{
  "data": {
    "a": {
      "slug": "node-red",
      "name": "Node-RED",
      "vendor": "OpenJS Foundation",
      "vendorUrl": "https://nodered.org",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Node-RED is an open-source flow-based automation runtime hosted by the OpenJS Foundation. The owner runs it on Node.js, and an Admin HTTP API and a command-line client deploy flows and install nodes.",
      "url": "https://www.anchorterminal.com/tools/node-red",
      "markdownUrl": "https://www.anchorterminal.com/tools/node-red.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/node-red.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/node-red.json",
      "repo": "https://github.com/node-red/node-red",
      "license": "Apache-2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "node-red"
        },
        {
          "registry": "npm",
          "name": "node-red-admin"
        },
        {
          "registry": "oci",
          "name": "nodered/node-red"
        }
      ],
      "auth": "mixed",
      "authNotes": "A default install has no authentication. Setting `adminAuth` in `settings.js` turns on users with bcrypt-hashed passwords and permissions of `*`, `read` or a list such as `flows.read`. An agent then posts the username and password to `/auth/token` for a bearer token, valid seven days by default with no refresh. Access is self-serve, by running the software. Routes made by HTTP In nodes share one basic-auth username and password.",
      "pricing": "free",
      "pricingNotes": "Free under Apache-2.0 with nothing to buy from the project, so an agent can start with no account, card or contract. FlowFuse, a separate company, sells a hosted platform for Node-RED that the docs link, and it is not graded here (https://nodered.org/about/license/, checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source. The project sells nothing (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 23729,
        "npmWeekly": 55172,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://nodered.org/docs/api/admin/",
      "capabilities": [
        "automation.workflows",
        "automation.webhooks",
        "automation.code",
        "automation.apps"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "local",
        "free",
        "javascript",
        "webhooks",
        "cli",
        "docker"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61,
        "grade": "C",
        "agentReady": false,
        "rank": 486,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 44,
          "maintenance": 81,
          "payments": 60,
          "reliability": 90,
          "schema": 41,
          "security": 51,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.",
        "bestFor": "Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.",
        "strengths": [
          "Apache-2.0, with 12 releases between 30 July and 8 October 2026 on the 5.x and 4.x lines",
          "Admin API permissions are per resource, such as `flows.read` and `flows.write`, and a user or token can be limited to `read`",
          "`POST /flows` with `Node-RED-API-Version: v2` takes a `rev` value and answers 409 when the runtime holds newer flows",
          "Usage telemetry is opt-in, lists the four fields sent, and can be switched off in settings, by flag or by environment variable",
          "A release plan gives each major version a maintenance start and an end-of-life date, with 4.x ending on 31 December 2026"
        ],
        "weaknesses": [
          "No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org",
          "`adminAuth` is commented out in the default settings file, so a fresh install has no authentication on the editor or the Admin API",
          "No pagination, filtering or field selection. `GET /flows` returns the whole flow configuration",
          "Access tokens come from a username and password grant, last seven days by default and cannot be refreshed",
          "Routes for context, plugins, library and projects exist in the source and are missing from the published method list"
        ],
        "agentNotes": [
          "Call `GET /auth/login` first. An empty object means no authentication is set and every Admin API call is open",
          "Send `Node-RED-API-Version: v2` and the last `rev` on `POST /flows`, and re-read the flows on a 409",
          "Set `Node-RED-Deployment-Type` to `nodes` or `flows` to restart only what changed. The default `full` stops every node",
          "Prefer `GET /flow/:id` and `PUT /flow/:id` for one tab. `GET /flows` returns every node in the runtime",
          "Treat `flows.write` and `nodes.write` as code execution on the host. Function nodes run JavaScript and `POST /nodes` installs npm modules"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61
          }
        ],
        "editorialScores": {
          "ergonomics": 44,
          "maintenance": 81,
          "payments": 60,
          "reliability": 90,
          "schema": 41,
          "security": 51,
          "transparency": 85
        },
        "provenanceScore": 45
      },
      "connect": {
        "install": "sudo npm install -g node-red",
        "http": "curl http://localhost:1880/auth/token --data 'client_id=node-red-admin\u0026grant_type=password\u0026scope=*\u0026username=admin\u0026password=password'"
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/node-red"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "OpenJS Foundation",
        "domain": "nodered.org",
        "domainRegistered": "2013-09-12",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/node-red/node-red/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The licence page on nodered.org says copyright is retained by the OpenJS Foundation, and the site footer reads Copyright OpenJS Foundation and Node-RED contributors.",
          "No terms or privacy link is given. Node-RED is Apache-2.0 software the owner runs, and the project publishes no service agreement or privacy policy of its own. The site footer links the OpenJS Foundation's terms of use and privacy policy, which are a parent body's website documents and were not read.",
          "The Admin API answers on the owner's own host, by default http://localhost:1880. Only the opt-in telemetry report goes to an endpoint the project hosts.",
          "https://nodered.org/.well-known/security.txt returns 404. SECURITY.md in the repository gives team@nodered.org and escalation to the OpenJS Foundation CNA.",
          "RDAP for nodered.org gives a registration date of 2013-09-12. The lookup through rdap.org was redirected to the registry's RDAP host.",
          "nodered.org has no robots.txt (404). No status page exists because there is no hosted service."
