{
  "data": {
    "a": {
      "slug": "kestra",
      "name": "Kestra",
      "vendor": "Kestra Technologies",
      "vendorUrl": "https://kestra.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Kestra is an open-source workflow orchestrator from Kestra Technologies. Flows are written in YAML and run on a server the owner hosts, with a REST API, SDKs in four languages and flows exposed as MCP tools.",
      "url": "https://www.anchorterminal.com/tools/kestra",
      "markdownUrl": "https://www.anchorterminal.com/tools/kestra.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kestra.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kestra.json",
      "repo": "https://github.com/kestra-io/kestra",
      "license": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "kestra/kestra"
        },
        {
          "registry": "pypi",
          "name": "kestrapy"
        },
        {
          "registry": "npm",
          "name": "@kestra-io/kestra-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "The open-source edition takes HTTP Basic auth with one username and password, set in `kestra.server.basic-auth` or on the setup page at first start. That credential has full access. Bearer API tokens, service accounts, OAuth, SSO and role-based access are in the Enterprise Edition and Kestra Cloud only. Access to open source is self-serve, by running the server. Webhook triggers are called with a key in the URL path.",
      "pricing": "freemium",
      "pricingNotes": "The open-source edition is free under Apache-2.0 with unlimited flows and executions, and an agent can start on it with no contract or account. Enterprise Edition is an annual subscription per instance through sales, with no public price. Kestra Cloud is by access request, with 14 days free and no card, then billed on task runs and Cloud runner time at rates that are not published (https://kestra.io/pricing, checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 29427,
        "npmWeekly": 244,
        "pypiWeekly": 170,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://kestra.io/docs",
      "llmsTxt": "https://kestra.io/llms.txt",
      "openapi": "https://kestra.io/kestra.yml",
      "capabilities": [
        "automation.workflows",
        "automation.code",
        "automation.webhooks",
        "automation.apps",
        "agent.tools"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "local",
        "hosted",
        "freemium",
        "openapi",
        "llms-txt",
        "mcp",
        "python",
        "typescript",
        "java",
        "go",
        "webhooks",
        "enterprise",
        "soc2"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.6,
        "grade": "B",
        "agentReady": false,
        "rank": 387,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -7,
        "negativeNotes": [
          "Five advisories rated critical were published on the repository in six months. GHSA-365w-2m69-mp9x (CVE-2026-34612, remote code execution through SQL injection, 30 March 2026), GHSA-5vc5-wxxq-3fjx and GHSA-2q47-568g-9h4f (CVE-2026-49869 and CVE-2026-53576, unauthenticated remote code execution through authentication filter bypass, 3 June 2026), and GHSA-rjhm-qm6w-m7x9 and GHSA-j5cv-8rw9-vv2p (unauthenticated remote code execution and authentication bypass, 29 September 2026). All are fixed, in 1.3.38 and 1.0.60 at the latest, and the maintainers published each one, so the deduction is reduced (https://github.com/kestra-io/kestra/security/advisories).",
          "Two further high advisories affected the default open-source setup. GHSA-hrr4-xg8h-5p6f, an unauthenticated gRPC control plane on port 50051, fixed in 2.0.3 and published 29 September 2026, and GHSA-94pv-f379-3gp3, a revoked administrator credential that stayed valid, fixed in 1.3.41 and published 6 October 2026 (https://github.com/kestra-io/kestra/security/advisories)."
