{
  "data": {
    "a": {
      "slug": "gumloop",
      "name": "Gumloop",
      "vendor": "AgentHub Inc.",
      "vendorUrl": "https://www.gumloop.com",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Gumloop is a hosted platform from AgentHub Inc. for building AI agents that work across company apps and run on schedules, webhooks and app events. It has a REST API, a Python SDK, a CLI and a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/gumloop",
      "markdownUrl": "https://www.anchorterminal.com/tools/gumloop.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/gumloop.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/gumloop.json",
      "repo": "https://github.com/gumloop/gumloop-py",
      "license": "Proprietary service under Gumloop's terms of service. The Python SDK and CLI repository and the npm package are Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.gumloop.com/api/v1",
      "packages": [
        {
          "registry": "pypi",
          "name": "gumloop"
        },
        {
          "registry": "npm",
          "name": "gumloop"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve API key on the Pro plan or above, created on the Connectors page in the app and sent as a bearer token. A personal key carries its owner's identity and also needs the `x-auth-key` header with the user ID. A team key can run as any team member named in `user_id`. OAuth 2.0 (authorisation code with PKCE, refresh tokens, revocation) is for apps other users sign in to, and client registration is by email to support. The key is also accepted as an `api_key` query parameter. Webhook triggers take no credential beyond the secret in their URL.",
      "pricing": "paid",
      "pricingNotes": "Pro is $37 a month with 20,000 credits, unlimited seats and API keys. No free plan is listed. The 14-day Pro trial needs a card and converts to a paid plan unless cancelled, so an agent cannot start without a person and a card. Usage is billed in credits at $0.005 each, with overage capped at 1,000,000 credits a period on Pro. Enterprise is priced through sales (https://www.gumloop.com/pricing, https://docs.gumloop.com/core-concepts/credits.md, checked 2026-10-08).",
      "priceSummary": "$37 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI file or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 188,
        "pypiWeekly": 2865,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.gumloop.com/api-reference/getting-started",
      "llmsTxt": "https://docs.gumloop.com/llms.txt",
      "openapi": "https://docs.gumloop.com/api-reference/openapi.yaml",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.webhooks",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "paid",
        "openapi",
        "llms-txt",
        "mcp",
        "oauth",
        "python",
        "cli",
        "webhooks",
        "agents",
        "approvals",
        "soc2",
        "enterprise"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61.6,
        "grade": "C",
        "agentReady": false,
        "rank": 419,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 77,
          "payments": 20,
          "reliability": 82,
          "schema": 83,
          "security": 50,
          "transparency": 57
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -2,
        "negativeNotes": [
          "2026-10-08. The API getting-started page says the Python and JavaScript SDKs 'wrap all of it'. The JavaScript SDK page documents only `runFlow`, and the npm package `gumloop` is 1.0.2 from 30 December 2024 (https://docs.gumloop.com/api-reference/getting-started.md, https://registry.npmjs.org/gumloop). 2 points for a misleading claim."
        ],
        "verdict": "Gumloop's REST API has a public OpenAPI file with 105 operations, Markdown docs and a changelog with 28 dated releases since 9 July 2026. API keys need the $37 Pro plan, the trial needs a card, the key can travel in the URL, and self-serve content may be used to train Gumloop's models.",
        "bestFor": "A team that wants hosted agents with connectors, approvals and triggers, driven or configured by an outside agent through the API or MCP server.",
        "strengths": [
          "OpenAPI 3.0 file with 105 operations on 83 paths, and every docs page served as Markdown with `llms.txt` and `llms-full.txt`",
          "Per-unit prices are public. One credit is $0.005, compute is 5 credits a session-minute and a connector call is 1 credit",
          "Tool approvals can be set per connector or per tool, and a paused session can be approved or rejected through `POST /sessions/{session_id}/approvals`",
          "28 dated changelog releases between 9 July and 7 October 2026, and the Python SDK reached 0.5.5 on 8 October 2026",
