Self-hosted functionally, on-prem unclear
Yes via Helm, full on-prem unconfirmed
Yes, two self-host tiers
No, denied in their own FAQ
Yes, explicit
Air-Gapped
Fully offline operation
Yes, explicit
Likely no
Claimed, not corroborated
Likely no
Likely no
Close, not named as such

Go deeper

Full head-to-head breakdowns and independent roundups for each platform.

See the difference in your own stack

Ship agent tool-calling with per-tenant authorization built in from day one.