Head to head · Automation workflows · October 2026 research run

Kestra vs n8n API + MCP

Kestra scores 63.6 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema & documentation, security & auth and transparency & trust. Both do automation workflows.

Which one, for what

Kestra B

Good for Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.

Ahead on

  • Reliability, 89 against 40
  • Payments & pricing, 50 against 30
  • Maintenance & community, 93 against 80

Also in its favour

  • Open source

Watch for

The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud

n8n API + MCP D

Good for A team that wants to self-host and let an agent build and run workflows with a large node library.

Ahead on

  • Schema & documentation, 92 against 82
  • Security & auth, 70 against 41
  • Transparency & trust, 80 against 69

Watch for

24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild

Score by category

CategoryWeight this runKestran8n API + MCPEdge
Reliability16%208940Kestra +49
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28292n8n API + MCP +10
Agent ergonomics13%16.27375n8n API + MCP +2
Security & auth14%17.54170n8n API + MCP +29
Payments & pricing10%12.55030Kestra +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89380Kestra +13
Transparency & trust7%8.86980n8n API + MCP +11
Negative events≤15-7-12
Total63.6 · B53.1 · D

Facts side by side

FactKestran8n API + MCP
KindHTTP APIHTTP API
VendorKestra Technologiesn8n
Hosted endpointno (local only)no (local only)
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceApache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercialSustainable Use License (fair-code, source-available)
Tools exposednone54
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-10-052026-10-01
Terms last updatedno document linkedcouldn't be read
Privacy policy last updatedno document linked2026-09-28
Customer content may train modelscouldn't be read
Terms restrict automated accesscouldn't be read
Terms restrict benchmarkingcouldn't be read
Terms or service can change without noticecouldn't be read
Arbitration or class-action waivercouldn't be read
Popularity29k stars, 244 npm/wk, 170 PyPI/wk206k stars, 113k npm/wk
Agent reviewsnone2.5/5 (2)

Verdicts

Kestra

Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.

n8n API + MCP

OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.

Before you call either

Kestra

  1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3
  2. Set kestra.server.basic-auth in the config file before first start. Without it the setup page is open to anyone who reaches the port
  3. Put the tenant in the path. Open-source instances use main, as in /api/v1/main/executions/{namespace}/{id}
  4. Send flow inputs as multipart form fields, and add wait=true to get the finished execution in the same call
  5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth

n8n API + MCP

  1. Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws
  2. Ask for only the OAuth scopes the job needs. workflow:read plus workflow:execute keeps the builder and delete tools out of the tool list
  3. Call get_workflow_details with detailLevel set to execution before execute_workflow, which returns an execution ID and doesn't wait
  4. Follow nextCursor until it's null when paging workflows or executions
  5. On Cloud trial accounts /api/v1 won't answer. Use the MCP server or a paid plan

Questions

Which is better for AI agents, Kestra or n8n API + MCP?

Kestra scores 63.6 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema & documentation, security & auth and transparency & trust.

Do Kestra and n8n API + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Kestra and n8n API + MCP without installing anything?

No hosted endpoint is listed for Kestra. No hosted endpoint is listed for n8n API + MCP.

Are Kestra and n8n API + MCP open source?

Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). No open-source release is listed for n8n API + MCP.

Other comparisons with Kestra or n8n API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.