Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

DIY vs IBM watsonx Orchestrate

Build it yourself (DIY)

Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools

IBM watsonx Orchestrate

Agent management platform to build, deploy, orchestrate, and govern AI agents

Short answer

DIY is not a product: you connect and govern agents yourself on open protocols such as A2A, which leaves authorization logic to each implementation, and MCP, where authorization is optional.⁠Source 1, Source 2 IBM describes watsonx Orchestrate as a vendor platform to build, run, and govern agents, and says its control plane also governs agents built elsewhere.⁠Source 3, Source 4, Source 5

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both can bring agent connections under central control: IBM says its control plane governs agents wherever built or run; Uber built an MCP registry as its control plane.⁠Source 5, Source 6
Where they differ
IBM says watsonx Orchestrate is also for building agents; those configured with its Agent Development Kit run on it.⁠Source 3, Source 4 With DIY, frameworks such as LangGraph build and deploy agents.⁠Source 7
Running both
IBM says agents from third-party frameworks can join watsonx Orchestrate as external agents through supported protocols.⁠Source 8
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • You build it

DIY

  • Build agents: You build itOpen-source frameworks like ADK⁠Source 9
  • Host and run agents: You build itSelf-hosted, like LangGraph⁠Source 7
  • Identity and access: You build itYour own identity provider⁠Source 10
  • Registry and governance: You build itYour own agent registry⁠Source 11
  • Traffic between agents, tools, and models: You build itYour gateway and service mesh⁠Source 6
  • Agents across organizations: You build itA2A with API management⁠Source 12

IBM watsonx Orchestrate

  • Build agents: OfferedVisual builder and ADK⁠Source 13
  • Host and run agents: OfferedAgents run on watsonx Orchestrate⁠Source 4
  • Identity and access: PreviewAgent identity⁠Source 14
  • Registry and governance: OfferedAgentic Control Plane⁠Source 5
  • Traffic between agents, tools, and models: OfferedA2A calls to agent endpoints⁠Source 15
  • Agents across organizations: OfferedPartner A2A agents in catalog⁠Source 15

At a glance

TopicDIYIBM watsonx Orchestrate
What it isAn in-house build on open protocols such as A2A and MCP, which the A2A specification calls complementary.⁠Source 1IBM describes it as an agent management platform to build, deploy, orchestrate, manage, and govern AI agents, wherever they are built or run.⁠Source 3
Building agentsWith frameworks you choose, such as LangGraph or Google’s open-source Agent Development Kit (ADK).⁠Source 7, Source 9IBM’s Agent Development Kit (ADK) configures agents that run on watsonx Orchestrate.⁠Source 4 IBM says it also offers a drag-and-drop visual builder.⁠Source 13
Where it runsWherever you run it: Pinterest, for example, optimized for MCP servers hosted in its internal cloud.⁠Source 16Managed SaaS in AWS and IBM Cloud regions, or on-premises on IBM Cloud Pak for Data or IBM Software Hub.⁠Source 17, Source 18
Agent identityIn A2A, identity is established at the HTTP layer and authorization logic is implementation-specific.⁠Source 1, Source 12 MCP authorization is optional.⁠Source 2Existing authentication types use an impersonation model.⁠Source 14 Agent identity through IBM Verify or Microsoft Entra is in private preview.⁠Source 19
PricingThe A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 20 Build and running costs are not publicly documented.Essentials from $530 and Standard from $6,360 USD a month; Premium on request.⁠Source 21 A 30-day free trial.⁠Source 21

What each one is

Build it yourself (DIY)

DIY means connecting and governing agents without buying a platform: MCP and A2A wired together in-house, existing infrastructure stretched to cover agents, an in-house platform, self-hosted open-source frameworks, or no central approach; Uber and Pinterest have each written about the MCP registry they built.⁠Source 6, Source 16

