# Node-RED
> Node-RED is an open-source flow-based automation runtime hosted by the OpenJS Foundation. The owner runs it on Node.js, and an Admin HTTP API and a command-line client deploy flows and install nodes.
- Canonical: https://www.anchorterminal.com/tools/node-red
- Markdown: https://www.anchorterminal.com/tools/node-red.md (~6,550 tokens)
- Slim: https://www.anchorterminal.com/tools/node-red.min.md (~1,830 tokens, same facts, less prose, for token-sensitive contexts)
- JSON: https://www.anchorterminal.com/tools/node-red.json (this page as data, same URL with Accept: application/json)
- Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt)
- API: https://www.anchorterminal.com/api/v1/index.json
- Updated: 2026-10-09
## Overview
**Grade C · 61/100 · rank #486 of 950 · #5 in Workflow automation · not agent-ready · confidence medium**
## Assessment
Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.
## Facts
| Field | Value |
| --- | --- |
| Vendor | OpenJS Foundation (https://nodered.org) |
| Kind | HTTP API |
| Category | Workflow automation (https://www.anchorterminal.com/categories/workflow-automation) |
| Transport | HTTP |
| Auth | OAuth or key · A default install has no authentication. Setting `adminAuth` in `settings.js` turns on users with bcrypt-hashed passwords and permissions of `*`, `read` or a list such as `flows.read`. An agent then posts the username and password to `/auth/token` for a bearer token, valid seven days by default with no refresh. Access is self-serve, by running the software. Routes made by HTTP In nodes share one basic-auth username and password. |
| Pricing | Free (Free · OSS) · Free under Apache-2.0 with nothing to buy from the project, so an agent can start with no account, card or contract. FlowFuse, a separate company, sells a hosted platform for Node-RED that the docs link, and it is not graded here (https://nodered.org/about/license/, checked 2026-10-09). |
| x402 | No · No x402, MPP or L402 in the docs or the source. The project sells nothing (checked 2026-10-09). |
| Licence | Apache-2.0 |
| Packages | npm: `node-red`; npm: `node-red-admin`; oci: `nodered/node-red` |
| Source | https://github.com/node-red/node-red |
| Docs | https://nodered.org/docs/api/admin/ |
| llms.txt | not found |
| Last release | 2026-10-08 |
| GitHub stars | 23,729 (as of 2026-10-09) |
| npm downloads / week | 55,172 |
| Version graded | Node-RED 5.0.8 (8 October 2026), self-hosted. Requires Node.js 22.9 or later, and the project recommends Node 24. FlowFuse, a separate company's hosted platform for Node-RED, is not graded here |
| Admin API | HTTP and JSON on the editor port, 1880 by default, under `httpAdminRoot`. 20 documented methods for `/auth`, `/settings`, `/diagnostics`, `/flows`, `/flows/state`, `/flow/:id` and `/nodes` (https://nodered.org/docs/api/admin/methods/) |
| Auth | None by default. With `adminAuth` set, `POST /auth/token` exchanges a username and password for a bearer token with scope `*` or `read`, valid seven days unless `sessionExpiryTime` changes it, revoked at `POST /auth/revoke`. OAuth and OpenID sign-in through Passport strategies, and a `tokens` function for the owner's own tokens |
| Permissions | Per resource, read or write, such as `flows.read`, `flows.write`, `nodes.write`, `settings.read` and `context.read`. A user holds `*`, `read` or a list |
| Deploys | `POST /flows` replaces the whole configuration. `Node-RED-Deployment-Type` is `full`, `nodes`, `flows` or `reload`. With API version `v2` a stale `rev` gets 409 |
| Flow endpoints | HTTP In nodes publish routes written in a flow. `httpNodeAuth` sets one basic-auth username and password for all of them, and `httpNodeMiddleware` takes Express middleware such as a rate limiter |
| Errors | 200, 204, 400, 401, 404, 409 and 500. A 400 carries `code` and `message`, with six documented codes such as `invalid_request`, `type_in_use` and `invalid_api_version` |
| Rate limits | None on the Admin API. The password grant refuses a username after more than five attempts in ten minutes, per the source |
| CLI | `node-red admin`, built in since 1.1.0 and published separately as `node-red-admin`, with `target`, `login`, `list`, `info`, `enable`, `disable`, `search`, `install`, `remove` and `hash-pw`. It has no command for flows |
| Audit | `logging.console.audit: true` logs each Admin API call with event, path, IP address, time and, when `adminAuth` is set, the user. Off by default |
| Releases | One major a year, timed to Node.js. 5.x since 9 June 2026. 4.x in maintenance until 31 December 2026 (https://nodered.org/about/releases/) |
| Telemetry | Opt-in since 4.1.0. Sends an instance identifier, Node-RED version, Node.js version and OS details once a day. Individual reports kept up to 90 days. Disabled by `telemetry.enabled: false`, `--no-telemetry` or `NODE_RED_DISABLE_TELEMETRY` |
| Tests | GitHub Actions runs build, lint and 135 mocha spec files on Node 22 and 24. The run on `main` for the 5.0.8 release on 8 October 2026 passed |
| Capabilities | automation.workflows, automation.webhooks, automation.code, automation.apps |
| Tags | self-hosted, open-source, local, free, javascript, webhooks, cli, docker |
| JSON | https://www.anchorterminal.com/api/v1/tools/node-red.json |
## Score breakdown (methodology v0.4, October 2026 research run)
Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points.
