ReviewUpdated 2026-09-10

Arcade Review 2026: Agent Authorization, Tools, and Pricing

A research-based Arcade review covering features, pricing, privacy, limitations, alternatives, and a practical buyer test.

By DiscoverAI Editorial TeamReviewed by DiscoverAI Editorial Review2 min readWork & OperationsHow we evaluate
Paper-cut agent passing through consent and policy gates before using connected business tools
Original DiscoverAI editorial illustration. Agent authorization is useful when every credential, scope, confirmation, action, and revocation remains visible.

Bottom line

Arcade is an actions runtime for AI agents that manages OAuth, user tokens, tool execution, and policy enforcement across thousands of agent-oriented tools.

Editorial accountability

Who checked this guide

Meet the editorial team →
Evaluation type
Hands-on evaluation
Last materially checked
Evidence
4 listed sources

Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.

Editorial freshness

Checked this month

Pricing and material product claims were checked September 10, 2026.

Review evidence

What this guidance is based on

Review type
Research-based product assessment
Material review date
September 10, 2026
Evidence
Current first-party product, pricing, documentation, and policy material
Buyer test
Controlled quality, cost, permissions, privacy, reliability, and failure-path evaluation

Important limits

  • DiscoverAI did not complete the proposed long-term paid deployment for this review.
  • Features, prices, limits, security controls, and provider data paths can change; verify the linked first-party pages before purchase.
In this guide
  1. Short answer
  2. Best for
  3. Look elsewhere if
  4. What Arcade verifiably does
  5. Important limitations
  6. Arcade pricing
  7. A fair buyer test
  8. Final verdict

Short answer

Arcade is worth testing when an agent must act in a user's Gmail, Drive, Slack, GitHub, or another authenticated service without turning OAuth and token custody into bespoke application code. Its strongest value is the authorization boundary, not the size of its tool catalog. Teams still need least-privilege scopes, per-action confirmation, idempotency, audit review, and a reliable way to revoke access.

Best for

  • Agents acting in user-owned SaaS accounts
  • Teams centralizing OAuth and tool governance
  • Developers shipping MCP-based actions

Look elsewhere if

  • High-risk writes without confirmation
  • Workloads that cannot use third-party token custody
  • Simple agents with one stable internal API

What Arcade verifiably does

First-party material describes managed OAuth and token storage, runtime authorization, more than 7,500 tools across 81 MCP servers, custom tools and MCP servers, policy enforcement, registries, version control, OpenTelemetry logs, and integrations with common agent frameworks. Enterprise options include VPC and air-gapped deployment, SSO, RBAC, audit logs, and a private registry.

Important limitations

An agent action can send messages, alter records, or expose data even when authentication works perfectly. Broad OAuth scopes, stale consent, prompt injection, repeated retries, and confusing tool descriptions remain application risks. Authentication events and calls are separate meters, while downstream APIs may add quotas and fees. The vendor becomes a sensitive credential and execution dependency.

Arcade pricing

Arcade lists Free at $0 with 2,000 monthly authentication events and 2,000 tool calls. Team costs $25 per month plus $0.10 per authentication event and $0.01 per tool call. Enterprise uses annual bundles and custom deployment, governance, and support terms. Model, target-service, and surrounding infrastructure costs remain separate. Reviewed September 10, 2026.

A fair buyer test

Build 30 read and write tasks across three approved services. Seed expired consent, revoked tokens, duplicate requests, prompt injection, ambiguous identities, rate limits, and a partial outage. Measure correct authorization, scope minimization, confirmation quality, duplicate writes, audit completeness, revocation time, p95 latency, and total cost per accepted action. Require direct verification of every consequential write.

Final verdict

Arcade earns a pilot for teams whose agents have outgrown hand-built OAuth and tool wrappers. Start with reversible actions, narrow scopes, explicit confirmations, short-lived sessions, and audited revocation. Do not mistake a large catalog for permission to expose every tool to every agent.

This is a research-based product assessment, not a claim of hands-on long-term testing. Product, pricing, privacy, security, and usage claims were checked against the first-party sources below on September 10, 2026. Verify current terms and run the proposed test with approved data before adoption.

