AI Agent Frameworks Compared: n8n, LangGraph, CrewAI, Microsoft Agent Framework, Pydantic AI

Editorial note: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, prices, versions, licensing terms, and external content may change. Please verify the information provided independently, particularly before making business-critical or security-related decisions. This article does not replace individual professional, legal, or tax advice.

Introducing AI agents with approvals and an audit trail? WZ-IT builds agents with defined tools, human approval and tracing and operates them on local or European infrastructure, see AI agents in the AI hub. Book a meeting
An AI agent is quick to build. An AI agent that reliably creates tickets, obtains approvals, logs every step traceably for twelve months and still works after a security update is an operations topic. Most framework comparisons rate developer convenience and multi-agent patterns. This article rates the common options from the perspective of the people who run them: license, self-hosting, approvals, logging, MCP, local models, release cadence and the AI Act.
The comparison covers the workflow platform n8n and four code frameworks: LangGraph, CrewAI, Microsoft Agent Framework and Pydantic AI. All versions, licenses and features reflect the state at the end of September 2026 and are referenced to each project's documentation or repository.
Table of Contents
- The five frameworks at a glance
- License and self-hosting
- Approvals and human-in-the-loop
- Logging and Langfuse
- MCP integration
- Local models instead of a cloud API
- Operations: updates, state, telemetry
- AI Act: what the framework does and does not cover
- Which framework for which case
- Our approach at WZ-IT
- Further guides
The five frameworks at a glance
| Framework | Type | Language | License | Current version (end of September 2026) |
|---|---|---|---|---|
| n8n | Workflow platform with AI Agent node | visual, code nodes in JavaScript and Python | Sustainable Use License (fair code) plus n8n Enterprise License for .ee files | 2.41.4 stable, 30 Sep 2026; 1.123.83 for the 1.x branch |
| LangGraph | Graph framework for stateful agents | Python, TypeScript | MIT | 1.2.12, 21 Sep 2026 |
| CrewAI | Framework for teams of role-based agents (Crews) and flows (Flows) | Python | MIT | 1.15.23, 28 Sep 2026 |
| Microsoft Agent Framework | Agents and graph-based workflows, successor of AutoGen and Semantic Kernel | .NET, Python, Go (preview) | MIT | Python 1.19.0, 18 Sep 2026 |
| Pydantic AI | Typed agent framework | Python | MIT | 2.52.0, 30 Sep 2026 |
Sources: n8n releases, LangGraph on PyPI, CrewAI on PyPI, agent-framework on PyPI, pydantic-ai on PyPI.
The fundamental difference lies between the first row and the rest. n8n is a running application with a user interface, user management, database and execution history. The four code frameworks are libraries: they are built into an application of your own, and runtime, database, authentication and user interface are provided by the operator or through a commercial platform from the vendor.
Two notes on maturity: LangGraph reached version 1.0 in October 2025, CrewAI also in October 2025, Microsoft Agent Framework in April 2026, Pydantic AI version 1.0 in September 2025 and version 2.0 in June 2026 (release dates according to PyPI). Microsoft's predecessor AutoGen is in maintenance mode according to its repository and receives no new features.
License and self-hosting
For operation in your own data centre or on your own server, the question is not only whether the software is freely available, but which parts need a commercial license for production use.
| Framework | Free to self-host | Paid or license-bound |
|---|---|---|
| n8n | Community Edition for your own internal business purposes, queue mode, logging | SSO (SAML, LDAP), log streaming, projects and roles, environments, Git version control, external secrets, multi-main |
| LangGraph | Library including PostgreSQL checkpointer, in your own application | self-hosted LangSmith (Enterprise add-on), standalone Agent Server (license key) |
| CrewAI | Library including Crews, Flows, local approvals | CrewAI AMP with webhook-based approvals and approval management |
| Microsoft Agent Framework | Library entirely under MIT | no license-bound part in the framework; Azure services are billed separately if used |
| Pydantic AI | Library entirely under MIT | Logfire as an optional observability service; OpenTelemetry export to other targets possible |
Evidence: the features missing from the n8n Community Edition are listed in the edition comparison. The limits of the Sustainable Use License are set out in the license text: use only for your own internal business purposes or non-commercially, distribution only free of charge and for non-commercial purposes. The License FAQ explicitly allows charging customers for workflow creation, setup and maintenance and prohibits hosting n8n as a service in which customers build their own workflows. According to the LangChain documentation, self-hosted LangSmith is an add-on to the Enterprise plan; the standalone Agent Server requires a license key as well as PostgreSQL and Redis.
