{
  "data": {
    "a": {
      "slug": "gumloop",
      "name": "Gumloop",
      "vendor": "AgentHub Inc.",
      "vendorUrl": "https://www.gumloop.com",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Gumloop is a hosted platform from AgentHub Inc. for building AI agents that work across company apps and run on schedules, webhooks and app events. It has a REST API, a Python SDK, a CLI and a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/gumloop",
      "markdownUrl": "https://www.anchorterminal.com/tools/gumloop.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/gumloop.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/gumloop.json",
      "repo": "https://github.com/gumloop/gumloop-py",
      "license": "Proprietary service under Gumloop's terms of service. The Python SDK and CLI repository and the npm package are Apache-2.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.gumloop.com/api/v1",
      "packages": [
        {
          "registry": "pypi",
          "name": "gumloop"
        },
        {
          "registry": "npm",
          "name": "gumloop"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve API key on the Pro plan or above, created on the Connectors page in the app and sent as a bearer token. A personal key carries its owner's identity and also needs the `x-auth-key` header with the user ID. A team key can run as any team member named in `user_id`. OAuth 2.0 (authorisation code with PKCE, refresh tokens, revocation) is for apps other users sign in to, and client registration is by email to support. The key is also accepted as an `api_key` query parameter. Webhook triggers take no credential beyond the secret in their URL.",
      "pricing": "paid",
      "pricingNotes": "Pro is $37 a month with 20,000 credits, unlimited seats and API keys. No free plan is listed. The 14-day Pro trial needs a card and converts to a paid plan unless cancelled, so an agent cannot start without a person and a card. Usage is billed in credits at $0.005 each, with overage capped at 1,000,000 credits a period on Pro. Enterprise is priced through sales (https://www.gumloop.com/pricing, https://docs.gumloop.com/core-concepts/credits.md, checked 2026-10-08).",
      "priceSummary": "$37 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the OpenAPI file or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 188,
        "pypiWeekly": 2865,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.gumloop.com/api-reference/getting-started",
      "llmsTxt": "https://docs.gumloop.com/llms.txt",
      "openapi": "https://docs.gumloop.com/api-reference/openapi.yaml",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.webhooks",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "paid",
        "openapi",
        "llms-txt",
        "mcp",
        "oauth",
        "python",
        "cli",
        "webhooks",
        "agents",
        "approvals",
        "soc2",
        "enterprise"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61.6,
        "grade": "C",
        "agentReady": false,
        "rank": 419,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 77,
          "payments": 20,
          "reliability": 82,
          "schema": 83,
          "security": 50,
          "transparency": 57
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -2,
        "negativeNotes": [
          "2026-10-08. The API getting-started page says the Python and JavaScript SDKs 'wrap all of it'. The JavaScript SDK page documents only `runFlow`, and the npm package `gumloop` is 1.0.2 from 30 December 2024 (https://docs.gumloop.com/api-reference/getting-started.md, https://registry.npmjs.org/gumloop). 2 points for a misleading claim."
