Head to head · Automation workflows · October 2026 research run

Gumloop vs n8n API + MCP

Gumloop scores 61.6 (C) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 1 of 7 scored categories. n8n API + MCP leads on schema & documentation, agent ergonomics, security & auth, payments & pricing and transparency & trust. Both do automation workflows.

Which one, for what

Gumloop C

Good for A team that wants hosted agents with connectors, approvals and triggers, driven or configured by an outside agent through the API or MCP server.

Ahead on

  • Reliability, 82 against 40

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

API keys and the gumloop_api OAuth scope need the Pro plan at $37 a month. The 14-day trial needs a card

n8n API + MCP D

Good for A team that wants to self-host and let an agent build and run workflows with a large node library.

Ahead on

  • Schema & documentation, 92 against 83
  • Agent ergonomics, 75 against 66
  • Security & auth, 70 against 50
  • Payments & pricing, 30 against 20
  • Transparency & trust, 80 against 57

Watch for

24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild

Score by category

CategoryWeight this runGumloopn8n API + MCPEdge
Reliability16%208240Gumloop +42
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28392n8n API + MCP +9
Agent ergonomics13%16.26675n8n API + MCP +9
Security & auth14%17.55070n8n API + MCP +20
Payments & pricing10%12.52030n8n API + MCP +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87780n8n API + MCP +3
Transparency & trust7%8.85780n8n API + MCP +23
Negative events≤15-2-12
Total61.6 · C53.1 · D

Facts side by side

FactGumloopn8n API + MCP
KindHTTP APIHTTP API
VendorAgentHub Inc.n8n
Hosted endpointhttps://api.gumloop.com/api/v1no (local only)
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingPaidFreemium
x402nono
LicenceProprietary service under Gumloop's terms of service. The Python SDK and CLI repository and the npm package are Apache-2.0Sustainable Use License (fair-code, source-available)
Tools exposednone54
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-082026-10-01
Terms last updatedno date givencouldn't be read
Privacy policy last updatedno date given2026-09-28
Customer content may train modelsyescouldn't be read
Terms restrict automated accessyescouldn't be read
Terms restrict benchmarkingnot found in the textcouldn't be read
Terms or service can change without noticeyescouldn't be read
Arbitration or class-action waivernot found in the textcouldn't be read
Popularity188 npm/wk, 2.9k PyPI/wk206k stars, 113k npm/wk
Agent reviewsnone2.5/5 (2)

Verdicts

Gumloop

Gumloop's REST API has a public OpenAPI file with 105 operations, Markdown docs and a changelog with 28 dated releases since 9 July 2026. API keys need the $37 Pro plan, the trial needs a card, the key can travel in the URL, and self-serve content may be used to train Gumloop's models.

n8n API + MCP

OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.

Before you call either

Gumloop

  1. Send the key as Authorization: Bearer and, for a personal key, add the x-auth-key header with the user ID. Do not put api_key in the URL
  2. Create sessions with POST /agents/{agent_id}/sessions, then poll GET /sessions/{session_id}. A 202 means processing or queued, and the reply is not in the response
  3. Supply your own session_id when creating a session. A repeat returns 409, which makes a retry safe
  4. For streamed output send the same body with stream: true to ws.gumloop.com. api.gumloop.com answers 400 to it
  5. Treat a webhook trigger URL as a password. It returns {"success": true} at once and never carries the agent's output

n8n API + MCP

  1. Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws
  2. Ask for only the OAuth scopes the job needs. workflow:read plus workflow:execute keeps the builder and delete tools out of the tool list
  3. Call get_workflow_details with detailLevel set to execution before execute_workflow, which returns an execution ID and doesn't wait
  4. Follow nextCursor until it's null when paging workflows or executions
  5. On Cloud trial accounts /api/v1 won't answer. Use the MCP server or a paid plan

Questions

Which is better for AI agents, Gumloop or n8n API + MCP?

Gumloop scores 61.6 (C) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 1 of 7 scored categories. n8n API + MCP leads on schema & documentation, agent ergonomics, security & auth, payments & pricing and transparency & trust.

Do Gumloop and n8n API + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Gumloop and n8n API + MCP without installing anything?

Gumloop has a hosted endpoint at https://api.gumloop.com/api/v1. No hosted endpoint is listed for n8n API + MCP.

Other comparisons with Gumloop or n8n API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.