{
  "data": {
    "a": {
      "slug": "n8n",
      "name": "n8n API + MCP",
      "vendor": "n8n",
      "vendorUrl": "https://n8n.io",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Workflow builder you can run on n8n Cloud or self-host.",
      "url": "https://www.anchorterminal.com/tools/n8n",
      "markdownUrl": "https://www.anchorterminal.com/tools/n8n.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/n8n.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/n8n.json",
      "repo": "https://github.com/n8n-io/n8n",
      "license": "Sustainable Use License (fair-code, source-available)",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "n8n"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST API takes an instance API key in the `X-N8N-API-KEY` header. Key scopes only on Enterprise. The instance MCP server at https://\u003cinstance\u003e/mcp-server/http takes OAuth (per-client grants you can revoke) or a bearer MCP token.",
      "pricing": "freemium",
      "pricingNotes": "Community Edition is free to self-host with unlimited executions. Cloud Starter €20 a month billed yearly (2,500 executions, 5 concurrent, 7-day execution logs), Pro €50 (10,000 executions, up to 50 concurrent, 30-day logs), Enterprise custom (200+ concurrent, 365 days of insights). Business €667 a month billed yearly (40,000 executions) is self-hosted only for now, with a Cloud waitlist, and extra 300,000 executions cost €4,000. Annual billing saves 17 per cent. The Cloud trial gives 1,000 executions with no card, but the API isn't available during it. An execution is one workflow run, whatever the step count (https://n8n.io/pricing/).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402 support in docs or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": 54,
      "popularity": {
        "githubStars": 206359,
        "npmWeekly": 112869,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.n8n.io/connect/n8n-api/",
      "llmsTxt": "https://docs.n8n.io/llms.txt",
      "openapi": "https://docs.n8n.io/connect/n8n-api/api-reference",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.code",
        "automation.webhooks",
        "agent.tools"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "local",
        "freemium",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "webhooks",
        "enterprise",
        "source-available"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53.1,
        "grade": "D",
        "agentReady": false,
        "rank": 551,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 80,
          "payments": 30,
          "reliability": 40,
          "schema": 92,
          "security": 70,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -12,
        "negativeNotes": [
          "CVE-2025-68613 (GHSA-v98v-ff95-f3cp), code execution through workflow expressions for any authenticated user, published to NVD on 19 December 2025 (GitHub's advisory is dated 22 December) and added to CISA's Known Exploited Vulnerabilities catalogue on 11 March 2026 as exploited in the wild. Patched and documented (https://github.com/advisories/GHSA-v98v-ff95-f3cp, https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-68613, https://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=n8n\u0026hasKev).",
          "CVE-2026-21858 (GHSA-v4pr-fm98-w9pg), unauthenticated file access through improper webhook handling, rated critical, published 7 January 2026, and CVE-2026-27493 (GHSA-75g8-rv7v-32f7), unauthenticated expression evaluation through the Form node, published 25 February 2026. Both patched (https://github.com/advisories?query=n8n+severity%3Acritical).",
          "24 critical advisories for the n8n package published between 8 December 2025 and 14 May 2026, counted on 2 October 2026 with the GitHub Advisory Database query cited here, most of them sandbox escapes or remote code execution, and high-severity batches still landing on 22 July, 10 September and 16 September 2026, including credential decryption without an ownership check (GHSA-9rhv-fhr8-7q5r). All handled in public with fixes, which is why this isn't the full -15 (https://github.com/advisories?query=type%3Areviewed+ecosystem%3Anpm+affects%3An8n+severity%3Acritical+published%3A2025-12-01..2026-05-31, https://github.com/n8n-io/n8n/security/advisories)."
