FM
FlowMarket
MarketplaceRequest custom workSell
FM
FlowMarket

n8n automation services, setup and templates.

Navigation

  • Marketplace
  • Request custom work
  • Sell
  • Where to sell n8n workflows
  • Pricing & fees
  • How it works
  • Sell on FlowMarket
  • Setup guide
  • Maintenance guide
  • Tools

Terms

  • Terms of Use
  • Terms of Sale
  • Seller Terms

Legal

  • Legal Notice
  • Liability

Privacy

  • Privacy Policy
  • Cookies

Community

  • Guides
  • Support
  • FlowMarket LinkedIn
  • FlowMarket Discord

    Tickets, help, and community chat.

© 2026 FlowMarket — All rights reserved.

n8n marketplace · automation servicesStartup Fame

Back to blogAI Agent Marketplaces: A 2026 Buyer's Guide

3 August 2026 · 15 min read

AI Agent Marketplaces: A 2026 Buyer's Guide to the New App Stores

For twenty years, buying business software meant browsing an app store, reading a few reviews, and clicking install. In 2026 that pattern has arrived for autonomous software — but with a twist that changes everything about how you should shop. The agents in these new marketplaces do not just display data or nudge a spreadsheet; they log into your systems, make decisions, and take actions on your behalf. Salesforce, Microsoft, Google, Oracle and Anthropic have all opened agent marketplaces in the last eighteen months, and the money is following. This guide explains who runs these stores, how they charge, and — most importantly — how to buy from them without inheriting a governance problem you did not sign up for.

Why agent marketplaces exploded in 2026

The surge is not hype; it is arithmetic. The AI agents market reached roughly 10.9 to 12 billion dollars in 2026, growing at a 44 to 46 percent compound annual rate from about 7.6 billion in 2025, according to market trackers, and long-range forecasts put it above 200 billion dollars by 2035. Gartner expects 40 percent of enterprise applications to embed task-specific AI agents by the end of 2026, up from under 5 percent a year earlier, and projects that by 2028 the average Fortune 500 company will run more than 150,000 agents — against fewer than 15 in 2025. When demand curves bend that sharply, distribution becomes the prize, and every major platform wants to be the store where those agents are found, bought and billed.

The traction is already visible. Salesforce's AgentExchange, which the company relaunched in spring 2026, sits on top of an Agentforce business that Salesforce has described in the region of 800 million dollars in annual recurring revenue and roughly 18,500 customers, with more than 200 launch partners including Google Cloud, Docusign and Box. Microsoft's marketplace has cleared 11,000 prepackaged models and more than 4,000 AI apps and agents. Google folded its Agentspace discovery layer into Gemini Enterprise, complete with an AI-powered "agent finder" that recommends an agent for a given task. Oracle added an AI Agent Marketplace inside Fusion Cloud Applications, and Anthropic opened a Claude Marketplace in March 2026 with Snowflake, GitLab and Harvey AI among its first partners. The land grab is on, and buyers are the ones being courted.

The shift in one line: a marketplace listing used to distribute code you would run. An agent listing distributes an actor that will run inside your business — so the buying decision is now a permissions decision, not just a features decision.

The five kinds of marketplace you will actually encounter

"AI agent marketplace" is a single label stretched across at least five different distribution models, and knowing which one you are standing in tells you what questions to ask. They differ in who does the vetting, how deeply the agent is embedded in your stack, and how much you can inspect before you commit.

  • Suite-native agent stores. AgentExchange, Microsoft Marketplace, Oracle's Fusion marketplace. The agent lives inside a platform you already pay for, inherits its identity and permission model, and is billed through it.
  • Model-vendor marketplaces. Anthropic's Claude Marketplace and comparable offerings from foundation-model providers, where agents and connectors are distributed close to the model that powers them.
  • Discovery layers. Google's Agentspace-style finders that sit across many sources and recommend an agent for a task, blurring the line between a catalog and a search engine.
  • Automation-platform template libraries. The pre-built scenario and workflow galleries inside Zapier, Make and n8n. These are marketplaces for automations you can read and adapt, not opaque agents.
  • Independent and community catalogs. Developer hubs and specialist stores where smaller builders publish agents, skills and connectors that plug into the platforms above.

