Agentic Index
Dify vs StackAI (2026)
Both build and deploy agents on enterprise data without code, at 12 and 13.5 of 14. That verdict is the Agentic Index coverage score, graded from each vendor's own published materials.
Dify is open source for building agents, chatbots and workflows, from 59 dollars a month with a free sandbox and free self hosting. StackAI is no code for workflows and agents on enterprise data, free to 500 runs monthly then enterprise custom per seat. StackAI documents more and leans harder into enterprise data connectivity; Dify is open source, which for some organizations settles it.
This comparison is published by Agentic Index, an independent agentic AI vendor research platform. Dify and StackAI are each graded against the same 14 capability Agentic Index taxonomy, from the vendor's own public materials under the Agentic Index verification standard, alongside 969 researched vendors. No vendor pays for placement and no vendor has reviewed this page. How this evidence is graded
Choose Dify if
- Open source with free self hosting is a requirement rather than a preference.
- Chatbots alongside agents and workflows is the range you need.
- A free sandbox lets you evaluate before any commitment.
Choose StackAI if
- Documented coverage is broader and enterprise data connectivity is the hard part.
- Enterprise per seat pricing is the model your procurement expects.
- No self hosting burden is what your team can actually operate.
| At a glance | Dify | StackAI |
|---|---|---|
| Category | Agent builder | Agent builder |
| Entry price | From $59/mo · Sandbox free demo + free self-host | Free (500 runs/mo) · Enterprise custom (per-seat) |
| Free / trial | Free | Free |
| Pricing confidence | public partial | contact only |
| Feature | D Dify |
S StackAI |
|---|---|---|
| Action & orchestration | ||
|
Integrations & Tool Calling Ability to connect agents to real systems through native integrations, OAuth-authenticated actions, custom tools, APIs, webhooks, or MCP-compatible tools. |
Full / Explicit
Stands at F on re-retrieved evidence; the April basis cited only an internal research report. Breadth is across classes rather than deep in one ecosystem, which is what the axis asks for: model providers, SaaS tools, data sources and arbitrary HTTP all have first-class surfaces. The auto-generated versus manual tool parameter distinction is worth carrying to comparison pages, since it is a control most builders in this lane do not expose. |
Full / Explicit
Stands at F on an enumerated catalogue of roughly ninety individually documented app nodes, each with its own actions, inputs and outputs, which makes this checkable rather than a headline number. Breadth across classes is emphatic and skews enterprise in a way that distinguishes it from the prosumer catalogues elsewhere in this lane: SAP, NetSuite, Oracle, Workday, ServiceNow, Snowflake, Databricks and Egnyte are not integrations a no-code tool aimed at individuals carries. Eight database and warehouse connectors with natural-language-to-SQL querying is a second distinguishing cluster. The MCP node means anything exposed as an MCP server becomes callable too, so the ceiling is open. Recorded per section 7: the Zapier and Make nodes are StackAI reaching out to those platforms, which counts as its own integration breadth here and is not evidence of StackAI's extensibility, graded separately on Ext. |
|
Workflow Orchestration Ability to sequence, branch, retry, route, and combine deterministic workflow nodes with autonomous agent steps. |
Full / Explicit
Stands at F on re-retrieved evidence. Multi-agent composition here is workflow-as-tool and agent-as-node rather than a peer-to-peer agent society: one flow calls another, and an Agent node is a bounded autonomous step inside a deterministic harness. That is a meaningfully different shape from crewai or langgraph and should be described that way on comparison pages rather than levelled flat. The max-iterations ceiling on Agent nodes is a real containment property and doubles as a cost control. |
Full / Explicit
Stands at F. Both halves are documented. Multi-step control flow is complete: AI Routing for model-decided branching, If/Else for deterministic branching, Loop Subflow for iteration, Delay for pacing, and Code and Python nodes as escape hatches. Multi-agent is genuine and works two ways, which is the part worth carrying: Subflow Tools let an AI Agent node call another flow AS A TOOL, so a supervising agent selects among specialist subflows at runtime, and the StackAI Project Node lets one project invoke another as a unit. A dedicated Orchestrating AI Agents guide sits in the tips tree, and Handling Errors and Fallback plus Skip and Replace Node give the reliability affordances that separate a production orchestrator from a demo canvas. |
|
Triggers & Channel Coverage How agents wake up and where they work: schedules, webhooks, message events, CRM events, inbox events, chat, email, voice, and collaboration tools. |
Full / Explicit
P>F. All three trigger classes the axis asks for are documented as first-class nodes: events (webhook and plugin), schedules, and channels. The April P looks like an accurate reading of an older product rather than an error; the Trigger node family and the Workflows Can Start Themselves framing both postdate that build. The pricing-page corroboration is the strongest part of the evidence, since a metered quota with per-tier caps is a shipped feature in a way a product-page claim is not. |
