{
  "data": {
    "a": {
      "slug": "kestra",
      "name": "Kestra",
      "vendor": "Kestra Technologies",
      "vendorUrl": "https://kestra.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Kestra is an open-source workflow orchestrator from Kestra Technologies. Flows are written in YAML and run on a server the owner hosts, with a REST API, SDKs in four languages and flows exposed as MCP tools.",
      "url": "https://www.anchorterminal.com/tools/kestra",
      "markdownUrl": "https://www.anchorterminal.com/tools/kestra.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kestra.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kestra.json",
      "repo": "https://github.com/kestra-io/kestra",
      "license": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "kestra/kestra"
        },
        {
          "registry": "pypi",
          "name": "kestrapy"
        },
        {
          "registry": "npm",
          "name": "@kestra-io/kestra-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "The open-source edition takes HTTP Basic auth with one username and password, set in `kestra.server.basic-auth` or on the setup page at first start. That credential has full access. Bearer API tokens, service accounts, OAuth, SSO and role-based access are in the Enterprise Edition and Kestra Cloud only. Access to open source is self-serve, by running the server. Webhook triggers are called with a key in the URL path.",
      "pricing": "freemium",
      "pricingNotes": "The open-source edition is free under Apache-2.0 with unlimited flows and executions, and an agent can start on it with no contract or account. Enterprise Edition is an annual subscription per instance through sales, with no public price. Kestra Cloud is by access request, with 14 days free and no card, then billed on task runs and Cloud runner time at rates that are not published (https://kestra.io/pricing, checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 29427,
        "npmWeekly": 244,
        "pypiWeekly": 170,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://kestra.io/docs",
      "llmsTxt": "https://kestra.io/llms.txt",
      "openapi": "https://kestra.io/kestra.yml",
      "capabilities": [
        "automation.workflows",
        "automation.code",
        "automation.webhooks",
        "automation.apps",
        "agent.tools"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "local",
        "hosted",
        "freemium",
        "openapi",
        "llms-txt",
        "mcp",
        "python",
        "typescript",
        "java",
        "go",
        "webhooks",
        "enterprise",
        "soc2"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.6,
        "grade": "B",
        "agentReady": false,
        "rank": 351,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -7,
        "negativeNotes": [
          "Five advisories rated critical were published on the repository in six months. GHSA-365w-2m69-mp9x (CVE-2026-34612, remote code execution through SQL injection, 30 March 2026), GHSA-5vc5-wxxq-3fjx and GHSA-2q47-568g-9h4f (CVE-2026-49869 and CVE-2026-53576, unauthenticated remote code execution through authentication filter bypass, 3 June 2026), and GHSA-rjhm-qm6w-m7x9 and GHSA-j5cv-8rw9-vv2p (unauthenticated remote code execution and authentication bypass, 29 September 2026). All are fixed, in 1.3.38 and 1.0.60 at the latest, and the maintainers published each one, so the deduction is reduced (https://github.com/kestra-io/kestra/security/advisories).",
          "Two further high advisories affected the default open-source setup. GHSA-hrr4-xg8h-5p6f, an unauthenticated gRPC control plane on port 50051, fixed in 2.0.3 and published 29 September 2026, and GHSA-94pv-f379-3gp3, a revoked administrator credential that stayed valid, fixed in 1.3.41 and published 6 October 2026 (https://github.com/kestra-io/kestra/security/advisories)."
