WZ-IT Logo

AI Agent Frameworks Compared: n8n, LangGraph, CrewAI, Microsoft Agent Framework, Pydantic AI

Timo Wevelsiep
Timo Wevelsiep
•
#AI #AIAgents #n8n #LangGraph #CrewAI #PydanticAI #MCP #Langfuse

Editorial note: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, prices, versions, licensing terms, and external content may change. Please verify the information provided independently, particularly before making business-critical or security-related decisions. This article does not replace individual professional, legal, or tax advice.

AI Agent Frameworks Compared: n8n, LangGraph, CrewAI, Microsoft Agent Framework, Pydantic AI

Introducing AI agents with approvals and an audit trail? WZ-IT builds agents with defined tools, human approval and tracing and operates them on local or European infrastructure, see AI agents in the AI hub. Book a meeting

An AI agent is quick to build. An AI agent that reliably creates tickets, obtains approvals, logs every step traceably for twelve months and still works after a security update is an operations topic. Most framework comparisons rate developer convenience and multi-agent patterns. This article rates the common options from the perspective of the people who run them: license, self-hosting, approvals, logging, MCP, local models, release cadence and the AI Act.

The comparison covers the workflow platform n8n and four code frameworks: LangGraph, CrewAI, Microsoft Agent Framework and Pydantic AI. All versions, licenses and features reflect the state at the end of September 2026 and are referenced to each project's documentation or repository.

Table of Contents

  1. The five frameworks at a glance
  2. License and self-hosting
  3. Approvals and human-in-the-loop
  4. Logging and Langfuse
  5. MCP integration
  6. Local models instead of a cloud API
  7. Operations: updates, state, telemetry
  8. AI Act: what the framework does and does not cover
  9. Which framework for which case
  10. Our approach at WZ-IT
  11. Further guides

The five frameworks at a glance

Framework Type Language License Current version (end of September 2026)
n8n Workflow platform with AI Agent node visual, code nodes in JavaScript and Python Sustainable Use License (fair code) plus n8n Enterprise License for .ee files 2.41.4 stable, 30 Sep 2026; 1.123.83 for the 1.x branch
LangGraph Graph framework for stateful agents Python, TypeScript MIT 1.2.12, 21 Sep 2026
CrewAI Framework for teams of role-based agents (Crews) and flows (Flows) Python MIT 1.15.23, 28 Sep 2026
Microsoft Agent Framework Agents and graph-based workflows, successor of AutoGen and Semantic Kernel .NET, Python, Go (preview) MIT Python 1.19.0, 18 Sep 2026
Pydantic AI Typed agent framework Python MIT 2.52.0, 30 Sep 2026

Sources: n8n releases, LangGraph on PyPI, CrewAI on PyPI, agent-framework on PyPI, pydantic-ai on PyPI.

The fundamental difference lies between the first row and the rest. n8n is a running application with a user interface, user management, database and execution history. The four code frameworks are libraries: they are built into an application of your own, and runtime, database, authentication and user interface are provided by the operator or through a commercial platform from the vendor.

Two notes on maturity: LangGraph reached version 1.0 in October 2025, CrewAI also in October 2025, Microsoft Agent Framework in April 2026, Pydantic AI version 1.0 in September 2025 and version 2.0 in June 2026 (release dates according to PyPI). Microsoft's predecessor AutoGen is in maintenance mode according to its repository and receives no new features.

License and self-hosting

For operation in your own data centre or on your own server, the question is not only whether the software is freely available, but which parts need a commercial license for production use.