Full / Explicit
P>F. Channel coverage is the strongest part and is documented page by page rather than claimed: eight distinct end-user surfaces, which is wider than anything else reviewed in this lane. Events are covered by a dedicated Trigger node plus app-level triggers such as inbound email and inbound webhooks. Schedules are the thinnest of the three classes and the reason confidence is medium rather than high: recurring execution is referenced in two separate documentation pages as an established pattern, but no dedicated scheduling page appears in the complete index, so the configuration surface was not read. Fetching the Trigger Node page would settle it and is the single call that would take this to high confidence. Graded F because all three classes are documented as shipped rather than because the schedule surface is fully described. |
| Knowledge & context | ||
|
Knowledge Grounding & RAG Ability to ground agent behavior in company data through document ingestion, retrieval, external knowledge APIs, semantic search, or RAG layers. |
Full / Explicit
Stands at F on re-retrieved evidence. Relevant to the open Knowledge convention question: Dify sits squarely on the maintained-retrieval-structure side of the line rather than per-request assembly. The knowledge base is a durable, managed, separately quota'd artifact with its own build pipeline, versioning and lifecycle, and the retrieval settings are configured once and reused, not assembled per call. If that line is drawn as ratified, Dify is a clean positive example to calibrate against. |
Full / Explicit
Stands at F. Knowledge bases are durable managed artifacts with their own creation, usage, node and feature documentation, plus a REST endpoint and, importantly, their own PERMISSION model, which is rare: access to a knowledge base is restricted independently of access to the workflow that uses it. For a regulated buyer that is the control that makes a shared agent platform viable across departments. Relevant to the open Knowledge convention: this is decisively a maintained retrieval structure rather than per-request assembly, and the vendor documents two distinct ways an agent consumes it. A Dynamic Vector Store covers the runtime-constructed case, and Search Connected Apps grounds on live systems without indexing them first, so both patterns are available and separable. Customer-managed vector stores through Pinecone and Weaviate mean the index can live outside the platform entirely. |
|
Memory & State Persistence Ability to persist context across a run, conversation, workflow, user, team, or longer-term memory layer. |
Partial
Stands at P on re-retrieved evidence, and the absence side is now properly evidenced rather than assumed: the complete first-party documentation index was enumerated and contains no memory product. The mechanism is a bounded token-buffer window plus conversation-scoped variables, which is retained state, not memory that accumulates or is learned from. That keeps it clearly below the F bar applied in Coding agent to cognition, cosine and greptile, all of which document an agent improving from its own prior runs. Confidence is high on both halves because the node reference and the full docs index were both reached. |
Partial
Stands at P, and it is now the ONLY cell below F on this record, so the reasoning matters. The Shared Memory node is explicitly a windowed context-passing mechanism, not a memory store: the builder chooses how many past interactions to forward and the documentation warns that passing too many will overwhelm the receiving model's context window. That is the same token-buffer shape as dify, and it is bounded by the context window rather than by a persistence layer. Nothing in the complete documentation index describes memory that survives a session, accumulates over time, or is learned from prior runs, which is the F bar met by cosine, greptile and cognition. Two things were deliberately NOT counted here, to avoid one fact doing work on three axes: the browser sandbox persists cookies and session state across runs, which is graded on Comp, and Canvas keeps per-conversation version history, which is a document feature. The Dynamic Vector Store is a retrieval structure and is graded on Know. |
| Control & trust | ||
|
Human Oversight & Guardrails Approval steps, consent checkpoints, escalation rules, structured guardrails, policy constraints, and pause/resume controls. |
Full / Explicit
RESOLVED FROM U. The April build left this Unspecified; it is now decisively F. The mechanism is the vendor's own approve-and-edit surface inside the run, not a delivery convention borrowed from a system the customer already owns, so it clears the 30 August ruling that a gate the customer already owns is not the vendor's mechanism. Approve, edit, comment, forward and timeout are named as the available human actions, which is a wider set than the approve/reject pattern most vendors ship. Second, separable guardrail: a Sensitive Content Moderation API extension sits outside the HITL node. Grade rests on the shipped node, not on governance prose. |
Full / Explicit
