← Back to home
Comparison · PM

Wakapi vs Tracecat

A side-by-side editorial comparison of Wakapi and Tracecat — release velocity, themes, recent moves, and the top alternatives to consider.

Wakapi vs Tracecat: at a glance

FeatureWakapiTracecat
SectorPMPM
Velocity score2.57.5
Sparks · 30d02
Top themestime-tracking, self-hosted, oidc, container-hardeningsecurity-automation, agent-native, mcp, soar
Last editorial update2h ago1d ago
WebsiteVisit →Visit →

What is Wakapi?

Wakapi is quietly rebuilding itself around the login and container requirements teams ask for.

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has also carried a responsibly disclosed security fix and dropped its relay endpoint. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

Read the full Wakapi trajectory →

What is Tracecat?

Tracecat is handing its agents the workflow engine, then hardening everything around them.

Tracecat ships release candidates on the 1.0.0-beta.51 line every three to five days, and the notes are dense and well-sectioned. The recent run is split almost evenly between agent capability — batch approvals, a Mistral provider, custom model catalog IDs, deferred tool loading in the Claude runtime, and now workflow execution tools — and the isolation work that makes those agents safe to run, including row-level-security session pooling, expanded audit logs, and a rule that inbound auth is no longer forwarded to user MCP servers. Security integrations keep arriving alongside: Google Security Command Center, SentinelOne alert lifecycle actions, Elastic API templates, Scanner YAML templates.

Read the full Tracecat trajectory →

Wakapi vs Tracecat: editorial side-by-side

W2.5

Wakapi is quietly rebuilding itself around the login and container requirements teams ask for.

◆ Current state

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has also carried a responsibly disclosed security fix and dropped its relay endpoint. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

◆ Where it's heading

The direction is a self-hosted tool making itself deployable somewhere other than one developer's server. External identity providers, an option to disable local login entirely, per-key credentials and a container that runs as a nonroot user with no shell are the requirements that come from someone else's security review, not from a hobbyist's wishlist. The corresponding cost is visible too: dropped MSSQL support and a Docker base change that forces SQLite users to fix directory permissions by hand.

◆ Prediction

The identity and packaging thread is the only sustained one in this feed, so further hardening in that area is the most likely continuation; the sparse release notes make anything more specific guesswork.

T7.5

Tracecat is handing its agents the workflow engine, then hardening everything around them.

◆ Current state

Tracecat ships release candidates on the 1.0.0-beta.51 line every three to five days, and the notes are dense and well-sectioned. The recent run is split almost evenly between agent capability — batch approvals, a Mistral provider, custom model catalog IDs, deferred tool loading in the Claude runtime, and now workflow execution tools — and the isolation work that makes those agents safe to run, including row-level-security session pooling, expanded audit logs, and a rule that inbound auth is no longer forwarded to user MCP servers. Security integrations keep arriving alongside: Google Security Command Center, SentinelOne alert lifecycle actions, Elastic API templates, Scanner YAML templates.

◆ Where it's heading

The direction is an agent that operates the SOAR platform rather than sits beside it. Agents gained model choice, then approval batching, then MCP tooling, and the newest candidate gives them workflow execution tools — the point at which an agent can trigger the automation the platform exists to run. Every step of that expansion is paired with a constraint shipped in the same release, which is why run_python was pulled from agent tools and nested action execution was fenced. Making the Action Gateway mandatory in July was the architectural version of the same instinct: one enforced path for anything an action touches.

◆ Prediction

The beta.51 candidate count suggests a 1.0.0 cut is being stabilized toward rather than freely developed on, so expect the remaining candidates to narrow to fixes. On the agent side, workflow execution tools landing with an AI security architecture in the same release points to approval and audit controls specifically scoped to agent-triggered workflow runs.

Alternatives to Wakapi and Tracecat

Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Wakapi or Tracecat.

See all Wakapi alternatives → · See all Tracecat alternatives →

Recent activity from Wakapi and Tracecat

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 1d agoTracecatAgents get workflow execution tools and a Claude deferred-tool runtime
  2. 7d agoTracecatAgent MCP servers stop receiving forwarded inbound auth
  3. 12d agoTracecatBatch agent approvals, Mistral provider, custom model catalog IDs
  4. 15d agoTracecatMCP OAuth resource override and SentinelOne contract fixes
  5. 19d agoWakapiRelease 2.17.5
  6. 19d agoTracecatAction Gateway becomes mandatory in beta.51-rc.8
  7. 22d agoTracecatGPT-5.6 catalog models and stdio MCP connection testing
  8. 2mo agoWakapiRelease 2.17.4
  9. 4mo agoWakapiRelease 2.17.3
  10. 5mo agoWakapiRelease 2.17.2
  11. 6mo agoWakapiRelease 2.17.1
  12. 7mo agoWakapiRelease 2.17.0

Frequently asked questions

What is the difference between Wakapi and Tracecat?

They serve adjacent needs but don't currently overlap on shipped themes. Tracecat is currently shipping more aggressively (velocity 7.5 vs 2.5), with 2 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Wakapi better than Tracecat?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Tracecat is currently shipping more aggressively (velocity 7.5 vs 2.5), with 2 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.

What are the best alternatives to Wakapi?

Top Wakapi alternatives in PM are ranked by recent ship velocity. Browse the "Wakapi alternatives" section above for the current picks, or visit /alternatives/wakapi for the full list with editorial commentary on each.

What are the best alternatives to Tracecat?

Top Tracecat alternatives in PM are ranked by recent ship velocity. Browse the "Tracecat alternatives" section above for the current picks, or visit /alternatives/tracecat for the full list with editorial commentary on each.