Moxo vs Kissflow in 2026: What an Outside Approver Costs, and What the Record Proves
Moxo and Kissflow both sell approvals to people who do not write code, and each wins one round outright: Moxo's Web and Headless SDKs run the approval inside the buyer's own product, under the buyer's own sign-in. Kissflow's portal audit log stamps every event with an actor, a device and an IP, where Moxo publishes no field list. Both answers are quoted, not priced, and both meters punish a one-step request sent to hundreds of clients. Cost, the decision record, rejection routes, AI metering and governance, verified 14 to 23 September 2026.
The Bottom Line: For the client, Moxo; for the auditor, Kissflow. Moxo's Web and Headless SDKs put the approval inside the buyer's own product, texted links can land on the buyer's own URL rather than Moxo's, and its meter counts flows rather than the people invited. Kissflow stamps every portal event with an actor, a device and an IP, promises "No surcharges for AI or API usage", and halts and resumes parallel branches around a rejection. Both answers for the outsider are Enterprise quotes, and Moxo's published Team plan, "$5,000/yr" for "100 flows/yr", carries neither the SDKs nor the audit log.
Overview
These two are a close match. Moxo and Kissflow both sell process-shaped work to people who do not write code, and both ship an approval as a first-class thing. Both talk about external users, too. They part on two linked questions: what an outside approver costs you, and what the record proves about them afterwards.
An earlier guide, Client Portals vs Workflow Orchestration, asks whether a whole category fits and puts both of these on the orchestration side of that line. This page takes the next question, in five scored rounds and one draw. Moxo's side rests on its legal and pricing pages, its API reference and synthetic AutomationAtlas builder tests on 14 and 15 September 2026; Kissflow's rests on its published documentation, pricing page, help centre and privacy policy, read 21 September 2026.
Company Snapshot
| Moxo | Kissflow | |
|---|---|---|
| Founded | Predecessor Moxtra "co-founded in 2012" (PR Newswire, June 2021) | "At the 2012 Google IO, Kissflow was launched"; predecessor OrangeScape dates to 2003 (about-us page) |
| Legal entity | Moxo, Inc., San Francisco (Terms and Conditions, 17 Sep 2026) | Kissflow Inc., Wilmington, Delaware; group company OrangeScape Technologies registered in Chennai (privacy policy, 21 Sep 2026) |
| Customers | No count in the sources read (21 Sep 2026) | "Join 10,000+ companies already using Kissflow"; "50+ Fortune 500 companies" (pricing page, 21 Sep 2026) |
| Funding / valuation | Private company; third-party totals conflict (14 Sep 2026) | No figure on the pages read (21 Sep 2026) |
| Recent signal | Team listed at 100 flows/yr in the 10 Sep 2026 archive capture, against 250 on 26 Aug | Pricing page publishes no plan price, offering "Fixed annual agreements" (21 Sep 2026) |
The Core Trade-Off: Where the Client Stands Goes to Moxo, Through Its SDKs
Moxo wins where the client stands, and it wins by knockout. Moxo ships a Web SDK and a Headless SDK, so the approval can run inside your own product, under your own sign-in, with the engine out of sight; moxo.com/pricing lists "Moxo SDK (Embed)" on Enterprise. Partner notification routing now covers every channel, so a texted SMS or WhatsApp link lands on your URL rather than Moxo's (developers.moxo.com changelog, read 23 September 2026). That is not a better link. It moves the client's side of the process onto ground you control.
Kissflow's answer is a portal Kissflow hosts. The outsider signs in to something Kissflow runs, on the Enterprise plan, with a soft limit of 10 portals raised by contacting support (help centre, read 21 September 2026). Kissflow does well for outsiders who come back every week: each holds a named portal account, and every action ties to it. Both answers are Enterprise quotes, so this round is one sales conversation against another.
Moxo's default route, without the SDKs, gives the outsider a user record, kind external and status ACTIVE, but never a login. They reach an assigned task through a Magic Link, and in synthetic runs on 14 and 15 September 2026 Moxo's audit log recorded that actor as "Public link". Where the same outside people return week after week and each action must tie to a named account, that label is the trade you would be making, and the audit log itself starts on the custom-quoted Scale plan.
The Cost of One More Outside Approver Goes to Moxo
Moxo wins the cost of one more outside approver. Its meter is the flow, not the person: Team is "$5,000/yr" for "100 flows/yr · $100 of AI/yr · Unlimited seats", and nothing on the pricing page or in the Description of Services charges for an outside recipient (read 23 September 2026). A process with twelve outside participants spends the same single flow as a process with one, so the design rewards a few rich processes with many participants.
