{
  "data": {
    "a": {
      "slug": "activepieces",
      "name": "Activepieces API + MCP",
      "vendor": "Activepieces",
      "vendorUrl": "https://www.activepieces.com",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Open-source flow builder with 760+ app integrations (pieces), run on Activepieces Cloud or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/activepieces",
      "markdownUrl": "https://www.anchorterminal.com/tools/activepieces.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/activepieces.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/activepieces.json",
      "repo": "https://github.com/activepieces/activepieces",
      "license": "MIT (core), commercial licence for enterprise-only parts",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://cloud.activepieces.com/api/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@activepieces/pieces-framework"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST API keys are created in the platform dashboard and sent as `Authorization: Bearer`. The docs say that dashboard is only in the Platform and Enterprise editions. The MCP server at https://\u003cinstance\u003e/mcp uses OAuth and is scoped to one project.",
      "pricing": "freemium",
      "pricingNotes": "Cloud Free 1,000 credits a month, one user, no card. Plus $20 a month (10,000 credits, up to 5 users), Team $200 a month (50,000 credits, 25 users), extra credits $0.007 each. Ultimate and Enterprise custom, embedding from $36,000 a year. Self-hosted Community Edition is free under MIT, enterprise-only parts need a licence key (https://www.activepieces.com/pricing).",
      "priceSummary": "$20 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": 45,
      "popularity": {
        "githubStars": 24814,
        "npmWeekly": 451816,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.activepieces.com/docs",
      "llmsTxt": "https://www.activepieces.com/docs/llms.txt",
      "openapi": "https://www.activepieces.com/docs/openapi.json",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.embedded",
        "automation.code",
        "automation.webhooks",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "local",
        "freemium",
        "no-card",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "webhooks"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.5,
        "grade": "C",
        "agentReady": false,
        "rank": 545,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 80,
          "payments": 35,
          "reliability": 55,
          "schema": 80,
          "security": 64,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -6,
        "negativeNotes": [
          "GHSA-m992-8rcw-vmrx, published 9 August 2026, critical (CVSS 9.2). The Bull-Board queue dashboard at /api/ui skipped its auth check in 0.80.0 to 0.84.0, so anyone could read and change background job queues on self-hosted instances that had turned the dashboard on. Fixed in 0.84.1 (https://github.com/activepieces/activepieces/security/advisories/GHSA-m992-8rcw-vmrx).",
          "Three high-severity advisories on 17 July 2026, command injection through a Code step name (GHSA-3pfv-m69p-5fv5), a V8 isolate sandbox bypass (GHSA-gr3h-c2j7-r52g) and cross-tenant data exposure through the Code piece sandbox cache (GHSA-5h2x-g6m3-grmq). All fixed and published, so the deduction is reduced (https://github.com/activepieces/activepieces/security/advisories)."
        ],
        "verdict": "MIT core, self-hostable, with the enterprise parts clearly separated. Docs say API keys come from the platform dashboard in Platform and Enterprise editions, while the pricing page lists the API on every plan.",
        "bestFor": "A team that wants an MIT-licensed builder it can self-host or embed, with an agent that builds flows through MCP.",
        "strengths": [
          "MIT core, self-hostable, with the enterprise parts clearly separated",
          "MCP over OAuth with PKCE, bound to one project, with tool groups switchable per project",
          "Annotations on 45 of 48 MCP tools, including `destructiveHint` and `idempotentHint`",
          "One 33-minute worker degradation on the status page in 90 days",
          "Free plan of 1,000 credits a month with no card"
        ],
        "weaknesses": [
          "Docs say API keys come from the platform dashboard in Platform and Enterprise editions, while the pricing page lists the API on every plan",
          "OpenAPI file documents no error responses, and no rate limits are published",
          "A critical and three high advisories in July and August 2026",
          "Privacy and terms pages need JavaScript, and no DPA or subprocessor list was found",
          "MCP tool calls aren't written to the audit log"
        ],
        "agentNotes": [
          "Run `ap_validate_flow` before publishing a flow",
          "Use `ap_search_actions` with a plain task description rather than listing pieces",
          "Turn off the Flow Building and Tables groups for a project the agent should only read",
          "Page with `limit` and `cursor` and stop when `next` is null",
          "Cloud runs stop at 10 minutes of active time. Waits and approvals don't count"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.5
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 80,
          "payments": 35,
          "reliability": 55,
          "schema": 80,
