ToolJet
Also known as: ToolJet, tooljet.com, tooljet.ai, ToolJet Agent Builder, ToolJet Workflows, ToolJet MCP
Open source internal tools platform whose self hosted edition adds an agent builder: an AI agent node that picks its own tools inside visual workflows, woken by webhooks, schedules or app events, with SSO, RBAC and air gapped deployment.
ToolJet is a low code platform for internal tools, customer portals and back office applications, built around a visual app builder, a built in PostgreSQL database, a workflow engine and more than 100 data source connectors. Its agent layer sits inside the workflow canvas. An AI agent node takes a system prompt, a user prompt and an output schema, connects to a model the builder chooses, and is handed any workflow node as a tool: a database query, a REST call to Slack, Gmail or GitHub, a JavaScript step or a ToolJet Database table. The agent decides which tools to call and in what order, within step, retry and timeout limits the builder sets.
Agents start the way workflows start. A ToolJet app can invoke one on a button click or form submission, an external system can call a typed webhook, including an asynchronous endpoint for long runs, and a scheduler fires on an interval or a cron expression in a chosen timezone. Workflows add branching, loops and child workflows around the agent, so an agent step can sit inside a longer process with deterministic steps on either side.
The agent builder ships only on self hosted ToolJet, which runs on Docker, Kubernetes, a customer VPC or on premises, with an air gapped option on the enterprise license. ToolJet Cloud carries the app builder and its AI assisted building features but not workflows or agents. Governance follows the platform: custom user groups, SSO through SAML, OIDC or LDAP, audit logs, and on enterprise plans SCIM, row level security and page, component and query level access rules.
ToolJet also publishes an MCP server that lets a coding agent such as Claude Code, Codex or Cursor build and modify ToolJet apps, manage page and query permissions and administer users, authenticated with a personal access token and recorded in the platform audit log. The documented limits sit on the agent side: no native approval step for agent tool calls, no memory layer across runs, and no evaluation harness for agent behavior.
Vendor details
Canonical URL
https://tooljet.com
Category
Agent builder
Subcategory
Agent nodes inside an internal tools workflow engine
Funding status
Private and venture backed (ToolJet Solutions Inc, San Francisco). The pricing page reports 37,602 GitHub stars and 625+ contributors on the open source repository.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
More than 100 data sources and SaaS connectors, including PostgreSQL, MySQL, MongoDB, REST and GraphQL APIs, Slack, Gmail, GitHub, Stripe, Weaviate and Hugging Face. Any workflow node can be handed to an agent as a tool. Model providers for the agent node include OpenAI, Anthropic, Gemini and Mistral. A REST API with personal access tokens, a GitSync API and an MCP server for coding agents extend the platform.
In practice
An operations team adds an agent node to a webhook triggered workflow so that inbound refund requests are checked against order data and routed to Stripe or a human queue.
An IT group runs the self hosted edition inside its own Kubernetes cluster so that agents, workflows and the apps that call them never leave its network.
A developer uses Claude Code with the ToolJet MCP server to generate an admin app against existing tables, then restricts its pages and queries to named user groups.
