# Wacht > Wacht is the open-source stack for building AI-native apps — identity & auth, B2B multitenancy, machine auth, webhooks, notifications, and an AI agent runtime, as one product on one shared user model. ## Product - [Home](/) - [Pricing](/pricing) - [Design partners](/partners) ## Compare - [Wacht vs Clerk](/compare/clerk) - [Wacht vs Auth0](/compare/auth0) - [Wacht vs WorkOS](/compare/workos) - [Wacht vs Svix](/compare/svix) - [Wacht vs Novu](/compare/novu) ## Documentation - [Docs home](https://wacht.dev/docs) - [Next.js SDK quickstart](https://wacht.dev/docs/sdks/nextjs/quickstart) - [React Router SDK quickstart](https://wacht.dev/docs/sdks/react-router/quickstart) - [TanStack Router SDK quickstart](https://wacht.dev/docs/sdks/tanstack-router/quickstart) - [Backend (Node) SDK](https://wacht.dev/docs/sdks/node) - [Rust SDK](https://wacht.dev/docs/sdks/rust/getting-started) - [llms.txt (docs subdomain)](https://wacht.dev/docs/llms.txt) ## Policy - [Privacy](/privacy) - [Terms](/terms) - [Refund Policy](/refund) ## Blog - [Full corpus (all posts, markdown)](/llms-full.txt) - [What's Actually Changing in AI Agents in 2026](/md/blog/ai-agent-trends-2026) - [AI Agents Are Non-Human Identities — Treat Them Like It](/md/blog/ai-agents-are-non-human-identities) - [Best LLMs for AI Agents in 2026: Benchmarks vs. Reality](/md/blog/best-llm-for-ai-agents-2026) - [How to Give an AI Agent Access to an API, Safely](/md/blog/give-ai-agent-api-access-safely) - [Just-in-Time Access for AI Agents: Zero Standing Privilege](/md/blog/just-in-time-access-for-ai-agents) - [MCP Finally Has Real Auth: The OAuth 2.1 Spec, Explained](/md/blog/mcp-oauth-authorization-spec) - [OAuth vs. API Keys for AI Agents: Which to Use](/md/blog/oauth-vs-api-keys-for-ai-agents) - [Secrets Management for AI Agents: Stop Leaking Tokens](/md/blog/secrets-management-for-ai-agents) - [Self-Hosting LLMs for AI Agents: When It's Worth It](/md/blog/self-hosting-llms-for-agents) - [Why Your AI Agent Needs an Identity, Not an API Key](/md/blog/why-ai-agents-need-identity) - [Add Auth to Next.js in 5 Minutes with Wacht](/md/blog/add-authentication-nextjs) - [B2B SAML SSO for Every Customer: A Setup Guide](/md/blog/b2b-saml-sso-setup) - [Issue Scoped API Keys to Customers — Without a Control Plane](/md/blog/scoped-api-keys-for-customers) - [AI Agent Tool Access and Human Approvals, Done Right](/md/blog/ai-agent-tool-access-approvals) - [Webhook HMAC Verification: Signatures, Retries, and Replay](/md/blog/verify-webhooks-hmac-retries) - [The Case Against Six Vendors for One Product](/md/blog/against-six-vendors-one-product) - [Auth for AI Agents: Why Per-Action Authorization Now Matters](/md/blog/auth-was-easy-agents-changed-it) - [Inside the Wacht Agent Sandbox: Firecracker and BYOK](/md/blog/inside-wacht-agent-sandbox) - [One User Model, Six Systems: A Unified Identity Architecture](/md/blog/one-user-model-six-systems) - [Webhook Delivery: Signing, Retries, and Replay Done Right](/md/blog/signed-replayable-webhook-delivery) - [MCP Explained: Auth and Identity for Model Context Protocol](/md/blog/mcp-explained-for-auth) - [Securing MCP Servers: Identity and Scopes for AI Agents](/md/blog/securing-mcp-servers) - [AI Agent Memory: Why Persistence Needs Identity](/md/blog/agent-memory-needs-identity)