Each publication is substitutable if it covers what the customer already knows. Each becomes irreplaceable only if it translates the adjacent layer the customer doesn't monitor.
TinyFish knows browser-agent infrastructure cold. It does not track what enterprise identity governance will demand of that infrastructure. Okta knows governance cold. It does not track what browser-agent tools actually do with credentials at the protocol level. The Anchor publications earn their keep only as bridges between these two layers. If they stay inside the customer's own domain, they lose to the customer's own content.
The Model Context Protocol is an open standard for connecting AI agents to external tools and data sources. TinyFish's agents use browser sessions that MCP-connected tools will eventually need to authorize; Okta's governance layer must control which agents get access through MCP connectors. The contested surface is MCP's authorization spec, which requires servers to validate that access tokens were issued specifically for them but leaves implementation to each server. A May 2026 study found that 96.6% of OAuth-enabled MCP servers had flaws in dynamic client registration, the mechanism that lets new applications register themselves with an authorization server on the fly. That gap between spec and practice is where both customers' information problems live.
TinyFish
The customer's information problem
TinyFish sells browser infrastructure for AI agents: APIs that let an agent open a web page, log in, navigate dynamic content, and extract structured data. The competitive field is crowded and moving fast. Browser Use has roughly 100k GitHub stars. Stagehand, built by Browserbase, has over 23k. Open-source alternatives ship new releases weekly.
TinyFish's strategic bet is that credential isolation will become the differentiator. Its Vault feature injects passwords at the browser level so the AI model never sees them. This matters because enterprise buyers will eventually ask a specific question: can I let an agent log into Salesforce on my behalf without giving the agent my password? TinyFish is building toward that buyer.
The company's own Vault post is unusually candid that Vault does not prevent post-login session misuse, data exfiltration, or session-cookie exposure. TinyFish knows where its product stops. What it may not know is what the enterprise governance layer above it will require. That governance layer, where companies like Okta control which agents can act on behalf of which humans, will set the architectural requirements TinyFish's infrastructure must satisfy. TinyFish's information problem is visibility into those requirements before they become table stakes.
What the publication is doing
The publication's configuration targets the space between browser-agent execution and the broader identity governance stack. Its theory of value: TinyFish needs intelligence connecting credential handling to MCP authorization, enterprise identity provider requirements, and where TinyFish's infrastructure fits in a buyer's security architecture.
This is the right bet if TinyFish's team lacks visibility into enterprise identity governance. It is the wrong bet if TinyFish's current buyers are developers, not CISOs, and the team doesn't yet care about the governance layer. The evidence is indirect, but TinyFish's Vault post suggests the company is already thinking about enterprise trust. A publication that feeds that thinking with intelligence from the governance layer above would land on receptive ground. Moderate confidence.
The replacement landscape
TinyFish's own blog. The strongest substitute and the hardest to beat. TinyFish published ten posts in twelve days in June 2026, including a WebVoyager benchmark that names competitors by score, separates infrastructure failures (blocks, CAPTCHAs, timeouts) from reasoning failures (extracting the wrong answer from the right page), and lists the benchmark's own limitations. Most vendor blogs are marketing dressed as analysis. TinyFish's blog is a build log with failure analysis. Any Anchor publication covering the same browser-agent layer will lose to this, because TinyFish knows its own product and competitive set better than any external source can. The overlap at the browser layer is total. But TinyFish's blog does not look upward at enterprise identity governance.
Browserbase and Stagehand documentation. Stagehand's June 2026 commits include WebMCP documentation and work on bearer authentication, the pattern where a client presents a token to prove its identity. Browserbase publishes authentication guides covering persistent contexts, stored cookies, and 2FA handling. This is the competitor-tracking substitute. The information is public and current. An Anchor publication adds value only if it synthesizes across competitors rather than reporting on them individually. Like TinyFish's own blog, none of this translates upward to governance.
Browser Use's repo and examples. Browser Use handles authentication by reusing existing Chrome profiles with saved logins rather than separating credential injection from model context. This architectural difference, preserving a logged-in session versus isolating the secret from the model entirely, defines a competitive boundary TinyFish could exploit. But the information is visible in the repo. No intermediary needed. Same limitation as above: nothing here connects to the governance layer.
