# Kestra > Kestra is an open-source workflow orchestrator from Kestra Technologies. Flows are written in YAML and run on a server the owner hosts, with a REST API, SDKs in four languages and flows exposed as MCP tools. - Canonical: https://www.anchorterminal.com/tools/kestra - Markdown: https://www.anchorterminal.com/tools/kestra.md (~6,500 tokens) - Slim: https://www.anchorterminal.com/tools/kestra.min.md (~1,930 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/kestra.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade B · 63.6/100 · rank #351 of 842 · #2 in Workflow automation · not agent-ready · confidence medium** ## Assessment Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed. ## Facts | Field | Value | | --- | --- | | Vendor | Kestra Technologies (https://kestra.io) | | Kind | HTTP API | | Category | Workflow automation (https://www.anchorterminal.com/categories/workflow-automation) | | Transport | HTTP, Streamable HTTP | | Auth | OAuth or key · The open-source edition takes HTTP Basic auth with one username and password, set in `kestra.server.basic-auth` or on the setup page at first start. That credential has full access. Bearer API tokens, service accounts, OAuth, SSO and role-based access are in the Enterprise Edition and Kestra Cloud only. Access to open source is self-serve, by running the server. Webhook triggers are called with a key in the URL path. | | Pricing | Freemium (Freemium) · The open-source edition is free under Apache-2.0 with unlimited flows and executions, and an agent can start on it with no contract or account. Enterprise Edition is an annual subscription per instance through sales, with no public price. Kestra Cloud is by access request, with 14 days free and no card, then billed on task runs and Cloud runner time at rates that are not published (https://kestra.io/pricing, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the docs, the OpenAPI spec or the pricing page (checked 2026-10-08). | | Licence | Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial | | Packages | oci: `kestra/kestra`; pypi: `kestrapy`; npm: `@kestra-io/kestra-sdk` | | Source | https://github.com/kestra-io/kestra | | Docs | https://kestra.io/docs | | llms.txt | https://kestra.io/llms.txt | | Last release | 2026-10-05 | | GitHub stars | 29,427 (as of 2026-10-08) | | npm downloads / week | 244 | | PyPI downloads / week | 170 | | Edition graded | Open-source edition 2.0.5, self-hosted. Kestra Cloud is request-access and Enterprise is sold by contract, so neither is graded here | | API | REST under `/api/v1/{tenant}/` on port 8080, OpenAPI 3.0.1 at https://kestra.io/kestra.yml with 216 operations on 194 paths. The Enterprise spec is at https://kestra.io/kestra-ee.yml | | Auth | Open source has one basic-auth username and password, required since basic auth became mandatory. API tokens, service accounts, OAuth, SSO and RBAC are Enterprise and Cloud only | | MCP | A `default` MCP server per tenant at `/api/v1/{tenant}/mcp/{id}`. A flow with `McpToolTrigger` becomes a tool, with its inputs as the JSON Schema. Basic auth on open source, API token or OAuth on Enterprise and Cloud | | Docs MCP server | https://api.kestra.io/v1/mcp, no authentication, six tools (search, task_schema, list_plugins, plugin_tasks, list_installed_versions, list_plugin_elements). It reads docs and plugin schemas and does not control an instance | | Pagination | `page` and `size` (1 to 1,000, default 10), `sort`, and `filters[field][OPERATOR]=value` on search endpoints | | Errors | application/problem+json `ProblemDetail`. 401, 403 and 500 documented on 213 operations, 409 on 23, 400 on 22 | | Rate limits | None published for the API. One 429 in the spec, on plugin install when too many jobs are pending. Flow concurrency limits are set per flow, and execution quotas are Enterprise | | SDKs | Python `kestrapy` 2.0.1 (11 September 2026), JavaScript `@kestra-io/kestra-sdk` 2.0.1, Java and Go, generated from the spec in kestra-io/client-sdk (Apache-2.0) | | Releases | 2.0 LTS (8 September 2026, supported to September 2027) and 1.3 LTS (to March 2027). Patch releases every Tuesday, feature releases about every two months. Requires Java 25, or the Docker image | | Telemetry | Anonymous usage reporting is on by default, server side and from the UI. Set `kestra.anonymous-usage-report.enabled` and `kestra.ui-anonymous-usage-report.enabled` to false to stop both | | Cloud | Managed Enterprise instances on Google Cloud in the EU or US. Access by request form, 14 days free without a card, billed on task runs and Cloud runner time with no public rates. The terms carry no SLA | | Certifications | SOC 2 Type 2 for the company and the managed service, per kestra.io/security. A self-hosted deployment is outside its scope | | Capabilities | automation.workflows, automation.code, automation.webhooks, automation.apps, agent.tools | | Tags | self-hosted, open-source, local, hosted, freemium, openapi, llms-txt, mcp, python, typescript, java, go, webhooks, enterprise, soc2 | | JSON | https://www.anchorterminal.com/api/v1/tools/kestra.