The power of n8n & Zapier, supercharged with autonomous AI browser agents, multi-language cloud sandboxes, durable DAG execution, encrypted credential vaulting, and real-time multiplayer collaboration.
Core Pillarsย ย โขย ย Comparisonย ย โขย ย Credential Vaultย ย โขย ย Node Ecosystemย ย โขย ย Command Paletteย ย โขย ย Architectureย ย โขย ย Engineeringย ย โขย ย Quick Start
Design complex automations together on a real-time multiplayer canvas, execute isolated Python/JS scripts in secure cloud sandboxes, manage encrypted API keys in the Credential Vault, and observe step-by-step video replays.
Traditional automation tools like Zapier and Make excel at standard API webhooks, but break whenever a website lacks a public API or requires custom code and human-like interactions. On the other hand, classic browser automation scripts (Puppeteer, Playwright) break the moment a CSS selector changes and lack visual workflow management.
Nodus bridges this gap completely.
It combines:
- Visual DAG Flow Control & Data Routing (like n8n)
- Universal Triggers & Webhook Integrations (like Zapier)
- Isolated Multi-Language Cloud Sandboxes (E2B Python & JavaScript)
- Encrypted Zero-Trust Credential Vault (AES-256-GCM Secret Store)
- Autonomous AI-Driven Browser Infrastructure (Stagehand + Browserbase)
- Real-time Multiplayer Collaboration (Figma for Automations)
- Fault-Tolerant Background Execution (Trigger.dev v4)
Whether you are scraping dynamic SPAs behind logins, running data processing scripts in isolated sandboxes, automating enterprise SaaS workflows without APIs, or orchestrating multi-step AI pipelinesโNodus provides a single, unified visual platform.
mindmap
root((โก NODUS))
Visual DAG Engine (n8n)
Multi-branch Parallel Forks
Diamond Convergence (Merge/Join)
Loop & Iteration Control (forEach/while/until)
Winner-Takes-All Branch Pruning
Multi-Condition If/Else & Switch
Cloud Code & Sandbox Execution (E2B)
JavaScript & TypeScript Sandbox
Python 3 Data Processing
Real-Time Infinite Loop Detection
Custom Theme-Matched CodeMirror
Encrypted Credential Vault
AES-256-GCM Ciphertext Storage
Organization-Scoped Key-Value Secrets
Dynamic {{ secrets.KEY }} Token Chips
Pre-flight Missing Secret Validation
Automatic E2B Sandbox Env Injection
Autonomous AI Browser Agents
Natural Language Browser Actions
Schema-Driven AI Extraction
Dynamic Element Observation
Full Video Session Replays
Multiplayer Realtime Collaboration
Live Collaborative Canvas (Liveblocks)
Real-Time Cursors & Presence
Instant State Conflict Resolution
Multi-Tenant Org Isolation (Clerk)
| Capability | Zapier / Make | n8n | Raw Selenium / Playwright | โก Nodus |
|---|---|---|---|---|
| Visual Flow Canvas | โ | โ | โ | ๐ข Yes (React Flow) |
| Real-time Multiplayer Collaboration | โ | โ | โ | ๐ข Yes (Liveblocks Cursors & Sync) |
| Encrypted Credential Vault | โ | ๐ข Yes (AES-256-GCM Org Vault) | ||
| Multi-Language Cloud Sandboxes | โ | ๐ข Yes (E2B Isolated JS & Python) | ||
| Live Infinite Loop Analysis | โ | โ | โ | ๐ข Yes (Real-time AST Linter) |
| AI Autonomous Browser Actions | โ | โ | โ | ๐ข Yes (Stagehand v4 AI) |
| Handling Sites Without APIs | โ | โ | ๐ข Yes (Natural Language & Vision) | |
| Video Session Replays of Runs | โ | โ | โ | ๐ข Yes (Browserbase HLS Replays) |
| Multi-Branch DAG & Sibling Pruning | โ | ๐ข Yes (Topological DAG Engine) | ||
| Looping & Iteration Control | โ | ๐ข Yes (Loop Primitive with 4 Modes) | ||
| Workflow Portability (JSON Export/Import) | โ | โ | ๐ข Yes (Validated Zod Schema) | |
| Durable Long-Running Cloud Tasks | ๐ข Yes (Trigger.dev v4 Workers) |