MCP specification and security research. The May 2026 arXiv study tested 119 OAuth-enabled MCP servers and found every one had at least one authorization flaw, producing 325 total flaws and nine CVE IDs. The MCP authorization spec requires tokens scoped to the specific server they were issued for but leaves implementation to each server. This research defines the security environment TinyFish's agents will operate in. It is published in open-access papers and protocol docs. Whether TinyFish's team reads arXiv is an open question. Partial overlap, partial gap.
Enterprise identity governance intelligence. This is where the replacement landscape goes empty. No source in TinyFish's natural content ecosystem connects browser-level credential isolation to what enterprise identity providers are building for agent governance. Okta's Claude Enterprise announcement describes MCP connector authorization with group-based scoping and offboarding. An April 2026 paper on AI identity argues that current standards do not adequately govern nondeterministic, boundary-crossing agents. A May 2026 paper on authorization propagation identifies unsolved problems around transitive delegation in multi-agent systems. TinyFish's Vault post stops at the browser. Nobody is telling TinyFish what the governance layer expects, how it will evaluate credential-handling approaches, or what architectural choices today will make TinyFish compatible or incompatible with enterprise requirements tomorrow.
The verdict
Substitutable at the browser layer. Irreplaceable at the cross-layer bridge. High confidence on the first claim: TinyFish's own blog and public competitor repos cover the browser-agent space with a quality and currency Anchor cannot match. Moderate confidence on the second: the bridge value depends on an inference that TinyFish's team does not already monitor enterprise identity governance, which I cannot verify from public signals.
What determined this: whether the publication connects governance-layer developments (Okta-style agent identity announcements, MCP authorization security findings, academic research on agent delegation) to specific architectural decisions TinyFish faces about Vault's design, credential scoping, and session management. If it does that work, nothing else in TinyFish's information environment does.
What would move the verdict: if TinyFish starts publishing about enterprise governance on its own blog, the bridge value evaporates. As of June 22, 2026, it hasn't.
Okta
The customer's information problem
Okta is making AI agents the center of its growth narrative. Todd McKinnon told investors on May 28, 2026 that AI agents are "a new workforce" whose identities must be secured alongside humans, and that agent identity was the "#1 topic of interest" from customers. In a six-week span, Okta shipped integrations with Google Cloud, Anthropic's Claude Enterprise, and Amazon Bedrock AgentCore.
Okta has no awareness gap here. Okta is creating the narrative. Its information problem is credibility: convincing enterprise buyers that agent identity governance is a real, urgent problem rather than a vendor-manufactured anxiety. That requires evidence from outside Okta's own narrative. What does the agent infrastructure layer actually look like? How broken is authentication in practice? What are the real failure modes buyers should worry about? Okta's survey of 784 respondents frames the urgency, but survey data produced by the vendor selling the solution is positioning evidence, not independent validation.
What the publication is doing
The publication's configuration targets competitive and market intelligence about the AI agent identity space. This bet faces a structural problem: Okta's own content machine is producing positioning material at extraordinary velocity. Six AI-agent announcements in ten weeks. Earnings calls scripted around the narrative. A purpose-built survey.
Okta already dominates reporting on what's happening in agent identity. Anchor's opportunity, if one exists, lies in translating the messy technical reality beneath Okta's governance claims into intelligence Okta's product and sales teams can use. The publication earns its keep if it arms Okta's teams with grounded answers for the moment a buyer challenges the governance claim: does your agent authorization actually work at the protocol level? That is the decision point where external intelligence matters. If the publication isn't embedded in that moment, it's background reading at best.
The replacement landscape
Okta's own newsroom and earnings materials. The dominant substitute. At least six substantive AI-agent pieces between April and June 2026. The earnings transcript contains more strategic framing of agent identity than most analyst reports. This covers positioning, partnerships, and narrative comprehensively. What it cannot cover: the implementation reality beneath the positioning. Okta will not publish that its governance claims rest on an MCP authorization layer where independent research found pervasive flaws. Total coverage of positioning; nothing on technical-reality translation.
Analyst firms (Gartner, Forrester, KuppingerCole). A public summary of Gartner coverage shows Gartner recommending proportional governance based on agent autonomy levels: observe, advise, act with approval, full autonomy. Analyst frameworks validate market categories but are gated, quarterly, and abstract. They describe what governance should look like without evaluating whether current implementations achieve it. They overlap with Anchor on market framing but do not touch the technical-reality layer.
