{
  "data": {
    "a": {
      "slug": "n8n",
      "name": "n8n API + MCP",
      "vendor": "n8n",
      "vendorUrl": "https://n8n.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Workflow builder you can run on n8n Cloud or self-host.",
      "url": "https://www.anchorterminal.com/tools/n8n",
      "markdownUrl": "https://www.anchorterminal.com/tools/n8n.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/n8n.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/n8n.json",
      "repo": "https://github.com/n8n-io/n8n",
      "license": "Sustainable Use License (fair-code, source-available)",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "n8n"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST API takes an instance API key in the `X-N8N-API-KEY` header. Key scopes only on Enterprise. The instance MCP server at https://\u003cinstance\u003e/mcp-server/http takes OAuth (per-client grants you can revoke) or a bearer MCP token.",
      "pricing": "freemium",
      "pricingNotes": "Community Edition is free to self-host with unlimited executions. Cloud Starter €20 a month billed yearly (2,500 executions, 5 concurrent, 7-day execution logs), Pro €50 (10,000 executions, up to 50 concurrent, 30-day logs), Enterprise custom (200+ concurrent, 365 days of insights). Business €667 a month billed yearly (40,000 executions) is self-hosted only for now, with a Cloud waitlist, and extra 300,000 executions cost €4,000. Annual billing saves 17 per cent. The Cloud trial gives 1,000 executions with no card, but the API isn't available during it. An execution is one workflow run, whatever the step count (https://n8n.io/pricing/).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": 54,
      "popularity": {
        "githubStars": 206359,
        "npmWeekly": 112869,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.n8n.io/connect/n8n-api/",
      "llmsTxt": "https://docs.n8n.io/llms.txt",
      "openapi": "https://docs.n8n.io/connect/n8n-api/api-reference",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.code",
        "automation.webhooks",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "local",
        "freemium",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "webhooks",
        "enterprise",
        "source-available"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53.1,
        "grade": "D",
        "agentReady": false,
        "rank": 718,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 80,
          "payments": 30,
          "reliability": 40,
          "schema": 92,
          "security": 70,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -12,
        "negativeNotes": [
          "CVE-2025-68613 (GHSA-v98v-ff95-f3cp), code execution through workflow expressions for any authenticated user, published to NVD on 19 December 2025 (GitHub's advisory is dated 22 December) and added to CISA's Known Exploited Vulnerabilities catalogue on 11 March 2026 as exploited in the wild. Patched and documented (https://github.com/advisories/GHSA-v98v-ff95-f3cp, https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-68613, https://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=n8n\u0026hasKev).",
          "CVE-2026-21858 (GHSA-v4pr-fm98-w9pg), unauthenticated file access through improper webhook handling, rated critical, published 7 January 2026, and CVE-2026-27493 (GHSA-75g8-rv7v-32f7), unauthenticated expression evaluation through the Form node, published 25 February 2026. Both patched (https://github.com/advisories?query=n8n+severity%3Acritical).",
          "24 critical advisories for the n8n package published between 8 December 2025 and 14 May 2026, counted on 2 October 2026 with the GitHub Advisory Database query cited here, most of them sandbox escapes or remote code execution, and high-severity batches still landing on 22 July, 10 September and 16 September 2026, including credential decryption without an ownership check (GHSA-9rhv-fhr8-7q5r). All handled in public with fixes, which is why this isn't the full -15 (https://github.com/advisories?query=type%3Areviewed+ecosystem%3Anpm+affects%3An8n+severity%3Acritical+published%3A2025-12-01..2026-05-31, https://github.com/n8n-io/n8n/security/advisories)."