        ],
        "verdict": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.",
        "bestFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "strengths": [
          "OpenAPI 3.0.1 spec for the open-source API with 216 operations, 213 of them documenting 401, 403 and 500 as problem+json",
          "Every docs page is served as Markdown by adding `.md`, with `llms.txt` and `llms-full.txt`",
          "32 releases between 15 July and 5 October 2026, with patches each week on the 1.3 and 2.0 long-term support lines",
          "Any flow becomes an MCP tool through `McpToolTrigger`, with read-only, destructive and idempotent hints set per flow",
          "Apache-2.0 server, and usage reporting documented field by field with two switches to turn it off"
        ],
        "weaknesses": [
          "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud",
          "Five critical advisories from 30 March to 29 September 2026, four of them unauthenticated remote code execution or authentication bypass, all fixed",
          "Kestra Cloud is request-access with no public price, and Enterprise is sold by annual contract through sales",
          "No rate limits and no idempotency key on the API. The correlation ID pattern needs a guard written into the flow",
          "The docs say `kestrapy` 2.0.1 imports `regex` without declaring it, so a plain install fails on import"
        ],
        "agentNotes": [
          "Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3",
          "Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port",
          "Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`",
          "Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call",
          "Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.6
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 86
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "docker run --pull=always --rm -it -p 8080:8080 --user=root --name kestra -v kestra_data:/app/storage -v kestra_db:/app/data -v /var/run/docker.sock:/var/run/docker.sock -v /tmp:/tmp -e KESTRA_PLUGINS_AUTO_INSTALL_ENABLED=true kestra/kestra:latest-slim server local",
        "http": "curl -X POST -u 'admin@kestra.io:kestra' http://localhost:8080/api/v1/main/executions/company.team/hello_world",
        "claudeCode": "claude mcp add \u003cserver-id\u003e \u003cserver-url\u003e --transport http --header \"Authorization: Basic $(echo -n 'username:password' | base64)\""
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/kestra"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Kestra Technologies SAS",
        "domain": "kestra.io",
        "domainRegistered": "2019-12-18",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/kestra-io/kestra/releases",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Cloud terms name Kestra Technologies SAS (RCS 900 427 873), 81 rue du Pré Catelan, 59110 La Madeleine, France, and Kestra Technologies Inc., a Delaware corporation, for customers billed in the Americas.",
          "No terms or privacy link is given because the edition graded is Apache-2.0 software the owner runs. The Kestra Cloud Terms of Service and Kestra Cloud Privacy Policy (both 14 September 2026) say they do not cover the open-source project, and the privacy policy at kestra.io/privacy-policy covers only the website.",
          "The API answers on the owner's own host. Only the documentation MCP server (api.kestra.io) and the usage reports go to a Kestra domain.",
          "https://kestra.io/.well-known/security.txt names security@kestra.io and the GitHub advisory form, and expires on 26 August 2028.",
          "RDAP for kestra.io gives a registration date of 2019-12-18.",
          "status.kestra.io did not answer our requests on 8 October 2026 and no status page is linked from the pricing, security or Cloud pages."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kestra.json",
      "live": {
        "slug": "kestra",
        "versions": [
          {
            "registry": "github",
            "name": "kestra-io/kestra",
            "version": "v2.0.5",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:00:07.156813448Z"
          },
          {
            "registry": "npm",
            "name": "@kestra-io/kestra-sdk",
            "version": "2.0.1",
            "seenAt": "2026-10-09T17:00:06.275016115Z"
          },
          {
            "registry": "pypi",
            "name": "kestrapy",
            "version": "2.0.1",
            "released": "2026-09-11",
            "seenAt": "2026-10-09T17:00:06.083664173Z"
          }
        ],
        "githubStars": 29456,
        "npmWeekly": 266,
        "pypiWeekly": 227,
        "securityTxt": {
          "url": "https://kestra.io/.well-known/security.txt",
          "state": "valid",
          "expires": "2028-08-26T00:00:00.000Z",
          "checkedAt": "2026-10-09T15:39:51.010707527Z"
        },
        "llmsTxt": {
          "url": "https://kestra.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:02:11.836658178Z"
        },
        "pages": [
          {
            "url": "https://kestra.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:40:38.900711725Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d49664bbbe0e"
          }
        ],
        "updatedAt": "2026-10-09T18:40:38.900711725Z"
      }
    },
    "answer": "Kestra scores 63.6 (B) on agent readiness against Node-RED's 61 (C), and leads in 4 of 7 scored categories. Node-RED leads on security \u0026 auth and payments \u0026 pricing.",
    "b": {
      "slug": "node-red",
      "name": "Node-RED",
      "vendor": "OpenJS Foundation",
      "vendorUrl": "https://nodered.org",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Node-RED is an open-source flow-based automation runtime hosted by the OpenJS Foundation. The owner runs it on Node.js, and an Admin HTTP API and a command-line client deploy flows and install nodes.",
      "url": "https://www.anchorterminal.com/tools/node-red",
      "markdownUrl": "https://www.anchorterminal.com/tools/node-red.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/node-red.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/node-red.json",
