n8n Hits $5.2B. It Still Can't Touch Your Logged-In Tabs.
So SAP put a number on n8n this week: $5.2 billion. I saw it land in my feed next to an n8n “automation masterclass” thread and a Hacker News post about a local AI automation desktop thing, and for a few minutes it felt like the whole timeline had agreed that workflow automation is the only topic worth caring about today.
Good for them, honestly. n8n is a genuinely nice piece of software and the valuation isn’t crazy if you believe automation is eating ops work, which I mostly do.
But here’s where my enthusiasm runs into a wall. Almost every n8n workflow I’ve ever built or watched someone build starts with the same chore: connect the credential. Register an OAuth app. Paste the API key. Pick the right integration node and pray it has the endpoint you need.
The valuation is for the API layer
n8n lives in the API layer. That’s not a knock, it’s just what it is. The whole model assumes that the services you want to automate expose clean, documented APIs, and that you’re willing to do the authentication dance to reach each one.
When that assumption holds, it’s magical. Webhook comes in, data gets transformed, row lands in a database, Slack message fires. Beautiful. I have workflows like this and I’d be sad to lose them.
The assumption breaks more often than the demos suggest. Plenty of the tools people actually live in all day either don’t have an API, hide it behind an enterprise tier, or expose a crippled version that’s missing the one field you care about. The internal dashboard your finance team uses. That vendor portal with the export button and no docs. Half of LinkedIn.
Where do the OAuth tokens come from?
This is the part nobody puts in the masterclass. Before any of your slick workflow runs, somebody has to stand in front of each service and authenticate on its behalf. You generate tokens. You store them on the automation server. You renew them when they expire, which they do, usually at the worst possible time on a Friday.
And every one of those tokens is a copy of your access sitting somewhere other than your own session. That’s a security surface, a maintenance burden, and a small ongoing tax on your attention. Martin Fowler wrote a sharp post recently about agentic email and the “lethal trifecta” — untrusted content, sensitive data, and a path to send it out. Stockpiling broad OAuth grants on a server is how you walk straight into that trifecta without noticing.
You already authenticated to all these services. In your browser. This morning. The tokens exist; they’re just sitting in a tab instead of on n8n’s server.
A browser agent uses the session you already have
A browser agent runs inside Chrome, in the tab you’ve already logged into. There is no connector to build because there is no API call being made. It reads the page and clicks the buttons, the same way you would, using the cookies and session that are already there.
Want the CSV that’s locked behind the $100/month export tier? It reads the table on screen. Need to reply to fourteen emails in a tone that sounds like you? It drafts them in the compose box you’re staring at. Pull three numbers out of an internal tool that SAP itself probably couldn’t get an API key for? It just looks at the screen and grabs them.
Dassi works this way. It’s a Chrome extension that lives in the side panel, sees what you see, and does the logged-in, click-here work without you wiring up a single credential. No tokens to store, because it borrows the session you opened yourself. We’ve written before about why cloud browser agents can’t see your tabs and the deeper point that browser agents are the new API when no real API exists.
I’d run both, and that’s the actual answer
I’m not going to tell you n8n is dead. That’d be dumb, and also wrong. For the backend pipeline stuff, like scheduled syncs, webhook fan-out, gluing two systems that both have proper APIs, it’s excellent and worth the billions.
The split in my head is pretty clean. n8n for the plumbing that lives behind APIs. A browser agent for everything that lives behind a login and a click, which turns out to be most of the annoying daily work. The $5.2B story is real, but it’s a story about one half of automation, and a lot of people are about to discover the other half exists only when they hit a service with no node for it.
You can add Dassi to Chrome and point it at whatever tab n8n couldn’t reach. Bring your own LLM key, or sign in with the ChatGPT subscription you’re already paying for. The token you don’t have to generate is the best kind.