…
Skip to content
Topics
On this page

n8n AI Agent Tutorial

An n8n AI agent is a workflow in n8n, a workflow automation platform, in which the AI Agent node runs a language model that calls tools until it reaches an answer. Triggers, tools, approvals and notifications are nodes connected in a visual editor, so an agent can be built with little or no code.

  • Trigger: The node that starts a run, such as a webhook call from the alerting system.
  • Agent: The AI Agent node, which executes the model's tool-calling loop and returns its final answer to the next node.
  • Model: A chat model sub-node, which connects the agent to a model provider through an encrypted, stored credential.
  • Tools: Sub-nodes the agent may invoke, such as HTTP Request tools for logs, metrics and deployment history.
  • Approval: A messaging step that pauses the workflow execution until a designated person responds.
  • Expressions: Short templates in double braces that pass data from earlier nodes into fields.
An n8n AI agent workflow for incident triageA webhook from the alerting system starts the AI Agent node. A chat model and three read-only HTTP Request tools are attached to the agent as sub-nodes, shown with dashed lines. The agent's recommendation goes to a Slack approval step, the rollback runs only if a person approves, and a notification is posted to the incident channel. The flow is illustrative.Webhookalert POSTAI Agenttool loopApprovalSlack waitRollbackif approvedChat modelHTTP tools3 read-onlyNotify
An n8n AI agent workflow for incident triage

For example, an alert about a 5xx spike on the checkout service calls a webhook, the agent reads logs, metrics and deploys, and the on-call engineer approves or rejects the proposed rollback in Slack.

The incident triage agent from the CrewAI tutorial is rebuilt here without Python. The tools are the same three read-only calls, read_logs, get_metrics and list_recent_deploys, exposed as HTTP endpoints of internal services.

Prerequisites

  • Infrastructure: A machine with Docker installed, or an account on the hosted n8n service.
  • Credentials: An API key for a chat model provider and a Slack app token with permission to post messages.
  • Endpoints: HTTP APIs for logs, metrics and deploy history; a small mock service works for testing.
  • Background: Familiarity with tool calling in LLMs and the purpose of human-in-the-loop approval.

Setup

Self-host n8n with Docker, where the named volume preserves workflows and encrypted credentials across container restarts.

Bash
docker volume create n8n_data
docker run -it --rm --name n8n -p 5678:5678 \
  -v n8n_data:/home/node/.n8n \
  docker.n8n.io/n8nio/n8n

Open http://localhost:5678, create the owner account, then create a new workflow. n8n is distributed under a fair-code licence, so review its terms before commercial use.

Step 1: Add the Webhook Trigger

Add a Webhook node, set the method to POST and the path to checkout-5xx, then point the alerting system at the production URL. A test call from the terminal sends the same payload the alerting system would send.

Bash
curl -X POST http://localhost:5678/webhook-test/checkout-5xx \
  -H "Content-Type: application/json" \
  -d '{"service": "checkout", "alert": "5xx rate above 5%", "started_at": "14:02"}'

Step 2: Configure the n8n AI Agent Node

Add an AI Agent node after the webhook and attach a chat model sub-node, such as Anthropic Chat Model, with a new credential that holds the API key. Set the prompt source to a defined prompt and write the task and system message.

  • Prompt: The text Find the likely cause of the 5xx spike on {{ $json.body.service }}. inserts the service name from the webhook payload.
  • Instructions: The system message states that the agent only reads data, cites tool results and never performs a rollback.
  • Formatting: The answer ends with one action line, either ROLLBACK <version> or INVESTIGATE, so later nodes can evaluate it with a simple condition.
  • Iterations: A maximum iteration setting stops a run in which the agent keeps calling tools without finishing.

Step 3: Add HTTP Request Tools

Attach three HTTP Request Tool sub-nodes to the agent's tool input and name them read_logs, get_metrics and list_recent_deploys. Each has a description, which the model reads when it chooses a tool, and a GET URL on the internal service; the $fromAI() expression lets the model fill a parameter such as the service name.

The excerpt below is an illustrative, simplified export of the workflow; real exports also contain node ids, positions and type versions.

