Shuffle

APIyesOSS—FREEyesDOCS5/5
SH7.3#1 of 21
outWeb—Windows—MacoutLinux—Android—iOS

Ranked in Runbook Automation Software ·Free plan

About

Shuffle is an open-source automation platform built for security teams to create and run workflows. Its visual workflow designer works with a no-code app builder that can create integrations from Swagger or OpenAPI specifications and API documentation URLs. The public app catalog lists more than 2,500 apps, including Slack, Gmail, MISP, Wazuh, Splunk, and Jira. Workflows can start from webhooks, schedules, subflows, or user input; extensions include AWS Lambda, AWS S3, Kafka, and Pub/Sub. Shuffle is available as self-hosted open source, self-hosted licensed software, or cloud SaaS, and hybrid deployment is documented. Runtime options include Docker Compose, distributed Docker Swarm, hybrid cloud with a local Orborus runner, and Kubernetes through Helm charts. Shuffle documents bcrypt password hashing, AES-256 encryption, tenant-controlled SAML/SSO and MFA, and Bearer-token API authentication. The Scale plan is 0.00 USD per free and includes 2,000 app runs per month, with a hard limit, three tenants, and one location. Custom Python apps are not yet easy to create for Shuffle Cloud; on-prem instances support local app hotloading.

Who it is for

Shuffle suits security operations centers and CERT/SIRT teams seeking workflow automation that can be self-hosted, cloud-based, or hybrid. Its app catalog, approval steps, event triggers, and API access may fit teams coordinating security processes and detections.

What is good

  • More than 2,500 apps in the public catalog
  • Self-hosted, cloud, and hybrid deployment options
  • Visual workflow designer and no-code app creator
  • Scale plan includes 2,000 monthly app runs
  • Documents tenant-controlled SSO and MFA

What to know first

  • Scale has a hard app-run limit
  • Scale includes only three tenants and one location
  • Custom Python apps are not easy to create for Shuffle Cloud
  • Scale lists no support or onboarding

Inferse review

Shuffle: the full review

Shuffle combines security-focused workflow automation with multiple deployment choices and a large app catalog. Teams evaluating the free Scale plan should account for its hard run limit and the cloud custom-app limitation.

Shuffle is an open-source automation platform built around security workflows, with a visual designer and a large integration catalog. It suits security operations teams that need to connect existing tools and choose between cloud and self-hosted deployment. Its strongest case is the combination of app-building flexibility and deployment choice; the free cloud plan’s hard run cap and custom-app constraint are meaningful trade-offs.

Overview

Shuffle targets the CERT/SIRT and security operations communities, where teams need to share processes, automations, and detections. The visual workflow designer is paired with a no-code app creator that can generate integrations from Swagger/OpenAPI specifications or API documentation URLs. That makes it more adaptable than a fixed collection of built-in actions, though cloud users face a constraint when they need custom Python apps.

Key features

The public catalog contains more than 2,500 apps, including Slack, Gmail, MISP, Wazuh, Splunk, and Jira. Core triggers include webhooks, schedules, subflows, and user input; extensions include AWS Lambda, AWS S3, Kafka, and Pub/Sub. For teams coordinating security response, that range can connect event sources to existing communications and security tools without requiring every workflow to start from a schedule or manual action.

Shuffle documents approval steps, scheduled runs, event triggers, incident integrations, and audit logs. It describes its API as API-first and documents Bearer-token authentication on cloud and on-prem installations, useful for teams that need workflows to participate in a broader toolchain rather than remain isolated in a UI.

Security documentation describes bcrypt password hashing and AES-256 encryption for app authentication, protected datastore keys, and files. Tenant-controlled SAML/SSO and MFA are supported, with Okta, Auth0, PingID, and AzureAD named. For AI requests, Shuffle says cloud traffic goes to regional model endpoints with tenant contexts isolated; on-prem installations can use local models without external requests. These controls and choices make the platform relevant to organizations with identity and data-boundary requirements, though the right deployment still depends on each team’s own architecture needs.

Pricing

Shuffle uses a freemium model. Scale costs 0.00 USD per free (Free / month) and includes 2k App Runs, 3 tenants, 1 location, and 98.2% feature coverage. Its hard App Runs limit is the key constraint: it is a sensible starting point for evaluation or modest workloads, but teams with run volume that can exceed the cap should plan for a paid tier rather than treat it as an elastic free service. No support or onboarding is listed for Scale.

Business has custom pricing, with App Runs starting at 300k on a soft limit, unlimited tenants, locations, and branding, 100% feature coverage, onboarding and setup, and three use cases covered. SLA and email support are included. It fits organizations that need a larger allowance and formal support, while the use-case coverage is narrower than Enterprise.

Enterprise also has custom pricing and starts at 300k App Runs on a soft limit. It adds unlimited use cases to unlimited tenants, locations, and branding, alongside 100% feature coverage, professional services, onboarding and setup, and SLA, email, on-call, and alert mechanism support. It is the more suitable tier for broad deployments that need on-call coverage and services; teams without those requirements may not need its expanded package.