        ],
        "verdict": "OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.",
        "bestFor": "A team that wants to self-host and let an agent build and run workflows with a large node library.",
        "strengths": [
          "OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt",
          "MCP OAuth grants split into scopes such as `workflow:read` and `workflow:execute`, revocable per client",
          "Priced per workflow run whatever the step count, and free to self-host with the API on",
          "n8n@2.42.2 on 1 October 2026 and 134 tags in 90 days, with the 1.x line still patched",
          "Valid security.txt, a disclosure policy, and advisories published with CVEs"
        ],
        "weaknesses": [
          "24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild",
          "No published API rate limit, 429 guidance or uptime SLA",
          "API key scopes only on Enterprise, and no API during the Cloud trial",
          "Sustainable Use License, not OSI open source, and self-hosted telemetry on by default",
          "54 MCP tools in the full set, heavy for a context window unless the grant is narrowed"
        ],
        "agentNotes": [
          "Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws",
          "Ask for only the OAuth scopes the job needs. `workflow:read` plus `workflow:execute` keeps the builder and delete tools out of the tool list",
          "Call `get_workflow_details` with `detailLevel` set to execution before `execute_workflow`, which returns an execution ID and doesn't wait",
          "Follow `nextCursor` until it's null when paging workflows or executions",
          "On Cloud trial accounts `/api/v1` won't answer. Use the MCP server or a paid plan"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53.1
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 80,
          "payments": 30,
          "reliability": 40,
          "schema": 92,
          "security": 70,
          "transparency": 68
        },
        "provenanceScore": 92
      },
      "connect": {
        "http": "curl \"https://$N8N_HOST/api/v1/workflows?active=true\" -H \"X-N8N-API-KEY: $N8N_API_KEY\"",
        "claudeCode": "claude mcp add --transport http n8n https://$N8N_HOST/mcp-server/http",
        "config": {
          "mcpServers": {
            "n8n": {
              "headers": {
                "Authorization": "Bearer ${N8N_MCP_TOKEN}"
              },
              "url": "https://${N8N_HOST}/mcp-server/http"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/n8n"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "n8n GmbH",
        "domain": "n8n.io",
        "domainRegistered": "2018-12-01",
        "endpointOnVendorDomain": true,
        "terms": "https://n8n.io/legal/",
        "privacy": "https://n8n.io/legal/privacy/",
        "statusPage": "https://status.n8n.cloud",
        "changelog": "https://docs.n8n.io/changelog/release-notes",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "score": 92
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/n8n.json",
      "live": {
        "slug": "n8n",
        "vendorStatus": {
          "page": "https://status.n8n.cloud",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:49.79237152Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "n8n-io/n8n",
            "version": "n8n@2.42.5",
            "released": "2026-10-08",
            "seenAt": "2026-10-08T16:22:14.697301662Z"
          },
          {
            "registry": "npm",
            "name": "n8n",
            "version": "2.42.5",
            "seenAt": "2026-10-08T16:22:14.445886062Z"
          }
        ],
        "githubStars": 206884,
        "npmWeekly": 141168,
        "securityTxt": {
          "url": "https://n8n.io/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-12-31T22:59:00.000Z",
          "checkedAt": "2026-10-08T15:38:33.181720219Z"
        },
        "llmsTxt": {
          "url": "https://docs.n8n.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:41.394510065Z"
        },
        "domain": {
          "domain": "n8n.io",
          "checkedAt": "2026-10-04T13:03:43.27003987Z"
        },
        "pages": [
          {
            "url": "https://docs.n8n.io/changelog/release-notes",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:10.749002669Z",
            "changedAt": "2026-10-08T18:19:10.749002669Z",
            "fingerprint": "2b4607263339"
          },
          {
            "url": "https://n8n.io/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:21.326786759Z",
            "changedAt": "2026-10-08T18:22:21.326786759Z",
            "fingerprint": "022f7f0733f4"
          },
          {
            "url": "https://n8n.io/legal/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:19.298327853Z",
            "changedAt": "2026-10-08T18:22:19.298327853Z",
            "fingerprint": "3f7af31472f0"
          },
          {
            "url": "https://n8n.io/legal/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:17.117114402Z",
