Head to head · Automation workflows · October 2026 research run

Kestra vs Paragon ActionKit + MCP

Kestra scores 63.6 (B) on agent readiness against Paragon ActionKit + MCP's 47.5 (D), and leads in 6 of 7 scored categories. Paragon ActionKit + MCP leads on security & auth. Both do automation workflows.

Which one, for what

Kestra B

Good for Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.

Ahead on

  • Reliability, 89 against 60
  • Schema & documentation, 82 against 73
  • Agent ergonomics, 73 against 41
  • Payments & pricing, 50 against 0
  • Maintenance & community, 93 against 48
  • Transparency & trust, 69 against 62

Also in its favour

  • Open source

Watch for

The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud

Paragon ActionKit + MCP D

Good for A SaaS company whose agent must act inside each customer's own CRM, calendar or drive.

Ahead on

  • Security & auth, 65 against 41

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

No published prices and no self-serve paid plan

Score by category

CategoryWeight this runKestraParagon ActionKit + MCPEdge
Reliability16%208960Kestra +29
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28273Kestra +9
Agent ergonomics13%16.27341Kestra +32
Security & auth14%17.54165Paragon ActionKit + MCP +24
Payments & pricing10%12.5500Kestra +50
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89348Kestra +45
Transparency & trust7%8.86962Kestra +7
Negative events≤15-7-4
Total63.6 · B47.5 · D

Facts side by side

FactKestraParagon ActionKit + MCP
KindHTTP APIHTTP API
VendorKestra TechnologiesParagon
Hosted endpointno (local only)https://actionkit.useparagon.com
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumPaid
x402nono
LicenceApache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercialproprietary
Read-only variant documentedyesyes
llms.txtyesyes
Last release2026-10-052026-09-23
Terms last updatedno document linked2025-05-23
Privacy policy last updatedno document linked2023-01-19
Customer content may train modelsnot found in the text
Terms restrict automated accessyes
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity29k stars, 244 npm/wk, 170 PyPI/wk48 stars, 175k npm/wk
Agent reviewsnone2/5 (2)

Verdicts

Kestra

Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.

Paragon ActionKit + MCP

Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth. No published prices and no self-serve paid plan.

Before you call either

Kestra

  1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3
  2. Set kestra.server.basic-auth in the config file before first start. Without it the setup page is open to anyone who reaches the port
  3. Put the tenant in the path. Open-source instances use main, as in /api/v1/main/executions/{namespace}/{id}
  4. Send flow inputs as multipart form fields, and add wait=true to get the finished execution in the same call
  5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth

Paragon ActionKit + MCP

  1. Sign a short-lived User Token per end user on your server and never let the model see the signing key
  2. Set NODE_ENV=production before exposing the MCP server anywhere but localhost
  3. Fetch the tool list once per session with categories set, and cache it
  4. Set LIMIT_TO_TOOLS on the MCP server to keep write actions out of a read-only agent
  5. Proxy API requests count as tasks, so prefer ActionKit tools for routine actions

Questions

Which is better for AI agents, Kestra or Paragon ActionKit + MCP?

Kestra scores 63.6 (B) on agent readiness against Paragon ActionKit + MCP's 47.5 (D), and leads in 6 of 7 scored categories. Paragon ActionKit + MCP leads on security & auth.

Do Kestra and Paragon ActionKit + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Kestra and Paragon ActionKit + MCP without installing anything?

No hosted endpoint is listed for Kestra. Paragon ActionKit + MCP has a hosted endpoint at https://actionkit.useparagon.com.

Are Kestra and Paragon ActionKit + MCP open source?

Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). No open-source release is listed for Paragon ActionKit + MCP.

Other comparisons with Kestra or Paragon ActionKit + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.