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 89 | 17.8 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 82 | 13.3 | | Agent ergonomics | 13% | 16.2 | 73 | 11.9 | | Security & auth | 14% | 17.5 | 41 | 7.2 | | Payments & pricing | 10% | 12.5 | 50 | 6.2 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 93 | 8.1 | | Transparency & trust (editorial 86, provenance 51) | 7% | 8.8 | 69 | 6.0 | | Negative events | up to −15 | up to −15 | Five advisories rated critical were published on the repository in six months. GHSA-365w-2m69-mp9x (CVE-2026-34612, remote code execution through SQL injection, 30 March 2026), GHSA-5vc5-wxxq-3fjx and GHSA-2q47-568g-9h4f (CVE-2026-49869 and CVE-2026-53576, unauthenticated remote code execution through authentication filter bypass, 3 June 2026), and GHSA-rjhm-qm6w-m7x9 and GHSA-j5cv-8rw9-vv2p (unauthenticated remote code execution and authentication bypass, 29 September 2026). All are fixed, in 1.3.38 and 1.0.60 at the latest, and the maintainers published each one, so the deduction is reduced (https://github.com/kestra-io/kestra/security/advisories). Two further high advisories affected the default open-source setup. GHSA-hrr4-xg8h-5p6f, an unauthenticated gRPC control plane on port 50051, fixed in 2.0.3 and published 29 September 2026, and GHSA-94pv-f379-3gp3, a revoked administrator credential that stayed valid, fixed in 1.3.41 and published 6 October 2026 (https://github.com/kestra-io/kestra/security/advisories). | -7 | | **Total** | | | | **63.6 → B** | ### Why each score - Reliability 89: Graded as software the owner runs, on the open-source edition 2.0.5. Official Docker image `kestra/kestra` and a stated runtime of Java 25 (20). Public CI with unit and end-to-end tests. The latest `main-build` run on the `develop` branch on 8 October 2026 passed, after one failure two hours earlier (22). 840 open issues and pull requests. The nine issues opened on 7 and 8 October were all labelled and had one to twelve comments each (17). Major, feature and patch versions follow a written release policy, and each version's breaking changes have a migration guide (15). Version 2.0, with 1.0 released on 9 September 2025 (15). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 82: OpenAPI 3.0.1 file for the open-source API at kestra.io/kestra.yml, 216 operations on 194 paths, versioned 2.0.5 (25). `llms.txt`, `llms-full.txt` and every docs page as Markdown by adding `.md` (10). 213 of 216 operations have a summary, most of them one line saying what the call does and none saying when to choose it (11). 49 enum schemas and bounds such as `size` 1 to 1,000, but execution inputs are an untyped multipart array and filters are strings in a nested query syntax (10). 401, 403 and 500 are documented as problem+json on 213 operations, 409 on 23 and 400 on 22, and the API guide has curl examples (11). The path carries `v1`, the spec carries the release number, and release notes and migration guides are public (15). - Agent ergonomics 73: List and search calls take `page` and `size`, and execution search returns a light execution type. No field selection (15). Paging, sorting and operator filters on search endpoints (20). Errors are problem+json, though most operations document only the generic 401, 403 and 500 (13). No idempotency key. The documented pattern passes `system.correlationId` as a label and needs a duplicate check written into the flow. Flows exposed as MCP tools can set read-only, destructive and idempotent hints (10). Executing a flow needs only namespace and flow id, and there are generated SDKs for Python, JavaScript, Java and Go (15). - Security & auth 41: The open-source edition has one basic-auth username and password with full access, and no tokens or scopes (10). No read-only mode or approval step in open source. RBAC, service accounts and human approval tasks are Enterprise. MCP servers are private by default (3). Allow and deny lists restrict outbound HTTP from tasks. No guidance on untrusted content reaching an agent was found (5). Audit logs are Enterprise only. Open source keeps execution history and logs, and MCP calls are labelled `system.from:mcp` (7). A valid security.txt, a SECURITY.md with a two-business-day acknowledgement, 33 advisories published by the maintainers, and SOC 2 Type 2 for the company and the managed service. No bug bounty found (16). - Payments & pricing 50: Read with the self-hosted rule. No x402, MPP or L402 (0). The open-source edition is free with unlimited flows and executions, stated on the pricing page. The paid options have no public price, Enterprise through sales and Cloud by access request, so half marks (10). Free to run with no card (20). An agent can start the Docker image and set the credential in configuration with no signup (20). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 93: v2.0.5 and v1.3.42 released on 5 October 2026 (30). 