{
  "data": {
    "a": {
      "slug": "node-red",
      "name": "Node-RED",
      "vendor": "OpenJS Foundation",
      "vendorUrl": "https://nodered.org",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Node-RED is an open-source flow-based automation runtime hosted by the OpenJS Foundation. The owner runs it on Node.js, and an Admin HTTP API and a command-line client deploy flows and install nodes.",
      "url": "https://www.anchorterminal.com/tools/node-red",
      "markdownUrl": "https://www.anchorterminal.com/tools/node-red.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/node-red.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/node-red.json",
      "repo": "https://github.com/node-red/node-red",
      "license": "Apache-2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "node-red"
        },
        {
          "registry": "npm",
          "name": "node-red-admin"
        },
        {
          "registry": "oci",
          "name": "nodered/node-red"
        }
      ],
      "auth": "mixed",
      "authNotes": "A default install has no authentication. Setting `adminAuth` in `settings.js` turns on users with bcrypt-hashed passwords and permissions of `*`, `read` or a list such as `flows.read`. An agent then posts the username and password to `/auth/token` for a bearer token, valid seven days by default with no refresh. Access is self-serve, by running the software. Routes made by HTTP In nodes share one basic-auth username and password.",
      "pricing": "free",
      "pricingNotes": "Free under Apache-2.0 with nothing to buy from the project, so an agent can start with no account, card or contract. FlowFuse, a separate company, sells a hosted platform for Node-RED that the docs link, and it is not graded here (https://nodered.org/about/license/, checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source. The project sells nothing (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 23729,
        "npmWeekly": 55172,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://nodered.org/docs/api/admin/",
      "capabilities": [
        "automation.workflows",
        "automation.webhooks",
        "automation.code",
        "automation.apps"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "local",
        "free",
        "javascript",
        "webhooks",
        "cli",
        "docker"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61,
        "grade": "C",
        "agentReady": false,
        "rank": 486,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 44,
          "maintenance": 81,
          "payments": 60,
          "reliability": 90,
          "schema": 41,
          "security": 51,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.",
        "bestFor": "Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.",
        "strengths": [
          "Apache-2.0, with 12 releases between 30 July and 8 October 2026 on the 5.x and 4.x lines",
          "Admin API permissions are per resource, such as `flows.read` and `flows.write`, and a user or token can be limited to `read`",
          "`POST /flows` with `Node-RED-API-Version: v2` takes a `rev` value and answers 409 when the runtime holds newer flows",
          "Usage telemetry is opt-in, lists the four fields sent, and can be switched off in settings, by flag or by environment variable",
          "A release plan gives each major version a maintenance start and an end-of-life date, with 4.x ending on 31 December 2026"
        ],
        "weaknesses": [
          "No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org",
          "`adminAuth` is commented out in the default settings file, so a fresh install has no authentication on the editor or the Admin API",
          "No pagination, filtering or field selection. `GET /flows` returns the whole flow configuration",
          "Access tokens come from a username and password grant, last seven days by default and cannot be refreshed",
          "Routes for context, plugins, library and projects exist in the source and are missing from the published method list"
        ],
        "agentNotes": [
          "Call `GET /auth/login` first. An empty object means no authentication is set and every Admin API call is open",
          "Send `Node-RED-API-Version: v2` and the last `rev` on `POST /flows`, and re-read the flows on a 409",
          "Set `Node-RED-Deployment-Type` to `nodes` or `flows` to restart only what changed. The default `full` stops every node",
          "Prefer `GET /flow/:id` and `PUT /flow/:id` for one tab. `GET /flows` returns every node in the runtime",
          "Treat `flows.write` and `nodes.write` as code execution on the host. Function nodes run JavaScript and `POST /nodes` installs npm modules"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61
          }
        ],
        "editorialScores": {
          "ergonomics": 44,
          "maintenance": 81,
          "payments": 60,
          "reliability": 90,
          "schema": 41,
          "security": 51,
          "transparency": 85
        },
        "provenanceScore": 45
      },
      "connect": {
        "install": "sudo npm install -g node-red",
        "http": "curl http://localhost:1880/auth/token --data 'client_id=node-red-admin\u0026grant_type=password\u0026scope=*\u0026username=admin\u0026password=password'"
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/node-red"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "OpenJS Foundation",
        "domain": "nodered.org",
        "domainRegistered": "2013-09-12",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/node-red/node-red/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The licence page on nodered.org says copyright is retained by the OpenJS Foundation, and the site footer reads Copyright OpenJS Foundation and Node-RED contributors.",
          "No terms or privacy link is given. Node-RED is Apache-2.0 software the owner runs, and the project publishes no service agreement or privacy policy of its own. The site footer links the OpenJS Foundation's terms of use and privacy policy, which are a parent body's website documents and were not read.",
          "The Admin API answers on the owner's own host, by default http://localhost:1880. Only the opt-in telemetry report goes to an endpoint the project hosts.",
          "https://nodered.org/.well-known/security.txt returns 404. SECURITY.md in the repository gives team@nodered.org and escalation to the OpenJS Foundation CNA.",
          "RDAP for nodered.org gives a registration date of 2013-09-12. The lookup through rdap.org was redirected to the registry's RDAP host.",
          "nodered.org has no robots.txt (404). No status page exists because there is no hosted service."