        ],
        "verdict": "Gumloop's REST API has a public OpenAPI file with 105 operations, Markdown docs and a changelog with 28 dated releases since 9 July 2026. API keys need the $37 Pro plan, the trial needs a card, the key can travel in the URL, and self-serve content may be used to train Gumloop's models.",
        "bestFor": "A team that wants hosted agents with connectors, approvals and triggers, driven or configured by an outside agent through the API or MCP server.",
        "strengths": [
          "OpenAPI 3.0 file with 105 operations on 83 paths, and every docs page served as Markdown with `llms.txt` and `llms-full.txt`",
          "Per-unit prices are public. One credit is $0.005, compute is 5 credits a session-minute and a connector call is 1 credit",
          "Tool approvals can be set per connector or per tool, and a paused session can be approved or rejected through `POST /sessions/{session_id}/approvals`",
          "28 dated changelog releases between 9 July and 7 October 2026, and the Python SDK reached 0.5.5 on 8 October 2026",
          "Status page on incident.io with Platform and API components and no incident reported from July to October 2026"
        ],
        "weaknesses": [
          "API keys and the `gumloop_api` OAuth scope need the Pro plan at $37 a month. The 14-day trial needs a card",
          "The docs call the API key in the URL query string the default method, and a webhook trigger's secret is part of its URL",
          "The privacy policy of 11 June 2026 says self-serve content, Pro and trials included, may be used to train Gumloop's AI models",
          "The npm package `gumloop` is still 1.0.2 from 30 December 2024 and only runs legacy flows, while the docs say both SDKs wrap the whole API",
          "No SLA and no per-request rate limit found. On Pro, a 26th concurrent run is rejected with HTTP 429 and skipped for triggers"
        ],
        "agentNotes": [
          "Send the key as `Authorization: Bearer` and, for a personal key, add the `x-auth-key` header with the user ID. Do not put `api_key` in the URL",
          "Create sessions with `POST /agents/{agent_id}/sessions`, then poll `GET /sessions/{session_id}`. A 202 means processing or queued, and the reply is not in the response",
          "Supply your own `session_id` when creating a session. A repeat returns 409, which makes a retry safe",
          "For streamed output send the same body with `stream: true` to `ws.gumloop.com`. `api.gumloop.com` answers 400 to it",
          "Treat a webhook trigger URL as a password. It returns `{\"success\": true}` at once and never carries the agent's output"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61.6
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 77,
          "payments": 20,
          "reliability": 82,
          "schema": 83,
          "security": 50,
          "transparency": 41
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "uv add gumloop",
        "http": "curl -X POST 'https://api.gumloop.com/api/v1/agents/abc123DEFghiJKL/sessions' -H 'Authorization: Bearer YOUR_ACCESS_TOKEN' -H 'Content-Type: application/json' -d '{\"input\": \"Research Acme Corp and draft a brief.\"}'",
        "config": {
          "mcpServers": {
            "gumloop": {
              "args": [
                "-y",
                "mcp-remote",
                "https://mcp.gumloop.com/gumloop/mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/gumloop"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 37,
          "note": "20,000 credits a month, unlimited seats and agents, 25 concurrent agent interactions, API keys included"
        },
        {
          "item": "Credit (overage and list price)",
          "unit": "credit",
          "usd": 0.005,
          "note": "Pro overage is capped at 1,000,000 credits a billing period. Model calls bill at provider cost divided by $0.005"
        },
        {
          "item": "Agent compute",
          "unit": "session-hour",
          "usd": 1.5,
          "note": "5 credits per session-minute of active processing, minimum 1 credit a response, before the 8 per cent orchestration fee"
        },
        {
          "item": "Connector tool call",
          "unit": "call",
          "usd": 0.005,
          "note": "1 credit per successful call, plus the tool's own charge for enrichment or scraping tools. Failed calls are free"
        }
      ],
      "provenance": {
        "legalEntity": "AgentHub Inc. (doing business as Gumloop)",
        "domain": "gumloop.com",
        "domainRegistered": "2024-04-25",
        "endpointOnVendorDomain": true,
        "terms": "https://www.gumloop.com/tos",
        "privacy": "https://www.gumloop.com/privacy-policy",
        "statusPage": "https://status.gumloop.com",
        "changelog": "https://www.gumloop.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (last updated 11/06/2026, read as 11 June 2026) and the privacy policy (effective the same date) both name AgentHub Inc. (doing business as Gumloop). The terms are governed by Delaware law. No postal address was found in the passages read.",
          "The terms of service are the only published agreement for self-serve customers. They open as terms for the web pages at gumloop.com and also cover subscriptions, the content licence and AI training. Enterprise customers sign a separate agreement that is not published.",
          "The API answers at api.gumloop.com, streaming at ws.gumloop.com and the MCP server at mcp.gumloop.com.",
          "https://www.gumloop.com/.well-known/security.txt returned 404 on 8 October 2026.",
          "RDAP for gumloop.com gives a registration date of 2024-04-25.",
          "status.gumloop.com is on incident.io with Platform, API and four external AI provider components."
