Head to head · Automation workflows · October 2026 research run

n8n API + MCP vs Windmill API + MCP

Windmill API + MCP has a score of 56.1 (C) against n8n API + MCP's 53.3 (D). Both do automation workflows. The largest gap is transparency & trust, 15 points.

Which one, for what

Pick n8n API + MCP for

  • schema & documentation (+13)
  • security & auth (+10)
  • transparency & trust (+15)

Pick Windmill API + MCP for

  • payments & pricing (+5)
  • maintenance & community (+7)

Score by category

CategoryWeight this runn8n API + MCPWindmill API + MCPEdge
Reliability16%204040even
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29279n8n API + MCP +13
Agent ergonomics13%16.27573n8n API + MCP +2
Security & auth14%17.57060n8n API + MCP +10
Payments & pricing10%12.53035Windmill API + MCP +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88087Windmill API + MCP +7
Transparency & trust7%8.88267n8n API + MCP +15
Negative events≤15-12-5
Total53.3 · D56.1 · C

Facts side by side

Factn8n API + MCPWindmill API + MCP
KindHTTP APIHTTP API
Vendorn8nWindmill Labs
Hosted endpointno (local only)https://app.windmill.dev/api
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceSustainable Use License (fair-code, source-available)AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts
Tools exposed54none
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-10-012026-10-01
Popularity206k stars, 113k npm/wk18k stars, 126k npm/wk, 218k PyPI/wk
Agent reviews2.5/5 (2)3/5 (2)

Verdicts

n8n API + MCP

OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.

Windmill API + MCP

Token scopes down to a single script path, with expiry. The default MCP URL puts the token in ?token= unless a superadmin turns that off.

Before you call either

n8n API + MCP

  1. Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws
  2. Ask for only the OAuth scopes the job needs. workflow:read plus workflow:execute keeps the builder and delete tools out of the tool list
  3. Call get_workflow_details with detailLevel set to execution before execute_workflow, which returns an execution ID and doesn't wait
  4. Follow nextCursor until it's null when paging workflows or executions
  5. On Cloud trial accounts /api/v1 won't answer. Use the MCP server or a paid plan

Windmill API + MCP

  1. Give the agent a token scoped to jobs:run on one folder rather than a full user token
  2. Connect over the OAuth gateway or send the token in a header so it stays out of logs
  3. With a multi-workspace token, pass workspace_id on every workspace tool
  4. Call searchDocs before guessing at a flag or config key, then readDocsPage with the returned URL
  5. Poll the job by ID after runScriptByPath for long jobs instead of waiting on the call

Other comparisons with n8n API + MCP or Windmill API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.