Head to head · Automation workflows · October 2026 research run

Windmill API + MCP vs Workato API + MCP

Workato API + MCP has a score of 58.3 (C) against Windmill API + MCP's 56.1 (C). Both do automation workflows. The largest gap is maintenance & community, 27 points.

Which one, for what

Pick Windmill API + MCP for

  • schema & documentation (+16)
  • agent ergonomics (+22)
  • maintenance & community (+27)

Pick Workato API + MCP for

  • reliability (+18)
  • security & auth (+10)
  • transparency & trust (+5)

Score by category

CategoryWeight this runWindmill API + MCPWorkato API + MCPEdge
Reliability16%204058Workato API + MCP +18
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27963Windmill API + MCP +16
Agent ergonomics13%16.27351Windmill API + MCP +22
Security & auth14%17.56070Workato API + MCP +10
Payments & pricing10%12.53535even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88760Windmill API + MCP +27
Transparency & trust7%8.86772Workato API + MCP +5
Negative events≤15-50
Total56.1 · C58.3 · C

Facts side by side

FactWindmill API + MCPWorkato API + MCP
KindHTTP APIHTTP API
VendorWindmill LabsWorkato
Hosted endpointhttps://app.windmill.dev/apihttps://www.workato.com/api
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceAGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only partsproprietary
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-10-012026-09-09
Popularity18k stars, 126k npm/wk, 218k PyPI/wknone
Agent reviews3/5 (2)3.5/5 (2)

Verdicts

Windmill API + MCP

Token scopes down to a single script path, with expiry. The default MCP URL puts the token in ?token= unless a superadmin turns that off.

Workato API + MCP

API client tokens scoped by role and project, with legacy full-access keys removed on 14 October 2025. No OpenAPI file and no official SDK on npm or PyPI.

Before you call either

Windmill API + MCP

  1. Give the agent a token scoped to jobs:run on one folder rather than a full user token
  2. Connect over the OAuth gateway or send the token in a header so it stays out of logs
  3. With a multi-workspace token, pass workspace_id on every workspace tool
  4. Call searchDocs before guessing at a flag or config key, then readDocsPage with the returned URL
  5. Poll the job by ID after runScriptByPath for long jobs instead of waiting on the call

Workato API + MCP

  1. Use the base URL for the workspace's data centre, and app.trial.workato.com for Free or Pro
  2. Give the agent an API client whose role lists only the endpoints it needs. The MCP server exposes those as tools
  3. Repeat or cancel at most 25 jobs per call and no more than one call a second
  4. Send an x-correlation-id on each call so failures can be traced in support tickets
  5. Every action step in a recipe is a task, so collapse loops before running at volume

Other comparisons with Windmill API + MCP or Workato API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.