          "security": 64,
          "transparency": 70
        },
        "provenanceScore": 76
      },
      "connect": {
        "http": "curl \"https://cloud.activepieces.com/api/v1/flows?projectId=$AP_PROJECT_ID\u0026limit=10\" -H \"Authorization: Bearer $AP_API_KEY\"",
        "claudeCode": "claude mcp add --transport http activepieces https://cloud.activepieces.com/mcp",
        "config": {
          "mcpServers": {
            "activepieces": {
              "url": "https://cloud.activepieces.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/activepieces"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Plus plan",
          "unit": "month",
          "usd": 20,
          "note": "10,000 credits, up to 5 users"
        },
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 200,
          "note": "50,000 credits, 25 users"
        },
        {
          "item": "Extra credit",
          "unit": "credit",
          "usd": 0.007,
          "note": "on Plus and Team"
        }
      ],
      "provenance": {
        "legalEntity": "Activepieces Inc.",
        "domain": "activepieces.com",
        "domainRegistered": "2021-10-18",
        "endpointOnVendorDomain": true,
        "terms": "https://www.activepieces.com/terms",
        "privacy": "https://www.activepieces.com/privacy",
        "statusPage": "https://status.activepieces.com",
        "changelog": "https://www.activepieces.com/docs/about/changelog",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The terms and privacy pages load their text with JavaScript. The legal name is from the copyright line in the repository licence."
        ],
        "score": 76
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/activepieces.json",
      "live": {
        "slug": "activepieces",
        "probe": {
          "target": "https://cloud.activepieces.com/api/v1",
          "method": "get",
          "lastAt": "2026-10-09T10:42:34.33904693Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 86,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 90,
          "p95ms24h": 217,
          "samples24h": 260,
          "samples30d": 2300,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 114,
              "ok": 114
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.activepieces.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:34.354983475Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "activepieces/activepieces",
            "version": "0.92.2",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T15:56:25.171318994Z"
          },
          {
            "registry": "npm",
            "name": "@activepieces/pieces-framework",
            "version": "0.32.0",
            "seenAt": "2026-10-08T15:56:21.434695197Z"
          }
        ],
        "githubStars": 24951,
        "npmWeekly": 461262,
        "securityTxt": {
          "url": "https://activepieces.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:36.083475194Z"
        },
        "llmsTxt": {
          "url": "https://www.activepieces.com/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:00.088524788Z"
        },
        "domain": {
          "domain": "activepieces.com",
          "registered": "2021-10-18",
          "source": "https://rdap.verisign.com/com/v1/domain/activepieces.com",
          "checkedAt": "2026-10-04T13:04:25.500762105Z"
        },
        "pages": [
          {
            "url": "https://www.activepieces.com/docs/about/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:53.84737977Z",
            "changedAt": "2026-10-06T16:13:36.951148704Z",
            "fingerprint": "1c2072d82d3f"
          },
          {
            "url": "https://www.activepieces.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:56.181494826Z",
            "changedAt": "2026-10-07T18:10:35.595682263Z",
            "fingerprint": "d208a96b1ab4"
          },
          {
            "url": "https://www.activepieces.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:57.897847999Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "87085c5a5f7a"
          },
          {
            "url": "https://www.activepieces.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:59.975430189Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "eebfacc51747"
          }
        ],
        "updatedAt": "2026-10-09T10:42:34.33904693Z"
      }
    },
    "answer": "Kestra scores 63.6 (B) on agent readiness against Activepieces API + MCP's 57.5 (C), and leads in 5 of 7 scored categories. Activepieces API + MCP leads on security \u0026 auth.",
    "b": {
      "slug": "kestra",
      "name": "Kestra",
      "vendor": "Kestra Technologies",
      "vendorUrl": "https://kestra.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Kestra is an open-source workflow orchestrator from Kestra Technologies. Flows are written in YAML and run on a server the owner hosts, with a REST API, SDKs in four languages and flows exposed as MCP tools.",
      "url": "https://www.anchorterminal.com/tools/kestra",
      "markdownUrl": "https://www.anchorterminal.com/tools/kestra.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kestra.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kestra.json",
      "repo": "https://github.com/kestra-io/kestra",
      "license": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "kestra/kestra"
        },
        {
          "registry": "pypi",
