n8n adds agents that use workflows as tools
Agents call n8n workflows as tools and pause before sensitive ones until someone approves. One turn with an agent counts as a single execution.
n8n introduced a new type called Agents on September 25, 2026. Users describe in plain language what an agent should do, pick a language model and define which tools and workflows it may use; the agent works out the individual steps itself. Tools can be n8n integrations, MCP servers or existing workflows, and agents can also call other agents as sub-agents. They are triggered through channels such as Slack, Telegram, Linear and Discord or on a schedule. The feature is labelled as a preview and is available on n8n Cloud to everyone on the latest stable version, while self-hosted instances need extra setup.
A tool marked as sensitive stops the agent until someone approves or rejects the call. Each tool runs with the credentials attached to it; according to n8n, the agent itself never holds the keys to the instance. One turn with an agent is billed as one execution, tool calls to workflows and sub-agents are not counted separately, and agents share the execution quota with workflows. The existing AI Agent node stays unchanged, and knowledge files in CSV, PDF, Markdown or TXT format are only available on n8n Cloud.
Why it matters: Anyone already running client processes as automations in n8n can put an agent on top of those workflows instead of rebuilding the logic in a second system. What the agent is allowed to do then depends on the tools, their credentials and the approvals, not on the model. It is still unclear what setup self-hosted instances actually need, as the post only points to the documentation. Anyone running n8n themselves should check that before deploying it for a client, especially since the feature is still in preview.
Discussion
I read every comment before it appears.No comments yet. Yours would be the first.