{
  "data": {
    "a": {
      "slug": "windmill",
      "name": "Windmill API + MCP",
      "vendor": "Windmill Labs",
      "vendorUrl": "https://www.windmill.dev",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Code-first engine for scripts, flows and internal apps in 20+ languages, written in Rust, on Windmill Cloud or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/windmill",
      "markdownUrl": "https://www.anchorterminal.com/tools/windmill.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/windmill.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/windmill.json",
      "repo": "https://github.com/windmill-labs/windmill",
      "license": "AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://app.windmill.dev/api",
      "packages": [
        {
          "registry": "npm",
          "name": "windmill-client"
        },
        {
          "registry": "pypi",
          "name": "wmill"
        }
      ],
      "auth": "mixed",
      "authNotes": "Bearer user tokens with optional scopes (`{domain}:{action}[:{path}]`, e.g. `jobs:run:flows`) and expiry. MCP by OAuth at /api/mcp/gateway, or a token either in the URL (`?token=`) or in an Authorization header. Admins can make the MCP endpoints refuse tokens in URLs.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosted Community Edition is free with unlimited executions (up to 50 users, 3 workspaces). Self-hosted Enterprise from $120 a month, priced as developer seats $20 a month, operators $10 and compute at $50 a month per standard 2 GB worker. Pro gets the same terms for companies under 10 staff and $250,000 revenue. Cloud has a free tier and paid Team and Enterprise workspaces billed on seats and compute (https://www.windmill.dev/pricing).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 18070,
        "npmWeekly": 126287,
        "pypiWeekly": 218343,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.windmill.dev/docs",
      "llmsTxt": "https://www.windmill.dev/llms.txt",
      "openapi": "https://app.windmill.dev/api/openapi.yaml",
      "capabilities": [
        "automation.workflows",
        "automation.code",
        "automation.webhooks",
        "automation.embedded",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "local",
        "freemium",
        "mcp",
        "llms-txt",
        "openapi",
        "python",
        "typescript",
        "webhooks",
        "enterprise"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.1,
        "grade": "C",
        "agentReady": false,
        "rank": 306,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 87,
          "payments": 35,
          "reliability": 40,
          "schema": 79,
          "security": 60,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "CVE-2026-23696, SQL injection in folder ownership management for any low-privilege user in Windmill 1.276.0 to 1.603.2, CVSS 4.0 score 9.4, exposing JWT secrets and admin identifiers. Fixed in 1.603.3 and published by NVD on 7 April 2026 (https://github.com/advisories/GHSA-34m2-qrpf-6v7q).",
          "GHSA-24fr-44f8-fqwg, published 2 March 2026, high. SUPERADMIN_SECRET could be read publicly through RCE on versions before 1.603.3. CVE-2026-22683, missing authorisation in 1.56.0 to 1.614.0, rated high on 7 April 2026. All fixed, so the deduction is reduced (https://github.com/windmill-labs/windmill/security/advisories, https://github.com/advisories?query=windmill)."
