SAP just valued n8n at $5.2 billion. I saw the headline somewhere between a Hacker News thread and a half-finished cup of coffee, and the first thing my brain did was picture the credentials screen. You know the one. Every node you drop onto an n8n canvas wants something before it’ll move: a Google OAuth consent, a Slack bot token, a Stripe restricted key, an Airtable PAT.

The product is genuinely good. n8n is one of the better things to happen to workflow automation in years, and SAP didn’t hand over five billion for nothing. But the model underneath it hasn’t really changed since Zapier shipped in 2011. To touch an app, you authenticate to that app. Every single one.

The credential is the integration

Let me be blunt about what an “integration” actually is. It’s a stored secret. When n8n connects to your Gmail, what it has is a token that grants read or send access to your mailbox, sitting in n8n’s database or, if you self-hosted, on a box you now have to secure yourself, and that token is the integration, nothing more mystical than that.

So the work of automation quietly becomes the work of credential management. You generate keys. You scope them. You rotate them when they leak. You re-auth when Google decides your refresh token went stale. And every one of those tokens is a copy of your access living somewhere outside your own session.

Your browser already authenticated, hours ago

Different starting point. You are, right now, logged into Gmail. And Notion. And your CRM, your bank’s dashboard, the internal admin panel that nobody ever built an API for. Those sessions are live in your tabs at this exact moment. No token got minted for a third party to hold. The cookies belong to you and to the browser sitting in front of you, and that turns out to be the whole game.

A browser agent works inside that. It doesn’t ask Stripe for a key, because it’s already looking at the Stripe dashboard you logged into this morning. It clicks where you’d click. It reads what’s on the screen. There’s no integration to set up because there is no second party to authenticate to in the first place.

This is the part the credential-heavy model glosses over: the API key mostly exists to give some remote server the permission you already have. Dassi skips that middle step. It runs as a Chrome extension in your real browser, using your real logged-in state, which means the list of “supported integrations” is just every website you can open. We dug into this more in Browser Agents Are the New API, back when saying it out loud felt weirder than it does now.

What you stop maintaining

No OAuth app registrations. No key rotation. No “this integration needs admin approval from your Workspace.” No third-party server holding a token that can send mail as you. If a site has no API at all, fine, the agent uses the same screen you do.

”But isn’t a real API more reliable?”

Sometimes, yes. A clean REST endpoint is faster and steadier than driving a UI, and for high-volume backend plumbing I’d still reach for n8n or a proper integration. I’m not going to pretend a browser agent should run your nightly ETL.

But most of the automation people actually want isn’t backend plumbing. It’s “pull these twelve invoices off the portal.” It’s “draft replies to everyone in this folder.” It’s the long tail of apps that will never ship an API worth wiring up, and the forty MCP tools that still can’t fill out a form. For that tail, logging in once and letting the agent see the page beats minting a credential per service every damn time.

The valuation argues against itself

A five-billion-dollar price tag is a bet that wiring credentials together by hand is a durable, expanding business, and maybe it is, but it’s also a loud signal that the credential layer got heavy enough to be worth owning. That’s usually the exact moment something simpler shows up underneath it.

The simpler thing is the session you’re already in. Dassi is free, keeps everything inside your browser, and runs whatever model you bring to it: a Claude, GPT, or Gemini key, or just sign in with the ChatGPT subscription you already pay for. No middleman holding your keys. You can grab it on the Chrome Web Store and point it at a tab.

FAQ

Does a browser agent need API keys like n8n does? No. It acts inside your already-logged-in browser tabs, so there’s no OAuth flow or per-app token to set up. The site treats it like you.

Is this a replacement for n8n? Not for heavy backend pipelines. For the long tail of apps without good APIs, or one-off browser tasks, a browser agent skips the integration work entirely.

Where do my credentials live with Dassi? In your own browser session, same as when you use the sites yourself. With BYOK, your model API key goes straight to your LLM provider, not through a third-party server.