{
  "data": {
    "a": {
      "slug": "kestra",
      "name": "Kestra",
      "vendor": "Kestra Technologies",
      "vendorUrl": "https://kestra.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Kestra is an open-source workflow orchestrator from Kestra Technologies. Flows are written in YAML and run on a server the owner hosts, with a REST API, SDKs in four languages and flows exposed as MCP tools.",
      "url": "https://www.anchorterminal.com/tools/kestra",
      "markdownUrl": "https://www.anchorterminal.com/tools/kestra.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kestra.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kestra.json",
      "repo": "https://github.com/kestra-io/kestra",
      "license": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "kestra/kestra"
        },
        {
          "registry": "pypi",
          "name": "kestrapy"
        },
        {
          "registry": "npm",
          "name": "@kestra-io/kestra-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "The open-source edition takes HTTP Basic auth with one username and password, set in `kestra.server.basic-auth` or on the setup page at first start. That credential has full access. Bearer API tokens, service accounts, OAuth, SSO and role-based access are in the Enterprise Edition and Kestra Cloud only. Access to open source is self-serve, by running the server. Webhook triggers are called with a key in the URL path.",
      "pricing": "freemium",
      "pricingNotes": "The open-source edition is free under Apache-2.0 with unlimited flows and executions, and an agent can start on it with no contract or account. Enterprise Edition is an annual subscription per instance through sales, with no public price. Kestra Cloud is by access request, with 14 days free and no card, then billed on task runs and Cloud runner time at rates that are not published (https://kestra.io/pricing, checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 29427,
        "npmWeekly": 244,
        "pypiWeekly": 170,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://kestra.io/docs",
      "llmsTxt": "https://kestra.io/llms.txt",
      "openapi": "https://kestra.io/kestra.yml",
      "capabilities": [
        "automation.workflows",
        "automation.code",
        "automation.webhooks",
        "automation.apps",
        "agent.tools"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "local",
        "hosted",
        "freemium",
        "openapi",
        "llms-txt",
        "mcp",
        "python",
        "typescript",
        "java",
        "go",
        "webhooks",
        "enterprise",
        "soc2"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.6,
        "grade": "B",
        "agentReady": false,
        "rank": 351,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -7,
        "negativeNotes": [
          "Five advisories rated critical were published on the repository in six months. GHSA-365w-2m69-mp9x (CVE-2026-34612, remote code execution through SQL injection, 30 March 2026), GHSA-5vc5-wxxq-3fjx and GHSA-2q47-568g-9h4f (CVE-2026-49869 and CVE-2026-53576, unauthenticated remote code execution through authentication filter bypass, 3 June 2026), and GHSA-rjhm-qm6w-m7x9 and GHSA-j5cv-8rw9-vv2p (unauthenticated remote code execution and authentication bypass, 29 September 2026). All are fixed, in 1.3.38 and 1.0.60 at the latest, and the maintainers published each one, so the deduction is reduced (https://github.com/kestra-io/kestra/security/advisories).",
          "Two further high advisories affected the default open-source setup. GHSA-hrr4-xg8h-5p6f, an unauthenticated gRPC control plane on port 50051, fixed in 2.0.3 and published 29 September 2026, and GHSA-94pv-f379-3gp3, a revoked administrator credential that stayed valid, fixed in 1.3.41 and published 6 October 2026 (https://github.com/kestra-io/kestra/security/advisories)."