        ],
        "verdict": "Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off.",
        "strengths": [
          "Token scopes down to a single script path, with expiry",
          "OpenAPI 3.0.3 with 913 operations and Apache-2.0 clients for TypeScript, Python, Go and Rust",
          "Every script and flow is an MCP tool, filterable by folder and favourites",
          "97 tagged releases in 90 days, latest v1.821.0 on 1 October 2026",
          "Free unlimited executions on Cloud free workspaces and self-hosted Community Edition"
        ],
        "weaknesses": [
          "The default MCP URL puts the token in `?token=` unless a superadmin turns that off",
          "CVE-2026-23696, a critical SQL injection fixed in 1.603.3, had no Windmill advisory",
          "No published API rate limits, 429 guidance or uptime SLA",
          "The OpenAPI file documents errors for only about 30 operations",
          "No SECURITY.md or security.txt"
        ],
        "agentNotes": [
          "Give the agent a token scoped to `jobs:run` on one folder rather than a full user token",
          "Connect over the OAuth gateway or send the token in a header so it stays out of logs",
          "With a multi-workspace token, pass `workspace_id` on every workspace tool",
          "Call `searchDocs` before guessing at a flag or config key, then `readDocsPage` with the returned URL",
          "Poll the job by ID after `runScriptByPath` for long jobs instead of waiting on the call"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.1
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 87,
          "payments": 35,
          "reliability": 40,
          "schema": 79,
          "security": 60,
          "transparency": 51
        },
        "provenanceScore": 82
      },
      "connect": {
        "http": "curl \"https://app.windmill.dev/api/w/$WM_WORKSPACE/scripts/list\" -H \"Authorization: Bearer $WM_TOKEN\"",
        "claudeCode": "claude mcp add --transport http windmill https://app.windmill.dev/api/mcp/gateway",
        "config": {
          "mcpServers": {
            "windmill": {
              "headers": {
                "Authorization": "Bearer ${WM_TOKEN}"
              },
              "url": "https://app.windmill.dev/api/mcp/w/${WM_WORKSPACE}/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/windmill"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Developer seat (Enterprise)",
          "unit": "seat-month",
          "usd": 20
        },
        {
          "item": "Operator seat (Enterprise)",
          "unit": "seat-month",
          "usd": 10,
          "note": "run-only users and external JWT users"
        },
        {
          "item": "Compute (Enterprise)",
          "unit": "compute-unit",
          "usd": 25,
          "note": "$50 a month per standard 2 GB worker, which is 2 CU"
        },
        {
          "item": "Enterprise minimum",
          "unit": "month",
          "usd": 120,
          "note": "from price shown on the pricing page"
        }
      ],
      "provenance": {
        "legalEntity": "Windmill Labs, Inc.",
        "domain": "windmill.dev",
        "domainRegistered": "2022-01-06",
        "endpointOnVendorDomain": true,
        "terms": "https://www.windmill.dev/terms",
        "privacy": "https://www.windmill.dev/privacy_policy",
        "statusPage": "https://status.windmill.dev",
        "changelog": "https://www.windmill.dev/changelog",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "status.windmill.dev redirects to an UptimeRobot page."
        ],
        "score": 82
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/windmill.json",
      "live": {
        "slug": "windmill",
        "probe": {
          "target": "https://app.windmill.dev/api",
          "method": "get",
          "lastAt": "2026-10-05T01:43:48.339922231Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 201,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 193,
          "p95ms24h": 270,
          "samples24h": 272,
          "samples30d": 1122,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.windmill.dev",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:34.344290717Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "windmill-labs/windmill",
            "version": "v1.823.0",
            "released": "2026-10-04",
            "seenAt": "2026-10-04T16:44:06.725357613Z"
          },
          {
            "registry": "npm",
            "name": "windmill-client",
            "version": "1.823.0",
            "seenAt": "2026-10-04T16:44:05.723408816Z"
          },
          {
            "registry": "pypi",
            "name": "wmill",
            "version": "1.823.0",
            "released": "2026-10-04",
            "seenAt": "2026-10-04T16:44:06.517494992Z"
          }
        ],
        "githubStars": 18100,
        "npmWeekly": 115148,
        "pypiWeekly": 202114,
        "securityTxt": {
          "url": "https://windmill.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:56.890039603Z"
        },
        "llmsTxt": {
          "url": "https://www.windmill.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:21.79889133Z"
        },