Stands at F. Human in the Loop is a documented first-class node rather than a posture, and the vendor treats it as foundational enough to build the first of its five learning challenges around it, which is a good signal that it is a load-bearing feature rather than a checkbox. The approval surface is the vendor's own and is delivered where the approver already is: the product page shows an approval prompt in Slack with explicit approve and disapprove controls. That clears the 30 August ruling, since Slack is the delivery channel while the gate itself belongs to StackAI. Workflow Notifications and the production workflow lock in Project Controls are separable second and third oversight mechanisms, the latter unusual because it constrains what a builder can change rather than what an agent can do. |
|
Security, Identity & Governance RBAC, SSO, auditability, encryption, least-privilege tool access, compliance posture, and data handling policy. |
Full / Explicit
P>F. The April basis cited only an internal research report, so nothing could be checked. The section 7 conjunction is met twice over: two attestations with a named audit firm, plus five separately named customer-facing controls. Graded strictly on the control surface. THE VPC, ON-PREM AND AIR-GAPPED DELIVERY OPTIONS ARE DELIBERATELY EXCLUDED FROM THIS BASIS and carried on Dep instead, per the 30 August ruling that sovereign delivery never reaches Security. AGGREGATOR OVERSTATEMENT RECORDED, same shape as the Motion precedent: a vendor-risk profile site lists Dify as FedRAMP and CSA STAR Level 1 compliant, neither of which appears on any Dify page; the vendor's own claim is SOC 2, ISO 27001:2022 and GDPR only. The aggregator was not used as evidence. Reports are gated behind a paid plan and a support email rather than a self-serve trust portal, which is a notch below the best disclosure in the index but well above the P floor. |
Full / Explicit
Stands at F and is among the two or three strongest Sec cells in the index. The conjunction is met several times over, and unusually the control surface is documented page by page rather than asserted as a bullet list: RBAC, workspace and folder isolation, feature-level admin enforcement, per-connection and per-knowledge-base permissions, MFA, and full SCIM provisioning with separate Okta and Entra guides. Encrypted environment variables resolved per stage is a maturity signal most no-code platforms lack. Graded strictly on the control surface: on-premise deployment and government cloud are carried on Dep and deliberately excluded here, per the 30 August ruling that sovereign delivery never reaches Security. Disclosure quality is high by index standards, with a trust centre, a SOC 2 report request route, model-provider DPAs published as signed PDFs and a BAA route, though no audit firm is named. |
|
Observability & Auditability Traces, logs, execution histories, metrics, audit events, and debugging detail for production agent behavior. |
Full / Explicit
Stands at F on re-retrieved evidence. Clears the reporting-is-not-auditing line comfortably: the dashboard alone would be reporting, but per-node inputs, outputs, variable values, execution path and typed error metadata let a run be reconstructed rather than merely counted, and the OpenTelemetry export means the trace leaves the vendor's perimeter in a form the customer controls. Tamper-evident audit logging is the strongest single claim and is Enterprise-tier; the trace and log surface below it is available on the self-serve plans, so the grade does not depend on the gated tier. |
Full / Explicit
Stands at F but at MEDIUM confidence, and the gap is named rather than glossed. A dedicated Observability section with three pages, a REST Analytics endpoint, audit logs on the product page and version history through the development lifecycle is comfortably more than reporting, and the Evaluator adds a quality dimension most vendors have nothing equivalent to. What was NOT confirmed is the per-run trace: the Manager page was identified from the complete documentation index but not read, so whether a customer can reconstruct why a specific run took the path it did is inferred rather than verified. One detail cuts slightly against F and is recorded honestly: a guide titled Adding Advanced Logging for Analytics suggests some richer telemetry is assembled by the builder rather than supplied. Fetching the Manager and Analytics pages would settle this to high confidence either way, and it is the main outstanding item on this record. |
|
Deployment & Data Residency Deployment modes and options, including SaaS, dedicated cloud, VPC, on-prem, hybrid, local runtime, and self-hosting. |
Full / Explicit
Stands at F on re-retrieved evidence and is now one of the best-evidenced Dep cells reviewed so far. This is genuine residency under the section 7 test, not legal cover: the customer chooses the region, or runs the software inside its own account, or runs it offline. Per the 30 August ruling the sovereign delivery properties live here and only here; the Security cell was written on the control surface alone and deliberately excludes air-gap and VPC. Worth noting for lane comparisons that free self-hosting puts full deployment control at the zero-price point, which almost no commercial vendor in this lane matches. |
Full / Explicit
