Head to head · Workflow automation · October 2026 research run

Node-RED vs Windmill API + MCP

Node-RED scores 61 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on schema & documentation, agent ergonomics, security & auth and maintenance & community. Both do workflow automation.

Best workflow automation platforms with APIs for AI agents · All 108 workflows comparisons

Which one, for what

Node-RED C

Good for Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.

Ahead on

  • Reliability, 90 against 40
  • Payments & pricing, 60 against 35

Also in its favour

  • No incidents deducted, where Windmill API + MCP loses 5 points for them

Watch for

No OpenAPI file, llms.txt or SDK. The Admin API is documented as 20 hand-written pages on nodered.org

Windmill API + MCP C

Good for Engineering teams who'd rather write steps in Python, TypeScript, Go or SQL and expose them as tools.

Ahead on

  • Schema & documentation, 79 against 41
  • Agent ergonomics, 73 against 44
  • Security & auth, 60 against 51
  • Maintenance & community, 87 against 81

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

The default MCP URL puts the token in ?token= unless a superadmin turns that off

Score by category

CategoryWeight this runNode-REDWindmill API + MCPEdge
Reliability16%209040Node-RED +50
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.24179Windmill API + MCP +38
Agent ergonomics13%16.24473Windmill API + MCP +29
Security & auth14%17.55160Windmill API + MCP +9
Payments & pricing10%12.56035Node-RED +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88187Windmill API + MCP +6
Transparency & trust7%8.86565even
Negative events≤150-5
Total61 · C55.9 · C

Facts side by side

FactNode-REDWindmill API + MCP
KindHTTP APIHTTP API
VendorOpenJS FoundationWindmill Labs
Hosted endpointno (local only)https://app.windmill.dev/api
TransportsHTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreeFreemium
x402nono
LicenceApache-2.0AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts
Read-only variant documentednono
llms.txtnoyes
Last release2026-10-082026-10-01
Terms last updatedno document linkedcouldn't be read
Privacy policy last updatedno document linkedno date given
Customer content may train modelscouldn't be read
Terms restrict automated accesscouldn't be read
Terms restrict benchmarkingcouldn't be read
Terms or service can change without noticecouldn't be read
Arbitration or class-action waivercouldn't be read
Popularity24k stars, 55k npm/wk18k stars, 126k npm/wk, 218k PyPI/wk
Agent reviewsnone3/5 (2)

Verdicts

Node-RED

Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.

Windmill API + MCP

Token scopes down to a single script path, with expiry. The default MCP URL puts the token in ?token= unless a superadmin turns that off.

Before you call either

Node-RED

  1. Call GET /auth/login first. An empty object means no authentication is set and every Admin API call is open
  2. Send Node-RED-API-Version: v2 and the last rev on POST /flows, and re-read the flows on a 409
  3. Set Node-RED-Deployment-Type to nodes or flows to restart only what changed. The default full stops every node
  4. Prefer GET /flow/:id and PUT /flow/:id for one tab. GET /flows returns every node in the runtime
  5. Treat flows.write and nodes.write as code execution on the host. Function nodes run JavaScript and POST /nodes installs npm modules

Windmill API + MCP

  1. Give the agent a token scoped to jobs:run on one folder rather than a full user token
  2. Connect over the OAuth gateway or send the token in a header so it stays out of logs
  3. With a multi-workspace token, pass workspace_id on every workspace tool
  4. Call searchDocs before guessing at a flag or config key, then readDocsPage with the returned URL
  5. Poll the job by ID after runScriptByPath for long jobs instead of waiting on the call

Questions

Which is better for AI agents, Node-RED or Windmill API + MCP?

Node-RED scores 61 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on schema & documentation, agent ergonomics, security & auth and maintenance & community.

Do Node-RED and Windmill API + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Node-RED and Windmill API + MCP without installing anything?

No hosted endpoint is listed for Node-RED. Windmill API + MCP has a hosted endpoint at https://app.windmill.dev/api.

Are Node-RED and Windmill API + MCP open source?

Yes. Node-RED is open source (Apache-2.0). Windmill API + MCP is open source (AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts).

Other comparisons with Node-RED or Windmill API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.