# Gumloop > Gumloop is a hosted platform from AgentHub Inc. for building AI agents that work across company apps and run on schedules, webhooks and app events. It has a REST API, a Python SDK, a CLI and a hosted MCP server. - Canonical: https://www.anchorterminal.com/tools/gumloop - Markdown: https://www.anchorterminal.com/tools/gumloop.md (~8,150 tokens) - Slim: https://www.anchorterminal.com/tools/gumloop.min.md (~2,080 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/gumloop.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade C · 61.6/100 · rank #419 of 842 · #4 in Workflow automation · not agent-ready · confidence medium** ## Assessment Gumloop's REST API has a public OpenAPI file with 105 operations, Markdown docs and a changelog with 28 dated releases since 9 July 2026. API keys need the $37 Pro plan, the trial needs a card, the key can travel in the URL, and self-serve content may be used to train Gumloop's models. ## Facts | Field | Value | | --- | --- | | Vendor | AgentHub Inc. (https://www.gumloop.com) | | Kind | HTTP API | | Category | Workflow automation (https://www.anchorterminal.com/categories/workflow-automation) | | Transport | HTTP, Streamable HTTP | | Endpoint | `https://api.gumloop.com/api/v1` | | Auth | OAuth or key · Self-serve API key on the Pro plan or above, created on the Connectors page in the app and sent as a bearer token. A personal key carries its owner's identity and also needs the `x-auth-key` header with the user ID. A team key can run as any team member named in `user_id`. OAuth 2.0 (authorisation code with PKCE, refresh tokens, revocation) is for apps other users sign in to, and client registration is by email to support. The key is also accepted as an `api_key` query parameter. Webhook triggers take no credential beyond the secret in their URL. | | Pricing | Paid ($37 / mo) · Pro is $37 a month with 20,000 credits, unlimited seats and API keys. No free plan is listed. The 14-day Pro trial needs a card and converts to a paid plan unless cancelled, so an agent cannot start without a person and a card. Usage is billed in credits at $0.005 each, with overage capped at 1,000,000 credits a period on Pro. Enterprise is priced through sales (https://www.gumloop.com/pricing, https://docs.gumloop.com/core-concepts/credits.md, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the docs index, the OpenAPI file or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under Gumloop's terms of service. The Python SDK and CLI repository and the npm package are Apache-2.0 | | Packages | pypi: `gumloop`; npm: `gumloop` | | Source | https://github.com/gumloop/gumloop-py | | Docs | https://docs.gumloop.com/api-reference/getting-started | | llms.txt | https://docs.gumloop.com/llms.txt | | Last release | 2026-10-08 | | npm downloads / week | 188 | | PyPI downloads / week | 2,865 | | Surface graded | The public REST API at https://api.gumloop.com/api/v1. The hosted MCP server, the CLI and the Python SDK call the same service and are described here but not graded apart | | API | OpenAPI 3.0.0 `Public API` 1.0.0 at https://docs.gumloop.com/api-reference/openapi.yaml, 105 operations on 83 paths. Agents, sessions, triggers, skills, artifacts, MCP servers, Company Brain, evaluations, models, chat completions, organisation administration and seven legacy flow endpoints such as `/start_pipeline` | | Auth | Personal or team API key as a bearer token (a personal key also needs `x-auth-key` with the user ID), or an OAuth 2.0 access token from the authorisation code grant with PKCE. Scopes are `gumloop_api` and `userinfo`. Keys and the `gumloop_api` scope need Pro or above | | MCP server | https://mcp.gumloop.com/gumloop/mcp, Streamable HTTP with OAuth sign-in, 46 tools for agents, sessions, skills, artifacts, connected apps, Brain search, flows, organisation and docs search | | Webhook triggers | `POST https://api.gumloop.com/trigger_incoming_webhook//` with no other credential. 