        ],
        "verdict": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.",
        "bestFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "strengths": [
          "OpenAPI 3.0.1 spec for the open-source API with 216 operations, 213 of them documenting 401, 403 and 500 as problem+json",
          "Every docs page is served as Markdown by adding `.md`, with `llms.txt` and `llms-full.txt`",
          "32 releases between 15 July and 5 October 2026, with patches each week on the 1.3 and 2.0 long-term support lines",
          "Any flow becomes an MCP tool through `McpToolTrigger`, with read-only, destructive and idempotent hints set per flow",
          "Apache-2.0 server, and usage reporting documented field by field with two switches to turn it off"
        ],
        "weaknesses": [
          "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud",
          "Five critical advisories from 30 March to 29 September 2026, four of them unauthenticated remote code execution or authentication bypass, all fixed",
          "Kestra Cloud is request-access with no public price, and Enterprise is sold by annual contract through sales",
          "No rate limits and no idempotency key on the API. The correlation ID pattern needs a guard written into the flow",
          "The docs say `kestrapy` 2.0.1 imports `regex` without declaring it, so a plain install fails on import"
        ],
        "agentNotes": [
          "Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3",
          "Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port",
          "Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`",
          "Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call",
          "Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.6
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 86
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "docker run --pull=always --rm -it -p 8080:8080 --user=root --name kestra -v kestra_data:/app/storage -v kestra_db:/app/data -v /var/run/docker.sock:/var/run/docker.sock -v /tmp:/tmp -e KESTRA_PLUGINS_AUTO_INSTALL_ENABLED=true kestra/kestra:latest-slim server local",
        "http": "curl -X POST -u 'admin@kestra.io:kestra' http://localhost:8080/api/v1/main/executions/company.team/hello_world",
        "claudeCode": "claude mcp add \u003cserver-id\u003e \u003cserver-url\u003e --transport http --header \"Authorization: Basic $(echo -n 'username:password' | base64)\""
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/kestra"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Kestra Technologies SAS",
        "domain": "kestra.io",
        "domainRegistered": "2019-12-18",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/kestra-io/kestra/releases",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Cloud terms name Kestra Technologies SAS (RCS 900 427 873), 81 rue du Pré Catelan, 59110 La Madeleine, France, and Kestra Technologies Inc., a Delaware corporation, for customers billed in the Americas.",
          "No terms or privacy link is given because the edition graded is Apache-2.0 software the owner runs. The Kestra Cloud Terms of Service and Kestra Cloud Privacy Policy (both 14 September 2026) say they do not cover the open-source project, and the privacy policy at kestra.io/privacy-policy covers only the website.",
          "The API answers on the owner's own host. Only the documentation MCP server (api.kestra.io) and the usage reports go to a Kestra domain.",
          "https://kestra.io/.well-known/security.txt names security@kestra.io and the GitHub advisory form, and expires on 26 August 2028.",
          "RDAP for kestra.io gives a registration date of 2019-12-18.",
          "status.kestra.io did not answer our requests on 8 October 2026 and no status page is linked from the pricing, security or Cloud pages."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kestra.json"
    },
    "answer": "Kestra scores 63.6 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust.",
    "b": {
      "slug": "n8n",
      "name": "n8n API + MCP",
      "vendor": "n8n",
      "vendorUrl": "https://n8n.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Workflow builder you can run on n8n Cloud or self-host.",
      "url": "https://www.anchorterminal.com/tools/n8n",
      "markdownUrl": "https://www.anchorterminal.com/tools/n8n.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/n8n.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/n8n.json",
      "repo": "https://github.com/n8n-io/n8n",
      "license": "Sustainable Use License (fair-code, source-available)",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "n8n"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST API takes an instance API key in the `X-N8N-API-KEY` header. Key scopes only on Enterprise. The instance MCP server at https://\u003cinstance\u003e/mcp-server/http takes OAuth (per-client grants you can revoke) or a bearer MCP token.",
