{
  "data": {
    "a": {
      "slug": "tray",
      "name": "Tray.ai API + MCP",
      "vendor": "Tray.ai",
      "vendorUrl": "https://tray.ai",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Low-code integration platform with an embedded product for SaaS vendors.",
      "url": "https://www.anchorterminal.com/tools/tray",
      "markdownUrl": "https://www.anchorterminal.com/tools/tray.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/tray.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/tray.json",
      "license": "proprietary",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.tray.io/core/v1",
      "packages": [],
      "auth": "mixed",
      "authNotes": "REST and GraphQL endpoints take a bearer token, either the org master token (you act) or an end user's user token (you act as them). Tray Headless MCP uses a one-time OAuth2 sign-in bound to one workspace, and the docs say not to send a static Authorization header. Agent Gateway MCP servers take OAuth2 or an API token, and API token users can't use per-user credentials.",
      "pricing": "paid",
      "pricingNotes": "Pro, Team and Enterprise plans, all quoted by sales and billed on tasks that cover integration, automation, MCP and agent use. Every plan lists full API access and Tray Headless, and Agent Gateway is an add-on. A free trial exists with no stated length. No prices are published (https://tray.ai/pricing/).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in Tray docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://tray.ai/documentation/developer/getting-started/introduction",
      "llmsTxt": "https://tray.ai/documentation/llms.txt",
      "openapi": "https://tray.ai/documentation/files/openapi/trayapi.yaml",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.embedded",
        "automation.code",
        "automation.webhooks",
        "automation.auth",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "mcp",
        "llms-txt",
        "openapi",
        "enterprise",
        "closed-source",
        "webhooks"
      ],
      "lastRelease": "2026-09-09",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.6,
        "grade": "C",
        "agentReady": false,
        "rank": 312,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 6,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 33,
          "maintenance": 60,
          "payments": 0,
          "reliability": 72,
          "schema": 80,
          "security": 66,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Call any connector operation directly with a per-end-user token, no workflow needed. No published prices and no self-serve plan.",
        "strengths": [
          "Call any connector operation directly with a per-end-user token, no workflow needed",
          "Published API limits, 30 requests a second with bursts to 50",
          "Every action logged and streamable, with settable retention and log masking",
          "Four minor incidents in 90 days, none on the core APIs",
          "US, EU and APAC regions, SOC 2 Type 2 and a pentest dated 23 September 2026"
        ],
        "weaknesses": [
          "No published prices and no self-serve plan",
          "Upstream 429s are wrapped in a 200, which hides throttling from naive retry logic",
          "Headless MCP can delete projects, workflows and auths with no server-side confirmation",
          "No official SDK and no tool annotations",
          "API lives on api.tray.io while the brand, docs and legal pages are on tray.ai"
        ],
        "agentNotes": [
          "Use a user token when acting for a customer and the master token only for admin work",
          "Parse the body of call-connector responses for upstream status codes before treating a 200 as success",
          "Point Headless MCP at the workspace's region, api.eu1.tray.io or api.ap1.tray.io outside the US",
          "Pick the workspace at OAuth sign-in. Headless MCP binds it to the session and takes no workspace ID",
          "Ask before any Headless MCP delete. The server won't"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.6
          }
        ],
        "editorialScores": {
          "ergonomics": 33,
          "maintenance": 60,
          "payments": 0,
          "reliability": 72,
          "schema": 80,
          "security": 66,
          "transparency": 67
        },
        "provenanceScore": 71
      },
      "connect": {
        "http": "curl https://api.tray.io/core/v1/connectors -H \"Authorization: Bearer $TRAY_MASTER_TOKEN\"",
        "claudeCode": "claude mcp add --transport http tray https://api.tray.io/mcp",
        "config": {
          "mcpServers": {
            "tray": {
              "url": "https://api.tray.io/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/tray"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Tray.ai, Inc.",
        "domain": "tray.ai",
        "domainRegistered": "2017-12-15",
        "domainNote": "The API and MCP hosts are on tray.io, the company's former domain. The brand, docs and legal pages are on tray.ai.",
        "endpointOnVendorDomain": false,
        "terms": "https://tray.ai/legal/msa/",
        "privacy": "https://tray.ai/legal/privacy-policy/",
        "statusPage": "https://status.tray.ai/",
        "changelog": "https://tray.ai/documentation/releases",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/tray.json",
      "live": {
        "slug": "tray",
        "probe": {