IBM watsonx Orchestrate

IBM describes watsonx Orchestrate as an agent management platform to build, deploy, orchestrate, manage, and govern AI agents.⁠Source 3 IBM says its Agentic Control Plane, introduced in June 2026, observes and governs agents wherever they were built or run.⁠Source 5, Source 22

The differences that matter

  1. Agent registry and discovery

    DIY

    A2A’s current specification prescribes no standard API for curated registries; Pinterest’s internal MCP registry is its source of truth for approved servers.⁠Source 11, Source 16

    IBM watsonx Orchestrate

    IBM says its searchable catalog holds prebuilt and custom agents and tools; an A2A endpoint lists the agents in its live environment.⁠Source 23, Source 24

    IBM says its AI Gateway, in preview, can discover agents in Amazon Bedrock AgentCore, Gemini Enterprise Agent Platform, or Azure AI Foundry, and import selected ones.⁠Source 25, Source 26, Source 27, Source 28

  2. Policy and controls

    DIY

    MCP says implementers should build consent and authorization flows; Uber starts every MCP server and tool disabled until its owning team reviews and enables it.⁠Source 6, Source 29

    IBM watsonx Orchestrate

    On SaaS outside AWS GovCloud, controls can block unsafe content, protect data, govern model traffic, and restrict network access; agent controls cover A2A agents.⁠Source 30

    Pinterest requires every MCP server that isn’t a one-off experiment to have an owning team, appear in its registry, and go through review.⁠Source 16

  3. Agents at other companies

    DIY

    A2A is designed for agents from different companies on separate servers; each A2A server authorizes requests under its own policies.⁠Source 1, Source 31

    IBM watsonx Orchestrate

    Agents that IBM’s partners list in its catalog can be added as A2A collaborators, though not in on-premises deployments.⁠Source 15, Source 32

    A connection defines how watsonx Orchestrate authenticates to an external A2A agent.⁠Source 33 Beyond that, how another company controls who reaches its agents is not publicly documented.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicDIYIBM watsonx Orchestrate
Network exposureMCP servers on Streamable HTTP expose an HTTP endpoint; A2A agents on HTTP use HTTPS URLs in production.⁠Source 1, Source 34Outside agents need an accessible endpoint.⁠Source 35 IBM documents a Satellite TLS tunnel and private endpoints on IBM Cloud.⁠Source 36, Source 37
IdentityIdentity is established at the HTTP layer in A2A.⁠Source 12 MCP authorization is optional.⁠Source 2Existing authentication types use an impersonation model.⁠Source 14 Agent identity through IBM Verify or Microsoft Entra is in private preview.⁠Source 19
Access changes and revocationEach A2A server authorizes requests under its own policies; the specification calls that logic implementation-specific.⁠Source 1IBM Cloud tracks undeploying a released agent version.⁠Source 38 Agents removed from AI Gateway’s directory (preview) can’t be collaborators.⁠Source 39
Audit trailA2A docs advise auditing task creation, critical state changes, and agent actions.⁠Source 12 Pinterest’s MCP servers log inputs and outputs.⁠Source 16Audit events can route to destinations you choose on IBM Cloud, or to your own S3 and CloudWatch on AWS.⁠Source 40, Source 41
ComplianceA2A docs say to comply with relevant rules such as GDPR, CCPA, and HIPAA.⁠Source 12 MCP leaves data protections to implementers.⁠Source 29IBM says watsonx Orchestrate is FedRAMP authorized on AWS GovCloud (US).⁠Source 42 The Premium plan lists a HIPAA-ready option.⁠Source 21