      "pricing": "freemium",
      "pricingNotes": "Community Edition is free to self-host with unlimited executions. Cloud Starter €20 a month billed yearly (2,500 executions, 5 concurrent, 7-day execution logs), Pro €50 (10,000 executions, up to 50 concurrent, 30-day logs), Enterprise custom (200+ concurrent, 365 days of insights). Business €667 a month billed yearly (40,000 executions) is self-hosted only for now, with a Cloud waitlist, and extra 300,000 executions cost €4,000. Annual billing saves 17 per cent. The Cloud trial gives 1,000 executions with no card, but the API isn't available during it. An execution is one workflow run, whatever the step count (https://n8n.io/pricing/).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": 54,
      "popularity": {
        "githubStars": 206359,
        "npmWeekly": 112869,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.n8n.io/connect/n8n-api/",
      "llmsTxt": "https://docs.n8n.io/llms.txt",
      "openapi": "https://docs.n8n.io/connect/n8n-api/api-reference",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.code",
        "automation.webhooks",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "local",
        "freemium",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "webhooks",
        "enterprise",
        "source-available"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53.1,
        "grade": "D",
        "agentReady": false,
        "rank": 638,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 80,
          "payments": 30,
          "reliability": 40,
          "schema": 92,
          "security": 70,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -12,
        "negativeNotes": [
          "CVE-2025-68613 (GHSA-v98v-ff95-f3cp), code execution through workflow expressions for any authenticated user, published to NVD on 19 December 2025 (GitHub's advisory is dated 22 December) and added to CISA's Known Exploited Vulnerabilities catalogue on 11 March 2026 as exploited in the wild. Patched and documented (https://github.com/advisories/GHSA-v98v-ff95-f3cp, https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-68613, https://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=n8n\u0026hasKev).",
          "CVE-2026-21858 (GHSA-v4pr-fm98-w9pg), unauthenticated file access through improper webhook handling, rated critical, published 7 January 2026, and CVE-2026-27493 (GHSA-75g8-rv7v-32f7), unauthenticated expression evaluation through the Form node, published 25 February 2026. Both patched (https://github.com/advisories?query=n8n+severity%3Acritical).",
          "24 critical advisories for the n8n package published between 8 December 2025 and 14 May 2026, counted on 2 October 2026 with the GitHub Advisory Database query cited here, most of them sandbox escapes or remote code execution, and high-severity batches still landing on 22 July, 10 September and 16 September 2026, including credential decryption without an ownership check (GHSA-9rhv-fhr8-7q5r). All handled in public with fixes, which is why this isn't the full -15 (https://github.com/advisories?query=type%3Areviewed+ecosystem%3Anpm+affects%3An8n+severity%3Acritical+published%3A2025-12-01..2026-05-31, https://github.com/n8n-io/n8n/security/advisories)."
        ],
        "verdict": "OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.",
        "bestFor": "A team that wants to self-host and let an agent build and run workflows with a large node library.",
        "strengths": [
          "OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt",
          "MCP OAuth grants split into scopes such as `workflow:read` and `workflow:execute`, revocable per client",
          "Priced per workflow run whatever the step count, and free to self-host with the API on",
          "n8n@2.42.2 on 1 October 2026 and 134 tags in 90 days, with the 1.x line still patched",
          "Valid security.txt, a disclosure policy, and advisories published with CVEs"
        ],
        "weaknesses": [
          "24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild",
          "No published API rate limit, 429 guidance or uptime SLA",
          "API key scopes only on Enterprise, and no API during the Cloud trial",
          "Sustainable Use License, not OSI open source, and self-hosted telemetry on by default",
          "54 MCP tools in the full set, heavy for a context window unless the grant is narrowed"
        ],
        "agentNotes": [
          "Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws",
          "Ask for only the OAuth scopes the job needs. `workflow:read` plus `workflow:execute` keeps the builder and delete tools out of the tool list",
