Cerbos vs Hanko
Hanko scores higher on the AgentReady, 48/100 against 46/100. They differ on 9 of the 41 signals. Which ones decides whether an agent can adopt them without a person watching.
What each one is
Cerbos. Authorization management platform for applications, APIs, AI agents, MCP servers, services, and workloads.
Hanko. Hanko is an open-source authentication and user management platform for modern web and mobile apps.
Where Cerbos is ahead
Cerbos passes clear product positioning and mcp discoverable, and Hanko does not. That is discover, whether an agent can find the product at all without being told it exists.
It also holds adopt: mcp integration available. Hanko misses it.
Where Hanko is ahead
Hanko passes clear canonical domain, and Cerbos does not. That is discover, whether an agent can find the product at all without being told it exists.
It also holds understand: pricing understandable. Cerbos misses it.
And on adopt, self-service signup, free trial or free allowance and fast time to first request. Cerbos misses those.
Finally, on operate, structured, predictable output. Cerbos misses it.
What neither does
Both fail structured api reference, openapi / spec quality, authentication documented, request examples provided, response examples provided, errors and status codes documented, limits / constraints documented, no mandatory sales call, agent-compatible signup flow, programmatic credential creation, cli available, machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable, agent compatibility verified. If your agent needs any of those, you will be building it yourself either way.
Score, pillar by pillar
The AgentReady splits into four pillars, scored separately, because a product can be easy to find and still impossible to adopt.
Discover is whether an agent can find the product at all without being told it exists. Cerbos leads 93 to 73. Cerbos misses clear canonical domain; Hanko misses clear product positioning, mcp discoverable.
Understand. Hanko leads 23 to 15. Cerbos misses structured api reference, openapi / spec quality, authentication documented, pricing understandable, request examples provided, response examples provided, errors and status codes documented, limits / constraints documented; Hanko misses structured api reference, openapi / spec quality, authentication documented, request examples provided, response examples provided, errors and status codes documented, limits / constraints documented.
Adopt. Hanko leads 50 to 40. Cerbos misses self-service signup, no mandatory sales call, agent-compatible signup flow, programmatic credential creation, free trial or free allowance, fast time to first request, cli available; Hanko misses no mandatory sales call, agent-compatible signup flow, programmatic credential creation, cli available, mcp integration available.
Operate. Hanko leads 47 to 35. Cerbos misses structured, predictable output, machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable, agent compatibility verified; Hanko misses machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable, agent compatibility verified.
Pricing
Cerbos does not publish a machine-readable starting price. Hanko starts at $29/month and has a free tier.
| Cerbos plans | Hanko plans |
|---|---|
| - | Starter Free |
| - | Pro $29/month + $0.01 per monthly active user > 10,000 |
Signal by signal
| Signal | Cerbos | Hanko |
|---|---|---|
| AgentReady | 46 | 48 |
| Discovery | 93 | 73 |
| Understanding | 15 | 23 |
| Adoption | 40 | 50 |
| Operability | 35 | 47 |
| Public API | Yes | Yes |
| MCP server | Yes | No |
| OpenAPI spec | Unknown | Unknown |
| CLI | Unknown | Unknown |
| llms.txt | Yes | Yes |
| Self-serve signup | Unknown | Yes |
| Free tier | Unknown | Yes |
Which to pick
Hanko clears more of the signals an agent needs, so it is the safer default for unattended use. Full profiles: Cerbos and Hanko. Alternatives to each: Cerbos, Hanko.
An agent can fetch this as data: POST /v1/compare {"slugs": ["cerbos", "hanko"]}