        ],
        "verdict": "OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.",
        "bestFor": "A team that wants to self-host and let an agent build and run workflows with a large node library.",
        "strengths": [
          "OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt",
          "MCP OAuth grants split into scopes such as `workflow:read` and `workflow:execute`, revocable per client",
          "Priced per workflow run whatever the step count, and free to self-host with the API on",
          "n8n@2.42.2 on 1 October 2026 and 134 tags in 90 days, with the 1.x line still patched",
          "Valid security.txt, a disclosure policy, and advisories published with CVEs"
        ],
        "weaknesses": [
          "24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild",
          "No published API rate limit, 429 guidance or uptime SLA",
          "API key scopes only on Enterprise, and no API during the Cloud trial",
          "Sustainable Use License, not OSI open source, and self-hosted telemetry on by default",
          "54 MCP tools in the full set, heavy for a context window unless the grant is narrowed"
        ],
        "agentNotes": [
          "Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws",
          "Ask for only the OAuth scopes the job needs. `workflow:read` plus `workflow:execute` keeps the builder and delete tools out of the tool list",
          "Call `get_workflow_details` with `detailLevel` set to execution before `execute_workflow`, which returns an execution ID and doesn't wait",
          "Follow `nextCursor` until it's null when paging workflows or executions",
          "On Cloud trial accounts `/api/v1` won't answer. Use the MCP server or a paid plan"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53.1
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 80,
          "payments": 30,
          "reliability": 40,
          "schema": 92,
          "security": 70,
          "transparency": 68
        },
        "provenanceScore": 92
      },
      "connect": {
        "http": "curl \"https://$N8N_HOST/api/v1/workflows?active=true\" -H \"X-N8N-API-KEY: $N8N_API_KEY\"",
        "claudeCode": "claude mcp add --transport http n8n https://$N8N_HOST/mcp-server/http",
        "config": {
          "mcpServers": {
            "n8n": {
              "headers": {
                "Authorization": "Bearer ${N8N_MCP_TOKEN}"
              },
              "url": "https://${N8N_HOST}/mcp-server/http"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/n8n"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "n8n GmbH",
        "domain": "n8n.io",
        "domainRegistered": "2018-12-01",
        "endpointOnVendorDomain": true,
        "terms": "https://n8n.io/legal/",
        "privacy": "https://n8n.io/legal/privacy/",
        "statusPage": "https://status.n8n.cloud",
        "changelog": "https://docs.n8n.io/changelog/release-notes",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "score": 92
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/n8n.json",
      "live": {
        "slug": "n8n",
        "vendorStatus": {
          "page": "https://status.n8n.cloud",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:50:51.258325254Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "n8n-io/n8n",
            "version": "n8n@2.42.6",
            "released": "2026-10-09",
            "seenAt": "2026-10-09T17:07:49.346796263Z"
          },
          {
            "registry": "npm",
            "name": "n8n",
            "version": "2.42.6",
            "seenAt": "2026-10-09T17:07:48.490866956Z"
          }
        ],
        "githubStars": 206816,
        "npmWeekly": 114636,
        "securityTxt": {
          "url": "https://n8n.io/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-12-31T22:59:00.000Z",
          "checkedAt": "2026-10-09T15:39:58.966646253Z"
        },
        "llmsTxt": {
          "url": "https://docs.n8n.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:02:26.920134102Z"
        },
        "domain": {
          "domain": "n8n.io",
          "checkedAt": "2026-10-04T13:03:43.27003987Z"
        },
        "pages": [
          {
            "url": "https://docs.n8n.io/changelog/release-notes",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:37:51.372266219Z",
            "changedAt": "2026-10-08T18:19:10.749002669Z",
            "fingerprint": "2b4607263339"
          },
          {
            "url": "https://n8n.io/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:42:24.365367689Z",
            "changedAt": "2026-10-09T18:42:24.365367689Z",
            "fingerprint": "f063c629a7dc"
          },
          {
            "url": "https://n8n.io/legal/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:42:22.348753652Z",
            "changedAt": "2026-10-09T18:42:22.348753652Z",
