Head to head · Workflow automation · October 2026 research run

Kestra vs Node-RED

Kestra scores 63.6 (B) on agent readiness against Node-RED's 61 (C), and leads in 4 of 7 scored categories. Node-RED leads on security & auth and payments & pricing. Both do workflow automation.

Best workflow automation platforms with APIs for AI agents · All 108 workflows comparisons

Which one, for what

Kestra B

Good for Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.

Ahead on

  • Schema & documentation, 82 against 41
  • Agent ergonomics, 73 against 44
  • Maintenance & community, 93 against 81

Watch for

The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud

Node-RED C

Good for Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.

Ahead on

  • Security & auth, 51 against 41
  • Payments & pricing, 60 against 50

Also in its favour

  • No incidents deducted, where Kestra loses 7 points for them

Watch for

No OpenAPI file, llms.txt or SDK. The Admin API is documented as 20 hand-written pages on nodered.org

Score by category

CategoryWeight this runKestraNode-REDEdge
Reliability16%208990Node-RED +1
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28241Kestra +41
Agent ergonomics13%16.27344Kestra +29
Security & auth14%17.54151Node-RED +10
Payments & pricing10%12.55060Node-RED +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89381Kestra +12
Transparency & trust7%8.86965Kestra +4
Negative events≤15-70
Total63.6 · B61 · C

Facts side by side

FactKestraNode-RED
KindHTTP APIHTTP API
VendorKestra TechnologiesOpenJS Foundation
Hosted endpointno (local only)no (local only)
TransportsHTTP, Streamable HTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFree
x402nono
LicenceApache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercialApache-2.0
Read-only variant documentedyesno
llms.txtyesno
Last release2026-10-052026-10-08
Terms last updatedno document linkedno document linked
Privacy policy last updatedno document linkedno document linked
Customer content may train models
Terms restrict automated access
Terms restrict benchmarking
Terms or service can change without notice
Arbitration or class-action waiver
Popularity29k stars, 244 npm/wk, 170 PyPI/wk24k stars, 55k npm/wk

Verdicts

Kestra

Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.

Node-RED

Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.

Before you call either

Kestra

  1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3
  2. Set kestra.server.basic-auth in the config file before first start. Without it the setup page is open to anyone who reaches the port
  3. Put the tenant in the path. Open-source instances use main, as in /api/v1/main/executions/{namespace}/{id}
  4. Send flow inputs as multipart form fields, and add wait=true to get the finished execution in the same call
  5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth

Node-RED

  1. Call GET /auth/login first. An empty object means no authentication is set and every Admin API call is open
  2. Send Node-RED-API-Version: v2 and the last rev on POST /flows, and re-read the flows on a 409
  3. Set Node-RED-Deployment-Type to nodes or flows to restart only what changed. The default full stops every node
  4. Prefer GET /flow/:id and PUT /flow/:id for one tab. GET /flows returns every node in the runtime
  5. Treat flows.write and nodes.write as code execution on the host. Function nodes run JavaScript and POST /nodes installs npm modules

Questions

Which is better for AI agents, Kestra or Node-RED?

Kestra scores 63.6 (B) on agent readiness against Node-RED's 61 (C), and leads in 4 of 7 scored categories. Node-RED leads on security & auth and payments & pricing.

Do Kestra and Node-RED need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Kestra and Node-RED without installing anything?

No hosted endpoint is listed for Kestra. No hosted endpoint is listed for Node-RED.

Are Kestra and Node-RED open source?

Yes. Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). Node-RED is open source (Apache-2.0).

Other comparisons with Kestra or Node-RED

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.