{
  "data": {
    "a": {
      "slug": "kestra",
      "name": "Kestra",
      "vendor": "Kestra Technologies",
      "vendorUrl": "https://kestra.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Kestra is an open-source workflow orchestrator from Kestra Technologies. Flows are written in YAML and run on a server the owner hosts, with a REST API, SDKs in four languages and flows exposed as MCP tools.",
      "url": "https://www.anchorterminal.com/tools/kestra",
      "markdownUrl": "https://www.anchorterminal.com/tools/kestra.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/kestra.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kestra.json",
      "repo": "https://github.com/kestra-io/kestra",
      "license": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "oci",
          "name": "kestra/kestra"
        },
        {
          "registry": "pypi",
          "name": "kestrapy"
        },
        {
          "registry": "npm",
          "name": "@kestra-io/kestra-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "The open-source edition takes HTTP Basic auth with one username and password, set in `kestra.server.basic-auth` or on the setup page at first start. That credential has full access. Bearer API tokens, service accounts, OAuth, SSO and role-based access are in the Enterprise Edition and Kestra Cloud only. Access to open source is self-serve, by running the server. Webhook triggers are called with a key in the URL path.",
      "pricing": "freemium",
      "pricingNotes": "The open-source edition is free under Apache-2.0 with unlimited flows and executions, and an agent can start on it with no contract or account. Enterprise Edition is an annual subscription per instance through sales, with no public price. Kestra Cloud is by access request, with 14 days free and no card, then billed on task runs and Cloud runner time at rates that are not published (https://kestra.io/pricing, checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 29427,
        "npmWeekly": 244,
        "pypiWeekly": 170,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://kestra.io/docs",
      "llmsTxt": "https://kestra.io/llms.txt",
      "openapi": "https://kestra.io/kestra.yml",
      "capabilities": [
        "automation.workflows",
        "automation.code",
        "automation.webhooks",
        "automation.apps",
        "agent.tools"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "local",
        "hosted",
        "freemium",
        "openapi",
        "llms-txt",
        "mcp",
        "python",
        "typescript",
        "java",
        "go",
        "webhooks",
        "enterprise",
        "soc2"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.6,
        "grade": "B",
        "agentReady": false,
        "rank": 387,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -7,
        "negativeNotes": [
          "Five advisories rated critical were published on the repository in six months. GHSA-365w-2m69-mp9x (CVE-2026-34612, remote code execution through SQL injection, 30 March 2026), GHSA-5vc5-wxxq-3fjx and GHSA-2q47-568g-9h4f (CVE-2026-49869 and CVE-2026-53576, unauthenticated remote code execution through authentication filter bypass, 3 June 2026), and GHSA-rjhm-qm6w-m7x9 and GHSA-j5cv-8rw9-vv2p (unauthenticated remote code execution and authentication bypass, 29 September 2026). All are fixed, in 1.3.38 and 1.0.60 at the latest, and the maintainers published each one, so the deduction is reduced (https://github.com/kestra-io/kestra/security/advisories).",
          "Two further high advisories affected the default open-source setup. GHSA-hrr4-xg8h-5p6f, an unauthenticated gRPC control plane on port 50051, fixed in 2.0.3 and published 29 September 2026, and GHSA-94pv-f379-3gp3, a revoked administrator credential that stayed valid, fixed in 1.3.41 and published 6 October 2026 (https://github.com/kestra-io/kestra/security/advisories)."
