SAP Valued n8n at $5.2B. Every Workflow Still Starts With an API Key.
I saw the SAP headline this morning and did a small double-take. SAP is putting money into n8n at a $5.2 billion valuation, and the HN front page is basically a wall of n8n think-pieces today. Good for them. n8n is a genuinely nice piece of software, and self-hostable workflow automation deserves a win.
But I kept thinking about the first thing you do in any n8n workflow. Before a single node runs, before any “automation” happens, you sit there pasting credentials.
The part nobody screenshots
Every n8n tutorial skips the boring middle. You see the pretty canvas with the nodes connected by curvy lines, and then a triumphant “it works.” What you don’t see is the twenty minutes spent in Google Cloud Console creating an OAuth client, copying a client ID, copying a client secret, setting an authorized redirect URI, enabling the right API, and praying you picked the correct scope so the token doesn’t silently 403 you three steps later.
And that’s just Gmail. Now do it again for Slack. Again for Notion. Again for your CRM, which buries its API key behind a settings page that moved last quarter.
So the actual experience of “workflow automation” is mostly credential administration. The wiring is the work. The workflow is the easy part.
$5.2 billion buys a very expensive cron job
Here’s where I’ll be unfair for a second, because I think it’s a useful unfairness.
When SAP writes a number that big, what they’re really endorsing is the architecture: a cloud service that holds long-lived tokens for all your other services and acts on your behalf. That model is powerful and it scales to enterprise teams who want governance, audit logs, and a shared platform. I’m not knocking it for that use case.
The problem is that for a single person who just wants their browser stuff handled, the architecture is upside down. You’re being asked to hand a third-party server permanent keys to your accounts so it can pretend to be you from a data center somewhere. Each credential you provision is a tiny liability that lives forever, or until you remember to revoke it, which you won’t.
I wrote more about this in Browser Agents Are the New API, but the short version is that the API was never the hard part. Getting permission to use it was.
Your browser already did the auth
There’s a different starting point, and it’s sitting in front of you right now. You’re logged into Gmail. You’re logged into Slack, Notion, your CRM, your bank, that internal tool with no public API at all. Those sessions are real, they’re scoped exactly to what you can already do, and they expire on their own when you close the tab or the cookie ages out.
A browser agent works inside those sessions instead of around them. That’s the whole idea behind Dassi, a Chrome extension that lives in the side panel and acts in the tab you’re actually looking at. When I ask it to pull the open invoices from a billing dashboard and drop them into a reply, it reads the page I already have open and types into the box I’d type into. No OAuth client. No redirect URI. No scope that’s secretly too broad.
Because the agent is me, in my session, there’s no second copy of my permissions sitting on someone else’s server waiting to leak.
When n8n is still the right call
I don’t want to oversell this. If you need a thing to fire at 3am whether or not your laptop is open, a browser agent is the wrong tool and a hosted workflow engine is the right one. Scheduled, headless, runs-without-you automation is exactly what n8n is built for, and a side-panel agent that depends on your live browser session can’t replace that. Different jobs.
But a huge amount of what people actually wire up in n8n is daytime, ad-hoc, “take this from here and put it there” work that they’re awake and present for anyway. That stuff doesn’t need a credential vault. It needs to read the screen.
The wiring tax is the real product
Most of the friction in automation isn’t the logic. It’s the permissions plumbing, and we’ve collectively decided that’s just the price of admission. I think that’s wrong, or at least lazy. The setup friction is precisely the part that stops normal people from ever building the automation they wanted.
SAP’s check says the cloud-credential model has a long runway, and it probably does for the enterprise. For the rest of us doing browser chores between meetings, the cheaper trick is to skip the wiring entirely and let something act where you’re already signed in.
Anyway. $5.2 billion. I’m going to go ask my browser to do the thing I would’ve spent forty minutes credentialing for, and then I’m getting lunch.