Dify and Flowise are no longer two live open-source projects being compared on features: Dify is shipping — release 1.17.1 on September 10, 2026, last push September 18, 2026 — while the FlowiseAI/Flowise repository is archived, last pushed August 13, 2026, and its maintainers set End of Life at August 31, 2026. For a new build that decides it. For an existing Flowise deployment it does not, because the part that ended is the open-source repository, not the hosted service.
That distinction is the whole reason this page exists, and almost every comparison written before July 2026 gets it wrong in one direction or the other. The sunset timeline has exactly one column describing consequences, and its header reads "Impact on OSS Repository". Nothing in it mentions Flowise Cloud. On September 19, 2026 the marketing site carried the banner "We're sunsetting Flowise" and was still selling Starter and Pro, with a first-month-free call to action on the Starter card. So: the code is archived and at end of life; the hosted service has no announced end and is still on sale. Both halves are true at once.
What actually ended, and what did not
| Signal | Flowise | Dify |
|---|---|---|
| Repository | Archived, last push August 13, 2026, 55,467 stars | Not archived, last push September 18, 2026, 156,349 stars |
| Latest release | 3.1.4, published July 29, 2026 — final | 1.17.1, published September 10, 2026 |
| Vendor-stated end date | End of Life August 31, 2026, for the open-source project | None |
| Security reports | No longer accepted since August 3, 2026 | Accepted |
| Published packages | npm 3.1.4 live, 0 of 104 versions deprecated; Docker repository reports "active" | Published and current |
| Hosted service | Still sold; no shutdown date published | Sold as Dify Cloud |
| Ownership | Acquired by Workday, announced August 14, 2025 | LangGenius, Inc. |
Sources, all checked September 19, 2026: the Flowise repository and Dify repository through the GitHub API, the maintainers' announcement, the npm registry, Docker Hub, and Workday's acquisition release. Two details deserve their own sentence. The two published timelines disagree about the archival date — the sunset page schedules it for August 10, 2026 and the maintainers' own discussion post for August 13, 2026 — and GitHub settles it: the repository page, and those of the docs and embed repositories, each read "archived by the owner on Aug 13, 2026". And the announcement's statement that packages and images "will be marked deprecated" has not happened: at that check neither the npm package nor the Docker repository carried a deprecation flag. That is a stated intention, not a fact about the packages.
The security picture deserves its own paragraph, and it is worse than the archive notice suggests. Flowise stopped accepting new vulnerability reports on August 3, 2026 — its SECURITY.md says so in one line — a day before twenty-six advisories were published against it, ten of them critical. All twenty-six carry a patched version — twenty-five say 3.1.3 and one says 3.1.4 — so none of them leaves the final release exposed. Five published in the following week do: CVE-2026-67620, CVE-2026-67621, CVE-2026-67622, CVE-2026-70636 and CVE-2026-71962 each describe Flowise through 3.1.4 as affected, and each lists its patched version as unknown (GitHub advisories, checked September 19, 2026; that enumeration stopped at the 100 records the listing returned, so five is a floor rather than a total). An unpatched authentication bypass and an unauthenticated file-download path are in that set. Anyone staying on 3.1.4 is carrying them.
One more piece of care, because search results mix them: flowise.io is an unrelated work-management company and flowise.co.za is an unrelated South African software agency. Neither has anything to do with this product, and neither's pricing belongs on this page.
Which one should you pick
| Your situation | Pick | Why, specifically |
|---|---|---|
| Starting a new visual RAG or agent workflow today | Dify | It is the only one of the two still shipping releases — 1.17.1 landed on September 10, 2026. Starting on an archived builder buys you a migration you have not scheduled. |
| Your gateway speaks the Anthropic Messages protocol | Dify | Its first-party Anthropic plugin carries an optional anthropic_api_url credential. Flowise's Anthropic node has no URL field at all, so nothing in its builder points that protocol anywhere but Anthropic. |
| Flows are finished, deployed and pinned | Stay on Flowise only behind your own controls | 3.1.4 still installs, but five August 2026 advisories describe it as affected with no patched version, so an internet-facing instance is the case to move first. Moving costs a rebuild, not a file conversion. |
| You need many people in one workspace | Depends on the shape | Dify Cloud prices per workspace and caps members per tier — 3 on Professional, 50 on Team. Flowise Cloud Pro includes 5 users and charges $15 per user beyond that. Count your seats before comparing headline prices. |
| You must run it multi-tenant for your own customers | Neither, without a licence conversation | Dify's modified Apache 2.0 forbids operating a multi-tenant environment without written authorisation, one tenant meaning one workspace. Flowise is Apache 2.0 except its enterprise directory, which is under a separate commercial licence — and whether that licence can still be bought from a winding-down company is unverified. |
| You want the smallest possible model bill | Neither decides it | Both are builders, not billers. No published Flowise Cloud plan bundles model credits; Dify bundles message credits and its own tooltip says you switch to your key once they are used up. The rate you pay is set by whichever provider the key belongs to. |
The execution models also differ in a way the feature lists flatten. Flowise's cloud plans meter predictions per month — 100, 10,000, 50,000 by tier — plus storage. Dify's meter message credits against bundled model usage, after which, in the pricing page's own words, you can switch to your own API key. Whether a Flowise prediction run on your own API key still draws down that quota is not stated on the pricing section and was not tested here; if you are near a tier boundary, verify it in your own account before you budget.