Security is paramount in automated workflows. Nodus includes a built-in, organization-scoped Zero-Trust Credential Vault:
flowchart LR
User["User in UI"] -->|Input Secret Key & Value| VaultModal["Credential Vault Dialog"]
VaultModal -->|Server Action| Server["Server Cryptography Engine"]
Server -->|AES-256-GCM + Random 12-byte IV| DB[("Neon Postgres (Encrypted Row)")]
subgraph Execution_Time["At Workflow Execution Time"]
Runner["Trigger.dev Worker"] -->|Fetch & Decrypt in Memory| Decrypt["AES-256-GCM Decrypt"]
Decrypt -->|Interpolate {{ secrets.KEY }}| ActionExecutors["HTTP / Email / Resend"]
Decrypt -->|Inject env vars| Sandboxes["E2B Python & JS MicroVMs"]
end
- AES-256-GCM Symmetric Encryption: Every secret value is encrypted using standard
AES-256-GCMwith authenticated data tags and unique 12-byte initialization vectors (IV), preventing tampering and plaintext exposure in database records. - Organization-Scoped Multitenancy: Credentials strictly belong to the active Clerk organization (
orgId). Workspaces cannot access or query foreign credentials. - Universal
{{ secrets.KEY }}Token Insertion: Insert vault secrets into any input field, headers, or body payloads via the token insertion dropdown. Pills render with a branded Gold Lock icon badge. - Automatic Cloud Sandbox Injection: When executing code nodes, all organization secrets are automatically injected as environment variables in the E2B microVM (
process.env.KEYin JS /os.environ["KEY"]in Python). - Reactive UI Warning & Missing Secret Chips: If a secret is deleted from the vault, all canvas input fields referencing that secret immediately update to render a red warning chip:
[ โ ๏ธ Missing Secret ยท KEY ]. - Pre-Flight Validation Engine: Workflows validate secret existence before triggering tasks. If any required secret is missing, execution is halted with an informative alert before consuming compute credits.
Nodus features 20 production-ready nodes arranged in a clean, decoupled 3-Suite Modular Taxonomy:
features/workflows/system/suites/
โโโ flow/ # Graph topology, branching, loops, and control flow primitives
โโโ core/ # Compute sandboxes and network execution primitives
โโโ apps/ # Third-party integrations and browser agent tools
| Node | Type | Kind | Description | Key Outputs |
|---|---|---|---|---|
| Start | start |
trigger |
Workflow entrypoint for manual canvas runs, scheduled triggers, and webhooks. | timestamp |
| If / Else | if |
action |
Evaluates multi-condition rule sets (AND/OR, regex, numeric comparisons, null checks) and routes to True or False branch handles. |
result, branch, reason |
| Switch | switch |
action |
Multi-handle router directing execution across custom case branches or a default fallback branch. | routeIndex, matchedValue |
| Loop | loop |
action |
Iterates across lists or repeats execution in for_each, count, while, or until modes with dedicated loop-body and done output handles. |
item, index, iteration, isLast, totalItems |
| Merge / Join | merge |
action |
Synchronizes parallel branch convergence supporting first (winner-takes-all pass-through), combine (map results), and array (flatten) modes. |
mergedData, branchCount, winner |
| Wait / Delay | wait |
action |
Suspends execution durably for a specified duration in seconds before resuming. | waitedSeconds, resumedAt |
| Throw Error | throw-error |
action |
Intentionally halts workflow execution with a custom error message for dead-letter handling. | errorMessage, failedAt |
| Node | Type | Kind | Description | Key Outputs |