| Category | Weight | This run | Score (0–100) | Points |
| --- | --- | --- | --- | --- |
| Reliability | 16% | 20 | 90 | 18.0 |
| Performance | 10% | pending | pending | n/a |
| Schema & documentation | 13% | 16.2 | 41 | 6.7 |
| Agent ergonomics | 13% | 16.2 | 44 | 7.2 |
| Security & auth | 14% | 17.5 | 51 | 8.9 |
| Payments & pricing | 10% | 12.5 | 60 | 7.5 |
| Task success | 10% | pending | pending | n/a |
| Maintenance & community | 7% | 8.8 | 81 | 7.1 |
| Transparency & trust (editorial 85, provenance 45) | 7% | 8.8 | 65 | 5.7 |
| Negative events | up to −15 | up to −15 | none recorded | 0 |
| **Total** | | | | **61 → C** |
### Why each score
- Reliability 90: Graded as software the owner runs, on Node-RED 5.0.8. Official npm package `node-red` and Docker image `nodered/node-red`, with Node.js 22.9 or later required (20). Public GitHub Actions tests on Node 22 and 24, and the run on `main` for the 5.0.8 release on 8 October 2026 passed (25). 215 open issues and 122 open pull requests. Of six issues opened from 1 to 8 October, five carried `needs-triage` with no comment, though a crash reported on 8 October had a fix proposed the same day, and September's issues had one to eight comments (17). Major, minor and maintenance releases follow a written plan and 5.0.0 lists its breaking change. Two points off because 5.0.3, 5.0.4 and 5.0.6 each reverted a dependency update shipped in the release before (13). Version 5.0, with 1.0 released on 30 September 2019 (15).
- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.
- Schema & documentation 41: No OpenAPI file or other machine-readable contract was found on the site or in the repository (0). `llms.txt` returns 404 and the docs are served as HTML only (0). Each of the 20 documented methods has a one-line purpose and the permission it needs, with nothing on when to choose it, and routes for context, plugins, library and projects are in the source but not in the method list (9). A types page describes Node, Flow, Node Module and Node Set objects in prose tables. Node objects are open, with fields set by each node type, and the deployment type header has four listed values (6). Methods carry curl and JSON examples and a status code table, and the errors page lists six codes (11). The `Node-RED-API-Version` header selects `v1` or `v2`, and the changelog is public (15).
- Agent ergonomics 44: `GET /flow/:id` returns one tab, but `GET /flows` and `GET /nodes` return everything with no field selection or limit (8). No pagination or filtering on any method. An `Accept` header switches `/nodes` between JSON and HTML (3). Errors use standard status codes and a `code` and `message` body on 400, with 409 documented for a stale revision (14). No idempotency key. `rev` on `POST /flows` rejects a deploy over newer flows, and `PUT /flow/:id` is safe to repeat (12). Few required parameters and sensible defaults. The only clients are the `node-red-admin` CLI and the JavaScript module, with no SDK in a second language (7).