        ],
        "score": 45
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/node-red.json",
      "live": {
        "slug": "node-red",
        "versions": [
          {
            "registry": "github",
            "name": "node-red/node-red",
            "version": "5.0.8",
            "released": "2026-10-08",
            "seenAt": "2026-10-09T17:08:22.991909994Z"
          },
          {
            "registry": "npm",
            "name": "node-red",
            "version": "5.0.8",
            "seenAt": "2026-10-09T17:08:20.781082858Z"
          },
          {
            "registry": "npm",
            "name": "node-red-admin",
            "version": "4.1.8",
            "seenAt": "2026-10-09T17:08:21.396260251Z"
          }
        ],
        "githubStars": 23730,
        "npmWeekly": 55172,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/node-red/node-red/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:37.181546944Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4223a5392d5c"
          }
        ],
        "updatedAt": "2026-10-09T18:45:37.181546944Z"
      }
    },
    "answer": "Node-RED scores 61 (C) on agent readiness against Paragon ActionKit + MCP's 47.5 (D), and leads in 5 of 7 scored categories. Paragon ActionKit + MCP leads on schema \u0026 documentation and security \u0026 auth.",
    "b": {
      "slug": "paragon",
      "name": "Paragon ActionKit + MCP",
      "vendor": "Paragon",
      "vendorUrl": "https://www.useparagon.com",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Embedded integration platform for SaaS products.",
      "url": "https://www.anchorterminal.com/tools/paragon",
      "markdownUrl": "https://www.anchorterminal.com/tools/paragon.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paragon.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paragon.json",
      "repo": "https://github.com/useparagon/paragon-mcp",
      "license": "proprietary",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://actionkit.useparagon.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@useparagon/connect"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every call carries a Paragon User Token, an RS256 JWT your server signs with the project's private signing key and sends as 'Authorization: Bearer'. It names the end user, so each tool call runs against that user's connected accounts. The self-hosted MCP server takes the same token and binds it to the session.",
      "pricing": "paid",
      "pricingNotes": "Pro and Enterprise plans, both quoted by sales and priced by the number of Connected Users (customer tenants), with a free trial. Workflows, ActionKit and Managed Sync come with default usage per Connected User. Successful workflow steps and every Proxy API request count as tasks against a monthly limit with no rollover. No prices are published (https://www.useparagon.com/pricing).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in Paragon docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 48,
        "npmWeekly": 175443,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.useparagon.com/actionkit/overview",
      "llmsTxt": "https://docs.useparagon.com/llms.txt",
      "openapi": "https://docs.useparagon.com/actionkit/openapi.json",
      "capabilities": [
        "automation.embedded",
        "automation.workflows",
        "automation.apps",
        "automation.auth",
        "automation.webhooks",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "enterprise",
        "webhooks"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 47.5,
        "grade": "D",
        "agentReady": false,
        "rank": 833,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 13,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 41,
          "maintenance": 48,
          "payments": 0,
          "reliability": 60,
          "schema": 73,
          "security": 65,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -4,
        "negativeNotes": [
          "As of the 30 September 2026 commit, the self-hosted MCP server defaults `NODE_ENV` to development, and in development `/mcp` and `/sse` sign a user token for whatever ID arrives in `?user=`. The Dockerfile and the image its workflow publishes don't set `NODE_ENV`, so a server started from that image without the variable lets anyone who can reach it impersonate any end user. The README documents the behaviour and the compose file sets production, so the deduction is modest (https://github.com/useparagon/paragon-mcp/blob/main/src/index.ts, https://github.com/useparagon/paragon-mcp/blob/main/src/utils.ts)."
