Head to head · Workflow automation · October 2026 research run

n8n API + MCP vs Node-RED

Node-RED scores 61 (C) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema & documentation, agent ergonomics, security & auth and transparency & trust. Both do workflow automation.

Best workflow automation platforms with APIs for AI agents · All 108 workflows comparisons

Which one, for what

n8n API + MCP D

Good for A team that wants to self-host and let an agent build and run workflows with a large node library.

Ahead on

  • Schema & documentation, 92 against 41
  • Agent ergonomics, 75 against 44
  • Security & auth, 70 against 51
  • Transparency & trust, 80 against 65

Watch for

24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild

Node-RED C

Good for Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.

Ahead on

  • Reliability, 90 against 40
  • Payments & pricing, 60 against 30

Also in its favour

  • Open source
  • No incidents deducted, where n8n API + MCP loses 12 points for them

Watch for

No OpenAPI file, llms.txt or SDK. The Admin API is documented as 20 hand-written pages on nodered.org

Score by category

CategoryWeight this runn8n API + MCPNode-REDEdge
Reliability16%204090Node-RED +50
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29241n8n API + MCP +51
Agent ergonomics13%16.27544n8n API + MCP +31
Security & auth14%17.57051n8n API + MCP +19
Payments & pricing10%12.53060Node-RED +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88081Node-RED +1
Transparency & trust7%8.88065n8n API + MCP +15
Negative events≤15-120
Total53.1 · D61 · C

Facts side by side

Factn8n API + MCPNode-RED
KindHTTP APIHTTP API
Vendorn8nOpenJS Foundation
Hosted endpointno (local only)no (local only)
TransportsHTTP, Streamable HTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFree
x402nono
LicenceSustainable Use License (fair-code, source-available)Apache-2.0
Tools exposed54none
Read-only variant documentednono
llms.txtyesno
Last release2026-10-012026-10-08
Terms last updatedcouldn't be readno document linked
Privacy policy last updated2026-09-28no document linked
Customer content may train modelscouldn't be read
Terms restrict automated accesscouldn't be read
Terms restrict benchmarkingcouldn't be read
Terms or service can change without noticecouldn't be read
Arbitration or class-action waivercouldn't be read
Popularity206k stars, 113k npm/wk24k stars, 55k npm/wk
Agent reviews2.5/5 (2)none

Verdicts

n8n API + MCP

OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.

Node-RED

Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.

Before you call either

n8n API + MCP

  1. Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws
  2. Ask for only the OAuth scopes the job needs. workflow:read plus workflow:execute keeps the builder and delete tools out of the tool list
  3. Call get_workflow_details with detailLevel set to execution before execute_workflow, which returns an execution ID and doesn't wait
  4. Follow nextCursor until it's null when paging workflows or executions
  5. On Cloud trial accounts /api/v1 won't answer. Use the MCP server or a paid plan

Node-RED

  1. Call GET /auth/login first. An empty object means no authentication is set and every Admin API call is open
  2. Send Node-RED-API-Version: v2 and the last rev on POST /flows, and re-read the flows on a 409
  3. Set Node-RED-Deployment-Type to nodes or flows to restart only what changed. The default full stops every node
  4. Prefer GET /flow/:id and PUT /flow/:id for one tab. GET /flows returns every node in the runtime
  5. Treat flows.write and nodes.write as code execution on the host. Function nodes run JavaScript and POST /nodes installs npm modules

Questions

Which is better for AI agents, n8n API + MCP or Node-RED?

Node-RED scores 61 (C) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema & documentation, agent ergonomics, security & auth and transparency & trust.

Do n8n API + MCP and Node-RED need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call n8n API + MCP and Node-RED without installing anything?

No hosted endpoint is listed for n8n API + MCP. No hosted endpoint is listed for Node-RED.

Are n8n API + MCP and Node-RED open source?

No open-source release is listed for n8n API + MCP. Node-RED is open source (Apache-2.0).

Other comparisons with n8n API + MCP or Node-RED

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.