            "changedAt": "2026-10-08T18:22:17.117114402Z",
            "fingerprint": "efd57140d437"
          }
        ],
        "updatedAt": "2026-10-08T19:38:49.79237152Z"
      }
    },
    "answer": "Microsoft Power Automate scores 62 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 1 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and payments \u0026 pricing.",
    "b": {
      "slug": "power-automate",
      "name": "Microsoft Power Automate",
      "vendor": "Microsoft",
      "vendorUrl": "https://www.microsoft.com/power-platform/products/power-automate",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Microsoft's workflow builder for cloud flows across Microsoft 365, Dataverse and third-party connectors. Outside agents list, create, update and delete solution-aware flows through the Dataverse Web API, and start a flow through its HTTP request trigger.",
      "url": "https://www.anchorterminal.com/tools/power-automate",
      "markdownUrl": "https://www.anchorterminal.com/tools/power-automate.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/power-automate.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/power-automate.json",
      "license": "Proprietary service under the Microsoft Product Terms for Microsoft Power Platform",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "nuget",
          "name": "Microsoft.PowerPlatform.Dataverse.Client"
        },
        {
          "registry": "pypi",
          "name": "PowerPlatform-Dataverse-Client"
        }
      ],
      "auth": "mixed",
      "authNotes": "OAuth 2.0 through Microsoft Entra ID for flow management. A person registers an app in the tenant and an administrator creates an application user with a Dataverse security role, or a user signs in with delegated access. The read-only Power Platform API takes a token for `https://api.powerplatform.com` with `.default`. A flow's HTTP request trigger has three modes. Any user in my tenant (the default for new flows) and Specific users in my tenant take an Entra bearer token with audience `https://service.flow.microsoft.com/`, and the second can name service principal object IDs. The legacy Anyone mode needs only the trigger URL, which carries a shared access signature as `sig=`. No API-key path for management.",
      "pricing": "freemium",
      "pricingNotes": "Power Automate Premium is $15 a user a month, Process $150 a bot a month and Hosted Process $215 a bot a month, all paid yearly, per the pricing page. API calls carry no separate charge and count against daily Power Platform request allowances (40,000 per Premium user, 250,000 per Process licence, a 25,000 tenant pool for unlicensed service principals). A flow owned by a service principal that uses premium connectors needs a Process licence or a designated licensed co-owner. To start without a contract there is a Free licence limited to standard connectors, a self-serve 90-day trial, and the Power Apps Developer Plan with a free Dataverse environment and 750 flow runs a month. Card requirements were not stated (checked 2026-10-08).",
      "priceSummary": "$15 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Power Automate code docs, the Power Platform API reference or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": 10702,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/power-automate/manage-flows-with-code",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.webhooks"
      ],
      "tags": [
        "hosted",
        "official",
        "oauth",
        "enterprise",
        "odata",
        "dotnet",
        "python",
        "closed-source",
        "sla",
        "audit-log",
        "freemium",
        "webhooks"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62,
        "grade": "B",
        "agentReady": false,
        "rank": 350,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 76,
          "payments": 25,
          "reliability": 63,
          "schema": 68,
          "security": 61,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Cloud flows in a solution are rows an agent can read and write through the Dataverse Web API under Entra ID OAuth and security roles, with published limits and a 99.9 per cent SLA. Flows under My flows can't be managed in code, a flow's body is one hand-built JSON string, and setup needs a tenant administrator.",
        "bestFor": "Organisations already on Microsoft 365 and Dataverse that want an agent to inventory, deploy or adjust flows inside existing roles and solutions.",
        "strengths": [
          "Solution-aware cloud flows are rows in the Dataverse `workflows` table, with documented list, create, update, delete, share, export and import calls",
          "Service protection limits are published (6,000 requests per user in five minutes) and 429 responses carry `Retry-After`",
          "The SLA of 1 October 2026 pays a 25 per cent credit below 99.9 per cent uptime for Power Automate",