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

DIY and IBM watsonx Orchestrate compared on 18 criteria
DIYIBM watsonx Orchestrate
What it is
What it is and who it’s forAn in-house build on protocols such as A2A, an open standard for communication between agent systems, and MCP, which A2A’s specification calls complementary.⁠Source 1IBM describes an agent management platform to build, deploy, orchestrate, manage, and govern AI agents, for IT, security, and AI leaders.⁠Source 3
MaturityVaries by component: MCP’s latest revision is 2026-07-28.⁠Source 29, Source 43 The official MCP Registry is in preview and may have breaking changes or data resets.⁠Source 44IBM said its unified release was generally available in January 2024; the control plane, June 2026.⁠Source 22, Source 45 In preview: AI Gateway, agent identity, some dashboards.⁠Source 19, Source 25, Source 46
Control
Agent registry and discoveryThe current A2A specification prescribes no standard API for curated registries.⁠Source 11 The official MCP Registry, in preview, doesn’t support private servers.⁠Source 44IBM says its searchable catalog holds prebuilt and custom agents and tools.⁠Source 23 In preview, AI Gateway’s agent directory holds imported external agents.⁠Source 25, Source 39
Identity and access controlIn A2A, identity is established at the HTTP layer and authorization logic is implementation-specific.⁠Source 1, Source 12 MCP authorization is optional.⁠Source 2Platform SSO over OIDC or SAML; user, builder, and admin roles.⁠Source 47, Source 48 Agent identity is in private preview; existing authentication uses impersonation.⁠Source 14, Source 19
Ownership, policy, and revocationMCP says implementers should build consent and authorization flows.⁠Source 29 Pinterest requires owners, registry entries, and review for non-experimental MCP servers.⁠Source 16On SaaS outside AWS GovCloud, controls can block unsafe content, protect data, govern model traffic, and limit network access.⁠Source 30 Agent controls cover A2A agents.⁠Source 30
Audit log and observabilityA2A docs advise auditing significant events and distributed tracing, for example with OpenTelemetry.⁠Source 12 Pinterest’s MCP servers log inputs and outputs.⁠Source 16Traces give a high-level view of a request; registered outside agents can export theirs.⁠Source 49, Source 50 Audit events can go to IBM Cloud targets, or S3 and CloudWatch on AWS.⁠Source 40, Source 41
Connection
How agents connectMCP servers on Streamable HTTP expose an HTTP endpoint, and A2A agents on HTTP use HTTPS URLs in production.⁠Source 1, Source 34 AWS PrivateLink privately links a VPC to services.⁠Source 51Calls an outside agent at its running, accessible endpoint.⁠Source 15, Source 35 IBM’s outbound IPs can be allowlisted; IBM Cloud adds a Satellite TLS tunnel and private endpoints.⁠Source 17, Source 36, Source 37
Agents across organizationsA2A is designed for agents from different companies on separate servers.⁠Source 31 Each A2A server authorizes requests under its own policies.⁠Source 1Agents IBM’s partners list in its catalog can be A2A collaborators, except on-premises.⁠Source 15, Source 32 A connection defines how IBM authenticates to external A2A agents.⁠Source 33
Protocol supportMCP defines stdio and Streamable HTTP transports; its latest revision is 2026-07-28.⁠Source 29, Source 52 A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.⁠Source 1Calls external A2A agents over JSON-RPC 2.0 only, and exposes its own through A2A endpoints.⁠Source 24, Source 53 Imports MCP server tools; OAuth 2.1 isn’t supported there.⁠Source 54
Frameworks, models, and clouds supportedA2A gives agents built with different frameworks, languages, or vendors a common language.⁠Source 1 Google’s ADK says it is model-agnostic and deployment-agnostic.⁠Source 9IBM says it supports native, Langflow, LangGraph, and A2A agents.⁠Source 55 Also OpenAI-style chat endpoints and Copilot Studio agents via Direct Line.⁠Source 53
Operations
Deployment options and data residencyWherever you run it: Pinterest optimized for MCP servers in its internal cloud.⁠Source 16 A2A docs leave protecting stored data to your own policies.⁠Source 12Managed SaaS in AWS and IBM Cloud regions, or on-premises on IBM Cloud Pak for Data or IBM Software Hub.⁠Source 17, Source 18 The control plane isn’t supported in AWS GovCloud (US).⁠Source 46
Compliance attestationsA2A docs say to ensure compliance with relevant rules such as GDPR, CCPA, and HIPAA.⁠Source 12 MCP leaves access controls and data protections to implementers.⁠Source 29IBM says watsonx Orchestrate is FedRAMP authorized on AWS GovCloud (US).⁠Source 42 IBM says the company holds ISO/IEC 27001:2022 certification.⁠Source 56 Premium lists HIPAA-ready.⁠Source 21
Support and SLADepends on the component: MCP SDKs are tiered partly by maintenance commitments.⁠Source 57 The official MCP Registry, in preview, gives no uptime guarantees.⁠Source 44, Source 58On AWS, IBM states a 99.9% availability SLA; on IBM Cloud, it points to the base IBM Cloud Service Description.⁠Source 59, Source 60 Support cases can be opened.⁠Source 61
Time and effort to get runningA curated A2A registry is a service you deploy and maintain.⁠Source 11 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.⁠Source 16An admin guide covers setup and user access; platform SSO is set up with IBM.⁠Source 47, Source 62 Agent identity, in private preview, needs a separate IdP tenant.⁠Source 19
Pricing model and public pricesThe A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 20 Build and running costs are not publicly documented.Essentials from $530 and Standard from $6,360 USD a month, sized by active users and messages; Premium on request.⁠Source 21 30-day free trial.⁠Source 21 Prices are indicative.⁠Source 21
Building
Agent building toolsFrameworks such as LangGraph and Google’s open-source ADK build and deploy agents.⁠Source 7, Source 9 A2A has SDKs in six languages.⁠Source 63IBM says builders can use drag-and-drop, the ADK, Python, APIs, or open-source frameworks.⁠Source 4, Source 13 It says Langflow workflows can become tools.⁠Source 13
Model accessChosen by whoever builds the agents: Google’s ADK says it is optimized for Gemini and model-agnostic.⁠Source 9IBM-hosted and third-party models, varying by cloud, region, and deployment.⁠Source 64 Most regions default to GPT-OSS 120B via Groq.⁠Source 64 Other providers can be added.⁠Source 65
Integrations and ecosystemThe official MCP Registry, in preview, has a REST API for clients and aggregators to discover MCP servers.⁠Source 44IBM says its catalog shows how each IBM and partner agent connects to systems such as Microsoft 365, Salesforce, SAP, and Workday.⁠Source 23 Sold on AWS Marketplace too.⁠Source 21

