# Node-RED (slim) > Node-RED is an open-source flow-based automation runtime hosted by the OpenJS Foundation. The owner runs it on Node.js, and an Admin HTTP API and a command-line client deploy flows and install nodes. - Full: https://www.anchorterminal.com/tools/node-red.md (~6,550 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/node-red.json · canonical https://www.anchorterminal.com/tools/node-red - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 61/100 · rank #486 of 950 · #5 in Workflow automation · not agent-ready · confidence medium** Assessment: Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880. ## Facts - Kind: HTTP API · vendor: OpenJS Foundation · category: Workflow automation · legal entity: OpenJS Foundation · provenance 45/100 - Local only (HTTP): npm `node-red`, npm `node-red-admin`, oci `nodered/node-red` - Auth: OAuth or key · pricing: Free · x402: no · licence: Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Version graded: Node-RED 5.0.8 (8 October 2026), self-hosted. Requires Node.js 22.9 or later, and the project recommends Node 24. FlowFuse, a separate company's hosted platform for Node-RED, is not graded here - Admin API: HTTP and JSON on the editor port, 1880 by default, under `httpAdminRoot`. 20 documented methods for `/auth`, `/settings`, `/diagnostics`, `/flows`, `/flows/state`, `/flow/:id` and `/nodes` (https://nodered.org/docs/api/admin/methods/) - Auth: None by default. With `adminAuth` set, `POST /auth/token` exchanges a username and password for a bearer token with scope `*` or `read`, valid seven days unless `sessionExpiryTime` changes it, revoked at `POST /auth/revoke`. OAuth and OpenID sign-in through Passport strategies, and a `tokens` function for the owner's own tokens - Permissions: Per resource, read or write, such as `flows.read`, `flows.write`, `nodes.write`, `settings.read` and `context.read`. A user holds `*`, `read` or a list - Deploys: `POST /flows` replaces the whole configuration. `Node-RED-Deployment-Type` is `full`, `nodes`, `flows` or `reload`. With API version `v2` a stale `rev` gets 409 - Flow endpoints: HTTP In nodes publish routes written in a flow. `httpNodeAuth` sets one basic-auth username and password for all of them, and `httpNodeMiddleware` takes Express middleware such as a rate limiter - Errors: 200, 204, 400, 401, 404, 409 and 500. A 400 carries `code` and `message`, with six documented codes such as `invalid_request`, `type_in_use` and `invalid_api_version` - Rate limits: None on the Admin API. The password grant refuses a username after more than five attempts in ten minutes, per the source - CLI: `node-red admin`, built in since 1.1.0 and published separately as `node-red-admin`, with `target`, `login`, `list`, `info`, `enable`, `disable`, `search`, `install`, `remove` and `hash-pw`. It has no command for flows - Audit: `logging.console.audit: true` logs each Admin API call with event, path, IP address, time and, when `adminAuth` is set, the user. Off by default - Releases: One major a year, timed to Node.js. 5.x since 9 June 2026. 4.x in maintenance until 31 December 2026 (https://nodered.org/about/releases/) - Telemetry: Opt-in since 4.1.0. Sends an instance identifier, Node-RED version, Node.js version and OS details once a day. Individual reports kept up to 90 days. Disabled by `telemetry.enabled: false`, `--no-telemetry` or `NODE_RED_DISABLE_TELEMETRY` - Tests: GitHub Actions runs build, lint and 135 mocha spec files on Node 22 and 24. The run on `main` for the 5.0.8 release on 8 October 2026 passed - Scores: Reliability 90, Performance pending, Schema & documentation 41, Agent ergonomics 44, Security & auth 51, Payments & pricing 60, Task success pending, Maintenance & community 81, Transparency & trust 65 · total over the 7 assessed categories - Why: Reliability, Graded as software the owner runs, on Node-RED 5.0.8. Official npm package `node-red` and Docker image `nodered/node-red`, with Node.js 22.9… · Schema & documentation, No OpenAPI file or other machine-readable contract was found on the site or in the repository (0). · Agent ergonomics, `GET /flow/:id` returns one tab, but `GET /flows` and `GET /nodes` return everything with no field selection or limit (8). · Security & auth, Bearer tokens with scope `*` or `read`, per-user permissions by resource, revocation at `/auth/revoke` and a seven-day expiry. · Payments & pricing, Read with the self-hosted rule. · Maintenance & community, 5.0.8 and 4.1.16 released on 8 October 2026 (30). · Transparency & trust, Apache-2.0, copyright held by the OpenJS Foundation (30). - Sources: 23, open questions: 7, both in the full twin - Capabilities: automation.workflows, automation.webhooks, automation.code, automation.apps - JSON: https://www.anchorterminal.com/api/v1/tools/node-red.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/node-red.svg` or a link to https://www.anchorterminal.com/tools/node-red from a page on nodered.org or one of its subdomains, or the README of github.com/node-red/node-red, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call `GET /auth/login` first. An empty object means no authentication is set and every Admin API call is open 2. Send `Node-RED-API-Version: v2` and the last `rev` on `POST /flows`, and re-read the flows on a 409 3. Set `Node-RED-Deployment-Type` to `nodes` or `flows` to restart only what changed. The default `full` stops every node 4. Prefer `GET /flow/:id` and `PUT /flow/:id` for one tab. `GET /flows` returns every node in the runtime 5. Treat `flows.write` and `nodes.write` as code execution on the host. Function nodes run JavaScript and `POST /nodes` installs npm modules ## Connect ```bash sudo npm install -g node-red ``` ```bash curl http://localhost:1880/auth/token --data 'client_id=node-red-admin&grant_type=password&scope=*&username=admin&password=password' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/node-red ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Pipedream API + MCP | B | 65.5 | automation.workflows, automation.apps, automation.code, automation.webhooks | https://www.anchorterminal.com/tools/pipedream.min.md | | Kestra | B | 63.6 | automation.workflows, automation.code, automation.webhooks, automation.apps | https://www.anchorterminal.com/tools/kestra.min.md | | Prismatic | C | 59.1 | automation.workflows, automation.apps, automation.code, automation.webhooks | https://www.anchorterminal.com/tools/prismatic.min.md | | Workato API + MCP | C | 58 | automation.workflows, automation.apps, automation.code, automation.webhooks | https://www.anchorterminal.com/tools/workato.min.md | | Activepieces API + MCP | C | 57.5 | automation.workflows, automation.apps, automation.code, automation.webhooks | https://www.anchorterminal.com/tools/activepieces.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)