{
  "data": {
    "a": {
      "slug": "paragon",
      "name": "Paragon ActionKit + MCP",
      "vendor": "Paragon",
      "vendorUrl": "https://www.useparagon.com",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Embedded integration platform for SaaS products.",
      "url": "https://www.anchorterminal.com/tools/paragon",
      "markdownUrl": "https://www.anchorterminal.com/tools/paragon.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paragon.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paragon.json",
      "repo": "https://github.com/useparagon/paragon-mcp",
      "license": "proprietary",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://actionkit.useparagon.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@useparagon/connect"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every call carries a Paragon User Token, an RS256 JWT your server signs with the project's private signing key and sends as 'Authorization: Bearer'. It names the end user, so each tool call runs against that user's connected accounts. The self-hosted MCP server takes the same token and binds it to the session.",
      "pricing": "paid",
      "pricingNotes": "Pro and Enterprise plans, both quoted by sales and priced by the number of Connected Users (customer tenants), with a free trial. Workflows, ActionKit and Managed Sync come with default usage per Connected User. Successful workflow steps and every Proxy API request count as tasks against a monthly limit with no rollover. No prices are published (https://www.useparagon.com/pricing).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in Paragon docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 48,
        "npmWeekly": 175443,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.useparagon.com/actionkit/overview",
      "llmsTxt": "https://docs.useparagon.com/llms.txt",
      "openapi": "https://docs.useparagon.com/actionkit/openapi.json",
      "capabilities": [
        "automation.embedded",
        "automation.workflows",
        "automation.apps",
        "automation.auth",
        "automation.webhooks",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "enterprise",
        "webhooks"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 47.8,
        "grade": "D",
        "agentReady": false,
        "rank": 381,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 41,
          "maintenance": 48,
          "payments": 0,
          "reliability": 60,
          "schema": 73,
          "security": 65,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -4,
        "negativeNotes": [
          "As of the 30 September 2026 commit, the self-hosted MCP server defaults `NODE_ENV` to development, and in development `/mcp` and `/sse` sign a user token for whatever ID arrives in `?user=`. The Dockerfile and the image its workflow publishes don't set `NODE_ENV`, so a server started from that image without the variable lets anyone who can reach it impersonate any end user. The README documents the behaviour and the compose file sets production, so the deduction is modest (https://github.com/useparagon/paragon-mcp/blob/main/src/index.ts, https://github.com/useparagon/paragon-mcp/blob/main/src/utils.ts)."
        ],
        "verdict": "Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth. No published prices and no self-serve paid plan.",
        "strengths": [
          "Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth",
          "ActionKit lists tools as JSON Schema and has an OpenAPI 3.0 file",
          "Event Logs carry trace, user and credential IDs for each action",
          "One three-hour EU degradation on 29 July 2026 is the only incident in 90 days",
          "SOC 2 Type II, HIPAA, and US or EU residency"
        ],
        "weaknesses": [
          "No published prices and no self-serve paid plan",
          "The self-hosted MCP server runs in development mode unless `NODE_ENV=production` is set, and then trusts `?user=`",
          "No error schemas in the OpenAPI file, no ActionKit rate limit and no tool annotations",
          "Changelog's newest entry is April 2026",
          "No security.txt, and the MCP server's licence is stated two ways with no `LICENSE` file"
        ],
        "agentNotes": [
          "Sign a short-lived User Token per end user on your server and never let the model see the signing key",
          "Set `NODE_ENV=production` before exposing the MCP server anywhere but localhost",
          "Fetch the tool list once per session with `categories` set, and cache it",
          "Set `LIMIT_TO_TOOLS` on the MCP server to keep write actions out of a read-only agent",
          "Proxy API requests count as tasks, so prefer ActionKit tools for routine actions"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 47.8
          }
        ],
        "editorialScores": {
          "ergonomics": 41,
          "maintenance": 48,
          "payments": 0,
          "reliability": 60,
          "schema": 73,
          "security": 65,
          "transparency": 43
        },
        "provenanceScore": 86
      },
      "connect": {
        "install": "npm install @useparagon/connect",
