Find things
search_workflows locates workflows with optional filtering, get_workflow_details returns the full picture of one, and search_projects, search_folders and list_workflow_tags cover the structure around them.
n8n ships its own MCP server plus two MCP nodes, and there is a widely used community package with the same name. Setup steps, endpoints and tool names read from n8n's docs and the n8n-mcp README on 2 September 2026.
Interactive examples · No account is connected on this page
Updated
n8n MCP means three different things. n8n's own instance-level MCP server exposes chosen workflows to any client at https://<your-n8n-domain>/mcp-server/http. The MCP Server Trigger node turns one workflow into a server, and the MCP Client Tool node lets an n8n agent call other people's servers. Separately, the community n8n-mcp package feeds models n8n node documentation.
Pick an example to see which n8n MCP tools a task would call and what the result looks like. Examples are illustrative; nothing on this page connects to n8n.
To connect a client to n8n's own MCP server, enable instance-level MCP in Settings, then enable each workflow you want to expose, because nothing is exposed by default. Clients connect to https://<your-n8n-domain>/mcp-server/http with OAuth or an access token. To publish a single workflow instead, use the MCP Server Trigger node.
In n8n, go to Settings > Instance-level MCP and select Enable MCP access. The docs note this needs instance owner or admin permissions. Version floors differ by feature: workflow building and editing needs n8n 2.13.0 or newer, project- and folder-level access control needs 2.24.0, per-client connection setup needs 2.33.0, and auto-exposing new workflows needs 2.36.0. Self-hosted instances can instead drive these settings from environment variables, which locks the matching UI controls on every startup.
Settings > Instance-level MCP > Enable MCP accessEnabling MCP on the instance does not expose anything on its own. Each workflow is enabled individually with the Enable workflows button on the same settings page. That page then lists every workflow a client can reach, and lets you open it, revoke access from the action menu, or update its description. From a workflow card, the same revoke lives under Disable MCP access.
OAuth is the recommended path. Open Connection details, select Connect, pick your client type (CLI, Web or IDE) and follow the steps shown. Web clients get a one-click setup or can paste the server URL by hand. The URL is the same for every client: https://<your-n8n-domain>/mcp-server/http.
claude mcp add --transport http n8n https://<your-n8n-domain>/mcp-server/http
codex mcp add n8n --url "https://<your-n8n-domain>/mcp-server/http"
gemini mcp add --transport http n8n https://<your-n8n-domain>/mcp-server/httpFor clients without OAuth, the Connect dialog has an API key tab holding a ready-made configuration JSON block plus the raw server URL and access token. The token goes in an Authorization: Bearer header. Claude Desktop is the awkward one, because it wants a local command: n8n's docs bridge it with supergateway.
claude mcp add --transport http n8n-mcp https://<your-n8n-domain>/mcp-server/http \
--header "Authorization: Bearer <YOUR_N8N_MCP_TOKEN>"
{
"mcpServers": {
"n8n": {
"type": "streamable-http",
"url": "https://<your-n8n-domain>/mcp-server/http"
}
}
}If you want one workflow to be a server rather than opening the instance, use the MCP Server Trigger node. n8n describes it as an entry point that exposes a URL MCP clients interact with to access n8n tools; it connects only to tool nodes, not to ordinary downstream nodes. It has a test URL and a production URL, a randomly generated path you can override, and Bearer or Header authentication. It speaks SSE and streamable HTTP, and explicitly not stdio.
MCP Server Trigger > Path + Authentication (Bearer or Header)n8n-mcp is a separate MIT-licensed community project by czlonkowski. It gives a model n8n's node catalogue and workflow templates rather than your workflows. MCP_MODE=stdio is required for Claude Desktop, or you get JSON parsing errors in the UI. Adding N8N_API_URL and N8N_API_KEY unlocks its 21 n8n management tools on top of the 7 documentation tools.
claude mcp add n8n-mcp \
-e MCP_MODE=stdio \
-e LOG_LEVEL=error \
-e DISABLE_CONSOLE_OUTPUT=true \
-e N8N_API_URL=https://your-n8n-instance.com \
-e N8N_API_KEY=your-api-key \
-- npx n8n-mcpOfficial documentation: n8n MCP server docs.
Four different things are called n8n MCP. n8n publishes three: the instance-level MCP server, the MCP Server Trigger node that turns one workflow into a server, and the MCP Client Tool node that lets an n8n agent call external servers. The fourth, n8n-mcp, is an MIT-licensed community package that gives models n8n node documentation rather than your workflows.
| What differs | Instance-level MCP server | MCP Server Trigger node | MCP Client Tool node | Community n8n-mcp |
|---|---|---|---|---|
| Who publishes it | n8n, documented at docs.n8n.io | n8n, a built-in core node | n8n, a built-in cluster sub-node | czlonkowski, MIT licence, not n8n |
| Direction | n8n is the server | n8n is the server | n8n is the client | The package is the server |
| What it exposes | Workflows you enable, plus projects, folders, executions and the credential list | One workflow, and only the tool nodes wired into that trigger | Nothing; it consumes tools from an external MCP server | n8n node docs and templates; workflow management when API keys are set |
| Endpoint or entry point | https://<your-n8n-domain>/mcp-server/http | A test URL and a production URL on a path the node generates | An SSE endpoint you supply | npx n8n-mcp over stdio, Docker, or the hosted dashboard.n8n-mcp.com |
| Transport | Streamable HTTP | SSE and streamable HTTP; stdio is not supported | SSE endpoint | stdio, or HTTP when self-hosted remotely |
| Authentication | OAuth, or an access token in an Authorization: Bearer header | Bearer authentication or Header authentication | None, Bearer, header, multiple headers, or OAuth2 | N8N_API_URL and N8N_API_KEY environment variables |
Read from docs.n8n.io and the czlonkowski/n8n-mcp README on 2026-09-02. The community package and n8n's own server are different things that happen to share a name; you can run both at once.