      "repo": "https://github.com/node-red/node-red",
      "license": "Apache-2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "node-red"
        },
        {
          "registry": "npm",
          "name": "node-red-admin"
        },
        {
          "registry": "oci",
          "name": "nodered/node-red"
        }
      ],
      "auth": "mixed",
      "authNotes": "A default install has no authentication. Setting `adminAuth` in `settings.js` turns on users with bcrypt-hashed passwords and permissions of `*`, `read` or a list such as `flows.read`. An agent then posts the username and password to `/auth/token` for a bearer token, valid seven days by default with no refresh. Access is self-serve, by running the software. Routes made by HTTP In nodes share one basic-auth username and password.",
      "pricing": "free",
      "pricingNotes": "Free under Apache-2.0 with nothing to buy from the project, so an agent can start with no account, card or contract. FlowFuse, a separate company, sells a hosted platform for Node-RED that the docs link, and it is not graded here (https://nodered.org/about/license/, checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source. The project sells nothing (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 23729,
        "npmWeekly": 55172,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://nodered.org/docs/api/admin/",
      "capabilities": [
        "automation.workflows",
        "automation.webhooks",
        "automation.code",
        "automation.apps"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "local",
        "free",
        "javascript",
        "webhooks",
        "cli",
        "docker"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61,
        "grade": "C",
        "agentReady": false,
        "rank": 486,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 44,
          "maintenance": 81,
          "payments": 60,
          "reliability": 90,
          "schema": 41,
          "security": 51,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.",
        "bestFor": "Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.",
        "strengths": [
          "Apache-2.0, with 12 releases between 30 July and 8 October 2026 on the 5.x and 4.x lines",
          "Admin API permissions are per resource, such as `flows.read` and `flows.write`, and a user or token can be limited to `read`",
          "`POST /flows` with `Node-RED-API-Version: v2` takes a `rev` value and answers 409 when the runtime holds newer flows",
          "Usage telemetry is opt-in, lists the four fields sent, and can be switched off in settings, by flag or by environment variable",
          "A release plan gives each major version a maintenance start and an end-of-life date, with 4.x ending on 31 December 2026"
        ],
        "weaknesses": [
          "No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org",
          "`adminAuth` is commented out in the default settings file, so a fresh install has no authentication on the editor or the Admin API",
          "No pagination, filtering or field selection. `GET /flows` returns the whole flow configuration",
          "Access tokens come from a username and password grant, last seven days by default and cannot be refreshed",
          "Routes for context, plugins, library and projects exist in the source and are missing from the published method list"
        ],
        "agentNotes": [
          "Call `GET /auth/login` first. An empty object means no authentication is set and every Admin API call is open",
          "Send `Node-RED-API-Version: v2` and the last `rev` on `POST /flows`, and re-read the flows on a 409",
          "Set `Node-RED-Deployment-Type` to `nodes` or `flows` to restart only what changed. The default `full` stops every node",
          "Prefer `GET /flow/:id` and `PUT /flow/:id` for one tab. `GET /flows` returns every node in the runtime",
          "Treat `flows.write` and `nodes.write` as code execution on the host. Function nodes run JavaScript and `POST /nodes` installs npm modules"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61
          }
        ],
        "editorialScores": {
          "ergonomics": 44,
          "maintenance": 81,
          "payments": 60,
          "reliability": 90,
          "schema": 41,
          "security": 51,
          "transparency": 85
        },
        "provenanceScore": 45
      },
      "connect": {
        "install": "sudo npm install -g node-red",
        "http": "curl http://localhost:1880/auth/token --data 'client_id=node-red-admin\u0026grant_type=password\u0026scope=*\u0026username=admin\u0026password=password'"
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/node-red"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "OpenJS Foundation",
        "domain": "nodered.org",
        "domainRegistered": "2013-09-12",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/node-red/node-red/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The licence page on nodered.org says copyright is retained by the OpenJS Foundation, and the site footer reads Copyright OpenJS Foundation and Node-RED contributors.",
          "No terms or privacy link is given. Node-RED is Apache-2.0 software the owner runs, and the project publishes no service agreement or privacy policy of its own. The site footer links the OpenJS Foundation's terms of use and privacy policy, which are a parent body's website documents and were not read.",
          "The Admin API answers on the owner's own host, by default http://localhost:1880. Only the opt-in telemetry report goes to an endpoint the project hosts.",
          "https://nodered.org/.well-known/security.txt returns 404. SECURITY.md in the repository gives team@nodered.org and escalation to the OpenJS Foundation CNA.",
          "RDAP for nodered.org gives a registration date of 2013-09-12. The lookup through rdap.org was redirected to the registry's RDAP host.",
          "nodered.org has no robots.txt (404). No status page exists because there is no hosted service."
