Head to head · Browser automation · October 2026 research run

Skyvern vs TinyFish

TinyFish scores 67.7 (B) on agent readiness against Skyvern's 63.1 (B), and leads in 3 of 7 scored categories. Skyvern leads on maintenance & community and transparency & trust. Both do browser automation.

Which one, for what

Skyvern B

Good for Agents that must finish a multi-step job on sites with logins, 2FA and forms, where stored credentials, saved workflows and cached scripts matter more than raw browser time.

Ahead on

  • Maintenance & community, 85 against 80
  • Transparency & trust, 72 against 59

Also in its favour

  • Runs on your own machine
  • Open source

Watch for

Every API key and OAuth token has full organisation authority. The docs state there are no read-only, per-endpoint or per-resource keys

TinyFish B

Good for Agents that want one account for a goal-driven web agent, a raw CDP browser, and free search and fetch.

Ahead on

  • Payments & pricing, 55 against 32

Also in its favour

  • No incidents deducted, where Skyvern loses 3 points for them

Watch for

The terms of 17 August 2026 allow Tiny Fish to train and improve its models on customer data. No opt-out was found in the reviewed pages

Score by category

CategoryWeight this runSkyvernTinyFishEdge
Reliability16%205760TinyFish +3
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28885Skyvern +3
Agent ergonomics13%16.27679TinyFish +3
Security & auth14%17.55957Skyvern +2
Payments & pricing10%12.53255TinyFish +23
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88580Skyvern +5
Transparency & trust7%8.87259Skyvern +13
Negative events≤15-30
Total63.1 · B67.7 · B

Facts side by side

FactSkyvernTinyFish
KindHTTP APIHTTP API
VendorIkonomos Inc. (Skyvern)Tiny Fish, Inc.
Hosted endpointhttps://api.skyvern.com/v1https://agent.tinyfish.ai
TransportsHTTP, Streamable HTTP, stdioHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceAGPL-3.0 for the open-source server, SDKs and MCP server. Skyvern Cloud is a proprietary service under Skyvern's terms, and its anti-bot measures aren't in the repositoryProprietary service under Tiny Fish's terms of service. The MCP proxy @tiny-fish/mcp and the cookbook are MIT. The SDK packages state no licence in npm or PyPI metadata
Tools exposed114none
Read-only variant documentednono
llms.txtyesyes
MCP registryio.github.Skyvern-AI/skyvernai.tinyfish.agent/web-agent
Last release2026-10-012026-10-07
Terms last updated2026-02-272026-08-17
Privacy policy last updated2026-10-012025-12-14
Customer content may train modelsyes, with an opt-outyes
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waiveryesyes
Popularity23k stars, 3.2k npm/wk, 1.6k PyPI/wk5.7k npm/wk, 6.5k PyPI/wk

Verdicts

Skyvern

The hosted MCP server annotates every tool as read-only or destructive and can advertise a 29 or 32-tool subset in place of 114, and the API has a written six-month deprecation policy. Every key and OAuth token carries full organisation authority, with no read-only or scoped credential, and no request rate limits are documented.

TinyFish

OpenAPI documents are published for five APIs, errors carry typed codes and request IDs, and Search and Fetch are free within daily allowances. The terms let Tiny Fish train its models on customer data, run creation takes no idempotency keys, and the status page shows an hour or more of downtime on several days for the Browser and Search APIs.

Before you call either

Skyvern

  1. Connect to https://api.skyvern.com/mcp/x/lean or /x/operate, or send X-Skyvern-Scope, so the client loads 32 or 29 tools. The scope filters the list and does not limit permissions
  2. Use a separate Skyvern organisation for each blast radius. Any key or OAuth token can read and write stored credentials and delete workflows
  3. Never pass passwords to skyvern_act or skyvern_type. Store them as credentials and call skyvern_login
  4. Set max_steps on tasks, or x-max-steps-override on agent runs, to cap credits. A run that reaches the cap ends as timed_out
  5. On 503 from POST /v1/run/agents, wait Retry-After seconds. No run was created, so resubmitting is safe

TinyFish

  1. Check result as well as status. A run can be COMPLETED while the goal failed, with result.status set to failure
  2. Don't retry POST /v1/automation/run blindly after a timeout. There are no idempotency keys, so list runs first to avoid duplicates
  3. Use /v1/automation/run-async or /run-sse when a run may need cancelling. Runs started with the synchronous endpoint can't be cancelled
  4. Allow 60 seconds for Browser session creation, connect Playwright to cdp_url (not base_url), and DELETE the session when done because billing is per minute
  5. Never put passwords in goal, which is logged. Pass use_vault: true with credential_item_ids, or use_profile: true for saved login state

Questions

Which is better for AI agents, Skyvern or TinyFish?

TinyFish scores 67.7 (B) on agent readiness against Skyvern's 63.1 (B), and leads in 3 of 7 scored categories. Skyvern leads on maintenance & community and transparency & trust.

Do Skyvern and TinyFish need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Skyvern and TinyFish without installing anything?

Yes. Skyvern has a hosted endpoint at https://api.skyvern.com/v1 and TinyFish at https://agent.tinyfish.ai.

Are Skyvern and TinyFish open source?

Skyvern is open source (AGPL-3.0 for the open-source server, SDKs and MCP server. Skyvern Cloud is a proprietary service under Skyvern's terms, and its anti-bot measures aren't in the repository). No open-source release is listed for TinyFish.

Other comparisons with Skyvern or TinyFish

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.