Arc0 vs WorkOS Pipes.
Considering Arc0 as a WorkOS Pipes alternative? A like-for-like read on token handling, consent screens, and pricing, including where Pipes and the wider WorkOS suite are still the better choice.
Arc0 and WorkOS Pipes, line by line.
| Item | ARC0 | WORKOS PIPES |
|---|---|---|
| Catalog | 1,500+ apps; vendors' official MCP servers can sit behind Arc0 auth | 300+ integrations, with support for adding a custom OAuth or API-key provider |
| Entry pricing | Build plan free for up to 100 active users in production; Launch is $99/mo including 1,000 active users | No Pipes-specific price is published; workos.com/pricing and workos.com/pricing.md price AuthKit, SSO, Directory Sync, Audit Logs, and Radar but list no Pipes line item |
| Token export | Tokens can be exported at any time by API; tokens from the customer's own OAuth apps keep working after export | Access tokens can be fetched from your backend via the Pipes API for direct use; connections made through Pipes' 'Relay' mode proxy the call instead, so that token never leaves WorkOS |
| Your users' consent screen | Arc0 Connect carries the customer's logo on every plan; paid plans can run it on the customer's own domain with the customer's own OAuth apps | The Pipes widget is a React component styled inside your app, but each provider still requires you to register and configure your own OAuth client with that provider; no shared or WorkOS-branded consent screen is documented |
| Deployment / self-host | Hosted; one Arc0 MCP endpoint, SDK, or REST plus a proxy | Pipes itself is hosted by WorkOS, but Pipes MCP ships as a deployable, MIT-licensed sample server you run in your own infrastructure to expose provider actions as agent tools |
| Focus / ownership | Independent, focused only on agent connectivity; operated by Exa Labs LLC | One product inside the broader WorkOS enterprise identity platform, alongside AuthKit, SSO, Directory Sync, Audit Logs, and Radar |
Where WorkOS Pipes is the better choice.
Pipes ships alongside AuthKit, SSO, Directory Sync, Audit Logs, and Radar on one platform, so a team already buying WorkOS for login and SSO adds account connections without a new vendor or contract.
WorkOS states SOC 2, HIPAA, and GDPR compliance across its platform. Arc0 holds SOC 2 Type II and signs a DPA, but it does not claim HIPAA coverage.
WorkOS has sold SSO and directory sync to enterprise buyers for years before adding Pipes, giving it procurement relationships and production track record a newer, connectivity-only vendor has yet to build.
What Arc0 does differently.
Arc0 lists 1,500+ apps. WorkOS Pipes lists 300+ integrations, plus a path to add a custom OAuth or API-key provider.
Arc0 publishes per-active-user prices with a rate locked for 12 months. WorkOS has not published a Pipes-specific price; its public pricing page covers AuthKit, SSO, Directory Sync, Audit Logs, and Radar, but not Pipes.
Arc0 Connect carries the customer's logo by default and can run on the customer's own domain with the customer's own OAuth apps on paid plans. Pipes embeds a styleable widget in your app, but you still register your own OAuth client with each provider.
Pipes appeared in WorkOS's changelog in December 2025 and was covered publicly in January 2026, so it has under a year of production use as of this writing.
Arc0 is a single hosted MCP endpoint, SDK, or REST proxy. Getting agent-facing tool access from Pipes means deploying and operating your own MCP server built from WorkOS's sample code.
Free migration from WorkOS Pipes.
An engineer moves you over at no charge, on any plan. You keep shipping while we do the work, and nothing changes for your users until you say so.
- 01We map itEvery app, action and auth config your agent uses in WorkOS Pipes, matched to Arc0.
- 02We set it upYour OAuth apps registered, Arc0 Connect in your brand, and your first policies written with you.
- 03We move your usersTokens imported wherever WorkOS Pipes lets you export them, and reconnects staged in-product where it doesn’t.
What moving from WorkOS Pipes looks like.
Moving from Pipes means replacing a widget embedded in your app, and if you run Pipes MCP, a self-hosted server, with Arc0's hosted consent flow and MCP endpoint.
Connections
WorkOS's docs describe fetching access tokens from your backend through the Pipes API, so directly-issued tokens are not locked in. Tokens handled through Pipes' Relay mode never leave WorkOS, so there is no raw token to export for those connections; those users would reconnect once through Arc0 Connect.
Your agent
Agents built against a self-hosted Pipes MCP server point at Arc0's single hosted MCP endpoint instead, and Arc0's per-action read/write/destructive policies (allow, ask, deny) replace Pipes MCP's session-scoped, human-approved grants.
Questions, answered.
Is Arc0 a good WorkOS Pipes alternative?
Yes, if you want a dedicated, published-pricing connectivity layer with a larger app catalog and don't need the rest of the WorkOS identity suite. Stick with Pipes if you're already buying WorkOS for SSO and directory sync and want account connections in the same platform and contract.
Does WorkOS Pipes give agents more than OAuth tokens?
Yes. Beyond returning access tokens, Pipes offers a Relay mode that proxies API calls so the token never reaches your environment, and Pipes MCP (a self-hosted, MIT-licensed sample server) exposes connected providers as discoverable agent tools with session-scoped, human-approved authorization.
How many integrations does WorkOS Pipes support?
WorkOS lists 300+ integrations on workos.com/pipes, plus support for adding a custom OAuth or API-key provider when yours isn't listed.
What does WorkOS Pipes cost?
WorkOS had not published a Pipes-specific price as of September 2026. Its public pricing page prices AuthKit by monthly active users and SSO/Directory Sync per connection, but lists no separate rate for Pipes.
Moving from WorkOS Pipes? We’ll move you.
Tell us where your connections live today and what your agent does. An engineer plans and runs the move with you, free, including how to keep reconnects to a minimum.