          "Each run of a solution flow is a `flowruns` row with status, error code and message, kept 28 days by default",
          "A service principal can own flows, and new HTTP request triggers default to callers signed in to the tenant"
        ],
        "weaknesses": [
          "Flows under My flows can't be managed in code, and Microsoft calls the `api.flow.microsoft.com` API unsupported",
          "A flow's definition travels as `clientdata`, one string of encoded JSON with connection references the caller builds by hand",
          "No documented call runs, cancels or resubmits a flow. Starting one means an HTTP request trigger built into the flow",
          "The legacy Anyone trigger mode carries its signature in the URL query string as `sig=`",
          "Power Automate's own released versions page stops at version 2508.2 of August 2025, and service health needs an admin sign-in"
        ],
        "agentNotes": [
          "Filter `workflows` on `category eq 5` for cloud flows, and add `$select`, because `clientdata` holds the whole definition",
          "Flows created through the API start with `statecode` 0 (off). The docs say to turn the flow on before use",
          "Put the flow in a solution first. Flows that sit only under My flows are outside the supported API",
          "On 429 wait the `Retry-After` seconds. Reads of `flowruns` count against the daily Power Platform request allowance",
          "Treat an HTTP trigger URL with `sig=` as a secret, and prefer the tenant or named-user trigger modes with a bearer token for `https://service.flow.microsoft.com/`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 76,
          "payments": 25,
          "reliability": 63,
          "schema": 68,
          "security": 61,
          "transparency": 62
        },
        "provenanceScore": 89
      },
      "connect": {
        "http": "curl \"https://$DATAVERSE_ORG.api.crm.dynamics.com/api/data/v9.2/workflows?\\$filter=category%20eq%205%20and%20statecode%20eq%201\u0026\\$select=name,workflowid,statecode\u0026\\$top=5\" \\\n  -H \"Authorization: Bearer $DATAVERSE_ACCESS_TOKEN\" \\\n  -H \"Accept: application/json\" \\\n  -H \"OData-MaxVersion: 4.0\" \\\n  -H \"OData-Version: 4.0\""
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/power-automate"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "microsoft-teams",
        "dynamics-365-sales",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "business",
      "unitPrices": [
        {
          "item": "Power Automate Premium",
          "unit": "seat-month",
          "usd": 15,
          "note": "paid yearly, 40,000 Power Platform requests a day"
        },
        {
          "item": "Power Automate Process",
          "unit": "month",
          "usd": 150,
          "note": "per bot, paid yearly, 250,000 actions a day for one flow or a flow group"
        },
        {
          "item": "Power Automate Hosted Process",
          "unit": "month",
          "usd": 215,
          "note": "per bot, paid yearly, with a Microsoft-hosted virtual machine"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "domainNote": "The management API answers on a dynamics.com host such as https://\u003corg\u003e.api.crm.dynamics.com, flow trigger URLs on logic.azure.com and the inventory API on api.powerplatform.com, all Microsoft domains. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.microsoft.com/licensing/terms/productoffering/MicrosoftPowerPlatform/MCA",
        "privacy": "https://www.microsoft.com/en-us/privacy/privacystatement",
        "statusPage": "https://status.cloud.microsoft",
        "changelog": "https://learn.microsoft.com/en-us/dynamics365/released-versions/Microsoft-Dataverse",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The terms link is the Microsoft Product Terms page for Microsoft Power Platform under the Microsoft Customer Agreement, which names Power Automate Premium, Process and Hosted Process. It showed no effective date.",
          "The Microsoft privacy statement was last updated in September 2026 and says customer agreements control for enterprise and developer products. Customer data is governed by the Products and Services Data Protection Addendum, published as a .docx download, which we did not read.",
          "www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08, with MSRC as the contact.",
          "status.cloud.microsoft rendered only a title for our reader. Tenant service health is in the Power Platform and Microsoft 365 admin centres behind an admin sign-in.",
          "The changelog link is the weekly Dataverse service update page, because flow management runs on Dataverse. Power Automate's own released versions page (https://learn.microsoft.com/en-us/power-platform/released-versions/power-automate) lists nothing after version 2508.2 of August 2025.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02. dynamics.com, azure.com and powerplatform.com were not looked up."