Reusable trial worksheet

Test Arcade before you commit

Turn this review’s buyer test into evidence. Your entries autosave only in this browser and are never added to shared shortlist links.

0/7 checks complete
  1. Confirm the tool meets every must-have workflow and stakeholder requirement.

    Review starting point: Agents acting in user-owned SaaS accounts; Teams centralizing OAuth and tool governance; Developers shipping MCP-based actions

  2. Run the same representative work you would use in production; do not score a polished demo.

    Review starting point: Build 30 read and write tasks across three approved services. Seed expired consent, revoked tokens, duplicate requests, prompt injection, ambiguous identities, rate limits, and a partial outage. Measure correct authorization, scope minimization, confirmation quality, duplicate writes, audit completeness, revocation time, p95 latency, and total cost per accepted action. Require direct verification of every consequential write.

  3. Calculate the effective cost per accepted result, including usage, review, corrections, and required add-ons.

    Review starting point: Arcade lists Free at $0 with 2,000 monthly authentication events and 2,000 tool calls. Team costs $25 per month plus $0.10 per authentication event and $0.01 per tool call. Enterprise uses annual bundles and custom deployment, governance, and support terms. Model, target-service, and surrounding infrastructure costs remain separate. Reviewed September 10,…

  4. Define an acceptance threshold, test known answers and edge cases, and record every correction.

    Review starting point: Editorial quality signals: features 4.3/5; AI quality 4.1/5. Validate these signals in your own work.

  5. Verify what data enters the product, who can access it, how long it is retained, and whether it trains models.

    Review starting point: Use approved low-risk data first. Check roles, consent, deletion, subprocessors, model-training settings, and the contract—not only the marketing page.

  6. Test the real handoffs, permissions, failure states, and export path your team depends on.

    Review starting point: OpenAI Agents, LangChain, CrewAI, Vercel AI SDK, Mastra, MCP

  7. Record training, governance, reliability, accessibility, ownership, and change-management risks before rollout.

    Review starting point: Central credential and action dependency; Two usage meters plus downstream costs; Application-level safety remains the buyer's job

Open Decision Workspace

Loading saved worksheet… · private to this device or your optional account

Community evidence

How verified users put Arcade to work

Structured, editor-moderated experience—not star ratings. This complements our independent review and never changes its score.

No approved community evidence yet. Be the first verified user to contribute.

Sources and verification

Product details and claims were checked against the following primary sources.

Frequently asked questions

What is Arcade for AI agents?

Arcade is an authorization and actions runtime that lets agents connect to user accounts, manage OAuth tokens, execute tools, and apply governance policies.

How much does Arcade cost?

Arcade lists a free tier, Team at $25 per month plus authentication-event and tool-call usage, and custom Enterprise terms.

Does Arcade support MCP?

Yes. Arcade provides hosted MCP servers, supports custom MCP tools, and connects to MCP clients and common agent frameworks.

Does Arcade make agent actions safe automatically?

No. Teams still need narrow scopes, confirmation for consequential writes, prompt-injection defenses, idempotency, monitoring, and revocation tests.

Found this useful?

Get the next one in your inbox.

One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.

Free · one email a week · unsubscribe any time

Recommended tool

Use Arcade if this workflow fits your team

Authorization and execution in one runtime

Tools mentioned in this article

Arcade

Give AI agents governed access to user-authorized actions across business software

4.1

Arcade is an actions runtime for AI agents that manages OAuth, user tokens, tool execution, and policy enforcement across thousands of agent-oriented tools.

FreemiumAutomationCode

Composio

Authentication, tools, triggers, and execution infrastructure for action-taking agents

4.0

Composio gives agents authenticated access to more than a thousand toolkits, but token custody, action scope, trigger volume, third-party data paths, and approval design determine whether convenience becomes risk.

FreemiumAutomationCode

Klavis AI

Connect AI agents to hosted MCP servers, OAuth-enabled tools, and progressive tool discovery

4.1

Klavis AI packages hosted and open-source MCP integrations plus Strata progressive tool discovery, but credential scope, per-user isolation, write approvals, and nontransparent plan pricing require a careful pilot.

FreemiumCodeAutomation

Read next

More on Work & Operations