Stands at F, and the strongest single piece of evidence is not a claim but an artifact: StackAI ships a dedicated enterprise CLI whose entire purpose is deploying and managing the platform on customer infrastructure, with its own documentation set, engineering standards, Kubernetes and Docker migration guides and a CVE upgrade runbook. A vendor that maintains a deployment CLI with release engineering docs is not offering on-premise as a sales concession. Government deployment is a separate documented path including Azure OpenAI in Azure Government, which is a genuine sovereignty story rather than legal cover. Per the 30 August ruling all of this lives here and only here; the Security cell was written on the control surface alone. Local LLM hosting reinforces it, since an air-gapped-leaning customer can keep both the platform and the inference inside its own boundary. |
| Solution readiness | ||
|
Prebuilt Agents, Templates & Packs Ready-made workflows, packaged employees, templates, blueprints, industry solutions, and role-specific agents that reduce time-to-value. |
Full / Explicit
P>F, and the weakest of the four upward moves on this record, so the limit is recorded plainly. The catalogue's existence, navigation and type filters are confirmed first-party, but THE ITEM LISTINGS RENDER CLIENT-SIDE AND CAME BACK EMPTY, so no individual template was enumerated and the catalogue's depth is unmeasured. Graded to the browsable-catalogue bar carried over from Coding agent, which this clears. Flagging it against the open Prebuilt packs question: the templates are largely community-published rather than vendor-authored, and if the bar is later set at a curated vendor-maintained pack set rather than a browsable catalogue, this cell should be revisited along with the rest of the Agent builder lane, where the same marketplace pattern will recur on n8n, make, zapier, flowise and langflow. |
Full / Explicit
Stands at F and the basis is now specific where the April one named nothing. Three separable layers of prebuilt material, which is more than most: a browsable Templates catalogue reachable from both the product and the documentation, named agent templates such as Content Writer that the documentation directs users to open and adapt, and Skills, which are reusable instruction packs agents load on demand and which function as prebuilt behaviour rather than prebuilt structure. A Prompt Library and a Common Architectures page add reusable material at the prompt and pattern level. Clears the browsable-catalogue bar carried from Coding agent. Recorded honestly: the catalogue page itself was not enumerated this pass, so its depth is unmeasured, though the vendor names specific templates by name in the documentation which is stronger than a bare claim of a library. |
| Platform extensibility | ||
|
Model Flexibility & Routing Ability to work across multiple foundation models, route tasks to different models, or let buyers bring their own providers and keys. |
Full / Explicit
Stands at F on re-retrieved evidence. This is the strongest form of the axis: the customer chooses the model, chooses the provider, brings its own key, and can run a local model with no external inference at all. Per-node model selection is the detail worth carrying, since it means model choice is a workflow design decision rather than an account-level setting. Not to be confused with the Ext credit for Dify publishing MCP servers, which is the opposite direction of travel and is graded there. |
Full / Explicit
Stands at F, and the distinguishing feature is not the breadth of model choice but the GOVERNANCE over it, which nothing else reviewed in this lane ships. LLM Provider Governance lets an administrator control which models the organisation may use and where information is sent and stored, so model flexibility is bounded by policy rather than left to whoever builds the workflow. For a regulated buyer that is the difference between model choice being an asset and being a compliance risk. Underneath it the ordinary requirements are met: multiple providers, per-node selection, models hosted in the customer's own Azure or Bedrock account, and locally hosted models. Not to be confused with the Ext credit for publishing an MCP server, which is the opposite direction of travel and is graded there. |
|
APIs, SDKs & MCP Extensibility Composability layer: stable APIs, SDKs, MCP tool consumption/serving, custom tools, and integration into internal systems. |
Full / Explicit
Stands at F on re-retrieved evidence and clears Mike's 30 August Ext bar decisively, since the platform is callable from outside through a documented REST API with a published OpenAPI spec, which is the thing zencoder and baz lacked when they were corrected down to P. MCP is present as corroboration rather than as the bar. Under the section 7 axis rule the MCP server credits Ext and not Model, because the customer picks the assistant that reads Dify; the model-choice credit is graded separately and independently on its own evidence. No Dify API rate limit on the paid cloud tiers is a commercially relevant detail for anyone building on top. |
Full / Explicit