        ],
        "score": 72
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/gumloop.json",
      "live": {
        "slug": "gumloop",
        "probe": {
          "target": "https://api.gumloop.com/api/v1",
          "method": "get",
          "lastAt": "2026-10-09T10:14:16.40913033Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 186,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 177,
          "p95ms24h": 201,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.gumloop.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T10:10:59.315854007Z"
        },
        "updatedAt": "2026-10-09T10:14:16.40913033Z"
      }
    },
    "answer": "Gumloop scores 61.6 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on agent ergonomics, security \u0026 auth, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
    "b": {
      "slug": "windmill",
      "name": "Windmill API + MCP",
      "vendor": "Windmill Labs",
      "vendorUrl": "https://www.windmill.dev",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Code-first engine for scripts, flows and internal apps in 20+ languages, written in Rust, on Windmill Cloud or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/windmill",
      "markdownUrl": "https://www.anchorterminal.com/tools/windmill.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/windmill.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/windmill.json",
      "repo": "https://github.com/windmill-labs/windmill",
      "license": "AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://app.windmill.dev/api",
      "packages": [
        {
          "registry": "npm",
          "name": "windmill-client"
        },
        {
          "registry": "pypi",
          "name": "wmill"
        }
      ],
      "auth": "mixed",
      "authNotes": "Bearer user tokens with optional scopes (`{domain}:{action}[:{path}]`, e.g. `jobs:run:flows`) and expiry. MCP by OAuth at /api/mcp/gateway, or a token either in the URL (`?token=`) or in an Authorization header. Admins can make the MCP endpoints refuse tokens in URLs.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosted Community Edition is free with unlimited executions (up to 50 users, 3 workspaces). Self-hosted Enterprise from $120 a month, priced as developer seats $20 a month, operators $10 and compute at $50 a month per standard 2 GB worker. Pro gets the same terms for companies under 10 staff and $250,000 revenue. Cloud has a free tier and paid Team and Enterprise workspaces billed on seats and compute (https://www.windmill.dev/pricing).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 18070,
        "npmWeekly": 126287,
        "pypiWeekly": 218343,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.windmill.dev/docs",
      "llmsTxt": "https://www.windmill.dev/llms.txt",
      "openapi": "https://app.windmill.dev/api/openapi.yaml",
      "capabilities": [
        "automation.workflows",
        "automation.code",
        "automation.webhooks",
        "automation.embedded",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "local",
        "freemium",
        "mcp",
        "llms-txt",
        "openapi",
        "python",
        "typescript",
        "webhooks",
        "enterprise"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.9,
        "grade": "C",
        "agentReady": false,
        "rank": 579,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 87,
          "payments": 35,
          "reliability": 40,
          "schema": 79,
          "security": 60,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "CVE-2026-23696, SQL injection in folder ownership management for any low-privilege user in Windmill 1.276.0 to 1.603.2, CVSS 4.0 score 9.4, exposing JWT secrets and admin identifiers. Fixed in 1.603.3 and published by NVD on 7 April 2026 (https://github.com/advisories/GHSA-34m2-qrpf-6v7q).",
          "GHSA-24fr-44f8-fqwg, published 2 March 2026, high. SUPERADMIN_SECRET could be read publicly through RCE on versions before 1.603.3. CVE-2026-22683, missing authorisation in 1.56.0 to 1.614.0, rated high on 7 April 2026. All fixed, so the deduction is reduced (https://github.com/windmill-labs/windmill/security/advisories, https://github.com/advisories?query=windmill)."