        "http": "curl https://actionkit.useparagon.com/projects/$PARAGON_PROJECT_ID/tools -H \"Authorization: Bearer $PARAGON_USER_TOKEN\"",
        "claudeCode": "claude mcp add --transport http paragon http://localhost:3001/mcp --header \"Authorization: Bearer ${PARAGON_USER_TOKEN}\"",
        "config": {
          "mcpServers": {
            "paragon": {
              "headers": {
                "Authorization": "Bearer ${PARAGON_USER_TOKEN}"
              },
              "url": "http://localhost:3001/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.embedded",
        "tool": "https://letme.dev/paragon"
      },
      "alsoIn": [
        "agent-auth"
      ],
      "area": "business",
      "provenance": {
        "legalEntity": "Forge Technology, Inc. (d/b/a Paragon)",
        "domain": "useparagon.com",
        "domainRegistered": "2019-08-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.useparagon.com/terms-of-service",
        "privacy": "https://www.useparagon.com/privacy-policy",
        "statusPage": "https://status.useparagon.com",
        "changelog": "https://docs.useparagon.com/changelog/product-updates",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 86
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/paragon.json",
      "live": {
        "slug": "paragon",
        "probe": {
          "target": "https://actionkit.useparagon.com",
          "method": "get",
          "lastAt": "2026-10-05T01:43:42.625765544Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 307,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 309,
          "p95ms24h": 380,
          "samples24h": 272,
          "samples30d": 1122,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.useparagon.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T01:46:42.466958167Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@useparagon/connect",
            "version": "3.1.0",
            "seenAt": "2026-10-04T16:36:14.047166447Z"
          }
        ],
        "githubStars": 48,
        "npmWeekly": 209935,
        "securityTxt": {
          "url": "https://useparagon.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:38.675956466Z"
        },
        "llmsTxt": {
          "url": "https://docs.useparagon.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:05.97376219Z"
        },
        "domain": {
          "domain": "useparagon.com",
          "registered": "2019-08-30",
          "source": "https://rdap.verisign.com/com/v1/domain/useparagon.com",
          "checkedAt": "2026-10-04T13:08:02.741729991Z"
        },
        "pages": [
          {
            "url": "https://docs.useparagon.com/changelog/product-updates",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:44:12.572071633Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1f693d6387f4"
          },
          {
            "url": "https://www.useparagon.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:39.051971068Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8c248050adff"
          },
          {
            "url": "https://www.useparagon.com/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:41.720779341Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "63ed04f01ce4"
          },
          {
            "url": "https://www.useparagon.com/terms-of-service",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:43.233474446Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c2cc0e396ab4"
          }
        ],
        "updatedAt": "2026-10-05T01:46:42.466958167Z"
      }
    },
    "b": {
      "slug": "windmill",
      "name": "Windmill API + MCP",
      "vendor": "Windmill Labs",
      "vendorUrl": "https://www.windmill.dev",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Code-first engine for scripts, flows and internal apps in 20+ languages, written in Rust, on Windmill Cloud or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/windmill",
      "markdownUrl": "https://www.anchorterminal.com/tools/windmill.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/windmill.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/windmill.json",
      "repo": "https://github.com/windmill-labs/windmill",
      "license": "AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://app.windmill.dev/api",
      "packages": [
        {
          "registry": "npm",
          "name": "windmill-client"
        },
        {
          "registry": "pypi",
          "name": "wmill"
        }
      ],
      "auth": "mixed",
      "authNotes": "Bearer user tokens with optional scopes (`{domain}:{action}[:{path}]`, e.g. `jobs:run:flows`) and expiry. MCP by OAuth at /api/mcp/gateway, or a token either in the URL (`?token=`) or in an Authorization header. Admins can make the MCP endpoints refuse tokens in URLs.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosted Community Edition is free with unlimited executions (up to 50 users, 3 workspaces). Self-hosted Enterprise from $120 a month, priced as developer seats $20 a month, operators $10 and compute at $50 a month per standard 2 GB worker. Pro gets the same terms for companies under 10 staff and $250,000 revenue. Cloud has a free tier and paid Team and Enterprise workspaces billed on seats and compute (https://www.windmill.dev/pricing).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 18070,
