Arcade runs the layer that lets AI agents call outside tools; Smithery is the public index where developers find them. As of August 5, one company owns the catalog, the runtime, and the audit log.
Arcade runs the layer that authorizes an AI agent to call an outside tool, decides which user the agent is acting as, and writes the audit log when it does. Smithery is the public catalog where developers go to find those tools. As of August 5, the catalog and the execution layer are one company. Arcade is also the author of the MCP authorization specification those tools are written against.
The acquisition, reported on August 10 by Forbes contributor Janakiram MSV, is small in dollar terms. Neither side disclosed a price. The structure is the news. Before this deal, an enterprise that wanted AI agents to call external services had to assemble the pieces: a registry to find MCP servers, an execution layer to handle delegated authorization, and an audit log to record who-did-what-when. Arcade already sold the middle and bottom of that stack. With Smithery, it now owns the top.
That changes what an enterprise is actually buying. It is no longer procurement of a runtime plus a discovery habit. It is a stack.
MCP — the Model Context Protocol — is an open standard that lets AI models call outside tools. Think of it as a phone system: every tool a model might want to use exposes a "server" with a manifest of capabilities, and the agent dials in. Smithery grew to host tens of thousands of these servers, per Arcade's announcement, and positioned itself as the default discovery layer for developers who didn't want to roll their own index. Anirudh Kamath, Smithery's co-founder, is joining Arcade as part of the deal.
Arcade's pitch has always been the part developers don't want to build: the secure action layer. When an agent needs to send an email as a specific user, or post to a specific Slack channel, it cannot just inherit a god-mode token. Arcade handles delegated authorization so the agent acts as one user, with only that user's permissions, and writes an audit record per action. The company also says it authored the MCP authorization spec referenced by major clients and servers, meaning the standard those tools are written against carries its fingerprints.
In June, Arcade closed a $60 million Series A led by SYN Ventures, with strategic capital from Morgan Stanley and Wipro, bringing total funding to $72 million. The Smithery deal lands two months later, with a real catalog already in production.
Arcade is making a market-structure case for the deal, and it leans on a benchmark the company itself built. ToolBench, an Arcade-published index, scanned 43,400 MCP servers and 219,069 tools and graded them on an A+ to F rubric based on how the tools behaved when a model actually called them. The headline result: 0.5% earned an A grade.
That number has to be handled carefully. Arcade writes the rubric. Arcade also sells the remedy. The underlying observation, that the long tail of community MCP servers has malformed schemas, missing descriptions, and overlapping tool names, is independently observable, and the rest of the industry has been saying some version of it for months. The specific 0.5%, though, is Arcade's measurement of Arcade's definition of quality. Treat it as the company's argument for why the supply chain needs a curator, not as a neutral market fact.
The argument is also directionally significant. The agent-tool ecosystem has, until this deal, been a market of independent parts: registries, runtimes, authorization layers, and audit systems, mostly sold by different vendors. Arcade's bet is that enterprises moving agents out of pilots will want to buy the whole thing from one accountable counterparty, and that being the curator is more valuable than being any single piece. Whether that bet holds is the question the next twelve months will answer. A $72M balance sheet and a real catalog in production is a credible shot at it.
MCP is open. Anyone can run their own registry. The author of the authorization spec is not the same thing as its owner, and Arcade's spec authorship is a claim, not a regulatory designation. The deal is directionally significant, not a lock-in event. The next time an enterprise architect evaluates this stack, the question is whether the convenience of one vendor is worth the option value of an open market, and that, more than the 0.5% statistic, is what the Arcade and Smithery combination puts on the table.