        ],
        "verdict": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.",
        "bestFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "strengths": [
          "OpenAPI 3.0.1 spec for the open-source API with 216 operations, 213 of them documenting 401, 403 and 500 as problem+json",
          "Every docs page is served as Markdown by adding `.md`, with `llms.txt` and `llms-full.txt`",
          "32 releases between 15 July and 5 October 2026, with patches each week on the 1.3 and 2.0 long-term support lines",
          "Any flow becomes an MCP tool through `McpToolTrigger`, with read-only, destructive and idempotent hints set per flow",
          "Apache-2.0 server, and usage reporting documented field by field with two switches to turn it off"
        ],
        "weaknesses": [
          "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud",
          "Five critical advisories from 30 March to 29 September 2026, four of them unauthenticated remote code execution or authentication bypass, all fixed",
          "Kestra Cloud is request-access with no public price, and Enterprise is sold by annual contract through sales",
          "No rate limits and no idempotency key on the API. The correlation ID pattern needs a guard written into the flow",
          "The docs say `kestrapy` 2.0.1 imports `regex` without declaring it, so a plain install fails on import"
        ],
        "agentNotes": [
          "Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3",
          "Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port",
          "Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`",
          "Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call",
          "Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.6
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 86
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "docker run --pull=always --rm -it -p 8080:8080 --user=root --name kestra -v kestra_data:/app/storage -v kestra_db:/app/data -v /var/run/docker.sock:/var/run/docker.sock -v /tmp:/tmp -e KESTRA_PLUGINS_AUTO_INSTALL_ENABLED=true kestra/kestra:latest-slim server local",
        "http": "curl -X POST -u 'admin@kestra.io:kestra' http://localhost:8080/api/v1/main/executions/company.team/hello_world",
        "claudeCode": "claude mcp add \u003cserver-id\u003e \u003cserver-url\u003e --transport http --header \"Authorization: Basic $(echo -n 'username:password' | base64)\""
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/kestra"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Kestra Technologies SAS",
        "domain": "kestra.io",
        "domainRegistered": "2019-12-18",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/kestra-io/kestra/releases",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Cloud terms name Kestra Technologies SAS (RCS 900 427 873), 81 rue du Pré Catelan, 59110 La Madeleine, France, and Kestra Technologies Inc., a Delaware corporation, for customers billed in the Americas.",
          "No terms or privacy link is given because the edition graded is Apache-2.0 software the owner runs. The Kestra Cloud Terms of Service and Kestra Cloud Privacy Policy (both 14 September 2026) say they do not cover the open-source project, and the privacy policy at kestra.io/privacy-policy covers only the website.",
          "The API answers on the owner's own host. Only the documentation MCP server (api.kestra.io) and the usage reports go to a Kestra domain.",
          "https://kestra.io/.well-known/security.txt names security@kestra.io and the GitHub advisory form, and expires on 26 August 2028.",
          "RDAP for kestra.io gives a registration date of 2019-12-18.",
          "status.kestra.io did not answer our requests on 8 October 2026 and no status page is linked from the pricing, security or Cloud pages."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kestra.json"
    },
    "answer": "Kestra scores 63.6 (B) on agent readiness against Microsoft Power Automate's 62 (B), and leads in 5 of 7 scored categories. Microsoft Power Automate leads on security \u0026 auth and transparency \u0026 trust.",
    "b": {
      "slug": "power-automate",
      "name": "Microsoft Power Automate",
      "vendor": "Microsoft",
      "vendorUrl": "https://www.microsoft.com/power-platform/products/power-automate",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Microsoft's workflow builder for cloud flows across Microsoft 365, Dataverse and third-party connectors. Outside agents list, create, update and delete solution-aware flows through the Dataverse Web API, and start a flow through its HTTP request trigger.",
      "url": "https://www.anchorterminal.com/tools/power-automate",
      "markdownUrl": "https://www.anchorterminal.com/tools/power-automate.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/power-automate.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/power-automate.json",
      "license": "Proprietary service under the Microsoft Product Terms for Microsoft Power Platform",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "nuget",
          "name": "Microsoft.PowerPlatform.Dataverse.Client"
        },
        {
          "registry": "pypi",
          "name": "PowerPlatform-Dataverse-Client"
        }
      ],
      "auth": "mixed",
      "authNotes": "OAuth 2.0 through Microsoft Entra ID for flow management. A person registers an app in the tenant and an administrator creates an application user with a Dataverse security role, or a user signs in with delegated access. The read-only Power Platform API takes a token for `https://api.powerplatform.com` with `.default`. A flow's HTTP request trigger has three modes. Any user in my tenant (the default for new flows) and Specific users in my tenant take an Entra bearer token with audience `https://service.flow.microsoft.com/`, and the second can name service principal object IDs. The legacy Anyone mode needs only the trigger URL, which carries a shared access signature as `sig=`. No API-key path for management.",
      "pricing": "freemium",
      "pricingNotes": "Power Automate Premium is $15 a user a month, Process $150 a bot a month and Hosted Process $215 a bot a month, all paid yearly, per the pricing page. API calls carry no separate charge and count against daily Power Platform request allowances (40,000 per Premium user, 250,000 per Process licence, a 25,000 tenant pool for unlicensed service principals). A flow owned by a service principal that uses premium connectors needs a Process licence or a designated licensed co-owner. To start without a contract there is a Free licence limited to standard connectors, a self-serve 90-day trial, and the Power Apps Developer Plan with a free Dataverse environment and 750 flow runs a month. Card requirements were not stated (checked 2026-10-08).",
