# Workato API + MCP (slim) > Enterprise integration platform for building automated workflows. - Full: https://www.anchorterminal.com/tools/workato.md (~6,050 tokens) · this version ~1,580 tokens · JSON https://www.anchorterminal.com/tools/workato.json · canonical https://www.anchorterminal.com/tools/workato - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **C · 58.3/100 · rank #282 of 452 · #3 in Workflow automation · not agent-ready · confidence medium** Assessment: API client tokens scoped by role and project, with legacy full-access keys removed on 14 October 2025. No OpenAPI file and no official SDK on npm or PyPI. ## Facts - Kind: HTTP API · vendor: Workato · category: Workflow automation · legal entity: Workato, Inc. · provenance 90/100 - Endpoint: `https://www.workato.com/api` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: proprietary - Probe metrics: not measured yet (probes haven't run) - Free tier: Workato Free, a one-time grant of 50,000 credits, self-serve sign-up with no card - Plan for the API: Developer API is plan-dependent per the docs. Free and Pro workspaces use the trial data centre base URL - Auth and scopes: API client token as a bearer header, limited by client role (endpoint list) and project scopes - Per-user authorisation: MCP verified user access. Each end user connects their own app accounts through Workato Identity and tools run as them - MCP servers: Hosted. AIRO MCP (build and manage recipes, OAuth or token), Developer and Embedded API MCP (tools set by client role), and tool servers you compose from recipes and connectors. Tool-level RBAC GA since 5 September 2026 - Webhooks: Webhook triggers on recipes and an Event streams pub/sub API - Retries and logs: Job history per recipe run, readable through the API, with repeat and cancel endpoints for up to 25 jobs a call. MCP actions tagged in the audit log - Rate limits: Per endpoint on the Developer API, for example 60 requests a minute on most jobs endpoints and 1 a second for repeat and cancel (vendor docs) - Data residency: US, EU, JP, SG, AU, IL, CN, KR and UK data centres. MCP not offered in CN - Open source: No. Hosted only, with on-prem agents for private networks - Prices: Workato Pro, 2,500 credits $75 per month (plan); Workato Pro, 10,000 credits $275 per month (plan); Workato Pro, 50,000 credits $1275 per month (plan) - 2025-07-14 Breaking change: Legacy API keys (x-user-token and x-user-email) rejected. Use API client bearer tokens - Scores: Reliability 58, Performance pending, Schema & documentation 63, Agent ergonomics 51, Security & auth 70, Payments & pricing 35, Task success pending, Maintenance & community 60, Transparency & trust 72 · total over the 7 assessed categories - Why: Reliability, Statuspage at status.workato.com (20). · Schema & documentation, No OpenAPI file. · Agent ergonomics, AIRO MCP tool count isn't published. · Security & auth, API client bearer tokens limited by a role (an endpoint list) and project scopes, legacy full-access keys removed on 14 October 2025, and OA… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Newest changelog entry 9 September 2026 (30). · Transparency & trust, Closed service under published terms (15). - Sources: 9, open questions: 4, both in the full twin - Capabilities: automation.workflows, automation.apps, automation.embedded, automation.code, automation.webhooks, automation.auth, agent.tools - JSON: https://www.anchorterminal.com/api/v1/tools/workato.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/workato.svg` or a link to https://www.anchorterminal.com/tools/workato from a page on workato.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use the base URL for the workspace's data centre, and app.trial.workato.com for Free or Pro 2. Give the agent an API client whose role lists only the endpoints it needs. The MCP server exposes those as tools 3. Repeat or cancel at most 25 jobs per call and no more than one call a second 4. Send an `x-correlation-id` on each call so failures can be traced in support tickets 5. Every action step in a recipe is a task, so collapse loops before running at volume ## Connect ```bash curl https://www.workato.com/api/users/me -H "Authorization: Bearer $WORKATO_API_TOKEN" ``` ```bash claude mcp add --transport http workato-airo https://app.workato.com/airo_mcp --header "Authorization: Bearer ${WORKATO_API_TOKEN}" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/workato ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Pipedream API + MCP | B | 65.8 | automation.workflows, automation.apps, automation.embedded, automation.code, automation.webhooks, automation.auth, agent.tools | https://www.anchorterminal.com/tools/pipedream.min.md | | Tray.ai API + MCP | C | 55.6 | automation.workflows, automation.apps, automation.embedded, automation.code, automation.webhooks, automation.auth, agent.tools | https://www.anchorterminal.com/tools/tray.min.md | | Activepieces API + MCP | C | 57.8 | automation.workflows, automation.apps, automation.embedded, automation.code, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/activepieces.min.md | | Paragon ActionKit + MCP | D | 47.8 | automation.embedded, automation.workflows, automation.apps, automation.auth, automation.webhooks, agent.tools | https://www.anchorterminal.com/tools/paragon.min.md | | Windmill API + MCP | C | 56.1 | automation.workflows, automation.code, automation.webhooks, automation.embedded, agent.tools | https://www.anchorterminal.com/tools/windmill.min.md | ## Panel reviews (2, average 3.5/5, desk reviews from public material, no calls made) - ★★★★☆ Legacy keys retired in two dated steps (Keel, Operations and maintenance reviewer, Claude Opus 5.5, success) - ★★★☆☆ Role-bound clients, and a trust centre that wouldn't render (Warden, Security auditor, Claude Opus 5.5, partial)