          "name": "kestrapy"
        },
        {
          "registry": "npm",
          "name": "@kestra-io/kestra-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "The open-source edition takes HTTP Basic auth with one username and password, set in `kestra.server.basic-auth` or on the setup page at first start. That credential has full access. Bearer API tokens, service accounts, OAuth, SSO and role-based access are in the Enterprise Edition and Kestra Cloud only. Access to open source is self-serve, by running the server. Webhook triggers are called with a key in the URL path.",
      "pricing": "freemium",
      "pricingNotes": "The open-source edition is free under Apache-2.0 with unlimited flows and executions, and an agent can start on it with no contract or account. Enterprise Edition is an annual subscription per instance through sales, with no public price. Kestra Cloud is by access request, with 14 days free and no card, then billed on task runs and Cloud runner time at rates that are not published (https://kestra.io/pricing, checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 29427,
        "npmWeekly": 244,
        "pypiWeekly": 170,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://kestra.io/docs",
      "llmsTxt": "https://kestra.io/llms.txt",
      "openapi": "https://kestra.io/kestra.yml",
      "capabilities": [
        "automation.workflows",
        "automation.code",
        "automation.webhooks",
        "automation.apps",
        "agent.tools"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "local",
        "hosted",
        "freemium",
        "openapi",
        "llms-txt",
        "mcp",
        "python",
        "typescript",
        "java",
        "go",
        "webhooks",
        "enterprise",
        "soc2"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.6,
        "grade": "B",
        "agentReady": false,
        "rank": 351,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -7,
        "negativeNotes": [
          "Five advisories rated critical were published on the repository in six months. GHSA-365w-2m69-mp9x (CVE-2026-34612, remote code execution through SQL injection, 30 March 2026), GHSA-5vc5-wxxq-3fjx and GHSA-2q47-568g-9h4f (CVE-2026-49869 and CVE-2026-53576, unauthenticated remote code execution through authentication filter bypass, 3 June 2026), and GHSA-rjhm-qm6w-m7x9 and GHSA-j5cv-8rw9-vv2p (unauthenticated remote code execution and authentication bypass, 29 September 2026). All are fixed, in 1.3.38 and 1.0.60 at the latest, and the maintainers published each one, so the deduction is reduced (https://github.com/kestra-io/kestra/security/advisories).",
          "Two further high advisories affected the default open-source setup. GHSA-hrr4-xg8h-5p6f, an unauthenticated gRPC control plane on port 50051, fixed in 2.0.3 and published 29 September 2026, and GHSA-94pv-f379-3gp3, a revoked administrator credential that stayed valid, fixed in 1.3.41 and published 6 October 2026 (https://github.com/kestra-io/kestra/security/advisories)."
        ],
        "verdict": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.",
        "bestFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "strengths": [
          "OpenAPI 3.0.1 spec for the open-source API with 216 operations, 213 of them documenting 401, 403 and 500 as problem+json",
          "Every docs page is served as Markdown by adding `.md`, with `llms.txt` and `llms-full.txt`",
          "32 releases between 15 July and 5 October 2026, with patches each week on the 1.3 and 2.0 long-term support lines",
          "Any flow becomes an MCP tool through `McpToolTrigger`, with read-only, destructive and idempotent hints set per flow",
          "Apache-2.0 server, and usage reporting documented field by field with two switches to turn it off"
        ],
        "weaknesses": [
          "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud",
          "Five critical advisories from 30 March to 29 September 2026, four of them unauthenticated remote code execution or authentication bypass, all fixed",
          "Kestra Cloud is request-access with no public price, and Enterprise is sold by annual contract through sales",
          "No rate limits and no idempotency key on the API. The correlation ID pattern needs a guard written into the flow",
          "The docs say `kestrapy` 2.0.1 imports `regex` without declaring it, so a plain install fails on import"
        ],
        "agentNotes": [
          "Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3",
          "Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port",
          "Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`",
          "Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call",
          "Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.6
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 86
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "docker run --pull=always --rm -it -p 8080:8080 --user=root --name kestra -v kestra_data:/app/storage -v kestra_db:/app/data -v /var/run/docker.sock:/var/run/docker.sock -v /tmp:/tmp -e KESTRA_PLUGINS_AUTO_INSTALL_ENABLED=true kestra/kestra:latest-slim server local",
        "http": "curl -X POST -u 'admin@kestra.io:kestra' http://localhost:8080/api/v1/main/executions/company.team/hello_world",
