n8n Is Worth $5.2B. It Still Needs an API Key for Everything.
SAP put a $5.2B valuation on n8n this week, and the TechCrunch headline framed it as a bet on AI automation eating the enterprise. Fair enough. n8n is genuinely good software, and I’ve built more than a few workflows in it that saved me real hours. But I kept staring at the number and thinking about the part nobody puts in the press release: before any n8n workflow does a single useful thing, you have to hand it credentials for every service it touches.
That’s the toll booth at the entrance to the whole automation dream, and it doesn’t go away no matter how much money flows in.
The credentials come first, the magic comes second
Open n8n. Pick a node. Say you want it to read your Gmail and drop something into a Notion database. Before either node runs, you’re staring at an OAuth consent screen for Google, then a separate integration token for Notion, then probably a Slack app config if you want a notification at the end.
Each of those is a long-lived key sitting in a credentials store. You created it. You own the security of it. And you’ll re-create it the next time the OAuth scope changes or the token silently expires on a Tuesday.
This is the model the entire automation industry runs on. Zapier, Make, n8n, every workflow tool valued in the billions. They connect services by holding copies of your access to those services. The connection IS the product.
A browser is already logged in
Now think about what your actual Chrome window knows about you. You’re logged into Gmail. You’re logged into Notion. Slack, your CRM, that internal admin panel with no public API, the SaaS dashboard that gates CSV export behind a $100 upgrade. All of it, authenticated, sitting in tabs right now.
A browser agent works there. It reads the page you’re looking at and acts inside the session you already have, which means there is no second copy of your credentials to create, store, rotate, or leak. dassi runs as a Chrome side panel and does exactly this: it drives the tab, not a server-side clone of your accounts.
So the n8n flow that needs a Google OAuth app, a Notion integration token, and a Slack bot config becomes “read this thread, add it to that database, tell the channel.” No node graph. No credentials vault. The authentication already happened when you logged in this morning.
Where the n8n model genuinely wins
I want to be honest about this, because pretending browser agents replace everything would be dumb. n8n shines when something needs to run at 3am with nobody watching. Scheduled jobs, webhook-triggered pipelines, high-volume server-to-server syncs where a real browser would be absurd overhead. If your task is “every hour, pull new Stripe charges and reconcile them,” you want a workflow engine with stored credentials, full stop. A browser agent dozing in a side panel is the wrong tool for that.
The mismatch shows up in the other direction. So much of what people actually wire into n8n is not high-volume batch infrastructure. It’s “summarize my inbox,” “draft a reply,” “pull the numbers off this dashboard,” “fill out this form with data from that spreadsheet.” Human-paced, browser-shaped work that someone forced into a workflow engine because that was the only automation tool they knew, and then spent an afternoon collecting API keys for services they were already logged into two tabs over. That entire category of task never needed a server in the middle, and routing it through one mostly adds a credential to lose. We wrote more about that gap in Browser Agents Are the New API, and it’s the part of the automation story the funding round skips right past.
The stored credential is the liability
Every OAuth token in a credentials store is a thing that can be stolen. Not theoretically. The whole reason “lethal trifecta” entered the security vocabulary is that the combination of broad access plus stored secrets plus an automated process is exactly what attackers love.
A browser agent acting in your live session doesn’t mint a new long-lived secret. When you close the tab, the access closes with it. There’s no warehouse of tokens waiting to be breached, because the authentication never left your machine in the first place.
And there’s a BYOK angle that rhymes with this. n8n still needs you to plug in an LLM provider key on top of all the service credentials. dassi lets you log in with your existing ChatGPT subscription or bring your own key for Claude, Gemini, whatever you prefer, so the model runs on your terms and the data stays in your browser. Two different philosophies about where your secrets should live. I know which one I trust more.
What $5.2B doesn’t buy
A bigger valuation buys n8n more nodes, more integrations, more pre-built connectors to more services. It does not change the fundamental shape of the thing. More money means more credentials to collect, not fewer.
The funny part is that the alternative was sitting in your taskbar the entire time. If you want to feel the difference, grab dassi from the Chrome Web Store and ask it to do one thing you’d normally build a workflow for. No OAuth screen. Just the tab you already had open.