|---|---|---|---|---|
| JavaScript | js-code |
action |
Executes JavaScript / TypeScript in an isolated E2B cloud sandbox. Features live AST infinite loop detection, smart async IIFE wrapping, and token interpolation. | result, stdout, stderr |
| Python | python-code |
action |
Executes Python 3 in an isolated E2B cloud sandbox with math, data transformation, and scripting capabilities. | result, stdout, stderr |
| HTTP Request | http-request |
action |
Performs REST API requests (GET, POST, PUT, DELETE, PATCH) with custom headers, query params, and JSON payloads. |
status, data, headers |
| Category | Node | Type | Kind | Description | Key Outputs |
|---|---|---|---|---|---|
| Browserbase | Open URL | open-url |
action |
Navigates the cloud browser session to a destination URL. | url, pageTitle, status |
| Browserbase | Act | act |
action |
Executes natural-language actions ("Click the Sign In button", "Type %password% into input"). | success, message, currentUrl |
| Browserbase | Extract | extract |
action |
Extracts structured data from web pages using natural language and strict Zod JSON schemas. | extraction, itemCount |
| Browserbase | Observe | observe |
action |
Discovers interactive elements matching a description and returns candidate selectors. | matches, selector, description |
| Browserbase | Agent | agent |
action |
Autonomous multi-step agent that plans and executes complex end-to-end web tasks. | success, message, completedSteps |
| Stripe | Stripe Webhook | stripe-trigger |
trigger |
Listens for real-time Stripe billing events (payment_intent.succeeded, subscription.created). |
event, customerId, amount, currency |
| Google Forms | Google Forms Webhook | google-form-trigger |
trigger |
Receives live Google Forms submissions via webhook payloads. | responses, email, timestamp |
| Resend | Send Email | send-email |
action |
Delivers transactional HTML emails via Resend with vault API key resolution. | emailId, status |
| Slack | Slack Webhook | slack |
action |
Sends notification messages and structured payloads to Slack channels. | messageContent, success |
| Discord | Discord Webhook | discord |
action |
Sends rich formatted messages and alerts directly to Discord channels. | content, success |
To scale to thousands of integrations without client memory degradation, Nodus uses a Hierarchical Command Palette Drawer with on-demand chunk loading:
flowchart TD
Root["Right Sidebar: Palette"] -->|Click Flow or Core| Direct["Direct Suite View (Flow / Core)"]
Root -->|Click Apps| AppsList["Apps Category Directory"]
AppsList -->|Click App (e.g. Stripe, Slack)| Category["Category View (e.g. Stripe)"]
Direct --> TriggersDirect["Accordion: Triggers"]
Direct --> ActionsDirect["Accordion: Actions"]
Category --> TriggersApp["Accordion: Triggers"]
Category --> ActionsApp["Accordion: Actions"]
- Zero-Node Initial Memory: When browsing suites or app categories, 0 node manifests or executors are loaded into heap memory. Only pure metadata (IDs, brand icons, and count badges) is initially present.
- On-Demand Dynamic Imports: Clicking into an active suite or category triggers dynamic
import()loaders (loadPaletteNodeGroup) cached in a module map. - Code-Split Sidebar Inspector: The node property inspector is loaded dynamically with
next/dynamicand skeleton fallbacks, keeping token input libraries completely unloaded during canvas navigation. - Store Hook Decoupling: Canvas dimensions are read non-reactively via
useStoreApi().getState()during node placement, eliminating re-renders when the sidebar is resized.