        "npmWeekly": 126287,
        "pypiWeekly": 218343,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.windmill.dev/docs",
      "llmsTxt": "https://www.windmill.dev/llms.txt",
      "openapi": "https://app.windmill.dev/api/openapi.yaml",
      "capabilities": [
        "automation.workflows",
        "automation.code",
        "automation.webhooks",
        "automation.embedded",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "local",
        "freemium",
        "mcp",
        "llms-txt",
        "openapi",
        "python",
        "typescript",
        "webhooks",
        "enterprise"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.1,
        "grade": "C",
        "agentReady": false,
        "rank": 306,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 87,
          "payments": 35,
          "reliability": 40,
          "schema": 79,
          "security": 60,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "CVE-2026-23696, SQL injection in folder ownership management for any low-privilege user in Windmill 1.276.0 to 1.603.2, CVSS 4.0 score 9.4, exposing JWT secrets and admin identifiers. Fixed in 1.603.3 and published by NVD on 7 April 2026 (https://github.com/advisories/GHSA-34m2-qrpf-6v7q).",
          "GHSA-24fr-44f8-fqwg, published 2 March 2026, high. SUPERADMIN_SECRET could be read publicly through RCE on versions before 1.603.3. CVE-2026-22683, missing authorisation in 1.56.0 to 1.614.0, rated high on 7 April 2026. All fixed, so the deduction is reduced (https://github.com/windmill-labs/windmill/security/advisories, https://github.com/advisories?query=windmill)."
        ],
        "verdict": "Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off.",
        "strengths": [
          "Token scopes down to a single script path, with expiry",
          "OpenAPI 3.0.3 with 913 operations and Apache-2.0 clients for TypeScript, Python, Go and Rust",
          "Every script and flow is an MCP tool, filterable by folder and favourites",
          "97 tagged releases in 90 days, latest v1.821.0 on 1 October 2026",
          "Free unlimited executions on Cloud free workspaces and self-hosted Community Edition"
        ],
        "weaknesses": [
          "The default MCP URL puts the token in `?token=` unless a superadmin turns that off",
          "CVE-2026-23696, a critical SQL injection fixed in 1.603.3, had no Windmill advisory",
          "No published API rate limits, 429 guidance or uptime SLA",
          "The OpenAPI file documents errors for only about 30 operations",
          "No SECURITY.md or security.txt"
        ],
        "agentNotes": [
          "Give the agent a token scoped to `jobs:run` on one folder rather than a full user token",
          "Connect over the OAuth gateway or send the token in a header so it stays out of logs",
          "With a multi-workspace token, pass `workspace_id` on every workspace tool",
          "Call `searchDocs` before guessing at a flag or config key, then `readDocsPage` with the returned URL",
          "Poll the job by ID after `runScriptByPath` for long jobs instead of waiting on the call"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.1
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 87,
          "payments": 35,
          "reliability": 40,
          "schema": 79,
          "security": 60,
          "transparency": 51
        },
        "provenanceScore": 82
      },
      "connect": {
        "http": "curl \"https://app.windmill.dev/api/w/$WM_WORKSPACE/scripts/list\" -H \"Authorization: Bearer $WM_TOKEN\"",
        "claudeCode": "claude mcp add --transport http windmill https://app.windmill.dev/api/mcp/gateway",
        "config": {
          "mcpServers": {
            "windmill": {
              "headers": {
                "Authorization": "Bearer ${WM_TOKEN}"
              },
              "url": "https://app.windmill.dev/api/mcp/w/${WM_WORKSPACE}/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/windmill"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Developer seat (Enterprise)",
          "unit": "seat-month",
          "usd": 20
        },
        {
          "item": "Operator seat (Enterprise)",
          "unit": "seat-month",
          "usd": 10,
          "note": "run-only users and external JWT users"
        },
        {
          "item": "Compute (Enterprise)",
          "unit": "compute-unit",
          "usd": 25,
          "note": "$50 a month per standard 2 GB worker, which is 2 CU"
        },
        {
          "item": "Enterprise minimum",
          "unit": "month",
          "usd": 120,
          "note": "from price shown on the pricing page"
        }
      ],
      "provenance": {
        "legalEntity": "Windmill Labs, Inc.",
        "domain": "windmill.dev",
        "domainRegistered": "2022-01-06",
        "endpointOnVendorDomain": true,
        "terms": "https://www.windmill.dev/terms",
        "privacy": "https://www.windmill.dev/privacy_policy",
        "statusPage": "https://status.windmill.dev",
        "changelog": "https://www.windmill.dev/changelog",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "status.windmill.dev redirects to an UptimeRobot page."