        ],
        "verdict": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.",
        "bestFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "strengths": [
          "OpenAPI 3.0.1 spec for the open-source API with 216 operations, 213 of them documenting 401, 403 and 500 as problem+json",
          "Every docs page is served as Markdown by adding `.md`, with `llms.txt` and `llms-full.txt`",
          "32 releases between 15 July and 5 October 2026, with patches each week on the 1.3 and 2.0 long-term support lines",
          "Any flow becomes an MCP tool through `McpToolTrigger`, with read-only, destructive and idempotent hints set per flow",
          "Apache-2.0 server, and usage reporting documented field by field with two switches to turn it off"
        ],
        "weaknesses": [
          "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud",
          "Five critical advisories from 30 March to 29 September 2026, four of them unauthenticated remote code execution or authentication bypass, all fixed",
          "Kestra Cloud is request-access with no public price, and Enterprise is sold by annual contract through sales",
          "No rate limits and no idempotency key on the API. The correlation ID pattern needs a guard written into the flow",
          "The docs say `kestrapy` 2.0.1 imports `regex` without declaring it, so a plain install fails on import"
        ],
        "agentNotes": [
          "Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3",
          "Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port",
          "Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`",
          "Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call",
          "Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.6
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 93,
          "payments": 50,
          "reliability": 89,
          "schema": 82,
          "security": 41,
          "transparency": 86
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "docker run --pull=always --rm -it -p 8080:8080 --user=root --name kestra -v kestra_data:/app/storage -v kestra_db:/app/data -v /var/run/docker.sock:/var/run/docker.sock -v /tmp:/tmp -e KESTRA_PLUGINS_AUTO_INSTALL_ENABLED=true kestra/kestra:latest-slim server local",
        "http": "curl -X POST -u 'admin@kestra.io:kestra' http://localhost:8080/api/v1/main/executions/company.team/hello_world",
        "claudeCode": "claude mcp add \u003cserver-id\u003e \u003cserver-url\u003e --transport http --header \"Authorization: Basic $(echo -n 'username:password' | base64)\""
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/kestra"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Kestra Technologies SAS",
        "domain": "kestra.io",
        "domainRegistered": "2019-12-18",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/kestra-io/kestra/releases",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Cloud terms name Kestra Technologies SAS (RCS 900 427 873), 81 rue du Pré Catelan, 59110 La Madeleine, France, and Kestra Technologies Inc., a Delaware corporation, for customers billed in the Americas.",
          "No terms or privacy link is given because the edition graded is Apache-2.0 software the owner runs. The Kestra Cloud Terms of Service and Kestra Cloud Privacy Policy (both 14 September 2026) say they do not cover the open-source project, and the privacy policy at kestra.io/privacy-policy covers only the website.",
          "The API answers on the owner's own host. Only the documentation MCP server (api.kestra.io) and the usage reports go to a Kestra domain.",
          "https://kestra.io/.well-known/security.txt names security@kestra.io and the GitHub advisory form, and expires on 26 August 2028.",
          "RDAP for kestra.io gives a registration date of 2019-12-18.",
          "status.kestra.io did not answer our requests on 8 October 2026 and no status page is linked from the pricing, security or Cloud pages."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kestra.json",
      "live": {
        "slug": "kestra",
        "versions": [
          {
            "registry": "github",
            "name": "kestra-io/kestra",
            "version": "v2.0.5",
            "released": "2026-10-05",
            "seenAt": "2026-10-09T17:00:07.156813448Z"
          },
          {
            "registry": "npm",
            "name": "@kestra-io/kestra-sdk",
            "version": "2.0.1",
            "seenAt": "2026-10-09T17:00:06.275016115Z"
          },
          {
            "registry": "pypi",
            "name": "kestrapy",
            "version": "2.0.1",
            "released": "2026-09-11",
            "seenAt": "2026-10-09T17:00:06.083664173Z"
          }
        ],
        "githubStars": 29456,
        "npmWeekly": 266,
        "pypiWeekly": 227,
        "securityTxt": {
          "url": "https://kestra.io/.well-known/security.txt",
          "state": "valid",
          "expires": "2028-08-26T00:00:00.000Z",
          "checkedAt": "2026-10-09T15:39:51.010707527Z"
        },
        "llmsTxt": {
          "url": "https://kestra.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:02:11.836658178Z"
        },
        "pages": [
          {
            "url": "https://kestra.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:40:38.900711725Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d49664bbbe0e"
          }
        ],
        "updatedAt": "2026-10-09T18:40:38.900711725Z"
      }
    },
    "answer": "Kestra scores 63.6 (B) on agent readiness against Prismatic's 59.1 (C), and leads in 6 of 7 scored categories. Prismatic leads on security \u0026 auth.",
    "b": {
      "slug": "prismatic",
      "name": "Prismatic",
      "vendor": "Prismatic Software Inc.",
      "vendorUrl": "https://prismatic.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Prismatic is an embedded integration platform for B2B software companies. Teams build integrations in a low-code designer or in TypeScript, deploy them to customers, and manage them through a GraphQL API, the Prism CLI and MCP servers.",
      "url": "https://www.anchorterminal.com/tools/prismatic",
