{
  "data": {
    "a": {
      "slug": "n8n",
      "name": "n8n API + MCP",
      "vendor": "n8n",
      "vendorUrl": "https://n8n.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Workflow builder you can run on n8n Cloud or self-host.",
      "url": "https://www.anchorterminal.com/tools/n8n",
      "markdownUrl": "https://www.anchorterminal.com/tools/n8n.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/n8n.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/n8n.json",
      "repo": "https://github.com/n8n-io/n8n",
      "license": "Sustainable Use License (fair-code, source-available)",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "n8n"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST API takes an instance API key in the `X-N8N-API-KEY` header. Key scopes only on Enterprise. The instance MCP server at https://\u003cinstance\u003e/mcp-server/http takes OAuth (per-client grants you can revoke) or a bearer MCP token.",
      "pricing": "freemium",
      "pricingNotes": "Community Edition is free to self-host with unlimited executions. Cloud Starter €20 a month billed yearly (2,500 executions, 5 concurrent, 7-day execution logs), Pro €50 (10,000 executions, up to 50 concurrent, 30-day logs), Enterprise custom (200+ concurrent, 365 days of insights). Business €667 a month billed yearly (40,000 executions) is self-hosted only for now, with a Cloud waitlist, and extra 300,000 executions cost €4,000. Annual billing saves 17 per cent. The Cloud trial gives 1,000 executions with no card, but the API isn't available during it. An execution is one workflow run, whatever the step count (https://n8n.io/pricing/).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": 54,
      "popularity": {
        "githubStars": 206359,
        "npmWeekly": 112869,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.n8n.io/connect/n8n-api/",
      "llmsTxt": "https://docs.n8n.io/llms.txt",
      "openapi": "https://docs.n8n.io/connect/n8n-api/api-reference",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.code",
        "automation.webhooks",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "local",
        "freemium",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "webhooks",
        "enterprise",
        "source-available"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53.3,
        "grade": "D",
        "agentReady": false,
        "rank": 335,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 80,
          "payments": 30,
          "reliability": 40,
          "schema": 92,
          "security": 70,
          "transparency": 82
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -12,
        "negativeNotes": [
          "CVE-2025-68613 (GHSA-v98v-ff95-f3cp), code execution through workflow expressions for any authenticated user, published to NVD on 19 December 2025 (GitHub's advisory is dated 22 December) and added to CISA's Known Exploited Vulnerabilities catalogue on 11 March 2026 as exploited in the wild. Patched and documented (https://github.com/advisories/GHSA-v98v-ff95-f3cp, https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-68613, https://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=n8n\u0026hasKev).",
          "CVE-2026-21858 (GHSA-v4pr-fm98-w9pg), unauthenticated file access through improper webhook handling, rated critical, published 7 January 2026, and CVE-2026-27493 (GHSA-75g8-rv7v-32f7), unauthenticated expression evaluation through the Form node, published 25 February 2026. Both patched (https://github.com/advisories?query=n8n+severity%3Acritical).",
          "24 critical advisories for the n8n package published between 8 December 2025 and 14 May 2026, counted on 2 October 2026 with the GitHub Advisory Database query cited here, most of them sandbox escapes or remote code execution, and high-severity batches still landing on 22 July, 10 September and 16 September 2026, including credential decryption without an ownership check (GHSA-9rhv-fhr8-7q5r). All handled in public with fixes, which is why this isn't the full -15 (https://github.com/advisories?query=type%3Areviewed+ecosystem%3Anpm+affects%3An8n+severity%3Acritical+published%3A2025-12-01..2026-05-31, https://github.com/n8n-io/n8n/security/advisories)."
