Head to head · Automation workflows · October 2026 research run

Gumloop vs Kestra

Kestra scores 63.6 (B) on agent readiness against Gumloop's 61.6 (C), and leads in 5 of 7 scored categories. Gumloop leads on security & auth. Both do automation workflows.

Which one, for what

Gumloop C

Good for A team that wants hosted agents with connectors, approvals and triggers, driven or configured by an outside agent through the API or MCP server.

Ahead on

  • Security & auth, 50 against 41

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

API keys and the gumloop_api OAuth scope need the Pro plan at $37 a month. The 14-day trial needs a card

Kestra B

Good for Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.

Ahead on

  • Reliability, 89 against 82
  • Agent ergonomics, 73 against 66
  • Payments & pricing, 50 against 20
  • Maintenance & community, 93 against 77
  • Transparency & trust, 69 against 57

Also in its favour

  • Open source

Watch for

The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud

Score by category

CategoryWeight this runGumloopKestraEdge
Reliability16%208289Kestra +7
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28382Gumloop +1
Agent ergonomics13%16.26673Kestra +7
Security & auth14%17.55041Gumloop +9
Payments & pricing10%12.52050Kestra +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87793Kestra +16
Transparency & trust7%8.85769Kestra +12
Negative events≤15-2-7
Total61.6 · C63.6 · B

Facts side by side

FactGumloopKestra
KindHTTP APIHTTP API
VendorAgentHub Inc.Kestra Technologies
Hosted endpointhttps://api.gumloop.com/api/v1no (local only)
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingPaidFreemium
x402nono
LicenceProprietary service under Gumloop's terms of service. The Python SDK and CLI repository and the npm package are Apache-2.0Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-10-082026-10-05
Terms last updatedno date givenno document linked
Privacy policy last updatedno date givenno document linked
Customer content may train modelsyes
Terms restrict automated accessyes
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticeyes
Arbitration or class-action waivernot found in the text
Popularity188 npm/wk, 2.9k PyPI/wk29k stars, 244 npm/wk, 170 PyPI/wk

Verdicts

Gumloop

Gumloop's REST API has a public OpenAPI file with 105 operations, Markdown docs and a changelog with 28 dated releases since 9 July 2026. API keys need the $37 Pro plan, the trial needs a card, the key can travel in the URL, and self-serve content may be used to train Gumloop's models.

Kestra

Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.

Before you call either

Gumloop

  1. Send the key as Authorization: Bearer and, for a personal key, add the x-auth-key header with the user ID. Do not put api_key in the URL
  2. Create sessions with POST /agents/{agent_id}/sessions, then poll GET /sessions/{session_id}. A 202 means processing or queued, and the reply is not in the response
  3. Supply your own session_id when creating a session. A repeat returns 409, which makes a retry safe
  4. For streamed output send the same body with stream: true to ws.gumloop.com. api.gumloop.com answers 400 to it
  5. Treat a webhook trigger URL as a password. It returns {"success": true} at once and never carries the agent's output

Kestra

  1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3
  2. Set kestra.server.basic-auth in the config file before first start. Without it the setup page is open to anyone who reaches the port
  3. Put the tenant in the path. Open-source instances use main, as in /api/v1/main/executions/{namespace}/{id}
  4. Send flow inputs as multipart form fields, and add wait=true to get the finished execution in the same call
  5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth

Questions

Which is better for AI agents, Gumloop or Kestra?

Kestra scores 63.6 (B) on agent readiness against Gumloop's 61.6 (C), and leads in 5 of 7 scored categories. Gumloop leads on security & auth.

Do Gumloop and Kestra need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Gumloop and Kestra without installing anything?

Gumloop has a hosted endpoint at https://api.gumloop.com/api/v1. No hosted endpoint is listed for Kestra.

Are Gumloop and Kestra open source?

No open-source release is listed for Gumloop. Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial).

Other comparisons with Gumloop or Kestra

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.