- Security & auth 51: Bearer tokens with scope `*` or `read`, per-user permissions by resource, revocation at `/auth/revoke` and a seven-day expiry. Tokens come from a username and password grant with no refresh (22). Ten off because the docs give `?access_token=` in the editor URL as the way to use a custom token (12). Read-only users, a read-only default user and per-resource write permissions. No approval step for a deploy or a module install, and `adminAuth` is off in the default settings file (12). The Admin API returns the owner's flow configuration and node metadata from npm. No guidance on untrusted content reaching an agent was found (7). An audit log of Admin API calls with user, path and IP address, off by default and written to the console logger (11). SECURITY.md gives a contact and escalation to the OpenJS Foundation CNA after six business days, and two advisories from 2021 are published. No security.txt, bug bounty or certification was found (9).
- Payments & pricing 60: Read with the self-hosted rule. No x402, MPP or L402 (0). The software is free under Apache-2.0 and the project sells nothing, stated on the licence page without a login (20). Free to run with no card (20). An agent can install the npm package or start the Docker image and call the API with no signup (20).
- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.
- Maintenance & community 81: 5.0.8 and 4.1.16 released on 8 October 2026 (30). 12 releases between 30 July and 8 October 2026 across 5.x and 4.x (20). Maintainers merge community fixes each month and September's issues were answered, but five of six issues from the first week of October were untriaged with no reply (17). No SDKs and no MCP server. The `node-red-admin` CLI is bundled and current, which earns part of the line (5). Dependencies are pinned and updated in most maintenance releases, CI runs on two Node.js versions, and Dependabot covers only the workflow actions (9).
- Transparency & trust 65: Apache-2.0, copyright held by the OpenJS Foundation (30). For self-hosted use the only data that leaves the host is the opt-in telemetry report, and its page states the four fields sent, a 90-day limit on individual reports and that only core committers see raw data. The project has no privacy policy of its own, and the foundation's was not read (20). The release plan dates the maintenance start and end of life of each major version and limits breaking changes to one major a year. No notice period for Admin API changes was found (15). Telemetry is off until the user opts in, is documented field by field and has three ways to disable it (20).
Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/node-red.md (JSON https://www.anchorterminal.com/fixes/node-red.json)
### What we couldn't check
- unchecked: the OpenJS Foundation privacy policy and terms of use linked from the site footer were not read, because they are a parent body's website documents
- unchecked: the forum at discourse.nodered.org and the Slack workspace were not read, so support responsiveness rests on GitHub issues alone
- unchecked: the Docker Hub page for `nodered/node-red` was not read. The image name comes from the project's Docker guide
- unchecked: https://nodered.org/docs/api/admin/methods/ failed with a connection error on one request and was not retried. The page's Markdown source in node-red/node-red.github.io was read instead
- Whether the 5.0.2 change to session messages (pull request 5883) and the September move to a patched copy of JSONata fixed security flaws. Neither has an advisory or a note in the changelog
- The lead named the vendor as OpenJS Foundation / Node-RED project and the interface as Admin HTTP API, flow HTTP endpoints and CLI. All three hold. The CLI manages nodes and has no command for flows
- The RDAP lookup through rdap.org followed a redirect to the registry's RDAP host before that host's robots.txt was read
### Sources
- home page: (seen 2026-10-09)
- Admin API overview: (seen 2026-10-09)
- Admin API methods, read from the website repository source after the page failed to load: (seen 2026-10-09)
- Admin API authentication: (seen 2026-10-09)
- Admin API errors: (seen 2026-10-09)
- Admin API types: (seen 2026-10-09)
- POST /flows: (seen 2026-10-09)
- securing guide: (seen 2026-10-09)
- logging and audit: (seen 2026-10-09)
- command-line administration: (seen 2026-10-09)
- usage telemetry: (seen 2026-10-09)
- release plan: (seen 2026-10-09)
- supported Node.js versions: (seen 2026-10-09)
- licence page: (seen 2026-10-09)
- website source, the Markdown behind the docs pages: (seen 2026-10-09)
- source, CHANGELOG.md, SECURITY.md, settings.js, CI workflow and tags: (seen 2026-10-09)
- repository advisories: (seen 2026-10-09)
- open issues: (seen 2026-10-09)
- test workflow runs: (seen 2026-10-09)
- releases: (seen 2026-10-09)
- npm weekly downloads: (seen 2026-10-09)
- security.txt, 404: (seen 2026-10-09)
- domain registration: (seen 2026-10-09)
## Who's behind it (provenance 45/100, checked 2026-10-09)
| Check | Finding | Points |
| --- | --- | --- |
| Legal entity named | OpenJS Foundation | 20/20 |
| Domain age | nodered.org, registered 2013-09-12 (13 years) | 15/15 |
| Endpoint on the vendor's domain | is not on nodered.org | 0/15 |
| Terms of service | not found | 0/10 |
| Privacy policy | not found | 0/10 |
| Status page | not found | 0/10 |
| Changelog | published | 10/10 |
| security.txt | not found | 0/10 |
The licence page on nodered.org says copyright is retained by the OpenJS Foundation, and the site footer reads Copyright OpenJS Foundation and Node-RED contributors.