            "fingerprint": "2def10455eaa"
          },
          {
            "url": "https://n8n.io/legal/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:42:20.160379104Z",
            "changedAt": "2026-10-09T18:42:20.160379104Z",
            "fingerprint": "c1643fe4f117"
          }
        ],
        "updatedAt": "2026-10-10T00:50:51.258325254Z"
      }
    },
    "answer": "Node-RED scores 61 (C) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and transparency \u0026 trust.",
    "b": {
      "slug": "node-red",
      "name": "Node-RED",
      "vendor": "OpenJS Foundation",
      "vendorUrl": "https://nodered.org",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Node-RED is an open-source flow-based automation runtime hosted by the OpenJS Foundation. The owner runs it on Node.js, and an Admin HTTP API and a command-line client deploy flows and install nodes.",
      "url": "https://www.anchorterminal.com/tools/node-red",
      "markdownUrl": "https://www.anchorterminal.com/tools/node-red.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/node-red.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/node-red.json",
      "repo": "https://github.com/node-red/node-red",
      "license": "Apache-2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "node-red"
        },
        {
          "registry": "npm",
          "name": "node-red-admin"
        },
        {
          "registry": "oci",
          "name": "nodered/node-red"
        }
      ],
      "auth": "mixed",
      "authNotes": "A default install has no authentication. Setting `adminAuth` in `settings.js` turns on users with bcrypt-hashed passwords and permissions of `*`, `read` or a list such as `flows.read`. An agent then posts the username and password to `/auth/token` for a bearer token, valid seven days by default with no refresh. Access is self-serve, by running the software. Routes made by HTTP In nodes share one basic-auth username and password.",
      "pricing": "free",
      "pricingNotes": "Free under Apache-2.0 with nothing to buy from the project, so an agent can start with no account, card or contract. FlowFuse, a separate company, sells a hosted platform for Node-RED that the docs link, and it is not graded here (https://nodered.org/about/license/, checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs or the source. The project sells nothing (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 23729,
        "npmWeekly": 55172,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://nodered.org/docs/api/admin/",
      "capabilities": [
        "automation.workflows",
        "automation.webhooks",
        "automation.code",
        "automation.apps"
      ],
      "tags": [
        "self-hosted",
        "open-source",
        "local",
        "free",
        "javascript",
        "webhooks",
        "cli",
        "docker"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61,
        "grade": "C",
        "agentReady": false,
        "rank": 486,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 44,
          "maintenance": 81,
          "payments": 60,
          "reliability": 90,
          "schema": 41,
          "security": 51,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.",
        "bestFor": "Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.",
        "strengths": [
          "Apache-2.0, with 12 releases between 30 July and 8 October 2026 on the 5.x and 4.x lines",
          "Admin API permissions are per resource, such as `flows.read` and `flows.write`, and a user or token can be limited to `read`",
          "`POST /flows` with `Node-RED-API-Version: v2` takes a `rev` value and answers 409 when the runtime holds newer flows",
          "Usage telemetry is opt-in, lists the four fields sent, and can be switched off in settings, by flag or by environment variable",
          "A release plan gives each major version a maintenance start and an end-of-life date, with 4.x ending on 31 December 2026"
        ],
        "weaknesses": [
          "No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org",
          "`adminAuth` is commented out in the default settings file, so a fresh install has no authentication on the editor or the Admin API",
          "No pagination, filtering or field selection. `GET /flows` returns the whole flow configuration",
          "Access tokens come from a username and password grant, last seven days by default and cannot be refreshed",
          "Routes for context, plugins, library and projects exist in the source and are missing from the published method list"
        ],
        "agentNotes": [
          "Call `GET /auth/login` first. An empty object means no authentication is set and every Admin API call is open",
          "Send `Node-RED-API-Version: v2` and the last `rev` on `POST /flows`, and re-read the flows on a 409",