      "markdownUrl": "https://www.anchorterminal.com/tools/prismatic.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/prismatic.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/prismatic.json",
      "repo": "https://github.com/prismatic-io/prism",
      "license": "Proprietary service. The Prism CLI, the Spectral and embedded SDKs, the Prism MCP dev server and the Claude Code skills on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://mcp.prismatic.io/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@prismatic-io/prism"
        },
        {
          "registry": "npm",
          "name": "@prismatic-io/prism-mcp"
        },
        {
          "registry": "npm",
          "name": "@prismatic-io/spectral"
        },
        {
          "registry": "npm",
          "name": "@prismatic-io/embedded"
        }
      ],
      "auth": "oauth",
      "authNotes": "Access starts with a person creating an account, by free trial or contract, and logging in through the browser (`prism login`). The API takes that user's JWT as a Bearer token. `prism me:token --type refresh` prints a refresh token for headless use, exchanged at `/auth/refresh` for an access token valid for 7 days. Tokens have no scopes of their own and act with the user's role. The hosted MCP flow server uses MCP OAuth or the same Bearer token, and embedded end users get a JWT signed by the customer's backend.",
      "pricing": "paid",
      "pricingNotes": "No public prices. The pricing page lists Scale, Enterprise and Custom plans with volume per-instance pricing, each ending in a demo request. A free trial exists, and the Terms of Use set it at 30 days unless stated otherwise at signup. Whether the trial needs a card could not be read because the signup form is drawn by script. Contracts set fair use limits in gigabyte-seconds of compute per instance per month (checked 2026-10-09).",
      "priceSummary": "Paid",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the API docs or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 29,
        "npmWeekly": 8416,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://prismatic.io/docs/api/",
      "llmsTxt": "https://prismatic.io/docs/llms.txt",
      "registryName": "io.github.prismatic-io/prism-mcp",
      "capabilities": [
        "automation.workflows",
        "automation.embedded",
        "automation.apps",
        "automation.code",
        "automation.webhooks",
        "automation.auth",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "graphql",
        "mcp",
        "cli",
        "oauth",
        "llms-txt",
        "typescript",
        "sales-led",
        "status-page",
        "soc2",
        "webhooks",
        "closed-source"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.1,
        "grade": "C",
        "agentReady": false,
        "rank": 561,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 83,
          "payments": 0,
          "reliability": 67,
          "schema": 75,
          "security": 59,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "The GraphQL API covers 120 queries and 124 mutations with typed inputs, cursor pagination and Markdown documentation, and tokens follow seven user roles. No price is published, paid use runs under an agreement that is not public, and no API rate limit or idempotency key was found in the reviewed documentation.",
        "bestFor": "A B2B software company that wants to build integrations once, deploy them per customer and let an in-app agent call them as MCP tools.",
        "strengths": [
          "GraphQL API with 120 documented queries and 124 mutations, field selection, cursor pagination and per-query filters",
          "Every docs page has a Markdown twin, indexed by `llms.txt` at prismatic.io/docs/llms.txt",
          "Hosted MCP flow server in seven regions, with OAuth 2.0 and endpoints scoped to one integration or one instance",
          "Seven organisation roles, including a read-only guest and a third-party role limited to named integrations, components or customers",
          "Dated changelog with ten entries from 20 August to 1 October 2026, and CLI and SDK releases in the same weeks"
        ],
        "weaknesses": [
          "No prices on the pricing page. All three plans end in a demo request",
          "Paid use is governed by a separate agreement that is not published. The public terms cover the website and 30-day trials",
          "No API rate limit, `Retry-After` behaviour or idempotency key found in the reviewed documentation",
          "API tokens carry the whole role of the user who created them, and revoking one refresh token revokes all of that user's",
          "Mutation failures return HTTP 200 with an `errors` array of field and message, with no error codes"
        ],
        "agentNotes": [
          "Have a person run `prism login` once, then store the output of `prism me:token --type refresh` as `PRISM_REFRESH_TOKEN`. Access tokens last 7 days",
          "Read the `errors` array on every mutation. A failed mutation still returns HTTP 200",
          "Pass `sortBy` with `CREATED_AT` when paging. Without a sort order pages can repeat or skip records",
          "Use the regional host for the tenant, such as `app.eu-west-1.prismatic.io` and `mcp.eu-west-1.prismatic.io`",
          "Create a guest user for a read-only agent, because tokens have no scopes of their own"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.1
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 83,
          "payments": 0,
          "reliability": 67,
          "schema": 75,
          "security": 59,
          "transparency": 40
        },
        "provenanceScore": 89
      },
      "connect": {
        "install": "npm install --global @prismatic-io/prism",
        "http": "curl https://app.prismatic.io/api --request POST --header \"Authorization: Bearer ${PRISMATIC_API_TOKEN}\" --header \"Content-Type: application/json\" --data '{\"query\": \"query { integrations { nodes { id name }}}\"}'",
        "claudeCode": "claude mcp add-json prismatic '{\"type\":\"stdio\",\"command\":\"npx\",\"args\":[\"-y\",\"mcp-remote\",\"https://mcp.prismatic.io/mcp\"]}'",
        "config": {
          "mcpServers": {
            "prism": {
              "args": [
                "-y",
                "@prismatic-io/prism-mcp",
                "."