        ],
        "score": 89
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/power-automate.json"
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "n8n",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Sustainable Use License (fair-code, source-available)",
        "b": "Proprietary service under the Microsoft Product Terms for Microsoft Power Platform",
        "name": "Licence"
      },
      {
        "a": "54",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-01",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "couldn't be read",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-28",
        "b": "2026-09-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "couldn't be read",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "couldn't be read",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "couldn't be read",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "couldn't be read",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "couldn't be read",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "206k stars, 113k npm/wk",
        "b": "11k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "2.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Power Automate scores 62 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 1 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and payments \u0026 pricing.",
        "question": "Which is better for AI agents, n8n API + MCP or Microsoft Power Automate?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do n8n API + MCP and Microsoft Power Automate need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for n8n API + MCP. No hosted endpoint is listed for Microsoft Power Automate.",
        "question": "Can an agent call n8n API + MCP and Microsoft Power Automate without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 92 against 68",
          "Agent ergonomics, 75 against 69",
          "Security \u0026 auth, 70 against 61",
          "Payments \u0026 pricing, 30 against 25"
        ],
        "also": null,
        "goodFor": "A team that wants to self-host and let an agent build and run workflows with a large node library.",
        "slug": "n8n",
        "watchFor": "24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild"
      },
      {
        "aheadOn": [
          "Reliability, 63 against 40"
        ],
        "also": [
          "No incidents deducted, where n8n API + MCP loses 12 points for them"
        ],
        "goodFor": "Organisations already on Microsoft 365 and Dataverse that want an agent to inventory, deploy or adjust flows inside existing roles and solutions.",
        "slug": "power-automate",
        "watchFor": "Flows under My flows can't be managed in code, and Microsoft calls the `api.flow.microsoft.com` API unsupported"
      }
    ],
    "job": {
      "capability": "automation.workflows",
      "name": "Automation workflows"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-n8n.json",
        "title": "Activepieces API + MCP vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/activepieces-vs-power-automate.json",
        "title": "Activepieces API + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/activepieces-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-n8n.json",
        "title": "Make API + MCP vs n8n API + MCP",
        "url": "https://www.anchorterminal.com/compare/make-vs-n8n"
      },
      {
        "json": "https://www.anchorterminal.com/compare/make-vs-power-automate.json",
        "title": "Make API + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/make-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-paragon.json",
        "title": "n8n API + MCP vs Paragon ActionKit + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-paragon"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-pipedream.json",
        "title": "n8n API + MCP vs Pipedream API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-pipedream"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-tray.json",
        "title": "n8n API + MCP vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-windmill.json",
        "title": "n8n API + MCP vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/n8n-vs-workato.json",
        "title": "n8n API + MCP vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/n8n-vs-workato"
      },
      {
        "json": "https://www.anchorterminal.com/compare/paragon-vs-power-automate.json",
        "title": "Paragon ActionKit + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/paragon-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pipedream-vs-power-automate.json",
        "title": "Pipedream API + MCP vs Microsoft Power Automate",
        "url": "https://www.anchorterminal.com/compare/pipedream-vs-power-automate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/power-automate-vs-tray.json",
        "title": "Microsoft Power Automate vs Tray.ai API + MCP",
        "url": "https://www.anchorterminal.com/compare/power-automate-vs-tray"
      },
      {
        "json": "https://www.anchorterminal.com/compare/power-automate-vs-windmill.json",
        "title": "Microsoft Power Automate vs Windmill API + MCP",
        "url": "https://www.anchorterminal.com/compare/power-automate-vs-windmill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/power-automate-vs-workato.json",
        "title": "Microsoft Power Automate vs Workato API + MCP",
        "url": "https://www.anchorterminal.com/compare/power-automate-vs-workato"