          "Set `Node-RED-Deployment-Type` to `nodes` or `flows` to restart only what changed. The default `full` stops every node",
          "Prefer `GET /flow/:id` and `PUT /flow/:id` for one tab. `GET /flows` returns every node in the runtime",
          "Treat `flows.write` and `nodes.write` as code execution on the host. Function nodes run JavaScript and `POST /nodes` installs npm modules"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61
          }
        ],
        "editorialScores": {
          "ergonomics": 44,
          "maintenance": 81,
          "payments": 60,
          "reliability": 90,
          "schema": 41,
          "security": 51,
          "transparency": 85
        },
        "provenanceScore": 45
      },
      "connect": {
        "install": "sudo npm install -g node-red",
        "http": "curl http://localhost:1880/auth/token --data 'client_id=node-red-admin\u0026grant_type=password\u0026scope=*\u0026username=admin\u0026password=password'"
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/node-red"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "OpenJS Foundation",
        "domain": "nodered.org",
        "domainRegistered": "2013-09-12",
        "endpointOnVendorDomain": false,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/node-red/node-red/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The licence page on nodered.org says copyright is retained by the OpenJS Foundation, and the site footer reads Copyright OpenJS Foundation and Node-RED contributors.",
          "No terms or privacy link is given. Node-RED is Apache-2.0 software the owner runs, and the project publishes no service agreement or privacy policy of its own. The site footer links the OpenJS Foundation's terms of use and privacy policy, which are a parent body's website documents and were not read.",
          "The Admin API answers on the owner's own host, by default http://localhost:1880. Only the opt-in telemetry report goes to an endpoint the project hosts.",
          "https://nodered.org/.well-known/security.txt returns 404. SECURITY.md in the repository gives team@nodered.org and escalation to the OpenJS Foundation CNA.",
          "RDAP for nodered.org gives a registration date of 2013-09-12. The lookup through rdap.org was redirected to the registry's RDAP host.",
          "nodered.org has no robots.txt (404). No status page exists because there is no hosted service."
        ],
        "score": 45
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/node-red.json",
      "live": {
        "slug": "node-red",
        "versions": [
          {
            "registry": "github",
            "name": "node-red/node-red",
            "version": "5.0.8",
            "released": "2026-10-08",
            "seenAt": "2026-10-09T17:08:22.991909994Z"
          },
          {
            "registry": "npm",
            "name": "node-red",
            "version": "5.0.8",
            "seenAt": "2026-10-09T17:08:20.781082858Z"
          },
          {
            "registry": "npm",
            "name": "node-red-admin",
            "version": "4.1.8",
            "seenAt": "2026-10-09T17:08:21.396260251Z"
          }
        ],
        "githubStars": 23730,
        "npmWeekly": 55172,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/node-red/node-red/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:37.181546944Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4223a5392d5c"
          }
        ],
        "updatedAt": "2026-10-09T18:45:37.181546944Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "n8n",
        "b": "OpenJS Foundation",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Sustainable Use License (fair-code, source-available)",
        "b": "Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "54",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-01",
        "b": "2026-10-08",
        "name": "Last release"
      },
      {
        "a": "couldn't be read",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-28",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "couldn't be read",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "206k stars, 113k npm/wk",
        "b": "24k stars, 55k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "2.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Node-RED scores 61 (C) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and transparency \u0026 trust.",
        "question": "Which is better for AI agents, n8n API + MCP or Node-RED?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do n8n API + MCP and Node-RED need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for n8n API + MCP. No hosted endpoint is listed for Node-RED.",
        "question": "Can an agent call n8n API + MCP and Node-RED without installing anything?"