200 with `{"success": true}` on acceptance, 404 for an unknown or disabled trigger or a wrong secret, 100 requests a minute per trigger with `Retry-After` on 429 | | Sessions | `POST /agents/{agent_id}/sessions` returns 202 with the session `processing` or `queued`, or 201 for an idle session. States include `approval_required`. Streaming is Server-Sent Events on `ws.gumloop.com` | | Pagination | `page_size` and `cursor` with `next_cursor` on 13 list operations, plus `search`, `team_id`, `status` and `sort_order` filters | | Errors | 401 documented on 103 operations, 403 on 99, 404 on 77, 400 on 63, 409 on 16 and 429 on 5. No shared error schema in the OpenAPI file. MCP tool calls return a per-result `status` and an `error` with `code`, `message` and `type` | | Rate limits | Concurrency, not request rate. 25 concurrent agent interactions on Pro and 100 on Enterprise, across the organisation. At the limit Pro gets HTTP 429 with `gummie_rate_limit` and Enterprise requests are queued with a `queue_position` | | Approvals | Per connector, Always allow (the default), Ask each time, Ask for writes/deletes, Never allow or Custom per tool, plus App Rules written as CEL conditions. `POST /sessions/{session_id}/approvals` resolves a pending ask | | SDKs | Python `gumloop` 0.5.5 (8 October 2026, Apache-2.0, Python 3.10 or later). JavaScript `gumloop` 1.0.2 (30 December 2024), flows only. CLI installed by a shell script from gumloop.com | | Billing | Credits at $0.005 each. A run is model cost at list price, 1 credit per successful connector call plus any tool charge, 5 credits per session-minute of compute, and an 8 per cent orchestration fee (16 per cent with your own model key). Failed connector calls are not charged | | Releases | Numbered releases on https://www.gumloop.com/changelog, 12.1.0 on 7 October 2026. 3 in October, 9 in September, 9 in August and 11 in July 2026 | | Compliance | The security page claims SOC 2 Type II attestation, HIPAA compliance with BAAs on eligible plans, and certification under the EU-U.S. Data Privacy Framework. DPAs are on request for Enterprise. The trust centre at trust.gumloop.com is drawn by script and was not read | | Capabilities | automation.workflows, automation.apps, automation.webhooks, agent.tools | | Tags | hosted, paid, openapi, llms-txt, mcp, oauth, python, cli, webhooks, agents, approvals, soc2, enterprise | | JSON | https://www.anchorterminal.com/api/v1/tools/gumloop.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 82 | 16.4 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 83 | 13.5 | | Agent ergonomics | 13% | 16.2 | 66 | 10.7 | | Security & auth | 14% | 17.5 | 50 | 8.8 | | Payments & pricing | 10% | 12.5 | 20 | 2.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 77 | 6.7 | | Transparency & trust (editorial 41, provenance 72) | 7% | 8.8 | 57 | 5.0 | | Negative events | up to −15 | up to −15 | 2026-10-08. The API getting-started page says the Python and JavaScript SDKs 'wrap all of it'. The JavaScript SDK page documents only `runFlow`, and the npm package `gumloop` is 1.0.2 from 30 December 2024 (https://docs.gumloop.com/api-reference/getting-started.md, https://registry.npmjs.org/gumloop). 2 points for a misleading claim. | -2 | | **Total** | | | | **61.6 → C** | ### Why each score - Reliability 82: Graded as a hosted service on the REST API. Status page on incident.io with Platform and API components and a history view (20). The history shows no incident reported for July, August, September or October 2026 (30). Limits are published as concurrency, 25 agent interactions on Pro and 100 on Enterprise, and 100 requests a minute per webhook trigger. No per-request limit for the API was found (12). On Pro a request over the limit gets HTTP 429 with `gummie_rate_limit`, webhook 429s carry `Retry-After`, and a caller-supplied `session_id` returns 409 on a repeat. No backoff guidance for the API was found (10). No SLA found on the pricing page, the terms or the docs (0). The API is not marked beta or preview (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 83: Public OpenAPI 3.0.0 file with 105 operations on 83 paths (25). `llms.txt`, `llms-full.txt` and a Markdown copy of every docs page (10). 98 of 105 operations carry a description, and many say what is idempotent, what merges and what replaces (16). Typed parameters with 80 enums, but only 27 named schemas and free-form `metadata` objects on agents (10). cURL and Python samples and status codes on most operations, with no shared error schema (11). The path is versioned at `/api/v1` and the product changelog is public and dated, but the file's version stays at 1.0.0 and there is no changelog for the API alone (11). - Agent ergonomics 66: List operations take `page_size`, and a session read returns its whole message list. The MCP server has 46 tools, with no toolsets found (15). Cursor pagination on 13 operations with