          "Status page on incident.io with Platform and API components and no incident reported from July to October 2026"
        ],
        "weaknesses": [
          "API keys and the `gumloop_api` OAuth scope need the Pro plan at $37 a month. The 14-day trial needs a card",
          "The docs call the API key in the URL query string the default method, and a webhook trigger's secret is part of its URL",
          "The privacy policy of 11 June 2026 says self-serve content, Pro and trials included, may be used to train Gumloop's AI models",
          "The npm package `gumloop` is still 1.0.2 from 30 December 2024 and only runs legacy flows, while the docs say both SDKs wrap the whole API",
          "No SLA and no per-request rate limit found. On Pro, a 26th concurrent run is rejected with HTTP 429 and skipped for triggers"
        ],
        "agentNotes": [
          "Send the key as `Authorization: Bearer` and, for a personal key, add the `x-auth-key` header with the user ID. Do not put `api_key` in the URL",
          "Create sessions with `POST /agents/{agent_id}/sessions`, then poll `GET /sessions/{session_id}`. A 202 means processing or queued, and the reply is not in the response",
          "Supply your own `session_id` when creating a session. A repeat returns 409, which makes a retry safe",
          "For streamed output send the same body with `stream: true` to `ws.gumloop.com`. `api.gumloop.com` answers 400 to it",
          "Treat a webhook trigger URL as a password. It returns `{\"success\": true}` at once and never carries the agent's output"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61.6
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 77,
          "payments": 20,
          "reliability": 82,
          "schema": 83,
          "security": 50,
          "transparency": 41
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "uv add gumloop",
        "http": "curl -X POST 'https://api.gumloop.com/api/v1/agents/abc123DEFghiJKL/sessions' -H 'Authorization: Bearer YOUR_ACCESS_TOKEN' -H 'Content-Type: application/json' -d '{\"input\": \"Research Acme Corp and draft a brief.\"}'",
        "config": {
          "mcpServers": {
            "gumloop": {
              "args": [
                "-y",
                "mcp-remote",
                "https://mcp.gumloop.com/gumloop/mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/gumloop"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 37,
          "note": "20,000 credits a month, unlimited seats and agents, 25 concurrent agent interactions, API keys included"
        },
        {
          "item": "Credit (overage and list price)",
          "unit": "credit",
          "usd": 0.005,
          "note": "Pro overage is capped at 1,000,000 credits a billing period. Model calls bill at provider cost divided by $0.005"
        },
        {
          "item": "Agent compute",
          "unit": "session-hour",
          "usd": 1.5,
          "note": "5 credits per session-minute of active processing, minimum 1 credit a response, before the 8 per cent orchestration fee"
        },
        {
          "item": "Connector tool call",
          "unit": "call",
          "usd": 0.005,
          "note": "1 credit per successful call, plus the tool's own charge for enrichment or scraping tools. Failed calls are free"
        }
      ],
      "provenance": {
        "legalEntity": "AgentHub Inc. (doing business as Gumloop)",
        "domain": "gumloop.com",
        "domainRegistered": "2024-04-25",
        "endpointOnVendorDomain": true,
        "terms": "https://www.gumloop.com/tos",
        "privacy": "https://www.gumloop.com/privacy-policy",
        "statusPage": "https://status.gumloop.com",
        "changelog": "https://www.gumloop.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last updated 11/06/2026, read as 11 June 2026) and the privacy policy (effective the same date) both name AgentHub Inc. (doing business as Gumloop). The terms are governed by Delaware law. No postal address was found in the passages read.",
          "The terms of service are the only published agreement for self-serve customers. They open as terms for the web pages at gumloop.com and also cover subscriptions, the content licence and AI training. Enterprise customers sign a separate agreement that is not published.",
          "The API answers at api.gumloop.com, streaming at ws.gumloop.com and the MCP server at mcp.gumloop.com.",
          "https://www.gumloop.com/.well-known/security.txt returned 404 on 8 October 2026.",
          "RDAP for gumloop.com gives a registration date of 2024-04-25.",
          "status.gumloop.com is on incident.io with Platform, API and four external AI provider components."