        ],
        "score": 82
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/windmill.json",
      "live": {
        "slug": "windmill",
        "probe": {
          "target": "https://app.windmill.dev/api",
          "method": "get",
          "lastAt": "2026-10-05T01:43:48.339922231Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 201,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 193,
          "p95ms24h": 270,
          "samples24h": 272,
          "samples30d": 1122,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.windmill.dev",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:34.344290717Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "windmill-labs/windmill",
            "version": "v1.823.0",
            "released": "2026-10-04",
            "seenAt": "2026-10-04T16:44:06.725357613Z"
          },
          {
            "registry": "npm",
            "name": "windmill-client",
            "version": "1.823.0",
            "seenAt": "2026-10-04T16:44:05.723408816Z"
          },
          {
            "registry": "pypi",
            "name": "wmill",
            "version": "1.823.0",
            "released": "2026-10-04",
            "seenAt": "2026-10-04T16:44:06.517494992Z"
          }
        ],
        "githubStars": 18100,
        "npmWeekly": 115148,
        "pypiWeekly": 202114,
        "securityTxt": {
          "url": "https://windmill.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:56.890039603Z"
        },
        "llmsTxt": {
          "url": "https://www.windmill.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:21.79889133Z"
        },
        "domain": {
          "domain": "windmill.dev",
          "registered": "2022-01-06",
          "source": "https://pubapi.registry.google/rdap/domain/windmill.dev",
          "checkedAt": "2026-10-04T13:08:55.755645623Z"
        },
        "pages": [
          {
            "url": "https://www.windmill.dev/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:52:54.602469194Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d84df043288b"
          },
          {
            "url": "https://www.windmill.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:52:56.757806304Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "afa04f8b73f5"
          },
          {
            "url": "https://www.windmill.dev/privacy_policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:52:58.695821422Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d11624ab86ec"
          },
          {
            "url": "https://www.windmill.dev/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:53:00.660836822Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e3b0c44298fc"
          }
        ],
        "updatedAt": "2026-10-05T01:43:48.339922231Z"
      }
    },
    "summary": "Windmill API + MCP has a score of 56.1 (C) against Paragon ActionKit + MCP's 47.8 (D). Both do automation embedded. The largest gap is maintenance \u0026 community, 39 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/paragon-vs-windmill",
    "json": "https://www.anchorterminal.com/compare/paragon-vs-windmill.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/paragon-vs-windmill.md",
    "slim": "https://www.anchorterminal.com/compare/paragon-vs-windmill.min.md"
  },
  "markdown": "Windmill API + MCP has a score of 56.1 (C) against Paragon ActionKit + MCP's 47.8 (D). Both do automation embedded. The largest gap is maintenance \u0026 community, 39 points.\n\n- Paragon ActionKit + MCP: grade D, 47.8/100, rank #381 of 452. Markdown https://www.anchorterminal.com/tools/paragon.md · JSON https://www.anchorterminal.com/api/v1/tools/paragon.json\n- Windmill API + MCP: grade C, 56.1/100, rank #306 of 452. Markdown https://www.anchorterminal.com/tools/windmill.md · JSON https://www.anchorterminal.com/api/v1/tools/windmill.json\n\n## Which one, for what\n\nPick Paragon ActionKit + MCP for reliability (+20), security \u0026 auth (+5).\n\nPick Windmill API + MCP for schema \u0026 documentation (+6), agent ergonomics (+32), payments \u0026 pricing (+35), maintenance \u0026 community (+39).