Framework Free to self-host Paid or license-bound
n8n Community Edition for your own internal business purposes, queue mode, logging SSO (SAML, LDAP), log streaming, projects and roles, environments, Git version control, external secrets, multi-main
LangGraph Library including PostgreSQL checkpointer, in your own application self-hosted LangSmith (Enterprise add-on), standalone Agent Server (license key)
CrewAI Library including Crews, Flows, local approvals CrewAI AMP with webhook-based approvals and approval management
Microsoft Agent Framework Library entirely under MIT no license-bound part in the framework; Azure services are billed separately if used
Pydantic AI Library entirely under MIT Logfire as an optional observability service; OpenTelemetry export to other targets possible

Evidence: the features missing from the n8n Community Edition are listed in the edition comparison. The limits of the Sustainable Use License are set out in the license text: use only for your own internal business purposes or non-commercially, distribution only free of charge and for non-commercial purposes. The License FAQ explicitly allows charging customers for workflow creation, setup and maintenance and prohibits hosting n8n as a service in which customers build their own workflows. According to the LangChain documentation, self-hosted LangSmith is an add-on to the Enterprise plan; the standalone Agent Server requires a license key as well as PostgreSQL and Redis.

For operations this means:

  • n8n can be used for internal agents without license costs. Anyone who needs several teams with separate permissions, SSO or export of execution logs to a SIEM ends up on Business or Enterprise. That should be settled before the project, not after the third team.
  • LangGraph is free as long as you build the runtime yourself: your own API, a worker, PostgreSQL as the checkpointer. That is feasible and common, but it is development work that n8n does not require.
  • CrewAI, Microsoft Agent Framework and Pydantic AI are pure libraries under MIT. The operating platform is always your own application.

Approvals and human-in-the-loop

An agent that sends emails, changes records or triggers orders needs points at which a human consents. How such approval points are set from a business perspective is described in the article on permissions and approvals for AI agents. Technically, the frameworks differ in where the pause is stored and who delivers the approval.

Framework Mechanism Where the waiting state lives
n8n Human review per tool on the AI Agent node; channels include n8n Chat, Slack, Microsoft Teams, Telegram, Discord, Gmail execution pauses in the n8n database
LangGraph interrupt() in the node, resume with Command(resume=...) checkpointer, in production e.g. PostgreSQL, addressed via thread_id
CrewAI human_input on tasks, @human_feedback in Flows (from 1.8.0); webhook approvals in CrewAI AMP synchronous in the local application; asynchronous in the commercial platform
Microsoft Agent Framework approval_mode="always_require" (Python), ApprovalRequiredAIFunction (.NET) agent session; approval responses are bound to the session's pending request by default
Pydantic AI requires_approval=True or ApprovalRequired; run ends with DeferredToolRequests message history that the application stores and resumes with DeferredToolResults

Sources: n8n Human-in-the-loop for tools, LangGraph interrupts, CrewAI Human-in-the-Loop, Microsoft Agent Framework tool approval, Pydantic AI deferred tools.

Two points matter more in operations than the API:

  • Asynchronous approvals need persistence. An approval granted the next morning has to survive a server restart. n8n and LangGraph with a PostgreSQL checkpointer handle this without extra work. With Pydantic AI and Microsoft Agent Framework, your own application stores the state; Pydantic AI additionally offers durable execution with Temporal, DBOS or Prefect (Pydantic AI durable execution). For CrewAI, the documentation assigns asynchronous, webhook-based approvals to the commercial platform; in the open source package, approvals are described for synchronous flows.
  • The approval must be bound to exactly the requested call. Microsoft explicitly documents that an unbound approval response is ignored, because otherwise a fabricated or replayed response could approve a privileged tool call. The same requirement applies to any approval interface you build yourself.

Logging and Langfuse

For troubleshooting and evidence, knowing that a run took place is not enough. What is needed is the chain: input, retrieved context, chosen tool, parameters, result, model response, approval. Langfuse records this chain as a trace and can be self-hosted. The core is MIT-licensed, some add-on features require a license key; as infrastructure, Langfuse needs PostgreSQL, ClickHouse, Redis or Valkey and S3-compatible storage (Langfuse self-hosting).