        ],
        "score": 72
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/gumloop.json",
      "live": {
        "slug": "gumloop",
        "probe": {
          "target": "https://api.gumloop.com/api/v1",
          "method": "get",
          "lastAt": "2026-10-09T11:46:30.232226546Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 180,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 180,
          "p95ms24h": 201,
          "samples24h": 44,
          "samples30d": 44,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 44,
              "ok": 44
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.gumloop.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T11:39:31.553693711Z"
        },
        "updatedAt": "2026-10-09T11:46:30.232226546Z"
      }
    },
    "answer": "Kestra scores 63.6 (B) on agent readiness against Gumloop's 61.6 (C), and leads in 5 of 7 scored categories. Gumloop leads on security \u0026 auth.",
    "b": {
      "slug": "kestra",
      "name": "Kestra",
      "vendor": "Kestra Technologies",
      "vendorUrl": "https://kestra.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Kestra is an open-source workflow orchestrator from Kestra Technologies. Flows are written in YAML and run on a server the owner hosts, with a REST API, SDKs in four languages and flows exposed as MCP tools.",
      "url": "https://www.anchorterminal.com/tools/kestra",
      "markdownUrl": "https://www.anchorterminal.com/tools/kestra.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kestra.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kestra.json",
      "repo": "https://github.com/kestra-io/kestra",
      "license": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "kestra/kestra"
        },
        {
          "registry": "pypi",
          "name": "kestrapy"
        },
        {
          "registry": "npm",
          "name": "@kestra-io/kestra-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "The open-source edition takes HTTP Basic auth with one username and password, set in `kestra.server.basic-auth` or on the setup page at first start. That credential has full access. Bearer API tokens, service accounts, OAuth, SSO and role-based access are in the Enterprise Edition and Kestra Cloud only. Access to open source is self-serve, by running the server. Webhook triggers are called with a key in the URL path.",
      "pricing": "freemium",
      "pricingNotes": "The open-source edition is free under Apache-2.0 with unlimited flows and executions, and an agent can start on it with no contract or account. Enterprise Edition is an annual subscription per instance through sales, with no public price. Kestra Cloud is by access request, with 14 days free and no card, then billed on task runs and Cloud runner time at rates that are not published (https://kestra.io/pricing, checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 29427,
        "npmWeekly": 244,
        "pypiWeekly": 170,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://kestra.io/docs",
      "llmsTxt": "https://kestra.io/llms.txt",
      "openapi": "https://kestra.io/kestra.yml",
      "capabilities": [
        "automation.workflows",
        "automation.code",
        "automation.webhooks",
        "automation.apps",
        "agent.tools"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "local",
        "hosted",
        "freemium",
        "openapi",
        "llms-txt",
        "mcp",
        "python",
        "typescript",
        "java",
        "go",
        "webhooks",
        "enterprise",
        "soc2"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.6,
        "grade": "B",
        "agentReady": false,
        "rank": 351,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -7,
        "negativeNotes": [
          "Five advisories rated critical were published on the repository in six months. GHSA-365w-2m69-mp9x (CVE-2026-34612, remote code execution through SQL injection, 30 March 2026), GHSA-5vc5-wxxq-3fjx and GHSA-2q47-568g-9h4f (CVE-2026-49869 and CVE-2026-53576, unauthenticated remote code execution through authentication filter bypass, 3 June 2026), and GHSA-rjhm-qm6w-m7x9 and GHSA-j5cv-8rw9-vv2p (unauthenticated remote code execution and authentication bypass, 29 September 2026). All are fixed, in 1.3.38 and 1.0.60 at the latest, and the maintainers published each one, so the deduction is reduced (https://github.com/kestra-io/kestra/security/advisories).",
          "Two further high advisories affected the default open-source setup. GHSA-hrr4-xg8h-5p6f, an unauthenticated gRPC control plane on port 50051, fixed in 2.0.3 and published 29 September 2026, and GHSA-94pv-f379-3gp3, a revoked administrator credential that stayed valid, fixed in 1.3.41 and published 6 October 2026 (https://github.com/kestra-io/kestra/security/advisories)."
