n8n 2.36 adds agent sandboxes, MCP folders
Archive item — written before sources were shown.
n8n's 2.36.0 release adds agent sandboxes, MCP server folder/move support, a Confluence OAuth2 credential, and Discord moderation actions across 100+ fixes.
n8n shipped 2.36.0, a release the project describes as its largest in weeks, bundling more than 100 fixes and features. The headline additions are agent sandboxes, which isolate what an AI agent node can touch while it runs, and folder and move support for MCP servers, letting teams organize a growing list of connected MCP tools instead of managing them as one flat list. The release also adds a Confluence OAuth2 credential, Discord moderation actions, catch-up coalescing for Schedule Trigger nodes, and workflow-review system improvements.
What it means for you
If you’re running n8n workflows that hand off to AI agents with tool access, the sandboxing addition is the one to test first: it’s aimed directly at the failure mode where an agent node does more than the workflow intended. Teams with more than a handful of MCP servers connected will likely appreciate the folder support more than any single feature in this release, since MCP tool sprawl inside a workflow builder has been a real organizational problem as the MCP ecosystem keeps expanding. Update and test agent-node workflows in a staging environment before rolling the sandbox change to production, since isolation changes can alter what a previously-working agent node is allowed to do. It’s part of a broader push toward guardrails for autonomous agents, alongside AWS’s newly-GA AgentCore Payments released the same week.
- 01n8n Releases: n8n@2.36.0github.com · primary, release notes