Sources & related URLs
Related / legacy domains
Agentic Index coverage score
10.5 / 14 capabilities · 75%
| Integrations & Tool Calling | Full |
|---|---|
|
Any workflow node can be attached to the agent node as a tool, so agents take authenticated action in outside systems. Tools include datasource queries against PostgreSQL, MySQL and MongoDB, REST calls to Slack, GitHub, Gmail and Twilio, JavaScript steps and ToolJet Database tables, over a catalog of 100+ connectors whose credentials stay server side. Documented examples send Slack messages, create incidents and draft or forward Gmail. Sourcedocs.tooljet.com/docs/workflows/nodes/agentread 2026-10-02 |
|
| Workflow Orchestration | Full |
|
A visual node based workflow engine runs multi step processes with logic nodes (JavaScript, If/Else, Loop), datasource and REST nodes, a workflow node for child workflow orchestration, and an agent node that plans its own tool calls within max steps, retries and timeout. The agent builder page describes long running processes with retries and external waits, run in parallel across workflows. Sourcetooljet.com/pricingread 2026-10-02 |
|
| Knowledge Grounding & RAG | Partial |
|
Context is assembled per run. The agent reads business data through the tools it is handed, such as database queries and API calls, and the agent builder page describes context aware agents fed by connected data. No maintained retrieval structure for agents, such as an index, embeddings layer or knowledge base, is documented. A Weaviate connector exists in the catalog, but the store is the customer's own and no retrieval feature is built on it. Sourcetooljet.com/ai-agent-builderread 2026-10-02 |
|
| Human Oversight & Guardrails | Partial |
|
Builders choose exactly which nodes an agent may call and cap it with max steps, max retries and a timeout, and workflow branching can route outcomes. Those are constraints the customer controls rather than an approval step. The agent builder page claims workflows that manage approvals and human in the loop steps, but the workflow node list documents no approval or human task node that pauses an agent action before it commits, which keeps this at Partial. ActionRail, a separate ToolJet open source project in public beta, holds agent tool calls for a human, but it is not part of the agent builder. Sourcedocs.tooljet.com/docs/workflows/nodes/agentread 2026-10-02 |
|
| Security, Identity & Governance | Full |
|
ToolJet documents both access control and compliance. Access runs through RBAC with predefined and custom user groups and SSO through Google, GitHub, OIDC, LDAP and SAML, and Enterprise adds SCIM provisioning, group sync, row level security and page, component and query level access rules. The compliance docs state ToolJet undergoes regular SOC 2 Type II audits and point to a trust center at trust.tooljet.com. ISO 27001 is worded as following the standard, which is alignment, not certification. Audit logs are kept 14 days on Team and unlimited on Enterprise. Sourcedocs.tooljet.com/docs/security/complianceread 2026-10-02 |
|
| Observability & Auditability | Full |
|
Workflow run logs with node level visibility show each tool node the agent invoked and the parameters it passed. The agent builder page offers click to inspect debugging of agent runs, platform audit logs record acting user, action and timestamp, and self hosted instances export OpenTelemetry. Reasoning traces inside the agent node are not described. Sourcetooljet.com/pricingread 2026-10-02 |
|
| Memory & State Persistence | Partial |
|
State persists inside a run. The agent builder page says agents retain context and continue reasoning across extended processes with waits and retries, and only the agent node's final result passes to later nodes. No memory layer with a stated scope and lifetime across runs is documented. ToolJet Database tables the agent can query are the application's data model, not a memory layer. Sourcedocs.tooljet.com/docs/workflows/nodes/agentread 2026-10-02 |
|
| Deployment & Data Residency | Full |
|
The customer chooses the environment. Self hosted ToolJet runs on Docker, Kubernetes, the customer's VPC or on premises, with multi instance and air gapped deployment on the Enterprise license, and the agent builder is available only on self hosted. ToolJet Cloud runs on AWS EKS. Sourcetooljet.com/pricingread 2026-10-02 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Packaged assets exist for apps, not agents. App templates for lead management, KPI dashboards, inventory, leave management and applicant tracking can be adopted, but none is an agent or an agentic workflow. The agent builder page and agent node docs present scheduling, Slack task, purchase order, campaign and refund agents as worked examples the customer assembles, not installable prebuilt agents. Sourcetooljet.com/ai-agent-builderread 2026-10-02 |
|
| Triggers & Channel Coverage | Full |
|
Agents wake autonomously. A webhook trigger with typed parameters lets external systems invoke a workflow and its agent, an asynchronous webhook endpoint serves long runs, and a scheduler fires on an interval or a cron expression in a chosen timezone on paid self hosted tiers. App events such as button clicks, form submissions or data changes also start agents. Sourcetooljet.com/ai-agent-builderread 2026-10-02 |