              ],
              "command": "npx",
              "env": {
                "PRISMATIC_URL": "https://app.prismatic.io"
              },
              "type": "stdio"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/prismatic"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Prismatic Software Inc.",
        "domain": "prismatic.io",
        "domainRegistered": "2016-07-09",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "https://prismatic.io/legal/privacy/",
        "statusPage": "https://www.prismatic-status.io",
        "changelog": "https://prismatic.io/docs/changelog/",
        "securityTxt": "valid",
        "checked": "2026-10-09",
        "notes": [
          "The Terms of Use (last updated 17 March 2023) name Prismatic Software Inc., 5013 S Louise Ave #122, Sioux Falls, SD 57108, and are governed by South Dakota law.",
          "No terms link is recorded. The Terms of Use at https://prismatic.io/legal/terms/ are website terms that also cover trial accounts, and they say non-trial use of the Services is subject to a separate agreement, which is not published.",
          "The Privacy Policy (last updated 26 June 2024) covers the website and the web application at app.prismatic.io.",
          "security.txt at https://prismatic.io/.well-known/security.txt names security@prismatic.io and a PGP key and expires on 16 June 2027.",
          "The API, the regional hosts and the MCP flow server are all on prismatic.io subdomains. The status page is on prismatic-status.io and the trust centre on trust-prismatic.io.",
          "RDAP for prismatic.io gives a registration date of 2016-07-09."
        ],
        "score": 89
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/prismatic.json",
      "live": {
        "slug": "prismatic",
        "probe": {
          "target": "https://mcp.prismatic.io/mcp",
          "method": "get",
          "lastAt": "2026-10-10T02:55:06.837417349Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 296,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 298,
          "p95ms24h": 389,
          "samples24h": 115,
          "samples30d": 115,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 30,
              "ok": 30
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.prismatic-status.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T02:50:43.967273294Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "prismatic-io/prism",
            "version": "v10.5.0",
            "released": "2026-09-30",
            "seenAt": "2026-10-09T17:14:48.08709817Z"
          },
          {
            "registry": "npm",
            "name": "@prismatic-io/embedded",
            "version": "4.14.0",
            "seenAt": "2026-10-09T17:14:46.07500175Z"
          },
          {
            "registry": "npm",
            "name": "@prismatic-io/prism",
            "version": "10.5.0",
            "seenAt": "2026-10-09T17:14:41.869797583Z"
          },
          {
            "registry": "npm",
            "name": "@prismatic-io/prism-mcp",
            "version": "1.5.0",
            "seenAt": "2026-10-09T17:14:42.93328997Z"
          },
          {
            "registry": "npm",
            "name": "@prismatic-io/spectral",
            "version": "10.34.1",
            "seenAt": "2026-10-09T17:14:44.108249111Z"
          }
        ],
        "githubStars": 29,
        "npmWeekly": 8416,
        "pages": [
          {
            "url": "https://prismatic.io/docs/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:50.569023777Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8f4fb9151364"
          },
          {
            "url": "https://prismatic.io/legal/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:53.22345549Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6521c9b1a5d9"
          }
        ],
        "updatedAt": "2026-10-10T02:55:06.837417349Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Kestra Technologies",
        "b": "Prismatic Software Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mcp.prismatic.io/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial",
        "b": "Proprietary service. The Prism CLI, the Spectral and embedded SDKs, the Prism MCP dev server and the Claude Code skills on GitHub are MIT",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "not listed",
        "b": "io.github.prismatic-io/prism-mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-05",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "2024-06-26",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "29k stars, 244 npm/wk, 170 PyPI/wk",
        "b": "29 stars, 8.4k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Kestra scores 63.6 (B) on agent readiness against Prismatic's 59.1 (C), and leads in 6 of 7 scored categories. Prismatic leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Kestra or Prismatic?"