Published plans and prices
| Flowise Cloud plan | Published price | What the plan lists |
|---|---|---|
| Free | $0 / month | 2 flows and assistants; 100 predictions per month; 5MB storage; evaluations and metrics; custom embedded chatbot branding; community support |
| Starter | $35 / month | Everything in Free; unlimited flows and assistants; 10,000 predictions per month; 1GB storage; community support |
| Pro | $65 / month, plus $15 per user beyond 5 | Everything in Starter; 50,000 predictions per month; 10GB storage; unlimited workspaces; 5 users; admin roles and permissions; priority support |
| Self-hosted | $0 | Apache 2.0, except packages/server/src/enterprise and files such as IdentityManager.ts, which are under a separate commercial licence. You pay hosting and your model provider. |
Read from the Pricing section of the Flowise homepage on September 19, 2026, which is the only public price source for this product — flowiseai.com/pricing redirects to a login form and shows no prices at all. The self-hosted licence carve-out comes from the repository's LICENSE.md, which matters because the sunset page's "the Apache 2.0 licensed code is yours" is true but partial: the enterprise authentication and role layer is not covered by it.
| Dify plan | Published price | What the plan lists |
|---|---|---|
| Sandbox | Free | 200 message credits; 1 workspace; 1 member; 5 apps; 50 knowledge documents; 50MB knowledge storage; 3,000 trigger events; 30 days log history; 5,000 API rate limit per month |
| Professional | $590 per workspace / year, shown as $59 / month on the page's own monthly toggle | 5,000 message credits per month; 3 members; 50 apps; 500 knowledge documents; 5GB storage; 20,000 trigger events per month; unlimited log history |
| Team | $1,590 per workspace / year, shown as $159 / month on the toggle | 10,000 message credits per month; 50 members; 200 apps; 1,000 knowledge documents; 20GB storage; unlimited trigger events; unlimited log history |
| Community (self-hosted) | Free | Core features from the public repository; single workspace; under the modified Apache 2.0 Dify licence |
| Enterprise | Custom, contact sales | Commercial licence authorisation; multiple workspaces and enterprise management; single sign-on; advanced security and controls |
Read from dify.ai/pricing on September 19, 2026. Three caveats carried from that page. It states "Prices exclude applicable taxes, which may be added at checkout". The annual figures are what the page renders by default; the monthly figures come from the page's own monthly toggle and were not confirmed at a checkout. And the pricing page calls the allowance "message credits" while the documentation calls it "AI credits" — one quota, two names, not two allowances. The per-model credit rate is not published on the page fetched here, so credits cannot be converted into tokens on this page.
The connection boundary, field by field
Both products are bring-your-own-key, and both take an OpenAI-compatible base URL. The differences that bite are narrower than the marketing pages suggest.
| What you are wiring | Dify | Flowise |
|---|---|---|
| OpenAI-compatible chat | First-party OpenAI-API-compatible plugin, added one model at a time: model (full name), endpoint_url labelled "API Base URL" and required, api_key, and a required context_size | The OpenAI Custom Model node: Model Name as free text, Base Path, and Base Options for default headers, with the key on an optional credential |
| Anthropic Messages endpoint | Supported: the first-party Anthropic plugin exposes an optional anthropic_api_url credential beside the key | No field for it: ChatAnthropic.ts defines no base URL, API URL or client-options input at all, so the builder offers no way to redirect it |
| Where the model list comes from | Typed by hand per model; the compatible plugin is customizable-model only, so there is no catalog to go stale | A dropdown the loader fetches from the archived repository's main branch, now frozen; override it with MODEL_LIST_CONFIG_JSON or use the free-text custom node |
| A gateway on localhost or a private range | Not checked here | Refused by default: the custom node runs checkDenyList against a list covering localhost, 10/8, 127/8, 172.16/12, 192.168/16 and more, unless HTTP_SECURITY_CHECK=false |
| Version path in the base URL | For chat models the plugin appends only the operation path, so the version segment must be in your base URL | The base path is passed straight to the client as baseURL, so it must include the version segment too |
Field names and behaviour read on September 19, 2026 from the compatible provider schema, the Anthropic provider schema, ChatOpenAICustom.ts, ChatAnthropic.ts and httpSecurity.ts, with the dropdown behaviour from modelLoader.ts and the frozen models.json it fetches. For Kunavo those fields take https://api.kunavo.com/v1 on the OpenAI-compatible route — see the chat endpoint reference and authentication — and the separate origin-form value documented under the Anthropic base URL for Dify's Anthropic plugin. Kunavo publishes those as configuration references and has not runtime-tested either product against them, so treat the first call as the test.