Which to choose

Choose DIY if

  • You want no agent platform contract: the A2A and MCP specifications are openly licensed, A2A under Apache 2.0.⁠Source 1, Source 20
  • You want A2A over gRPC or HTTP/REST: the specification defines both bindings, and IBM calls external A2A agents over JSON-RPC 2.0 only.⁠Source 1, Source 53
  • You want your own review rules: Uber starts every MCP server and tool disabled until its owning team reviews and enables it.⁠Source 6
  • You want MCP calls checked by systems you already run, as Pinterest does with end-user JWTs and service-mesh identities.⁠Source 16

Choose IBM watsonx Orchestrate if

  • You want one platform to build, run, and govern agents, with IBM’s Agent Development Kit and, IBM says, a drag-and-drop builder.⁠Source 3, Source 4, Source 13
  • You want controls, on SaaS outside AWS GovCloud, that can block unsafe content, protect data, govern model traffic, and restrict network access.⁠Source 30
  • You want a catalog IBM says shows how each IBM and partner agent connects to systems such as SAP and Workday.⁠Source 23
  • You want published starting prices, a 30-day free trial, and a 99.9% availability SLA on AWS.⁠Source 21, Source 59

Questions buyers ask

Can IBM watsonx Orchestrate govern agents we built ourselves?