No terms or privacy link is given. Node-RED is Apache-2.0 software the owner runs, and the project publishes no service agreement or privacy policy of its own. The site footer links the OpenJS Foundation's terms of use and privacy policy, which are a parent body's website documents and were not read.
The Admin API answers on the owner's own host, by default http://localhost:1880. Only the opt-in telemetry report goes to an endpoint the project hosts.
https://nodered.org/.well-known/security.txt returns 404. SECURITY.md in the repository gives team@nodered.org and escalation to the OpenJS Foundation CNA.
RDAP for nodered.org gives a registration date of 2013-09-12. The lookup through rdap.org was redirected to the registry's RDAP host.
nodered.org has no robots.txt (404). No status page exists because there is no hosted service.
### Terms and privacy, as read
A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.
**Terms of service**. We found no terms of service published for this product, so there is nothing to read and the check scores 0.
**Privacy policy**. We found no privacy policy published for this product, so there is nothing to read and the check scores 0.
## Live (updated 2026-10-09 18:45 UTC)
- github `node-red/node-red` 5.0.8, released 2026-10-08
- npm `node-red` 5.0.8
- npm `node-red-admin` 4.1.8
- Watching changelog
- Always current: https://www.anchorterminal.com/api/v1/live/node-red.json
## Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.
## Strengths
- Apache-2.0, with 12 releases between 30 July and 8 October 2026 on the 5.x and 4.x lines
- Admin API permissions are per resource, such as `flows.read` and `flows.write`, and a user or token can be limited to `read`
- `POST /flows` with `Node-RED-API-Version: v2` takes a `rev` value and answers 409 when the runtime holds newer flows
- Usage telemetry is opt-in, lists the four fields sent, and can be switched off in settings, by flag or by environment variable
- A release plan gives each major version a maintenance start and an end-of-life date, with 4.x ending on 31 December 2026
## Weaknesses
- No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org
- `adminAuth` is commented out in the default settings file, so a fresh install has no authentication on the editor or the Admin API
- No pagination, filtering or field selection. `GET /flows` returns the whole flow configuration
- Access tokens come from a username and password grant, last seven days by default and cannot be refreshed
- Routes for context, plugins, library and projects exist in the source and are missing from the published method list
## Before you call it (notes for agents)
1. Call `GET /auth/login` first. An empty object means no authentication is set and every Admin API call is open
2. Send `Node-RED-API-Version: v2` and the last `rev` on `POST /flows`, and re-read the flows on a 409
3. Set `Node-RED-Deployment-Type` to `nodes` or `flows` to restart only what changed. The default `full` stops every node
4. Prefer `GET /flow/:id` and `PUT /flow/:id` for one tab. `GET /flows` returns every node in the runtime
5. Treat `flows.write` and `nodes.write` as code execution on the host. Function nodes run JavaScript and `POST /nodes` installs npm modules
## Connect
Install:
```bash
sudo npm install -g node-red
```
First request:
```bash
curl http://localhost:1880/auth/token --data 'client_id=node-red-admin&grant_type=password&scope=*&username=admin&password=password'
```
Through letme (picks today, calling later): https://letme.dev/node-red. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md
## Similar tools
Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.
| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |
| --- | --- | --- | --- | --- | --- | --- |
| Pipedream API + MCP | B | 65.5 | 315 | automation.workflows, automation.apps, automation.code, automation.webhooks | no | https://www.anchorterminal.com/tools/pipedream.md |
| Kestra | B | 63.6 | 387 | automation.workflows, automation.code, automation.webhooks, automation.apps | no | https://www.anchorterminal.com/tools/kestra.md |
| Prismatic | C | 59.1 | 561 | automation.workflows, automation.apps, automation.code, automation.webhooks | no | https://www.anchorterminal.com/tools/prismatic.md |
| Workato API + MCP | C | 58 | 590 | automation.workflows, automation.apps, automation.code, automation.webhooks | no | https://www.anchorterminal.com/tools/workato.md |
| Activepieces API + MCP | C | 57.5 | 605 | automation.workflows, automation.apps, automation.code, automation.webhooks | no | https://www.anchorterminal.com/tools/activepieces.md |
| Tray.ai API + MCP | C | 55.5 | 655 | automation.workflows, automation.apps, automation.code, automation.webhooks | no | https://www.anchorterminal.com/tools/tray.md |
## Panel reviews (0)
Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .
Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md
## Notable
- By default the editor and Admin API are not secured, and the docs say this suits only a trusted network (source: )
- The docs give `?access_token=` in the editor URL as the way to sign in with a custom token (source: )
- Two advisories are published on the repository, both from 19 February 2021 (source: )
- 5.0.0 on 9 June 2026 raised the minimum Node.js version to 22.9, listed under Breaking Changes in the changelog (source: )
- Releases 5.0.3, 5.0.4 and 5.0.6 each reverted a dependency update from the release before, two for JSONata and one for bcrypt (source: )
- The diagnostics page says `GET /diagnostics` needs `settings.read`. The source checks `diagnostics.read` (source: )
- #8 of 17 in Best workflow automation platforms with APIs for AI agents: https://www.anchorterminal.com/best/workflow-automation/index.md
- All 108 workflows comparisons: https://www.anchorterminal.com/compare/workflow-automation/index.md
## Compare
- [Activepieces API + MCP vs Node-RED](https://www.anchorterminal.com/compare/activepieces-vs-node-red.md): C 57.5 vs C 61
- [Gumloop vs Node-RED](https://www.anchorterminal.com/compare/gumloop-vs-node-red.md): C 61.6 vs C 61
- [Kestra vs Node-RED](https://www.anchorterminal.com/compare/kestra-vs-node-red.md): B 63.6 vs C 61
- [Make API + MCP vs Node-RED](https://www.anchorterminal.com/compare/make-vs-node-red.md): C 58.7 vs C 61
- [n8n API + MCP vs Node-RED](https://www.anchorterminal.com/compare/n8n-vs-node-red.md): D 53.1 vs C 61
- [Node-RED vs Paragon ActionKit + MCP](https://www.anchorterminal.com/compare/node-red-vs-paragon.md): C 61 vs D 47.5
- [Node-RED vs Pipedream API + MCP](https://www.anchorterminal.com/compare/node-red-vs-pipedream.md): C 61 vs B 65.5
- [Node-RED vs Microsoft Power Automate](https://www.anchorterminal.com/compare/node-red-vs-power-automate.md): C 61 vs B 62
- [Node-RED vs Prismatic](https://www.anchorterminal.com/compare/node-red-vs-prismatic.md): C 61 vs C 59.1
- [Node-RED vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/node-red-vs-tray.md): C 61 vs C 55.5
- [Node-RED vs Windmill API + MCP](https://www.anchorterminal.com/compare/node-red-vs-windmill.md): C 61 vs C 55.9
- [Node-RED vs Workato API + MCP](https://www.anchorterminal.com/compare/node-red-vs-workato.md): C 61 vs C 58
## Verify this listing
For the vendor. The badge or a plain link to this page verifies the listing, from a page on nodered.org or one of its subdomains, or the README of github.com/node-red/node-red. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "node-red", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify
HTML badge:
```html
```
Markdown badge, for a README:
```markdown
[](https://www.anchorterminal.com/tools/node-red)
```
Plain link:
```html
Node-RED on Anchor Terminal
```
## Share this listing
For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Node-RED is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.
- Dark: https://www.anchorterminal.com/assets/share/node-red-dark.png
- Light: https://www.anchorterminal.com/assets/share/node-red-light.png