        ],
        "score": 45
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/node-red.json",
      "live": {
        "slug": "node-red",
        "versions": [
          {
            "registry": "github",
            "name": "node-red/node-red",
            "version": "5.0.8",
            "released": "2026-10-08",
            "seenAt": "2026-10-09T17:08:22.991909994Z"
          },
          {
            "registry": "npm",
            "name": "node-red",
            "version": "5.0.8",
            "seenAt": "2026-10-09T17:08:20.781082858Z"
          },
          {
            "registry": "npm",
            "name": "node-red-admin",
            "version": "4.1.8",
            "seenAt": "2026-10-09T17:08:21.396260251Z"
          }
        ],
        "githubStars": 23730,
        "npmWeekly": 55172,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/node-red/node-red/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:37.181546944Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4223a5392d5c"
          }
        ],
        "updatedAt": "2026-10-09T18:45:37.181546944Z"
      }
    },
    "answer": "Node-RED scores 61 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and maintenance \u0026 community.",
    "b": {
      "slug": "windmill",
      "name": "Windmill API + MCP",
      "vendor": "Windmill Labs",
      "vendorUrl": "https://www.windmill.dev",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Code-first engine for scripts, flows and internal apps in 20+ languages, written in Rust, on Windmill Cloud or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/windmill",
      "markdownUrl": "https://www.anchorterminal.com/tools/windmill.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/windmill.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/windmill.json",
      "repo": "https://github.com/windmill-labs/windmill",
      "license": "AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://app.windmill.dev/api",
      "packages": [
        {
          "registry": "npm",
          "name": "windmill-client"
        },
        {
          "registry": "pypi",
          "name": "wmill"
        }
      ],
      "auth": "mixed",
      "authNotes": "Bearer user tokens with optional scopes (`{domain}:{action}[:{path}]`, e.g. `jobs:run:flows`) and expiry. MCP by OAuth at /api/mcp/gateway, or a token either in the URL (`?token=`) or in an Authorization header. Admins can make the MCP endpoints refuse tokens in URLs.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosted Community Edition is free with unlimited executions (up to 50 users, 3 workspaces). Self-hosted Enterprise from $120 a month, priced as developer seats $20 a month, operators $10 and compute at $50 a month per standard 2 GB worker. Pro gets the same terms for companies under 10 staff and $250,000 revenue. Cloud has a free tier and paid Team and Enterprise workspaces billed on seats and compute (https://www.windmill.dev/pricing).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 18070,
        "npmWeekly": 126287,
        "pypiWeekly": 218343,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.windmill.dev/docs",
      "llmsTxt": "https://www.windmill.dev/llms.txt",
      "openapi": "https://app.windmill.dev/api/openapi.yaml",
      "capabilities": [
        "automation.workflows",
        "automation.code",
        "automation.webhooks",
        "automation.embedded",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "local",
        "freemium",
        "mcp",
        "llms-txt",
        "openapi",
        "python",
        "typescript",
        "webhooks",
        "enterprise"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.9,
        "grade": "C",
        "agentReady": false,
        "rank": 644,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 87,
          "payments": 35,
          "reliability": 40,
          "schema": 79,
          "security": 60,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "CVE-2026-23696, SQL injection in folder ownership management for any low-privilege user in Windmill 1.276.0 to 1.603.2, CVSS 4.0 score 9.4, exposing JWT secrets and admin identifiers. Fixed in 1.603.3 and published by NVD on 7 April 2026 (https://github.com/advisories/GHSA-34m2-qrpf-6v7q).",
          "GHSA-24fr-44f8-fqwg, published 2 March 2026, high. SUPERADMIN_SECRET could be read publicly through RCE on versions before 1.603.3. CVE-2026-22683, missing authorisation in 1.56.0 to 1.614.0, rated high on 7 April 2026. All fixed, so the deduction is reduced (https://github.com/windmill-labs/windmill/security/advisories, https://github.com/advisories?query=windmill)."