flowchart TD
subgraph Client["Frontend Layer (Next.js 16 + React 19)"]
UI["Visual Canvas (React Flow)"]
Palette["Hierarchical Command Palette Drawer"]
Inspector["Right Sidebar Inspector & CodeMirror 6"]
LB_Client["Liveblocks Real-Time Client"]
Console["Live Run Console & Video Replay"]
end
subgraph Auth_Data["Auth & Persistence Layer"]
Clerk["Clerk Auth & Billing (RBAC & Plans)"]
Postgres[("Neon Serverless Postgres\n(Drizzle ORM)")]
Vault[("AES-256-GCM Vault Secrets")]
LB_Cloud["Liveblocks Cloud (Presence & Room Storage)"]
end
subgraph Execution["Durable Execution Engine (Trigger.dev v4)"]
Runner["runWorkflowTask (Topological DAG Runner)"]
MergeSync["Merge Synchronizer & Branch Pruner"]
Executors["Node Executors Registry"]
end
subgraph Cloud_Sandboxes["E2B Code Sandboxes"]
E2B_JS["E2B JavaScript / TypeScript Sandbox"]
E2B_PY["E2B Python 3 Sandbox"]
end
subgraph Browser_Infra["Autonomous Cloud Browser Layer"]
BB["Browserbase Cloud Sessions"]
Stagehand["Stagehand v4 AI Engine"]
end
UI <-->|Real-time Sync| LB_Client
LB_Client <--> LB_Cloud
UI -->|Mutations & Auth| Clerk
UI -->|Persist Graph & Secrets| Postgres
Postgres -.-> Vault
UI -->|Trigger Run| Runner
Runner -->|Pre-flight Secret Decryption| Vault
Runner --> MergeSync
Runner --> Executors
Executors -->|Code Execution + Injected Secrets| E2B_JS
Executors -->|Code Execution + Injected Secrets| E2B_PY
Executors -->|Browser Automation| Stagehand
Stagehand -->|Managed Browser & Recording| BB
Runner -.->|Live SSE Step Events| Console
BB -.->|Proxied HLS Video Replay| Console
To prevent live Trigger.dev streaming events from causing full graph re-render cascades:
WorkflowRunsProviderexposes a slice-based external store with referential snapshot caching.StepNodeandWorkflowEdgesubscribe exclusively to their own computed status (useNodeRunStatusanduseEdgeRunStatus).- Result: Canvas re-renders during live runs are reduced by over 90%, ensuring a locked 60 FPS animation frame rate even during heavy parallel streaming.
Rather than executing arbitrary code on worker instances, scripts execute inside isolated E2B microVMs:
- Smart Wrapper: Automatically wraps top-level
returnstatements in async IIFEs while preserving root-level ESimportstatements. - Strict Teardown: Sandbox destruction is guaranteed via
finally { await sandbox.kill() }, preventing leaked cloud containers. - User-Friendly Error Formatting: Replaces raw internal timeout flags with clear error explanations pointing to potential infinite loops.
An integrated client-side static analyzer inspects code as the user types in CodeMirror:
- Detects unbounded
while (true)/while True:,for (;;), and invariant loop variables. - Renders non-intrusive amber warning banners with line numbers before execution occurs.
React Flow triggers coordinate changes on every frame (60โ120fps). To eliminate costly graph re-traversals during dragging:
- We compute a deterministic structural fingerprint (
nodeId#nodesDigest#edgesDigest). - BFS traversal, upstream token generation, and switch edge pruning are completely decoupled from
(x, y)coordinates. - Memoized store selectors with custom equality checking (
equalityFn) prevent the Inspector and sidebar from re-rendering during node movement.
When workflows split into parallel execution paths (e.g. attempting 3 fallback login methods), the MergeSynchronizer dynamically tracks sibling branch lifecycles:
- As soon as the first winning branch finishes, all sibling branches in the queue are cancelled in real time.
- Prevents wasteful compute and eliminates race conditions.
- Framework: Next.js 16 (App Router, React 19 Server Actions, Turbopack)
- Visual Canvas: React Flow / @xyflow/react
- Code Editor: CodeMirror 6 (
@uiw/react-codemirror+@codemirror/lang-javascript+@codemirror/lang-python) - Cloud Code Sandboxes: E2B (
@e2b/code-interpreter) - Multiplayer State: Liveblocks (Real-time CRDTs, Cursors, Presence)
- Durable Task Engine: Trigger.dev v4
- AI Browser Framework: Stagehand v4
- Autonomous Browser Infrastructure: Browserbase (HLS Video Replays, Cloud Chromium)
- AI Model Provider: Google Gemini (Powers Stagehand Vision & Natural Language Agents)
- Database & ORM: Neon Serverless Postgres + Drizzle ORM
- Authentication & Monetization: Clerk (Organizations, RBAC, Billing & Pricing Tables)
- Styling: Tailwind CSS + shadcn/ui
- Email Service: Resend
- Telemetry & Monitoring: Sentry
- Node.js (v20+) and npm
- Accounts for: Clerk, Neon, Trigger.dev, E2B, Liveblocks, Browserbase, Google AI Studio, and Resend.