        ],
        "verdict": "Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off.",
        "bestFor": "Engineering teams who'd rather write steps in Python, TypeScript, Go or SQL and expose them as tools.",
        "strengths": [
          "Token scopes down to a single script path, with expiry",
          "OpenAPI 3.0.3 with 913 operations and Apache-2.0 clients for TypeScript, Python, Go and Rust",
          "Every script and flow is an MCP tool, filterable by folder and favourites",
          "97 tagged releases in 90 days, latest v1.821.0 on 1 October 2026",
          "Free unlimited executions on Cloud free workspaces and self-hosted Community Edition"
        ],
        "weaknesses": [
          "The default MCP URL puts the token in `?token=` unless a superadmin turns that off",
          "CVE-2026-23696, a critical SQL injection fixed in 1.603.3, had no Windmill advisory",
          "No published API rate limits, 429 guidance or uptime SLA",
          "The OpenAPI file documents errors for only about 30 operations",
          "No SECURITY.md or security.txt"
        ],
        "agentNotes": [
          "Give the agent a token scoped to `jobs:run` on one folder rather than a full user token",
          "Connect over the OAuth gateway or send the token in a header so it stays out of logs",
          "With a multi-workspace token, pass `workspace_id` on every workspace tool",
          "Call `searchDocs` before guessing at a flag or config key, then `readDocsPage` with the returned URL",
          "Poll the job by ID after `runScriptByPath` for long jobs instead of waiting on the call"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.9
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 87,
          "payments": 35,
          "reliability": 40,
          "schema": 79,
          "security": 60,
          "transparency": 51
        },
        "provenanceScore": 78
      },
      "connect": {
        "http": "curl \"https://app.windmill.dev/api/w/$WM_WORKSPACE/scripts/list\" -H \"Authorization: Bearer $WM_TOKEN\"",
        "claudeCode": "claude mcp add --transport http windmill https://app.windmill.dev/api/mcp/gateway",
        "config": {
          "mcpServers": {
            "windmill": {
              "headers": {
                "Authorization": "Bearer ${WM_TOKEN}"
              },
              "url": "https://app.windmill.dev/api/mcp/w/${WM_WORKSPACE}/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/windmill"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Developer seat (Enterprise)",
          "unit": "seat-month",
          "usd": 20
        },
        {
          "item": "Operator seat (Enterprise)",
          "unit": "seat-month",
          "usd": 10,
          "note": "run-only users and external JWT users"
        },
        {
          "item": "Compute (Enterprise)",
          "unit": "compute-unit",
          "usd": 25,
          "note": "$50 a month per standard 2 GB worker, which is 2 CU"
        },
        {
          "item": "Enterprise minimum",
          "unit": "month",
          "usd": 120,
          "note": "from price shown on the pricing page"
        }
      ],
      "provenance": {
        "legalEntity": "Windmill Labs, Inc.",
        "domain": "windmill.dev",
        "domainRegistered": "2022-01-06",
        "endpointOnVendorDomain": true,
        "terms": "https://www.windmill.dev/terms",
        "privacy": "https://www.windmill.dev/privacy_policy",
        "statusPage": "https://status.windmill.dev",
        "changelog": "https://www.windmill.dev/changelog",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "status.windmill.dev redirects to an UptimeRobot page."
        ],
        "score": 78
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/windmill.json",
      "live": {
        "slug": "windmill",
        "probe": {
          "target": "https://app.windmill.dev/api",
          "method": "get",
          "lastAt": "2026-10-09T10:14:32.726622978Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 196,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 189,
          "p95ms24h": 271,
          "samples24h": 260,
          "samples30d": 2295,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 109,
              "ok": 109
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.windmill.dev",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:41.048851882Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "windmill-labs/windmill",
            "version": "v1.828.0",
            "released": "2026-10-08",
            "seenAt": "2026-10-08T16:34:57.523072328Z"
          },
          {
            "registry": "npm",
            "name": "windmill-client",
            "version": "1.828.0",
            "seenAt": "2026-10-08T16:34:56.930406591Z"
          },
          {
            "registry": "pypi",
            "name": "wmill",
            "version": "1.828.0",
            "released": "2026-10-08",
            "seenAt": "2026-10-08T16:34:57.315141476Z"
          }
        ],
        "githubStars": 18137,
        "npmWeekly": 116203,
        "pypiWeekly": 213676,
        "securityTxt": {
          "url": "https://windmill.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:59.869602981Z"
        },
        "llmsTxt": {
          "url": "https://www.windmill.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:01:00.866846241Z"
        },
        "domain": {
          "domain": "windmill.dev",
          "registered": "2022-01-06",
          "source": "https://pubapi.registry.google/rdap/domain/windmill.dev",
          "checkedAt": "2026-10-04T13:08:55.755645623Z"
        },
        "pages": [
          {
            "url": "https://www.windmill.dev/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:31:36.542918048Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f07472d4d072"
          },
          {
            "url": "https://www.windmill.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:31:38.770165489Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "afa04f8b73f5"
          },
          {
            "url": "https://www.windmill.dev/privacy_policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:31:40.737161697Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d11624ab86ec"
          },
          {
            "url": "https://www.windmill.dev/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:31:42.693903067Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e3b0c44298fc"
          }
        ],
        "updatedAt": "2026-10-09T10:14:32.726622978Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "AgentHub Inc.",
        "b": "Windmill Labs",
        "name": "Vendor"
      },
      {
        "a": "https://api.gumloop.com/api/v1",
        "b": "https://app.windmill.dev/api",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Gumloop's terms of service. The Python SDK and CLI repository and the npm package are Apache-2.0",
        "b": "AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-08",
        "b": "2026-10-01",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "188 npm/wk, 2.9k PyPI/wk",
        "b": "18k stars, 126k npm/wk, 218k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Gumloop scores 61.6 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on agent ergonomics, security \u0026 auth, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Gumloop or Windmill API + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Gumloop and Windmill API + MCP need an API key?"