Framework Connection to Langfuse Other telemetry
n8n no native tracing integration according to Langfuse; community solutions OpenTelemetry traces for workflow and node executions (preview since 2.19.0), log streaming only on Business/Enterprise
LangGraph Langfuse CallbackHandler for LangChain and LangGraph LangSmith (SaaS or Enterprise self-hosting)
CrewAI via OpenInference instrumentation and OpenTelemetry tracing in CrewAI AMP
Microsoft Agent Framework documented integration via OpenTelemetry OpenTelemetry built in following the GenAI conventions; prompts and tool arguments only with ENABLE_SENSITIVE_DATA=true
Pydantic AI via OpenTelemetry instrumentation Logfire

Sources: Langfuse and n8n, n8n OpenTelemetry, Langfuse and LangChain/LangGraph, Langfuse and CrewAI, Langfuse and Microsoft Agent Framework, Microsoft Agent Framework observability, Langfuse and Pydantic AI.

With n8n the situation is split. The OpenTelemetry spans describe workflow and nodes (ID, type, status, number of items), not the content of the prompts. Tracing the content of AI steps in n8n requires either an additional solution or a gateway such as LiteLLM in front of the model that logs every model request. n8n labels its OpenTelemetry support as a preview that may still change.

What a log should contain for the AI Act and how Langfuse is set up for it is covered in the article on Langfuse and EU AI Act logging. WZ-IT runs it as Managed Langfuse.

MCP integration

The Model Context Protocol separates tool integration from the framework: an MCP server for the ticket system works with any client that speaks MCP. Fundamentals and risks are explained in the article MCP in the enterprise.

Framework MCP as client MCP as server
n8n MCP Client Tool on the AI Agent node, MCP Client as a workflow step MCP Server Trigger exposes workflows as tools
LangGraph langchain-mcp-adapters (MIT) via your own application
CrewAI mcps field on the agent or MCPServerAdapter; stdio, SSE, Streamable HTTP not part of the framework
Microsoft Agent Framework MCP clients built in via your own application
Pydantic AI MCP client (stdio, Streamable HTTP) via your own application

Sources: n8n MCP Client Tool, n8n MCP Server Trigger, LangChain MCP, CrewAI MCP, Pydantic AI MCP client.

All five support MCP, so it is no longer a differentiator. Three rules count in operations:

  • stdio servers are code execution. An MCP server started via stdio runs as a process on the agent's host. It belongs in the same review as any other installed software.
  • An MCP server collects credentials. Connecting ten systems bundles ten sets of access in one place. Each server gets its own technical account with minimal permissions.
  • Tool descriptions are input. Text supplied by an MCP server ends up in the model's context and can contain instructions. Countermeasures are described in the article on prompt injection.

How quickly an integration layer becomes a target itself is shown by the LiteLLM vulnerability of September 2026, where a privilege escalation reached code execution via MCP stdio.

Local models instead of a cloud API

All five frameworks can call OpenAI-compatible endpoints such as those provided by vLLM or Ollama. n8n also has dedicated Ollama nodes, and Microsoft Agent Framework lists Ollama among its model providers (Microsoft Agent Framework overview). An agent with a local model is therefore technically possible with every framework.

The limitation lies with the model, not the framework:

  • Tool calling has to be reliable. An agent fails less often on answer quality than on faulty tool calls: wrong tool, invalid parameters, invented fields. The chosen model should be tested with your own tools and test cases before the framework is decided.
  • Structured output lowers the error rate. Pydantic AI validates tool parameters and outputs against Pydantic models, Microsoft Agent Framework works with typed functions. Invalid parameters are caught before they reach the target system's API.
  • A gateway decouples model and agent. With LiteLLM the model can be switched without touching the agent, and every request is logged centrally.

Which model size fits which hardware is covered in the article Which LLM to self-host. WZ-IT runs models on the AI Cube in your own network or on managed GPU servers with NVIDIA RTX PRO 4000 Blackwell (24 GB GDDR7 ECC) or RTX PRO 6000 Blackwell Max-Q (96 GB GDDR7 ECC).