search, team, status and sort filters (18). Named error codes such as `gummie_rate_limit` and `trigger_type_not_editable`, and MCP calls return a per-result `code`, `message` and `type`, but the API has no single error format (13). A caller-supplied `session_id`, idempotent attach and detach calls and an agent `version` check on update. No idempotency key, and no MCP tool annotations found in the docs (12). The Python SDK and CLI are current. The npm package dates from 30 December 2024 and runs flows only (8). - Security & auth 50: Personal and team API keys, and OAuth 2.0 with PKCE, refresh tokens and a revoke endpoint, where the one API scope, `gumloop_api`, grants the whole developer API. Key rotation was not found in the pages read (20). Less 10 because the docs name the `api_key` query parameter the default method, and a webhook trigger's secret sits in its URL (10). Approval modes per connector and per tool, CEL app rules and an approvals endpoint, with Always allow as the default and no read-only API key (15). Agents read third-party content through connectors and a browser, and no prompt-injection guidance was found in the pages read (3). Audit logs through `GET /get_audit_logs` and connector activity logs, with retention set by the Enterprise agreement (12). The security page claims SOC 2 Type II and HIPAA. No security.txt, no bug bounty found, and the trust centre was not read (10). - Payments & pricing 20: No x402, MPP or L402 (0). Per-unit prices are public without a login, $0.005 a credit, 5 credits a session-minute, 1 credit a connector call and an 8 per cent orchestration fee (20). No free plan is listed and the 14-day trial needs a card (0). A person signs up in a browser, adds a card and creates the key in the app (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 77: Release 12.1.0 is dated 7 October 2026 and the Python SDK 0.5.5 was published on 8 October (30). 28 dated changelog releases between 9 July and 7 October 2026 (20). Public changelog, a forum, a help centre and support by email and ticket form. We did not test a support channel (10). The Python SDK is current but the npm package has had no release since 30 December 2024, and no entry was found in the official MCP registry (10). The SDK repository runs ruff, pyright and pytest in CI and locks dependencies. It has no changelog file (7). - Transparency & trust 57: Closed service under published terms with AgentHub Inc., and the SDK is Apache-2.0 (15). The privacy policy and terms agree that self-serve content may be used to train Gumloop's models and Enterprise content is not. Retention is 'as long as is necessary' with no periods, and DPAs are for Enterprise on request (14). Flows are labelled Legacy on the pricing page and the SDK's flows client raises a deprecation warning, with no dated policy or end date found (6). The privacy policy says data is processed in the United States. No subprocessor list was read, because the trust centre is drawn by script (6). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/gumloop.md (JSON https://www.anchorterminal.com/fixes/gumloop.json) ### What we couldn't check - unchecked: the trust centre at trust.gumloop.com is drawn by script, so certifications, the subprocessor list and any disclosure contact there were not read - unchecked: the MCP server's tool definitions and annotations, which are only visible after signing in. The count of 46 is the docs' figure - unchecked: GitHub stars, open issues and how quickly issues are answered on gumloop/gumloop-py - unchecked: the pricing page's FAQ answers, which the page did not show our reader - The terms of service forbid access by any robot, spider or other automatic device. We read the public site pages that robots.txt allows before reaching that clause, and read nothing further on www.gumloop.com after it - The terms give the date as 11/06/2026, which we read as 11 June 2026 - Whether API keys can be rotated or limited in scope was not found in the pages read - No free plan appears on the pricing page, though the privacy policy mentions free accounts ### Sources - docs index for agents: (seen 2026-10-08) - OpenAPI file: (seen 2026-10-08) - API getting started, webhooks and key in URL: (seen 2026-10-08) - authentication and key types: (seen 2026-10-08) - OAuth 2.0 and scopes: (seen 2026-10-08) - rate limits: (seen 2026-10-08) - credits, plans and trial: (seen 2026-10-08) - trial needs a