        ],
        "verdict": "Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth. No published prices and no self-serve paid plan.",
        "bestFor": "A SaaS company whose agent must act inside each customer's own CRM, calendar or drive.",
        "strengths": [
          "Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth",
          "ActionKit lists tools as JSON Schema and has an OpenAPI 3.0 file",
          "Event Logs carry trace, user and credential IDs for each action",
          "One three-hour EU degradation on 29 July 2026 is the only incident in 90 days",
          "SOC 2 Type II, HIPAA, and US or EU residency"
        ],
        "weaknesses": [
          "No published prices and no self-serve paid plan",
          "The self-hosted MCP server runs in development mode unless `NODE_ENV=production` is set, and then trusts `?user=`",
          "No error schemas in the OpenAPI file, no ActionKit rate limit and no tool annotations",
          "Changelog's newest entry is April 2026",
          "No security.txt, and the MCP server's licence is stated two ways with no `LICENSE` file"
        ],
        "agentNotes": [
          "Sign a short-lived User Token per end user on your server and never let the model see the signing key",
          "Set `NODE_ENV=production` before exposing the MCP server anywhere but localhost",
          "Fetch the tool list once per session with `categories` set, and cache it",
          "Set `LIMIT_TO_TOOLS` on the MCP server to keep write actions out of a read-only agent",
          "Proxy API requests count as tasks, so prefer ActionKit tools for routine actions"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 47.5
          }
        ],
        "editorialScores": {
          "ergonomics": 41,
          "maintenance": 48,
          "payments": 0,
          "reliability": 60,
          "schema": 73,
          "security": 65,
          "transparency": 43
        },
        "provenanceScore": 80
      },
      "connect": {
        "install": "npm install @useparagon/connect",
        "http": "curl https://actionkit.useparagon.com/projects/$PARAGON_PROJECT_ID/tools -H \"Authorization: Bearer $PARAGON_USER_TOKEN\"",
        "claudeCode": "claude mcp add --transport http paragon http://localhost:3001/mcp --header \"Authorization: Bearer ${PARAGON_USER_TOKEN}\"",
        "config": {
          "mcpServers": {
            "paragon": {
              "headers": {
                "Authorization": "Bearer ${PARAGON_USER_TOKEN}"
              },
              "url": "http://localhost:3001/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.embedded",
        "tool": "https://letme.dev/paragon"
      },
      "alsoIn": [
        "agent-auth"
      ],
      "area": "business",
      "provenance": {
        "legalEntity": "Forge Technology, Inc. (d/b/a Paragon)",
        "domain": "useparagon.com",
        "domainRegistered": "2019-08-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.useparagon.com/terms-of-service",
        "privacy": "https://www.useparagon.com/privacy-policy",
        "statusPage": "https://status.useparagon.com",
        "changelog": "https://docs.useparagon.com/changelog/product-updates",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 80
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/paragon.json",
      "live": {
        "slug": "paragon",
        "probe": {
          "target": "https://actionkit.useparagon.com",
          "method": "get",
          "lastAt": "2026-10-10T05:39:00.163428638Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 330,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 327,
          "p95ms24h": 1302,
          "samples24h": 248,
          "samples30d": 2494,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 58,
              "ok": 58
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.useparagon.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-10T05:35:36.028707675Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@useparagon/connect",
            "version": "3.1.0",
            "seenAt": "2026-10-09T17:12:01.135974005Z"
          }
        ],
        "githubStars": 48,
        "npmWeekly": 148245,
        "securityTxt": {
          "url": "https://useparagon.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:31.983485923Z"
        },
        "llmsTxt": {
          "url": "https://docs.useparagon.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:02:34.147462922Z"
        },
        "domain": {
          "domain": "useparagon.com",
          "registered": "2019-08-30",
          "source": "https://rdap.verisign.com/com/v1/domain/useparagon.com",
          "checkedAt": "2026-10-04T13:08:02.741729991Z"
        },
        "pages": [
          {
            "url": "https://docs.useparagon.com/changelog/product-updates",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:38:39.01055202Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1f693d6387f4"
          },
          {
            "url": "https://www.useparagon.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-09T18:55:19.561742894Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8c248050adff"
          },
          {
            "url": "https://www.useparagon.com/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-09T18:55:21.821371215Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "63ed04f01ce4"
          },
          {
            "url": "https://www.useparagon.com/terms-of-service",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-09T18:55:23.800429843Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c2cc0e396ab4"
          }
        ],
        "updatedAt": "2026-10-10T05:39:00.163428638Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "OpenJS Foundation",
        "b": "Paragon",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://actionkit.useparagon.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "proprietary",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-08",
        "b": "2026-09-23",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2025-05-23",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "2023-01-19",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "24k stars, 55k npm/wk",
        "b": "48 stars, 175k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Node-RED scores 61 (C) on agent readiness against Paragon ActionKit + MCP's 47.5 (D), and leads in 5 of 7 scored categories. Paragon ActionKit + MCP leads on schema \u0026 documentation and security \u0026 auth.",
        "question": "Which is better for AI agents, Node-RED or Paragon ActionKit + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Node-RED and Paragon ActionKit + MCP need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Node-RED. Paragon ActionKit + MCP has a hosted endpoint at https://actionkit.useparagon.com.",
        "question": "Can an agent call Node-RED and Paragon ActionKit + MCP without installing anything?"
