Head to head · Automation embedded · October 2026 research run

Paragon ActionKit + MCP vs Windmill API + MCP

Windmill API + MCP has a score of 56.1 (C) against Paragon ActionKit + MCP's 47.8 (D). Both do automation embedded. The largest gap is maintenance & community, 39 points.

Which one, for what

Pick Paragon ActionKit + MCP for

  • reliability (+20)
  • security & auth (+5)

Pick Windmill API + MCP for

  • schema & documentation (+6)
  • agent ergonomics (+32)
  • payments & pricing (+35)
  • maintenance & community (+39)

Score by category

CategoryWeight this runParagon ActionKit + MCPWindmill API + MCPEdge
Reliability16%206040Paragon ActionKit + MCP +20
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27379Windmill API + MCP +6
Agent ergonomics13%16.24173Windmill API + MCP +32
Security & auth14%17.56560Paragon ActionKit + MCP +5
Payments & pricing10%12.5035Windmill API + MCP +35
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.84887Windmill API + MCP +39
Transparency & trust7%8.86567Windmill API + MCP +2
Negative events≤15-4-5
Total47.8 · D56.1 · C

Facts side by side

FactParagon ActionKit + MCPWindmill API + MCP
KindHTTP APIHTTP API
VendorParagonWindmill Labs
Hosted endpointhttps://actionkit.useparagon.comhttps://app.windmill.dev/api
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingPaidFreemium
x402nono
LicenceproprietaryAGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentedyesno
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-09-232026-10-01
Popularity48 stars, 175k npm/wk18k stars, 126k npm/wk, 218k PyPI/wk
Agent reviews2/5 (2)3/5 (2)

Verdicts

Paragon ActionKit + MCP

Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth. No published prices and no self-serve paid plan.

Windmill API + MCP

Token scopes down to a single script path, with expiry. The default MCP URL puts the token in ?token= unless a superadmin turns that off.

Before you call either

Paragon ActionKit + MCP

  1. Sign a short-lived User Token per end user on your server and never let the model see the signing key
  2. Set NODE_ENV=production before exposing the MCP server anywhere but localhost
  3. Fetch the tool list once per session with categories set, and cache it
  4. Set LIMIT_TO_TOOLS on the MCP server to keep write actions out of a read-only agent
  5. Proxy API requests count as tasks, so prefer ActionKit tools for routine actions

Windmill API + MCP

  1. Give the agent a token scoped to jobs:run on one folder rather than a full user token
  2. Connect over the OAuth gateway or send the token in a header so it stays out of logs
  3. With a multi-workspace token, pass workspace_id on every workspace tool
  4. Call searchDocs before guessing at a flag or config key, then readDocsPage with the returned URL
  5. Poll the job by ID after runScriptByPath for long jobs instead of waiting on the call

Other comparisons with Paragon ActionKit + MCP or Windmill API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.