Operations: updates, state, telemetry

Release cadence. All five projects release at short intervals. n8n maintains a stable branch, a beta branch and the 1.x branch in parallel; on 30 September 2026, 2.41.4, 2.42.1 (beta) and 1.123.83 were released at the same time (n8n releases). On the same day, n8n published 14 security advisories (10 rated high, 4 medium), which the article on the n8n security update of September 2026 puts into context. Pydantic AI continues to maintain the 1.x branch alongside version 2 (1.107.7 on 30 Sep 2026). For code frameworks: pin versions, lock dependencies in a lockfile and run updates against your own test cases.

Attack surface. n8n is a web application with login, webhooks and stored credentials and has to be secured as one: not publicly reachable where that is not necessary, webhooks exposed selectively, updates applied promptly. A code framework has no user interface of its own; the attack surface comes from the application the operator builds around it.

State and recovery. Long-running agents need a state store that survives restarts. n8n stores executions in its database, LangGraph in a checkpointer (LangGraph persistence), CrewAI Flows persist their state with @persist, using SQLite by default (CrewAI Flows), workflows in Microsoft Agent Framework support checkpoints (Microsoft Agent Framework checkpoints), and Pydantic AI relies on external durable execution systems for long-running runs.

Telemetry to the vendor. CrewAI collects anonymous telemetry by default: tool names, agent roles, versions and execution metadata, according to the vendor without prompts. With share_crew, goals, backstories, context and outputs are also transmitted. It can be switched off with CREWAI_DISABLE_TELEMETRY=true or OTEL_SDK_DISABLED=true (CrewAI telemetry). In an environment with personal data, this setting belongs in the baseline configuration.

AI Act: what the framework does and does not cover

The AI Act regulates AI systems by their purpose of use, not the library they are built with. No framework is "AI Act compliant" or not. It provides building blocks with which obligations can be implemented technically:

Requirement Building block in the framework What the operator also defines
Transparency towards people interacting with the system labelling in responses and triggered messages wording, channel, exceptions
Human oversight approval before tool calls which actions require approval, who approves, deputies
Logging tracing, execution history retention period, access, data protection of the logs
Robustness schema validation, retry limits test cases, regression test before a model change

The transparency obligations of Article 50 have applied since 2 August 2026; details are in the article on the AI labelling obligation. Most enterprise agents are not high-risk. For agents in areas such as HR, the high-risk obligations apply later following the Digital Omnibus, as described in the article on permissions and approvals and in RAG and the AI Act. This assessment is not legal advice.

Which framework for which case

Starting point Obvious choice Reason
Agent connects existing systems, business team should adapt flows n8n built-in integrations and community nodes, visual maintenance, approvals without code
Multi-step flow with pauses, branches, resumption after days LangGraph explicit graph, checkpointer in PostgreSQL, interrupt()
Typed agent in an existing Python application Pydantic AI validation of parameters and outputs, approvals via deferred tools
.NET environment or existing Semantic Kernel or AutoGen code Microsoft Agent Framework official successor with migration guides
Several role-based agents work together on one task CrewAI Crews and Flows as the core concept; switch off telemetry

Two notes from practice:

  • Many projects requested as agents are workflows. If the order of steps is fixed and the model only classifies or fills fields, a workflow in n8n is the more verifiable solution. The difference between workflow and agent is explained in the article AI agents and automation.
  • Hybrid setups are common. An n8n workflow handles triggers, integrations and approval, a code agent handles the actual decision logic, connected via HTTP or MCP.

Our approach at WZ-IT

  1. Assessment. Process, systems involved, data types, risks of the possible actions. This shows whether a workflow is enough or an agent is needed.
  2. Framework and model selection. Matching the requirements for approvals, logging, license and operating model against the options in this comparison, testing the model with your own tools.
  3. Tools and permissions. Each tool with its own technical account, minimal permissions and schema validation; actions requiring approval are defined and documented.
  4. Logging. Tracing with Langfuse, model access through LiteLLM, retention of and access to logs defined.
  5. Operations. Updates, monitoring and regression tests before model or version changes on your own or European infrastructure, with support, consulting and implementation by WZ-IT.

For n8n, WZ-IT handles setup and operations as managed n8n. If you want to clarify which path suits a process before implementation, you can start with the AI process assessment.