Kissflow's meter is the person, and it can run out. Its help centre says an invited portal user is activated when "there are available user licenses", and that where there is a shortage "the invited user will remain inactive and unable to sign in to the portal"; "if you're out of licenses, contact support to buy more licenses". Kissflow's portal overview says "Portal eliminates the need to add external users to your Kissflow account", which is true of the main account and easy to misread as free.
Moxo's catch is light use and a long tail of simple processes: at Team's annual price, 20 flows a year works out at $250 each (AutomationAtlas arithmetic). Kissflow's pool can at least be cycled, because a deactivated user's licence is revoked back to it.
Both Meters Punish the Campaign, in Different Ways
Call this round a draw. A case is one client and many steps over weeks: an onboarding, a claim, a disputed invoice. A campaign is one request to hundreds of clients at once, like the annual KYC refresh or a re-signed engagement letter. Most firms buying either product run both shapes, and the two meters price them so differently that you should count your mix before either demo.
Moxo counts a campaign one recipient at a time. Its bulk-start endpoint creates "one flow per recipient" (developers.moxo.com/v1/openapi.json, read 23 September 2026), and the API sits on Scale, whose allowance is 500 flows a year, so a single 400-client refresh spends four-fifths of it. On Team's 100 the same campaign does not fit at all, while a twelve-step onboarding with six participants is still one flow.
Kissflow counts people, and its pool can be cycled: a portal user's licence "gets revoked after deactivation", which frees it for the next invitee, so a patient admin can move 400 clients through 50 licences in waves. Read the rest of that help-centre sentence before you plan on it. The user's data "is retained temporarily in our systems before eventual deletion", and the article does not say whether that includes what they submitted. For a KYC refresh the submission is the record, so get that answer in writing before you cycle a single licence.
The Evidence Behind Each Event Goes to Kissflow, Clearly
Kissflow wins the evidence round by knockout, and it is the clearest win either product has here. Its portal audit log publishes its full field list: Audit ID, Timestamp, Actor, Action, Object, Event category, Platform, IP and Batch ID, one row per event (help centre, read 21 September 2026). Every approval carries a device and a network alongside the name. That is the difference between knowing an approval happened and being able to defend it.
Moxo labels each actor, and labels them well. In synthetic runs on 14 and 15 September 2026, its audit log marked each row with a person's name or with "AI Agent", "System" or "Public link", keeping human, machine and link-borne work separable in one list, and the Description of Services adds that significant actions are "recorded as immutable events" and that "exports carry SHA-256 fingerprints for integrity verification". But Moxo publishes no field list, its legal pages state no retention period (its security page markets a "7+ Year audit trail"), and its audit log starts on Scale.
Kissflow's limit is reach: filtering runs over the last 30 days, or a custom range "within the last 90 days", and the help centre does not say how long the rows are kept.
Choosing the Way Back After a No Goes to Moxo, Narrowly
Moxo takes this round narrowly, because on Moxo the person who says no can choose where the work goes back to. The Approval step offers four named routes on a rejection, "Revise and resubmit", "Let the approver decide", "Run rejection steps" and "End the flow", and in a synthetic template on 15 September 2026 the builder refused to publish "Revise and resubmit" until the steps to reopen had been picked. On Kissflow the send-back is an administrator's act after the fact. Process admins "can reopen completed or rejected items and send them back to a previous step in the workflow", entering a reason, and items "can only be sent back to steps that were previously completed. Skipped steps cannot be selected." The person choosing the return point is not the approver who rejected the work.
Kissflow does better with parallel branches, the behaviour designers most often get wrong on paper: a rejection in one branch stops the item in the others, and reopening the rejected step resumes them all from where they stopped (help centre, read 21 September 2026).
Moxo is shakier there. On 14 September 2026 its own Build with AI called two approvals "independently in parallel", then the publish validator refused the design because the second needed data from a step starting at the same time. The validator was right, but the draft was wrong first.
AI Without a Second Meter Goes to Kissflow
Kissflow takes the AI round by removing the meter. Its pricing page promises "No surcharges for AI or API usage" (read 21 September 2026), a real advantage for anyone who has watched a credit balance decide whether a process runs, even if it sits behind a price nobody outside a sales call has seen. Moxo puts a dollar allowance on AI instead: Team includes "$100 of AI/yr" and Scale "$500 of AI/yr", with no published conversion to the credits the product logs against a flow, so allowance and consumption cannot be reconciled from public pages.
Moxo does well on the terms around its AI. Its Terms and Conditions say "Moxo will not use AI Content to train Moxo's own AI models", and bar its third-party providers from training on that content too. On Enterprise you can also bring agents built elsewhere, "from OpenAI, Anthropic, or your own stack", and run them alongside Moxo's.
