RepoDaily · 2026-08-23 · Security tool

n8n 2.36: Self-Hosted AI Workflow Automation, 1500+ Integrations, and the Fair-Code Catch

#20 Security tool TypeScript +202 n8n-io/n8n Open repository

n8n picked up 202 stars on August 23, 2026, five days after shipping v2.36.0. Here is what the README, changelog, and package.json reveal about running AI agents on infrastructure you control.

Repo typeSecurity tool
Best forOps and platform teams that must run credential-heavy AI automation on their own infrastructure with audit trails and role-based access
Risk levelMedium: source-available under the Sustainable Use License, but not OSI open source
Time to evaluateHalf a day: two Docker commands to a running editor, plus a license read

Primary question: Do the Sustainable Use License's commercial limits fit how you plan to deploy, embed, or redistribute n8n?

91/100

RepoDaily adoption score

RepoDaily rates this as 91/100 (strong) for adoption: evidence, installation path, production risk, differentiation, license clarity, and AI/agent fit are scored from the article sources and adoption notes.

Directional score from RepoDaily sources and adoption notes, not a benchmark.Risk: Medium
100Evidence quality

7 source(s) across 5 source category/categories, plus a RepoDaily-specific evidence module when available.

100Installability

5 workflow step(s), 4 next-action step(s), and 7 command/install signal(s) were detected.

61Maintenance confidence

Trending momentum is +202 stars, with maintenance/release/issue signals counted when present.

96Production readiness

Risk is marked medium, with 6 security note(s) and 4 explicit skip condition(s).

100Differentiation

3 opportunity lens item(s), 6 alternative(s), and 5 type-specific section(s) support differentiation.

82License clarity

License source or license wording is present.

84Agent / AI fit

6 AI/agent-related signal(s) were detected in the article text and metadata.

Project overview

n8n is a fair-code platform for building and running AI agents and automation flows, written in TypeScript and distributed as a pnpm monorepo. The pitch in the README is specific: a visual canvas for multi-step agents, JavaScript, Python, and npm packages when nodes are not enough, 1500+ integrations, and 9,000+ workflow templates, with the choice of self-hosting or the vendor cloud at app.n8n.cloud. The name, per founder Jan Oberhauser, is short for nodemation — 'node' for the node view and Node.js, '-mation' for automation, pronounced n-eight-n.

The trend snapshot for 2026-08-23 shows 202 stars and rank 20, arriving five days after release 2.36.0 landed on 2026-08-18. That release is dense for a patch train: it aligns human-in-the-loop approval resume schemas with the confirm envelope (#36047), stops agents from claiming integration tool-call success early (#36196), exposes incoming request headers to MCP trigger tools (#35236), and applies TLS options per hop when requests go through a proxy (#35518). Those are the kinds of fixes you ship when agents are doing real work in production.

Read through a security lens — this page's category — n8n's appeal is control. Credentials, execution data, and logs stay on your Docker host, the README's enterprise tier adds role-based access and audit trails, and SECURITY.md routes vulnerability reports through a published disclosure program rather than public issues. The counterweight is licensing: the Sustainable Use License plus a separate n8n Enterprise License (LICENSE_EE.md) make the project source-available, not OSI open source.

Problem it solves

  • AI agent prototypes strand in notebooks because glue code lacks credential handling, retries, approvals, and logs.
  • SaaS automation keeps credentials and execution history on someone else's infrastructure.
  • Switching LLM providers usually means rewriting agent plumbing; the README positions provider switching across OpenAI, Anthropic, Google, or open-source models as architecture-neutral.
  • Hand-rolled cron jobs fail quietly: no audit trail, no role-based access, and no versioned node settings — a gap v2.36.0 addresses directly with workflow version comparison fixes (#36066).

How it works

  1. Design on the visual canvas: the Vue editor in /packages/frontend/editor-ui wires nodes into multi-step flows with logic and tool use.
  2. Drop into code where needed: JavaScript, Python, and npm packages inside the same flow.
  3. Connect systems through 1500+ integrations, MCP client/server support, or custom nodes generated with the /packages/node-dev CLI.
  4. Add governance: per-node credentials, human approval steps (HITL), and execution data with full observability.
  5. Deploy on your terms: self-host the Docker image on port 5678, or run in the vendor cloud at app.n8n.cloud.