      },
      {
        "answer": "Kestra takes an API key or an OAuth sign-in. Prismatic uses an OAuth sign-in.",
        "question": "Do Kestra and Prismatic need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Kestra. Prismatic has a hosted endpoint at https://mcp.prismatic.io/mcp.",
        "question": "Can an agent call Kestra and Prismatic without installing anything?"
      },
      {
        "answer": "Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). No open-source release is listed for Prismatic.",
        "question": "Are Kestra and Prismatic open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 89 against 67",
          "Schema \u0026 documentation, 82 against 75",
          "Agent ergonomics, 73 against 63",
          "Payments \u0026 pricing, 50 against 0",
          "Maintenance \u0026 community, 93 against 83"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.",
        "slug": "kestra",
        "watchFor": "The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 59 against 41"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Runs on your own machine",
          "No incidents deducted, where Kestra loses 7 points for them"
        ],
        "goodFor": "A B2B software company that wants to build integrations once, deploy them per customer and let an in-app agent call them as MCP tools.",
        "slug": "prismatic",
        "watchFor": "No prices on the pricing page. All three plans end in a demo request"
      }
    ],
    "job": {
      "capability": "automation.workflows",
      "name": "Workflow automation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-kestra.json",
        "title": "Activepieces API + MCP vs Kestra",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-kestra"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-prismatic.json",
        "title": "Activepieces API + MCP vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-kestra.json",
        "title": "Gumloop vs Kestra",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-kestra"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-prismatic.json",
        "title": "Gumloop vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-make.json",
        "title": "Kestra vs Make API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-make"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-n8n.json",
        "title": "Kestra vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-node-red.json",
        "title": "Kestra vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-paragon.json",
        "title": "Kestra vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-pipedream.json",
        "title": "Kestra vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-power-automate.json",
        "title": "Kestra vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-tray.json",
        "title": "Kestra vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-windmill.json",
        "title": "Kestra vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-workato.json",
        "title": "Kestra vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-prismatic.json",
        "title": "Make API + MCP vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/make-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-prismatic.json",
        "title": "n8n API + MCP vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-prismatic.json",
        "title": "Node-RED vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pipedream-vs-prismatic.json",
        "title": "Pipedream API + MCP vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/pipedream-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/power-automate-vs-prismatic.json",
        "title": "Microsoft Power Automate vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/power-automate-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prismatic-vs-tray.json",
        "title": "Prismatic vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/prismatic-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prismatic-vs-windmill.json",
        "title": "Prismatic vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/prismatic-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prismatic-vs-workato.json",
        "title": "Prismatic vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/prismatic-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paragon-vs-prismatic.json",
        "title": "Paragon ActionKit + MCP vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/paragon-vs-prismatic"
      }
    ],
    "scores": [
      {
        "by": 22,
        "edge": "kestra",
        "kestra": 89,
        "key": "reliability",
        "name": "Reliability",
        "prismatic": 67,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "edge": "kestra",
        "kestra": 82,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "prismatic": 75,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "kestra",
        "kestra": 73,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "prismatic": 63,
        "weight": 13
      },
      {
        "by": 18,
        "edge": "prismatic",
        "kestra": 41,