Yes. IBM says its control plane observes and governs agents wherever they were built or run.⁠Source 5 On SaaS outside AWS GovCloud, its agent controls apply to external agents that use A2A, and it can show traces from agents running outside it, built with any framework.⁠Source 30, Source 50

Is there a standard API for agent registries?

Not in A2A: its docs say the current specification prescribes no standard API for curated registries.⁠Source 11 The official MCP Registry, in preview, defines an OpenAPI spec that other MCP registries can implement, but it lists MCP servers, not agents.⁠Source 44

Does IBM watsonx Orchestrate support A2A and MCP?

Yes. It calls external A2A agents over JSON-RPC 2.0 only, and exposes its own agents through A2A endpoints.⁠Source 24, Source 53 Its agents can use tools imported from MCP servers, though MCP connections don’t support OAuth 2.1 or Dynamic Client Registration.⁠Source 54

How do the costs compare?

IBM’s Essentials plan starts at $530 USD a month and Standard at $6,360; Premium is priced on request, and there is a 30-day free trial.⁠Source 21 For DIY, the protocol specifications are openly licensed; build and running costs are not publicly documented.⁠Source 1, Source 20

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

70 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Agent2Agent (A2A) Protocol Specification a2a-protocol.org · checked Back:abcdefghijklmnopq

  2. Source 2: Authorization - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:abcd

  3. Source 3: IBM watsonx Orchestrate IBM · checked Back:abcdef

  4. Source 4: Welcome to IBM watsonx Orchestrate Agent Development Kit IBM · checked Back:abcdef

  5. Source 5: AI Agent Control Plane | IBM watsonx Orchestrate IBM · checked Back:abcde

  6. Source 6: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog uber.com · checked Back:abcde

  7. Source 7: langchain-ai/langgraph README (GitHub) github.com · checked Back:abcd

  8. Source 8: Overview - Agents (watsonx Orchestrate ADK docs) IBM · checked Back:ab

  9. Source 9: google/adk-python README (GitHub) github.com · checked Back:abcde

  10. Source 10: Integrating with Model Context Protocol (MCP) - Keycloak keycloak.org · checked Back to text

  11. Source 11: Agent Discovery - A2A Protocol a2a-protocol.org · checked Back:abcde

  12. Source 12: Enterprise Features - A2A Protocol a2a-protocol.org · checked Back:abcdefghi

  13. Source 13: AI Agent Builder | IBM watsonx Orchestrate IBM · checked Back:abcde

  14. Source 14: Agent identity overview IBM · checked Back:abcd

  15. Source 15: Partner A2A (Agent2Agent) agents IBM · checked Back:abcde

  16. Source 16: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog medium.com · checked Back:abcdefghij

  17. Source 17: Regional availability and outbound IP addresses IBM · checked Back:abc

  18. Source 18: Installing on IBM watsonx Orchestrate On-premises IBM · checked Back:ab

  19. Source 19: Prerequisites for configuring agent identity IBM · checked Back:abcde

  20. Source 20: modelcontextprotocol/modelcontextprotocol LICENSE (GitHub) github.com · checked Back:abcd

  21. Source 21: IBM watsonx Orchestrate Pricing IBM · checked Back:abcdefghij

  22. Source 22: Agentic Control Plane in IBM watsonx Orchestrate: One place to control every AI agent IBM · checked Back:ab

