The Identity & Access Management use case on apis.io covers the job every integration starts with: authenticate the user or the machine, then control what it can reach. SSO and MFA, OAuth and OIDC flows, provisioning and deprovisioning, roles, entitlements, access certification. The page lists 27 providers and 139 APIs, with four in the exemplar band.
The first half of that list is the job done well. The second half is the reason this post exists.
The providers that do the job
| Step | Providers on the page (Kin Score, Agent Readiness) |
|---|---|
| Sign-in, SSO, OIDC | Microsoft Entra ID (82.7, 56.3), Auth0 (70.0, 37.9), Descope (56.3, 27.6), Zitadel (50.5, 21.0), Casdoor (23.8, 23.2) |
| Directory and provisioning | Microsoft Active Directory (61.4, 27.3), Amazon Directory Service (51.4, 21.5) |
| Certificates for machine identity | Amazon Private CA (55.6, 29.2) |
| Fine-grained authorization | Cerbos (44.1, 23.4) |
| Access review and data access | Varonis (39.3, 30.6), Productiv (37.7, 24.8) |
That is a real build path. Microsoft Entra ID is the strongest record on the page at 82.7, exemplar, and agent-ready at 56.3. Descope, which positions itself as customer and agentic identity, and Zitadel, the open-source identity platform, cover sign-in without Microsoft. Cerbos externalizes the permission decision from application code, which is the layer agents will lean on hardest.
Note the gap between the two columns. Of the eleven in that table, only Entra ID clears 50 on Agent Readiness. The category that is supposed to hand agents their credentials mostly scores agent-aware.
The providers that should not be here
The page also lists Novu, a notification engine, as one of its four exemplars. It lists Axios, the JavaScript HTTP client; Varnish, the HTTP cache; Apache TinkerPop, the graph computing framework; and payment processors Paysafe and Cielo, whose “authentication” is 3D Secure card authentication. Those are real providers with real APIs, and not one of them is an identity and access management product.
The cause is in the page’s own record. Membership is built from 24 raw terms, including “3D Secure Authentication”, “Face Authentication” and “Authentication Offloading”. Any surface that authenticates something gets swept in.
The inverse failure is worse. Kinde scores 86.1, exemplar, higher than anything on this page, and bundles authentication, roles, permissions, scopes and B2B organizations. It is not listed. Neither are WorkOS, Okta, Stytch, Frontegg, SailPoint or FusionAuth, all of which the catalog profiles and scores.
What would move the page
This one is ours to fix, not the providers’. The use-case matcher needs to weight what a provider sells over what any one of its operations does, so a card processor’s 3DS flow stops counting as identity. Then the missing identity platforms come in, the page’s median score should rise, and the build path above gets the vendors a buyer would actually shortlist.
Until then, read the top of the table and trust it. See the live page at apis.io/use-cases/identity-access-management/.