      },
      {
        "answer": "Node-RED is open source (Apache-2.0). No open-source release is listed for Paragon ActionKit + MCP.",
        "question": "Are Node-RED and Paragon ActionKit + MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 90 against 60",
          "Payments \u0026 pricing, 60 against 0",
          "Maintenance \u0026 community, 81 against 48"
        ],
        "also": [
          "Open source",
          "No incidents deducted, where Paragon ActionKit + MCP loses 4 points for them"
        ],
        "goodFor": "Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.",
        "slug": "node-red",
        "watchFor": "No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 73 against 41",
          "Security \u0026 auth, 65 against 51"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "A SaaS company whose agent must act inside each customer's own CRM, calendar or drive.",
        "slug": "paragon",
        "watchFor": "No published prices and no self-serve paid plan"
      }
    ],
    "job": {
      "capability": "automation.workflows",
      "name": "Workflow automation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-node-red.json",
        "title": "Activepieces API + MCP vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-paragon.json",
        "title": "Activepieces API + MCP vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-node-red.json",
        "title": "Gumloop vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-paragon.json",
        "title": "Gumloop vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-node-red.json",
        "title": "Kestra vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-paragon.json",
        "title": "Kestra vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-node-red.json",
        "title": "Make API + MCP vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/make-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-paragon.json",
        "title": "Make API + MCP vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/make-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-node-red.json",
        "title": "n8n API + MCP vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-paragon.json",
        "title": "n8n API + MCP vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-pipedream.json",
        "title": "Node-RED vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-power-automate.json",
        "title": "Node-RED vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-prismatic.json",
        "title": "Node-RED vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-tray.json",
        "title": "Node-RED vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-windmill.json",
        "title": "Node-RED vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-workato.json",
        "title": "Node-RED vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paragon-vs-power-automate.json",
        "title": "Paragon ActionKit + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/paragon-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paragon-vs-pipedream.json",
        "title": "Paragon ActionKit + MCP vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/paragon-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paragon-vs-prismatic.json",
        "title": "Paragon ActionKit + MCP vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/paragon-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paragon-vs-tray.json",
        "title": "Paragon ActionKit + MCP vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/paragon-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paragon-vs-windmill.json",
        "title": "Paragon ActionKit + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/paragon-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paragon-vs-workato.json",
        "title": "Paragon ActionKit + MCP vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/paragon-vs-workato"
      }
    ],
    "scores": [
      {
        "by": 30,
        "edge": "node-red",
        "key": "reliability",
        "name": "Reliability",
        "node-red": 90,
        "paragon": 60,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 32,
        "edge": "paragon",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "node-red": 41,
        "paragon": 73,
        "weight": 13
      },
      {
        "by": 3,
        "edge": "node-red",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "node-red": 44,
        "paragon": 41,
        "weight": 13
      },
      {
        "by": 14,
        "edge": "paragon",
        "key": "security",
        "name": "Security \u0026 auth",
        "node-red": 51,
        "paragon": 65,
        "weight": 14
      },
      {
        "by": 60,
        "edge": "node-red",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "node-red": 60,
        "paragon": 0,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 33,