          "target": "https://api.tray.io/core/v1",
          "method": "get",
          "lastAt": "2026-10-05T00:57:29.595844866Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 470,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 443,
          "p95ms24h": 498,
          "samples24h": 272,
          "samples30d": 1113,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 11,
              "ok": 11
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.tray.ai",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T00:54:07.267885248Z"
        },
        "securityTxt": {
          "url": "https://tray.ai/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:48.622064082Z"
        },
        "llmsTxt": {
          "url": "https://tray.ai/documentation/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:18.435740616Z"
        },
        "domain": {
          "domain": "tray.ai",
          "registered": "2017-12-15",
          "source": "https://rdap.identitydigital.services/rdap/domain/tray.ai",
          "checkedAt": "2026-10-04T13:09:14.155471976Z"
        },
        "pages": [
          {
            "url": "https://tray.ai/documentation/releases",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:29.705138929Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7b99a20c97aa"
          },
          {
            "url": "https://tray.ai/pricing/",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:35.754465067Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d5fff351c231"
          },
          {
            "url": "https://tray.ai/legal/privacy-policy/",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:33.769653273Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "dd9225a00b9d"
          },
          {
            "url": "https://tray.ai/legal/msa/",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:31.993785138Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "67ce69d3046a"
          }
        ],
        "updatedAt": "2026-10-05T00:57:29.595844866Z"
      }
    },
    "b": {
      "slug": "windmill",
      "name": "Windmill API + MCP",
      "vendor": "Windmill Labs",
      "vendorUrl": "https://www.windmill.dev",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Code-first engine for scripts, flows and internal apps in 20+ languages, written in Rust, on Windmill Cloud or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/windmill",
      "markdownUrl": "https://www.anchorterminal.com/tools/windmill.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/windmill.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/windmill.json",
      "repo": "https://github.com/windmill-labs/windmill",
      "license": "AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://app.windmill.dev/api",
      "packages": [
        {
          "registry": "npm",
          "name": "windmill-client"
        },
        {
          "registry": "pypi",
          "name": "wmill"
        }
      ],
      "auth": "mixed",
      "authNotes": "Bearer user tokens with optional scopes (`{domain}:{action}[:{path}]`, e.g. `jobs:run:flows`) and expiry. MCP by OAuth at /api/mcp/gateway, or a token either in the URL (`?token=`) or in an Authorization header. Admins can make the MCP endpoints refuse tokens in URLs.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosted Community Edition is free with unlimited executions (up to 50 users, 3 workspaces). Self-hosted Enterprise from $120 a month, priced as developer seats $20 a month, operators $10 and compute at $50 a month per standard 2 GB worker. Pro gets the same terms for companies under 10 staff and $250,000 revenue. Cloud has a free tier and paid Team and Enterprise workspaces billed on seats and compute (https://www.windmill.dev/pricing).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 18070,
        "npmWeekly": 126287,
        "pypiWeekly": 218343,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.windmill.dev/docs",
      "llmsTxt": "https://www.windmill.dev/llms.txt",
      "openapi": "https://app.windmill.dev/api/openapi.yaml",
      "capabilities": [
        "automation.workflows",
        "automation.code",
        "automation.webhooks",
        "automation.embedded",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "local",
        "freemium",
        "mcp",
        "llms-txt",
        "openapi",
        "python",
        "typescript",
        "webhooks",
        "enterprise"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.1,
        "grade": "C",
        "agentReady": false,
        "rank": 306,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 87,
          "payments": 35,
          "reliability": 40,
          "schema": 79,
          "security": 60,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "CVE-2026-23696, SQL injection in folder ownership management for any low-privilege user in Windmill 1.276.0 to 1.603.2, CVSS 4.0 score 9.4, exposing JWT secrets and admin identifiers. Fixed in 1.603.3 and published by NVD on 7 April 2026 (https://github.com/advisories/GHSA-34m2-qrpf-6v7q).",
          "GHSA-24fr-44f8-fqwg, published 2 March 2026, high. SUPERADMIN_SECRET could be read publicly through RCE on versions before 1.603.3. CVE-2026-22683, missing authorisation in 1.56.0 to 1.614.0, rated high on 7 April 2026. All fixed, so the deduction is reduced (https://github.com/windmill-labs/windmill/security/advisories, https://github.com/advisories?query=windmill)."
