Cerbos vs Ory
Ory scores higher on the AgentReady, 55/100 against 46/100. They differ on 5 of the 41 signals. Which ones decides whether an agent can adopt them without a person watching.
What each one is
Cerbos. Authorization management platform for applications, APIs, AI agents, MCP servers, services, and workloads.
Ory. Ory provides secure, friction-free identity and access management for customers, partners, machines, and agents - with seamless access, granular permissions, and real-time protection.
Where Cerbos is ahead
Cerbos passes llms-full.txt / full agent docs, and Ory does not. That is discover, whether an agent can find the product at all without being told it exists.
Where Ory is ahead
Ory passes clear canonical domain, and Cerbos does not. That is discover, whether an agent can find the product at all without being told it exists.
It also holds adopt: no mandatory sales call and cli available. Cerbos misses those.
And on operate, agent compatibility verified. Cerbos misses it.
What neither does
Both fail structured api reference, openapi / spec quality, authentication documented, pricing understandable, request examples provided, response examples provided, errors and status codes documented, limits / constraints documented, self-service signup, agent-compatible signup flow, programmatic credential creation, free trial or free allowance, fast time to first request, structured, predictable output, machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable. If your agent needs any of those, you will be building it yourself either way.
Score, pillar by pillar
The AgentReady splits into four pillars, scored separately, because a product can be easy to find and still impossible to adopt.
Discover. Both sit at 93/100 here. Cerbos misses clear canonical domain; Ory misses llms-full.txt / full agent docs.
Understand. Both sit at 15/100 here. Cerbos misses structured api reference, openapi / spec quality, authentication documented, pricing understandable, request examples provided, response examples provided, errors and status codes documented, limits / constraints documented; Ory misses structured api reference, openapi / spec quality, authentication documented, pricing understandable, request examples provided, response examples provided, errors and status codes documented, limits / constraints documented.
Adopt. Ory leads 57 to 40. Cerbos misses self-service signup, no mandatory sales call, agent-compatible signup flow, programmatic credential creation, free trial or free allowance, fast time to first request, cli available; Ory misses self-service signup, agent-compatible signup flow, programmatic credential creation, free trial or free allowance, fast time to first request.
Operate is whether an agent can run against it in production and recover when a call fails. Ory leads 53 to 35. Cerbos misses structured, predictable output, machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable, agent compatibility verified; Ory misses structured, predictable output, machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable.
Pricing
Cerbos does not publish a machine-readable starting price. Ory does not publish one.
Signal by signal
| Signal | Cerbos | Ory |
|---|---|---|
| AgentReady | 46 | 55 |
| Discovery | 93 | 93 |
| Understanding | 15 | 15 |
| Adoption | 40 | 57 |
| Operability | 35 | 53 |
| Public API | Yes | Yes |
| MCP server | Yes | Yes |
| OpenAPI spec | Unknown | Unknown |
| CLI | Unknown | Yes |
| llms.txt | Yes | Yes |
| Self-serve signup | Unknown | Unknown |
| Free tier | Unknown | Unknown |
Which to pick
Ory clears more of the signals an agent needs, so it is the safer default for unattended use. Full profiles: Cerbos and Ory. Alternatives to each: Cerbos, Ory.
An agent can fetch this as data: POST /v1/compare {"slugs": ["cerbos", "ory"]}