card: (seen 2026-10-08) - create session reference: (seen 2026-10-08) - MCP server overview: (seen 2026-10-08) - MCP and REST coverage: (seen 2026-10-08) - approval settings: (seen 2026-10-08) - audit logging: (seen 2026-10-08) - Python SDK docs: (seen 2026-10-08) - JavaScript SDK docs: (seen 2026-10-08) - CLI overview: (seen 2026-10-08) - pricing: (seen 2026-10-08) - changelog: (seen 2026-10-08) - security page: (seen 2026-10-08) - terms of service: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - site llms.txt: (seen 2026-10-08) - status page history: (seen 2026-10-08) - PyPI package: (seen 2026-10-08) - npm package: (seen 2026-10-08) - Python SDK repository: (seen 2026-10-08) - domain registration: (seen 2026-10-08) ## Who's behind it (provenance 72/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | AgentHub Inc. (doing business as Gumloop) | 20/20 | | Domain age | gumloop.com, registered 2024-04-25 (2 years) | 7/15 | | Endpoint on the vendor's domain | api.gumloop.com | 15/15 | | Terms of service | read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points | 2.3/10 | | Privacy policy | read, states 7 of the 8 things a reader expects, and has 1 clause that costs points | 7.3/10 | | Status page | status.gumloop.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The terms of service (last updated 11/06/2026, read as 11 June 2026) and the privacy policy (effective the same date) both name AgentHub Inc. (doing business as Gumloop). The terms are governed by Delaware law. No postal address was found in the passages read. The terms of service are the only published agreement for self-serve customers. They open as terms for the web pages at gumloop.com and also cover subscriptions, the content licence and AI training. Enterprise customers sign a separate agreement that is not published. The API answers at api.gumloop.com, streaming at ws.gumloop.com and the MCP server at mcp.gumloop.com. https://www.gumloop.com/.well-known/security.txt returned 404 on 8 October 2026. RDAP for gumloop.com gives a registration date of 2024-04-25. status.gumloop.com is on incident.io with Platform, API and four external AI provider components. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.gumloop.com/tos), read 2026-10-08, gives no date, states 5 of the 7 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "(doing business as Gumloop) a non-exclusive, worldwide, royalty-free license to use, reproduce, and modify your Content to provide and improve the Service and, unless you use the Service on the Enterprise Tier under a signed agreement with us, to develop, train, and improve our AI models as described in our Privacy Po…" - To know. Restricts automated access (costs points). "(b) Use any robot, spider, or other automatic device, process, or means to access Service for any purpose, including monitoring or copying any of the material on Service." - To know. Says the terms or the service can change without notice (costs points). "We reserve the right to withdraw or amend our Service, and any service or material we provide via Service, in our sole discretion without notice." - To know. Says access can be ended without notice or for any reason. "We may terminate or suspend your account and bar access to Service immediately, without prior notice or liability, under our sole discretion, for any reason whatsoever and without limitation, including but not limited to a breach of Terms." - Not found in the text. Gives the date it was last updated. - Names the governing law or courts. The law of the State of Delaware. - States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence. - Says how changes to the terms are announced. Changes are posted, with no other notice named. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). The licence to use customer content for model training continues after termination for models already developed. "This license survives termination as to models already developed." - Also in the text (2026-10-08). The vendor may change subscription fees at its sole discretion at any time, with the change taking effect at the end of the current billing cycle. "AgentHub Inc. (doing business as Gumloop), in its sole discretion and at any time, may modify Subscription fees for the Subscriptions. Any Subscription fee change will become effective at the end of the then-current Billing Cycle." **Privacy policy** (https://www.gumloop.com/privacy-policy), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "Self-Serve Tier. We may use Self-Serve Tier Content to develop, train, and improve our AI models." - Not found in the text. Gives the date it was last updated. - Says how long data is kept. For as long as needed, with no period named. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. privacy@gumloop.com. - Says where data is transferred or stored. Relies on the Data Privacy Framework. - Also in the text (2026-10-08). Content from the Enterprise Tier is not used to train AI models unless the customer asks in writing. "Enterprise Tier. We do not use Content from the Enterprise Tier to train AI models unless you ask us to in writing." - Also in the text (2026-10-08). The vendor says it has agreements with OpenAI and Anthropic under which they commit not to train on data sent to them through Gumloop's API. "We have an agreement directly with OpenAI and Anthropic to ensure they’re committed to not training on any data sent to them via Gumloop’s API." - Also in the text (2026-10-08). Information may be disclosed in order to show the customer's company logo on the vendor's website. "(iv) for the purpose of including your company’s logo on our website;" ## Live (updated 2026-10-09 09:26 UTC) - Right now: up, HTTP 404, 237 ms, checked 2026-10-09 09:26 UTC (get on `https://api.gumloop.com/api/v1`) - Uptime 24h 100.0% (20 probes) · 30 days 100.0% (20 probes) · p50 184 ms · p95 201 ms - Vendor status page: none, All Systems Operational - Always current: https://www.anchorterminal.com/api/v1/live/gumloop.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Pro plan | $37 | per month (plan) | 20,000 credits a month, unlimited seats and agents, 25 concurrent agent interactions, API keys included | | Credit (overage and list price) | $0.005 | per credit | Pro overage is capped at 1,000,000 credits a billing period. Model calls bill at provider cost divided by $0.005 | | Agent compute | $1.50 | per session-hour | 5 credits per session-minute of active processing, minimum 1 credit a response, before the 8 per cent orchestration fee | | Connector tool call | $0.005 | per call | 1 credit per successful call, plus the tool's own charge for enrichment or scraping tools. Failed calls are free | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - OpenAPI 3.0 file with 105 operations on 83 paths, and every docs page served as Markdown with `llms.txt` and `llms-full.txt` - Per-unit prices are public. One credit is $0.005, compute is 5 credits a session-minute and a connector call is 1 credit - Tool approvals can be set per connector or per tool, and a paused session can be approved or rejected through `POST /sessions/{session_id}/approvals` - 28 dated changelog releases between 9 July and 7 October 2026, and the Python SDK reached 0.5.5 on 8 October 2026 - Status page on incident.io with Platform and API components and no incident reported from July to October 2026 ## Weaknesses - API keys and the `gumloop_api` OAuth scope need the Pro plan at $37 a month. The 14-day trial needs a card - The docs call the API key in the URL query string the default method, and a webhook trigger's secret is part of its URL - The privacy policy of 11 June 2026 says self-serve content, Pro and trials included, may be used to train Gumloop's AI models - The npm package `gumloop` is still 1.0.2 from 30 December 2024 and only runs legacy flows, while the docs say both SDKs wrap the whole API - No SLA and no per-request rate limit found. On Pro, a 26th concurrent run is rejected with HTTP 429 and skipped for triggers ## Before you call it (notes for agents) 1. Send the key as `Authorization: Bearer` and, for a personal key, add the `x-auth-key` header with the user ID. Do not put `api_key` in the URL 2. Create sessions with `POST /agents/{agent_id}/sessions`, then poll `GET /sessions/{session_id}`. A 202 means processing or queued, and the reply is not in the response 3. Supply your own `session_id` when creating a session. A repeat returns 409, which makes a retry safe 4. For streamed output send the same body with `stream: true` to `ws.gumloop.com`. `api.gumloop.com` answers 400 to it 5. Treat a webhook trigger URL as a password. It returns `{"success": true}` at once and never carries the agent's output ## Connect Install: ```bash uv add gumloop ``` First request: ```bash curl -X POST 'https://api.gumloop.com/api/v1/agents/abc123DEFghiJKL/sessions' -H 'Authorization: Bearer YOUR_ACCESS_TOKEN' -H 'Content-Type: application/json' -d '{"input": "Research Acme Corp and draft a brief."