← Back to home
Comparison · PM

Tracecat vs Wakapi

A side-by-side editorial comparison of Tracecat and Wakapi — release velocity, themes, recent moves, and the top alternatives to consider.

Tracecat vs Wakapi: at a glance

FeatureTracecatWakapi
SectorPMPM
Velocity score7.52.5
Sparks · 30d00
Top themesagentic-soar, sandbox-isolation, mcp, case-managementtime-tracking, self-hosted, oidc, auth-bypass
Last editorial update4d ago1h ago
WebsiteVisit →Visit →

What is Tracecat?

Tracecat is turning case comments into an agent console while it hardens the sandbox around them

Tracecat is deep in a beta.52 release-candidate train, eight RCs in, following the beta.51 release that made the Action Gateway mandatory. Two threads dominate: agents are becoming addressable from inside case comments, and the sandbox that runs them is being bounded — socket budgets, registry artifact caches, egress filtering. The product is a security automation platform steadily converting its agent story from a feature into the primary interaction surface.

Read the full Tracecat trajectory →

What is Wakapi?

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

Read the full Wakapi trajectory →

Tracecat vs Wakapi: editorial side-by-side

T7.5

Tracecat is turning case comments into an agent console while it hardens the sandbox around them

◆ Current state

Tracecat is deep in a beta.52 release-candidate train, eight RCs in, following the beta.51 release that made the Action Gateway mandatory. Two threads dominate: agents are becoming addressable from inside case comments, and the sandbox that runs them is being bounded — socket budgets, registry artifact caches, egress filtering. The product is a security automation platform steadily converting its agent story from a feature into the primary interaction surface.

◆ Where it's heading

The agent work is moving from 'you can invoke an agent' to 'the agent lives in the case thread' — mentions, session chat, activity shown inline, and now MCP integration references correlated on workspace pull. Running alongside it is a sustained isolation effort: every second RC raises or filters the NSTUN socket budget, which reads as capacity being tuned under real agent load rather than a one-off fix. The UI is catching up too, with a properties rail and editor redesign borrowed from Linear's density.

◆ Prediction

Expect beta.52 to land as a final release with agent-in-comments as its headline, and the NSTUN capacity raises to stop once the ceiling holds. Whether the MCP reference correlation grows into full workspace-level integration mapping is not yet visible in these entries.

W2.5

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

◆ Current state

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

◆ Where it's heading

The direction is a self-hosted tool making itself deployable somewhere other than one developer's server. External identity providers, an option to disable local login entirely, per-key credentials and a container that runs as a nonroot user are the requirements that come from someone else's security review. The 2.17.6 bypass sits awkwardly against that: a cache keyed without proper namespacing is exactly the class of bug that multi-tenant deployment surfaces, which suggests the auth work is now being exercised harder than the code was written for. Releases have also thinned to roughly one a month from a much faster earlier cadence.

◆ Prediction

The identity and packaging thread is the only sustained one in this feed, so further hardening in that area is the most likely continuation; the sparse release notes make anything more specific guesswork.

Alternatives to Tracecat and Wakapi

Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Tracecat or Wakapi.

See all Tracecat alternatives → · See all Wakapi alternatives →

Recent activity from Tracecat and Wakapi

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 7h agoWakapiCritical auth bypass from a shared cache key namespace
  2. 4d agoTracecatMCP integration refs correlate on workspace pull
  3. 4d agoTracecatLinear-style properties rail lands with an editor and picker redesign
  4. 4d agoTracecatComment-invoked agent sessions get simpler, mentions get docs
  5. 5d agoTracecatTracecat beta.52-rc.5 bounds the registry artifact cache and adds custom field display names
  6. 6d agoTracecatTracecat beta.52-rc.4 lets agents be invoked from comment mentions
  7. 6d agoTracecatTracecat beta.52-rc.3 enforces filtered NSTUN egress
  8. 1mo agoWakapiRelease 2.17.5
  9. 2mo agoWakapiRelease 2.17.4
  10. 4mo agoWakapiSecurity fix, relay endpoint dropped, summaries may need regenerating
  11. 5mo agoWakapiDistroless nonroot container image; SQLite permissions need fixing
  12. 6mo agoWakapiOIDC-only login mode disables local accounts

Frequently asked questions

What is the difference between Tracecat and Wakapi?

They serve adjacent needs but don't currently overlap on shipped themes. Tracecat is currently shipping more aggressively (velocity 7.5 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Tracecat better than Wakapi?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Tracecat is currently shipping more aggressively (velocity 7.5 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.

What are the best alternatives to Tracecat?

Top Tracecat alternatives in PM are ranked by recent ship velocity. Browse the "Tracecat alternatives" section above for the current picks, or visit /alternatives/tracecat for the full list with editorial commentary on each.

What are the best alternatives to Wakapi?

Top Wakapi alternatives in PM are ranked by recent ship velocity. Browse the "Wakapi alternatives" section above for the current picks, or visit /alternatives/wakapi for the full list with editorial commentary on each.