Two capability notes that cause runtime surprises rather than setup errors. Dify's compatible plugin makes you declare context size, tool-call style and the vision, audio, video and document flags by hand; a wrong value fails later as a request error, not as a configuration error. It also validates a new model by issuing a real one-word request to your endpoint, so an endpoint that cannot complete a tiny call will not save — the error reference is the right place to start if that step fails. On Dify Cloud, spreading requests across several keys for the same model is badged Professional and Team in the documentation; whether that feature exists on the self-hosted Community edition is not stated on its documentation page and is unverified here.
One boundary that applies to both, and to Kunavo specifically: Kunavo does not serve embedding, speech-to-text or text-to-speech models. Both builders have slots for them — Dify's compatible plugin covers five model types, and every knowledge base needs an embedding step — so those slots point at a different provider or at something you run locally. Only the chat-model slots are what a Kunavo key fills. That also sidesteps an unresolved question in Dify's own material, where the plugin README and its current source disagree about whether a version path is appended for non-chat model types.
Migration cost, honestly
Both products export, and neither exports into the other. Dify exports an app as DSL in YAML, carrying app configuration, workflow orchestration and node settings, model parameters and prompt templates, and knowledge-base connections but not the knowledge data itself; third-party API keys are deliberately excluded, as are usage logs (app management docs, September 19, 2026). Flowise Cloud exports selected data as JSON and, in its own words, excludes credentials, which must be recreated (migration docs — note this is the older Cloud V1 to V2 guide and predates the sunset, so it is not a sunset migration path).
No converter between the two formats was found. That is the absence of a search result rather than proof that none exists, but plan on rebuilding each flow node by node and re-entering every credential. For a team with a handful of flows this is an afternoon; for a library of fifty it is the dominant cost of the decision and it dwarfs the subscription difference. Forking is what the maintainers themselves suggest, on both the sunset page and the announcement — which means inheriting the unpatched advisories above along with the code.
A worked model-cost estimate
This is illustrative token arithmetic, not a measured task cost and not a bill ceiling. Assume one knowledge-assisted workflow run sends 18,000 uncached input tokens — system prompt, retrieved chunks and a short history — and returns 700 output tokens, and that you run 1,000 of them in a month. Rates are live Kunavo catalog prices per million tokens.
| Model | Input / output per 1M | Estimate per run | Estimate for 1,000 runs |
|---|---|---|---|
| Claude Haiku 4.5 | $0.40 / $2.00 | $0.0086 | $8.60 |
| Gemini 3.8 Flash | $0.525 / $2.625 | $0.0113 | $11.29 |
| GPT-5.6 Terra | $0.70 / $4.20 | $0.0155 | $15.54 |
| Claude Sonnet 4.6 | $1.20 / $6.00 | $0.0258 | $25.80 |
| Claude Opus 5 | $2.00 / $10.00 | $0.0430 | $43.00 |
Read it against the platform line rather than instead of it. Under these assumptions the spread between the cheapest and the most expensive model in this lane is $34.40 a month — larger than the $35-versus-$59 platform difference in either direction, which is why model choice, not builder choice, is usually where the money is. Retrieved-context size is the other lever: these runs are input-dominated, so trimming chunks moves the total more than trimming answers does. AI cost optimization covers that method, and RAG implementation covers where the retrieval step belongs.
Kunavo's catalog amount is a billing floor rather than a cap: when the upstream reports its charge, the bill is the greater of catalog cost and upstream cost times the applicable markup. Cache charges, embeddings and external tools sit outside this example. The minimum top-up is $10 in prepaid credit, a funding minimum rather than a task fee or a subscription — see billing details and usage for what the account records per call.
Where to go from here
If you are choosing the builder, the short version is: new work goes to Dify, an existing Flowise deployment can keep running but is now carrying advisories nobody will patch, and the protocol you need decides the rest. If you are choosing what sits behind it, the agent API directory records the connection boundary for both — Flowise is listed in its archived section — and the OpenAI-compatible API guide covers the mechanism both use. LiteLLM alternatives is worth a look if you are comparing gateways rather than builders. Create a Kunavo account when you want a key to put in either tool, then run one bounded flow and read the charge your account recorded for it before you scale.
FAQ
Is Flowise dead?