        "key": "security",
        "name": "Security \u0026 auth",
        "prismatic": 59,
        "weight": 14
      },
      {
        "by": 50,
        "edge": "kestra",
        "kestra": 50,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "prismatic": 0,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 10,
        "edge": "kestra",
        "kestra": 93,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "prismatic": 83,
        "weight": 7
      },
      {
        "by": 4,
        "edge": "kestra",
        "kestra": 69,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "prismatic": 65,
        "weight": 7
      }
    ],
    "summary": "Kestra scores 63.6 (B) on agent readiness against Prismatic's 59.1 (C), and leads in 6 of 7 scored categories. Prismatic leads on security \u0026 auth. Both do workflow automation.",
    "verdicts": {
      "kestra": "Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.",
      "prismatic": "The GraphQL API covers 120 queries and 124 mutations with typed inputs, cursor pagination and Markdown documentation, and tokens follow seven user roles. No price is published, paid use runs under an agreement that is not public, and no API rate limit or idempotency key was found in the reviewed documentation."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/kestra-vs-prismatic",
    "json": "https://www.anchorterminal.com/compare/kestra-vs-prismatic.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/kestra-vs-prismatic.md",
    "slim": "https://www.anchorterminal.com/compare/kestra-vs-prismatic.min.md"
  },
  "markdown": "Kestra scores 63.6 (B) on agent readiness against Prismatic's 59.1 (C), and leads in 6 of 7 scored categories. Prismatic leads on security \u0026 auth. Both do workflow automation.\n\n- Kestra: grade B, 63.6/100, rank #387 of 950. Markdown https://www.anchorterminal.com/tools/kestra.md · JSON https://www.anchorterminal.com/api/v1/tools/kestra.json\n- Prismatic: grade C, 59.1/100, rank #561 of 950. Markdown https://www.anchorterminal.com/tools/prismatic.md · JSON https://www.anchorterminal.com/api/v1/tools/prismatic.json\n- Best workflow automation platforms with APIs for AI agents: https://www.anchorterminal.com/best/workflow-automation/index.md\n- All 108 workflows comparisons: https://www.anchorterminal.com/compare/workflow-automation/index.md\n\n## Which one, for what\n\n### Kestra (B)\n\nGood for: Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.\n\nAhead on:\n- Reliability, 89 against 67\n- Schema \u0026 documentation, 82 against 75\n- Agent ergonomics, 73 against 63\n- Payments \u0026 pricing, 50 against 0\n- Maintenance \u0026 community, 93 against 83\n\nAlso in its favour:\n- Open source\n\nWatch for: The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud\n\n### Prismatic (C)\n\nGood for: A B2B software company that wants to build integrations once, deploy them per customer and let an in-app agent call them as MCP tools.\n\nAhead on:\n- Security \u0026 auth, 59 against 41\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Runs on your own machine\n- No incidents deducted, where Kestra loses 7 points for them\n\nWatch for: No prices on the pricing page. All three plans end in a demo request\n\n\n## Score by category\n\n| Category | Weight | Kestra | Prismatic | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 89 | 67 | Kestra +22 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 75 | Kestra +7 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 63 | Kestra +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 41 | 59 | Prismatic +18 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 0 | Kestra +50 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 93 | 83 | Kestra +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 65 | Kestra +4 |\n| Negative events | ≤15 | -7 | 0 | |\n| **Total** | | **63.6 · B** | **59.1 · C** | |\n\n## Facts side by side\n\n| Fact | Kestra | Prismatic |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Kestra Technologies | Prismatic Software Inc. |\n| Hosted endpoint | no (local only) | `https://mcp.prismatic.io/mcp` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP, stdio |\n| Auth | OAuth or key | OAuth |\n| Pricing | Freemium | Paid |\n| x402 | no | no |\n| Licence | Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial | Proprietary service. The Prism CLI, the Spectral and embedded SDKs, the Prism MCP dev server and the Claude Code skills on GitHub are MIT |\n| Read-only variant documented | yes | yes |\n| llms.txt | yes | yes |\n| MCP registry | not listed | `io.github.prismatic-io/prism-mcp` |\n| Last release | 2026-10-05 | 2026-10-06 |\n| Terms last updated | no document linked | no document linked |\n| Privacy policy last updated | no document linked | 2024-06-26 |\n| Customer content may train models |  |  |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 29k stars, 244 npm/wk, 170 PyPI/wk | 29 stars, 8.4k npm/wk |\n\n## Verdicts\n\n**Kestra.** Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.\n\n**Prismatic.