Build1 publisherNot yet confirmed elsewhere2 min readPublished
n8n 2.43.0 blocks publishing of workflows with unconnected required inputs
n8n 2.43.0, shipped October 6, refuses to publish any workflow whose required node inputs are unconnected, according to a dev.to review of the changelog. The check covers wiring only, so wrong credentials and bad prompts still need their own tests before an agent goes live.
The Engineer · Build desk

What happened
- Before 2.43.0, a workflow with a dangling required input, such as an Agent node with its model connected but no chat trigger, could be published and then fail silently in production.
- Organisation policies that restrict nodes or credentials now also apply when workflows are imported or executed through the n8n CLI, under change #39714.
- Error workflows, the ones that run when another workflow fails, now fall under the same MCP availability rules as other workflows (#39885).
- Agent messages that some paths delivered more than once, producing duplicate Slack or webhook replies, are now deduplicated (#39794).
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Staging pipelines now have to import under the same policy set as production, or a workflow that passes staging will be refused at the production CLI import.
- exposure Teams that activate workflows from CI cannot count on the unconnected-input block as a gate until they confirm it runs on the API path as well as in the editor.
- capability Failure handlers can be tested under the same MCP tooling assumptions as the workflows they cover, so an error path is less likely to meet a missing tool during an incident.
On an Agent node, "required inputs" covers more than the trigger. According to the dev.to review, it includes the tool connections, memory and model sub-nodes the Agent node depends on [4]. The reviewer argues that agents, which carry more connections than any other kind of workflow, are the likeliest to go live with some of them missing [4].
For a self-hosted team, where the check runs matters as much as what it checks. In the review's account, the editor is what refuses to publish until required inputs are connected [2]. For pipelines that activate workflows through the API or CLI, the reviewer writes that the block pairs with the new CLI policy checks, and that "the same guardrail logic is being applied everywhere publishing happens" [14]. The CLI entry the review cites names import and execute commands [6]. The review does not say whether activating a workflow through the API runs the structural check.
The CLI policy change is the best engineering in the release. Before it, if a policy barred a risky node in the editor, importing the same workflow through the CLI got around it [7]. A rule the editor enforced bound only the people using the editor. The change is filed under core [6]. The review's verdict on the bypass: "That's a real hole, and it's now closed" [15].
SQLite is the default for small Docker and npm installs, according to the review [10]. Agent session pagination on SQLite was wrong until #39802, so sessions could show missing or duplicated messages [10]. Anyone who judged an agent from its session history on such an install before 2.43.0 was reading a list that could be wrong [10].
The remaining agent changes are housekeeping. Slack Agent channels now connect through n8n's managed MCP setup, the path the review says n8n wants users on [11]. The Agent Builder now handles removed fields correctly when it patches an agent config [12].
The review's author sums up the cycle in one line: "n8n is spending this release cycle on making agents fail less often, not do more things" [13].
What to watch
- Whether n8n's own release notes or docs confirm that activating a workflow through the public API or CLI runs the unconnected-required-input check.
- Whether workflows already published with unconnected required inputs are flagged, deactivated or left running after an upgrade to 2.43.0.
- Whether policy checks extend to CLI commands beyond import and execute in a later release.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
n8n shipped version 2.43.0 on October 6, 2026.
- [2]
n8n 2.43.0 blocks publishing a workflow that has unconnected required node inputs (commit 5e28ff8, #37265); the editor refuses to publish until required inputs are connected.
- [3]
Before 2.43.0, a workflow with a dangling required input could be published (activated), for example an Agent node with the model connected but the chat trigger never wired; it would run in production and fail silently or fire half-built automations against real APIs.
- [4]
For agent workflows, required inputs include the tool connections, memory and model sub-nodes the Agent node depends on; the post argues agents are the workflows most likely to be published half-wired because they have the most connections.
- [5]
The publishing block only catches structurally unconnected required inputs; it will not catch a connected-but-misconfigured node, a wrong credential, or a prompt that hallucinates.
- [6]
core: Apply policy checks to CLI import and execute commands (#39714). Organisations that define policies, such as restrictions on node usage or credentials, now get those policies enforced when workflows are imported or executed through the n8n CLI.
- [7]
Before #39714, a policy that blocked a risky node in the editor could be bypassed by importing the same workflow from the command line.
- [8]
core: Apply MCP availability rules to error workflow settings (#39885). The MCP availability rules now apply to error workflows, the workflows that run when another workflow fails; the post says failure handlers get the same tooling guarantees as main workflows.
- [9]
core: Deduplicate agent message deliveries (#39794). Agent messages were being delivered more than once in some paths, meaning duplicate replies when an agent talks to Slack or a webhook.
- [10]
core: Correct Agent session pagination on SQLite (#39802). SQLite is the default for small Docker/npm installs; agent session history pagination was wrong, meaning sessions could show missing or duplicated messages.
- [11]
core: Connect Slack Agent channels through managed setup in MCP (#39776); the post says managed MCP setup is the path n8n wants users on for agent-to-channel integrations.
- [12]
core: Apply removed fields when the Agent Builder patches agent config (#40122); the AI-assisted agent builder now handles deprecated fields correctly when patching agent configs.
- [13]
n8n is spending this release cycle on making agents fail less often, not do more things.
- [14]
For automated publishing (CI/CD pipelines that activate workflows via the API or CLI), the post says the publishing block pairs with the new CLI policy checks: "the same guardrail logic is being applied everywhere publishing happens."
- [15]
That's a real hole, and it's now closed.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.ton8n 2.43.0 Is a Guardrails Release: No More Publishing Broken Workflows
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.