For operations this means:
- n8n can be used for internal agents without license costs. Anyone who needs several teams with separate permissions, SSO or export of execution logs to a SIEM ends up on Business or Enterprise. That should be settled before the project, not after the third team.
- LangGraph is free as long as you build the runtime yourself: your own API, a worker, PostgreSQL as the checkpointer. That is feasible and common, but it is development work that n8n does not require.
- CrewAI, Microsoft Agent Framework and Pydantic AI are pure libraries under MIT. The operating platform is always your own application.
Approvals and human-in-the-loop
An agent that sends emails, changes records or triggers orders needs points at which a human consents. How such approval points are set from a business perspective is described in the article on permissions and approvals for AI agents. Technically, the frameworks differ in where the pause is stored and who delivers the approval.
| Framework | Mechanism | Where the waiting state lives |
|---|---|---|
| n8n | Human review per tool on the AI Agent node; channels include n8n Chat, Slack, Microsoft Teams, Telegram, Discord, Gmail | execution pauses in the n8n database |
| LangGraph | interrupt() in the node, resume with Command(resume=...) |
checkpointer, in production e.g. PostgreSQL, addressed via thread_id |
| CrewAI | human_input on tasks, @human_feedback in Flows (from 1.8.0); webhook approvals in CrewAI AMP |
synchronous in the local application; asynchronous in the commercial platform |
| Microsoft Agent Framework | approval_mode="always_require" (Python), ApprovalRequiredAIFunction (.NET) |
agent session; approval responses are bound to the session's pending request by default |
| Pydantic AI | requires_approval=True or ApprovalRequired; run ends with DeferredToolRequests |
message history that the application stores and resumes with DeferredToolResults |
Sources: n8n Human-in-the-loop for tools, LangGraph interrupts, CrewAI Human-in-the-Loop, Microsoft Agent Framework tool approval, Pydantic AI deferred tools.
Two points matter more in operations than the API:
- Asynchronous approvals need persistence. An approval granted the next morning has to survive a server restart. n8n and LangGraph with a PostgreSQL checkpointer handle this without extra work. With Pydantic AI and Microsoft Agent Framework, your own application stores the state; Pydantic AI additionally offers durable execution with Temporal, DBOS or Prefect (Pydantic AI durable execution). For CrewAI, the documentation assigns asynchronous, webhook-based approvals to the commercial platform; in the open source package, approvals are described for synchronous flows.
- The approval must be bound to exactly the requested call. Microsoft explicitly documents that an unbound approval response is ignored, because otherwise a fabricated or replayed response could approve a privileged tool call. The same requirement applies to any approval interface you build yourself.
Logging and Langfuse
For troubleshooting and evidence, knowing that a run took place is not enough. What is needed is the chain: input, retrieved context, chosen tool, parameters, result, model response, approval. Langfuse records this chain as a trace and can be self-hosted. The core is MIT-licensed, some add-on features require a license key; as infrastructure, Langfuse needs PostgreSQL, ClickHouse, Redis or Valkey and S3-compatible storage (Langfuse self-hosting).
| Framework | Connection to Langfuse | Other telemetry |
|---|---|---|
| n8n | no native tracing integration according to Langfuse; community solutions | OpenTelemetry traces for workflow and node executions (preview since 2.19.0), log streaming only on Business/Enterprise |
| LangGraph | Langfuse CallbackHandler for LangChain and LangGraph | LangSmith (SaaS or Enterprise self-hosting) |
| CrewAI | via OpenInference instrumentation and OpenTelemetry | tracing in CrewAI AMP |
| Microsoft Agent Framework | documented integration via OpenTelemetry | OpenTelemetry built in following the GenAI conventions; prompts and tool arguments only with ENABLE_SENSITIVE_DATA=true |
| Pydantic AI | via OpenTelemetry instrumentation | Logfire |
Sources: Langfuse and n8n, n8n OpenTelemetry, Langfuse and LangChain/LangGraph, Langfuse and CrewAI, Langfuse and Microsoft Agent Framework, Microsoft Agent Framework observability, Langfuse and Pydantic AI.
