← Back to home
Comparison · PM

Wakapi vs Tracecat

A side-by-side editorial comparison of Wakapi and Tracecat — release velocity, themes, recent moves, and the top alternatives to consider.

Wakapi vs Tracecat: at a glance

FeatureWakapiTracecat
SectorPMPM
Velocity score2.56.3
Sparks · 30d01
Top themestime-tracking, self-hosted, oidc, auth-bypasssecurity-automation, soar, ai-agents, mcp
Last editorial update28d ago3h ago
WebsiteVisit →Visit →

What is Wakapi?

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

Read the full Wakapi trajectory →

What is Tracecat?

Tracecat 1.0 stable lands with workspace entitlements, SSRF hardening, and an open-source MCP skills catalog

Tracecat shipped version 1.0.0 stable on September 16, marking the first production-commitment release for the open-source security automation platform. The release draws a commercial boundary via multi-workspace entitlements, blocks SSRF in MCP and LLM agent requests, expands case management with filtered aggregation, and open-sources its preset skills and MCP catalog connectors. The 1.0 stable tag reflects a deliberate signal: the core architecture is settled enough for production commitments.

Read the full Tracecat trajectory →

Wakapi vs Tracecat: editorial side-by-side

W2.5

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

◆ Current state

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

◆ Where it's heading

The direction is a self-hosted tool making itself deployable somewhere other than one developer's server. External identity providers, an option to disable local login entirely, per-key credentials and a container that runs as a nonroot user are the requirements that come from someone else's security review. The 2.17.6 bypass sits awkwardly against that: a cache keyed without proper namespacing is exactly the class of bug that multi-tenant deployment surfaces, which suggests the auth work is now being exercised harder than the code was written for. Releases have also thinned to roughly one a month from a much faster earlier cadence.

◆ Prediction

The identity and packaging thread is the only sustained one in this feed, so further hardening in that area is the most likely continuation; the sparse release notes make anything more specific guesswork.

T6.3

Tracecat 1.0 stable lands with workspace entitlements, SSRF hardening, and an open-source MCP skills catalog

◆ Current state

Tracecat shipped version 1.0.0 stable on September 16, marking the first production-commitment release for the open-source security automation platform. The release draws a commercial boundary via multi-workspace entitlements, blocks SSRF in MCP and LLM agent requests, expands case management with filtered aggregation, and open-sources its preset skills and MCP catalog connectors. The 1.0 stable tag reflects a deliberate signal: the core architecture is settled enough for production commitments.

◆ Where it's heading

Tracecat is following an open-core model—OSS core, paid multi-tenancy—with 1.0 as the line where that separation becomes contractual. The SSRF hardening in agentic contexts and the open-sourced MCP catalog are complementary moves: more trust for AI agents running in production, more community-contributed integrations via MCP. Case management (aggregation actions, rich text comments) is getting substantial investment, pointing toward a more complete SOC workflow tool.

◆ Prediction

The next major push will be an expanded MCP connector catalog—now that it's open-source, community PRs will accelerate the integration count. Expect deepening case management automation (aggregation actions are just in; richer query and reporting capabilities follow) alongside further commercial tier differentiation.

Alternatives to Wakapi and Tracecat

Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Wakapi or Tracecat.

See all Wakapi alternatives → · See all Tracecat alternatives →

Recent activity from Wakapi and Tracecat

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 5h agoTracecatTracecat 1.0.0
  2. 20h agoTracecatTracecat 1.0.0-rc.2
  3. 2d agoTracecatTracecat 1.0 RC1: open-source MCP catalog + workspace entitlements
  4. 4d agoTracecatTracecat 1.0 beta.53 pre-release candidate
  5. 4d agoTracecatTracecat 1.0.0-beta.52
  6. 8d agoTracecatTracecat beta.52 RC24: case field resolver + rich text comments
  7. 28d agoWakapiCritical auth bypass from a shared cache key namespace
  8. 2mo agoWakapiRelease 2.17.5
  9. 3mo agoWakapiRelease 2.17.4
  10. 5mo agoWakapiSecurity fix, relay endpoint dropped, summaries may need regenerating
  11. 6mo agoWakapiDistroless nonroot container image; SQLite permissions need fixing
  12. 7mo agoWakapiOIDC-only login mode disables local accounts

Frequently asked questions

What is the difference between Wakapi and Tracecat?

They serve adjacent needs but don't currently overlap on shipped themes. Tracecat is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Wakapi better than Tracecat?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Tracecat is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.

What are the best alternatives to Wakapi?

Top Wakapi alternatives in PM are ranked by recent ship velocity. Browse the "Wakapi alternatives" section above for the current picks, or visit /alternatives/wakapi for the full list with editorial commentary on each.

What are the best alternatives to Tracecat?

Top Tracecat alternatives in PM are ranked by recent ship velocity. Browse the "Tracecat alternatives" section above for the current picks, or visit /alternatives/tracecat for the full list with editorial commentary on each.