        ],
        "verdict": "Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off.",
        "strengths": [
          "Token scopes down to a single script path, with expiry",
          "OpenAPI 3.0.3 with 913 operations and Apache-2.0 clients for TypeScript, Python, Go and Rust",
          "Every script and flow is an MCP tool, filterable by folder and favourites",
          "97 tagged releases in 90 days, latest v1.821.0 on 1 October 2026",
          "Free unlimited executions on Cloud free workspaces and self-hosted Community Edition"
        ],
        "weaknesses": [
          "The default MCP URL puts the token in `?token=` unless a superadmin turns that off",
          "CVE-2026-23696, a critical SQL injection fixed in 1.603.3, had no Windmill advisory",
          "No published API rate limits, 429 guidance or uptime SLA",
          "The OpenAPI file documents errors for only about 30 operations",
          "No SECURITY.md or security.txt"
        ],
        "agentNotes": [
          "Give the agent a token scoped to `jobs:run` on one folder rather than a full user token",
          "Connect over the OAuth gateway or send the token in a header so it stays out of logs",
          "With a multi-workspace token, pass `workspace_id` on every workspace tool",
          "Call `searchDocs` before guessing at a flag or config key, then `readDocsPage` with the returned URL",
          "Poll the job by ID after `runScriptByPath` for long jobs instead of waiting on the call"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.1
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 87,
          "payments": 35,
          "reliability": 40,
          "schema": 79,
          "security": 60,
          "transparency": 51
        },
        "provenanceScore": 82
      },
      "connect": {
        "http": "curl \"https://app.windmill.dev/api/w/$WM_WORKSPACE/scripts/list\" -H \"Authorization: Bearer $WM_TOKEN\"",
        "claudeCode": "claude mcp add --transport http windmill https://app.windmill.dev/api/mcp/gateway",
        "config": {
          "mcpServers": {
            "windmill": {
              "headers": {
                "Authorization": "Bearer ${WM_TOKEN}"
              },
              "url": "https://app.windmill.dev/api/mcp/w/${WM_WORKSPACE}/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/windmill"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Developer seat (Enterprise)",
          "unit": "seat-month",
          "usd": 20
        },
        {
          "item": "Operator seat (Enterprise)",
          "unit": "seat-month",
          "usd": 10,
          "note": "run-only users and external JWT users"
        },
        {
          "item": "Compute (Enterprise)",
          "unit": "compute-unit",
          "usd": 25,
          "note": "$50 a month per standard 2 GB worker, which is 2 CU"
        },
        {
          "item": "Enterprise minimum",
          "unit": "month",
          "usd": 120,
          "note": "from price shown on the pricing page"
        }
      ],
      "provenance": {
        "legalEntity": "Windmill Labs, Inc.",
        "domain": "windmill.dev",
        "domainRegistered": "2022-01-06",
        "endpointOnVendorDomain": true,
        "terms": "https://www.windmill.dev/terms",
        "privacy": "https://www.windmill.dev/privacy_policy",
        "statusPage": "https://status.windmill.dev",
        "changelog": "https://www.windmill.dev/changelog",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "status.windmill.dev redirects to an UptimeRobot page."
        ],
        "score": 82
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/windmill.json",
      "live": {
        "slug": "windmill",
        "probe": {
          "target": "https://app.windmill.dev/api",
          "method": "get",
          "lastAt": "2026-10-05T00:57:31.036033123Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 205,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 193,
          "p95ms24h": 271,
          "samples24h": 272,
          "samples30d": 1113,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 11,
              "ok": 11
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.windmill.dev",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:34.344290717Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "windmill-labs/windmill",
            "version": "v1.823.0",
            "released": "2026-10-04",
            "seenAt": "2026-10-04T16:44:06.725357613Z"
          },
          {
            "registry": "npm",
            "name": "windmill-client",
            "version": "1.823.0",
            "seenAt": "2026-10-04T16:44:05.723408816Z"
          },
          {
            "registry": "pypi",
            "name": "wmill",
            "version": "1.823.0",
            "released": "2026-10-04",
            "seenAt": "2026-10-04T16:44:06.517494992Z"
          }
        ],
        "githubStars": 18100,
        "npmWeekly": 115148,
        "pypiWeekly": 202114,
        "securityTxt": {
          "url": "https://windmill.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:56.890039603Z"
        },
        "llmsTxt": {
          "url": "https://www.windmill.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:21.79889133Z"
        },
        "domain": {
          "domain": "windmill.dev",
          "registered": "2022-01-06",
          "source": "https://pubapi.registry.google/rdap/domain/windmill.dev",
          "checkedAt": "2026-10-04T13:08:55.755645623Z"
        },
        "pages": [
          {
            "url": "https://www.windmill.dev/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:52:54.602469194Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d84df043288b"
          },
          {
            "url": "https://www.windmill.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:52:56.757806304Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "afa04f8b73f5"
          },
          {
            "url": "https://www.windmill.dev/privacy_policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:52:58.695821422Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d11624ab86ec"