  23. Source 23: IBM watsonx Orchestrate Agent Catalog IBM · checked Back:abcd

  24. Source 24: Agent-to-Agent (A2A) Protocol endpoints IBM · checked Back:abc

  25. Source 25: Governing assets with AI Gateway IBM · checked Back:abc

  26. Source 26: Connecting and configuring Amazon Bedrock IBM · checked Back to text

  27. Source 27: Connecting and configuring Gemini Enterprise Agent Platform IBM · checked Back to text

  28. Source 28: Connecting and configuring Microsoft Azure AI Foundry IBM · checked Back to text

  29. Source 29: Specification - Model Context Protocol 2026-07-28 modelcontextprotocol.io · checked Back:abcdef

  30. Source 30: Protecting assets with controls IBM · checked Back:abcde

  31. Source 31: a2aproject/A2A README (GitHub) github.com · checked Back:ab

  32. Source 32: Any agent, any framework: Inside the IBM watsonx Orchestrate Agent Catalog IBM · checked Back:ab

  33. Source 33: Adding an agent-to-agent connection IBM · checked Back:ab

  34. Source 34: Streamable HTTP - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:ab

  35. Source 35: Adding agents from third-party platforms IBM · checked Back:ab

  36. Source 36: Configuring TLS tunnel IBM · checked Back:ab

  37. Source 37: Using private network endpoints IBM · checked Back:ab

  38. Source 38: List of events for activity tracking IBM · checked Back to text

  39. Source 39: Managing the agent directory IBM · checked Back:ab

  40. Source 40: Activity tracking events on IBM Cloud IBM · checked Back:ab

  41. Source 41: Enabling external logging for AWS IBM · checked Back:ab

  42. Source 42: IBM Expands FedRAMP Portfolio with Authorization of 11 Software Solutions, Including watsonx IBM · checked Back:ab

  43. Source 43: Key Changes - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back to text

  44. Source 44: The MCP Registry - Model Context Protocol modelcontextprotocol.io · checked Back:abcde

  45. Source 45: The AI Assistant for everyone: watsonx Orchestrate combines generative AI and automation to boost productivity | IBM IBM · checked Back to text

  46. Source 46: Agentic Control Plane IBM · checked Back:ab

  47. Source 47: Configuring SSO for platform access IBM · checked Back:ab

  48. Source 48: Roles on IBM watsonx Orchestrate IBM · checked Back to text

  49. Source 49: Overview - Traces (watsonx Orchestrate ADK docs) IBM · checked Back to text

  50. Source 50: Exporting observability traces with OpenTelemetry (watsonx Orchestrate ADK docs) IBM · checked Back:ab

  51. Source 51: What is AWS PrivateLink? - Amazon Virtual Private Cloud docs.aws.amazon.com · checked Back to text

  52. Source 52: Transports - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back to text

  53. Source 53: Connect to external agents (watsonx Orchestrate ADK docs) IBM · checked Back:abcde

  54. Source 54: MCP servers IBM · checked Back:abc

  55. Source 55: Manage all your AI agents in one place with watsonx Orchestrate IBM · checked Back to text

  56. Source 56: ISO 27001 - IBM Corporation Certificate (Bureau Veritas, ISO/IEC 27001:2022) IBM · checked Back to text

  57. Source 57: SDK Tiers - Model Context Protocol modelcontextprotocol.io · checked Back to text

  58. Source 58: MCP Registry Aggregators - Model Context Protocol modelcontextprotocol.io · checked Back to text

  59. Source 59: High availability, business continuity, backups and disaster recovery on AWS IBM · checked Back:ab

  60. Source 60: Licenses and entitlements for watsonx Orchestrate on IBM Cloud IBM · checked Back to text

  61. Source 61: Getting help and support IBM · checked Back to text

  62. Source 62: Getting started as an administrator IBM · checked Back to text

  63. Source 63: A2A protocol roadmap a2a-protocol.org · checked Back to text

  64. Source 64: Available AI models IBM · checked Back:ab

  65. Source 65: Choosing your LLM (watsonx Orchestrate ADK docs) IBM · checked Back to text

  66. Source 66: Your company's private network Blocks.ai · checked Back to text

  67. Source 67: Network requirements Blocks.ai · checked Back to text

  68. Source 68: Solutions: Agent sprawl Blocks.ai · checked Back to text

  69. Source 69: Why Blocks? Blocks.ai · checked Back to text

  70. Source 70: What is Blocks? Blocks.ai · checked Back to text