Pricing (as of September 2026)
Moxo (from moxo.com/pricing)
Team is "$5,000/yr" for "100 flows/yr · $100 of AI/yr · Unlimited seats", and on 22 September 2026 the page showed no monthly figure for any plan, with every plan's button reading "Book a demo". The header also links "Request free trial", a trial Moxo's team builds around your processes. The smallest paid commitment is therefore a year, which matters to anyone who wanted to run one quarter before deciding. Scale is a "Custom quote" at 500 flows a year, Enterprise is quoted too, and there is no free plan. The audit log, the named agents, Agent Foundry, Webhooks, REST APIs and Connect via MCP all begin on Scale.
Kissflow (from kissflow.com/pricing)
No plan price is published. The page offers "Pricing built around the value you receive", "Fixed annual agreements" and "No surcharges for AI or API usage". It does not name its plans either, which is the odd part, because the help centre does: every article read for this guide carries a plan line, and the portal audit log article's plan line reads "✕ Basic ✓ Enterprise" (read 21 September 2026). The documentation knows there are two tiers. The pricing page prices neither.
Cost Comparison (Estimated Annual)
| Tier | Moxo | Kissflow |
|---|---|---|
| Free tier carrying an external approval | None listed | None listed |
| Entry paid, published | Team, $5,000/yr, annual only | None published |
| Metered unit | Flows a year, plus dollars of AI | Not published; portal users take licences |
| Cost of one more outside approver | Nothing stated; "Unlimited seats" | A licence from a finite pool |
| Plan carrying the record of external actions | Scale (custom quote) | Enterprise (no published price) |
| AI inside the process | "$100 of AI/yr" on Team | "No surcharges for AI or API usage" |
Neither publishes a price for the plan carrying the record of what an outsider did: Moxo puts the audit log on Scale, Kissflow puts portals and the portal audit log on Enterprise. A buyer whose reason for automating is evidence cannot cost that evidence without a sales call.
Editor's Note: Both vendors have an answer to the outside approver, and both answers live somewhere else. Kissflow's is a portal Kissflow hosts and licenses per user. Moxo's default is a task sitting on Moxo. There is a third answer, and it is Moxo's: the Web and Headless SDKs, which moxo.com/pricing lists as "Moxo SDK (Embed)" on Enterprise, put the approval inside your own product, under your own sign-in, with the engine out of sight. For a firm whose clients already log in somewhere every week, that removes a step that is easy to underestimate: teaching a busy counterparty to use a second system. The SDK route sits on Enterprise, with no published price, and we would weigh it against Kissflow's portal audit log, which stamps every event with an actor, a device and an IP. — Rafal Fila, ShadowGen
Governance, Admin Controls, and Compliance
Both vendors' compliance statements need checking against the reports behind them. Moxo's security page says it "is SOC 2 Type II and SOC 3 certified"; its Description of Services says only that "Moxo undergoes SOC 2 Type II auditing". Kissflow's external-portal FAQ promises "compliance with standards like ISO 27001, SOC 2, GDPR, and HIPAA", four standards named without a report named against any of them.
Retention is the gap on both sides, in different shapes. Kissflow publishes what a portal admin can filter, the last 30 days or a custom range within 90, but not how long the rows are kept. Moxo's legal pages carried no retention figure at all when they were read on 15 September 2026, although its security page markets a "7+ Year audit trail". The duty behind all of it falls on you: the EU AI Act as amended by Regulation (EU) 2026/1744, the NIST AI Risk Management Framework and ISO/IEC 42001 place the oversight obligation on the deployer, not the vendor.
Selection Framework
Decide where the outsider should be standing, then on what you would show an auditor.
| Priority | Recommended platform |
|---|---|
| The approval must appear inside your own product, under your own sign-in | Moxo (Web and Headless SDK, Enterprise) |
| Cost that must not grow with the number of outside approvers | Moxo (seats are not the meter; 100 flows a year on Team is) |
| The approver who rejects work chooses where it goes back to | Moxo ("Let the approver decide", one of four named routes) |
| AI terms that rule out training on your content | Moxo (Terms and Conditions) |
| Sign-off by any one, all or a majority of a group | Moxo (documented completion modes) |
| Every approval event stamped with an actor, a device and an IP | Kissflow (portal audit log) |
| The same outsiders return weekly and each needs a named account | Kissflow (portal users) |
| AI inside the process with no second meter | Kissflow ("No surcharges for AI or API usage") |
| A rejection in one parallel branch that must halt and resume the others | Kissflow (documented branch behaviour) |
| A rejected item reopened by an admin and sent to a named earlier step | Kissflow (process administration) |
Tools Mentioned
Related Guides
Moxo vs Camunda 8 in 2026: BPMN User Tasks for Staff, Step Types for Outsiders
Camunda 8 can fix a process under cases already running, since active instances migrate onto a corrected definition and, for Camunda user tasks, "a migrated active user task remains assigned to the same user". Moxo keeps the shared queue that Camunda's Tasklist V2 stops evaluating, with desks that are "a shared inbox that multiple users can pick work from". Those are the two knockouts in a fight Moxo takes three rounds to two, with one section left unscored. Portability, AI review gates and a published price decide the rest, verified 14 to 23 September 2026.