        ],
        "verdict": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.",
        "bestFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "strengths": [
          "OpenAPI 3.0.1 spec for the open-source API with 216 operations, 213 of them documenting 401, 403 and 500 as problem+json",
          "Every docs page is served as Markdown by adding `.md`, with `llms.txt` and `llms-full.txt`",
          "32 releases between 15 July and 5 October 2026, with patches each week on the 1.3 and 2.0 long-term support lines",
          "Any flow becomes an MCP tool through `McpToolTrigger`, with read-only, destructive and idempotent hints set per flow",
          "Apache-2.0 server, and usage reporting documented field by field with two switches to turn it off"
        ],
        "weaknesses": [
          "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud",
          "Five critical advisories from 30 March to 29 September 2026, four of them unauthenticated remote code execution or authentication bypass, all fixed",
          "Kestra Cloud is request-access with no public price, and Enterprise is sold by annual contract through sales",
          "No rate limits and no idempotency key on the API. The correlation ID pattern needs a guard written into the flow",
          "The docs say `kestrapy` 2.0.1 imports `regex` without declaring it, so a plain install fails on import"
        ],
        "agentNotes": [
          "Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3",
          "Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port",
          "Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`",
          "Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call",
          "Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.6
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 86
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "docker run --pull=always --rm -it -p 8080:8080 --user=root --name kestra -v kestra_data:/app/storage -v kestra_db:/app/data -v /var/run/docker.sock:/var/run/docker.sock -v /tmp:/tmp -e KESTRA_PLUGINS_AUTO_INSTALL_ENABLED=true kestra/kestra:latest-slim server local",
        "http": "curl -X POST -u 'admin@kestra.io:kestra' http://localhost:8080/api/v1/main/executions/company.team/hello_world",
        "claudeCode": "claude mcp add \u003cserver-id\u003e \u003cserver-url\u003e --transport http --header \"Authorization: Basic $(echo -n 'username:password' | base64)\""
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/kestra"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Kestra Technologies SAS",
        "domain": "kestra.io",
        "domainRegistered": "2019-12-18",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/kestra-io/kestra/releases",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Cloud terms name Kestra Technologies SAS (RCS 900 427 873), 81 rue du Pré Catelan, 59110 La Madeleine, France, and Kestra Technologies Inc., a Delaware corporation, for customers billed in the Americas.",
          "No terms or privacy link is given because the edition graded is Apache-2.0 software the owner runs. The Kestra Cloud Terms of Service and Kestra Cloud Privacy Policy (both 14 September 2026) say they do not cover the open-source project, and the privacy policy at kestra.io/privacy-policy covers only the website.",
          "The API answers on the owner's own host. Only the documentation MCP server (api.kestra.io) and the usage reports go to a Kestra domain.",
          "https://kestra.io/.well-known/security.txt names security@kestra.io and the GitHub advisory form, and expires on 26 August 2028.",
          "RDAP for kestra.io gives a registration date of 2019-12-18.",
          "status.kestra.io did not answer our requests on 8 October 2026 and no status page is linked from the pricing, security or Cloud pages."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kestra.json"
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "AgentHub Inc.",
        "b": "Kestra Technologies",
        "name": "Vendor"
      },
      {
        "a": "https://api.gumloop.com/api/v1",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Gumloop's terms of service. The Python SDK and CLI repository and the npm package are Apache-2.0",
        "b": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-08",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "188 npm/wk, 2.9k PyPI/wk",
        "b": "29k stars, 244 npm/wk, 170 PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Kestra scores 63.6 (B) on agent readiness against Gumloop's 61.6 (C), and leads in 5 of 7 scored categories. Gumloop leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Gumloop or Kestra?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Gumloop and Kestra need an API key?"
      },
      {
        "answer": "Gumloop has a hosted endpoint at https://api.gumloop.com/api/v1. No hosted endpoint is listed for Kestra.",
        "question": "Can an agent call Gumloop and Kestra without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Gumloop. Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial).",
        "question": "Are Gumloop and Kestra open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 50 against 41"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "A team that wants hosted agents with connectors, approvals and triggers, driven or configured by an outside agent through the API or MCP server.",
        "slug": "gumloop",
        "watchFor": "API keys and the `gumloop_api` OAuth scope need the Pro plan at $37 a month. The 14-day trial needs a card"
      },
      {
        "aheadOn": [
          "Reliability, 89 against 82",
          "Agent ergonomics, 73 against 66",
          "Payments \u0026 pricing, 50 against 20",
          "Maintenance \u0026 community, 93 against 77",
          "Transparency \u0026 trust, 69 against 57"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "slug": "kestra",
