# Kestra (slim) > Kestra is an open-source workflow orchestrator from Kestra Technologies. Flows are written in YAML and run on a server the owner hosts, with a REST API, SDKs in four languages and flows exposed as MCP tools. - Full: https://www.anchorterminal.com/tools/kestra.md (~6,500 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/kestra.json · canonical https://www.anchorterminal.com/tools/kestra - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 63.6/100 · rank #351 of 842 · #2 in Workflow automation · not agent-ready · confidence medium** Assessment: Kestra's open-source edition has a 216-operation OpenAPI spec, Markdown docs for agents and weekly patch releases on two long-term support lines. Its only credential is one basic-auth username and password with full access, and five critical advisories were published between March and September 2026, all fixed. ## Facts - Kind: HTTP API · vendor: Kestra Technologies · category: Workflow automation · legal entity: Kestra Technologies SAS · provenance 51/100 - Local only (HTTP, Streamable HTTP): oci `kestra/kestra`, pypi `kestrapy`, npm `@kestra-io/kestra-sdk` - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Apache-2.0 (open-source server and SDK repository). Enterprise Edition and Kestra Cloud are commercial - Probe metrics: not measured yet (probes haven't run) - Edition graded: Open-source edition 2.0.5, self-hosted. Kestra Cloud is request-access and Enterprise is sold by contract, so neither is graded here - API: REST under `/api/v1/{tenant}/` on port 8080, OpenAPI 3.0.1 at https://kestra.io/kestra.yml with 216 operations on 194 paths. The Enterprise spec is at https://kestra.io/kestra-ee.yml - Auth: Open source has one basic-auth username and password, required since basic auth became mandatory. API tokens, service accounts, OAuth, SSO and RBAC are Enterprise and Cloud only - MCP: A `default` MCP server per tenant at `/api/v1/{tenant}/mcp/{id}`. A flow with `McpToolTrigger` becomes a tool, with its inputs as the JSON Schema. Basic auth on open source, API token or OAuth on Enterprise and Cloud - Docs MCP server: https://api.kestra.io/v1/mcp, no authentication, six tools (search, task_schema, list_plugins, plugin_tasks, list_installed_versions, list_plugin_elements). It reads docs and plugin schemas and does not control an instance - Pagination: `page` and `size` (1 to 1,000, default 10), `sort`, and `filters[field][OPERATOR]=value` on search endpoints - Errors: application/problem+json `ProblemDetail`. 401, 403 and 500 documented on 213 operations, 409 on 23, 400 on 22 - Rate limits: None published for the API. One 429 in the spec, on plugin install when too many jobs are pending. Flow concurrency limits are set per flow, and execution quotas are Enterprise - SDKs: Python `kestrapy` 2.0.1 (11 September 2026), JavaScript `@kestra-io/kestra-sdk` 2.0.1, Java and Go, generated from the spec in kestra-io/client-sdk (Apache-2.0) - Releases: 2.0 LTS (8 September 2026, supported to September 2027) and 1.3 LTS (to March 2027). Patch releases every Tuesday, feature releases about every two months. Requires Java 25, or the Docker image - Telemetry: Anonymous usage reporting is on by default, server side and from the UI. Set `kestra.anonymous-usage-report.enabled` and `kestra.ui-anonymous-usage-report.enabled` to false to stop both - Cloud: Managed Enterprise instances on Google Cloud in the EU or US. Access by request form, 14 days free without a card, billed on task runs and Cloud runner time with no public rates. The terms carry no SLA - Certifications: SOC 2 Type 2 for the company and the managed service, per kestra.io/security. A self-hosted deployment is outside its scope - Scores: Reliability 89, Performance pending, Schema & documentation 82, Agent ergonomics 73, Security & auth 41, Payments & pricing 50, Task success pending, Maintenance & community 93, Transparency & trust 69 · negative events -7 · total over the 7 assessed categories - Why: Reliability, Graded as software the owner runs, on the open-source edition 2.0.5. Official Docker image `kestra/kestra` and a stated runtime of Java 25… · Schema & documentation, OpenAPI 3.0.1 file for the open-source API at kestra.io/kestra.yml, 216 operations on 194 paths, versioned 2.0.5 (25). · Agent ergonomics, List and search calls take `page` and `size`, and execution search returns a light execution type. · Security & auth, The open-source edition has one basic-auth username and password with full access, and no tokens or scopes (10). · Payments & pricing, Read with the self-hosted rule. · Maintenance & community, v2.0.5 and v1.3.42 released on 5 October 2026 (30). · Transparency & trust, Apache-2.0 for the server and the SDK repository (30). - Sources: 23, open questions: 6, both in the full twin - Capabilities: automation.workflows, automation.code, automation.webhooks, automation.apps, agent.tools - JSON: https://www.anchorterminal.com/api/v1/tools/kestra.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/kestra.svg` or a link to https://www.anchorterminal.com/tools/kestra from a page on kestra.io or one of its subdomains, or the README of github.com/kestra-io/kestra, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Run 2.0.5 or 1.3.42 or later. Earlier builds carry unauthenticated remote code execution advisories fixed in 1.3.38 and 2.0.3 2. Set `kestra.server.basic-auth` in the config file before first start. Without it the setup page is open to anyone who reaches the port 3. Put the tenant in the path. Open-source instances use `main`, as in `/api/v1/main/executions/{namespace}/{id}` 4. Send flow inputs as multipart form fields, and add `wait=true` to get the finished execution in the same call 5. Keep port 8081 off any shared network. The management endpoints there skip the API's basic auth ## Connect ```bash docker run --pull=always --rm -it -p 8080:8080 --user=root --name kestra -v kestra_data:/app/storage -v kestra_db:/app/data -v /var/run/docker.sock:/var/run/docker.sock -v /tmp:/tmp -e KESTRA_PLUGINS_AUTO_INSTALL_ENABLED=true kestra/kestra:latest-slim server local ``` ```bash curl -X POST -u 'admin@kestra.io:kestra' http://localhost:8080/api/v1/main/executions/company.team/hello_world ``` ```bash claude mcp add --transport http --header "Authorization: Basic $(echo -n 'username:password' | base64)" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/kestra ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Pipedream API + MCP | B | 65.5 | automation.workflows, automation.apps, automation.code, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/pipedream.min.md | | Workato API + MCP | C | 58 | automation.workflows, automation.apps, automation.code, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/workato.min.md | | Activepieces API + MCP | C | 57.5 | automation.workflows, automation.apps, automation.code, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/activepieces.min.md | | Tray.ai API + MCP | C | 55.5 | automation.workflows, automation.apps, automation.code, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/tray.min.md | | n8n API + MCP | D | 53.1 | automation.workflows, automation.apps, automation.code, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/n8n.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)