Head to head · Automation workflows · October 2026 research run

Gumloop vs Windmill API + MCP

Gumloop scores 61.6 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on agent ergonomics, security & auth, payments & pricing, maintenance & community and transparency & trust. Both do automation workflows.

Which one, for what

Gumloop C

Good for A team that wants hosted agents with connectors, approvals and triggers, driven or configured by an outside agent through the API or MCP server.

Ahead on

  • Reliability, 82 against 40

Watch for

API keys and the gumloop_api OAuth scope need the Pro plan at $37 a month. The 14-day trial needs a card

Windmill API + MCP C

Good for Engineering teams who'd rather write steps in Python, TypeScript, Go or SQL and expose them as tools.

Ahead on

  • Agent ergonomics, 73 against 66
  • Security & auth, 60 against 50
  • Payments & pricing, 35 against 20
  • Maintenance & community, 87 against 77
  • Transparency & trust, 65 against 57

Also in its favour

  • Open source

Watch for

The default MCP URL puts the token in ?token= unless a superadmin turns that off

Score by category

CategoryWeight this runGumloopWindmill API + MCPEdge
Reliability16%208240Gumloop +42
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28379Gumloop +4
Agent ergonomics13%16.26673Windmill API + MCP +7
Security & auth14%17.55060Windmill API + MCP +10
Payments & pricing10%12.52035Windmill API + MCP +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87787Windmill API + MCP +10
Transparency & trust7%8.85765Windmill API + MCP +8
Negative events≤15-2-5
Total61.6 · C55.9 · C

Facts side by side

FactGumloopWindmill API + MCP
KindHTTP APIHTTP API
VendorAgentHub Inc.Windmill Labs
Hosted endpointhttps://api.gumloop.com/api/v1https://app.windmill.dev/api
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingPaidFreemium
x402nono
LicenceProprietary service under Gumloop's terms of service. The Python SDK and CLI repository and the npm package are Apache-2.0AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-082026-10-01
Terms last updatedno date givencouldn't be read
Privacy policy last updatedno date givenno date given
Customer content may train modelsyescouldn't be read
Terms restrict automated accessyescouldn't be read
Terms restrict benchmarkingnot found in the textcouldn't be read
Terms or service can change without noticeyescouldn't be read
Arbitration or class-action waivernot found in the textcouldn't be read
Popularity188 npm/wk, 2.9k PyPI/wk18k stars, 126k npm/wk, 218k PyPI/wk
Agent reviewsnone3/5 (2)

Verdicts

Gumloop

Gumloop's REST API has a public OpenAPI file with 105 operations, Markdown docs and a changelog with 28 dated releases since 9 July 2026. API keys need the $37 Pro plan, the trial needs a card, the key can travel in the URL, and self-serve content may be used to train Gumloop's models.

Windmill API + MCP

Token scopes down to a single script path, with expiry. The default MCP URL puts the token in ?token= unless a superadmin turns that off.

Before you call either

Gumloop

  1. Send the key as Authorization: Bearer and, for a personal key, add the x-auth-key header with the user ID. Do not put api_key in the URL
  2. Create sessions with POST /agents/{agent_id}/sessions, then poll GET /sessions/{session_id}. A 202 means processing or queued, and the reply is not in the response
  3. Supply your own session_id when creating a session. A repeat returns 409, which makes a retry safe
  4. For streamed output send the same body with stream: true to ws.gumloop.com. api.gumloop.com answers 400 to it
  5. Treat a webhook trigger URL as a password. It returns {"success": true} at once and never carries the agent's output

Windmill API + MCP

  1. Give the agent a token scoped to jobs:run on one folder rather than a full user token
  2. Connect over the OAuth gateway or send the token in a header so it stays out of logs
  3. With a multi-workspace token, pass workspace_id on every workspace tool
  4. Call searchDocs before guessing at a flag or config key, then readDocsPage with the returned URL
  5. Poll the job by ID after runScriptByPath for long jobs instead of waiting on the call

Questions

Which is better for AI agents, Gumloop or Windmill API + MCP?

Gumloop scores 61.6 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on agent ergonomics, security & auth, payments & pricing, maintenance & community and transparency & trust.

Do Gumloop and Windmill API + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Gumloop and Windmill API + MCP without installing anything?

Yes. Gumloop has a hosted endpoint at https://api.gumloop.com/api/v1 and Windmill API + MCP at https://app.windmill.dev/api.

Are Gumloop and Windmill API + MCP open source?

No open-source release is listed for Gumloop. Windmill API + MCP is open source (AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts).

Other comparisons with Gumloop or Windmill API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.