        ],
        "score": 45
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/node-red.json",
      "live": {
        "slug": "node-red",
        "versions": [
          {
            "registry": "github",
            "name": "node-red/node-red",
            "version": "5.0.8",
            "released": "2026-10-08",
            "seenAt": "2026-10-09T17:08:22.991909994Z"
          },
          {
            "registry": "npm",
            "name": "node-red",
            "version": "5.0.8",
            "seenAt": "2026-10-09T17:08:20.781082858Z"
          },
          {
            "registry": "npm",
            "name": "node-red-admin",
            "version": "4.1.8",
            "seenAt": "2026-10-09T17:08:21.396260251Z"
          }
        ],
        "githubStars": 23730,
        "npmWeekly": 55172,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/node-red/node-red/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:37.181546944Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4223a5392d5c"
          }
        ],
        "updatedAt": "2026-10-09T18:45:37.181546944Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Kestra Technologies",
        "b": "OpenJS Foundation",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
        "b": "Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-05",
        "b": "2026-10-08",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "29k stars, 244 npm/wk, 170 PyPI/wk",
        "b": "24k stars, 55k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Kestra scores 63.6 (B) on agent readiness against Node-RED's 61 (C), and leads in 4 of 7 scored categories. Node-RED leads on security \u0026 auth and payments \u0026 pricing.",
        "question": "Which is better for AI agents, Kestra or Node-RED?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Kestra and Node-RED need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Kestra. No hosted endpoint is listed for Node-RED.",
        "question": "Can an agent call Kestra and Node-RED without installing anything?"
      },
      {
        "answer": "Yes. Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). Node-RED is open source (Apache-2.0).",
        "question": "Are Kestra and Node-RED open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 82 against 41",
          "Agent ergonomics, 73 against 44",
          "Maintenance \u0026 community, 93 against 81"
        ],
        "also": null,
        "goodFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "slug": "kestra",
        "watchFor": "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 51 against 41",
          "Payments \u0026 pricing, 60 against 50"
        ],
        "also": [
          "No incidents deducted, where Kestra loses 7 points for them"
        ],
        "goodFor": "Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.",
        "slug": "node-red",
        "watchFor": "No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org"
      }
    ],
    "job": {
      "capability": "automation.workflows",
      "name": "Workflow automation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-kestra.json",
        "title": "Activepieces API + MCP vs Kestra",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-kestra"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-node-red.json",
        "title": "Activepieces API + MCP vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-kestra.json",
        "title": "Gumloop vs Kestra",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-kestra"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-node-red.json",
        "title": "Gumloop vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-make.json",
        "title": "Kestra vs Make API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-make"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-n8n.json",
        "title": "Kestra vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-paragon.json",
        "title": "Kestra vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-pipedream.json",
        "title": "Kestra vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-power-automate.json",
        "title": "Kestra vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-prismatic.json",
        "title": "Kestra vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-tray.json",
        "title": "Kestra vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-windmill.json",
        "title": "Kestra vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-workato.json",
        "title": "Kestra vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-node-red.json",
        "title": "Make API + MCP vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/make-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-node-red.json",
        "title": "n8n API + MCP vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-paragon.json",
        "title": "Node-RED vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-pipedream.json",
        "title": "Node-RED vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-power-automate.json",
