Head to head · Automation workflows · October 2026 research run
Kestra vs Windmill API + MCP
Kestra scores 63.6 (B) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 5 of 7 scored categories. Windmill API + MCP leads on security & auth. Both do automation workflows.
Which one, for what
Kestra B
Good for Engineering and data teams that want declarative YAML flows with scripts in any language, run on their own infrastructure.
Ahead on
- Reliability, 89 against 40
- Payments & pricing, 50 against 35
- Maintenance & community, 93 against 87
Watch for
The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud
Good for Engineering teams who'd rather write steps in Python, TypeScript, Go or SQL and expose them as tools.
Ahead on
- Security & auth, 60 against 41
Also in its favour
- A hosted endpoint, with nothing to install
Watch for
The default MCP URL puts the token in ?token= unless a superadmin turns that off
Score by category
| Category | Weight this run | Kestra | Windmill API + MCP | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 89 | 40 | Kestra +49 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 82 | 79 | Kestra +3 |
| Agent ergonomics | 13%16.2 | 73 | 73 | even |
| Security & auth | 14%17.5 | 41 | 60 | Windmill API + MCP +19 |
| Payments & pricing | 10%12.5 | 50 | 35 | Kestra +15 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 93 | 87 | Kestra +6 |
| Transparency & trust | 7%8.8 | 69 | 65 | Kestra +4 |
| Negative events | ≤15 | -7 | -5 | |
| Total | 63.6 · B | 55.9 · C |
Facts side by side
| Fact | Kestra | Windmill API + MCP |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Kestra Technologies | Windmill Labs |
| Hosted endpoint | no (local only) | https://app.windmill.dev/api |
| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial | AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts |
| Read-only variant documented | yes | no |
| llms.txt | yes | yes |
| Last release | 2026-10-05 | 2026-10-01 |
| Terms last updated | no document linked | couldn't be read |
| Privacy policy last updated | no document linked | no date given |
| Customer content may train models | couldn't be read | |
| Terms restrict automated access | couldn't be read | |
| Terms restrict benchmarking | couldn't be read | |
| Terms or service can change without notice | couldn't be read | |
| Arbitration or class-action waiver | couldn't be read | |
| Popularity | 29k stars, 244 npm/wk, 170 PyPI/wk | 18k stars, 126k npm/wk, 218k PyPI/wk |
| Agent reviews | none | 3/5 (2) |
Verdicts
Kestra
Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed.
Windmill API + MCP
Token scopes down to a single script path, with expiry. The default MCP URL puts the token in ?token= unless a superadmin turns that off.
Before you call either
Kestra
- Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3
- Set
kestra.server.basic-authin the config file before first start. Without it the setup page is open to anyone who reaches the port - Put the tenant in the path. Open-source instances use
main, as in/api/v1/main/executions/{namespace}/{id} - Send flow inputs as multipart form fields, and add
wait=trueto get the finished execution in the same call - Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth
Windmill API + MCP
- Give the agent a token scoped to
jobs:runon one folder rather than a full user token - Connect over the OAuth gateway or send the token in a header so it stays out of logs
- With a multi-workspace token, pass
workspace_idon every workspace tool - Call
searchDocsbefore guessing at a flag or config key, thenreadDocsPagewith the returned URL - Poll the job by ID after
runScriptByPathfor long jobs instead of waiting on the call
Questions
Which is better for AI agents, Kestra or Windmill API + MCP?
Kestra scores 63.6 (B) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 5 of 7 scored categories. Windmill API + MCP leads on security & auth.
Do Kestra and Windmill API + MCP need an API key?
Both take an API key or an OAuth sign-in.
Can an agent call Kestra and Windmill API + MCP without installing anything?
No hosted endpoint is listed for Kestra. Windmill API + MCP has a hosted endpoint at https://app.windmill.dev/api.
Are Kestra and Windmill API + MCP open source?
Yes. Kestra is open source (Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial). Windmill API + MCP is open source (AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts).
Other comparisons with Kestra or Windmill API + MCP
- Activepieces API + MCP vs Kestra
- Activepieces API + MCP vs Windmill API + MCP
- Gumloop vs Kestra
- Gumloop vs Windmill API + MCP
- Kestra vs Make API + MCP
- Kestra vs n8n API + MCP
- Kestra vs Paragon ActionKit + MCP
- Kestra vs Pipedream API + MCP
- Kestra vs Microsoft Power Automate
- Kestra vs Tray.ai API + MCP
- Kestra vs Workato API + MCP
- Make API + MCP vs Windmill API + MCP
- n8n API + MCP vs Windmill API + MCP
- Pipedream API + MCP vs Windmill API + MCP
- Microsoft Power Automate vs Windmill API + MCP
- Tray.ai API + MCP vs Windmill API + MCP
- Windmill API + MCP vs Workato API + MCP
- Paragon ActionKit + MCP vs Windmill API + MCP
Machine-readable
- This page as Markdown
/compare/kestra-vs-windmill.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/kestra.json·/api/v1/tools/windmill.json - From a terminal
anchor compare kestra windmill(the CLI) - Over MCP
compare_tools {"a": "kestra", "b": "windmill"}at/mcp, no key