      },
      {
        "answer": "Yes. Gumloop has a hosted endpoint at https://api.gumloop.com/api/v1 and Windmill API + MCP at https://app.windmill.dev/api.",
        "question": "Can an agent call Gumloop and Windmill API + MCP without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Gumloop. Windmill API + MCP is open source (AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts).",
        "question": "Are Gumloop and Windmill API + MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 82 against 40"
        ],
        "also": null,
        "goodFor": "A team that wants hosted agents with connectors, approvals and triggers, driven or configured by an outside agent through the API or MCP server.",
        "slug": "gumloop",
        "watchFor": "API keys and the `gumloop_api` OAuth scope need the Pro plan at $37 a month. The 14-day trial needs a card"
      },
      {
        "aheadOn": [
          "Agent ergonomics, 73 against 66",
          "Security \u0026 auth, 60 against 50",
          "Payments \u0026 pricing, 35 against 20",
          "Maintenance \u0026 community, 87 against 77",
          "Transparency \u0026 trust, 65 against 57"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Engineering teams who'd rather write steps in Python, TypeScript, Go or SQL and expose them as tools.",
        "slug": "windmill",
        "watchFor": "The default MCP URL puts the token in `?token=` unless a superadmin turns that off"
      }
    ],
    "job": {
      "capability": "automation.workflows",
      "name": "Automation workflows"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-gumloop.json",
        "title": "Activepieces API + MCP vs Gumloop",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-gumloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-windmill.json",
        "title": "Activepieces API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-kestra.json",
        "title": "Gumloop vs Kestra",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-kestra"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-make.json",
        "title": "Gumloop vs Make API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-make"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-n8n.json",
        "title": "Gumloop vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-paragon.json",
        "title": "Gumloop vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-pipedream.json",
        "title": "Gumloop vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-power-automate.json",
        "title": "Gumloop vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-tray.json",
        "title": "Gumloop vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-workato.json",
        "title": "Gumloop vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-windmill.json",
        "title": "Kestra vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-windmill.json",
        "title": "Make API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/make-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-windmill.json",
        "title": "n8n API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pipedream-vs-windmill.json",
        "title": "Pipedream API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/pipedream-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/power-automate-vs-windmill.json",
        "title": "Microsoft Power Automate vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/power-automate-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/tray-vs-windmill.json",
        "title": "Tray.ai API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/tray-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/windmill-vs-workato.json",
        "title": "Windmill API + MCP vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/windmill-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paragon-vs-windmill.json",
        "title": "Paragon ActionKit + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/paragon-vs-windmill"
      }
    ],
    "scores": [
      {
        "by": 42,
        "edge": "gumloop",
        "gumloop": 82,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16,
        "windmill": 40
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "gumloop",
        "gumloop": 83,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13,
        "windmill": 79
      },
      {
        "by": 7,
        "edge": "windmill",
        "gumloop": 66,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13,
        "windmill": 73
      },
      {
        "by": 10,
        "edge": "windmill",
        "gumloop": 50,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14,
        "windmill": 60
      },
      {
        "by": 15,
        "edge": "windmill",
        "gumloop": 20,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10,
        "windmill": 35