        ],
        "verdict": "OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.",
        "strengths": [
          "OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt",
          "MCP OAuth grants split into scopes such as `workflow:read` and `workflow:execute`, revocable per client",
          "Priced per workflow run whatever the step count, and free to self-host with the API on",
          "n8n@2.42.2 on 1 October 2026 and 134 tags in 90 days, with the 1.x line still patched",
          "Valid security.txt, a disclosure policy, and advisories published with CVEs"
        ],
        "weaknesses": [
          "24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild",
          "No published API rate limit, 429 guidance or uptime SLA",
          "API key scopes only on Enterprise, and no API during the Cloud trial",
          "Sustainable Use License, not OSI open source, and self-hosted telemetry on by default",
          "54 MCP tools in the full set, heavy for a context window unless the grant is narrowed"
        ],
        "agentNotes": [
          "Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws",
          "Ask for only the OAuth scopes the job needs. `workflow:read` plus `workflow:execute` keeps the builder and delete tools out of the tool list",
          "Call `get_workflow_details` with `detailLevel` set to execution before `execute_workflow`, which returns an execution ID and doesn't wait",
          "Follow `nextCursor` until it's null when paging workflows or executions",
          "On Cloud trial accounts `/api/v1` won't answer. Use the MCP server or a paid plan"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53.3
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 80,
          "payments": 30,
          "reliability": 40,
          "schema": 92,
          "security": 70,
          "transparency": 68
        },
        "provenanceScore": 96
      },
      "connect": {
        "http": "curl \"https://$N8N_HOST/api/v1/workflows?active=true\" -H \"X-N8N-API-KEY: $N8N_API_KEY\"",
        "claudeCode": "claude mcp add --transport http n8n https://$N8N_HOST/mcp-server/http",
        "config": {
          "mcpServers": {
            "n8n": {
              "headers": {
                "Authorization": "Bearer ${N8N_MCP_TOKEN}"
              },
              "url": "https://${N8N_HOST}/mcp-server/http"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/n8n"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "n8n GmbH",
        "domain": "n8n.io",
        "domainRegistered": "2018-12-01",
        "endpointOnVendorDomain": true,
        "terms": "https://n8n.io/legal/",
        "privacy": "https://n8n.io/legal/privacy/",
        "statusPage": "https://status.n8n.cloud",
        "changelog": "https://docs.n8n.io/changelog/release-notes",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "score": 96
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/n8n.json",
      "live": {
        "slug": "n8n",
        "vendorStatus": {
          "page": "https://status.n8n.cloud",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:40:15.86593822Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "n8n-io/n8n",
            "version": "n8n@2.41.6",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:34:11.228917818Z"
          },
          {
            "registry": "npm",
            "name": "n8n",
            "version": "2.41.6",
            "seenAt": "2026-10-04T16:34:10.993229544Z"
          }
        ],
        "githubStars": 206645,
        "npmWeekly": 137563,
        "securityTxt": {
          "url": "https://n8n.io/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-12-31T22:59:00.000Z",
          "checkedAt": "2026-10-04T15:15:42.986317237Z"
        },
        "llmsTxt": {
          "url": "https://docs.n8n.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:02.090465944Z"
        },
        "domain": {
          "domain": "n8n.io",
          "checkedAt": "2026-10-04T13:03:43.27003987Z"
        },
        "pages": [
          {
            "url": "https://docs.n8n.io/changelog/release-notes",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:50.120157228Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "3a49d72d7b1c"
          },
          {
            "url": "https://n8n.io/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:12.167588908Z",
            "changedAt": "2026-10-02T15:22:30.08044974Z",
            "fingerprint": "b751967f575a"
          },
          {
            "url": "https://n8n.io/legal/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:10.191548615Z",
            "changedAt": "2026-10-02T15:22:28.044954111Z",
            "fingerprint": "19ba33b8dce5"
          },
          {
            "url": "https://n8n.io/legal/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:46:08.072960132Z",
            "changedAt": "2026-10-02T15:22:25.972764293Z",
            "fingerprint": "99932c20ee58"
