SAP Just Paid $5.2B for n8n. The Workflows Still Need Your API Keys.
I read that SAP is putting real money behind n8n at a $5.2 billion valuation, and my first thought was that a lot of people are about to lose a weekend to credential setup. n8n is the workflow builder that’s been all over Hacker News this week, the one where you drag nodes onto a canvas and string together “when this happens, do that.” It’s genuinely good software. The valuation isn’t crazy either, given how much manual SaaS-to-SaaS glue work exists in the world.
But every one of those pretty little nodes is hungry. It wants a credential.
The part nobody screenshots
When someone posts their slick n8n workflow, you see the canvas. Clean boxes, clean arrows, a Gmail node feeding a Sheets node feeding a Slack node. What you don’t see is the forty minutes before the screenshot, where they generated an API key in one dashboard, set up an OAuth app in another, copied a client secret, configured a redirect URI, and pasted a webhook URL into a third service that then needed its own token to call back.
And that’s for three apps. Real workflows touch eight or ten. Each connection is a separate little bureaucratic errand, and each one drops a long-lived credential into a database that n8n (or whoever hosts your instance) is now responsible for keeping safe. So you’ve built automation, sure. You’ve also built a small pile of keys to your accounts sitting on someone else’s server, waiting for the day that server has a bad week.
Your browser already finished the OAuth dance
Sit in front of your actual computer for a second. Your Gmail is open and logged in. Your CRM is logged in. Your bank, your Notion, your internal admin panel that has no public API and never will. You authenticated to all of them, days or weeks ago, and your browser is quietly holding those sessions right now.
A browser agent works inside that. It drives the tab you already trust, as you, with the logins you already have, which means there is no key to generate and no OAuth app to register and nothing new to store anywhere because the credential is the cookie that’s already on your machine and never leaves it. Dassi runs as a Chrome extension in the side panel and does exactly this. You ask it to pull the open invoices off a page, draft replies to the three emails you flagged, copy the lead details into your CRM, and it does the clicking and typing in the same browser you’re sitting in front of. No connector to configure. No secret to paste. It’s the same idea we wrote about in Browser Agents Are the New API, and it gets sharper the more cluttered your stack is.
You can grab it from the Chrome Web Store and point it at a task in about a minute.
When the app has no node
Here’s a wall n8n hits constantly. Half the tools people actually use day to day don’t expose a clean API, or they put it behind an enterprise tier, or the one endpoint you need is the one they didn’t build. The Reddit API costs a hundred bucks a month now. A lot of internal dashboards have no programmatic access at all because nobody budgeted for it.
n8n can’t make a node for an app that won’t talk to machines. A browser agent doesn’t care, because the page renders the same pixels for it as it does for you. If you can see the number on the screen, the agent can read it and put it somewhere useful. We dug into this gap before in 40 MCP Tools and It Still Can’t Fill Out a Form, and it applies just as much to workflow plumbing.
So is n8n pointless now
No, and I’d be lying if I said otherwise. If you need a server-side pipeline that runs at 3am whether or not anyone’s logged in, syncs two databases on a cron, and never touches a UI, n8n is the right tool and a browser agent is the wrong one. Scheduled, headless, machine-to-machine work is its whole reason to exist.
The mismatch shows up with the human-in-the-loop stuff. The triage, the drafting, the “pull this, paste it there, check the one weird edge case” work that fills an actual workday. That’s the work people keep trying to force into workflow canvases, and it’s the work where wiring up six OAuth connections to automate a five-minute task stops making any sense.
SAP didn’t buy a five-billion-dollar company because connecting APIs is easy. They bought it partly because it’s such a pain that an entire product exists to manage the pain. Which is a strange thing to celebrate. The cleanest integration is the one you already did by logging in, and you finished that one ages ago without noticing.