          "Call `get_workflow_details` with `detailLevel` set to execution before `execute_workflow`, which returns an execution ID and doesn't wait",
          "Follow `nextCursor` until it's null when paging workflows or executions",
          "On Cloud trial accounts `/api/v1` won't answer. Use the MCP server or a paid plan"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53.1
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 80,
          "payments": 30,
          "reliability": 40,
          "schema": 92,
          "security": 70,
          "transparency": 68
        },
        "provenanceScore": 92
      },
      "connect": {
        "http": "curl \"https://$N8N_HOST/api/v1/workflows?active=true\" -H \"X-N8N-API-KEY: $N8N_API_KEY\"",
        "claudeCode": "claude mcp add --transport http n8n https://$N8N_HOST/mcp-server/http",
        "config": {
          "mcpServers": {
            "n8n": {
              "headers": {
                "Authorization": "Bearer ${N8N_MCP_TOKEN}"
              },
              "url": "https://${N8N_HOST}/mcp-server/http"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/n8n"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "n8n GmbH",
        "domain": "n8n.io",
        "domainRegistered": "2018-12-01",
        "endpointOnVendorDomain": true,
        "terms": "https://n8n.io/legal/",
        "privacy": "https://n8n.io/legal/privacy/",
        "statusPage": "https://status.n8n.cloud",
        "changelog": "https://docs.n8n.io/changelog/release-notes",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "score": 92
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/n8n.json",
      "live": {
        "slug": "n8n",
        "vendorStatus": {
          "page": "https://status.n8n.cloud",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:12.301190644Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "n8n-io/n8n",
            "version": "n8n@2.42.5",
            "released": "2026-10-08",
            "seenAt": "2026-10-08T16:22:14.697301662Z"
          },
          {
            "registry": "npm",
            "name": "n8n",
            "version": "2.42.5",
            "seenAt": "2026-10-08T16:22:14.445886062Z"
          }
        ],
        "githubStars": 206884,
        "npmWeekly": 141168,
        "securityTxt": {
          "url": "https://n8n.io/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-12-31T22:59:00.000Z",
          "checkedAt": "2026-10-08T15:38:33.181720219Z"
        },
        "llmsTxt": {
          "url": "https://docs.n8n.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:41.394510065Z"
        },
        "domain": {
          "domain": "n8n.io",
          "checkedAt": "2026-10-04T13:03:43.27003987Z"
        },
        "pages": [
          {
            "url": "https://docs.n8n.io/changelog/release-notes",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:10.749002669Z",
            "changedAt": "2026-10-08T18:19:10.749002669Z",
            "fingerprint": "2b4607263339"
          },
          {
            "url": "https://n8n.io/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:21.326786759Z",
            "changedAt": "2026-10-08T18:22:21.326786759Z",
            "fingerprint": "022f7f0733f4"
          },
          {
            "url": "https://n8n.io/legal/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:19.298327853Z",
            "changedAt": "2026-10-08T18:22:19.298327853Z",
            "fingerprint": "3f7af31472f0"
          },
          {
            "url": "https://n8n.io/legal/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:17.117114402Z",
            "changedAt": "2026-10-08T18:22:17.117114402Z",
            "fingerprint": "efd57140d437"
          }
        ],
        "updatedAt": "2026-10-09T07:58:12.301190644Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Kestra Technologies",
        "b": "n8n",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
        "b": "Sustainable Use License (fair-code, source-available)",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "54",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-05",
        "b": "2026-10-01",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "2026-09-28",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "29k stars, 244 npm/wk, 170 PyPI/wk",
        "b": "206k stars, 113k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Kestra scores 63.6 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Kestra or n8n API + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Kestra and n8n API + MCP need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Kestra. No hosted endpoint is listed for n8n API + MCP.",
        "question": "Can an agent call Kestra and n8n API + MCP without installing anything?"