      "priceSummary": "$15 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Power Automate code docs, the Power Platform API reference or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": 10702,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/power-automate/manage-flows-with-code",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.webhooks"
      ],
      "tags": [
        "hosted",
        "official",
        "oauth",
        "enterprise",
        "odata",
        "dotnet",
        "python",
        "closed-source",
        "sla",
        "audit-log",
        "freemium",
        "webhooks"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62,
        "grade": "B",
        "agentReady": false,
        "rank": 405,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 76,
          "payments": 25,
          "reliability": 63,
          "schema": 68,
          "security": 61,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Cloud flows in a solution are rows an agent can read and write through the Dataverse Web API under Entra ID OAuth and security roles, with published limits and a 99.9 per cent SLA. Flows under My flows can't be managed in code, a flow's body is one hand-built JSON string, and setup needs a tenant administrator.",
        "bestFor": "Organisations already on Microsoft 365 and Dataverse that want an agent to inventory, deploy or adjust flows inside existing roles and solutions.",
        "strengths": [
          "Solution-aware cloud flows are rows in the Dataverse `workflows` table, with documented list, create, update, delete, share, export and import calls",
          "Service protection limits are published (6,000 requests per user in five minutes) and 429 responses carry `Retry-After`",
          "The SLA of 1 October 2026 pays a 25 per cent credit below 99.9 per cent uptime for Power Automate",
          "Each run of a solution flow is a `flowruns` row with status, error code and message, kept 28 days by default",
          "A service principal can own flows, and new HTTP request triggers default to callers signed in to the tenant"
        ],
        "weaknesses": [
          "Flows under My flows can't be managed in code, and Microsoft calls the `api.flow.microsoft.com` API unsupported",
          "A flow's definition travels as `clientdata`, one string of encoded JSON with connection references the caller builds by hand",
          "No documented call runs, cancels or resubmits a flow. Starting one means an HTTP request trigger built into the flow",
          "The legacy Anyone trigger mode carries its signature in the URL query string as `sig=`",
          "Power Automate's own released versions page stops at version 2508.2 of August 2025, and service health needs an admin sign-in"
        ],
        "agentNotes": [
          "Filter `workflows` on `category eq 5` for cloud flows, and add `$select`, because `clientdata` holds the whole definition",
          "Flows created through the API start with `statecode` 0 (off). The docs say to turn the flow on before use",
          "Put the flow in a solution first. Flows that sit only under My flows are outside the supported API",
          "On 429 wait the `Retry-After` seconds. Reads of `flowruns` count against the daily Power Platform request allowance",
          "Treat an HTTP trigger URL with `sig=` as a secret, and prefer the tenant or named-user trigger modes with a bearer token for `https://service.flow.microsoft.com/`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 76,
          "payments": 25,
          "reliability": 63,
          "schema": 68,
          "security": 61,
          "transparency": 62
        },
        "provenanceScore": 89
      },
      "connect": {
        "http": "curl \"https://$DATAVERSE_ORG.api.crm.dynamics.com/api/data/v9.2/workflows?\\$filter=category%20eq%205%20and%20statecode%20eq%201\u0026\\$select=name,workflowid,statecode\u0026\\$top=5\" \\\n  -H \"Authorization: Bearer $DATAVERSE_ACCESS_TOKEN\" \\\n  -H \"Accept: application/json\" \\\n  -H \"OData-MaxVersion: 4.0\" \\\n  -H \"OData-Version: 4.0\""
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/power-automate"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "onedrive-sharepoint",
        "microsoft-teams",
        "dynamics-365-sales",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "business",
      "unitPrices": [
        {
          "item": "Power Automate Premium",
          "unit": "seat-month",
          "usd": 15,
          "note": "paid yearly, 40,000 Power Platform requests a day"
        },
        {
          "item": "Power Automate Process",
          "unit": "month",
          "usd": 150,
          "note": "per bot, paid yearly, 250,000 actions a day for one flow or a flow group"
        },
        {
          "item": "Power Automate Hosted Process",
          "unit": "month",
          "usd": 215,
          "note": "per bot, paid yearly, with a Microsoft-hosted virtual machine"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "domainNote": "The management API answers on a dynamics.com host such as https://\u003corg\u003e.api.crm.dynamics.com, flow trigger URLs on logic.azure.com and the inventory API on api.powerplatform.com, all Microsoft domains. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.microsoft.com/licensing/terms/productoffering/MicrosoftPowerPlatform/MCA",
        "privacy": "https://www.microsoft.com/en-us/privacy/privacystatement",
        "statusPage": "https://status.cloud.microsoft",
        "changelog": "https://learn.microsoft.com/en-us/dynamics365/released-versions/Microsoft-Dataverse",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The terms link is the Microsoft Product Terms page for Microsoft Power Platform under the Microsoft Customer Agreement, which names Power Automate Premium, Process and Hosted Process. It showed no effective date.",
          "The Microsoft privacy statement was last updated in September 2026 and says customer agreements control for enterprise and developer products. Customer data is governed by the Products and Services Data Protection Addendum, published as a .docx download, which we did not read.",
          "www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08, with MSRC as the contact.",
          "status.cloud.microsoft rendered only a title for our reader. Tenant service health is in the Power Platform and Microsoft 365 admin centres behind an admin sign-in.",
          "The changelog link is the weekly Dataverse service update page, because flow management runs on Dataverse. Power Automate's own released versions page (https://learn.microsoft.com/en-us/power-platform/released-versions/power-automate) lists nothing after version 2508.2 of August 2025.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02. dynamics.com, azure.com and powerplatform.com were not looked up."