        "title": "Node-RED vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-prismatic.json",
        "title": "Node-RED vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-tray.json",
        "title": "Node-RED vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-windmill.json",
        "title": "Node-RED vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-workato.json",
        "title": "Node-RED vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-workato"
      }
    ],
    "scores": [
      {
        "by": 1,
        "edge": "node-red",
        "kestra": 89,
        "key": "reliability",
        "name": "Reliability",
        "node-red": 90,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 41,
        "edge": "kestra",
        "kestra": 82,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "node-red": 41,
        "weight": 13
      },
      {
        "by": 29,
        "edge": "kestra",
        "kestra": 73,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "node-red": 44,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "node-red",
        "kestra": 41,
        "key": "security",
        "name": "Security \u0026 auth",
        "node-red": 51,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "node-red",
        "kestra": 50,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "node-red": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "edge": "kestra",
        "kestra": 93,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "node-red": 81,
        "weight": 7
      },
      {
        "by": 4,
        "edge": "kestra",
        "kestra": 69,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "node-red": 65,
        "weight": 7
      }
    ],
    "summary": "Kestra scores 63.6 (B) on agent readiness against Node-RED's 61 (C), and leads in 4 of 7 scored categories. Node-RED leads on security \u0026 auth and payments \u0026 pricing. Both do workflow automation.",
    "verdicts": {
      "kestra": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.",
      "node-red": "Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kestra-vs-node-red",
    "json": "https://www.anchorterminal.com/compare/kestra-vs-node-red.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kestra-vs-node-red.md",
    "slim": "https://www.anchorterminal.com/compare/kestra-vs-node-red.min.md"
  },
  "markdown": "Kestra scores 63.6 (B) on agent readiness against Node-RED's 61 (C), and leads in 4 of 7 scored categories. Node-RED leads on security \u0026 auth and payments \u0026 pricing. Both do workflow automation.\n\n- Kestra: grade B, 63.6/100, rank #387 of 950. Markdown https://www.anchorterminal.com/tools/kestra.md · JSON https://www.anchorterminal.com/api/v1/tools/kestra.json\n- Node-RED: grade C, 61/100, rank #486 of 950. Markdown https://www.anchorterminal.com/tools/node-red.md · JSON https://www.anchorterminal.com/api/v1/tools/node-red.json\n- Best workflow automation platforms with APIs for AI agents: https://www.anchorterminal.com/best/workflow-automation/index.md\n- All 108 workflows comparisons: https://www.anchorterminal.com/compare/workflow-automation/index.md\n\n## Which one, for what\n\n### Kestra (B)\n\nGood for: Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.\n\nAhead on:\n- Schema \u0026 documentation, 82 against 41\n- Agent ergonomics, 73 against 44\n- Maintenance \u0026 community, 93 against 81\n\nWatch for: The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud\n\n### Node-RED (C)\n\nGood for: Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.\n\nAhead on:\n- Security \u0026 auth, 51 against 41\n- Payments \u0026 pricing, 60 against 50\n\nAlso in its favour:\n- No incidents deducted, where Kestra loses 7 points for them\n\nWatch for: No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org\n\n\n## Score by category\n\n| Category | Weight | Kestra | Node-RED | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 89 | 90 | Node-RED +1 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 41 | Kestra +41 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 44 | Kestra +29 |\n| Security \u0026 auth | 14% (17.5 this run) | 41 | 51 | Node-RED +10 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 60 | Node-RED +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 93 | 81 | Kestra +12 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 65 | Kestra +4 |\n| Negative events | ≤15 | -7 | 0 | |\n| **Total** | | **63.6 · B** | **61 · C** | |\n\n## Facts side by side\n\n| Fact | Kestra | Node-RED |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Kestra Technologies | OpenJS Foundation |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial | Apache-2.0 |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | no |\n| Last release | 2026-10-05 | 2026-10-08 |\n| Terms last updated | no document linked | no document linked |\n| Privacy policy last updated | no document linked | no document linked |\n| Customer content may train models |  |  |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 29k stars, 244 npm/wk, 170 PyPI/wk | 24k stars, 55k npm/wk |\n\n## Verdicts\n\n**Kestra.** Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.\n\n**Node-RED.** Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.\n\n## Before you call either\n\n### Kestra\n\n1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3\n2. Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port\n3. Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`\n4. Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call\n5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth\n\n### Node-RED\n\n1. Call `GET /auth/login` first. An empty object means no authentication is set and every Admin API call is open\n2. Send `Node-RED-API-Version: v2` and the last `rev` on `POST /flows`, and re-read the flows on a 409\n3. Set `Node-RED-Deployment-Type` to `nodes` or `flows` to restart only what changed. The default `full` stops every node\n4. Prefer `GET /flow/:id` and `PUT /flow/:id` for one tab. `GET /flows` returns every node in the runtime\n5. Treat `flows.write` and `nodes.write` as code execution on the host. Function nodes run JavaScript and `POST /nodes` installs npm modules\n\n## Questions\n\n### Which is better for AI agents, Kestra or Node-RED?\n\nKestra scores 63.6 (B) on agent readiness against Node-RED's 61 (C), and leads in 4 of 7 scored categories. Node-RED leads on security \u0026 auth and payments \u0026 pricing.\n\n### Do Kestra and Node-RED need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Kestra and Node-RED without installing anything?\n\nNo hosted endpoint is listed for Kestra. No hosted endpoint is listed for Node-RED.\n\n### Are Kestra and Node-RED open source?\n\nYes. Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). Node-RED is open source (Apache-2.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kestra-vs-node-red.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kestra-vs-node-red.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kestra\", \"b\": \"node-red\"}`. From a terminal: `anchor compare kestra node-red`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kestra.json and https://www.anchorterminal.com/api/v1/tools/node-red.json\n\n## Other comparisons with Kestra or Node-RED\n\n- [Activepieces API + MCP vs Kestra](https://www.anchorterminal.com/compare/activepieces-vs-kestra.md)\n- [Activepieces API + MCP vs Node-RED](https://www.anchorterminal.com/compare/activepieces-vs-node-red.md)\n- [Gumloop vs Kestra](https://www.anchorterminal.com/compare/gumloop-vs-kestra.md)\n- [Gumloop vs Node-RED](https://www.anchorterminal.com/compare/gumloop-vs-node-red.md)\n- [Kestra vs Make API + MCP](https://www.anchorterminal.com/compare/kestra-vs-make.md)\n- [Kestra vs n8n API + MCP](https://www.anchorterminal.com/compare/kestra-vs-n8n.md)\n- [Kestra vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/kestra-vs-paragon.md)\n- [Kestra vs Pipedream API + MCP](https://www.anchorterminal.com/compare/kestra-vs-pipedream.md)\n- [Kestra vs Microsoft Power Automate](https://www.anchorterminal.com/compare/kestra-vs-power-automate.md)\n- [Kestra vs Prismatic](https://www.anchorterminal.com/compare/kestra-vs-prismatic.md)\n- [Kestra vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/kestra-vs-tray.md)\n- [Kestra vs Windmill API + MCP](https://www.anchorterminal.com/compare/kestra-vs-windmill.md)\n- [Kestra vs Workato API + MCP](https://www.anchorterminal.com/compare/kestra-vs-workato.md)\n- [Make API + MCP vs Node-RED](https://www.anchorterminal.com/compare/make-vs-node-red.md)\n- [n8n API + MCP vs Node-RED](https://www.anchorterminal.com/compare/n8n-vs-node-red.md)\n- [Node-RED vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/node-red-vs-paragon.md)\n- [Node-RED vs Pipedream API + MCP](https://www.anchorterminal.com/compare/node-red-vs-pipedream.md)\n- [Node-RED vs Microsoft Power Automate](https://www.anchorterminal.com/compare/node-red-vs-power-automate.md)\n- [Node-RED vs Prismatic](https://www.anchorterminal.com/compare/node-red-vs-prismatic.md)\n- [Node-RED vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/node-red-vs-tray.md)\n- [Node-RED vs Windmill API + MCP](https://www.anchorterminal.com/compare/node-red-vs-windmill.md)\n- [Node-RED vs Workato API + MCP](https://www.anchorterminal.com/compare/node-red-vs-workato.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kestra vs Node-RED",
        "url": ""
      }
    ],
    "description": "Kestra scores 63.6 (B) to Node-RED's 61 (C) for workflow automation. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Kestra B 63.6",
      "Node-RED C 61",
      "scores"
    ],
    "h1": "Kestra vs Node-RED",
    "image": "https://www.anchorterminal.com/assets/og/compare-kestra-vs-node-red.png",
    "path": "/compare/kestra-vs-node-red",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kestra vs Node-RED for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/kestra-vs-node-red"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 580
  },
  "version": 1
}