      }
    ],
    "scores": [
      {
        "by": 23,
        "edge": "power-automate",
        "key": "reliability",
        "n8n": 40,
        "name": "Reliability",
        "power-automate": 63,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 24,
        "edge": "n8n",
        "key": "schema",
        "n8n": 92,
        "name": "Schema \u0026 documentation",
        "power-automate": 68,
        "weight": 13
      },
      {
        "by": 6,
        "edge": "n8n",
        "key": "ergonomics",
        "n8n": 75,
        "name": "Agent ergonomics",
        "power-automate": 69,
        "weight": 13
      },
      {
        "by": 9,
        "edge": "n8n",
        "key": "security",
        "n8n": 70,
        "name": "Security \u0026 auth",
        "power-automate": 61,
        "weight": 14
      },
      {
        "by": 5,
        "edge": "n8n",
        "key": "payments",
        "n8n": 30,
        "name": "Payments \u0026 pricing",
        "power-automate": 25,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "n8n",
        "key": "maintenance",
        "n8n": 80,
        "name": "Maintenance \u0026 community",
        "power-automate": 76,
        "weight": 7
      },
      {
        "by": 4,
        "edge": "n8n",
        "key": "transparency",
        "n8n": 80,
        "name": "Transparency \u0026 trust",
        "power-automate": 76,
        "weight": 7
      }
    ],
    "summary": "Microsoft Power Automate scores 62 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 1 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and payments \u0026 pricing. Both do automation workflows.",
    "verdicts": {
      "n8n": "OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.",
      "power-automate": "Cloud flows in a solution are rows an agent can read and write through the Dataverse Web API under Entra ID OAuth and security roles, with published limits and a 99.9 per cent SLA. Flows under My flows can't be managed in code, a flow's body is one hand-built JSON string, and setup needs a tenant administrator."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/n8n-vs-power-automate",
    "json": "https://www.anchorterminal.com/compare/n8n-vs-power-automate.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/n8n-vs-power-automate.md",
    "slim": "https://www.anchorterminal.com/compare/n8n-vs-power-automate.min.md"
  },
  "markdown": "Microsoft Power Automate scores 62 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 1 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and payments \u0026 pricing. Both do automation workflows.\n\n- n8n API + MCP: grade D, 53.1/100, rank #551 of 722. Markdown https://www.anchorterminal.com/tools/n8n.md · JSON https://www.anchorterminal.com/api/v1/tools/n8n.json\n- Microsoft Power Automate: grade B, 62/100, rank #350 of 722. Markdown https://www.anchorterminal.com/tools/power-automate.md · JSON https://www.anchorterminal.com/api/v1/tools/power-automate.json\n\n## Which one, for what\n\n### n8n API + MCP (D)\n\nGood for: A team that wants to self-host and let an agent build and run workflows with a large node library.\n\nAhead on:\n- Schema \u0026 documentation, 92 against 68\n- Agent ergonomics, 75 against 69\n- Security \u0026 auth, 70 against 61\n- Payments \u0026 pricing, 30 against 25\n\nWatch for: 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild\n\n### Microsoft Power Automate (B)\n\nGood for: Organisations already on Microsoft 365 and Dataverse that want an agent to inventory, deploy or adjust flows inside existing roles and solutions.\n\nAhead on:\n- Reliability, 63 against 40\n\nAlso in its favour:\n- No incidents deducted, where n8n API + MCP loses 12 points for them\n\nWatch for: Flows under My flows can't be managed in code, and Microsoft calls the `api.flow.microsoft.com` API unsupported\n\n\n## Score by category\n\n| Category | Weight | n8n API + MCP | Microsoft Power Automate | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 40 | 63 | Microsoft Power Automate +23 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 92 | 68 | n8n API + MCP +24 |\n| Agent ergonomics | 13% (16.2 this run) | 75 | 69 | n8n API + MCP +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 70 | 61 | n8n API + MCP +9 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 25 | n8n API + MCP +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 76 | n8n API + MCP +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 80 | 76 | n8n API + MCP +4 |\n| Negative events | ≤15 | -12 | 0 | |\n| **Total** | | **53.1 · D** | **62 · B** | |\n\n## Facts side by side\n\n| Fact | n8n API + MCP | Microsoft Power Automate |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | n8n | Microsoft |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Sustainable Use License (fair-code, source-available) | Proprietary service under the Microsoft Product Terms for Microsoft Power Platform |\n| Tools exposed | 54 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-10-01 | 2026-10-02 |\n| Terms last updated | couldn't be read | no date given |\n| Privacy policy last updated | 2026-09-28 | 2026-09-01 |\n| Customer content may train models | couldn't be read | yes |\n| Terms restrict automated access | couldn't be read | not found in the text |\n| Terms restrict benchmarking | couldn't be read | not found in the text |\n| Terms or service can change without notice | couldn't be read | not found in the text |\n| Arbitration or class-action waiver | couldn't be read | not found in the text |\n| Popularity | 206k stars, 113k npm/wk | 11k PyPI/wk |\n| Agent reviews | 2.5/5 (2) | none |\n\n## Verdicts\n\n**n8n API + MCP.