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 10,
        "edge": "windmill",
        "gumloop": 77,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7,
        "windmill": 87
      },
      {
        "by": 8,
        "edge": "windmill",
        "gumloop": 57,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7,
        "windmill": 65
      }
    ],
    "summary": "Gumloop scores 61.6 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on agent ergonomics, security \u0026 auth, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do automation workflows.",
    "verdicts": {
      "gumloop": "Gumloop's REST API has a public OpenAPI file with 105 operations, Markdown docs and a changelog with 28 dated releases since 9 July 2026. API keys need the $37 Pro plan, the trial needs a card, the key can travel in the URL, and self-serve content may be used to train Gumloop's models.",
      "windmill": "Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/gumloop-vs-windmill",
    "json": "https://www.anchorterminal.com/compare/gumloop-vs-windmill.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/gumloop-vs-windmill.md",
    "slim": "https://www.anchorterminal.com/compare/gumloop-vs-windmill.min.md"
  },
  "markdown": "Gumloop scores 61.6 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on agent ergonomics, security \u0026 auth, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do automation workflows.\n\n- Gumloop: grade C, 61.6/100, rank #419 of 842. Markdown https://www.anchorterminal.com/tools/gumloop.md · JSON https://www.anchorterminal.com/api/v1/tools/gumloop.json\n- Windmill API + MCP: grade C, 55.9/100, rank #579 of 842. Markdown https://www.anchorterminal.com/tools/windmill.md · JSON https://www.anchorterminal.com/api/v1/tools/windmill.json\n\n## Which one, for what\n\n### Gumloop (C)\n\nGood for: A team that wants hosted agents with connectors, approvals and triggers, driven or configured by an outside agent through the API or MCP server.\n\nAhead on:\n- Reliability, 82 against 40\n\nWatch for: API keys and the `gumloop_api` OAuth scope need the Pro plan at $37 a month. The 14-day trial needs a card\n\n### Windmill API + MCP (C)\n\nGood for: Engineering teams who'd rather write steps in Python, TypeScript, Go or SQL and expose them as tools.\n\nAhead on:\n- Agent ergonomics, 73 against 66\n- Security \u0026 auth, 60 against 50\n- Payments \u0026 pricing, 35 against 20\n- Maintenance \u0026 community, 87 against 77\n- Transparency \u0026 trust, 65 against 57\n\nAlso in its favour:\n- Open source\n\nWatch for: The default MCP URL puts the token in `?token=` unless a superadmin turns that off\n\n\n## Score by category\n\n| Category | Weight | Gumloop | Windmill API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 82 | 40 | Gumloop +42 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 83 | 79 | Gumloop +4 |\n| Agent ergonomics | 13% (16.2 this run) | 66 | 73 | Windmill API + MCP +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 50 | 60 | Windmill API + MCP +10 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 35 | Windmill API + MCP +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 77 | 87 | Windmill API + MCP +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 57 | 65 | Windmill API + MCP +8 |\n| Negative events | ≤15 | -2 | -5 | |\n| **Total** | | **61.6 · C** | **55.9 · C** | |\n\n## Facts side by side\n\n| Fact | Gumloop | Windmill API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | AgentHub Inc. | Windmill Labs |\n| Hosted endpoint | `https://api.gumloop.com/api/v1` | `https://app.windmill.dev/api` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Gumloop's terms of service. The Python SDK and CLI repository and the npm package are Apache-2.0 | AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-08 | 2026-10-01 |\n| Terms last updated | no date given | couldn't be read |\n| Privacy policy last updated | no date given | no date given |\n| Customer content may train models | yes | couldn't be read |\n| Terms restrict automated access | yes | couldn't be read |\n| Terms restrict benchmarking | not found in the text | couldn't be read |\n| Terms or service can change without notice | yes | couldn't be read |\n| Arbitration or class-action waiver | not found in the text | couldn't be read |\n| Popularity | 188 npm/wk, 2.9k PyPI/wk | 18k stars, 126k npm/wk, 218k PyPI/wk |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Gumloop.** Gumloop's REST API has a public OpenAPI file with 105 operations, Markdown docs and a changelog with 28 dated releases since 9 July 2026. API keys need the $37 Pro plan, the trial needs a card, the key can travel in the URL, and self-serve content may be used to train Gumloop's models.\n\n**Windmill API + MCP.** Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off.