        "claudeCode": "claude mcp add \u003cserver-id\u003e \u003cserver-url\u003e --transport http --header \"Authorization: Basic $(echo -n 'username:password' | base64)\""
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/kestra"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Kestra Technologies SAS",
        "domain": "kestra.io",
        "domainRegistered": "2019-12-18",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/kestra-io/kestra/releases",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Cloud terms name Kestra Technologies SAS (RCS 900 427 873), 81 rue du Pré Catelan, 59110 La Madeleine, France, and Kestra Technologies Inc., a Delaware corporation, for customers billed in the Americas.",
          "No terms or privacy link is given because the edition graded is Apache-2.0 software the owner runs. The Kestra Cloud Terms of Service and Kestra Cloud Privacy Policy (both 14 September 2026) say they do not cover the open-source project, and the privacy policy at kestra.io/privacy-policy covers only the website.",
          "The API answers on the owner's own host. Only the documentation MCP server (api.kestra.io) and the usage reports go to a Kestra domain.",
          "https://kestra.io/.well-known/security.txt names security@kestra.io and the GitHub advisory form, and expires on 26 August 2028.",
          "RDAP for kestra.io gives a registration date of 2019-12-18.",
          "status.kestra.io did not answer our requests on 8 October 2026 and no status page is linked from the pricing, security or Cloud pages."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kestra.json"
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Activepieces",
        "b": "Kestra Technologies",
        "name": "Vendor"
      },
      {
        "a": "https://cloud.activepieces.com/api/v1",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT (core), commercial licence for enterprise-only parts",
        "b": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
        "name": "Licence"
      },
      {
        "a": "45",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "couldn't be read",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "25k stars, 452k npm/wk",
        "b": "29k stars, 244 npm/wk, 170 PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Kestra scores 63.6 (B) on agent readiness against Activepieces API + MCP's 57.5 (C), and leads in 5 of 7 scored categories. Activepieces API + MCP leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Activepieces API + MCP or Kestra?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Activepieces API + MCP and Kestra need an API key?"
      },
      {
        "answer": "Activepieces API + MCP has a hosted endpoint at https://cloud.activepieces.com/api/v1. No hosted endpoint is listed for Kestra.",
        "question": "Can an agent call Activepieces API + MCP and Kestra without installing anything?"
      },
      {
        "answer": "Yes. Activepieces API + MCP is open source (MIT (core), commercial licence for enterprise-only parts). Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial).",
        "question": "Are Activepieces API + MCP and Kestra open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 64 against 41"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card"
        ],
        "goodFor": "A team that wants an MIT-licensed builder it can self-host or embed, with an agent that builds flows through MCP.",
        "slug": "activepieces",
        "watchFor": "Docs say API keys come from the platform dashboard in Platform and Enterprise editions, while the pricing page lists the API on every plan"
      },
      {
        "aheadOn": [
          "Reliability, 89 against 55",
          "Agent ergonomics, 73 against 65",
          "Payments \u0026 pricing, 50 against 35",
          "Maintenance \u0026 community, 93 against 80"
        ],
        "also": null,
        "goodFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "slug": "kestra",
        "watchFor": "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud"
      }
    ],
    "job": {
      "capability": "automation.workflows",
      "name": "Automation workflows"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-gumloop.json",
        "title": "Activepieces API + MCP vs Gumloop",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-gumloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-make.json",
        "title": "Activepieces API + MCP vs Make API + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-make"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-n8n.json",
        "title": "Activepieces API + MCP vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-paragon.json",
        "title": "Activepieces API + MCP vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-pipedream.json",
        "title": "Activepieces API + MCP vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-power-automate.json",
        "title": "Activepieces API + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-tray.json",
        "title": "Activepieces API + MCP vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-windmill.json",
        "title": "Activepieces API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-workato.json",
        "title": "Activepieces API + MCP vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-kestra.json",
        "title": "Gumloop vs Kestra",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-kestra"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-make.json",