        ],
        "score": 89
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/power-automate.json"
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Kestra Technologies",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
        "b": "Proprietary service under the Microsoft Product Terms for Microsoft Power Platform",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-05",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "29k stars, 244 npm/wk, 170 PyPI/wk",
        "b": "11k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Kestra scores 63.6 (B) on agent readiness against Microsoft Power Automate's 62 (B), and leads in 5 of 7 scored categories. Microsoft Power Automate leads on security \u0026 auth and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Kestra or Microsoft Power Automate?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Kestra and Microsoft Power Automate need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Kestra. No hosted endpoint is listed for Microsoft Power Automate.",
        "question": "Can an agent call Kestra and Microsoft Power Automate without installing anything?"
      },
      {
        "answer": "Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). No open-source release is listed for Microsoft Power Automate.",
        "question": "Are Kestra and Microsoft Power Automate open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 89 against 63",
          "Schema \u0026 documentation, 82 against 68",
          "Payments \u0026 pricing, 50 against 25",
          "Maintenance \u0026 community, 93 against 76"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "slug": "kestra",
        "watchFor": "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 61 against 41",
          "Transparency \u0026 trust, 76 against 69"
        ],
        "also": [
          "No incidents deducted, where Kestra loses 7 points for them"
        ],
        "goodFor": "Organisations already on Microsoft 365 and Dataverse that want an agent to inventory, deploy or adjust flows inside existing roles and solutions.",
        "slug": "power-automate",
        "watchFor": "Flows under My flows can't be managed in code, and Microsoft calls the `api.flow.microsoft.com` API unsupported"
      }
    ],
    "job": {
      "capability": "automation.workflows",
      "name": "Automation workflows"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-kestra.json",
        "title": "Activepieces API + MCP vs Kestra",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-kestra"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-power-automate.json",
        "title": "Activepieces API + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-kestra.json",
        "title": "Gumloop vs Kestra",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-kestra"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-power-automate.json",
        "title": "Gumloop vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-make.json",
        "title": "Kestra vs Make API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-make"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-n8n.json",
        "title": "Kestra vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-paragon.json",
        "title": "Kestra vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-pipedream.json",
        "title": "Kestra vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-tray.json",
        "title": "Kestra vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-windmill.json",
        "title": "Kestra vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-workato.json",
        "title": "Kestra vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-power-automate.json",
        "title": "Make API + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/make-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-power-automate.json",
        "title": "n8n API + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paragon-vs-power-automate.json",
        "title": "Paragon ActionKit + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/paragon-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pipedream-vs-power-automate.json",
        "title": "Pipedream API + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/pipedream-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/power-automate-vs-tray.json",
        "title": "Microsoft Power Automate vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/power-automate-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/power-automate-vs-windmill.json",
        "title": "Microsoft Power Automate vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/power-automate-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/power-automate-vs-workato.json",
        "title": "Microsoft Power Automate vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/power-automate-vs-workato"
      }
    ],
    "scores": [
      {
        "by": 26,
        "edge": "kestra",
        "kestra": 89,
        "key": "reliability",
        "name": "Reliability",
        "power-automate": 63,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 14,
        "edge": "kestra",