        "domain": {
          "domain": "windmill.dev",
          "registered": "2022-01-06",
          "source": "https://pubapi.registry.google/rdap/domain/windmill.dev",
          "checkedAt": "2026-10-04T13:08:55.755645623Z"
        },
        "pages": [
          {
            "url": "https://www.windmill.dev/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:52:54.602469194Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d84df043288b"
          },
          {
            "url": "https://www.windmill.dev/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:52:56.757806304Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "afa04f8b73f5"
          },
          {
            "url": "https://www.windmill.dev/privacy_policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:52:58.695821422Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d11624ab86ec"
          },
          {
            "url": "https://www.windmill.dev/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:53:00.660836822Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e3b0c44298fc"
          }
        ],
        "updatedAt": "2026-10-05T01:43:48.339922231Z"
      }
    },
    "b": {
      "slug": "workato",
      "name": "Workato API + MCP",
      "vendor": "Workato",
      "vendorUrl": "https://www.workato.com",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Enterprise integration platform for building automated workflows.",
      "url": "https://www.anchorterminal.com/tools/workato",
      "markdownUrl": "https://www.anchorterminal.com/tools/workato.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/workato.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/workato.json",
      "license": "proprietary",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://www.workato.com/api",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Developer API takes an API client token as 'Authorization: Bearer', scoped by a client role and project scopes. Legacy full-access keys (x-user-token header) were rejected from 2025-07-14. The AIRO MCP server takes OAuth 2.0 in interactive clients or the same API token as a bearer header. Tool MCP servers use Workato Identity (OAuth2 SSO) or a token, and verified user access makes each end user connect their own app accounts.",
      "pricing": "freemium",
      "pricingNotes": "Usage is billed in Workato credits, one balance shared by recipe tasks (each action step), API calls, rows, pages and Genie actions. Workato Free is a one-time grant of 50,000 credits. Workato Pro is self-serve by card at $75 a month for 2,500 credits, $100 for 3,500, $275 for 10,000, $780 for 30,000 and $1,275 for 50,000, with no rollover. Enterprise is quoted by sales and the public pricing page lists no prices. Tools invoked over MCP bill as tasks (https://docs.workato.com/en/pricing/self-service/self-service.html).",
      "priceSummary": "$75 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in Workato docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.workato.com/en/workato-api.html",
      "llmsTxt": "https://docs.workato.com/llms.txt",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.embedded",
        "automation.code",
        "automation.webhooks",
        "automation.auth",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "freemium",
        "mcp",
        "llms-txt",
        "enterprise",
        "closed-source",
        "webhooks"
      ],
      "lastRelease": "2026-09-09",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.3,
        "grade": "C",
        "agentReady": false,
        "rank": 282,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 51,
          "maintenance": 60,
          "payments": 35,
          "reliability": 58,
          "schema": 63,
          "security": 70,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "API client tokens scoped by role and project, with legacy full-access keys removed on 14 October 2025. No OpenAPI file and no official SDK on npm or PyPI.",
        "strengths": [
          "API client tokens scoped by role and project, with legacy full-access keys removed on 14 October 2025",
          "Verified user access runs MCP tools with each end user's own app credentials",
          "MCP actions tagged \"(via AIRO)\" in the audit log, and tool-level RBAC since 5 September 2026",
          "Per-endpoint rate limits and specific error messages in the API reference",
          "Workato Free gives 50,000 credits once with no card"
        ],
        "weaknesses": [
          "No OpenAPI file and no official SDK on npm or PyPI",
          "15 status incidents since 1 July 2026, including about 53 hours of degraded FileStorage and API Platform in September",
          "Base URL changes per data centre, ten hosts in all",
          "The Developer API manages recipes and jobs. App actions come from recipes or MCP tools you publish",
          "Trust centre needs JavaScript and the public security overview dates from January 2025"
        ],
        "agentNotes": [
          "Use the base URL for the workspace's data centre, and app.trial.workato.com for Free or Pro",
          "Give the agent an API client whose role lists only the endpoints it needs. The MCP server exposes those as tools",