JSON
{
  "name": "Checkout 5xx triage",
  "nodes": [
    { "name": "Alert webhook", "type": "n8n-nodes-base.webhook",
      "parameters": { "httpMethod": "POST", "path": "checkout-5xx" } },
    { "name": "Triage agent", "type": "@n8n/n8n-nodes-langchain.agent",
      "parameters": {
        "promptType": "define",
        "text": "=Find the likely cause of the 5xx spike on {{ $json.body.service }}.",
        "options": { "systemMessage": "Read-only triage. Never perform a rollback." } } },
    { "name": "Claude model", "type": "@n8n/n8n-nodes-langchain.lmChatAnthropic",
      "credentials": { "anthropicApi": { "name": "Anthropic account" } } },
    { "name": "read_logs", "type": "n8n-nodes-base.httpRequestTool",
      "parameters": {
        "toolDescription": "Latest error log lines for a service",
        "url": "=https://logs.internal.example/api/search?service={{ $fromAI('service') }}" } }
  ],
  "connections": {
    "Alert webhook": { "main": [[{ "node": "Triage agent", "type": "main", "index": 0 }]] },
    "Claude model": { "ai_languageModel": [[{ "node": "Triage agent", "type": "ai_languageModel", "index": 0 }]] },
    "read_logs": { "ai_tool": [[{ "node": "Triage agent", "type": "ai_tool", "index": 0 }]] }
  }
}
  • Connections: Ordinary data flows through main connections, while sub-nodes connect through dedicated inputs for the language model and the tools.
  • Safety: All three tools use GET requests, so the agent can inspect production telemetry but cannot modify any production system.

Step 4: Add n8n Human Approval Before Rollback

Add an If node that checks whether the agent's output contains ROLLBACK. On the true branch, add a Slack node with the operation that sends a message and waits for a response, with Approve and Reject buttons, followed by a second If node on the response.

  • Approved: An HTTP Request node sends POST /rollback to the deploy system with the version from the agent's answer.
  • Rejected: The workflow records the decision with the approver's identity and makes no production change.
  • Timeout: A wait limit on the approval step prevents an execution from waiting indefinitely when nobody responds.
  • Auditability: The approval message, the responder and the timestamp are stored in the execution history, which provides evidence for the incident timeline.

Step 5: Send the Notification

Add a final Slack node, or an email node, that posts the agent's summary and the approval decision to the incident channel. Activate the workflow afterwards, because the production webhook URL accepts alerts only while the workflow is active.

Output

Illustrative message in the incident channel (the model's wording varies between runs):

Example
[Checkout 5xx triage]
Likely cause: deploy v2.41.0 at 14:00 cut the payments client timeout from 10 s to 3 s.
Evidence: payments-api timeouts (502) from 14:02; 5xx rate 0.3% -> 7.9%.
Recommended action: ROLLBACK v2.41.0
Decision: approved by priya.oncall at 14:11. Rollback requested from the deploy system.
  • Traceability: The execution log in n8n shows every tool call with its input and output, which supports the post-incident review.
  • Separation: The agent produced the recommendation, while a person and an ordinary node performed the rollback.

Common Errors

  • The requested webhook "POST checkout-5xx" is not registered: The test URL listens only after a test run is started, and the production URL works only when the workflow is active.
  • No prompt specified: The agent expected a chat input field, so set the prompt source to a defined prompt and fill the prompt text.
  • 401 Unauthorized from a tool: The internal API rejected the request, so attach an HTTP credential with a valid token to that tool node.
  • not_in_channel from Slack: The Slack app is not a member of the incident channel, so invite the app to that channel.
  • Agent stopped due to max iterations: The agent did not finish within the iteration limit, so sharpen the tool descriptions or raise the limit slightly.

Next Steps

Quick Quiz

Pick an answer to check yourself. Nothing is saved.

Question 1 / 3

  1. 1. In the n8n AI agent workflow, how does the chat model connect to the AI Agent node?

Frequently Asked Questions

What is the AI Agent node in n8n?

It is a workflow node that runs a language model in a tool-calling loop. A chat model, optional memory and one or more tools are attached to it as sub-nodes, and the node returns the model's final answer to the next step.

Can n8n be self-hosted?

Yes. Self-hosted n8n runs on a private server or laptop as a Docker container, which keeps workflow data and credentials inside the team's own infrastructure. A hosted cloud service is also available for teams that prefer not to operate it.

Does building an n8n AI agent require code?

Very little. n8n works as a low-code AI agent builder, so most of the workflow is configured in the visual editor, including triggers, tools and approvals. Short expressions are used to pass values between nodes, and a Code node is available when custom logic is needed.

How do you add human approval to an n8n agent workflow?

A messaging node such as Slack or email can send a message and pause the workflow until a person responds. The next node reads the response and continues only when the action is approved.

When is a Python framework a better choice than n8n?

A code framework suits agents that need custom state, complex branching, unit tests or deployment inside an existing service. n8n suits teams that want a visual workflow connected to many business tools with little code.