With n8n the situation is split. The OpenTelemetry spans describe workflow and nodes (ID, type, status, number of items), not the content of the prompts. Tracing the content of AI steps in n8n requires either an additional solution or a gateway such as LiteLLM in front of the model that logs every model request. n8n labels its OpenTelemetry support as a preview that may still change.
What a log should contain for the AI Act and how Langfuse is set up for it is covered in the article on Langfuse and EU AI Act logging. WZ-IT runs it as Managed Langfuse.
MCP integration
The Model Context Protocol separates tool integration from the framework: an MCP server for the ticket system works with any client that speaks MCP. Fundamentals and risks are explained in the article MCP in the enterprise.
| Framework | MCP as client | MCP as server |
|---|---|---|
| n8n | MCP Client Tool on the AI Agent node, MCP Client as a workflow step | MCP Server Trigger exposes workflows as tools |
| LangGraph | langchain-mcp-adapters (MIT) |
via your own application |
| CrewAI | mcps field on the agent or MCPServerAdapter; stdio, SSE, Streamable HTTP |
not part of the framework |
| Microsoft Agent Framework | MCP clients built in | via your own application |
| Pydantic AI | MCP client (stdio, Streamable HTTP) | via your own application |
Sources: n8n MCP Client Tool, n8n MCP Server Trigger, LangChain MCP, CrewAI MCP, Pydantic AI MCP client.
All five support MCP, so it is no longer a differentiator. Three rules count in operations:
- stdio servers are code execution. An MCP server started via stdio runs as a process on the agent's host. It belongs in the same review as any other installed software.
- An MCP server collects credentials. Connecting ten systems bundles ten sets of access in one place. Each server gets its own technical account with minimal permissions.
- Tool descriptions are input. Text supplied by an MCP server ends up in the model's context and can contain instructions. Countermeasures are described in the article on prompt injection.
How quickly an integration layer becomes a target itself is shown by the LiteLLM vulnerability of September 2026, where a privilege escalation reached code execution via MCP stdio.
Local models instead of a cloud API
All five frameworks can call OpenAI-compatible endpoints such as those provided by vLLM or Ollama. n8n also has dedicated Ollama nodes, and Microsoft Agent Framework lists Ollama among its model providers (Microsoft Agent Framework overview). An agent with a local model is therefore technically possible with every framework.
The limitation lies with the model, not the framework:
- Tool calling has to be reliable. An agent fails less often on answer quality than on faulty tool calls: wrong tool, invalid parameters, invented fields. The chosen model should be tested with your own tools and test cases before the framework is decided.
- Structured output lowers the error rate. Pydantic AI validates tool parameters and outputs against Pydantic models, Microsoft Agent Framework works with typed functions. Invalid parameters are caught before they reach the target system's API.
- A gateway decouples model and agent. With LiteLLM the model can be switched without touching the agent, and every request is logged centrally.
Which model size fits which hardware is covered in the article Which LLM to self-host. WZ-IT runs models on the AI Cube in your own network or on managed GPU servers with NVIDIA RTX PRO 4000 Blackwell (24 GB GDDR7 ECC) or RTX PRO 6000 Blackwell Max-Q (96 GB GDDR7 ECC).
Operations: updates, state, telemetry
Release cadence. All five projects release at short intervals. n8n maintains a stable branch, a beta branch and the 1.x branch in parallel; on 30 September 2026, 2.41.4, 2.42.1 (beta) and 1.123.83 were released at the same time (n8n releases). On the same day, n8n published 14 security advisories (10 rated high, 4 medium), which the article on the n8n security update of September 2026 puts into context. Pydantic AI continues to maintain the 1.x branch alongside version 2 (1.107.7 on 30 Sep 2026). For code frameworks: pin versions, lock dependencies in a lockfile and run updates against your own test cases.
Attack surface. n8n is a web application with login, webhooks and stored credentials and has to be secured as one: not publicly reachable where that is not necessary, webhooks exposed selectively, updates applied promptly. A code framework has no user interface of its own; the attack surface comes from the application the operator builds around it.
State and recovery. Long-running agents need a state store that survives restarts. n8n stores executions in its database, LangGraph in a checkpointer (LangGraph persistence), CrewAI Flows persist their state with @persist, using SQLite by default (CrewAI Flows), workflows in Microsoft Agent Framework support checkpoints (Microsoft Agent Framework checkpoints), and Pydantic AI relies on external durable execution systems for long-running runs.