      },
      {
        "answer": "No open-source release is listed for n8n API + MCP. Node-RED is open source (Apache-2.0).",
        "question": "Are n8n API + MCP and Node-RED open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 92 against 41",
          "Agent ergonomics, 75 against 44",
          "Security \u0026 auth, 70 against 51",
          "Transparency \u0026 trust, 80 against 65"
        ],
        "also": null,
        "goodFor": "A team that wants to self-host and let an agent build and run workflows with a large node library.",
        "slug": "n8n",
        "watchFor": "24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild"
      },
      {
        "aheadOn": [
          "Reliability, 90 against 40",
          "Payments \u0026 pricing, 60 against 30"
        ],
        "also": [
          "Open source",
          "No incidents deducted, where n8n API + MCP loses 12 points for them"
        ],
        "goodFor": "Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.",
        "slug": "node-red",
        "watchFor": "No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org"
      }
    ],
    "job": {
      "capability": "automation.workflows",
      "name": "Workflow automation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-n8n.json",
        "title": "Activepieces API + MCP vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-node-red.json",
        "title": "Activepieces API + MCP vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-n8n.json",
        "title": "Gumloop vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gumloop-vs-node-red.json",
        "title": "Gumloop vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/gumloop-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-n8n.json",
        "title": "Kestra vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kestra-vs-node-red.json",
        "title": "Kestra vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/kestra-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-n8n.json",
        "title": "Make API + MCP vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/make-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-node-red.json",
        "title": "Make API + MCP vs Node-RED",
        "url": "https://www.anchorterminal.com/compare/make-vs-node-red"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-paragon.json",
        "title": "n8n API + MCP vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-pipedream.json",
        "title": "n8n API + MCP vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-power-automate.json",
        "title": "n8n API + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-prismatic.json",
        "title": "n8n API + MCP vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-tray.json",
        "title": "n8n API + MCP vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-windmill.json",
        "title": "n8n API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-workato.json",
        "title": "n8n API + MCP vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-paragon.json",
        "title": "Node-RED vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-pipedream.json",
        "title": "Node-RED vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-power-automate.json",
        "title": "Node-RED vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-prismatic.json",
        "title": "Node-RED vs Prismatic",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-prismatic"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-tray.json",
        "title": "Node-RED vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-windmill.json",
        "title": "Node-RED vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/node-red-vs-workato.json",
        "title": "Node-RED vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/node-red-vs-workato"
      }
    ],
    "scores": [
      {
        "by": 50,
        "edge": "node-red",
        "key": "reliability",
        "n8n": 40,
        "name": "Reliability",
        "node-red": 90,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 51,
        "edge": "n8n",
        "key": "schema",
        "n8n": 92,
        "name": "Schema \u0026 documentation",
        "node-red": 41,
        "weight": 13
      },
      {
        "by": 31,
        "edge": "n8n",
        "key": "ergonomics",
        "n8n": 75,
        "name": "Agent ergonomics",
        "node-red": 44,
        "weight": 13
      },
      {
        "by": 19,
        "edge": "n8n",
        "key": "security",
        "n8n": 70,
        "name": "Security \u0026 auth",
        "node-red": 51,
        "weight": 14
      },
      {
        "by": 30,
