Aembit is a workload identity and access management platform that manages how workloads, services, and AI agents authenticate and access downstream APIs and services — without static credentials.
Directory
Identity, access & authentication tools
Compare IAM, SSO, MFA, CIAM, IGA, PAM, SCIM, and AI agent identity vendors. Filter by company size, deployment model, open source status, pricing, and integrations.
11 vendors
Akeyless is an established identity security platform delivering secrets management, certificate lifecycle management, encryption/KMS, and secure remote access from a unified SaaS, using patented Distributed Fragments Cryptography (DFC) instead of a self-managed vault. In 2025–2026 it extended the platform to AI-agent identity with ephemeral, task-scoped access.
Astrix Security discovers and secures non-human identities, AI agents, and MCP servers, and provisions secure-by-design agents through its Agent Control Plane with short-lived credentials and just-in-time access. Following its acquisition by Cisco, its capabilities are being integrated into Cisco's identity and zero-trust portfolio.
Cerbos is an authorization management platform built around an open source policy decision point (PDP). It enforces fine-grained RBAC, ABAC, PBAC, and ReBAC policies for applications, APIs, workloads, and AI agents.
Clutch Security is a non-human identity (NHI) security platform that maps service accounts, keys, tokens, and AI agents to their origins via its Identity Lineage graph, then layers on lifecycle management, posture, and threat detection. It added an Agentic AI Governance module for discovering and setting guardrails around AI agents and their credential usage.
Defakto (formerly SPIRL, rebranded in 2026) is a non-human identity and access management platform built on the SPIFFE standard. It issues dynamic, cryptographically verifiable identities for services, workloads, CI/CD pipelines, and AI agents in place of static credentials and service accounts.
Entro Security is an agentic AI and non-human identity security platform that discovers, classifies, and governs NHIs and secrets across clouds, code, vaults, and collaboration tools, with behavioral threat detection via its NHIDR engine. SailPoint completed its acquisition of Entro in June 2026, making it the NHI and secrets layer of SailPoint's Agentic Fabric.
Keycard is an identity and access platform purpose-built for AI agents, founded by former Snyk and Auth0 leaders (including the creator of Passport.js). It verifies agent identity, mints short-lived task-scoped tokens in place of static API keys, and enforces runtime policy with auditable logs.
Natoma provides a governed way to connect AI agents and clients (such as Claude Code, ChatGPT, and Snowflake Cortex) to enterprise tools through a catalog of 100+ verified MCP servers, with identity-aware access policies, agent IAM, and audit trails. It began as a non-human identity management platform and has centered its product on secure agentic connectivity.
Oasis Security is a non-human identity management platform covering inventory, ownership, posture, lifecycle, and secret rotation for machine identities, with AI-SPM and intent-aware access controls for AI agents. In July 2026, data-security company Cyera agreed to acquire Oasis for approximately $1 billion, with closing expected later in the year.
Token Security is a machine-first identity security platform that discovers non-human identities and AI agents across cloud, SaaS, and on-prem environments, then manages their posture, lifecycle, and threats. In March 2026 it introduced Intent-Based AI Agent Security, which aligns agent permissions with their stated purpose.
Not sure what to pick?
Run the IAM Stack Finder for a guided shortlist tailored to your stack.