Moxo vs n8n in 2026: Who Runs the Engine and Who Keeps the Record
n8n wins the engine room: Community Edition runs on a self-hosted server at no licence cost, and its code is open to read and change for internal use. Moxo wins the approval itself: its API refuses a step completion from an organisation key, a stalled step has named moves, and its documented deletion keeps the audit rows. Run together, n8n carries the volume and Moxo's flow meter counts only the exceptions. Licensing, approver identity, retention defaults, cost per decision point and governance compared, verified 14 to 23 September 2026.
Moxo vs ServiceNow in 2026: The Outsider as Counterparty, or as Customer
Moxo and ServiceNow split six rounds three apiece: ServiceNow wins on the estate around an approval, Moxo on the outsider inside it. ServiceNow's four sn_aia_ tables make its own agents' tool calls a query, and its free university runs a certification market Moxo's login-only Learning Center cannot match. Moxo gives a rejecting counterparty four named routes, records an override as an override, and makes a new outside approval a template step. Vendor documentation, SEC filings and synthetic tests, read to 23 September 2026.
Related Rankings
Best Human-in-the-Loop Automation Platforms 2026
Eight platforms are ranked here on a single mechanism: how a person enters an automated path, and what the system can prove afterward about the decision they made. Moxo scores 7.7 and ranks first; Camunda 8 scores 7.2, Microsoft Power Automate 7.1, Pega 6.9, n8n 6.7, Zapier 5.9, Kissflow 5.8 and ServiceNow 4.8, scored 22 September 2026 on the five weighted criteria. Those criteria cover the step type, the approver's account or licence, the routes available on a rejection, the audit record, and the meter that charges for the decision, and none of them can tell a review from a rubber stamp, so the methodology adds a check readers can run on any product in a few minutes: whether the decision record tells a considered approval from an instant one. Every figure was read from a vendor-owned surface and carries its own date.
Best Automation Platforms for AI Orchestration 2026
This ranking answers one question: how many real business applications can an AI agent act on out of the box? It evaluates nine platforms as of August 2026 on the reach they give an agent, not on the workflow logic they can express. That boundary is deliberate, because two neighbouring pages on this site answer different questions. Best Process Orchestration Platforms 2026 scores multi-step process control, error handling and state management. Best AI Agent Platforms 2026 scores building and hosting the agent itself. This page scores the layer between them: the connective tissue that lets an agent already built elsewhere reach the applications a business actually runs on. A platform that leads one of those pages can place low here, and two of them do. Scores derive from application and action catalogue counts, the exposure model each platform uses to publish those catalogues to an agent, setup effort, failure handling and cost per agent action. Every figure was retrieved from a vendor-owned surface on 11 August 2026 unless an earlier date is stated against it.
Common Questions
Can you automate a platform with no API using Zapier?
Not as a proper Zapier app. Zapier's help centre, updated 29 May 2026, says a private app can be built "for any service with a public API", and its fallbacks for a missing app are email parsing, RSS, webhooks, asking Zapier to add the app, or using a different app. Those let a no-API platform tell a Zap that something happened; none of them lets a Zap act inside the platform. The Zapier Agents Chrome extension can "run actions" on a page open in your own browser (help article updated 27 April 2026), but that is hands-on help, not a reusable Zap step.
How does Moxo keep humans in control when AI agents run a workflow?
Moxo keeps people on the decisions by design: approvals and other human steps are ones its product page says "only a person can close", and AI agents can fill preparer, advisor or reviewer slots around them (both read 15 September 2026). The checks on AI output are opt-in, though. In synthetic AutomationAtlas tests that day, an AI extract step's "Human review" and "Supervisor Agent" switches were both off by default, and the builder accepted the same role as a form's submitter and its approver.
What is Moxo?
Moxo AI (app.moxo.com) is a process orchestration platform from Moxo, formerly Moxtra, for work where several parties, approvals and documents meet. You build templates of human steps, AI steps and automations, each run is a Flow with its own data and status, and outsiders act through account-free Magic Links. Its only published price is Team, and the AI agents start on the custom-quoted Scale plan (moxo.com/pricing, 15 September 2026). It is not Moxo Classic, the older app.
How much does Moxo cost in 2026?
Moxo's only published price is Team: $500 a month in the monthly view or $5,000 a year in the yearly view, for 100 flows and $100 of AI a year with unlimited seats (moxo.com/pricing, 15 September 2026). Scale (500 flows and $500 of AI a year) and Enterprise are custom quotes. There is no free plan, no published overage rate and no stated trial length, and the dollar AI allowance has no published conversion to the credits Moxo's product logs.