          "Repeat or cancel at most 25 jobs per call and no more than one call a second",
          "Send an `x-correlation-id` on each call so failures can be traced in support tickets",
          "Every action step in a recipe is a task, so collapse loops before running at volume"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.3
          }
        ],
        "editorialScores": {
          "ergonomics": 51,
          "maintenance": 60,
          "payments": 35,
          "reliability": 58,
          "schema": 63,
          "security": 70,
          "transparency": 53
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl https://www.workato.com/api/users/me -H \"Authorization: Bearer $WORKATO_API_TOKEN\"",
        "claudeCode": "claude mcp add --transport http workato-airo https://app.workato.com/airo_mcp --header \"Authorization: Bearer ${WORKATO_API_TOKEN}\"",
        "config": {
          "mcpServers": {
            "workato": {
              "headers": {
                "Authorization": "Bearer ${WORKATO_API_TOKEN}"
              },
              "url": "https://app.workato.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/workato"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Workato Pro, 2,500 credits",
          "unit": "month",
          "usd": 75,
          "note": "credits cover tasks, API calls, rows and Genie actions, no rollover"
        },
        {
          "item": "Workato Pro, 10,000 credits",
          "unit": "month",
          "usd": 275
        },
        {
          "item": "Workato Pro, 50,000 credits",
          "unit": "month",
          "usd": 1275
        }
      ],
      "provenance": {
        "legalEntity": "Workato, Inc.",
        "domain": "workato.com",
        "domainRegistered": "2013-10-16",
        "endpointOnVendorDomain": true,
        "terms": "https://www.workato.com/legal/terms-of-service",
        "privacy": "https://www.workato.com/legal/privacy-policy",
        "statusPage": "https://status.workato.com",
        "changelog": "https://www.workato.com/product-hub/changelog/",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/workato.json",
      "live": {
        "slug": "workato",
        "probe": {
          "target": "https://www.workato.com/api",
          "method": "get",
          "lastAt": "2026-10-05T01:43:48.374513245Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 294,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 289,
          "p95ms24h": 346,
          "samples24h": 272,
          "samples30d": 1122,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.workato.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T01:46:49.575557395Z"
        },
        "securityTxt": {
          "url": "https://workato.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:49.152361528Z"
        },
        "llmsTxt": {
          "url": "https://docs.workato.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:22.263635257Z"
        },
        "domain": {
          "domain": "workato.com",
          "registered": "2013-10-16",
          "source": "https://rdap.verisign.com/com/v1/domain/workato.com",
          "checkedAt": "2026-10-04T13:04:44.120331178Z"
        },
        "pages": [
          {
            "url": "https://www.workato.com/product-hub/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:53:00.60809521Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a4683b4aa9be"
          },
          {
            "url": "https://docs.workato.com/en/workato-api.html",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-04T15:44:19.326387583Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "949db37e2d76"
          },
          {
            "url": "https://docs.workato.com/en/pricing/self-service/self-service.html",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:44:17.233211449Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "aaa7aa2e2d11"
          },
          {
            "url": "https://www.workato.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:56.201708986Z",
            "changedAt": "2026-10-03T15:40:46.071201667Z",
            "fingerprint": "b16fc348911e"
          },
          {
            "url": "https://www.workato.com/legal/terms-of-service",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:58.214869216Z",
            "changedAt": "2026-10-03T15:40:48.841630047Z",
            "fingerprint": "1ed57a9371b8"
          }
        ],
        "updatedAt": "2026-10-05T01:46:49.575557395Z"
      }
    },
    "summary": "Workato API + MCP has a score of 58.3 (C) against Windmill API + MCP's 56.1 (C). Both do automation workflows. The largest gap is maintenance \u0026 community, 27 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/windmill-vs-workato",
    "json": "https://www.anchorterminal.com/compare/windmill-vs-workato.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/windmill-vs-workato.md",
    "slim": "https://www.anchorterminal.com/compare/windmill-vs-workato.min.md"
  },