        "kestra": 82,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "power-automate": 68,
        "weight": 13
      },
      {
        "by": 4,
        "edge": "kestra",
        "kestra": 73,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "power-automate": 69,
        "weight": 13
      },
      {
        "by": 20,
        "edge": "power-automate",
        "kestra": 41,
        "key": "security",
        "name": "Security \u0026 auth",
        "power-automate": 61,
        "weight": 14
      },
      {
        "by": 25,
        "edge": "kestra",
        "kestra": 50,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "power-automate": 25,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 17,
        "edge": "kestra",
        "kestra": 93,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "power-automate": 76,
        "weight": 7
      },
      {
        "by": 7,
        "edge": "power-automate",
        "kestra": 69,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "power-automate": 76,
        "weight": 7
      }
    ],
    "summary": "Kestra scores 63.6 (B) on agent readiness against Microsoft Power Automate's 62 (B), and leads in 5 of 7 scored categories. Microsoft Power Automate leads on security \u0026 auth and transparency \u0026 trust. Both do automation workflows.",
    "verdicts": {
      "kestra": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.",
      "power-automate": "Cloud flows in a solution are rows an agent can read and write through the Dataverse Web API under Entra ID OAuth and security roles, with published limits and a 99.9 per cent SLA. Flows under My flows can't be managed in code, a flow's body is one hand-built JSON string, and setup needs a tenant administrator."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kestra-vs-power-automate",
    "json": "https://www.anchorterminal.com/compare/kestra-vs-power-automate.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kestra-vs-power-automate.md",
    "slim": "https://www.anchorterminal.com/compare/kestra-vs-power-automate.min.md"
  },
  "markdown": "Kestra scores 63.6 (B) on agent readiness against Microsoft Power Automate's 62 (B), and leads in 5 of 7 scored categories. Microsoft Power Automate leads on security \u0026 auth and transparency \u0026 trust. Both do automation workflows.\n\n- Kestra: grade B, 63.6/100, rank #351 of 842. Markdown https://www.anchorterminal.com/tools/kestra.md · JSON https://www.anchorterminal.com/api/v1/tools/kestra.json\n- Microsoft Power Automate: grade B, 62/100, rank #405 of 842. Markdown https://www.anchorterminal.com/tools/power-automate.md · JSON https://www.anchorterminal.com/api/v1/tools/power-automate.json\n\n## Which one, for what\n\n### Kestra (B)\n\nGood for: Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.\n\nAhead on:\n- Reliability, 89 against 63\n- Schema \u0026 documentation, 82 against 68\n- Payments \u0026 pricing, 50 against 25\n- Maintenance \u0026 community, 93 against 76\n\nAlso in its favour:\n- Open source\n\nWatch for: The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud\n\n### Microsoft Power Automate (B)\n\nGood for: Organisations already on Microsoft 365 and Dataverse that want an agent to inventory, deploy or adjust flows inside existing roles and solutions.\n\nAhead on:\n- Security \u0026 auth, 61 against 41\n- Transparency \u0026 trust, 76 against 69\n\nAlso in its favour:\n- No incidents deducted, where Kestra loses 7 points for them\n\nWatch for: Flows under My flows can't be managed in code, and Microsoft calls the `api.flow.microsoft.com` API unsupported\n\n\n## Score by category\n\n| Category | Weight | Kestra | Microsoft Power Automate | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 89 | 63 | Kestra +26 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 68 | Kestra +14 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 69 | Kestra +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 41 | 61 | Microsoft Power Automate +20 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 25 | Kestra +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 93 | 76 | Kestra +17 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 76 | Microsoft Power Automate +7 |\n| Negative events | ≤15 | -7 | 0 | |\n| **Total** | | **63.6 · B** | **62 · B** | |\n\n## Facts side by side\n\n| Fact | Kestra | Microsoft Power Automate |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Kestra Technologies | Microsoft |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial | Proprietary service under the Microsoft Product Terms for Microsoft Power Platform |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | no |\n| Last release | 2026-10-05 | 2026-10-02 |\n| Terms last updated | no document linked | no date given |\n| Privacy policy last updated | no document linked | 2026-09-01 |\n| Customer content may train models |  | yes |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 29k stars, 244 npm/wk, 170 PyPI/wk | 11k PyPI/wk |\n\n## Verdicts\n\n**Kestra.** Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.\n\n**Microsoft Power Automate.