Stands at F and clears Mike's 30 August Ext bar on every available route rather than just one. A documented REST API with named endpoints makes the platform callable from outside, which is the bar itself. StackAI also PUBLISHES ITS OWN MCP SERVER, which under the section 7 axis rule credits Ext and refuses Model, because the customer picks the assistant that reads StackAI. The enterprise CLI is a third surface, and project export and import means an agent definition is a portable artifact rather than something locked in a tenant. The Custom API node is the inbound counterpart, letting a workflow call anything the catalogue does not cover. This is a wider extensibility surface than most no-code platforms in this lane offer, and it is the reason the platform can sit underneath another product rather than only in front of a user. |
|
Testing, Debugging & Optimization Testing, debugging, scoring, retries, fallbacks, quality gates, and optimization loops for improving agent workflows before and after deployment. |
Partial
Stands at P on re-retrieved evidence, and the absence half is evidenced from a complete first-party documentation index rather than from a failed search. Real debugging and manual testing, no evals product: the customer can step a node, inspect variables and annotate outputs, but nothing scores a change against a dataset or catches a regression automatically. That is the P shape applied throughout Coding agent, where F required a harness the customer points at its own workload, as goose and openhands ship. Annotation is the nearest thing to a quality loop and is genuinely useful, but it curates answers rather than measuring them. This is the cell most likely to move if Dify ships evaluation, and it is worth re-checking each sweep. |
Full / Explicit
P>F. The Evaluator is a shipped customer-facing evaluation product, not the vendor testing its own work, which is the distinction the axis turns on. LLM-as-a-judge scoring of the customer's own agents clears the bar set by goose and openhands in Coding agent and matches the shape that took lyzr to F earlier in this lane. The surrounding surface is stronger than the Evaluator alone: an Agentic Development Lifecycle with version control, pull requests and prompt diffs, Project Controls that track versions during development and LOCK a workflow once in production, and documented troubleshooting and error-fallback guides. The production lock is the detail worth carrying, since it is a governance control on change rather than a testing feature and few vendors in this lane ship one. Recorded honestly: the Evaluator page itself was identified from the complete documentation index and its description rather than fetched in full, so the scoring mechanism's depth is not measured. |
| Specialist automation | ||
|
Browser & Computer Use Browser, desktop, or remote/local computer control for workflows that cannot be handled through stable APIs alone. |
No / Not documented
Stands at N on re-retrieved evidence, and the reasoning is the one thirteen June-cohort records in Coding agent got wrong. Sandboxed Code execution is present here and is NOT credited: running Python or JavaScript in a sandbox is code execution, not operating software the vendor does not control. Web crawling is likewise not computer use, since it fetches documents over a programmatic interface rather than driving a rendered UI. Confidence is medium rather than high because third-party browser-automation plugins may exist in the marketplace, whose listings render client-side and were not enumerated; under section 7 an installed third-party plugin would in any case be that plugin's capability and not Dify's. |
Full / Explicit
N>F, a full point, and the most consequential single correction of this lane so far. THE REASONING IS THE THIRTEEN JUNE COMP ERRORS RUN IN REVERSE, so this record is worth keeping as the worked example of the distinction. The StackAI Computer provider ships three actions and only one of them is Comp. THE TERMINAL TOOL IS EXPLICITLY NOT CREDITED HERE: running shell commands in an isolated sandbox is code execution, which is exactly what blink-new, codebuff, compyle, cosine, cubic and eight others were wrongly graded F for. Canvas is a document workspace and is likewise refused. What earns F is browser navigation, and it earns it decisively: the agent drives a real browser through authenticated web applications whose session state persists between runs, which is the definition of operating software with no programmatic interface. Two modes exist, a deterministic replay of a recorded sequence and an agentic mode for unfamiliar or dynamic tasks, and a separate HyperBrowser node adds a third route. A live stream URL for watching execution and a step-by-step result payload are unusual and make the capability inspectable rather than opaque. |
Pricing snapshot
Sourced from the Index pricing dataset · open each vendor's profile for full detail.
| Pricing | Dify |
StackAI |
|---|---|---|
|
Entry price Lowest public entry point |
From $59/mo · Sandbox free demo + free self-host | Free (500 runs/mo) · Enterprise custom (per-seat) |
|
Pricing confidence How public the numbers are |
Public, partial | Contact only |
|
Billing Primary billing axis |
credits | runs |
|
Variable cost Workload / overage exposure |
Medium variable cost | Medium variable cost |
|
Free tier / trial Try before you buy |
Free tier
|
Free tier
|
|
Buying motion Self-serve vs sales call |
Mixed | Mixed |
More comparisons with Dify or StackAI
Other matchups in agent builders
Not the pairing you were after? These compare a different set of agent builders on the same 14 capabilities.