  "markdown": "Workato API + MCP has a score of 58.3 (C) against Windmill API + MCP's 56.1 (C). Both do automation workflows. The largest gap is maintenance \u0026 community, 27 points.\n\n- Windmill API + MCP: grade C, 56.1/100, rank #306 of 452. Markdown https://www.anchorterminal.com/tools/windmill.md · JSON https://www.anchorterminal.com/api/v1/tools/windmill.json\n- Workato API + MCP: grade C, 58.3/100, rank #282 of 452. Markdown https://www.anchorterminal.com/tools/workato.md · JSON https://www.anchorterminal.com/api/v1/tools/workato.json\n\n## Which one, for what\n\nPick Windmill API + MCP for schema \u0026 documentation (+16), agent ergonomics (+22), maintenance \u0026 community (+27).\n\nPick Workato API + MCP for reliability (+18), security \u0026 auth (+10), transparency \u0026 trust (+5).\n\n## Score by category\n\n| Category | Weight | Windmill API + MCP | Workato API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 40 | 58 | Workato API + MCP +18 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 79 | 63 | Windmill API + MCP +16 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 51 | Windmill API + MCP +22 |\n| Security \u0026 auth | 14% (17.5 this run) | 60 | 70 | Workato API + MCP +10 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 35 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 87 | 60 | Windmill API + MCP +27 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 67 | 72 | Workato API + MCP +5 |\n| Negative events | ≤15 | -5 | 0 | |\n| **Total** | | **56.1 · C** | **58.3 · C** | |\n\n## Facts side by side\n\n| Fact | Windmill API + MCP | Workato API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Windmill Labs | Workato |\n| Hosted endpoint | `https://app.windmill.dev/api` | `https://www.workato.com/api` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts | proprietary |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-10-01 | 2026-09-09 |\n| Popularity | 18k stars, 126k npm/wk, 218k PyPI/wk | none |\n| Agent reviews | 3/5 (2) | 3.5/5 (2) |\n\n## Verdicts\n\n**Windmill API + MCP.** Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off.\n\n**Workato API + MCP.** API client tokens scoped by role and project, with legacy full-access keys removed on 14 October 2025. No OpenAPI file and no official SDK on npm or PyPI.\n\n## Before you call either\n\n### Windmill API + MCP\n\n1. Give the agent a token scoped to `jobs:run` on one folder rather than a full user token\n2. Connect over the OAuth gateway or send the token in a header so it stays out of logs\n3. With a multi-workspace token, pass `workspace_id` on every workspace tool\n4. Call `searchDocs` before guessing at a flag or config key, then `readDocsPage` with the returned URL\n5. Poll the job by ID after `runScriptByPath` for long jobs instead of waiting on the call\n\n### Workato API + MCP\n\n1. Use the base URL for the workspace's data centre, and app.trial.workato.com for Free or Pro\n2. Give the agent an API client whose role lists only the endpoints it needs. The MCP server exposes those as tools\n3. Repeat or cancel at most 25 jobs per call and no more than one call a second\n4. Send an `x-correlation-id` on each call so failures can be traced in support tickets\n5. Every action step in a recipe is a task, so collapse loops before running at volume\n\n## Other comparisons with Windmill API + MCP or Workato API + MCP\n\n- [Activepieces API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-windmill.md)\n- [Activepieces API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-workato.md)\n- [Make API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/make-vs-windmill.md)\n- [Make API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/make-vs-workato.md)\n- [n8n API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/n8n-vs-windmill.md)\n- [n8n API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/n8n-vs-workato.md)\n- [Pipedream API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/pipedream-vs-windmill.md)\n- [Pipedream API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/pipedream-vs-workato.md)\n- [Tray.ai API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/tray-vs-windmill.md)\n- [Tray.ai API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/tray-vs-workato.md)\n- [Paragon ActionKit + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/paragon-vs-windmill.md)\n- [Paragon ActionKit + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/paragon-vs-workato.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Windmill API + MCP vs Workato API + MCP",
        "url": ""
      }
    ],
    "description": "Workato API + MCP has a score of 58.3 (C) against Windmill API + MCP's 56.1 (C). Both do automation workflows. The largest gap is maintenance \u0026 community, 27 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Windmill API + MCP C 56.1",
      "Workato API + MCP C 58.3",
      "scores"
    ],
    "h1": "Windmill API + MCP vs Workato API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-windmill-vs-workato.png",
    "path": "/compare/windmill-vs-workato",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Windmill API + MCP vs Workato API + MCP for AI agents",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/windmill-vs-workato"
  },
  "tokens": {
    "markdown": 1500,
    "slim": 380
  },
  "version": 1
}