The practical consequence is that a suite-native agent and a Make template are not the same purchase, even if both promise to "automate your invoicing." One is a black box that acts with delegated authority; the other is a recipe you can open, understand and change. Neither is automatically better — but you evaluate them very differently, and the biggest buyer mistake is treating them as interchangeable.

How the money really works

Marketplace pricing is rarely a single number, and the sticker price is usually the smallest part of it. There are commonly three meters running at once: the platform's cut, the vendor's price, and the consumption the agent burns while it does its job. Ignore any of the three and your budget will drift.

The platform's cut is the most predictable. On Salesforce's marketplace, paid listings pay roughly 15 percent of net subscription revenue to Salesforce under the standard partner program (higher for embedded OEM arrangements), free listings pay nothing, and marketplace checkout adds a small per-transaction card fee on top. Those numbers are worth knowing because they shape vendor pricing: a builder handing 15 to 25 percent to the platform will price the agent to recover it. The vendor's own price is where the models diverge — flat monthly subscriptions, per-seat pricing, per-action or per-operation metering, and increasingly per-outcome or per-resolution billing where you pay only when the agent completes a defined result.

Cost layerWhat it coversBuyer question to ask
Platform revenue shareThe marketplace operator's cut of the saleIs it baked into my price or added at checkout?
Vendor licenceSubscription, per-seat, per-action or per-outcomeWhat exactly triggers a charge, and is it capped?
Model and token consumptionThe LLM calls the agent makes on each runWho pays for tokens — me, on my key, or the vendor?
Platform operations/creditsWorkflow runs, connector calls, storageDoes a chatty agent quietly inflate my platform bill?
Integration and oversightSetup, monitoring, human review timeWhat internal cost does running this safely add?

The trap is the third and fourth layers. An agent priced at a comfortable monthly figure can still generate a large model bill if it reasons verbosely on every run, and a "cheap" agent that fires hundreds of platform operations can push you into a higher consumption tier. Before you commit, model a realistic month of volume across all the meters, not just the headline subscription. Our breakdown of how to test an AI agent before you buy walks through building that kind of trial so the true run-rate surfaces before the contract does.

The risk a marketplace badge does not remove

It is tempting to read a marketplace listing as a seal of approval, and to a degree it is one: the operator has vetted the vendor, checked the packaging, and enforces platform-level guardrails. But that vetting certifies the vendor, not your deployment. The agent still runs with whatever permissions you grant it, in your data, against your customers — and that is where the real exposure lives.

The scale of the problem is now well documented. As of the first quarter of 2026, 80 percent of enterprises reported at least one production application embedding an AI agent, up from 33 percent in 2024. Yet 82 percent of CIOs say employees are creating agents and apps faster than IT can govern them, and 53 percent of organisations have already seen agents exceed their intended permissions. Gartner warns that by 2030, 40 percent of enterprises will have suffered a shadow-AI-related breach. Shadow agents are more dangerous than shadow apps for a simple reason: they operate at machine speed, can hold system access indefinitely, and can chain privileged actions together with no human in the loop. A marketplace makes it easier than ever for a team to install one on a personal credit card and wire it into live systems before anyone in security has heard of it.

Risk the badge does not coverHow it shows upWhat you control it with
Over-broad permissionsAgent can reach data far beyond its taskLeast-privilege scopes; a dedicated, limited identity
Silent, irreversible actionsMoney moved or records deleted without reviewHuman-in-the-loop gate on sensitive steps; a kill switch
No usable audit trailYou cannot reconstruct what it decided or whyEvidentiary logging of context, decision and outcome
Model swapped underneath youBehaviour changes after an unannounced updateModel change control and version notifications in the contract
Shadow adoptionTeams install agents procurement never sawAn agent registry and an approved-marketplace policy
Data residency driftPrompts and records processed in the wrong regionWritten data-processing and retention terms

None of this argues against buying from marketplaces. It argues for buying deliberately. The same convenience that makes an agent one click to install makes it one click to over-permission, so the discipline has to come from your side of the transaction.

The 2026 buyer's checklist

By the middle of 2026, enterprise procurement teams had stopped treating agents like ordinary software-as-a-service. The items below have moved from wish list to gating conditions — a deal simply does not proceed without them — and they are just as useful for a small business buying a single agent as for a corporation buying a fleet.