        ],
        "verdict": "Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off.",
        "bestFor": "Engineering teams who'd rather write steps in Python, TypeScript, Go or SQL and expose them as tools.",
        "strengths": [
          "Token scopes down to a single script path, with expiry",
          "OpenAPI 3.0.3 with 913 operations and Apache-2.0 clients for TypeScript, Python, Go and Rust",
          "Every script and flow is an MCP tool, filterable by folder and favourites",
          "97 tagged releases in 90 days, latest v1.821.0 on 1 October 2026",
          "Free unlimited executions on Cloud free workspaces and self-hosted Community Edition"
        ],
        "weaknesses": [
          "The default MCP URL puts the token in `?token=` unless a superadmin turns that off",
          "CVE-2026-23696, a critical SQL injection fixed in 1.603.3, had no Windmill advisory",
          "No published API rate limits, 429 guidance or uptime SLA",
          "The OpenAPI file documents errors for only about 30 operations",
          "No SECURITY.md or security.txt"
        ],
        "agentNotes": [
          "Give the agent a token scoped to `jobs:run` on one folder rather than a full user token",
          "Connect over the OAuth gateway or send the token in a header so it stays out of logs",
          "With a multi-workspace token, pass `workspace_id` on every workspace tool",
          "Call `searchDocs` before guessing at a flag or config key, then `readDocsPage` with the returned URL",
          "Poll the job by ID after `runScriptByPath` for long jobs instead of waiting on the call"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.9
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 87,
          "payments": 35,
          "reliability": 40,
          "schema": 79,
          "security": 60,
          "transparency": 51
        },
        "provenanceScore": 78
      },
      "connect": {
        "http": "curl \"https://app.windmill.dev/api/w/$WM_WORKSPACE/scripts/list\" -H \"Authorization: Bearer $WM_TOKEN\"",
        "claudeCode": "claude mcp add --transport http windmill https://app.windmill.dev/api/mcp/gateway",
        "config": {
          "mcpServers": {
            "windmill": {
              "headers": {
                "Authorization": "Bearer ${WM_TOKEN}"
              },
              "url": "https://app.windmill.dev/api/mcp/w/${WM_WORKSPACE}/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/windmill"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Developer seat (Enterprise)",
          "unit": "seat-month",
          "usd": 20
        },
        {
          "item": "Operator seat (Enterprise)",
          "unit": "seat-month",
          "usd": 10,
          "note": "run-only users and external JWT users"
        },
        {
          "item": "Compute (Enterprise)",
          "unit": "compute-unit",
          "usd": 25,
          "note": "$50 a month per standard 2 GB worker, which is 2 CU"
        },
        {
          "item": "Enterprise minimum",
          "unit": "month",
          "usd": 120,
          "note": "from price shown on the pricing page"
        }
      ],
      "provenance": {
        "legalEntity": "Windmill Labs, Inc.",
        "domain": "windmill.dev",
        "domainRegistered": "2022-01-06",
        "endpointOnVendorDomain": true,
        "terms": "https://www.windmill.dev/terms",
        "privacy": "https://www.windmill.dev/privacy_policy",
        "statusPage": "https://status.windmill.dev",
        "changelog": "https://www.windmill.dev/changelog",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "status.windmill.dev redirects to an UptimeRobot page."
