SAP led a funding round last week that values n8n at $5.2 billion, and I found out about it the way I find out about most things now: scrolling Hacker News, where a tutorial titled “Building N8n AI Automation Workflows” was sitting a few slots below the news itself. Two signals in the same feed. The market loves workflow automation, and developers are busy learning how to wire it up.

So I went and looked at what wiring it up actually involves.

Every node wants a credential

n8n is genuinely good software. You drag nodes onto a canvas, connect them, and data flows from one service to the next. Gmail to Slack. Airtable to Notion. A webhook into an OpenAI call into a Google Sheet.

But each of those nodes has to authenticate. The Gmail node wants OAuth access to your inbox. The Slack node wants a bot token. Airtable wants a personal access token, Notion wants an integration secret, and every third-party API in the chain wants its own key stored somewhere n8n can read it. Before your first automation ever runs, you are running a small identity-management operation on the side.

And these credentials live on a server. Whether you self-host or use n8n Cloud, the tokens sit in a database, ready to be used by a process that runs whether you’re at your desk or asleep.

What are you actually granting?

This is the part I keep coming back to. When you hand n8n an OAuth token for Gmail, you’ve created a copy of your access that exists outside your browser, outside your control, sitting in a workflow engine that can act on your behalf at 3am.

Martin Fowler wrote about this recently with agentic email, and his framing stuck with me: direct account access triggers what Simon Willison calls the lethal trifecta. Untrusted content, sensitive data, and the ability to communicate out. A credentialed workflow engine hits all three by design.

Most people building these flows aren’t thinking about the token they minted six integrations ago. It just works, until the day it does something nobody asked for.

The browser already logged in for you

A different model. You already authenticated to Gmail this morning. And Slack, and Airtable, and your CRM, and the six SaaS tabs open right now. Your browser is holding every one of those sessions.

A browser agent works inside those tabs. It doesn’t ask for an API key because it doesn’t need one. The session cookie your browser already has is the authentication. That’s the whole idea behind browser agents being the new API: when the login already exists in the tab, you don’t rebuild it as a credential.

Dassi does exactly this. It’s a Chrome extension that lives in the side panel and acts in the tab you’re looking at, using the login you already have. No OAuth consent screen per app. No token sitting in a cloud database. Close the tab and the access closes with it.

But n8n runs while I sleep

Fair. This is the real difference, and it’s worth being straight about it. n8n is built for unattended automation. The webhook fires at 3am and the workflow runs without you, which is a genuinely useful thing that a browser agent parked in your side panel cannot do while your laptop is shut.

For a lot of the work people actually build n8n flows for, though, the unattended part is theater. Drafting replies, pulling data off a dashboard that has no public API, shuttling information between two tools that refuse to talk to each other, filling the same intake form for the fortieth time. That work happens while you’re at the machine anyway, and it never needed a server or a stored token to begin with. Cloud agents can’t see your tabs, which is precisely why they demand all those credentials in the first place.

The $5.2 billion is real, and n8n earned it. But I think a solid chunk of what people are building with it is a workaround for a problem the browser doesn’t have. You mint tokens because the automation lives outside your session. Move it back inside the session and most of those tokens stop being necessary at all.

If you want the inside-the-session version, Dassi is a free Chrome extension that runs on your own model key.

Anyway. I closed the HN tab before I finished the tutorial. Felt like the right call.