** Cloud flows in a solution are rows an agent can read and write through the Dataverse Web API under Entra ID OAuth and security roles, with published limits and a 99.9 per cent SLA. Flows under My flows can't be managed in code, a flow's body is one hand-built JSON string, and setup needs a tenant administrator.\n\n## Before you call either\n\n### Kestra\n\n1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3\n2. Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port\n3. Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`\n4. Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call\n5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth\n\n### Microsoft Power Automate\n\n1. Filter `workflows` on `category eq 5` for cloud flows, and add `$select`, because `clientdata` holds the whole definition\n2. Flows created through the API start with `statecode` 0 (off). The docs say to turn the flow on before use\n3. Put the flow in a solution first. Flows that sit only under My flows are outside the supported API\n4. On 429 wait the `Retry-After` seconds. Reads of `flowruns` count against the daily Power Platform request allowance\n5. Treat an HTTP trigger URL with `sig=` as a secret, and prefer the tenant or named-user trigger modes with a bearer token for `https://service.flow.microsoft.com/`\n\n## Questions\n\n### Which is better for AI agents, Kestra or Microsoft Power Automate?\n\nKestra scores 63.6 (B) on agent readiness against Microsoft Power Automate's 62 (B), and leads in 5 of 7 scored categories. Microsoft Power Automate leads on security \u0026 auth and transparency \u0026 trust.\n\n### Do Kestra and Microsoft Power Automate need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Kestra and Microsoft Power Automate without installing anything?\n\nNo hosted endpoint is listed for Kestra. No hosted endpoint is listed for Microsoft Power Automate.\n\n### Are Kestra and Microsoft Power Automate open source?\n\nKestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). No open-source release is listed for Microsoft Power Automate.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kestra-vs-power-automate.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kestra-vs-power-automate.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kestra\", \"b\": \"power-automate\"}`. From a terminal: `anchor compare kestra power-automate`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kestra.json and https://www.anchorterminal.com/api/v1/tools/power-automate.json\n\n## Other comparisons with Kestra or Microsoft Power Automate\n\n- [Activepieces API + MCP vs Kestra](https://www.anchorterminal.com/compare/activepieces-vs-kestra.md)\n- [Activepieces API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/activepieces-vs-power-automate.md)\n- [Gumloop vs Kestra](https://www.anchorterminal.com/compare/gumloop-vs-kestra.md)\n- [Gumloop vs Microsoft Power Automate](https://www.anchorterminal.com/compare/gumloop-vs-power-automate.md)\n- [Kestra vs Make API + MCP](https://www.anchorterminal.com/compare/kestra-vs-make.md)\n- [Kestra vs n8n API + MCP](https://www.anchorterminal.com/compare/kestra-vs-n8n.md)\n- [Kestra vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/kestra-vs-paragon.md)\n- [Kestra vs Pipedream API + MCP](https://www.anchorterminal.com/compare/kestra-vs-pipedream.md)\n- [Kestra vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/kestra-vs-tray.md)\n- [Kestra vs Windmill API + MCP](https://www.anchorterminal.com/compare/kestra-vs-windmill.md)\n- [Kestra vs Workato API + MCP](https://www.anchorterminal.com/compare/kestra-vs-workato.md)\n- [Make API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/make-vs-power-automate.md)\n- [n8n API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/n8n-vs-power-automate.md)\n- [Paragon ActionKit + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/paragon-vs-power-automate.md)\n- [Pipedream API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/pipedream-vs-power-automate.md)\n- [Microsoft Power Automate vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/power-automate-vs-tray.md)\n- [Microsoft Power Automate vs Windmill API + MCP](https://www.anchorterminal.com/compare/power-automate-vs-windmill.md)\n- [Microsoft Power Automate vs Workato API + MCP](https://www.anchorterminal.com/compare/power-automate-vs-workato.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kestra vs Microsoft Power Automate",
        "url": ""
      }
    ],
    "description": "Kestra scores 63.6 (B) on agent readiness against Microsoft Power Automate's 62 (B), and leads in 5 of 7 scored categories. Microsoft Power Automate leads on security \u0026 auth and transparency \u0026 trust. Both do automation workflows. Category scores, facts, verdicts and agent notes…",
    "facts": [
      "Kestra B 63.6",
      "Microsoft Power Automate B 62",
      "scores"
    ],
    "h1": "Kestra vs Microsoft Power Automate",
    "image": "https://www.anchorterminal.com/assets/og/compare-kestra-vs-power-automate.png",
    "path": "/compare/kestra-vs-power-automate",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kestra vs Microsoft Power Automate for AI agents, B 63.6 vs B 62",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/kestra-vs-power-automate"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 730
  },
  "version": 1
}