        ],
        "score": 78
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/windmill.json",
      "live": {
        "slug": "windmill",
        "probe": {
          "target": "https://app.windmill.dev/api",
          "method": "get",
          "lastAt": "2026-10-10T01:38:13.678799271Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 220,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 191,
          "p95ms24h": 275,
          "samples24h": 250,
          "samples30d": 2453,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 17,
              "ok": 17
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.windmill.dev",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:51:25.582005635Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "windmill-labs/windmill",
            "version": "v1.829.0",
            "released": "2026-10-09",
            "seenAt": "2026-10-09T17:28:22.309613848Z"
          },
          {
            "registry": "npm",
            "name": "windmill-client",
            "version": "1.829.0",
            "seenAt": "2026-10-09T17:28:21.365335434Z"
          },
          {
            "registry": "pypi",
            "name": "wmill",
            "version": "1.829.0",
            "released": "2026-10-09",
            "seenAt": "2026-10-09T17:28:22.179053686Z"
          }
        ],
        "githubStars": 18151,
        "npmWeekly": 93813,
        "pypiWeekly": 222705,
        "securityTxt": {
          "url": "https://windmill.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:40:36.457806107Z"
        },
        "llmsTxt": {
          "url": "https://www.windmill.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:03:00.853117117Z"
        },
        "domain": {
          "domain": "windmill.dev",
          "registered": "2022-01-06",
          "source": "https://pubapi.registry.google/rdap/domain/windmill.dev",
          "checkedAt": "2026-10-04T13:08:55.755645623Z"
        },
        "pages": [
          {
            "url": "https://www.windmill.dev/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:55:39.656501106Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "27e9c4f4c553"
          },
          {
            "url": "https://www.windmill.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:55:41.913838964Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "afa04f8b73f5"
          },
          {
            "url": "https://www.windmill.dev/privacy_policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:55:43.893735474Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d11624ab86ec"
          },
          {
            "url": "https://www.windmill.dev/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:55:45.901525986Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e3b0c44298fc"
          }
        ],
        "updatedAt": "2026-10-10T01:38:13.678799271Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "OpenJS Foundation",
        "b": "Windmill Labs",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://app.windmill.dev/api",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-08",
        "b": "2026-10-01",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "24k stars, 55k npm/wk",
        "b": "18k stars, 126k npm/wk, 218k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Node-RED scores 61 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Node-RED or Windmill API + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Node-RED and Windmill API + MCP need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Node-RED. Windmill API + MCP has a hosted endpoint at https://app.windmill.dev/api.",
        "question": "Can an agent call Node-RED and Windmill API + MCP without installing anything?"
      },
      {
        "answer": "Yes. Node-RED is open source (Apache-2.0). Windmill API + MCP is open source (AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts).",
        "question": "Are Node-RED and Windmill API + MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 90 against 40",
          "Payments \u0026 pricing, 60 against 35"
        ],
        "also": [
          "No incidents deducted, where Windmill API + MCP loses 5 points for them"
        ],
        "goodFor": "Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.",
        "slug": "node-red",
        "watchFor": "No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 79 against 41",
          "Agent ergonomics, 73 against 44",
          "Security \u0026 auth, 60 against 51",
          "Maintenance \u0026 community, 87 against 81"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Engineering teams who'd rather write steps in Python, TypeScript, Go or SQL and expose them as tools.",
        "slug": "windmill",
        "watchFor": "The default MCP URL puts the token in `?token=` unless a superadmin turns that off"
      }
    ],
    "job": {
      "capability": "automation.workflows",
      "name": "Workflow automation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-node-red.json",
        "title": "Activepieces API + MCP vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-windmill.json",
        "title": "Activepieces API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-node-red.json",
        "title": "Gumloop vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-windmill.json",
        "title": "Gumloop vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-node-red.json",
        "title": "Kestra vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-windmill.json",
        "title": "Kestra vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-node-red.json",
        "title": "Make API + MCP vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/make-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-windmill.json",
        "title": "Make API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/make-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-node-red.json",
        "title": "n8n API + MCP vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-windmill.json",