Telemetry to the vendor. CrewAI collects anonymous telemetry by default: tool names, agent roles, versions and execution metadata, according to the vendor without prompts. With share_crew, goals, backstories, context and outputs are also transmitted. It can be switched off with CREWAI_DISABLE_TELEMETRY=true or OTEL_SDK_DISABLED=true (CrewAI telemetry). In an environment with personal data, this setting belongs in the baseline configuration.
AI Act: what the framework does and does not cover
The AI Act regulates AI systems by their purpose of use, not the library they are built with. No framework is "AI Act compliant" or not. It provides building blocks with which obligations can be implemented technically:
| Requirement | Building block in the framework | What the operator also defines |
|---|---|---|
| Transparency towards people interacting with the system | labelling in responses and triggered messages | wording, channel, exceptions |
| Human oversight | approval before tool calls | which actions require approval, who approves, deputies |
| Logging | tracing, execution history | retention period, access, data protection of the logs |
| Robustness | schema validation, retry limits | test cases, regression test before a model change |
The transparency obligations of Article 50 have applied since 2 August 2026; details are in the article on the AI labelling obligation. Most enterprise agents are not high-risk. For agents in areas such as HR, the high-risk obligations apply later following the Digital Omnibus, as described in the article on permissions and approvals and in RAG and the AI Act. This assessment is not legal advice.
Which framework for which case
| Starting point | Obvious choice | Reason |
|---|---|---|
| Agent connects existing systems, business team should adapt flows | n8n | built-in integrations and community nodes, visual maintenance, approvals without code |
| Multi-step flow with pauses, branches, resumption after days | LangGraph | explicit graph, checkpointer in PostgreSQL, interrupt() |
| Typed agent in an existing Python application | Pydantic AI | validation of parameters and outputs, approvals via deferred tools |
| .NET environment or existing Semantic Kernel or AutoGen code | Microsoft Agent Framework | official successor with migration guides |
| Several role-based agents work together on one task | CrewAI | Crews and Flows as the core concept; switch off telemetry |
Two notes from practice:
- Many projects requested as agents are workflows. If the order of steps is fixed and the model only classifies or fills fields, a workflow in n8n is the more verifiable solution. The difference between workflow and agent is explained in the article AI agents and automation.
- Hybrid setups are common. An n8n workflow handles triggers, integrations and approval, a code agent handles the actual decision logic, connected via HTTP or MCP.
Our approach at WZ-IT
- Assessment. Process, systems involved, data types, risks of the possible actions. This shows whether a workflow is enough or an agent is needed.
- Framework and model selection. Matching the requirements for approvals, logging, license and operating model against the options in this comparison, testing the model with your own tools.
- Tools and permissions. Each tool with its own technical account, minimal permissions and schema validation; actions requiring approval are defined and documented.
- Logging. Tracing with Langfuse, model access through LiteLLM, retention of and access to logs defined.
- Operations. Updates, monitoring and regression tests before model or version changes on your own or European infrastructure, with support, consulting and implementation by WZ-IT.
For n8n, WZ-IT handles setup and operations as managed n8n. If you want to clarify which path suits a process before implementation, you can start with the AI process assessment.
Further guides
- AI agents for companies, agents with defined tools, approvals and an audit trail.
- AI agents: permissions and approvals, under whose account an agent acts and where a human has to consent.
- MCP in the enterprise, how the Model Context Protocol works and which risks it brings.
- n8n security update September 2026, affected versions and hardening.
- Langfuse and EU AI Act logging, self-hosted tracing for LLM applications.
- Business process automation with n8n and AI agents, basics of AI agents in n8n.
- AI solutions from WZ-IT, the hub with all offerings for local AI and LLM operations.