  1. Permission scope. Exactly what data and actions does the agent need, and can you grant it a narrow, dedicated identity rather than a human's broad login?
  2. Audit trail. Does it log who authorised the agent, what context it had, what it decided, and whether that was consistent with policy — in a form you can export?
  3. Kill switch. Can you stop the agent instantly, and does stopping it fail safe rather than leaving work half-done?
  4. Human-in-the-loop boundaries. Which actions require approval before they execute, and can you configure that line yourself?
  5. Model change control. Will you be told before the underlying model or prompt changes, and can you pin a version?
  6. Outcome-based SLA. What does the vendor guarantee about accuracy or completion, and what happens when the agent is wrong?
  7. Attestations. Can the vendor show SOC 2, ISO/IEC 42001, or equivalent evidence rather than just asserting they are secure?
  8. Portability. If you leave, do your prompts, configuration, data and logs come with you?
Rule of thumb: if a marketplace vendor cannot answer the permission, audit and kill-switch questions in plain language, that is your answer. An agent you cannot see into and cannot stop is not ready to run your business, no matter how polished the listing looks.

The lock-in question buyers keep skipping

Marketplaces are convenient precisely because they are integrated — and integration is a quiet on-ramp to lock-in. An agent that only runs inside one suite, stores its logic and memory in that suite's proprietary format, and cannot export its configuration ties the value you build to a vendor you may not always want. The more central the agent becomes to a live process, the harder and more expensive it gets to leave.

You reduce that exposure by favouring agents that lean on open, portable foundations. Ask whether the agent speaks a standard protocol for tools and context rather than a closed proprietary one, whether your data and audit logs are yours to take, and whether the surrounding process would survive swapping the agent for a competitor. A helpful test is to imagine migrating away on day one: if the honest answer is "we would have to rebuild everything," treat that as a cost of ownership, not a footnote. Our guide to how to avoid automation vendor lock-in covers the portability clauses and architecture choices that keep your options open before you sign.

What the EU AI Act changed on August 2

The timing of the marketplace boom collides with a regulatory milestone. As of 2 August 2026 — one day before this was written — the obligations for high-risk AI systems under the EU AI Act apply. Organisations running agents in high-risk application domains within the EU are now expected to have conformity assessments, human-oversight mechanisms, and log retention (commonly cited at six months) in place. That reframes a marketplace purchase for any buyer touching European operations: the audit trail and human-in-the-loop controls on your checklist are no longer just good practice, they are how you demonstrate compliance.

Practically, this means adding one more line to every marketplace conversation: ask the vendor to show, not tell, how their agent supports conformity assessment, oversight and retention for a high-risk use case. A vendor that has thought this through will have documentation ready; one that treats it as your problem is telling you something. The regulation is not a reason to avoid agents — it is a reason to prefer the ones built to be governed, which happen to be the ones you wanted anyway. If you are mapping the wider compliance picture, our overview of the EU AI Act for business automation sets out which obligations bite and when.

Marketplace agent or adaptable template?

Not every automation problem needs a marketplace agent, and for many small and mid-size teams the better buy is the less glamorous one. A pre-built workflow from an automation platform's template library is something you can open, read, understand and change. A suite-native agent is faster to switch on but harder to inspect. The right choice depends on how much control and visibility the task demands.

ConsiderationMarketplace agentAdaptable pre-built workflow
TransparencyOften a black boxYou can read every step
Time to valueVery fast to installFast, with some configuration
Best forJudgment-heavy, cross-system tasksStructured, well-defined processes
Control over behaviourLimited to the vendor's settingsFull — you own the logic
Lock-in riskHigher if suite-nativeLower with portable platforms
Governance effortSignificant — it acts autonomouslyLower — behaviour is deterministic

A sensible default is to reach for a transparent, adaptable workflow whenever the task is structured enough to specify, and to spend your governance budget on marketplace agents only where genuine judgment is required. That keeps the black boxes rare and well-guarded, and it keeps the parts of your operation you most need to trust in a form you can actually see. This is also the safest way to avoid the shadow-adoption trap covered in our guide to buying automation without shadow AI.

A short field routine for your next marketplace visit

You do not need a procurement department to buy well. The following routine takes an afternoon and catches most of the mistakes that turn a promising agent into an incident report:

  • Name the job first. Write the single outcome you want before you browse, so the marketplace sells to your need rather than the other way around.
  • Decide agent versus template. If you can describe the task as clear steps, prefer a workflow you can read over an agent you cannot.
  • Run the three-meter maths. Estimate a realistic month across licence, model tokens and platform operations, not just the sticker price.
  • Demand the checklist answers. Permission scope, audit trail and kill switch in plain language, in writing.
  • Trial with a limited identity. Give the agent the narrowest access that lets it work, and watch what it actually touches.
  • Plan the exit before the entry. Confirm you can export your data, logs and configuration on day one.