        "title": "n8n API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-paragon.json",
        "title": "Node-RED vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-pipedream.json",
        "title": "Node-RED vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-power-automate.json",
        "title": "Node-RED vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-prismatic.json",
        "title": "Node-RED vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-tray.json",
        "title": "Node-RED vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-workato.json",
        "title": "Node-RED vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pipedream-vs-windmill.json",
        "title": "Pipedream API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/pipedream-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/power-automate-vs-windmill.json",
        "title": "Microsoft Power Automate vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/power-automate-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/prismatic-vs-windmill.json",
        "title": "Prismatic vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/prismatic-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/tray-vs-windmill.json",
        "title": "Tray.ai API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/tray-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/windmill-vs-workato.json",
        "title": "Windmill API + MCP vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/windmill-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paragon-vs-windmill.json",
        "title": "Paragon ActionKit + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/paragon-vs-windmill"
      }
    ],
    "scores": [
      {
        "by": 50,
        "edge": "node-red",
        "key": "reliability",
        "name": "Reliability",
        "node-red": 90,
        "weight": 16,
        "windmill": 40
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 38,
        "edge": "windmill",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "node-red": 41,
        "weight": 13,
        "windmill": 79
      },
      {
        "by": 29,
        "edge": "windmill",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "node-red": 44,
        "weight": 13,
        "windmill": 73
      },
      {
        "by": 9,
        "edge": "windmill",
        "key": "security",
        "name": "Security \u0026 auth",
        "node-red": 51,
        "weight": 14,
        "windmill": 60
      },
      {
        "by": 25,
        "edge": "node-red",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "node-red": 60,
        "weight": 10,
        "windmill": 35
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "edge": "windmill",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "node-red": 81,
        "weight": 7,
        "windmill": 87
      },
      {
        "by": 0,
        "edge": "",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "node-red": 65,
        "weight": 7,
        "windmill": 65
      }
    ],
    "summary": "Node-RED scores 61 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and maintenance \u0026 community. Both do workflow automation.",
    "verdicts": {
      "node-red": "Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.",
      "windmill": "Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/node-red-vs-windmill",
    "json": "https://www.anchorterminal.com/compare/node-red-vs-windmill.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/node-red-vs-windmill.md",
    "slim": "https://www.anchorterminal.com/compare/node-red-vs-windmill.min.md"
  },
  "markdown": "Node-RED scores 61 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and maintenance \u0026 community. Both do workflow automation.\n\n- Node-RED: grade C, 61/100, rank #486 of 950. Markdown https://www.anchorterminal.com/tools/node-red.md · JSON https://www.anchorterminal.com/api/v1/tools/node-red.json\n- Windmill API + MCP: grade C, 55.9/100, rank #644 of 950. Markdown https://www.anchorterminal.com/tools/windmill.md · JSON https://www.anchorterminal.com/api/v1/tools/windmill.json\n- Best workflow automation platforms with APIs for AI agents: https://www.anchorterminal.com/best/workflow-automation/index.md\n- All 108 workflows comparisons: https://www.anchorterminal.com/compare/workflow-automation/index.md\n\n## Which one, for what\n\n### Node-RED (C)\n\nGood for: Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.\n\nAhead on:\n- Reliability, 90 against 40\n- Payments \u0026 pricing, 60 against 35\n\nAlso in its favour:\n- No incidents deducted, where Windmill API + MCP loses 5 points for them\n\nWatch for: No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org\n\n### Windmill API + MCP (C)\n\nGood for: Engineering teams who'd rather write steps in Python, TypeScript, Go or SQL and expose them as tools.\n\nAhead on:\n- Schema \u0026 documentation, 79 against 41\n- Agent ergonomics, 73 against 44\n- Security \u0026 auth, 60 against 51\n- Maintenance \u0026 community, 87 against 81\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: The default MCP URL puts the token in `?token=` unless a superadmin turns that off\n\n\n## Score by category\n\n| Category | Weight | Node-RED | Windmill API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 90 | 40 | Node-RED +50 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 41 | 79 | Windmill API + MCP +38 |\n| Agent ergonomics | 13% (16.2 this run) | 44 | 73 | Windmill API + MCP +29 |\n| Security \u0026 auth | 14% (17.5 this run) | 51 | 60 | Windmill API + MCP +9 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 35 | Node-RED +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 81 | 87 | Windmill API + MCP +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 65 | 65 | even |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **61 · C** | **55.9 · C** | |\n\n## Facts side by side\n\n| Fact | Node-RED | Windmill API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | OpenJS Foundation | Windmill Labs |\n| Hosted endpoint | no (local only) | `https://app.windmill.dev/api` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 | AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| Last release | 2026-10-08 | 2026-10-01 |\n| Terms last updated | no document linked | couldn't be read |\n| Privacy policy last updated | no document linked | no date given |\n| Customer content may train models |  | couldn't be read |\n| Terms restrict automated access |  | couldn't be read |\n| Terms restrict benchmarking |  | couldn't be read |\n| Terms or service can change without notice |  | couldn't be read |\n| Arbitration or class-action waiver |  | couldn't be read |\n| Popularity | 24k stars, 55k npm/wk | 18k stars, 126k npm/wk, 218k PyPI/wk |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Node-RED.** Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.\n\n**Windmill API + MCP.** Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off.\n\n## Before you call either\n\n### Node-RED\n\n1. Call `GET /auth/login` first. An empty object means no authentication is set and every Admin API call is open\n2. Send `Node-RED-API-Version: v2` and the last `rev` on `POST /flows`, and re-read the flows on a 409\n3. Set `Node-RED-Deployment-Type` to `nodes` or `flows` to restart only what changed. The default `full` stops every node\n4. Prefer `GET /flow/:id` and `PUT /flow/:id` for one tab. `GET /flows` returns every node in the runtime\n5. Treat `flows.write` and `nodes.write` as code execution on the host. Function nodes run JavaScript and `POST /nodes` installs npm modules\n\n### Windmill API + MCP\n\n1. Give the agent a token scoped to `jobs:run` on one folder rather than a full user token\n2. Connect over the OAuth gateway or send the token in a header so it stays out of logs\n3. With a multi-workspace token, pass `workspace_id` on every workspace tool\n4. Call `searchDocs` before guessing at a flag or config key, then `readDocsPage` with the returned URL\n5. Poll the job by ID after `runScriptByPath` for long jobs instead of waiting on the call\n\n## Questions\n\n### Which is better for AI agents, Node-RED or Windmill API + MCP?\n\nNode-RED scores 61 (C) on agent readiness against Windmill API + MCP's 55.9 (C), and leads in 2 of 7 scored categories. Windmill API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and maintenance \u0026 community.\n\n### Do Node-RED and Windmill API + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Node-RED and Windmill API + MCP without installing anything?\n\nNo hosted endpoint is listed for Node-RED. Windmill API + MCP has a hosted endpoint at https://app.windmill.dev/api.\n\n### Are Node-RED and Windmill API + MCP open source?\n\nYes. Node-RED is open source (Apache-2.0). Windmill API + MCP is open source (AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/node-red-vs-windmill.json, and with the fewest tokens: https://www.anchorterminal.com/compare/node-red-vs-windmill.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"node-red\", \"b\": \"windmill\"}`. From a terminal: `anchor compare node-red windmill`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/node-red.json and https://www.anchorterminal.com/api/v1/tools/windmill.json\n\n## Other comparisons with Node-RED or Windmill API + MCP\n\n- [Activepieces API + MCP vs Node-RED](https://www.anchorterminal.com/compare/activepieces-vs-node-red.md)\n- [Activepieces API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-windmill.md)\n- [Gumloop vs Node-RED](https://www.anchorterminal.com/compare/gumloop-vs-node-red.md)\n- [Gumloop vs Windmill API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-windmill.md)\n- [Kestra vs Node-RED](https://www.anchorterminal.com/compare/kestra-vs-node-red.md)\n- [Kestra vs Windmill API + MCP](https://www.anchorterminal.com/compare/kestra-vs-windmill.md)\n- [Make API + MCP vs Node-RED](https://www.anchorterminal.com/compare/make-vs-node-red.md)\n- [Make API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/make-vs-windmill.md)\n- [n8n API + MCP vs Node-RED](https://www.anchorterminal.com/compare/n8n-vs-node-red.md)\n- [n8n API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/n8n-vs-windmill.md)\n- [Node-RED vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/node-red-vs-paragon.md)\n- [Node-RED vs Pipedream API + MCP](https://www.anchorterminal.com/compare/node-red-vs-pipedream.md)\n- [Node-RED vs Microsoft Power Automate](https://www.anchorterminal.com/compare/node-red-vs-power-automate.md)\n- [Node-RED vs Prismatic](https://www.anchorterminal.com/compare/node-red-vs-prismatic.md)\n- [Node-RED vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/node-red-vs-tray.md)\n- [Node-RED vs Workato API + MCP](https://www.anchorterminal.com/compare/node-red-vs-workato.md)\n- [Pipedream API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/pipedream-vs-windmill.md)\n- [Microsoft Power Automate vs Windmill API + MCP](https://www.anchorterminal.com/compare/power-automate-vs-windmill.md)\n- [Prismatic vs Windmill API + MCP](https://www.anchorterminal.com/compare/prismatic-vs-windmill.md)\n- [Tray.ai API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/tray-vs-windmill.md)\n- [Windmill API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/windmill-vs-workato.md)\n- [Paragon ActionKit + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/paragon-vs-windmill.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Node-RED vs Windmill API + MCP",
        "url": ""
      }
    ],
    "description": "Node-RED scores 61 (C) to Windmill's 55.9 (C) for workflow automation. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Node-RED C 61",
      "Windmill API + MCP C 55.9",
      "scores"
    ],
    "h1": "Node-RED vs Windmill API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-node-red-vs-windmill.png",
    "path": "/compare/node-red-vs-windmill",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Node-RED vs Windmill for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/node-red-vs-windmill"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 730
  },
  "version": 1
}