          },
          {
            "url": "https://www.windmill.dev/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:53:00.660836822Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e3b0c44298fc"
          }
        ],
        "updatedAt": "2026-10-05T00:57:31.036033123Z"
      }
    },
    "summary": "Windmill API + MCP has a score of 56.1 (C) against Tray.ai API + MCP's 55.6 (C). Both do automation workflows. The largest gap is agent ergonomics, 40 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/tray-vs-windmill",
    "json": "https://www.anchorterminal.com/compare/tray-vs-windmill.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/tray-vs-windmill.md",
    "slim": "https://www.anchorterminal.com/compare/tray-vs-windmill.min.md"
  },
  "markdown": "Windmill API + MCP has a score of 56.1 (C) against Tray.ai API + MCP's 55.6 (C). Both do automation workflows. The largest gap is agent ergonomics, 40 points.\n\n- Tray.ai API + MCP: grade C, 55.6/100, rank #312 of 452. Markdown https://www.anchorterminal.com/tools/tray.md · JSON https://www.anchorterminal.com/api/v1/tools/tray.json\n- Windmill API + MCP: grade C, 56.1/100, rank #306 of 452. Markdown https://www.anchorterminal.com/tools/windmill.md · JSON https://www.anchorterminal.com/api/v1/tools/windmill.json\n\n## Which one, for what\n\nPick Tray.ai API + MCP for reliability (+32), security \u0026 auth (+6).\n\nPick Windmill API + MCP for agent ergonomics (+40), payments \u0026 pricing (+35), maintenance \u0026 community (+27).\n\n## Score by category\n\n| Category | Weight | Tray.ai API + MCP | Windmill API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 72 | 40 | Tray.ai API + MCP +32 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 80 | 79 | Tray.ai API + MCP +1 |\n| Agent ergonomics | 13% (16.2 this run) | 33 | 73 | Windmill API + MCP +40 |\n| Security \u0026 auth | 14% (17.5 this run) | 66 | 60 | Tray.ai API + MCP +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 0 | 35 | Windmill API + MCP +35 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 60 | 87 | Windmill API + MCP +27 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 67 | Tray.ai API + MCP +2 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **55.6 · C** | **56.1 · C** | |\n\n## Facts side by side\n\n| Fact | Tray.ai API + MCP | Windmill API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Tray.ai | Windmill Labs |\n| Hosted endpoint | `https://api.tray.io/core/v1` | `https://app.windmill.dev/api` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | proprietary | AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-09 | 2026-10-01 |\n| Popularity | none | 18k stars, 126k npm/wk, 218k PyPI/wk |\n| Agent reviews | 2.5/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**Tray.ai API + MCP.** Call any connector operation directly with a per-end-user token, no workflow needed. No published prices and no self-serve plan.\n\n**Windmill API + MCP.** Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off.\n\n## Before you call either\n\n### Tray.ai API + MCP\n\n1. Use a user token when acting for a customer and the master token only for admin work\n2. Parse the body of call-connector responses for upstream status codes before treating a 200 as success\n3. Point Headless MCP at the workspace's region, api.eu1.tray.io or api.ap1.tray.io outside the US\n4. Pick the workspace at OAuth sign-in. Headless MCP binds it to the session and takes no workspace ID\n5. Ask before any Headless MCP delete. The server won't\n\n### Windmill API + MCP\n\n1. Give the agent a token scoped to `jobs:run` on one folder rather than a full user token\n2. Connect over the OAuth gateway or send the token in a header so it stays out of logs\n3. With a multi-workspace token, pass `workspace_id` on every workspace tool\n4. Call `searchDocs` before guessing at a flag or config key, then `readDocsPage` with the returned URL\n5. Poll the job by ID after `runScriptByPath` for long jobs instead of waiting on the call\n\n## Other comparisons with Tray.ai API + MCP or Windmill API + MCP\n\n- [Activepieces API + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-tray.md)\n- [Activepieces API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-windmill.md)\n- [Make API + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/make-vs-tray.md)\n- [Make API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/make-vs-windmill.md)\n- [n8n API + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/n8n-vs-tray.md)\n- [n8n API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/n8n-vs-windmill.md)\n- [Pipedream API + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/pipedream-vs-tray.md)\n- [Pipedream API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/pipedream-vs-windmill.md)\n- [Tray.ai API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/tray-vs-workato.md)\n- [Windmill API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/windmill-vs-workato.md)\n- [Paragon ActionKit + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/paragon-vs-tray.md)\n- [Paragon ActionKit + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/paragon-vs-windmill.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Tray.ai API + MCP vs Windmill API + MCP",
        "url": ""
      }
    ],
    "description": "Windmill API + MCP has a score of 56.1 (C) against Tray.ai API + MCP's 55.6 (C). Both do automation workflows. The largest gap is agent ergonomics, 40 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Tray.ai API + MCP C 55.6",
      "Windmill API + MCP C 56.1",
      "scores"
    ],
    "h1": "Tray.ai API + MCP vs Windmill API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-tray-vs-windmill.png",
    "path": "/compare/tray-vs-windmill",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Tray.ai API + MCP vs Windmill API + MCP for AI agents",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/tray-vs-windmill"
  },
  "tokens": {
    "markdown": 1500,
    "slim": 330
  },
  "version": 1
}
