AuthSec
SPIFFE/SPIRE certificate-based workload identity — Scalekit has none
XAA/ID-JAG ships as a real, production grant type; Scalekit's cross-app agent auth is still a blog post, not a product
M2M supports private_key_jwt in addition to client_credentials; Scalekit documents client_credentials only
RBAC includes access-approval and delegation workflows; Scalekit's RBAC is app-enforced token claims with no policy engine