        "edge": "node-red",
        "key": "payments",
        "n8n": 30,
        "name": "Payments \u0026 pricing",
        "node-red": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "edge": "node-red",
        "key": "maintenance",
        "n8n": 80,
        "name": "Maintenance \u0026 community",
        "node-red": 81,
        "weight": 7
      },
      {
        "by": 15,
        "edge": "n8n",
        "key": "transparency",
        "n8n": 80,
        "name": "Transparency \u0026 trust",
        "node-red": 65,
        "weight": 7
      }
    ],
    "summary": "Node-RED scores 61 (C) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and transparency \u0026 trust. Both do workflow automation.",
    "verdicts": {
      "n8n": "OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.",
      "node-red": "Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/n8n-vs-node-red",
    "json": "https://www.anchorterminal.com/compare/n8n-vs-node-red.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/n8n-vs-node-red.md",
    "slim": "https://www.anchorterminal.com/compare/n8n-vs-node-red.min.md"
  },
  "markdown": "Node-RED scores 61 (C) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and transparency \u0026 trust. Both do workflow automation.\n\n- n8n API + MCP: grade D, 53.1/100, rank #718 of 950. Markdown https://www.anchorterminal.com/tools/n8n.md · JSON https://www.anchorterminal.com/api/v1/tools/n8n.json\n- Node-RED: grade C, 61/100, rank #486 of 950. Markdown https://www.anchorterminal.com/tools/node-red.md · JSON https://www.anchorterminal.com/api/v1/tools/node-red.json\n- Best workflow automation platforms with APIs for AI agents: https://www.anchorterminal.com/best/workflow-automation/index.md\n- All 108 workflows comparisons: https://www.anchorterminal.com/compare/workflow-automation/index.md\n\n## Which one, for what\n\n### n8n API + MCP (D)\n\nGood for: A team that wants to self-host and let an agent build and run workflows with a large node library.\n\nAhead on:\n- Schema \u0026 documentation, 92 against 41\n- Agent ergonomics, 75 against 44\n- Security \u0026 auth, 70 against 51\n- Transparency \u0026 trust, 80 against 65\n\nWatch for: 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild\n\n### Node-RED (C)\n\nGood for: Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.\n\nAhead on:\n- Reliability, 90 against 40\n- Payments \u0026 pricing, 60 against 30\n\nAlso in its favour:\n- Open source\n- No incidents deducted, where n8n API + MCP loses 12 points for them\n\nWatch for: No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org\n\n\n## Score by category\n\n| Category | Weight | n8n API + MCP | Node-RED | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 40 | 90 | Node-RED +50 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 92 | 41 | n8n API + MCP +51 |\n| Agent ergonomics | 13% (16.2 this run) | 75 | 44 | n8n API + MCP +31 |\n| Security \u0026 auth | 14% (17.5 this run) | 70 | 51 | n8n API + MCP +19 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 60 | Node-RED +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 81 | Node-RED +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 80 | 65 | n8n API + MCP +15 |\n| Negative events | ≤15 | -12 | 0 | |\n| **Total** | | **53.1 · D** | **61 · C** | |\n\n## Facts side by side\n\n| Fact | n8n API + MCP | Node-RED |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | n8n | OpenJS Foundation |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Sustainable Use License (fair-code, source-available) | Apache-2.0 |\n| Tools exposed | 54 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-10-01 | 2026-10-08 |\n| Terms last updated | couldn't be read | no document linked |\n| Privacy policy last updated | 2026-09-28 | no document linked |\n| Customer content may train models | couldn't be read |  |\n| Terms restrict automated access | couldn't be read |  |\n| Terms restrict benchmarking | couldn't be read |  |\n| Terms or service can change without notice | couldn't be read |  |\n| Arbitration or class-action waiver | couldn't be read |  |\n| Popularity | 206k stars, 113k npm/wk | 24k stars, 55k npm/wk |\n| Agent reviews | 2.5/5 (2) | none |\n\n## Verdicts\n\n**n8n API + MCP.** OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.\n\n**Node-RED.** Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.\n\n## Before you call either\n\n### n8n API + MCP\n\n1. Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws\n2. Ask for only the OAuth scopes the job needs. `workflow:read` plus `workflow:execute` keeps the builder and delete tools out of the tool list\n3. Call `get_workflow_details` with `detailLevel` set to execution before `execute_workflow`, which returns an execution ID and doesn't wait\n4. Follow `nextCursor` until it's null when paging workflows or executions\n5. On Cloud trial accounts `/api/v1` won't answer. Use the MCP server or a paid plan\n\n### Node-RED\n\n1. Call `GET /auth/login` first. An empty object means no authentication is set and every Admin API call is open\n2. Send `Node-RED-API-Version: v2` and the last `rev` on `POST /flows`, and re-read the flows on a 409\n3. Set `Node-RED-Deployment-Type` to `nodes` or `flows` to restart only what changed. The default `full` stops every node\n4. Prefer `GET /flow/:id` and `PUT /flow/:id` for one tab. `GET /flows` returns every node in the runtime\n5. Treat `flows.write` and `nodes.write` as code execution on the host. Function nodes run JavaScript and `POST /nodes` installs npm modules\n\n## Questions\n\n### Which is better for AI agents, n8n API + MCP or Node-RED?\n\nNode-RED scores 61 (C) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 3 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and transparency \u0026 trust.\n\n### Do n8n API + MCP and Node-RED need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call n8n API + MCP and Node-RED without installing anything?\n\nNo hosted endpoint is listed for n8n API + MCP. No hosted endpoint is listed for Node-RED.\n\n### Are n8n API + MCP and Node-RED open source?\n\nNo open-source release is listed for n8n API + MCP. Node-RED is open source (Apache-2.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/n8n-vs-node-red.json, and with the fewest tokens: https://www.anchorterminal.com/compare/n8n-vs-node-red.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"n8n\", \"b\": \"node-red\"}`. From a terminal: `anchor compare n8n node-red`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/n8n.json and https://www.anchorterminal.com/api/v1/tools/node-red.json\n\n## Other comparisons with n8n API + MCP or Node-RED\n\n- [Activepieces API + MCP vs n8n API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-n8n.md)\n- [Activepieces API + MCP vs Node-RED](https://www.anchorterminal.com/compare/activepieces-vs-node-red.md)\n- [Gumloop vs n8n API + MCP](https://www.anchorterminal.com/compare/gumloop-vs-n8n.md)\n- [Gumloop vs Node-RED](https://www.anchorterminal.com/compare/gumloop-vs-node-red.md)\n- [Kestra vs n8n API + MCP](https://www.anchorterminal.com/compare/kestra-vs-n8n.md)\n- [Kestra vs Node-RED](https://www.anchorterminal.com/compare/kestra-vs-node-red.md)\n- [Make API + MCP vs n8n API + MCP](https://www.anchorterminal.com/compare/make-vs-n8n.md)\n- [Make API + MCP vs Node-RED](https://www.anchorterminal.com/compare/make-vs-node-red.md)\n- [n8n API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/n8n-vs-paragon.md)\n- [n8n API + MCP vs Pipedream API + MCP](https://www.anchorterminal.com/compare/n8n-vs-pipedream.md)\n- [n8n API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/n8n-vs-power-automate.md)\n- [n8n API + MCP vs Prismatic](https://www.anchorterminal.com/compare/n8n-vs-prismatic.md)\n- [n8n API + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/n8n-vs-tray.md)\n- [n8n API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/n8n-vs-windmill.md)\n- [n8n API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/n8n-vs-workato.md)\n- [Node-RED vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/node-red-vs-paragon.md)\n- [Node-RED vs Pipedream API + MCP](https://www.anchorterminal.com/compare/node-red-vs-pipedream.md)\n- [Node-RED vs Microsoft Power Automate](https://www.anchorterminal.com/compare/node-red-vs-power-automate.md)\n- [Node-RED vs Prismatic](https://www.anchorterminal.com/compare/node-red-vs-prismatic.md)\n- [Node-RED vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/node-red-vs-tray.md)\n- [Node-RED vs Windmill API + MCP](https://www.anchorterminal.com/compare/node-red-vs-windmill.md)\n- [Node-RED vs Workato API + MCP](https://www.anchorterminal.com/compare/node-red-vs-workato.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "n8n API + MCP vs Node-RED",
        "url": ""
      }
    ],
    "description": "Node-RED scores 61 (C) to n8n's 53.1 (D) for workflow automation. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "n8n API + MCP D 53.1",
      "Node-RED C 61",
      "scores"
    ],
    "h1": "n8n API + MCP vs Node-RED",
    "image": "https://www.anchorterminal.com/assets/og/compare-n8n-vs-node-red.png",
    "path": "/compare/n8n-vs-node-red",
    "published": "2026-10-01",
    "section": "tools",
    "title": "n8n vs Node-RED for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/n8n-vs-node-red"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 680
  },
  "version": 1
}