OWASP Non-Human Identities Top 10. The 2025 framework covers improper offboarding, secret leakage, overprivileged non-human identities (service accounts, API keys, and now AI agents that act on behalf of humans), and long-lived secrets. It anchors risk vocabulary that Okta's sales teams can reference. But it was written for traditional non-human identities, not AI agents with autonomous decision-making. It does not address agent delegation, MCP connector authorization, or the gap between governance claims and protocol reality. A useful reference point, but not a substitute for agent-specific intelligence.
Dark Reading and SC Media. My research did not surface qualifying articles from either outlet on AI agent identity or MCP security in the last 60 days. This absence is worth noting not as a research limitation but as a finding. Trade press has not yet built sustained coverage of this space. Okta's teams cannot passively absorb AI-agent identity intelligence from their normal reading. The information environment that would make an Anchor publication redundant does not exist yet. Low confidence that the absence is total; the search may have missed articles. But even sporadic coverage does not substitute for systematic monitoring.
Academic and security research. The arXiv MCP authentication study, authorization-propagation paper, and AI identity standards-gap research collectively describe a reality Okta's marketing does not acknowledge: MCP authorization is broadly broken in practice, multi-agent delegation creates unsolved authorization problems, and current standards do not adequately govern nondeterministic agents. This research is public but scattered across preprints. Okta's product engineers may read it. Okta's sales teams almost certainly do not. That translation gap is where Anchor could sit.
The verdict
Substitutable on positioning. Irreplaceable on implementation reality. High confidence on the first claim: Okta's own content ecosystem dominates the positioning layer, and analyst firms validate the category. No external publication will out-narrate Okta on Okta's own strategy.
Moderate confidence on the second. The irreplaceability opportunity is narrow but real, and two factors determined it. First, the trade press absence: Okta cannot outsource this intelligence to its normal information diet because that diet does not yet cover AI agent identity with any consistency. Second, the distance between Okta's governance claims and protocol reality: Okta's Claude Enterprise announcement describes MCP connector authorization with group-based scoping, while independent research says 96.6% of OAuth-enabled MCP servers have fundamental authorization flaws. That distance is where Anchor's value lives.
The product-configuration implication
TinyFish needs someone to translate the governance layer down. Okta needs someone to translate the infrastructure layer up. Both publications earn irreplaceability only by doing the bridging work that neither customer's own content ecosystem performs.
This points to a concrete configuration change: these two publications should be reading each other's domains. The TinyFish publication's research configuration should include Okta's newsroom and quarterly earnings transcripts as monitored sources, because those are the highest-signal indicators of what enterprise identity governance will demand of browser-agent infrastructure. The Okta publication should track GitHub commit activity on Stagehand, Browser Use, and TinyFish's own repo, plus MCP security research on arXiv, because those are the sources that reveal whether Okta's governance claims hold at the implementation layer.
A reusable test falls out of this analysis. Bridge dependency holds when four conditions are met:
- The customer operates in one layer.
- An adjacent layer's decisions materially affect the customer's product.
- The customer doesn't naturally monitor that adjacent layer.
- No existing source performs the translation.
All four hold for both TinyFish and Okta today. The founders can apply the same test to any customer where Anchor's publication covers a domain the customer already knows well. If all four conditions aren't met, the publication is competing on its customer's home turf.
The falsification condition: if either customer starts producing cross-layer content on its own blog, the bridge dependency model collapses for that customer. Monitor both blogs monthly.
- MCP authorization is broadly broken: A May 2026 measurement study tested 119 OAuth-enabled MCP servers and found 325 total flaws producing nine CVE IDs, with dynamic client registration failures in nearly all of them.
- Okta's agent-identity velocity is accelerating: Between May 14 and June 18, 2026, Okta announced agent-security integrations with Amazon Bedrock AgentCore, Google Cloud, and Anthropic's Claude Enterprise, a pace that tests whether monthly publication cadence can keep up.
- Multi-agent delegation remains unsolved: A May 2026 paper argues that authorization propagation across multi-agent systems creates transitive delegation and temporal validity problems that go beyond prompt injection and beyond what any single identity provider currently governs.
- TinyFish's blog cadence sets a high bar: TinyFish published ten posts in twelve days in June 2026, including benchmark methodology, failure taxonomies, and explicit product limitations, making it an unusually strong self-substitute that any Anchor publication must outflank rather than duplicate.