Agent or workflow? We review your process, select framework and model and build the agent with approvals, tracing and minimal permissions. Book a meeting
Sources
- n8n, releases on GitHub
- n8n, security advisories
- n8n, license text (Sustainable Use License)
- n8n, License FAQ
- n8n, compare editions
- n8n, Human-in-the-loop for tools
- n8n, trace executions with OpenTelemetry
- n8n, MCP Client Tool
- n8n, MCP Server Trigger
- LangGraph on PyPI
- LangGraph, interrupts
- LangGraph, persistence
- LangChain, MCP
- LangSmith, self-hosted
- LangSmith, standalone Agent Server
- CrewAI, Flows
- CrewAI on PyPI
- CrewAI, Human-in-the-Loop
- CrewAI, MCP
- CrewAI, telemetry
- Microsoft Agent Framework, overview
- Microsoft Agent Framework, tool approval
- Microsoft Agent Framework, observability
- Microsoft Agent Framework, checkpoints
- agent-framework on PyPI
- AutoGen, repository with maintenance mode notice
- pydantic-ai on PyPI
- Pydantic AI, deferred tools
- Pydantic AI, durable execution
- Pydantic AI, MCP client
- Langfuse, self-hosting
- Langfuse, integration with n8n
- Langfuse, integration with LangChain and LangGraph
- Langfuse, integration with CrewAI
- Langfuse, integration with Microsoft Agent Framework
- Langfuse, integration with Pydantic AI
Run AI agents with approvals and an audit trail
We assess your process, select the right framework, connect tools with minimal permissions and operate the agent with tracing and local or European models.
Frequently Asked Questions
Answers to important questions about this topic
It depends on who builds the agent and how much control over the flow is needed. n8n fits when a business team maintains workflows visually and the agent mainly connects existing systems. LangGraph fits stateful flows with pauses and approvals in Python or TypeScript. Pydantic AI and Microsoft Agent Framework suit typed agents in Python and .NET respectively. CrewAI is designed for teams of several role-based agents.
No, not in the sense of an OSI license. n8n is licensed under the Sustainable Use License, a fair-code license. It allows use for your own internal business purposes and operation by service providers, but prohibits, among other things, offering n8n as a service in which customers build their own workflows. Files with .ee in their name are under the n8n Enterprise License and require a license key.
The LangGraph library is MIT-licensed and runs without a license key in any Python or TypeScript application of your own, with PostgreSQL as the checkpointer. The runtime platform is what requires a license: according to the documentation, self-hosted LangSmith is an add-on to the Enterprise plan, and the standalone Agent Server requires a LangSmith license key.
Yes, anonymous telemetry by default: tool names, agent roles, versions and execution metadata, according to the documentation without prompts or task descriptions. With share_crew=True, goals, backstories, context and outputs are also transmitted. Telemetry can be switched off with CREWAI_DISABLE_TELEMETRY=true or OTEL_SDK_DISABLED=true.
All five, in different ways. n8n offers human review for tools of the AI Agent node with approval via chat, Slack, Teams, email and other channels. LangGraph pauses with interrupt() and resumes with Command. Microsoft Agent Framework has approval_mode=always_require, Pydantic AI requires_approval=True. CrewAI has human_input and @human_feedback in the open source package and webhook-based approvals in its commercial platform.
For production, usually yes. Execution logs show that a run took place but rarely the full chain of prompt, tool choice, parameters and model response. Langfuse records this chain as a trace and can be self-hosted. Documented integrations exist for LangGraph, CrewAI, Pydantic AI and Microsoft Agent Framework; for n8n, the Langfuse documentation states there is no native tracing integration.
No. The AI Act is tied to the purpose of use, not to the library. A framework provides building blocks such as approval points, state storage and tracing that can be used to implement oversight and logging. Which obligations apply follows from the classification of the use case. This assessment is not legal advice.
No. MCP is an interface, not a protection mechanism. An MCP server started via stdio is a process on the agent's host and therefore code execution. MCP makes it easier to switch models and frameworks, but the permissions of each tool still have to be limited individually.
Not for new projects. According to its GitHub repository, AutoGen is in maintenance mode, receives no new features and is community-managed. Microsoft directs new users to Microsoft Agent Framework, the successor of AutoGen and Semantic Kernel, with migration guides for both.
Yes. All five can call OpenAI-compatible endpoints such as those provided by vLLM or Ollama, and n8n also has dedicated Ollama nodes. What matters is that the chosen model handles tool calling reliably. This should be tested with your own tools before the project starts.

Written by
Timo Wevelsiep
Co-Founder & CEO
Co-Founder of WZ-IT. Specialized in cloud infrastructure, open-source platforms and managed services for SMEs and enterprise clients worldwide.
LinkedInLet's Talk About Your Idea
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.