        "watchFor": "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud"
      }
    ],
    "job": {
      "capability": "automation.workflows",
      "name": "Automation workflows"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-gumloop.json",
        "title": "Activepieces API + MCP vs Gumloop",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-gumloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-kestra.json",
        "title": "Activepieces API + MCP vs Kestra",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-kestra"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-make.json",
        "title": "Gumloop vs Make API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-make"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-n8n.json",
        "title": "Gumloop vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-paragon.json",
        "title": "Gumloop vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-pipedream.json",
        "title": "Gumloop vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-power-automate.json",
        "title": "Gumloop vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-tray.json",
        "title": "Gumloop vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-windmill.json",
        "title": "Gumloop vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-workato.json",
        "title": "Gumloop vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-make.json",
        "title": "Kestra vs Make API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-make"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-n8n.json",
        "title": "Kestra vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-paragon.json",
        "title": "Kestra vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-pipedream.json",
        "title": "Kestra vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-power-automate.json",
        "title": "Kestra vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-tray.json",
        "title": "Kestra vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-windmill.json",
        "title": "Kestra vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-workato.json",
        "title": "Kestra vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-workato"
      }
    ],
    "scores": [
      {
        "by": 7,
        "edge": "kestra",
        "gumloop": 82,
        "kestra": 89,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "edge": "gumloop",
        "gumloop": 83,
        "kestra": 82,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 7,
        "edge": "kestra",
        "gumloop": 66,
        "kestra": 73,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 9,
        "edge": "gumloop",
        "gumloop": 50,
        "kestra": 41,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 30,
        "edge": "kestra",
        "gumloop": 20,
        "kestra": 50,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 16,
        "edge": "kestra",
        "gumloop": 77,
        "kestra": 93,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 12,
        "edge": "kestra",
        "gumloop": 57,
        "kestra": 69,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Kestra scores 63.6 (B) on agent readiness against Gumloop's 61.6 (C), and leads in 5 of 7 scored categories. Gumloop leads on security \u0026 auth. Both do automation workflows.",
    "verdicts": {
      "gumloop": "Gumloop's REST API has a public OpenAPI file with 105 operations, Markdown docs and a changelog with 28 dated releases since 9 July 2026. API keys need the $37 Pro plan, the trial needs a card, the key can travel in the URL, and self-serve content may be used to train Gumloop's models.",
      "kestra": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/gumloop-vs-kestra",
    "json": "https://www.anchorterminal.com/compare/gumloop-vs-kestra.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/gumloop-vs-kestra.md",
    "slim": "https://www.anchorterminal.com/compare/gumloop-vs-kestra.min.md"
  },
  "markdown": "Kestra scores 63.6 (B) on agent readiness against Gumloop's 61.6 (C), and leads in 5 of 7 scored categories. Gumloop leads on security \u0026 auth. Both do automation workflows.\n\n- Gumloop: grade C, 61.6/100, rank #419 of 842. Markdown https://www.anchorterminal.com/tools/gumloop.md · JSON https://www.anchorterminal.com/api/v1/tools/gumloop.json\n- Kestra: grade B, 63.6/100, rank #351 of 842. Markdown https://www.anchorterminal.com/tools/kestra.md · JSON https://www.anchorterminal.com/api/v1/tools/kestra.json\n\n## Which one, for what\n\n### Gumloop (C)\n\nGood for: A team that wants hosted agents with connectors, approvals and triggers, driven or configured by an outside agent through the API or MCP server.\n\nAhead on:\n- Security \u0026 auth, 50 against 41\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: API keys and the `gumloop_api` OAuth scope need the Pro plan at $37 a month. The 14-day trial needs a card\n\n### Kestra (B)\n\nGood for: Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.