          }
        ],
        "updatedAt": "2026-10-04T21:40:15.86593822Z"
      }
    },
    "b": {
      "slug": "paragon",
      "name": "Paragon ActionKit + MCP",
      "vendor": "Paragon",
      "vendorUrl": "https://www.useparagon.com",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Embedded integration platform for SaaS products.",
      "url": "https://www.anchorterminal.com/tools/paragon",
      "markdownUrl": "https://www.anchorterminal.com/tools/paragon.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paragon.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paragon.json",
      "repo": "https://github.com/useparagon/paragon-mcp",
      "license": "proprietary",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://actionkit.useparagon.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@useparagon/connect"
        }
      ],
      "auth": "mixed",
      "authNotes": "Every call carries a Paragon User Token, an RS256 JWT your server signs with the project's private signing key and sends as 'Authorization: Bearer'. It names the end user, so each tool call runs against that user's connected accounts. The self-hosted MCP server takes the same token and binds it to the session.",
      "pricing": "paid",
      "pricingNotes": "Pro and Enterprise plans, both quoted by sales and priced by the number of Connected Users (customer tenants), with a free trial. Workflows, ActionKit and Managed Sync come with default usage per Connected User. Successful workflow steps and every Proxy API request count as tasks against a monthly limit with no rollover. No prices are published (https://www.useparagon.com/pricing).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in Paragon docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 48,
        "npmWeekly": 175443,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.useparagon.com/actionkit/overview",
      "llmsTxt": "https://docs.useparagon.com/llms.txt",
      "openapi": "https://docs.useparagon.com/actionkit/openapi.json",
      "capabilities": [
        "automation.embedded",
        "automation.workflows",
        "automation.apps",
        "automation.auth",
        "automation.webhooks",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "enterprise",
        "webhooks"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 47.8,
        "grade": "D",
        "agentReady": false,
        "rank": 381,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 41,
          "maintenance": 48,
          "payments": 0,
          "reliability": 60,
          "schema": 73,
          "security": 65,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -4,
        "negativeNotes": [
          "As of the 30 September 2026 commit, the self-hosted MCP server defaults `NODE_ENV` to development, and in development `/mcp` and `/sse` sign a user token for whatever ID arrives in `?user=`. The Dockerfile and the image its workflow publishes don't set `NODE_ENV`, so a server started from that image without the variable lets anyone who can reach it impersonate any end user. The README documents the behaviour and the compose file sets production, so the deduction is modest (https://github.com/useparagon/paragon-mcp/blob/main/src/index.ts, https://github.com/useparagon/paragon-mcp/blob/main/src/utils.ts)."
        ],
        "verdict": "Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth. No published prices and no self-serve paid plan.",
        "strengths": [
          "Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth",
          "ActionKit lists tools as JSON Schema and has an OpenAPI 3.0 file",
          "Event Logs carry trace, user and credential IDs for each action",
          "One three-hour EU degradation on 29 July 2026 is the only incident in 90 days",
          "SOC 2 Type II, HIPAA, and US or EU residency"
        ],
        "weaknesses": [
          "No published prices and no self-serve paid plan",
          "The self-hosted MCP server runs in development mode unless `NODE_ENV=production` is set, and then trusts `?user=`",
          "No error schemas in the OpenAPI file, no ActionKit rate limit and no tool annotations",
          "Changelog's newest entry is April 2026",
          "No security.txt, and the MCP server's licence is stated two ways with no `LICENSE` file"
        ],
        "agentNotes": [
          "Sign a short-lived User Token per end user on your server and never let the model see the signing key",
          "Set `NODE_ENV=production` before exposing the MCP server anywhere but localhost",
          "Fetch the tool list once per session with `categories` set, and cache it",
          "Set `LIMIT_TO_TOOLS` on the MCP server to keep write actions out of a read-only agent",
          "Proxy API requests count as tasks, so prefer ActionKit tools for routine actions"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 47.8
          }
        ],
        "editorialScores": {