        "edge": "node-red",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "node-red": 81,
        "paragon": 48,
        "weight": 7
      },
      {
        "by": 3,
        "edge": "node-red",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "node-red": 65,
        "paragon": 62,
        "weight": 7
      }
    ],
    "summary": "Node-RED scores 61 (C) on agent readiness against Paragon ActionKit + MCP's 47.5 (D), and leads in 5 of 7 scored categories. Paragon ActionKit + MCP leads on schema \u0026 documentation and security \u0026 auth. Both do workflow automation.",
    "verdicts": {
      "node-red": "Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.",
      "paragon": "Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth. No published prices and no self-serve paid plan."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/node-red-vs-paragon",
    "json": "https://www.anchorterminal.com/compare/node-red-vs-paragon.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/node-red-vs-paragon.md",
    "slim": "https://www.anchorterminal.com/compare/node-red-vs-paragon.min.md"
  },
  "markdown": "Node-RED scores 61 (C) on agent readiness against Paragon ActionKit + MCP's 47.5 (D), and leads in 5 of 7 scored categories. Paragon ActionKit + MCP leads on schema \u0026 documentation and security \u0026 auth. Both do workflow automation.\n\n- Node-RED: grade C, 61/100, rank #486 of 950. Markdown https://www.anchorterminal.com/tools/node-red.md · JSON https://www.anchorterminal.com/api/v1/tools/node-red.json\n- Paragon ActionKit + MCP: grade D, 47.5/100, rank #833 of 950. Markdown https://www.anchorterminal.com/tools/paragon.md · JSON https://www.anchorterminal.com/api/v1/tools/paragon.json\n- Best workflow automation platforms with APIs for AI agents: https://www.anchorterminal.com/best/workflow-automation/index.md\n- All 108 workflows comparisons: https://www.anchorterminal.com/compare/workflow-automation/index.md\n- Best auth and delegated access for AI agents: https://www.anchorterminal.com/best/agent-auth/index.md\n- All 111 agent auth comparisons: https://www.anchorterminal.com/compare/agent-auth/index.md\n\n## Which one, for what\n\n### Node-RED (C)\n\nGood for: Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.\n\nAhead on:\n- Reliability, 90 against 60\n- Payments \u0026 pricing, 60 against 0\n- Maintenance \u0026 community, 81 against 48\n\nAlso in its favour:\n- Open source\n- No incidents deducted, where Paragon ActionKit + MCP loses 4 points for them\n\nWatch for: No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org\n\n### Paragon ActionKit + MCP (D)\n\nGood for: A SaaS company whose agent must act inside each customer's own CRM, calendar or drive.\n\nAhead on:\n- Schema \u0026 documentation, 73 against 41\n- Security \u0026 auth, 65 against 51\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: No published prices and no self-serve paid plan\n\n\n## Score by category\n\n| Category | Weight | Node-RED | Paragon ActionKit + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 90 | 60 | Node-RED +30 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 41 | 73 | Paragon ActionKit + MCP +32 |\n| Agent ergonomics | 13% (16.2 this run) | 44 | 41 | Node-RED +3 |\n| Security \u0026 auth | 14% (17.5 this run) | 51 | 65 | Paragon ActionKit + MCP +14 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 0 | Node-RED +60 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 81 | 48 | Node-RED +33 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 65 | 62 | Node-RED +3 |\n| Negative events | ≤15 | 0 | -4 | |\n| **Total** | | **61 · C** | **47.5 · D** | |\n\n## Facts side by side\n\n| Fact | Node-RED | Paragon ActionKit + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | OpenJS Foundation | Paragon |\n| Hosted endpoint | no (local only) | `https://actionkit.useparagon.com` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Free | Paid |\n| x402 | no | no |\n| Licence | Apache-2.0 | proprietary |\n| Read-only variant documented | no | yes |\n| llms.txt | no | yes |\n| Last release | 2026-10-08 | 2026-09-23 |\n| Terms last updated | no document linked | 2025-05-23 |\n| Privacy policy last updated | no document linked | 2023-01-19 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | yes |\n| Terms restrict benchmarking |  | yes |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 24k stars, 55k npm/wk | 48 stars, 175k npm/wk |\n| Agent reviews | none | 2/5 (2) |\n\n## Verdicts\n\n**Node-RED.** Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.\n\n**Paragon ActionKit + MCP.** Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth. No published prices and no self-serve paid plan.