Product demo and interface preview

n8n.io - Screenshot
The n8n editor canvas — The README screenshot shows the node canvas you reach at http://localhost:5678 after the Docker start command. README.md image
n8n banner image
n8n banner image — The project banner from the README, introducing the fair-code automation platform branding. README.md image

Try-it path: from zero to a local editor in two commands

  • Install script, Docker required: curl -fsSL https://get.n8n.io | sh.
  • Manual Docker path: docker volume create n8n_data, then docker run -it --rm --name n8n -p 5678:5678 -v n8n_data:/home/node/.n8n docker.n8n.io/n8nio/n8n.
  • The editor opens at http://localhost:5678; the named volume n8n_data persists state under /home/node/.n8n.
  • No build step for a first look: the image is docker.n8n.io/n8nio/n8n.
  • v2.36.0 also fixed a false port-in-use error in the get-n8n script on Windows/WSL (#36026), which smooths this exact path.

Architecture read: a pnpm monorepo with a guarded core

  • /packages/cli runs front- and backend and contains the code for n8n's APIs.
  • /packages/core handles workflow execution, active webhooks, and workflows — contributors are told to contact n8n before changing anything here.
  • /packages/frontend/editor-ui is the Vue workflow editor; /packages/frontend/@n8n/design-system holds the Vue component library.
  • /packages/nodes-base carries the base nodes, /packages/node-dev is a CLI for creating new n8n-nodes, and /packages/workflow holds interfaces shared by front- and backend.
  • /docker/images contains the Dockerfiles behind the containers.
  • Development requires Node.js 24+ and pnpm 10.22+ (engines: node >=24.0.0, pnpm >=10.22.0); a VS Code Dev Container path is documented in CONTRIBUTING.md.

Command surface: what the repo scripts reveal

  • packageManager is [email protected], and preinstall runs scripts/block-npm-install.js — npm install is deliberately blocked.
  • Build and test run through turbo: pnpm build, pnpm test, pnpm typecheck, pnpm lint.
  • pnpm build:docker chains build-n8n.mjs and dockerize-n8n.mjs; build:docker:scan adds scripts/scan-n8n-image.mjs to scan the built image; build:docker:smoke runs smoke checks.
  • dev:e2e launches the Playwright UI (filter n8n-playwright); CONTRIBUTING.md documents unit, coverage, and E2E suites.
  • boundaries:check and check:workspace-private-deps enforce module boundaries inside the monorepo.

Maintenance read: release cadence and what v2.36.0 actually fixed

  • v2.36.0 released 2026-08-18, five days before this snapshot (2026-08-23); package.json carries the identical 2.36.0 version.
  • Agent-facing fixes: HITL approval resume schema alignment (#36047), skill save validation errors surfaced without reverting renames (#36055), LLM-provider credential lookup fallbacks (#35833), and tools executing in the order the root requested (#36009).
  • Core reliability: bounded database pool teardown (#36013), an abort deadline on workflow publication outbox processing (#36197), crash on unreadable enqueued execution data (#36010), and node settings change detection across workflow versions (#36066).
  • CONTRIBUTING.md documents community PR rules, a Contributor License Agreement, and stacked pull requests via gh stack — a structured intake process, not a free-for-all.
  • The trade-off: because /packages/core is maintainer-gated, stability is high but deep upstream contributions move on n8n's schedule, not yours.

Deployment notes: self-host defaults and the enterprise tier

  • The README's self-host default is the Docker container with a named volume; the cloud login lives at app.n8n.cloud.
  • The README lists role-based access, audit trails, and support for sensitive data under its Enterprise-Ready AI section.
  • Two licenses govern the code: the Sustainable Use License (LICENSE.md) and the n8n Enterprise License (LICENSE_EE.md); enterprise terms go through [email protected].
  • The README's fair-code summary is source available, self-hostable, extensible; docs.n8n.io/sustainable-use-license/ explains the limits.
  • SECURITY.md routes vulnerability reports to the Vulnerability Disclosure Program instead of public issues.

Who should pay attention?

Good fit if

  • Platform and ops teams consolidating credential-heavy integrations onto infrastructure they control.
  • AI engineers shipping multi-step agents that need tool use, human approvals, and provider switching.
  • Shops that want Python or JavaScript escape hatches inside a visual builder instead of a second codebase.
  • Anyone validating MCP client/server patterns — trigger and tooling fixes landed in v2.36.0 itself.

Skip for now if

  • You need OSI-approved open source for redistribution; the Sustainable Use License is not that.
  • You plan to fork n8n and resell automation as a hosted service — read LICENSE.md and LICENSE_EE.md before writing code.
  • Your workload is scheduled data pipelines rather than interactive integrations; Airflow-style schedulers fit better.
  • Nobody on the team can own a Docker host plus a release train that shipped 2.36.0 five days before this snapshot.