Further guides

Agent or workflow? We review your process, select framework and model and build the agent with approvals, tracing and minimal permissions. Book a meeting

Sources

Enquiry

Run AI agents with approvals and an audit trail

We assess your process, select the right framework, connect tools with minimal permissions and operate the agent with tracing and local or European models.

What is your situation?

How should we get back to you?

Frequently Asked Questions

Answers to important questions about this topic

It depends on who builds the agent and how much control over the flow is needed. n8n fits when a business team maintains workflows visually and the agent mainly connects existing systems. LangGraph fits stateful flows with pauses and approvals in Python or TypeScript. Pydantic AI and Microsoft Agent Framework suit typed agents in Python and .NET respectively. CrewAI is designed for teams of several role-based agents.

No, not in the sense of an OSI license. n8n is licensed under the Sustainable Use License, a fair-code license. It allows use for your own internal business purposes and operation by service providers, but prohibits, among other things, offering n8n as a service in which customers build their own workflows. Files with .ee in their name are under the n8n Enterprise License and require a license key.

The LangGraph library is MIT-licensed and runs without a license key in any Python or TypeScript application of your own, with PostgreSQL as the checkpointer. The runtime platform is what requires a license: according to the documentation, self-hosted LangSmith is an add-on to the Enterprise plan, and the standalone Agent Server requires a LangSmith license key.

Yes, anonymous telemetry by default: tool names, agent roles, versions and execution metadata, according to the documentation without prompts or task descriptions. With share_crew=True, goals, backstories, context and outputs are also transmitted. Telemetry can be switched off with CREWAI_DISABLE_TELEMETRY=true or OTEL_SDK_DISABLED=true.

All five, in different ways. n8n offers human review for tools of the AI Agent node with approval via chat, Slack, Teams, email and other channels. LangGraph pauses with interrupt() and resumes with Command. Microsoft Agent Framework has approval_mode=always_require, Pydantic AI requires_approval=True. CrewAI has human_input and @human_feedback in the open source package and webhook-based approvals in its commercial platform.

For production, usually yes. Execution logs show that a run took place but rarely the full chain of prompt, tool choice, parameters and model response. Langfuse records this chain as a trace and can be self-hosted. Documented integrations exist for LangGraph, CrewAI, Pydantic AI and Microsoft Agent Framework; for n8n, the Langfuse documentation states there is no native tracing integration.

No. The AI Act is tied to the purpose of use, not to the library. A framework provides building blocks such as approval points, state storage and tracing that can be used to implement oversight and logging. Which obligations apply follows from the classification of the use case. This assessment is not legal advice.

No. MCP is an interface, not a protection mechanism. An MCP server started via stdio is a process on the agent's host and therefore code execution. MCP makes it easier to switch models and frameworks, but the permissions of each tool still have to be limited individually.

Not for new projects. According to its GitHub repository, AutoGen is in maintenance mode, receives no new features and is community-managed. Microsoft directs new users to Microsoft Agent Framework, the successor of AutoGen and Semantic Kernel, with migration guides for both.

Yes. All five can call OpenAI-compatible endpoints such as those provided by vLLM or Ollama, and n8n also has dedicated Ollama nodes. What matters is that the chosen model handles tool calling reliably. This should be tested with your own tools before the project starts.

Timo Wevelsiep

Written by

Timo Wevelsiep

Co-Founder & CEO

Co-Founder of WZ-IT. Specialized in cloud infrastructure, open-source platforms and managed services for SMEs and enterprise clients worldwide.

LinkedIn

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

Arrange a callback

Callback

Arrange a callback

Leave your number and we will call back — at the latest on the next business day.

For a longer conversation you can book an appointment instead.

Companies worldwide trust WZ-IT

  • ml&s
  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • nextGYM
  • SweetConnect GmbH
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy AG
  • Negosh
  • ABCO Water Systems
1/3 - Topic Selection33%

What is your inquiry about?

First select the service area that best matches your project.