        "title": "Kestra vs Make API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-make"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-n8n.json",
        "title": "Kestra vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-paragon.json",
        "title": "Kestra vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-pipedream.json",
        "title": "Kestra vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-power-automate.json",
        "title": "Kestra vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-tray.json",
        "title": "Kestra vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-windmill.json",
        "title": "Kestra vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-workato.json",
        "title": "Kestra vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-workato"
      }
    ],
    "scores": [
      {
        "activepieces": 55,
        "by": 34,
        "edge": "kestra",
        "kestra": 89,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "activepieces": 80,
        "by": 2,
        "edge": "kestra",
        "kestra": 82,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "activepieces": 65,
        "by": 8,
        "edge": "kestra",
        "kestra": 73,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "activepieces": 64,
        "by": 23,
        "edge": "activepieces",
        "kestra": 41,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "activepieces": 35,
        "by": 15,
        "edge": "kestra",
        "kestra": 50,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "activepieces": 80,
        "by": 13,
        "edge": "kestra",
        "kestra": 93,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "activepieces": 73,
        "by": 4,
        "edge": "activepieces",
        "kestra": 69,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Kestra scores 63.6 (B) on agent readiness against Activepieces API + MCP's 57.5 (C), and leads in 5 of 7 scored categories. Activepieces API + MCP leads on security \u0026 auth. Both do automation workflows.",
    "verdicts": {
      "activepieces": "MIT core, self-hostable, with the enterprise parts clearly separated. Docs say API keys come from the platform dashboard in Platform and Enterprise editions, while the pricing page lists the API on every plan.",
      "kestra": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/activepieces-vs-kestra",
    "json": "https://www.anchorterminal.com/compare/activepieces-vs-kestra.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/activepieces-vs-kestra.md",
    "slim": "https://www.anchorterminal.com/compare/activepieces-vs-kestra.min.md"
  },
  "markdown": "Kestra scores 63.6 (B) on agent readiness against Activepieces API + MCP's 57.5 (C), and leads in 5 of 7 scored categories. Activepieces API + MCP leads on security \u0026 auth. Both do automation workflows.\n\n- Activepieces API + MCP: grade C, 57.5/100, rank #545 of 842. Markdown https://www.anchorterminal.com/tools/activepieces.md · JSON https://www.anchorterminal.com/api/v1/tools/activepieces.json\n- Kestra: grade B, 63.6/100, rank #351 of 842. Markdown https://www.anchorterminal.com/tools/kestra.md · JSON https://www.anchorterminal.com/api/v1/tools/kestra.json\n\n## Which one, for what\n\n### Activepieces API + MCP (C)\n\nGood for: A team that wants an MIT-licensed builder it can self-host or embed, with an agent that builds flows through MCP.\n\nAhead on:\n- Security \u0026 auth, 64 against 41\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n\nWatch for: Docs say API keys come from the platform dashboard in Platform and Enterprise editions, while the pricing page lists the API on every plan\n\n### Kestra (B)\n\nGood for: Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.\n\nAhead on:\n- Reliability, 89 against 55\n- Agent ergonomics, 73 against 65\n- Payments \u0026 pricing, 50 against 35\n- Maintenance \u0026 community, 93 against 80\n\nWatch for: The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud\n\n\n## Score by category\n\n| Category | Weight | Activepieces API + MCP | Kestra | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 55 | 89 | Kestra +34 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 80 | 82 | Kestra +2 |\n| Agent ergonomics | 13% (16.2 this run) | 65 | 73 | Kestra +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 64 | 41 | Activepieces API + MCP +23 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 50 | Kestra +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 93 | Kestra +13 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 73 | 69 | Activepieces API + MCP +4 |\n| Negative events | ≤15 | -6 | -7 | |\n| **Total** | | **57.5 · C** | **63.6 · B** | |\n\n## Facts side by side\n\n| Fact | Activepieces API + MCP | Kestra |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Activepieces | Kestra Technologies |\n| Hosted endpoint | `https://cloud.activepieces.com/api/v1` | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT (core), commercial licence for enterprise-only parts | Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial |\n| Tools exposed | 45 | none |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| Last release | 2026-09-30 | 2026-10-05 |\n| Terms last updated | couldn't be read | no document linked |\n| Privacy policy last updated | couldn't be read | no document linked |\n| Customer content may train models | couldn't be read |  |\n| Terms restrict automated access | couldn't be read |  |\n| Terms restrict benchmarking | couldn't be read |  |\n| Terms or service can change without notice | couldn't be read |  |\n| Arbitration or class-action waiver | couldn't be read |  |\n| Popularity | 25k stars, 452k npm/wk | 29k stars, 244 npm/wk, 170 PyPI/wk |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**Activepieces API + MCP.