JA_Available
// CASE STUDY · 2025–26

AutoFlow

An open-source automation platform: build workflows as node graphs on a visual canvas and run them on a durable execution engine — triggers, HTTP calls, AI models and chat deliveries, chained together.

Role
Sole developer · final-year thesis, Ho Technical University
Timeline
Oct 2025 — Sep 2026
Stack
Next.js 15 · tRPC · Inngest · Prisma
Workflow editorOpen the live demo
// Pre-beta · live demo
autoflow20.vercel.app/workflows
AutoFlow's workflow editor: a Webhook Trigger, Code and Condition workflow on the canvas, with the Add node panel open listing 15 triggers.

Origin — Started from a Code With Antonio course project and extended well beyond it: multi-tenant RBAC and audit logging, the encrypted credential vault, the AI provider registry, the pgvector knowledge base and 25 decision records.

01

The problem

Automation tools make you choose: no-code builders that stall on anything real, or self-hosted engines that come with a DevOps job attached. AutoFlow aims for the power of n8n without that burden — so durable execution, multi-tenant security and AI cost control have to be built in, not bolted on.

n8n's power without the DevOps burden.

— The product's central promise, ADR-0002

Results

From the project's progress log, Sep 2026
696Tests passing across 75 files, zero skipped
23Node types in the registry — triggers, AI, HTTP, approvals
25Architecture decision records, written before the code
02

The build

A Next.js 15 app with a tRPC API and a React Flow canvas. Workflows compile to a plan that runs on Inngest: every node executes inside a durable step, so a crashed run resumes without repeating side effects. Credentials live in an envelope-encrypted vault, and every read and write is scoped to the organisation.

saveGraphrunqueriesstep.rundecrypt onceCANVASReact Flow · autosaveTRPC APINext.js 15 · org-scopedINNGEST ENGINEdurable step per nodePOSTGRESQLPrisma · pgvectorEXECUTORSAI · HTTP · Slack · 23 typesCREDENTIAL VAULTAES-256-GCM envelope
// Decision 01

Inngest as the durable runtime

Each node runs inside step.run, so completed nodes are memoised and a resumed run never repeats a side effect. Cron, concurrency keys and cancellation come with it — no queue, workers or scheduler to operate.

// Decision 02

Expressions are parsed, not evaluated

Template expressions are parsed into a path and resolved against the run context. No eval, no new Function, no vm on the request or execution path — remote code execution is closed by construction, not by a sandbox.

// Decision 03

No plaintext read path for credentials

Each credential gets its own AES-256-GCM data key, wrapped by a master key that never touches the database. No endpoint returns decrypted material — not to the owner, not to an admin, not for a test button.

03

What I'd do differently

Docs drift from code. In August an audit found the progress log claiming things the code didn't do — and missing things it did. I rewrote it so every claim points at a file, and it's now updated in the same pull request as the change.

Writing decision records before code. Twenty-five ADRs in, the hardest calls — sandboxing, SSRF, credential handling — are each explained in one place.

// NEXT PROJECTCroeFinTech · React Native · Express 5 · PostgreSQL 16 · Redis