n8n's $5.2B Automation Still Needs Your Credentials
SAP just put a $5.2 billion valuation on n8n, and my first honest reaction was to go count the OAuth screens.
I’d been watching an n8n masterclass float around my feeds all week. The workflow-automation crowd is having a genuine moment, and n8n is the poster child for it. Drag a node, wire it to another node, watch data flow between apps that never used to talk to each other. It’s slick. The demos are hypnotic.
Then you actually try to build one of these things.
The part the demos skip
Every node in an n8n workflow that touches a real service needs credentials before it does anything. Gmail node? Spin up a Google Cloud project, enable the API, configure an OAuth2 consent screen, paste in a client ID and secret, then run the auth flow. The Slack node wants you to register an app and scope its permissions and generate a token. Notion, Airtable, HubSpot, your CRM. Each one is its own little bureaucratic errand before a single message moves.
I timed myself once wiring up a three-app workflow. The logic took four minutes. The credential plumbing took forty. And that was the happy path, the one where nothing had expired and every service still handed out tokens the same way it did last year.
This is the tax nobody prices into the “look how easy automation is” pitch. You’re not automating your work first. You’re becoming a part-time OAuth administrator so that a server somewhere gets permission to pretend to be you.
Why a server has to pretend to be you at all
n8n runs on a machine that is not your machine. It has no clue that you’re logged into Gmail in Chrome right this second, so the only way it can act for you is to keep its own copy of your identity, a token or a key or a secret, sitting on that server and valid until something revokes it.
That stored copy is the entire problem. It’s a credential living in a database you don’t control, scoped to your accounts, waiting around to leak. We watched LiteLLM get breached. We watched the industry slowly admit that every proxy holding your keys is a liability rather than a convenience. Now multiply that by every node in every workflow, and you’ve quietly built a sprawling attack surface for the crime of sending yourself a Slack ping when a form gets filled out.
There’s a subtler failure too. When Google rotates something or a scope changes, the workflow just dies without telling you, and you find out three weeks later that the automation you trusted stopped running on some random Tuesday.
A browser agent never asks for the key
You’re already logged into all of these services. In the tabs open on your screen right now, there are live authenticated sessions to Gmail, to Slack, to Notion. That session state is the credential. It already exists, and nobody needs to mint a second copy of it on a server.
A browser agent like Dassi runs inside that. It’s a Chrome extension in the side panel, and it sees the pages you see and acts inside the sessions you already hold. When it drafts a reply in Gmail, it isn’t authenticating against the Gmail API with some server-minted token. It’s typing in the Gmail tab you’re logged into, the way you would. No client ID. No consent screen. Nothing to rotate, nothing to leak.
I got into why cloud agents structurally can’t pull this off over in Cloud Browser Agents Can’t See Your Tabs, but the short version is that being on your machine, in your browser, changes what’s even possible.
BYOK is the same story, one floor up
The credential logic repeats at the model level. n8n’s AI nodes want your OpenAI key stored server-side, same pattern as everything else. Dassi lets you log in with your existing ChatGPT subscription or bring your own key, and that key stays local to your browser. The model does the reasoning; nobody in the middle sits holding your secrets in escrow. If you’ve felt the grind of key management, this is roughly why setup friction quietly eats your productivity gains.
Same model. Same automation goal. Wildly different plumbing underneath.
So what’s the $5.2B actually buying
I don’t think n8n is bad. For deterministic, high-volume, server-to-server pipelines, the kind of thing that fires ten thousand times a night and has to log every step, it’s genuinely good, and the valuation isn’t crazy for that market.
But so much of what people actually reach for n8n to do is just “handle this annoying thing across the three tabs I already have open.” For that, the whole credential apparatus is overhead you’re paying with no return. The workflow canvas is beautiful. The forty minutes of OAuth setup before it lifts a finger is not.
SAP bought into automation. I’d just check whether the automation you want really needs to know your API secrets, or whether it could’ve asked the tab that already does. You can grab Dassi from the Chrome Web Store and find out in about the time one OAuth flow would’ve taken.