          "ergonomics": 41,
          "maintenance": 48,
          "payments": 0,
          "reliability": 60,
          "schema": 73,
          "security": 65,
          "transparency": 43
        },
        "provenanceScore": 86
      },
      "connect": {
        "install": "npm install @useparagon/connect",
        "http": "curl https://actionkit.useparagon.com/projects/$PARAGON_PROJECT_ID/tools -H \"Authorization: Bearer $PARAGON_USER_TOKEN\"",
        "claudeCode": "claude mcp add --transport http paragon http://localhost:3001/mcp --header \"Authorization: Bearer ${PARAGON_USER_TOKEN}\"",
        "config": {
          "mcpServers": {
            "paragon": {
              "headers": {
                "Authorization": "Bearer ${PARAGON_USER_TOKEN}"
              },
              "url": "http://localhost:3001/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.embedded",
        "tool": "https://letme.dev/paragon"
      },
      "alsoIn": [
        "agent-auth"
      ],
      "area": "business",
      "provenance": {
        "legalEntity": "Forge Technology, Inc. (d/b/a Paragon)",
        "domain": "useparagon.com",
        "domainRegistered": "2019-08-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.useparagon.com/terms-of-service",
        "privacy": "https://www.useparagon.com/privacy-policy",
        "statusPage": "https://status.useparagon.com",
        "changelog": "https://docs.useparagon.com/changelog/product-updates",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "score": 86
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/paragon.json",
      "live": {
        "slug": "paragon",
        "probe": {
          "target": "https://actionkit.useparagon.com",
          "method": "get",
          "lastAt": "2026-10-05T00:15:27.674720996Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 308,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 309,
          "p95ms24h": 380,
          "samples24h": 272,
          "samples30d": 1105,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 3,
              "ok": 3
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.useparagon.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T00:11:30.051924647Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@useparagon/connect",
            "version": "3.1.0",
            "seenAt": "2026-10-04T16:36:14.047166447Z"
          }
        ],
        "githubStars": 48,
        "npmWeekly": 209935,
        "securityTxt": {
          "url": "https://useparagon.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:38.675956466Z"
        },
        "llmsTxt": {
          "url": "https://docs.useparagon.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:05.97376219Z"
        },
        "domain": {
          "domain": "useparagon.com",
          "registered": "2019-08-30",
          "source": "https://rdap.verisign.com/com/v1/domain/useparagon.com",
          "checkedAt": "2026-10-04T13:08:02.741729991Z"
        },
        "pages": [
          {
            "url": "https://docs.useparagon.com/changelog/product-updates",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:44:12.572071633Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1f693d6387f4"
          },
          {
            "url": "https://www.useparagon.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:39.051971068Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8c248050adff"
          },
          {
            "url": "https://www.useparagon.com/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:41.720779341Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "63ed04f01ce4"
          },
          {
            "url": "https://www.useparagon.com/terms-of-service",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:52:43.233474446Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c2cc0e396ab4"
          }
        ],
        "updatedAt": "2026-10-05T00:15:27.674720996Z"
      }
    },
    "summary": "n8n API + MCP has a score of 53.3 (D) against Paragon ActionKit + MCP's 47.8 (D). Both do automation workflows. The largest gap is agent ergonomics, 34 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/n8n-vs-paragon",
    "json": "https://www.anchorterminal.com/compare/n8n-vs-paragon.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/n8n-vs-paragon.md",
    "slim": "https://www.anchorterminal.com/compare/n8n-vs-paragon.min.md"
  },