** The GraphQL API covers 120 queries and 124 mutations with typed inputs, cursor pagination and Markdown documentation, and tokens follow seven user roles. No price is published, paid use runs under an agreement that is not public, and no API rate limit or idempotency key was found in the reviewed documentation.\n\n## Before you call either\n\n### Kestra\n\n1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3\n2. Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port\n3. Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}`\n4. Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call\n5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth\n\n### Prismatic\n\n1. Have a person run `prism login` once, then store the output of `prism me:token --type refresh` as `PRISM_REFRESH_TOKEN`. Access tokens last 7 days\n2. Read the `errors` array on every mutation. A failed mutation still returns HTTP 200\n3. Pass `sortBy` with `CREATED_AT` when paging. Without a sort order pages can repeat or skip records\n4. Use the regional host for the tenant, such as `app.eu-west-1.prismatic.io` and `mcp.eu-west-1.prismatic.io`\n5. Create a guest user for a read-only agent, because tokens have no scopes of their own\n\n## Questions\n\n### Which is better for AI agents, Kestra or Prismatic?\n\nKestra scores 63.6 (B) on agent readiness against Prismatic's 59.1 (C), and leads in 6 of 7 scored categories. Prismatic leads on security \u0026 auth.\n\n### Do Kestra and Prismatic need an API key?\n\nKestra takes an API key or an OAuth sign-in. Prismatic uses an OAuth sign-in.\n\n### Can an agent call Kestra and Prismatic without installing anything?\n\nNo hosted endpoint is listed for Kestra. Prismatic has a hosted endpoint at https://mcp.prismatic.io/mcp.\n\n### Are Kestra and Prismatic open source?\n\nKestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). No open-source release is listed for Prismatic.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/kestra-vs-prismatic.json, and with the fewest tokens: https://www.anchorterminal.com/compare/kestra-vs-prismatic.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"kestra\", \"b\": \"prismatic\"}`. From a terminal: `anchor compare kestra prismatic`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/kestra.json and https://www.anchorterminal.com/api/v1/tools/prismatic.json\n\n## Other comparisons with Kestra or Prismatic\n\n- [Activepieces API + MCP vs Kestra](https://www.anchorterminal.com/compare/activepieces-vs-kestra.md)\n- [Activepieces API + MCP vs Prismatic](https://www.anchorterminal.com/compare/activepieces-vs-prismatic.md)\n- [Gumloop vs Kestra](https://www.anchorterminal.com/compare/gumloop-vs-kestra.md)\n- [Gumloop vs Prismatic](https://www.anchorterminal.com/compare/gumloop-vs-prismatic.md)\n- [Kestra vs Make API + MCP](https://www.anchorterminal.com/compare/kestra-vs-make.md)\n- [Kestra vs n8n API + MCP](https://www.anchorterminal.com/compare/kestra-vs-n8n.md)\n- [Kestra vs Node-RED](https://www.anchorterminal.com/compare/kestra-vs-node-red.md)\n- [Kestra vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/kestra-vs-paragon.md)\n- [Kestra vs Pipedream API + MCP](https://www.anchorterminal.com/compare/kestra-vs-pipedream.md)\n- [Kestra vs Microsoft Power Automate](https://www.anchorterminal.com/compare/kestra-vs-power-automate.md)\n- [Kestra vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/kestra-vs-tray.md)\n- [Kestra vs Windmill API + MCP](https://www.anchorterminal.com/compare/kestra-vs-windmill.md)\n- [Kestra vs Workato API + MCP](https://www.anchorterminal.com/compare/kestra-vs-workato.md)\n- [Make API + MCP vs Prismatic](https://www.anchorterminal.com/compare/make-vs-prismatic.md)\n- [n8n API + MCP vs Prismatic](https://www.anchorterminal.com/compare/n8n-vs-prismatic.md)\n- [Node-RED vs Prismatic](https://www.anchorterminal.com/compare/node-red-vs-prismatic.md)\n- [Pipedream API + MCP vs Prismatic](https://www.anchorterminal.com/compare/pipedream-vs-prismatic.md)\n- [Microsoft Power Automate vs Prismatic](https://www.anchorterminal.com/compare/power-automate-vs-prismatic.md)\n- [Prismatic vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/prismatic-vs-tray.md)\n- [Prismatic vs Windmill API + MCP](https://www.anchorterminal.com/compare/prismatic-vs-windmill.md)\n- [Prismatic vs Workato API + MCP](https://www.anchorterminal.com/compare/prismatic-vs-workato.md)\n- [Paragon ActionKit + MCP vs Prismatic](https://www.anchorterminal.com/compare/paragon-vs-prismatic.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Kestra vs Prismatic",
        "url": ""
      }
    ],
    "description": "Kestra scores 63.6 (B) to Prismatic's 59.1 (C) for workflow automation. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Kestra B 63.6",
      "Prismatic C 59.1",
      "scores"
    ],
    "h1": "Kestra vs Prismatic",
    "image": "https://www.anchorterminal.com/assets/og/compare-kestra-vs-prismatic.png",
    "path": "/compare/kestra-vs-prismatic",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Kestra vs Prismatic for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/kestra-vs-prismatic"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 680
  },
  "version": 1
}