|
| Model Flexibility & Routing | Full |
|
The customer chooses the model. Each agent node is linked to an AI model datasource the builder configures, with OpenAI, Anthropic, Gemini and Mistral documented and 10+ vendors claimed, and the page says different models can serve different use cases. Temperature, max tokens and top P are set per node. Enterprise adds custom AI model options, an on premises AI gateway and bring your own keys for ToolJet AI. Sourcedocs.tooljet.com/docs/workflows/nodes/agentread 2026-10-02 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
The ToolJet API reference documents an API for the platform itself, with personal access tokens, user management APIs and a GitSync API, and webhook endpoints invoke workflows. ToolJet also publishes an MCP server authenticated by a workspace scoped personal access token, with a supported tools page. Its tools create and modify apps, set page and query permissions and manage users, which are the platform's own core objects. Sourcedocs.tooljet.com/docs/build-with-ai/mcp/overviewread 2026-10-02 |
|
| Testing, Debugging & Optimization | Partial |
|
ToolJet offers debugging rather than testing. The agent builder page offers visual click to inspect debugging of agent runs, and the pricing table lists run logs and AI auto fix for apps. No evaluation harness, scored test cases or quality gate for agent behavior is documented. The automation testing section of the docs covers the development lifecycle of apps. Sourcetooljet.com/ai-agent-builderread 2026-10-02 |
|
| Browser & Computer Use | Unable to verify |
|
No browser, desktop or remote computer control by the agent is documented. Agent tools are datasource queries, REST calls, JavaScript and ToolJet Database. The MCP docs note that a customer's own coding agent with browser access can open an app it built, but that is the customer's agent, not ToolJet's. Sourcedocs.tooljet.com/docs/workflows/nodes/agentread 2026-10-02 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
$199/builder/mo yearly ($249 monthly), self hosted · free community edition
builder seats, with end user caps per tier and a monthly AI credit allowance per builder; add on AI credits
Included quota
Self hosted Free: 2 builders, 50 end users, 10 apps, 2 agents, 100 AI credits a month. Self hosted Team: per builder seats, 100 end users, unlimited apps and agents, 3,000 AI credits per builder a month, 14 day audit logs.
What is public
Both the Cloud and self hosted plan tables, per builder prices, end user and app limits, AI credit allowances, the add on credit price and full feature comparisons are published. Enterprise is custom.
Billing mechanics
Per builder subscription, monthly or yearly with a 20 percent yearly saving, plus a shared workspace AI credit pool. Self hosted Team is bought as a license through a checkout on the pricing page; Enterprise is quoted.
Cost watchouts
The agent builder is self hosted only, so the buyer also carries infrastructure and operations cost. End user caps (50 on Free, 100 on Team) push larger internal audiences to Enterprise for unlimited end users. SCIM, row level security, granular access rules, BYOK and air gapped deployment are Enterprise only. Model calls made by the agent node run on the customer's own model provider account.
Variable cost rationale
Seat prices are fixed and published and AI credits are capped with a published add on rate, but self hosting moves infrastructure cost to the buyer and model usage by agents runs on the buyer's own provider bill.
Additional watchouts
Read the Cloud prices as app builder prices only; agents need the self hosted edition.
Overage / add-ons
AI credits reset monthly and do not roll over; add on credits cost $1 per 100 and last a year. Exceeding end user caps requires a higher tier.
Sales call required
Mixed (some tiers require a call)
Free / trial
Free self hosted community edition with 2 agents and 50 end users; free Cloud plan without agents; 14 day trial offered
Lowest paid plan
Self hosted Team at $199 per builder per month billed yearly ($249 monthly); Cloud Basic at $23 per builder per month is cheaper but excludes agents
Commercial notes
Self serve checkout for the Team license; Enterprise through a sales call. A free community edition supports open source self hosting.
Key ambiguities
The cheapest paid plan on the page (Cloud Basic at $23) does not include workflows or agents, so the paid entry price for the agent builder is the self hosted Team license. Whether agent node model calls ever draw on ToolJet AI credits, rather than the customer's own model datasource, is not stated.
Missing data
Enterprise floor, and whether agent runs consume AI credits.
Related vendors
- Lindy — AI teammate that lives in Slack, answers from your tools and…
- Activepieces — Open source, MIT licensed automation platform where every one of 700…
- AgentX — No code platform to build, evaluate, and deploy multi agent…
- AI Library — No-code platform for building and running AI agents, with a…
- Aigensei — Enterprise agentic workflow platform that runs business processes…
- Airia — Enterprise platform that unifies agent orchestration, security, and…