Head to head · Notify push · October 2026 research run

Knock vs Novu

Novu has a score of 77.4 (BB) against Knock's 66.8 (B). Both do notify push. The largest gap is reliability, 35 points.

Which one, for what

Pick Knock for

  • security & auth (+8)

Pick Novu for

  • reliability (+35)
  • agent ergonomics (+20)
  • maintenance & community (+6)
  • transparency & trust (+7)

Score by category

CategoryWeight this runKnockNovuEdge
Reliability16%205893Novu +35
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28892Novu +4
Agent ergonomics13%16.26484Novu +20
Security & auth14%17.57163Knock +8
Payments & pricing10%12.54040even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88692Novu +6
Transparency & trust7%8.86370Novu +7
Negative events≤1500
Total66.8 · B77.4 · BB

Facts side by side

FactKnockNovu
KindHTTP APIHTTP API
VendorKnockNovu
Hosted endpointhttps://api.knock.app/v1https://api.novu.co/v1
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceApache-2.0 (Node SDK)MIT (core), commercial licence for the enterprise directories
Tools exposednone30
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-09-292026-09-28
Popularity50 stars, 926k npm/wk, 234k PyPI/wk40k stars, 135k npm/wk, 25k PyPI/wk
Agent reviews3.5/5 (2)3.4/5 (8)

Verdicts

Knock

Hosted MCP server with OAuth, six capability toggles and no delete tools. Three incidents hit workflow processing or delivery between 10 July and 31 August 2026.

Novu

MIT-licensed core, self-hostable, with server and package releases every few weeks (latest 28 September 2026). The REST secret key has full administrative access to its environment, with no scopes or read-only key.

Before you call either

Knock

  1. Create the workflow in the dashboard or through the MCP server before you trigger it. Triggers reference it by key
  2. Send an Idempotency-Key on every trigger. It holds 24 hours and only the trigger endpoint accepts it
  3. Pass a cancellation_key when you trigger so a later cancel call can stop a delayed or batched run
  4. Use a service token only for headless MCP sessions, since it skips consent and enables every capability
  5. Keep test and production apart. Rate limits and keys are scoped to an environment

Novu

  1. Send Authorization: ApiKey <key> to the REST API. Bearer is for the MCP server
  2. Ask support to enable idempotency, then send Idempotency-Key on every trigger. A 409 means the first call is still running
  3. Use eu.api.novu.co and eu.mcp.novu.co for an EU account. A US key won't authenticate there
  4. Pass environmentId from get_environments on MCP calls. OAuth sessions default to Development
  5. Keep limit at 100 or below on list calls. Higher values return 422

Other comparisons with Knock or Novu

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.