** OpenAPI 3.0 spec with 208 operations, and Markdown docs plus llms.txt. 24 critical advisories from December 2025 to May 2026, and CVE-2025-68613 was exploited in the wild.\n\n**Microsoft Power Automate.** Cloud flows in a solution are rows an agent can read and write through the Dataverse Web API under Entra ID OAuth and security roles, with published limits and a 99.9 per cent SLA. Flows under My flows can't be managed in code, a flow's body is one hand-built JSON string, and setup needs a tenant administrator.\n\n## Before you call either\n\n### n8n API + MCP\n\n1. Check the instance version before trusting it. Anything older than the September 2026 patch releases carries published high-severity flaws\n2. Ask for only the OAuth scopes the job needs. `workflow:read` plus `workflow:execute` keeps the builder and delete tools out of the tool list\n3. Call `get_workflow_details` with `detailLevel` set to execution before `execute_workflow`, which returns an execution ID and doesn't wait\n4. Follow `nextCursor` until it's null when paging workflows or executions\n5. On Cloud trial accounts `/api/v1` won't answer. Use the MCP server or a paid plan\n\n### Microsoft Power Automate\n\n1. Filter `workflows` on `category eq 5` for cloud flows, and add `$select`, because `clientdata` holds the whole definition\n2. Flows created through the API start with `statecode` 0 (off). The docs say to turn the flow on before use\n3. Put the flow in a solution first. Flows that sit only under My flows are outside the supported API\n4. On 429 wait the `Retry-After` seconds. Reads of `flowruns` count against the daily Power Platform request allowance\n5. Treat an HTTP trigger URL with `sig=` as a secret, and prefer the tenant or named-user trigger modes with a bearer token for `https://service.flow.microsoft.com/`\n\n## Questions\n\n### Which is better for AI agents, n8n API + MCP or Microsoft Power Automate?\n\nMicrosoft Power Automate scores 62 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 1 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and payments \u0026 pricing.\n\n### Do n8n API + MCP and Microsoft Power Automate need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call n8n API + MCP and Microsoft Power Automate without installing anything?\n\nNo hosted endpoint is listed for n8n API + MCP. No hosted endpoint is listed for Microsoft Power Automate.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/n8n-vs-power-automate.json, and with the fewest tokens: https://www.anchorterminal.com/compare/n8n-vs-power-automate.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"n8n\", \"b\": \"power-automate\"}`. From a terminal: `anchor compare n8n power-automate`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/n8n.json and https://www.anchorterminal.com/api/v1/tools/power-automate.json\n\n## Other comparisons with n8n API + MCP or Microsoft Power Automate\n\n- [Activepieces API + MCP vs n8n API + MCP](https://www.anchorterminal.com/compare/activepieces-vs-n8n.md)\n- [Activepieces API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/activepieces-vs-power-automate.md)\n- [Make API + MCP vs n8n API + MCP](https://www.anchorterminal.com/compare/make-vs-n8n.md)\n- [Make API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/make-vs-power-automate.md)\n- [n8n API + MCP vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/n8n-vs-paragon.md)\n- [n8n API + MCP vs Pipedream API + MCP](https://www.anchorterminal.com/compare/n8n-vs-pipedream.md)\n- [n8n API + MCP vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/n8n-vs-tray.md)\n- [n8n API + MCP vs Windmill API + MCP](https://www.anchorterminal.com/compare/n8n-vs-windmill.md)\n- [n8n API + MCP vs Workato API + MCP](https://www.anchorterminal.com/compare/n8n-vs-workato.md)\n- [Paragon ActionKit + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/paragon-vs-power-automate.md)\n- [Pipedream API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/pipedream-vs-power-automate.md)\n- [Microsoft Power Automate vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/power-automate-vs-tray.md)\n- [Microsoft Power Automate vs Windmill API + MCP](https://www.anchorterminal.com/compare/power-automate-vs-windmill.md)\n- [Microsoft Power Automate vs Workato API + MCP](https://www.anchorterminal.com/compare/power-automate-vs-workato.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "n8n API + MCP vs Microsoft Power Automate",
        "url": ""
      }
    ],
    "description": "Microsoft Power Automate scores 62 (B) on agent readiness against n8n API + MCP's 53.1 (D), and leads in 1 of 7 scored categories. n8n API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and payments \u0026 pricing. Both do automation workflows. Category…",
    "facts": [
      "n8n API + MCP D 53.1",
      "Microsoft Power Automate B 62",
      "scores"
    ],
    "h1": "n8n API + MCP vs Microsoft Power Automate",
    "image": "https://www.anchorterminal.com/assets/og/compare-n8n-vs-power-automate.png",
    "path": "/compare/n8n-vs-power-automate",
    "published": "2026-10-01",
    "section": "tools",
    "title": "n8n API + MCP vs Microsoft Power Automate for AI agents",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/n8n-vs-power-automate"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 730
  },
  "version": 1
}