}' ``` MCP client configuration: ```json { "mcpServers": { "gumloop": { "args": [ "-y", "mcp-remote", "https://mcp.gumloop.com/gumloop/mcp" ], "command": "npx" } } } ``` Through letme (picks today, calling later): https://letme.dev/gumloop. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Pipedream API + MCP | B | 65.5 | 288 | automation.workflows, automation.apps, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/pipedream.md | | Kestra | B | 63.6 | 351 | automation.workflows, automation.webhooks, automation.apps, agent.tools | no | https://www.anchorterminal.com/tools/kestra.md | | Make API + MCP | C | 58.7 | 516 | automation.workflows, automation.apps, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/make.md | | Workato API + MCP | C | 58 | 533 | automation.workflows, automation.apps, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/workato.md | | Activepieces API + MCP | C | 57.5 | 545 | automation.workflows, automation.apps, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/activepieces.md | | Tray.ai API + MCP | C | 55.5 | 589 | automation.workflows, automation.apps, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/tray.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The pricing page lists one self-serve plan, Pro from $37 a month with 20,000 credits, and Enterprise. No free plan is listed, and workflows are labelled Legacy (source: ) - The 14-day Pro trial requires a card and rolls into a paid subscription unless cancelled (source: ) - API keys require the Pro plan or above, and OAuth client registration is invite-only by email to support (source: ) - The getting-started page names the API key as a URL query parameter the default method (source: ) - The privacy policy, section 21, says Self-Serve Tier content may be used to develop, train and improve Gumloop's AI models, and Enterprise content is not unless asked in writing (source: ) - The terms of service forbid using any robot, spider or other automatic device to access the Service for any purpose, while robots.txt allows the public pages and the docs describe API, CLI and MCP access for agents (source: ) - `https://www.gumloop.com/llms.txt` carries a 'When to use Gumloop' block addressed to AI models, and the CLI docs carry a prompt telling a coding agent to install the CLI. We recorded both and acted on neither (source: ) - The hosted MCP server at https://mcp.gumloop.com/gumloop/mcp lists 46 tools and does not cover evaluations, approvals, file transfer or chat completions (source: ) ## Compare - [Activepieces API + MCP vs Gumloop](https://www.anchorterminal.com/compare/activepieces-vs-gumloop.md): C 57.5 vs C 61.6 - [Gumloop vs Kestra](https://www.anchorterminal.com/compare/gumloop-vs-kestra.md): C 61.6 vs B 63.6 - [Gumloop vs Make API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-make.md): C 61.6 vs C 58.7 - [Gumloop vs n8n API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-n8n.md): C 61.6 vs D 53.1 - [Gumloop vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/gumloop-vs-paragon.md): C 61.6 vs D 47.5 - [Gumloop vs Pipedream API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-pipedream.md): C 61.6 vs B 65.5 - [Gumloop vs Microsoft Power Automate](https://www.anchorterminal.com/compare/gumloop-vs-power-automate.md): C 61.6 vs B 62 - [Gumloop vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-tray.md): C 61.6 vs C 55.5 - [Gumloop vs Windmill API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-windmill.md): C 61.6 vs C 55.9 - [Gumloop vs Workato API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-workato.md): C 61.6 vs C 58 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on gumloop.com or one of its subdomains, or the README of github.com/gumloop/gumloop-py. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "gumloop", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Gumloop on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Gumloop on Anchor Terminal](https://www.anchorterminal.com/badges/gumloop.svg)](https://www.anchorterminal.com/tools/gumloop) ``` Plain link: ```html Gumloop on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Gumloop is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/gumloop-dark.png - Light: https://www.anchorterminal.com/assets/share/gumloop-light.png