\n\n## Before you call either\n\n### Gumloop\n\n1. Send the key as `Authorization: Bearer` and, for a personal key, add the `x-auth-key` header with the user ID. Do not put `api_key` in the URL\n2. Create sessions with `POST /agents/{agent_id}/sessions`, then poll `GET /sessions/{session_id}`. A 202 means processing or queued, and the reply is not in the response\n3. Supply your own `session_id` when creating a session. A repeat returns 409, which makes a retry safe\n4. For streamed output send the same body with `stream: true` to `ws.gumloop.com`. `api.gumloop.com` answers 400 to it\n5. Treat a webhook trigger URL as a password. It returns `{\"success\": true}` at once and never carries the agent's output\n\n### Windmill API + MCP\n\n1. Give the agent a token scoped to `jobs:run` on one folder rather than a full user token\n2. Connect over the OAuth gateway or send the token in a header so it stays out of logs\n3. With a multi-workspace token, pass `workspace_id` on every workspace tool\n4. Call `searchDocs` before guessing at a flag or config key, then `readDocsPage` with the returned URL\n5. Poll the job by ID after `runScriptByPath` for long jobs instead of waiting on the call\n\n## Questions\n\n### Which is better for AI agents, Gumloop or Windmill API + MCP?\n\nGumloop scores 61.6 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on agent ergonomics, security \u0026 auth, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust.\n\n### Do Gumloop and Windmill API + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Gumloop and Windmill API + MCP without installing anything?\n\nYes. Gumloop has a hosted endpoint at https://api.gumloop.com/api/v1 and Windmill API + MCP at https://app.windmill.dev/api.\n\n### Are Gumloop and Windmill API + MCP open source?\n\nNo open-source release is listed for Gumloop. Windmill API + MCP is open source (AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/gumloop-vs-windmill.json, and with the fewest tokens: https://www.anchorterminal.com/compare/gumloop-vs-windmill.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"gumloop\", \"b\": \"windmill\"}`. From a terminal: `anchor compare gumloop windmill`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/gumloop.json and https://www.anchorterminal.com/api/v1/tools/windmill.json\n\n## Other comparisons with Gumloop or Windmill API + MCP\n\n- [Activepieces API + MCP vs Gumloop](https://www.anchorterminal.com/compare/activepieces-vs-gumloop.md)\n- [Activepieces API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-windmill.md)\n- [Gumloop vs Kestra](https://www.anchorterminal.com/compare/gumloop-vs-kestra.md)\n- [Gumloop vs Make API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-make.md)\n- [Gumloop vs n8n API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-n8n.md)\n- [Gumloop vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/gumloop-vs-paragon.md)\n- [Gumloop vs Pipedream API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-pipedream.md)\n- [Gumloop vs Microsoft Power Automate](https://www.anchorterminal.com/compare/gumloop-vs-power-automate.md)\n- [Gumloop vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-tray.md)\n- [Gumloop vs Workato API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-workato.md)\n- [Kestra vs Windmill API + MCP](https://www.anchorterminal.com/compare/kestra-vs-windmill.md)\n- [Make API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/make-vs-windmill.md)\n- [n8n API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/n8n-vs-windmill.md)\n- [Pipedream API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/pipedream-vs-windmill.md)\n- [Microsoft Power Automate vs Windmill API + MCP](https://www.anchorterminal.com/compare/power-automate-vs-windmill.md)\n- [Tray.ai API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/tray-vs-windmill.md)\n- [Windmill API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/windmill-vs-workato.md)\n- [Paragon ActionKit + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/paragon-vs-windmill.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Gumloop vs Windmill API + MCP",
        "url": ""
      }
    ],
    "description": "Gumloop scores 61.6 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on agent ergonomics, security \u0026 auth, payments \u0026 pricing, maintenance \u0026 community and transparency \u0026 trust. Both do automation…",
    "facts": [
      "Gumloop C 61.6",
      "Windmill API + MCP C 55.9",
      "scores"
    ],
    "h1": "Gumloop vs Windmill API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-gumloop-vs-windmill.png",
    "path": "/compare/gumloop-vs-windmill",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Gumloop vs Windmill API + MCP for AI agents, C 61.6 vs C 55.9",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/gumloop-vs-windmill"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 730
  },
  "version": 1
}