Platforms

Shuffle is available as self-hosted open source, self-hosted licensed software, and Shuffle Cloud SaaS; hybrid deployment is also documented. Runtime options include Docker Compose, distributed Docker Swarm, a cloud-hybrid setup with a local Orborus runner, and Kubernetes through Helm charts. This breadth is a practical advantage for teams fitting automation into an existing deployment model. The trade-off is that custom Python apps are not yet easy to create for Shuffle Cloud, while on-prem instances support local app hotloading, making self-hosting the stronger fit when bespoke integrations are central.

Supported platforms include API, Linux, self-hosted, and web.

Who it's for

Shuffle is best suited to security operations teams that want to automate incident-related processes across a broad set of tools and retain control over where the runtime and AI requests operate. It is less compelling for cloud-first teams whose workflows depend on custom Python apps, or for workloads that exceed Scale’s hard cap without a budget for custom-priced plans.

Pros and cons

  • Pros: More than 2,500 apps and multiple trigger types give security teams substantial room to connect workflows to existing systems.
  • Pros: Self-hosted, cloud, and hybrid deployment options accommodate different infrastructure and data-boundary needs.
  • Pros: SSO, MFA, audit logs, approvals, and documented encryption support security-conscious workflow operations.
  • Cons: Scale’s 2k monthly App Runs are subject to a hard limit, and the plan has no listed support or onboarding.
  • Cons: Creating custom Python apps is difficult on Shuffle Cloud, so teams needing bespoke integrations may have to use on-prem deployment.
  • Cons: Business and Enterprise pricing is custom, making budget comparison less direct than with the free tier.

Alternatives

For a broader comparison, see Runbook Automation Software. Choose Rundeck if a freemium option with a free Community plan for small teams is a better fit; it also offers a free trial. StackStorm is worth considering when a free, open-source project with no paid products is the priority. Tracecat may suit teams seeking a self-hosted open-source option with unlimited workflows, cases, and agents, and self-managed monthly executions.

Palo Alto Networks Cortex Cloud API Security, BlinkOps, Swimlane Turbine, Torq Case Management, and HCL BigFix are paid alternatives. BlinkOps describes usage-based pricing with its full platform included; HCL BigFix offers a free trial.

Verdict

Choose Shuffle if your security team needs flexible workflow automation, a wide integration catalog, and a real choice of cloud, hybrid, or self-hosted operation. Its combination of deployment options and security controls is the main reason to shortlist it. Look elsewhere if custom Python apps are essential in a cloud-only setup or if a hard free-tier run ceiling does not fit your workload; the paid plans may suit larger operations, but their custom pricing makes direct cost planning less straightforward.

Compared on runbook automation software

Free plan
Yesshuffler.io
Approval steps
Yesshuffler.io
Scheduled runs
Yesshuffler.io
Event triggers
Yesshuffler.io
Incident integrations
Yesshuffler.io
Audit logs
Yesshuffler.io
Self-hosted option
Yesshuffler.io
Runs included
$2,000/moshuffler.io

Facts

Purpose
Shuffle is an open-source automation platform designed for the security industry, for building and executing automation workflows.shuffler.io · 29 Sept 2026
Workflow and app builder
Its visual workflow designer works with a no-code app creator that can generate integrations from Swagger/OpenAPI specifications or API documentation URLs.shuffler.io · 29 Sept 2026
Integrations
Shuffle's public app catalog lists more than 2,500 apps, including integrations such as Slack, Gmail, MISP, Wazuh, Splunk, and Jira.shuffler.io · 29 Sept 2026
Triggers
Core workflow triggers include webhooks, schedules, subflows, and user input; listed extension triggers include AWS Lambda, AWS S3, Kafka, and Pub/Sub.shuffler.io · 29 Sept 2026
Deployment options
Shuffle is offered as self-hosted open source, self-hosted licensed, and Shuffle Cloud SaaS, with hybrid deployment also documented.shuffler.io · 29 Sept 2026
Runtime deployment
Documented runtime architectures include Docker Compose, distributed Docker Swarm, cloud hybrid with a local Orborus runner, and Kubernetes using Helm charts.shuffler.io · 29 Sept 2026
Security
The architecture documentation says passwords are bcrypt-hashed and app authentication, protected datastore keys, and files are AES-256 encrypted.shuffler.io · 29 Sept 2026
Authentication
Shuffle documents tenant-controlled SAML/SSO and MFA, and names Okta, Auth0, PingID, and AzureAD as supported platforms.shuffler.io · 29 Sept 2026
AI data handling
Shuffle says cloud AI requests are routed to regional model endpoints and tenant contexts are isolated; on-prem installations can use local models without external requests.shuffler.io · 29 Sept 2026
API
Shuffle describes itself as API-first and documents Bearer-token authentication for its API on both cloud and on-prem installations.shuffler.io · 29 Sept 2026
Integration implementation limit
The apps documentation says custom Python apps cannot yet be created easily for Shuffle Cloud, while on-prem instances support local app hotloading.shuffler.io · 29 Sept 2026
Audience
Shuffle says it was created to address automation problems in the CERT/SIRT community and aims to help security operations centers share processes, automations, and detections.shuffler.io · 29 Sept 2026
Support
The pricing page lists Shuffle Support with SLA and email support for Business, with on-call support and an alert mechanism additionally listed for Enterprise.shuffler.io · 29 Sept 2026

Company

Founded
2019shuffler.io · 28 Sept 2026

Best Shuffle alternatives

See all 20

Where it ranks on Inferse

Sources