\n\n## Before you call either\n\n### Node-RED\n\n1. Call `GET /auth/login` first. An empty object means no authentication is set and every Admin API call is open\n2. Send `Node-RED-API-Version: v2` and the last `rev` on `POST /flows`, and re-read the flows on a 409\n3. Set `Node-RED-Deployment-Type` to `nodes` or `flows` to restart only what changed. The default `full` stops every node\n4. Prefer `GET /flow/:id` and `PUT /flow/:id` for one tab. `GET /flows` returns every node in the runtime\n5. Treat `flows.write` and `nodes.write` as code execution on the host. Function nodes run JavaScript and `POST /nodes` installs npm modules\n\n### Paragon ActionKit + MCP\n\n1. Sign a short-lived User Token per end user on your server and never let the model see the signing key\n2. Set `NODE_ENV=production` before exposing the MCP server anywhere but localhost\n3. Fetch the tool list once per session with `categories` set, and cache it\n4. Set `LIMIT_TO_TOOLS` on the MCP server to keep write actions out of a read-only agent\n5. Proxy API requests count as tasks, so prefer ActionKit tools for routine actions\n\n## Questions\n\n### Which is better for AI agents, Node-RED or Paragon ActionKit + MCP?\n\nNode-RED scores 61 (C) on agent readiness against Paragon ActionKit + MCP's 47.5 (D), and leads in 5 of 7 scored categories. Paragon ActionKit + MCP leads on schema \u0026 documentation and security \u0026 auth.\n\n### Do Node-RED and Paragon ActionKit + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Node-RED and Paragon ActionKit + MCP without installing anything?\n\nNo hosted endpoint is listed for Node-RED. Paragon ActionKit + MCP has a hosted endpoint at https://actionkit.useparagon.com.\n\n### Are Node-RED and Paragon ActionKit + MCP open source?\n\nNode-RED is open source (Apache-2.0). No open-source release is listed for Paragon ActionKit + MCP.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/node-red-vs-paragon.json, and with the fewest tokens: https://www.anchorterminal.com/compare/node-red-vs-paragon.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"node-red\", \"b\": \"paragon\"}`. From a terminal: `anchor compare node-red paragon`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/node-red.json and https://www.anchorterminal.com/api/v1/tools/paragon.json\n\n## Other comparisons with Node-RED or Paragon ActionKit + MCP\n\n- [Activepieces API + MCP vs Node-RED](https://www.anchorterminal.com/compare/activepieces-vs-node-red.md)\n- [Activepieces API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/activepieces-vs-paragon.md)\n- [Gumloop vs Node-RED](https://www.anchorterminal.com/compare/gumloop-vs-node-red.md)\n- [Gumloop vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/gumloop-vs-paragon.md)\n- [Kestra vs Node-RED](https://www.anchorterminal.com/compare/kestra-vs-node-red.md)\n- [Kestra vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/kestra-vs-paragon.md)\n- [Make API + MCP vs Node-RED](https://www.anchorterminal.com/compare/make-vs-node-red.md)\n- [Make API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/make-vs-paragon.md)\n- [n8n API + MCP vs Node-RED](https://www.anchorterminal.com/compare/n8n-vs-node-red.md)\n- [n8n API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/n8n-vs-paragon.md)\n- [Node-RED vs Pipedream API + MCP](https://www.anchorterminal.com/compare/node-red-vs-pipedream.md)\n- [Node-RED vs Microsoft Power Automate](https://www.anchorterminal.com/compare/node-red-vs-power-automate.md)\n- [Node-RED vs Prismatic](https://www.anchorterminal.com/compare/node-red-vs-prismatic.md)\n- [Node-RED vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/node-red-vs-tray.md)\n- [Node-RED vs Windmill API + MCP](https://www.anchorterminal.com/compare/node-red-vs-windmill.md)\n- [Node-RED vs Workato API + MCP](https://www.anchorterminal.com/compare/node-red-vs-workato.md)\n- [Paragon ActionKit + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/paragon-vs-power-automate.md)\n- [Paragon ActionKit + MCP vs Pipedream API + MCP](https://www.anchorterminal.com/compare/paragon-vs-pipedream.md)\n- [Paragon ActionKit + MCP vs Prismatic](https://www.anchorterminal.com/compare/paragon-vs-prismatic.md)\n- [Paragon ActionKit + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/paragon-vs-tray.md)\n- [Paragon ActionKit + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/paragon-vs-windmill.md)\n- [Paragon ActionKit + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/paragon-vs-workato.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Node-RED vs Paragon ActionKit + MCP",
        "url": ""
      }
    ],
    "description": "Node-RED scores 61 (C) to Paragon ActionKit's 47.5 (D) for workflow automation. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Node-RED C 61",
      "Paragon ActionKit + MCP D 47.5",
      "scores"
    ],
    "h1": "Node-RED vs Paragon ActionKit + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-node-red-vs-paragon.png",
    "path": "/compare/node-red-vs-paragon",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Node-RED vs Paragon ActionKit for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/node-red-vs-paragon"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 730
  },
  "version": 1
}