The open-source project is finished; the hosted service has not been declared finished. The FlowiseAI/Flowise repository on GitHub is archived, with its last push on August 13, 2026, and the maintainers' published timeline sets End of Life at August 31, 2026, when official core-team presence in Discord and GitHub concludes. The sibling docs and embed repositories carry the same archival notice, and the maintainers point users at forking the repository rather than at any successor project. Separately, flowiseai.com was still selling the Starter and Pro cloud plans on September 19, 2026, with a sunset banner on the same page. No cloud shutdown date, data-export deadline or refund policy has been published anywhere reachable, so treat the hosted service as running-until-told-otherwise rather than as either safe or ended.
Should I migrate from Flowise to Dify?
Migrate if you need the project to keep receiving fixes, if you need an Anthropic Messages endpoint, or if new model names need to appear in your builder. Staying put is defensible for flows that are finished, deployed and pinned to an image, but it is not a free option: the final release 3.1.4 still installs, and five advisories in GitHub's listing — CVE-2026-67620, CVE-2026-67621, CVE-2026-67622, CVE-2026-70636 and CVE-2026-71962, all published in August 2026 — describe Flowise through 3.1.4 as affected and list no patched version. The cost of moving is a rebuild rather than a file conversion: no converter was found between Flowise's exported flow JSON and Dify's DSL YAML, and absence of one is not the same as proof that none exists. Budget the rebuild before the subscription.
Can I keep running my existing Flowise deployment?
Technically yes, and the risk is concrete rather than theoretical. As of September 19, 2026 the npm package flowise still resolves to 3.1.4 with none of its 104 versions marked deprecated, and the flowiseai/flowise Docker repository still reports active status — both contrary to the announcement, which said packages and images would be marked deprecated. The twenty-six advisories published on August 4, 2026 — ten of them critical — all name a patched version at or below the final release: twenty-five list 3.1.3 and one lists 3.1.4, so none of them reaches an instance running 3.1.4. Five published the following week do: CVE-2026-67620, CVE-2026-67621, CVE-2026-67622, CVE-2026-70636 and CVE-2026-71962 each describe Flowise through 3.1.4 as affected and carry no patched version, and they cover an authentication bypass on an OAuth2 refresh route, an unauthenticated file-download path, two authorisation gaps and an SSRF-guard bypass. That listing was bounded at the 100 records GitHub returned, so treat five as the floor. The project stopped accepting new security vulnerability reports on August 3, 2026, so nothing found from here on gets a vendor fix. Pin the image, keep it off the public internet, and own the patching yourself.
Is Dify cheaper than Flowise?
Not on the platform line. Flowise Cloud lists Free at $0, Starter at $35 per month and Pro at $65 per month plus $15 per user beyond five. Dify Cloud lists Sandbox free, Professional at $590 per workspace per year and Team at $1,590 per workspace per year, with the page's own monthly toggle showing $59 and $159; taxes are excluded and these were read from the pricing page rather than from a checkout. Both have a free self-hosted edition, so the platform line can be zero on either side. The model bill is the larger number for most teams and is independent of both: no Flowise Cloud plan on the published pricing section bundles model credits, while every Dify Cloud tier bundles message credits whose tooltip says that once they are used up you can switch to your own API key.
Can one API key serve both Dify and Flowise?
For OpenAI-compatible chat models, yes — both accept a base URL, a free-text model name and a key, so the same credentials can be entered in each. The boundary is the Anthropic Messages protocol. Dify's first-party Anthropic plugin exposes an optional API URL credential beside the API key, so an Anthropic-compatible endpoint can be pointed at it. Flowise's Anthropic node has no base URL, API URL or client-options field of any kind, so there is nothing in the builder to point it somewhere else, and the OpenAI-compatible node is the route that is actually documented. Whether an environment-level override on the underlying client would redirect it was not tested here, so read this as a missing field rather than a proven impossibility. One more Flowise constraint: its OpenAI Custom Model node checks the base URL you give it against a deny list covering localhost and the private IP ranges, so a gateway on your LAN is refused there unless you set HTTP_SECURITY_CHECK=false.
Will new models still appear in Flowise's model dropdown?
No. Flowise's model loader fetches models.json from the archived repository's main branch by default, and that branch is frozen. The list is already behind: its Anthropic entries stop at claude-opus-4-7, with no claude-opus-5, and its OpenAI entries stop at the gpt-5.5 generation. The escape hatch in that same loader is the MODEL_LIST_CONFIG_JSON environment variable, which points it at a URL or a local file you maintain. The other way around it is the OpenAI Custom Model node, whose model name is a plain text field rather than a dropdown, which is why that node is the one a gateway is normally wired into.
Repository status, releases, package registries, pricing pages, plugin schemas and node source for both products were fetched and read on September 19, 2026; the specific checks are listed inline beside each claim. Kunavo has run no compatibility test against Dify or Flowise — everything about either product here is transcribed from its own documentation, source and public APIs. Kunavo token rates come from the live catalog, and every dollar example on this page is illustrative token arithmetic.