\n\nAhead on:\n- Reliability, 89 against 82\n- Agent ergonomics, 73 against 66\n- Payments \u0026 pricing, 50 against 20\n- Maintenance \u0026 community, 93 against 77\n- Transparency \u0026 trust, 69 against 57\n\nAlso in its favour:\n- Open source\n\nWatch for: The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud\n\n\n## Score by category\n\n| Category | Weight | Gumloop | Kestra | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 82 | 89 | Kestra +7 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 83 | 82 | Gumloop +1 |\n| Agent ergonomics | 13% (16.2 this run) | 66 | 73 | Kestra +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 50 | 41 | Gumloop +9 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 50 | Kestra +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 77 | 93 | Kestra +16 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 57 | 69 | Kestra +12 |\n| Negative events | ≤15 | -2 | -7 | |\n| **Total** | | **61.6 · C** | **63.6 · B** | |\n\n## Facts side by side\n\n| Fact | Gumloop | Kestra |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | AgentHub Inc. | Kestra Technologies |\n| Hosted endpoint | `https://api.gumloop.com/api/v1` | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Gumloop's terms of service. The Python SDK and CLI repository and the npm package are Apache-2.0 | Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| Last release | 2026-10-08 | 2026-10-05 |\n| Terms last updated | no date given | no document linked |\n| Privacy policy last updated | no date given | no document linked |\n| Customer content may train models | yes |  |\n| Terms restrict automated access | yes |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 188 npm/wk, 2.9k PyPI/wk | 29k stars, 244 npm/wk, 170 PyPI/wk |\n\n## Verdicts\n\n**Gumloop.** Gumloop's REST API has a public OpenAPI file with 105 operations, Markdown docs and a changelog with 28 dated releases since 9 July 2026. API keys need the $37 Pro plan, the trial needs a card, the key can travel in the URL, and self-serve content may be used to train Gumloop's models.\n\n**Kestra.** Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.\n\n## Before you call either\n\n### Gumloop\n\n1. Send the key as `Authorization: Bearer` and, for a personal key, add the `x-auth-key` header with the user ID. Do not put `api_key` in the URL\n2. Create sessions with `POST /agents/{agent_id}/sessions`, then poll `GET /sessions/{session_id}`. A 202 means processing or queued, and the reply is not in the response\n3. Supply your own `session_id` when creating a session. A repeat returns 409, which makes a retry safe\n4. For streamed output send the same body with `stream: true` to `ws.gumloop.com`. `api.gumloop.com` answers 400 to it\n5. Treat a webhook trigger URL as a password. It returns `{\"success\": true}` at once and never carries the agent's output\n\n### Kestra\n\n1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3\n2. Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port\n3. Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`\n4. Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call\n5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth\n\n## Questions\n\n### Which is better for AI agents, Gumloop or Kestra?\n\nKestra scores 63.6 (B) on agent readiness against Gumloop's 61.6 (C), and leads in 5 of 7 scored categories. Gumloop leads on security \u0026 auth.\n\n### Do Gumloop and Kestra need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Gumloop and Kestra without installing anything?\n\nGumloop has a hosted endpoint at https://api.gumloop.com/api/v1. No hosted endpoint is listed for Kestra.\n\n### Are Gumloop and Kestra open source?\n\nNo open-source release is listed for Gumloop. Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/gumloop-vs-kestra.json, and with the fewest tokens: https://www.anchorterminal.com/compare/gumloop-vs-kestra.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"gumloop\", \"b\": \"kestra\"}`. From a terminal: `anchor compare gumloop kestra`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/gumloop.json and https://www.anchorterminal.com/api/v1/tools/kestra.json\n\n## Other comparisons with Gumloop or Kestra\n\n- [Activepieces API + MCP vs Gumloop](https://www.anchorterminal.com/compare/activepieces-vs-gumloop.md)\n- [Activepieces API + MCP vs Kestra](https://www.anchorterminal.com/compare/activepieces-vs-kestra.md)\n- [Gumloop vs Make API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-make.md)\n- [Gumloop vs n8n API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-n8n.md)\n- [Gumloop vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/gumloop-vs-paragon.md)\n- [Gumloop vs Pipedream API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-pipedream.md)\n- [Gumloop vs Microsoft Power Automate](https://www.anchorterminal.com/compare/gumloop-vs-power-automate.md)\n- [Gumloop vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-tray.md)\n- [Gumloop vs Windmill API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-windmill.md)\n- [Gumloop vs Workato API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-workato.md)\n- [Kestra vs Make API + MCP](https://www.anchorterminal.com/compare/kestra-vs-make.md)\n- [Kestra vs n8n API + MCP](https://www.anchorterminal.com/compare/kestra-vs-n8n.md)\n- [Kestra vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/kestra-vs-paragon.md)\n- [Kestra vs Pipedream API + MCP](https://www.anchorterminal.com/compare/kestra-vs-pipedream.md)\n- [Kestra vs Microsoft Power Automate](https://www.anchorterminal.com/compare/kestra-vs-power-automate.md)\n- [Kestra vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/kestra-vs-tray.md)\n- [Kestra vs Windmill API + MCP](https://www.anchorterminal.com/compare/kestra-vs-windmill.md)\n- [Kestra vs Workato API + MCP](https://www.anchorterminal.com/compare/kestra-vs-workato.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Gumloop vs Kestra",
        "url": ""
      }
    ],
    "description": "Kestra scores 63.6 (B) on agent readiness against Gumloop's 61.6 (C), and leads in 5 of 7 scored categories. Gumloop leads on security \u0026 auth. Both do automation workflows. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Gumloop C 61.6",
      "Kestra B 63.6",
      "scores"
    ],
    "h1": "Gumloop vs Kestra",
    "image": "https://www.anchorterminal.com/assets/og/compare-gumloop-vs-kestra.png",
    "path": "/compare/gumloop-vs-kestra",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Gumloop vs Kestra for AI agents, C 61.6 vs B 63.6 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/gumloop-vs-kestra"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 680
  },
  "version": 1
}