      },
      {
        "answer": "Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). No open-source release is listed for n8n API + MCP.",
        "question": "Are Kestra and n8n API + MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 89 against 40",
          "Payments \u0026 pricing, 50 against 30",
          "Maintenance \u0026 community, 93 against 80"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "slug": "kestra",
        "watchFor": "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 92 against 82",
          "Security \u0026 auth, 70 against 41",
          "Transparency \u0026 trust, 80 against 69"
        ],
        "also": null,
        "goodFor": "A team that wants to self-host and let an agent build and run workflows with a large node library.",
        "slug": "n8n",
        "watchFor": "24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild"
      }
    ],
    "job": {
      "capability": "automation.workflows",
      "name": "Automation workflows"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-kestra.json",
        "title": "Activepieces API + MCP vs Kestra",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-kestra"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-n8n.json",
        "title": "Activepieces API + MCP vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-kestra.json",
        "title": "Gumloop vs Kestra",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-kestra"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-n8n.json",
        "title": "Gumloop vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-make.json",
        "title": "Kestra vs Make API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-make"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-paragon.json",
        "title": "Kestra vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-pipedream.json",
        "title": "Kestra vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-power-automate.json",
        "title": "Kestra vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-tray.json",
        "title": "Kestra vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-windmill.json",
        "title": "Kestra vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-workato.json",
        "title": "Kestra vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-n8n.json",
        "title": "Make API + MCP vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/make-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-paragon.json",
        "title": "n8n API + MCP vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-pipedream.json",
        "title": "n8n API + MCP vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-power-automate.json",
        "title": "n8n API + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-tray.json",
        "title": "n8n API + MCP vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-windmill.json",
        "title": "n8n API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-workato.json",
        "title": "n8n API + MCP vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-workato"
      }
    ],
    "scores": [
      {
        "by": 49,
        "edge": "kestra",
        "kestra": 89,
        "key": "reliability",
        "n8n": 40,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 10,
        "edge": "n8n",
        "kestra": 82,
        "key": "schema",
        "n8n": 92,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 2,
        "edge": "n8n",
        "kestra": 73,
        "key": "ergonomics",
        "n8n": 75,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 29,
        "edge": "n8n",
        "kestra": 41,
        "key": "security",
        "n8n": 70,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 20,
        "edge": "kestra",
        "kestra": 50,
        "key": "payments",
        "n8n": 30,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 13,
        "edge": "kestra",
        "kestra": 93,
        "key": "maintenance",
        "n8n": 80,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 11,
        "edge": "n8n",
        "kestra": 69,
        "key": "transparency",
        "n8n": 80,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Kestra scores 63.6 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust. Both do automation workflows.",
    "verdicts": {
      "kestra": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.",
      "n8n": "OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kestra-vs-n8n",
    "json": "https://www.anchorterminal.com/compare/kestra-vs-n8n.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kestra-vs-n8n.md",
    "slim": "https://www.anchorterminal.com/compare/kestra-vs-n8n.min.md"
  },
  "markdown": "Kestra scores 63.6 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust. Both do automation workflows.\n\n- Kestra: grade B, 63.6/100, rank #351 of 842. Markdown https://www.anchorterminal.com/tools/kestra.md · JSON https://www.anchorterminal.com/api/v1/tools/kestra.json\n- n8n API + MCP: grade D, 53.1/100, rank #638 of 842. Markdown https://www.anchorterminal.com/tools/n8n.md · JSON https://www.anchorterminal.com/api/v1/tools/n8n.json\n\n## Which one, for what\n\n### Kestra (B)\n\nGood for: Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.\n\nAhead on:\n- Reliability, 89 against 40\n- Payments \u0026 pricing, 50 against 30\n- Maintenance \u0026 community, 93 against 80\n\nAlso in its favour:\n- Open source\n\nWatch for: The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud\n\n### n8n API + MCP (D)\n\nGood for: A team that wants to self-host and let an agent build and run workflows with a large node library.