Kinde scores 87.5, exemplar band. It is an Australian identity and customer-auth platform that bundles authentication, authorization, B2B organizations, billing and feature flags, and it publishes two OpenAPI contracts, the Management API and the Account API. The catalog splits those into 31 API pages, 30 of them contracts, and 90% of those contracts are callable.
The most interesting sentence in the whole record is not a number. It is a design decision.
The MCP server that cannot destroy anything
The Kinde MCP Server is tenant-scoped, one endpoint per Kinde business at {subdomain}.kinde.com/mcp, authenticated with an Environment API key. It publishes 22 tools across users, organizations, roles, permissions and configuration. Kinde grants it read and create scopes only. There are no update: or delete: scopes available to it at all, and Kinde says why in plain language: AI clients can misinterpret requests or hallucinate.
That is the most honest agent-safety posture I have seen from an identity vendor. An agent can look things up and provision new records. It cannot quietly rewrite a role or remove a user. The tool crosswalk binds all 22 tools one-to-one to Management API operations, and leaves 157 REST operations with no tool. That gap is the policy, not a backlog.
Where the score comes from
| Facet | Score |
|---|---|
| Access clarity | 90.3 |
| Operational transparency | 92.1 |
| Developer ergonomics | 91.1 |
| Contract quality | 68.2 |
| Discoverability | 63.3 |
| Contract governance | 45.5 |
The operational and ergonomic facets are near the ceiling: status page with RSS and Atom, changelog, roadmap, SDKs across the major languages, a trust center listing SOC 2, ISO 27001, HIPAA and GDPR. Contract governance at 45.5 is the soft spot.
Fairness requires one disclosure. Kinde’s agentic access profile (179 operations, 111 acting, 13 human-in-the-loop) and its agent skills are derived by us, not published by Kinde. The coverage block puts at least 12.0 of the 85.8 catalog points earned on first-party artifacts. The MCP server itself is first-party.
The identity layer is dark
Agent Readiness is 48.1, agent-ready, and the record says it was gated down from agent-native. Error semantics are verified, idempotency and rate limits are documented, and there is a well-known catalog. What is unlit is the part an identity company should own: delegated identity, consent identity, protected resource metadata and dynamic client registration. None of the four.
The scopes artifact reads “OAuth 2.0 · no documented scopes”, while Kinde’s own docs carry an operation-and-scope table for the MCP server. Getting that into a machine-readable scopes file is partly our work and partly theirs. And the home page registers as silent on AI language, despite Kinde selling MCP server generation over customers’ OpenAPI, launched in beta in July 2026.
Takeaway
Kinde built the restraint into its MCP server that most vendors only write blog posts about. What moves the number now is contract governance, and serving protected resource metadata and delegated identity on the surface agents actually hit. The identity vendor’s identity layer should be its brightest.
See the full profile at apis.io/providers/kinde/.