n8n in 2026 is an agent runtime with a visual canvas on top. Here are seven workflows that turn alerts, pull requests, and vulnerability feeds into supervised automations, plus how to build them from Claude Code over MCP.
See the workflow in action, tap through the tabs below:
// one-line self-hosted install (Docker required)
curl -fsSL https://get.n8n.io | sh # n8n is running at: http://localhost:5678 # upgrade later: curl -fsSL https://get.n8n.io | sh -s -- --upgrade
// AI Agent node, system prompt for the alert triage workflow
You are an on-call triage assistant. For each incoming alert:
1. Look up the service owner and runbook link with the get_runbook tool.
2. Query recent deploys for that service with the list_deploys tool.
3. Classify severity as P1, P2, or P3 and explain why in two sentences.
4. Propose ONE action (rollback, scale, or acknowledge). Never execute it.
Return JSON: {severity, summary, proposed_action, evidence}.
// expose your instance to Claude Code (n8n 2.18.3 or newer)
# 1. In n8n: Settings > Instance-level MCP > Enable MCP access # 2. Copy the Server URL (ends in /mcp-server/http) # 3. In Claude Code, register it, then authorize with OAuth: claude mcp add --transport http n8n https://YOUR-N8N-HOST/mcp-server/http # 4. Ask: "Build a workflow: GitHub PR webhook -> AI Agent reviews # Terraform diff -> posts a summary comment. Test it with sample data."
npm installs die with n8n 3.0 (October 2026). New installs go through Docker, full stop.
Agents propose, humans approve. Use the “Add human review step” option on any agent-to-tool connection before letting a model touch production.
Every workflow run is one execution, no matter how many nodes. Size your plan on runs, not steps. Error workflow runs no longer count against quota as of 2.38.
Read the script before piping it to sh. Download get.n8n.io, skim it, then run it. Same rule you apply to everything else.
What n8n actually is in 2026
n8n started as a fair-code Zapier alternative. That is years out of date. The 2.x line turned it into an agent runtime: an AI Agent node with schema-validated tool calls, memory backends, native web search, human approval on individual tool calls, OpenTelemetry traces, and an instance-level MCP server that lets Claude Code, Cursor, or ChatGPT build and test your workflows. The canvas is still there. It is no longer the point.
For DevOps and security work that matters because n8n sits where the job lives: webhooks in, API calls out, a Code node when nodes run out, and a Slack "are you sure?" step before anything destructive. If you read our Claude MCP connectors post, this is the other side of that handshake.
Quick setup: one command, Docker only
The old npx n8n route is on borrowed time. n8n 3.0 ships in October 2026 and is distributed only through Docker, so start the way you will have to finish:
curl -fsSL https://get.n8n.io | sh
That script checks Docker and Compose v2, writes a compose.yml and .env with unique secrets into ./n8n, pulls the image, and starts n8n on localhost:5678 backed by SQLite. Only port 5678 is exposed. Upgrade with --upgrade, pin with --version 2.38.6. Windows users run it from WSL. For a team instance, swap SQLite for Postgres via the Docker Compose guide; for the self-hosted n8n Assistant (2.35), add a model key to N8N_INSTANCE_AI_MODEL_API_KEY in that .env.
Prefer not to pipe the internet into sh? Fetch it to a file first, read it, then run it: curl -fsSL https://get.n8n.io -o get-n8n.sh. The docs recommend exactly that and so do we.
Mindset: the agent proposes, the workflow decides
The mistake everyone makes with n8n agents is wiring the model straight to the tool that does the thing. Do not. Treat the AI Agent node as a classifier and drafter: it reads context, picks a severity, proposes an action with evidence. Deterministic nodes and a human decide whether it runs. n8n gives you three enforcement points: Add human review step on any agent-to-tool connection (2.6), the Chat node's Send a message and wait for response with inline approval buttons (2.5), and Send and Wait nodes for Slack, Teams, Telegram, and Gmail that now record who approved and when (2.30). Build with that pattern and an auditor can read your automation.
7 n8n workflows for DevOps and security
1. Alert triage agent with a Slack approval gate
Point your alert manager's webhook at an n8n Webhook node. Feed the payload to an AI Agent with two tools: an HTTP Request tool that fetches the runbook and a sub-workflow tool that lists the last five deploys. The system prompt in the widget does the rest. Route the agent's JSON to a Slack Send and Wait node with two buttons, then an IF node that only runs the rollback sub-workflow on an explicit approve. Who clicked and when is captured on the execution (2.30), which is the line item your SOC 2 auditor will ask about.
2. Terraform PR reviewer
GitHub Trigger on pull requests, filter for .tf changes, hand the diff to the agent with your house rules. It posts one comment with findings ranked by blast radius. GitHub App authentication (2.29) means no personal access token tied to a human. Example prompt:
Review this Terraform diff as a cloud security engineer. Flag: public ingress, missing encryption at rest, IAM wildcards, unpinned module versions. For each finding give file, line, risk (High/Med/Low), and a one-line fix. Do not comment on style.