\n\nAhead on:\n- Schema \u0026 documentation, 92 against 82\n- Security \u0026 auth, 70 against 41\n- Transparency \u0026 trust, 80 against 69\n\nWatch for: 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild\n\n\n## Score by category\n\n| Category | Weight | Kestra | n8n API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 89 | 40 | Kestra +49 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 92 | n8n API + MCP +10 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 75 | n8n API + MCP +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 41 | 70 | n8n API + MCP +29 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 30 | Kestra +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 93 | 80 | Kestra +13 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 80 | n8n API + MCP +11 |\n| Negative events | ≤15 | -7 | -12 | |\n| **Total** | | **63.6 · B** | **53.1 · D** | |\n\n## Facts side by side\n\n| Fact | Kestra | n8n API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Kestra Technologies | n8n |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial | Sustainable Use License (fair-code, source-available) |\n| Tools exposed | none | 54 |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-05 | 2026-10-01 |\n| Terms last updated | no document linked | couldn't be read |\n| Privacy policy last updated | no document linked | 2026-09-28 |\n| Customer content may train models |  | couldn't be read |\n| Terms restrict automated access |  | couldn't be read |\n| Terms restrict benchmarking |  | couldn't be read |\n| Terms or service can change without notice |  | couldn't be read |\n| Arbitration or class-action waiver |  | couldn't be read |\n| Popularity | 29k stars, 244 npm/wk, 170 PyPI/wk | 206k stars, 113k npm/wk |\n| Agent reviews | none | 2.5/5 (2) |\n\n## Verdicts\n\n**Kestra.** Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.\n\n**n8n API + MCP.** OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.\n\n## Before you call either\n\n### Kestra\n\n1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3\n2. Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port\n3. Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`\n4. Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call\n5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth\n\n### n8n API + MCP\n\n1. Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws\n2. Ask for only the OAuth scopes the job needs. `workflow:read` plus `workflow:execute` keeps the builder and delete tools out of the tool list\n3. Call `get_workflow_details` with `detailLevel` set to execution before `execute_workflow`, which returns an execution ID and doesn't wait\n4. Follow `nextCursor` until it's null when paging workflows or executions\n5. On Cloud trial accounts `/api/v1` won't answer. Use the MCP server or a paid plan\n\n## Questions\n\n### Which is better for AI agents, Kestra or n8n API + MCP?\n\nKestra scores 63.6 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust.\n\n### Do Kestra and n8n API + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Kestra and n8n API + MCP without installing anything?\n\nNo hosted endpoint is listed for Kestra. No hosted endpoint is listed for n8n API + MCP.\n\n### Are Kestra and n8n API + MCP open source?\n\nKestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). No open-source release is listed for n8n API + MCP.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kestra-vs-n8n.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kestra-vs-n8n.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kestra\", \"b\": \"n8n\"}`. From a terminal: `anchor compare kestra n8n`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kestra.json and https://www.anchorterminal.com/api/v1/tools/n8n.json\n\n## Other comparisons with Kestra or n8n API + MCP\n\n- [Activepieces API + MCP vs Kestra](https://www.anchorterminal.com/compare/activepieces-vs-kestra.md)\n- [Activepieces API + MCP vs n8n API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-n8n.md)\n- [Gumloop vs Kestra](https://www.anchorterminal.com/compare/gumloop-vs-kestra.md)\n- [Gumloop vs n8n API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-n8n.md)\n- [Kestra vs Make API + MCP](https://www.anchorterminal.com/compare/kestra-vs-make.md)\n- [Kestra vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/kestra-vs-paragon.md)\n- [Kestra vs Pipedream API + MCP](https://www.anchorterminal.com/compare/kestra-vs-pipedream.md)\n- [Kestra vs Microsoft Power Automate](https://www.anchorterminal.com/compare/kestra-vs-power-automate.md)\n- [Kestra vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/kestra-vs-tray.md)\n- [Kestra vs Windmill API + MCP](https://www.anchorterminal.com/compare/kestra-vs-windmill.md)\n- [Kestra vs Workato API + MCP](https://www.anchorterminal.com/compare/kestra-vs-workato.md)\n- [Make API + MCP vs n8n API + MCP](https://www.anchorterminal.com/compare/make-vs-n8n.md)\n- [n8n API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/n8n-vs-paragon.md)\n- [n8n API + MCP vs Pipedream API + MCP](https://www.anchorterminal.com/compare/n8n-vs-pipedream.md)\n- [n8n API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/n8n-vs-power-automate.md)\n- [n8n API + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/n8n-vs-tray.md)\n- [n8n API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/n8n-vs-windmill.md)\n- [n8n API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/n8n-vs-workato.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kestra vs n8n API + MCP",
        "url": ""
      }
    ],
    "description": "Kestra scores 63.6 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, security \u0026 auth and transparency \u0026 trust. Both do automation workflows. Category scores, facts, verdicts and agent…",
    "facts": [
      "Kestra B 63.6",
      "n8n API + MCP D 53.1",
      "scores"
    ],
    "h1": "Kestra vs n8n API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-kestra-vs-n8n.png",
    "path": "/compare/kestra-vs-n8n",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kestra vs n8n API + MCP for AI agents, B 63.6 vs D 53.1",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/kestra-vs-n8n"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 680
  },
  "version": 1
}
