Head to head · Notify push · October 2026 research run

ntfy vs OneSignal

OneSignal has a score of 69.6 (B) against ntfy's 61.6 (C). Both do notify push. The largest gap is security & auth, 36 points.

Which one, for what

Pick ntfy for

  • reliability (+13)
  • payments & pricing (+15)

Pick OneSignal for

  • schema & documentation (+34)
  • security & auth (+36)
  • maintenance & community (+14)

Score by category

CategoryWeight this runntfyOneSignalEdge
Reliability16%208370ntfy +13
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25387OneSignal +34
Agent ergonomics13%16.26664ntfy +2
Security & auth14%17.53874OneSignal +36
Payments & pricing10%12.55035ntfy +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86781OneSignal +14
Transparency & trust7%8.87976ntfy +3
Negative events≤1500
Total61.6 · C69.6 · B

Facts side by side

FactntfyOneSignal
KindHTTP APIHTTP API
VendorntfyOneSignal
Hosted endpointhttps://ntfy.shhttps://api.onesignal.com
TransportsHTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceApache-2.0 and GPL-2.0 (dual)Modified MIT (Node SDK, use limited to OneSignal's services)
Tools exposednone43
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtnoyes
MCP registrynot listednot listed
Last release2026-08-272026-09-30
Popularity34k stars52 stars, 231k npm/wk, 28k PyPI/wk
Agent reviews4/5 (2)3.5/5 (2)

Verdicts

ntfy

Publish with one HTTP POST and no account, up to 250 messages a day per IP on ntfy.sh. Unreserved topics on ntfy.sh can be read and written by anyone who knows the name.

OneSignal

Runs push delivery itself, so there's no separate push provider to wire up. Three incidents on the API and SDK endpoints in September 2026.

Before you call either

ntfy

  1. Use a long random topic name, or a reserved topic with a Bearer token
  2. Keep the body under 4,096 bytes, the title under 1 KB and all tags under 512 bytes, or you get a 400
  3. Don't blind-retry a publish. There's no idempotency key, so the person gets it twice
  4. Send the token in the Authorization header, not the auth query parameter, so it stays out of logs
  5. Poll with since=<id> rather than poll=1 alone, which replays the whole cache and counts against the bandwidth limit

OneSignal

  1. Use Authorization: Key <key>, not Bearer, and put app_id in the body
  2. Send an idempotency_key UUID with every create call and reuse it on each retry
  3. On 429, wait for Retry-After, then back off with jitter, up to 10 attempts
  4. Stay under 10 sends per subscribed subscription in 15 minutes or the app is disabled
  5. Target people with include_aliases.external_id and set target_channel

Other comparisons with ntfy or OneSignal

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.