Do those six things and you get the upside of the marketplace era — speed, choice, and access to specialists you could never hire — without handing an unaccountable actor the keys to your business.

Prefer automations you can actually see into?

Browse ready-to-use, adaptable workflows and vetted specialists on FlowMarket — transparent building blocks you own, not black boxes you rent.

Explore the FlowMarket marketplace

FAQ

What is an AI agent marketplace?

It is the app-store pattern applied to agentic software: a catalog where you discover, buy and install AI agents built by third parties. The difference from a traditional app store is that these agents take actions on your data and in your systems, so the marketplace layers on permissions, audit trails and runtime governance rather than just distributing code.

Which AI agent marketplaces matter most in 2026?

The enterprise front-runners are Salesforce AgentExchange, Microsoft Marketplace, Google's Agentspace inside Gemini Enterprise, Oracle's AI Agent Marketplace in Fusion, and Anthropic's Claude Marketplace, which launched in March 2026. Alongside them sit the template libraries of automation platforms such as Zapier, Make and n8n, which behave like marketplaces for pre-built workflows.

How do AI agent marketplaces charge?

Most blend a platform revenue share with the vendor's own pricing. On Salesforce AgentExchange, paid listings pay roughly 15 percent of net subscription revenue to Salesforce for the standard program, and checkout transactions add a small card-processing fee. On top of that you pay the agent vendor's subscription or per-outcome price, plus the underlying model and platform consumption the agent burns while it runs.

Are marketplace agents safe to run on my data?

Listing in a marketplace is not the same as being safe for your environment. The marketplace vets the vendor and enforces platform-level guardrails, but the agent still runs with whatever permissions you grant it. You should scope those permissions tightly, require an audit trail and a kill switch, and treat any agent that touches money, records or customers as a high-risk deployment that needs a human gate.

What should be on my agent-buying checklist?

Ask for the permission scope, an evidentiary audit trail, a kill switch, human-in-the-loop boundaries, model change control, an outcome-based SLA, and a recognised attestation such as SOC 2 or ISO/IEC 42001. Confirm where data is processed and retained, how the agent behaves when it is uncertain, and what portability you have if you leave. By mid-2026 these have become gating procurement conditions, not nice-to-haves.

Does buying from a marketplace create vendor lock-in?

It can. An agent that only runs inside one vendor's platform, stores its logic and memory there, and cannot export its configuration ties you to that ecosystem. Favour agents that follow open protocols, keep your prompts, data and audit logs portable, and can be swapped without rebuilding the surrounding process.

Can small businesses use these marketplaces, or are they enterprise-only?

Both. The big-suite marketplaces skew enterprise, but the template and agent libraries inside Zapier, Make and n8n are aimed squarely at small and mid-size teams. A smaller business often gets more value from a well-scoped pre-built workflow it can read and adapt than from a black-box enterprise agent.

How does the EU AI Act affect what I buy?

As of 2 August 2026, obligations for high-risk AI systems apply in the EU, which means agents used in sensitive domains need conformity assessments, human oversight and log retention. If you operate in the EU, ask any marketplace vendor to show how their agent supports these requirements before you deploy it in a high-risk process.

Related articles

  • AI Agent vs. Rules-Based Workflow: A 2026 Decision Framework

    Every platform now nudges you to make everything an AI agent. Here is a 2026 decision framework for when a rules-based workflow is the smarter, safer choice.

  • AI Agents for Business: What They Are and How to Use Them

    Agentic AI is the defining 2026 automation trend. Learn what AI agents really do, the pilot-to-production gap, multi-agent orchestration, guardrails, and how n8n, Zapier and Make now support agents.

  • AI Automation for Business: 10 Real Use Cases

    Practical AI automation for business: 10 real use cases where AI adds value inside automated workflows — and where it doesn't. Plus the tools and how to start.

  • AI Customer Support Automation

    AI customer support automation in the agentic era: draft and triage with RAG-grounded replies, supervise emerging agentic support agents, keep human escalation, and add governance and guardrails.