** MIT core, self-hostable, with the enterprise parts clearly separated. Docs say API keys come from the platform dashboard in Platform and Enterprise editions, while the pricing page lists the API on every plan.\n\n**Kestra.** Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.\n\n## Before you call either\n\n### Activepieces API + MCP\n\n1. Run `ap_validate_flow` before publishing a flow\n2. Use `ap_search_actions` with a plain task description rather than listing pieces\n3. Turn off the Flow Building and Tables groups for a project the agent should only read\n4. Page with `limit` and `cursor` and stop when `next` is null\n5. Cloud runs stop at 10 minutes of active time. Waits and approvals don't count\n\n### Kestra\n\n1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3\n2. Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port\n3. Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`\n4. Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call\n5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth\n\n## Questions\n\n### Which is better for AI agents, Activepieces API + MCP or Kestra?\n\nKestra scores 63.6 (B) on agent readiness against Activepieces API + MCP's 57.5 (C), and leads in 5 of 7 scored categories. Activepieces API + MCP leads on security \u0026 auth.\n\n### Do Activepieces API + MCP and Kestra need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Activepieces API + MCP and Kestra without installing anything?\n\nActivepieces API + MCP has a hosted endpoint at https://cloud.activepieces.com/api/v1. No hosted endpoint is listed for Kestra.\n\n### Are Activepieces API + MCP and Kestra open source?\n\nYes. Activepieces API + MCP is open source (MIT (core), commercial licence for enterprise-only parts). Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/activepieces-vs-kestra.json, and with the fewest tokens: https://www.anchorterminal.com/compare/activepieces-vs-kestra.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"activepieces\", \"b\": \"kestra\"}`. From a terminal: `anchor compare activepieces kestra`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/activepieces.json and https://www.anchorterminal.com/api/v1/tools/kestra.json\n\n## Other comparisons with Activepieces API + MCP or Kestra\n\n- [Activepieces API + MCP vs Gumloop](https://www.anchorterminal.com/compare/activepieces-vs-gumloop.md)\n- [Activepieces API + MCP vs Make API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-make.md)\n- [Activepieces API + MCP vs n8n API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-n8n.md)\n- [Activepieces API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/activepieces-vs-paragon.md)\n- [Activepieces API + MCP vs Pipedream API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-pipedream.md)\n- [Activepieces API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/activepieces-vs-power-automate.md)\n- [Activepieces API + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-tray.md)\n- [Activepieces API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-windmill.md)\n- [Activepieces API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-workato.md)\n- [Gumloop vs Kestra](https://www.anchorterminal.com/compare/gumloop-vs-kestra.md)\n- [Kestra vs Make API + MCP](https://www.anchorterminal.com/compare/kestra-vs-make.md)\n- [Kestra vs n8n API + MCP](https://www.anchorterminal.com/compare/kestra-vs-n8n.md)\n- [Kestra vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/kestra-vs-paragon.md)\n- [Kestra vs Pipedream API + MCP](https://www.anchorterminal.com/compare/kestra-vs-pipedream.md)\n- [Kestra vs Microsoft Power Automate](https://www.anchorterminal.com/compare/kestra-vs-power-automate.md)\n- [Kestra vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/kestra-vs-tray.md)\n- [Kestra vs Windmill API + MCP](https://www.anchorterminal.com/compare/kestra-vs-windmill.md)\n- [Kestra vs Workato API + MCP](https://www.anchorterminal.com/compare/kestra-vs-workato.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Activepieces API + MCP vs Kestra",
        "url": ""
      }
    ],
    "description": "Kestra scores 63.6 (B) on agent readiness against Activepieces API + MCP's 57.5 (C), and leads in 5 of 7 scored categories. Activepieces API + MCP leads on security \u0026 auth. Both do automation workflows. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Activepieces API + MCP C 57.5",
      "Kestra B 63.6",
      "scores"
    ],
    "h1": "Activepieces API + MCP vs Kestra",
    "image": "https://www.anchorterminal.com/assets/og/compare-activepieces-vs-kestra.png",
    "path": "/compare/activepieces-vs-kestra",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Activepieces API + MCP vs Kestra for AI agents, C 57.5 vs B 63.6",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/activepieces-vs-kestra"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 730
  },
  "version": 1
}