3. Daily CVE digest with native web search
Schedule Trigger at 07:00 (schedules survive restarts as of 2.32), an agent with the web search capability added in 2.25, and a prompt like: "Search for CVEs published in the last 24 hours affecting Kubernetes, nginx, OpenSSH, and Postgres. Return only CVSS 7 or higher with the vendor advisory URL." Pipe it to Gmail or Teams. Self-hosted search runs through Brave or a bundled SearXNG, so you control what leaves the network.
4. Build and test workflows from Claude Code over MCP
This one changes how you use the other six. n8n 2.18.3 and newer ship an instance-level MCP server on every plan, Community included. Go to Settings, then Instance-level MCP, toggle Enable MCP access, copy the Server URL (ends in /mcp-server/http), register it in Claude Code with the command in the widget, and authorize with OAuth. Now "build a workflow that ingests Falco alerts from a webhook, dedupes by container ID with a Data table, and posts a summary to #security" appears on the canvas. It makes targeted edits (2.22), can restore workflow history (2.29), and can validate, run tests, and read execution logs to fix its own failures. n8n is also an official Claude Connector, so Claude Desktop is a paste-the-URL setup.
5. Human-reviewed remediation tools
Give the triage agent a real remediation tool, a sub-workflow that scales a deployment or revokes a key, but click the plus icon on the agent-to-tool connection and choose Add human review step. The agent can still propose the call; the call blocks until someone approves. Works for any tool, including the MCP Client tool and sub-workflows, so it is the cheapest guardrail around an agent that can reach something dangerous.
6. Promote workflows between dev and prod as packages
Since 2.27 you can bundle workflows into a portable .n8np package and move them between instances via the Public API or matching CLI commands. Pair that with Git version control and workflow diff on the Business plan and a workflow change follows the same path as code: branch, review the visual diff, merge, promote. Credentials stay out of the package, which is what you want.
7. Trace everything with OpenTelemetry
Set N8N_OTEL_ENABLED=true and N8N_OTEL_EXPORTER_OTLP_ENDPOINT and n8n emits a trace per execution with node-level spans, workflow version IDs, trace context propagation, and AI Agent telemetry (2.15 to 2.20). The agent's tool calls land next to the API calls they triggered in Tempo or Datadog, turning "the bot did something weird" into a span you can click.
Safety and gotchas
Execution data is evidence, and it may contain secrets. Anything a node returns is stored in the execution log. Execution data redaction (never shown in the UI until someone with the reveal permission asks, with every reveal audited) is an Enterprise feature. On other plans, scrub tokens in a Code node before they hit the log, and keep saved-execution retention short.
Expose MCP surgically. Workflows are not reachable from the MCP server unless you mark each one "Available in MCP", and they must be published with a webhook, form, schedule, or chat trigger. Leave the toggle off for anything that can spend money or delete infrastructure. If you never want the feature on a self-hosted box, set N8N_DISABLED_MODULES=mcp.
Verify your webhooks. Fourteen trigger nodes gained signature verification in 2.21. Turn it on. An unauthenticated webhook feeding an agent with tools is a prompt injection endpoint with a public IP.
Budget for the loop. Set the tool-call retry limit, a max iterations value, and a timeout on every agent, or a confused model will burn your budget on a Sunday.
npm is ending. n8n 3.0 (October 2026) is Docker only. Move now while it is boring.
Usage and cost tips
n8n bills on executions, one per full workflow run regardless of node count, with unlimited users and workflows on every plan. Cloud, billed annually: Starter at 20 EUR per month for 2,500 executions, Pro at 50 EUR for 10,000 with 20 concurrent runs and 7 days of insights, Business at 667 EUR for 40,000 with SSO, Git version control, environments, and 30 days of insights. Enterprise is custom and adds external secret stores, log streaming, and an SLA. Self-hosted Community is free with no execution cap; the trial is 1,000 executions, no card.
Three cost moves: batch chatty sources behind a Schedule Trigger, since a run that processes 500 alerts is still one execution. Put error handling in an error workflow, because as of 2.38 those runs do not count against quota. On Cloud, Gateway credits (2.36) let you bake off model providers on a prepaid balance before committing to API keys. Under 20 people? The Start-up plan is 50 percent off Business.
FAQ
Is n8n free to self-host for production use?
Yes. The Community edition is fair-code licensed and has no execution cap. You pay for Business or Enterprise when you need SSO, environments, Git version control, external secrets, redaction, or an SLA. From n8n 3.0 the only supported distribution is Docker.
Does n8n work with Claude Code and Claude Desktop?
Yes. n8n 2.18.3 and newer include an instance-level MCP server (Settings, then Instance-level MCP) that Claude Code, Claude Desktop, Cursor, ChatGPT, Codex, Windsurf, and others can connect to over HTTP with OAuth or an API key. n8n is also an official Claude Connector.
How do I estimate how many executions I need?
Count runs, not steps. A workflow on a five-minute schedule is roughly 8,600 to 8,900 executions a month. A webhook workflow equals the number of triggering events. A chatbot equals conversations times messages per conversation. Your Insights dashboard shows actual usage once you are running.
Ship one supervised agent this week
Pick workflow one. Wire the webhook, write the prompt, add the Slack gate, and run it in shadow mode for five days where the "action" is just a message. Then flip the switch. One agent, one gate, one audit trail. For the deeper version, our DevOps and AI tracks at tha-shed.com/our-courses/ go from first webhook to a production agent platform with the guardrails built in.

