n8n-nodes-kepil
v0.1.2
Published
Ask Kepil whether an action is allowed before your workflow does it, and keep a journal that cannot be rewritten
Maintainers
Readme
n8n-nodes-kepil
Ask Kepil whether an action is allowed before your workflow performs it — and keep a journal that cannot be rewritten afterwards.
53% of organisations have had an AI agent exceed its intended permissions. 48% of agents in production run with no monitoring at all. — Cloud Security Alliance, State of AI Agent Security, 2026
An n8n workflow that sends messages, writes to a CRM and spends money will eventually do it to the wrong recipient or in the wrong amount. The only question then is on what grounds. This node answers it in advance: the decision is made against a mandate and written into a hash-chained journal.
Install
n8n → Settings → Community nodes → Install → n8n-nodes-kepil
You also need Kepil itself running somewhere your n8n can reach:
pip install kepil
python -m kepil.admin # http://localhost:7317In the panel, open Settings and set an access token (Latin letters and digits). While the token is empty the API stays off completely.
Credentials
| Field | Value |
|---|---|
| Base URL | http://localhost:7317 |
| Access Token | the token from the panel, or KEPIL_API_TOKEN |
Operations
Check Action — the one you will use. Give it an order ID, an action like
send:message and a target system. You get back allowed, needs_human and a
human-readable reason, and the question lands in the journal with the step
name you choose.
By default the node stops the workflow when the action is refused or needs a person. Turn Stop on Refusal off to branch on the decision yourself.
Create Order — start a piece of work and issue a mandate for it.
Get Order / Run Step — read the state, or let the agent take its next step through the gate.
Verify Journal — fail the workflow if the action log has been tampered with.
What this node deliberately cannot do
Confirm. If a workflow could approve an irreversible action, the human would drop out of the chain and the whole point would be lost. The node can learn that a person is needed; the confirmation card goes to the operator — in the Kepil panel or in Telegram — and nothing in n8n can press it.
Example
Webhook → Kepil (Check Action: send:message → whatsapp.local) → Send messageIf the mandate allows it, the message goes out and the decision is recorded. If the mandate does not, the workflow stops with the reason — and that refusal is recorded too.
License
MIT. Kepil itself is AGPL-3.0-or-later.