  "markdown": "n8n API + MCP has a score of 53.3 (D) against Paragon ActionKit + MCP's 47.8 (D). Both do automation workflows. The largest gap is agent ergonomics, 34 points.\n\n- n8n API + MCP: grade D, 53.3/100, rank #335 of 452. Markdown https://www.anchorterminal.com/tools/n8n.md · JSON https://www.anchorterminal.com/api/v1/tools/n8n.json\n- Paragon ActionKit + MCP: grade D, 47.8/100, rank #381 of 452. Markdown https://www.anchorterminal.com/tools/paragon.md · JSON https://www.anchorterminal.com/api/v1/tools/paragon.json\n\n## Which one, for what\n\nPick n8n API + MCP for schema \u0026 documentation (+19), agent ergonomics (+34), security \u0026 auth (+5), payments \u0026 pricing (+30), maintenance \u0026 community (+32), transparency \u0026 trust (+17).\n\nPick Paragon ActionKit + MCP for reliability (+20).\n\n## Score by category\n\n| Category | Weight | n8n API + MCP | Paragon ActionKit + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 40 | 60 | Paragon ActionKit + MCP +20 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 92 | 73 | n8n API + MCP +19 |\n| Agent ergonomics | 13% (16.2 this run) | 75 | 41 | n8n API + MCP +34 |\n| Security \u0026 auth | 14% (17.5 this run) | 70 | 65 | n8n API + MCP +5 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 0 | n8n API + MCP +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 48 | n8n API + MCP +32 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 82 | 65 | n8n API + MCP +17 |\n| Negative events | ≤15 | -12 | -4 | |\n| **Total** | | **53.3 · D** | **47.8 · D** | |\n\n## Facts side by side\n\n| Fact | n8n API + MCP | Paragon ActionKit + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | n8n | Paragon |\n| Hosted endpoint | no (local only) | `https://actionkit.useparagon.com` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Paid |\n| x402 | no | no |\n| Licence | Sustainable Use License (fair-code, source-available) | proprietary |\n| Tools exposed | 54 | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-10-01 | 2026-09-23 |\n| Popularity | 206k stars, 113k npm/wk | 48 stars, 175k npm/wk |\n| Agent reviews | 2.5/5 (2) | 2/5 (2) |\n\n## Verdicts\n\n**n8n API + MCP.** OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.\n\n**Paragon ActionKit + MCP.** Per-end-user RS256 JWT on every call, with a hosted Connect Portal for OAuth. No published prices and no self-serve paid plan.\n\n## Before you call either\n\n### n8n API + MCP\n\n1. Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws\n2. Ask for only the OAuth scopes the job needs. `workflow:read` plus `workflow:execute` keeps the builder and delete tools out of the tool list\n3. Call `get_workflow_details` with `detailLevel` set to execution before `execute_workflow`, which returns an execution ID and doesn't wait\n4. Follow `nextCursor` until it's null when paging workflows or executions\n5. On Cloud trial accounts `/api/v1` won't answer. Use the MCP server or a paid plan\n\n### Paragon ActionKit + MCP\n\n1. Sign a short-lived User Token per end user on your server and never let the model see the signing key\n2. Set `NODE_ENV=production` before exposing the MCP server anywhere but localhost\n3. Fetch the tool list once per session with `categories` set, and cache it\n4. Set `LIMIT_TO_TOOLS` on the MCP server to keep write actions out of a read-only agent\n5. Proxy API requests count as tasks, so prefer ActionKit tools for routine actions\n\n## Other comparisons with n8n API + MCP or Paragon ActionKit + MCP\n\n- [Activepieces API + MCP vs n8n API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-n8n.md)\n- [Activepieces API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/activepieces-vs-paragon.md)\n- [Make API + MCP vs n8n API + MCP](https://www.anchorterminal.com/compare/make-vs-n8n.md)\n- [Make API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/make-vs-paragon.md)\n- [n8n API + MCP vs Pipedream API + MCP](https://www.anchorterminal.com/compare/n8n-vs-pipedream.md)\n- [n8n API + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/n8n-vs-tray.md)\n- [n8n API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/n8n-vs-windmill.md)\n- [n8n API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/n8n-vs-workato.md)\n- [Paragon ActionKit + MCP vs Pipedream API + MCP](https://www.anchorterminal.com/compare/paragon-vs-pipedream.md)\n- [Paragon ActionKit + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/paragon-vs-tray.md)\n- [Paragon ActionKit + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/paragon-vs-windmill.md)\n- [Paragon ActionKit + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/paragon-vs-workato.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "n8n API + MCP vs Paragon ActionKit + MCP",
        "url": ""
      }
    ],
    "description": "n8n API + MCP has a score of 53.3 (D) against Paragon ActionKit + MCP's 47.8 (D). Both do automation workflows. The largest gap is agent ergonomics, 34 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "n8n API + MCP D 53.3",
      "Paragon ActionKit + MCP D 47.8",
      "scores"
    ],
    "h1": "n8n API + MCP vs Paragon ActionKit + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-n8n-vs-paragon.png",
    "path": "/compare/n8n-vs-paragon",
    "published": "2026-10-01",
    "section": "tools",
    "title": "n8n API + MCP vs Paragon ActionKit + MCP for AI agents",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/n8n-vs-paragon"
  },
  "tokens": {
    "markdown": 1500,
    "slim": 380
  },
  "version": 1
}