Risks and cautions

Medium

The engine is mature and shipped on a tight cadence, but fair-code licensing and a maintainer-guarded core constrain redistribution and upstream change.

  • Two licenses govern the code — the Sustainable Use License (LICENSE.md) and the n8n Enterprise License (LICENSE_EE.md) — which is source-available, not OSI open source.
  • CONTRIBUTING.md asks contributors to contact n8n before touching /packages/core, where execution and webhook logic lives.
  • Self-hosting carries real operational load: Docker host, database, and upgrades on every release.
  • The toolchain is opinionated: npm installs are blocked by scripts/block-npm-install.js, and engines require Node >=24.0.0 and pnpm >=10.22.0 (packageManager [email protected]).
  • SECURITY.md publishes a Vulnerability Disclosure Program link rather than taking reports in public issues.
  • The README's enterprise tier lists role-based access, audit trails, and support for sensitive data.
  • v2.36.0 applies TLS options per hop when requests go through a proxy (#35518) — relevant when agent egress crosses corporate proxies.
  • v2.36.0 exposes incoming request headers to MCP trigger tools (#35236), enabling header-based auth on agent endpoints.
  • The build surface includes build:docker:scan, which runs scripts/scan-n8n-image.mjs against the built container image.
  • Enqueued executions with unreadable data now crash instead of proceeding silently (#36010).

Alternatives to compare

ApproachWhen to useTrade-off
Node-RED
Flow-based wiring for IoT and quick internal tools; lighter than n8n for agent-heavy workFree, open source, self-hosted
Apache Airflow
Scheduled batch pipelines written as Python DAGs; pick it when the job is data pipelines, not interactive integrationsFree, open source, self-hosted
Activepieces
You want an open-source alternative with a similar visual builder and a simpler licensing postureFree self-hosted core; paid cloud
Windmill
Scripts-first automation with a UI; fits when code, not nodes, is the primary artifactFree, open source, self-hosted; paid cloud
Zapier
Fastest setup with zero hosting, accepting SaaS-held credentials and per-task pricingCommercial subscription
Make
Visual scenario building without hosting; acceptable when self-hosting is off the tableCommercial subscription

What this trend reveals

Stand up an internal MCP tool server in a day

Because the repo ships MCP trigger support and v2.36.0 exposes incoming request headers to MCP trigger tools (#35236), a self-hosted instance can expose internal APIs to agents behind header checks instead of opening a new service.

Run the README's docker run command, create an MCP trigger, call it from an MCP client with a test header, and confirm the execution entry at http://localhost:5678.

Replace brittle cron scripts with observable executions

/packages/core owns execution and webhooks, and v2.36.0 targets the exact failure modes of hand-rolled jobs: bounded pool teardown (#36013), abort deadlines on outbox processing (#36197), and node settings diffing across versions (#36066).

Port three existing cron jobs into n8n flows, disable the old jobs for two weeks, and compare failure and retry behavior from execution data.

Custom nodes as the integration escape hatch

/packages/node-dev is a documented CLI for generating new n8n-nodes, so a gap in the 1500+ integration catalog does not have to end your trial.

Generate a node for one internal API with /packages/node-dev, mount it into your Docker setup, and verify it survives an upgrade to the next release image.

Best next action

Run the Docker one-liner and read the license before anything else

The cheapest decisive test is local: the README's Docker path gives a working editor in minutes, and LICENSE.md answers the redistribution question that determines whether n8n fits at all.

  1. Create the volume and container: docker volume create n8n_data, then docker run -it --rm --name n8n -p 5678:5678 -v n8n_data:/home/node/.n8n docker.n8n.io/n8nio/n8n.
  2. Open http://localhost:5678 and import one template from the 9,000+ at n8n.io/workflows that matches a current pain point.
  3. Read LICENSE.md and docs.n8n.io/sustainable-use-license/; if you plan to embed or redistribute, email [email protected] about the enterprise tier.
  4. Check SECURITY.md's Vulnerability Disclosure Program and confirm your incident process can use it.

RepoDaily verdict

n8n earns its trending slot the honest way: a working local install in two commands, a release five days old (v2.36.0, 2026-08-18) that fixes real agent and MCP defects, and security-relevant plumbing from per-hop TLS to header-aware MCP triggers. The catch is the Sustainable Use License — treat the code like production software and the license like a contract.

Sources