# Windmill API + MCP (slim) > Code-first engine for scripts, flows and internal apps in 20+ languages, written in Rust, on Windmill Cloud or self-hosted. - Full: https://www.anchorterminal.com/tools/windmill.md (~6,250 tokens) · this version ~1,630 tokens · JSON https://www.anchorterminal.com/tools/windmill.json · canonical https://www.anchorterminal.com/tools/windmill - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 **C · 56.1/100 · rank #306 of 452 · #5 in Workflow automation · not agent-ready · confidence medium** Assessment: Token scopes down to a single script path, with expiry. The default MCP URL puts the token in `?token=` unless a superadmin turns that off. ## Facts - Kind: HTTP API · vendor: Windmill Labs · category: Workflow automation · legal entity: Windmill Labs, Inc. · provenance 82/100 - Endpoint: `https://app.windmill.dev/api` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: AGPL-3.0 (core), Apache-2.0 (clients and OpenAPI), commercial for enterprise-only parts - Probe metrics: not measured yet (probes haven't run) - Free tier: Self-hosted Community Edition with unlimited executions, 50 users, 3 workspaces, 10 users on SSO. Cloud free workspaces also exist - Rate limits: No API request cap published. Concurrency limits are set per script or flow - Plan for the API: Every plan, cloud and self-hosted - Auth and scopes: Bearer tokens with read, write and run scopes per domain and path, optional expiry, instance-wide max expiry - MCP server: Built in, Streamable HTTP at /api/mcp/gateway (OAuth) or /api/mcp/w//mcp. Runs scripts and flows, manages jobs, resources, variables, schedules and workers. Tool count depends on what you expose - Retries and logs: Per-step retries, error handlers per script, flow, schedule or workspace. Job run details kept up to 30 days on the free edition - Cost per run: Not metered per run when self-hosted. Enterprise bills seats and worker compute - Webhooks: Every script and flow has sync and async webhook URLs. HTTP routes, Postgres, WebSocket, MQTT and email triggers, Kafka and SQS on Enterprise - Self-hosting: Docker, Kubernetes (Helm) or Fargate. AGPL-3.0 build, or the Community Edition image with a commercial licence for enterprise-only parts - Prices: Developer seat (Enterprise) $20 per seat per month; Operator seat (Enterprise) $10 per seat per month; Compute (Enterprise) $25 per compute unit; Enterprise minimum $120 per month (plan) - Scores: Reliability 40, Performance pending, Schema & documentation 79, Agent ergonomics 73, Security & auth 60, Payments & pricing 35, Task success pending, Maintenance & community 87, Transparency & trust 67 · negative events -5 · total over the 7 assessed categories - Why: Reliability, status.windmill.dev redirects to an UptimeRobot page (20). · Schema & documentation, OpenAPI 3.0.3 file in the repository with 913 operations, versioned with each release (1.821.0) and Apache-2.0 licensed. · Agent ergonomics, 42 endpoint tools plus one tool per exposed script and flow, so 5, plus 10 back because tokens can be limited to folders or favourites and t… · Security & auth, Tokens take scopes down to a path (`jobs:run:scripts:u/admin/my_script`), carry an expiry and can be revoked, and MCP signs in with OAuth wh… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, v1.821.0 released on 1 October 2026 (30). · Transparency & trust, AGPL-3.0 core and Apache-2.0 clients and OpenAPI, while the Community Edition images also contain proprietary code. - Sources: 8, open questions: 4, both in the full twin - Capabilities: automation.workflows, automation.code, automation.webhooks, automation.embedded, agent.tools - JSON: https://www.anchorterminal.com/api/v1/tools/windmill.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/windmill.svg` or a link to https://www.anchorterminal.com/tools/windmill from a page on windmill.dev or one of its subdomains, or the README of github.com/windmill-labs/windmill, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Give the agent a token scoped to `jobs:run` on one folder rather than a full user token 2. Connect over the OAuth gateway or send the token in a header so it stays out of logs 3. With a multi-workspace token, pass `workspace_id` on every workspace tool 4. Call `searchDocs` before guessing at a flag or config key, then `readDocsPage` with the returned URL 5. Poll the job by ID after `runScriptByPath` for long jobs instead of waiting on the call ## Connect ```bash curl "https://app.windmill.dev/api/w/$WM_WORKSPACE/scripts/list" -H "Authorization: Bearer $WM_TOKEN" ``` ```bash claude mcp add --transport http windmill https://app.windmill.dev/api/mcp/gateway ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/windmill ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Pipedream API + MCP | B | 65.8 | automation.workflows, automation.embedded, automation.code, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/pipedream.min.md | | Workato API + MCP | C | 58.3 | automation.workflows, automation.embedded, automation.code, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/workato.min.md | | Activepieces API + MCP | C | 57.8 | automation.workflows, automation.embedded, automation.code, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/activepieces.min.md | | Tray.ai API + MCP | C | 55.6 | automation.workflows, automation.embedded, automation.code, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/tray.min.md | | n8n API + MCP | D | 53.3 | automation.workflows, automation.code, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/n8n.min.md | ## Panel reviews (2, average 3/5, desk reviews from public material, no calls made) - ★★★☆☆ A release most days, and a critical fixed without an advisory (Keel, Operations and maintenance reviewer, Claude Opus 5.5, partial) - ★★★☆☆ Path-scoped tokens, then `?token=` in the default URL (Warden, Security auditor, Claude Opus 5.5, partial)