\n\n## Score by category\n\n| Category | Weight | Paragon ActionKit + MCP | Windmill API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 60 | 40 | Paragon ActionKit + MCP +20 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 73 | 79 | Windmill API + MCP +6 |\n| Agent ergonomics | 13% (16.2 this run) | 41 | 73 | Windmill API + MCP +32 |\n| Security \u0026 auth | 14% (17.5 this run) | 65 | 60 | Paragon ActionKit + MCP +5 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 0 | 35 | Windmill API + MCP +35 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 48 | 87 | Windmill API + MCP +39 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 65 | 67 | Windmill API + MCP +2 |\n| Negative events | ≤15 | -4 | -5 | |\n| **Total** | | **47.8 · D** | **56.1 · C** | |\n\n## Facts side by side\n\n| Fact | Paragon ActionKit + MCP | Windmill API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Paragon | Windmill Labs |\n| Hosted endpoint | `https://actionkit.useparagon.com` | `https://app.windmill.dev/api` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | proprietary | AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-23 | 2026-10-01 |\n| Popularity | 48 stars, 175k npm/wk | 18k stars, 126k npm/wk, 218k PyPI/wk |\n| Agent reviews | 2/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**Paragon ActionKit + MCP.** Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth. No published prices and no self-serve paid plan.\n\n**Windmill API + MCP.** Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off.\n\n## Before you call either\n\n### Paragon ActionKit + MCP\n\n1. Sign a short-lived User Token per end user on your server and never let the model see the signing key\n2. Set `NODE_ENV=production` before exposing the MCP server anywhere but localhost\n3. Fetch the tool list once per session with `categories` set, and cache it\n4. Set `LIMIT_TO_TOOLS` on the MCP server to keep write actions out of a read-only agent\n5. Proxy API requests count as tasks, so prefer ActionKit tools for routine actions\n\n### Windmill API + MCP\n\n1. Give the agent a token scoped to `jobs:run` on one folder rather than a full user token\n2. Connect over the OAuth gateway or send the token in a header so it stays out of logs\n3. With a multi-workspace token, pass `workspace_id` on every workspace tool\n4. Call `searchDocs` before guessing at a flag or config key, then `readDocsPage` with the returned URL\n5. Poll the job by ID after `runScriptByPath` for long jobs instead of waiting on the call\n\n## Other comparisons with Paragon ActionKit + MCP or Windmill API + MCP\n\n- [Activepieces API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/activepieces-vs-paragon.md)\n- [Activepieces API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-windmill.md)\n- [Make API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/make-vs-paragon.md)\n- [Make API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/make-vs-windmill.md)\n- [n8n API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/n8n-vs-paragon.md)\n- [n8n API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/n8n-vs-windmill.md)\n- [Pipedream API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/pipedream-vs-windmill.md)\n- [Tray.ai API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/tray-vs-windmill.md)\n- [Windmill API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/windmill-vs-workato.md)\n- [Paragon ActionKit + MCP vs Pipedream API + MCP](https://www.anchorterminal.com/compare/paragon-vs-pipedream.md)\n- [Paragon ActionKit + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/paragon-vs-tray.md)\n- [Paragon ActionKit + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/paragon-vs-workato.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Paragon ActionKit + MCP vs Windmill API + MCP",
        "url": ""
      }
    ],
    "description": "Windmill API + MCP has a score of 56.1 (C) against Paragon ActionKit + MCP's 47.8 (D). Both do automation embedded. The largest gap is maintenance \u0026 community, 39 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Paragon ActionKit + MCP D 47.8",
      "Windmill API + MCP C 56.1",
      "scores"
    ],
    "h1": "Paragon ActionKit + MCP vs Windmill API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-paragon-vs-windmill.png",
    "path": "/compare/paragon-vs-windmill",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Paragon ActionKit + MCP vs Windmill API + MCP for AI agents",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/paragon-vs-windmill"
  },
  "tokens": {
    "markdown": 1500,
    "slim": 380
  },
  "version": 1
}