git clone https://github.com/your-username/nodus.git
cd nodus
npm installcp .env.example .env.localEnsure all keys are provided in .env.local:
# App Public URL (Used for webhook destination URLs & callbacks)
NEXT_PUBLIC_APP_URL=http://localhost:3000
# Clerk Authentication & Organization Billing
NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY=pk_test_...
CLERK_SECRET_KEY=sk_test_...
NEXT_PUBLIC_CLERK_SIGN_IN_URL=/sign-in
NEXT_PUBLIC_CLERK_SIGN_UP_URL=/sign-up
NEXT_PUBLIC_CLERK_SIGN_IN_FALLBACK_REDIRECT_URL=/workflows
NEXT_PUBLIC_CLERK_SIGN_UP_FALLBACK_REDIRECT_URL=/workflows
# Neon Serverless Postgres Database
DATABASE_URL=postgres://user:password@ep-xyz-pooler.us-east-2.aws.neon.tech/neondb?sslmode=require
DATABASE_URL_UNPOOLED=postgres://user:password@ep-xyz.us-east-2.aws.neon.tech/neondb?sslmode=require
# Trigger.dev Background Execution Task Runner
TRIGGER_SECRET_KEY=tr_dev_...
# Organization Credential Vault (AES-256-GCM 32-byte master key - generate via `openssl rand -hex 32`)
VAULT_MASTER_KEY=0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
# E2B Cloud Code Sandbox (JavaScript & Python)
E2B_API_KEY=e2b_...
# Liveblocks Real-Time Multiplayer Collaboration
NEXT_PUBLIC_LIVEBLOCKS_PUBLIC_KEY=pk_liveblocks_...
LIVEBLOCKS_SECRET_KEY=sk_liveblocks_...
# Browserbase Cloud Browsers & Observability
BROWSERBASE_API_KEY=bb_...
BROWSERBASE_PROJECT_ID=...
# Gemini AI (Powers Stagehand v4 Autonomous Browser Agents)
GEMINI_API_KEY=AIzaSy...
# Resend Transactional Email
RESEND_API_KEY=re_...
# Sentry Monitoring & Error Reporting (Optional)
NEXT_PUBLIC_SENTRY_DSN=https://...
SENTRY_DSN=https://...
SENTRY_AUTH_TOKEN=...
SENTRY_ORG=...
SENTRY_PROJECT=...npm run db:pushnpm run trigger:devnpm run devNavigate to http://localhost:3000 and build your first workflow.
- Core Visual Canvas with React Flow & Liveblocks
- Stagehand v4 AI Browser Actions & Autonomous Agent
- Browserbase Video Session Replays
- Control Flow Suite (
If/Else,Switch,Merge/Join,Wait,Throw Error) - Loop & Batch Iteration Nodes (
forEach,count,while,until) - Multi-Language Cloud Code Sandboxes (
JavaScript,Pythonvia E2B) - Real-Time Static Infinite Loop Detection & CodeMirror 6 Editor
- Hierarchical Command Palette Drawer with Zero-Node Memory Footprint
- Universal JSON Workflow Import / Export Engine
- Credential Vault (AES-256-GCM Encrypted Secret Manager)
- Performance-Optimized Granular Execution Store (
useSyncExternalStore) - Multi-Agent Orchestration Teams (Supervisor + Specialized Subagents)
- Pre-built Connector Marketplace (Notion, GitHub, PostgreSQL, Linear)
# Run all unit and integration tests (188 tests passing across 52 suites)
npm test
# Run system parity integrity verification test
npx tsx --test features/workflows/system/parity.test.ts
# Run TypeScript typecheck
npm run typecheck
# Run Next.js production build
npm run buildThis project is licensed under the MIT License.