32 releases between 15 July and 5 October 2026 (20). New issues are labelled and answered within a day in the sample we read, against 840 open issues and pull requests (20). SDKs for four languages are generated from the spec, with `kestrapy` 2.0.1 published on 11 September 2026 (15). CI, CodeQL and scheduled end-to-end tests run on the repository. Two points off because the docs say `kestrapy` 2.0.1 imports a package it does not declare (8). - Transparency & trust 69: Apache-2.0 for the server and the SDK repository (30). For self-hosted use the security page says flows, logs and secrets stay in the owner's database and storage, which agrees with the usage-reporting page. The Cloud privacy policy and terms cover only Cloud, and the website policy only the website, so no document covers the usage reports as personal data (20). A written release policy gives each long-term support line a support end date, and removals come with migration guides. No notice period for API changes was found (16). Usage reporting is on by default, documented field by field with a link to the source, and both streams can be switched off (20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/kestra.md (JSON https://www.anchorterminal.com/fixes/kestra.json) ### What we couldn't check - unchecked: status.kestra.io did not answer our requests, so we could not tell whether Kestra Cloud has a status page - unchecked: the trust centre on app.drata.com (sub-processor list, SOC 2 report, policies) was not read - Kestra Cloud's rates for task runs and runner time are not published, and Enterprise is priced through sales - The lead said the docs give four language SDKs. That holds, though the repository README names only Python and JavaScript - Whether the open-source `default` MCP server can be limited to fewer flows per caller, given the single credential - kestra.io/terms returns 404. The only terms found are the Kestra Cloud Terms of Service, which exclude the open-source project ### Sources - pricing and edition comparison: (seen 2026-10-08) - open-source OpenAPI spec: (seen 2026-10-08) - llms.txt: (seen 2026-10-08) - resources for agents: (seen 2026-10-08) - MCP server docs: (seen 2026-10-08) - MCP tool trigger: (seen 2026-10-08) - API guide: (seen 2026-10-08) - idempotency guide: (seen 2026-10-08) - basic auth: (seen 2026-10-08) - release and LTS policy: (seen 2026-10-08) - 2.0.0 migration guide: (seen 2026-10-08) - usage reporting: (seen 2026-10-08) - security page: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - repository advisories: (seen 2026-10-08) - releases: (seen 2026-10-08) - source, LICENSE, SECURITY.md, CI workflows: (seen 2026-10-08) - open issues: (seen 2026-10-08) - Python SDK docs: (seen 2026-10-08) - Kestra Cloud page: (seen 2026-10-08) - Kestra Cloud terms: (seen 2026-10-08) - Kestra Cloud privacy policy: (seen 2026-10-08) - Cloud task runs: (seen 2026-10-08) ## Who's behind it (provenance 51/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Kestra Technologies SAS | 20/20 | | Domain age | kestra.io, registered 2019-12-18 (6 years) | 11/15 | | Endpoint on the vendor's domain | is not on kestra.io | 0/15 | | Terms of service | not found | 0/10 | | Privacy policy | not found | 0/10 | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The Cloud terms name Kestra Technologies SAS (RCS 900 427 873), 81 rue du Pré Catelan, 59110 La Madeleine, France, and Kestra Technologies Inc., a Delaware corporation, for customers billed in the Americas. No terms or privacy link is given because the edition graded is Apache-2.0 software the owner runs. The Kestra Cloud Terms of Service and Kestra Cloud Privacy Policy (both 14 September 2026) say they do not cover the open-source project, and the privacy policy at kestra.io/privacy-policy covers only the website. The API answers on the owner's own host. Only the documentation MCP server (api.kestra.io) and the usage reports go to a Kestra domain. https://kestra.io/.well-known/security.txt names security@kestra.io and the GitHub advisory form, and expires on 26 August 2028. RDAP for kestra.io gives a registration date of 2019-12-18. status.kestra.io did not answer our requests on 8 October 2026 and no status page is linked from the pricing, security or Cloud pages. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service**. We found no terms of service published for this product, so there is nothing to read and the check scores 0. **Privacy policy**. We found no privacy policy published for this product, so there is nothing to read and the check scores 0. ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - OpenAPI 3.0.1 spec for the open-source API with 216 operations, 213 of them documenting 401, 403 and 500 as problem+json - Every docs page is served as Markdown by adding `.md`, with `llms.txt` and `llms-full.txt` - 32 releases between 15 July and 5 October 2026, with patches each week on the 1.3 and 2.0 long-term support lines - Any flow becomes an MCP tool through `McpToolTrigger`, with read-only, destructive and idempotent hints set per flow - Apache-2.0 server, and usage reporting documented field by field with two switches to turn it off ## Weaknesses - The open-source edition has one basic-auth username and password. API tokens, service accounts, RBAC and audit logs need Enterprise or Cloud - Five critical advisories from 30 March to 29 September 2026, four of them unauthenticated remote code execution or authentication bypass, all fixed - Kestra Cloud is request-access with no public price, and Enterprise is sold by annual contract through sales - No rate limits and no idempotency key on the API. The correlation ID pattern needs a guard written into the flow - The docs say `kestrapy` 2.0.1 imports `regex` without declaring it, so a plain install fails on import ## Before you call it (notes for agents) 1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3 2. Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port 3. Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}` 4. Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call 5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth ## Connect Install: ```bash docker run --pull=always --rm -it -p 8080:8080 --user=root --name kestra -v kestra_data:/app/storage -v kestra_db:/app/data -v /var/run/docker.sock:/var/run/docker.sock -v /tmp:/tmp -e KESTRA_PLUGINS_AUTO_INSTALL_ENABLED=true kestra/kestra:latest-slim server local ``` First request: ```bash curl -X POST -u 'admin@kestra.io:kestra' http://localhost:8080/api/v1/main/executions/company.team/hello_world ``` Claude Code: ```bash claude mcp add --transport http --header "Authorization: Basic $(echo -n 'username:password' | base64)" ``` Through letme (picks today, calling later): https://letme.dev/kestra. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Pipedream API + MCP | B | 65.5 | 288 | automation.workflows, automation.apps, automation.code, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/pipedream.md | | Workato API + MCP | C | 58 | 533 | automation.workflows, automation.apps, automation.code, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/workato.md | | Activepieces API + MCP | C | 57.5 | 545 | automation.workflows, automation.apps, automation.code, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/activepieces.md | | Tray.ai API + MCP | C | 55.5 | 589 | automation.workflows, automation.apps, automation.code, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/tray.md | | n8n API + MCP | D | 53.1 | 638 | automation.workflows, automation.apps, automation.code, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/n8n.md | | Gumloop | C | 61.6 | 419 | automation.workflows, automation.apps, automation.webhooks, agent.tools | no | https://www.anchorterminal.com/tools/gumloop.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The open-source edition requires basic auth with a single username and password. API tokens and service accounts are marked not available in OSS (source: ) - Docs pages return Markdown when `.md` is added to the URL or `Accept: text/markdown` is sent (source: ) - `llms.txt` carries text addressed to AI agents, such as a 'Start here if you are an AI agent' line. We recorded it and did not act on it (source: ) - 33 advisories are published on the repository, 32 of them since 3 March 2026 and five rated critical (source: ) - Kestra 2.0.0 removed `ForEach`, trigger `conditions` and the `json()` function, with a migration guide and a `kestra-migrate --check` tool (source: ) - The Kestra Cloud terms of 14 September 2026 say they include no service-level agreement, uptime commitment or service credits (source: ) ## Compare - [Activepieces API + MCP vs Kestra](https://www.anchorterminal.com/compare/activepieces-vs-kestra.md): C 57.5 vs B 63.6 - [Gumloop vs Kestra](https://www.anchorterminal.com/compare/gumloop-vs-kestra.md): C 61.6 vs B 63.6 - [Kestra vs Make API + MCP](https://www.anchorterminal.com/compare/kestra-vs-make.md): B 63.6 vs C 58.7 - [Kestra vs n8n API + MCP](https://www.anchorterminal.com/compare/kestra-vs-n8n.md): B 63.6 vs D 53.1 - [Kestra vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/kestra-vs-paragon.md): B 63.6 vs D 47.5 - [Kestra vs Pipedream API + MCP](https://www.anchorterminal.com/compare/kestra-vs-pipedream.md): B 63.6 vs B 65.5 - [Kestra vs Microsoft Power Automate](https://www.anchorterminal.com/compare/kestra-vs-power-automate.md): B 63.6 vs B 62 - [Kestra vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/kestra-vs-tray.md): B 63.6 vs C 55.5 - [Kestra vs Windmill API + MCP](https://www.anchorterminal.com/compare/kestra-vs-windmill.md): B 63.6 vs C 55.9 - [Kestra vs Workato API + MCP](https://www.anchorterminal.com/compare/kestra-vs-workato.md): B 63.6 vs C 58 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on kestra.io or one of its subdomains, or the README of github.com/kestra-io/kestra. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "kestra", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Kestra on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Kestra on Anchor Terminal](https://www.anchorterminal.com/badges/kestra.svg)](https://www.anchorterminal.com/tools/kestra) ``` Plain link: ```html Kestra on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Kestra is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/kestra-dark.png - Light: https://www.anchorterminal.com/assets/share/kestra-light.png