The official n8n MCP server exposes tools for the whole workflow lifecycle: finding workflows and folders, running and testing them, publishing and rolling back versions, reading execution history, and building workflows as code with node lookups and validation. Credentials are listed but never read. The community n8n-mcp package answers a different question with its own seven documentation tools.
search_workflows locates workflows with optional filtering, get_workflow_details returns the full picture of one, and search_projects, search_folders and list_workflow_tags cover the structure around them.
execute_workflow runs a workflow by ID, test_workflow exercises the logic against simulated data, and prepare_workflow_pin_data generates the test data schemas that make that possible.
publish_workflow activates a workflow for production, unpublish_workflow deactivates it, get_workflow_versions_diff compares versions, and archive_workflow retires one.
get_workflow_execution fetches one execution by ID and search_workflow_executions queries them with filters, which is how an agent finds out why last night's run failed.
A second group targets construction: get_workflow_sdk_reference, search_nodes, get_node_types, get_workflow_best_practices, validate_workflow, validate_node_config, create_workflow_from_code and update_workflow.
explore_node_resources resolves a node's dynamic options against a real credential, so a generated workflow references a Slack channel or a Sheets tab that actually exists instead of an invented ID.
list_credentials shows which credentials are reachable. That is the whole credential surface of the official server; there is no tool that hands their contents to a model.
n8n-mcp's 7 core tools are tools_documentation, search_nodes, get_node, validate_node, validate_workflow, search_templates and get_template. Its README claims coverage of 2,616 nodes and 2,352 templates; treat those as the project's own numbers.
n8n MCP can mean three things. The instance-level MCP server exposes workflows you choose to any MCP client at https://<your-n8n-domain>/mcp-server/http. The MCP Server Trigger node publishes a single workflow as its own server. The MCP Client Tool node lets an n8n agent call someone else’s server.
Separately, the community n8n-mcp package gives a model n8n’s node documentation and templates, which helps it build workflows but does not connect to your instance’s workflows.
Settings > Instance-level MCP > Enable MCP access (owner or admin), then choose which workflows are exposed.
Use OAuth where the client supports it, or the generated access token in the client’s config.
Run search_workflows to confirm the exposed set before letting the agent execute or publish anything.
Search executions, open the failing one and read which node broke — without logging in to the editor.
Use the construction tools (search_nodes, validate_workflow, create_workflow_from_code) and explore_node_resources so the workflow references real channels and sheets.
Add an MCP Server Trigger node to a single workflow with Bearer or header authentication, instead of opening the whole instance.
Combine n8n with Slack MCP or GitHub MCP when the agent needs to read context before triggering a workflow.
These answers cover what trips people up with n8n and MCP: whether n8n-mcp is official, what the server URL looks like, how the MCP Server Trigger differs from the MCP Client Tool, what reverse proxies and queue mode need, how to keep an agent away from production workflows, and which n8n version each feature requires.
No. n8n-mcp is a community project by czlonkowski under the MIT licence, and its own README frames it as a bridge that gives AI assistants access to n8n node documentation. n8n's official server is the instance-level MCP server you enable under Settings > Instance-level MCP, served from https://<your-n8n-domain>/mcp-server/http. The two solve different problems and can run side by side.
n8n's client examples all use the same shape: https://<your-n8n-domain>/mcp-server/http, over streamable HTTP. You get the concrete URL, and an access token if you want one, from the Connect a client dialog on the Instance-level MCP settings page. The MCP Server Trigger node is different again: it generates its own path, with separate test and production URLs.
Direction. The MCP Server Trigger makes n8n a server: it exposes a URL that MCP clients call, and it connects only to tool nodes. The MCP Client Tool makes n8n a client: you give it an SSE endpoint and it lets an n8n agent use tools from someone else's server, with a Tools to Include setting of All, Selected, or All Except.
It needs care. n8n's docs on the MCP Server Trigger say that with multiple webhook replicas you must route all /mcp* requests to a single dedicated webhook replica, or connections fail. Behind a reverse proxy you have to disable proxy buffering for the endpoint, and may need to adjust gzip compression and chunked transfer encoding.
n8n's model is per-workflow consent: MCP exposes only the workflows you explicitly enable, and you can revoke one from the settings list or from the workflow card's Disable MCP access. For the community package, the README publishes a read-only recipe using DISABLED_TOOLS and DISABLED_TOOL_OPERATIONS, and recommends pairing it with a read-only n8n API key. Its own warning is blunt: never edit production workflows directly with AI.
It depends on the feature. n8n's docs give 2.13.0 or newer for workflow building and editing over MCP, 2.24.0 for project- and folder-level access control, 2.33.0 for per-client connection setup, and 2.36.0 for auto-exposing new workflows. Check your own instance before copying any of the commands above.
Exposing n8n over MCP lets a model reach your automations. Deciding which automations should exist, and what they should do when a step fails, is the older and harder half of the job: the trigger, the retry policy, the data each step is allowed to write, and the point where a person reviews the result.