n8n MCP
Lets AI clients search, run and build n8n workflows
n8n MCPProduct images: n8n MCP
Last verified: October 8, 2026
Maintenance status
ActiveThe linked repository is n8n itself; the n8n-mcp package is a separate community project.
How to Install n8n MCP
$claude mcp add --transport http n8n https://<your-n8n-domain>/mcp-server/httpRequires Claude Desktop, Cursor, Windsurf, or another MCP-compatible client.
Setup by client
Cursor (~/.cursor/mcp.json)
{
"mcpServers": {
"n8n-mcp": {
"url": "https://<your-n8n-domain>/mcp-server/http"
}
}
}VS Code (.vscode/mcp.json)
{
"servers": {
"n8n-mcp": {
"type": "http",
"url": "https://<your-n8n-domain>/mcp-server/http"
}
}
}Claude Code (terminal)
claude mcp add --transport http n8n-mcp https://<your-n8n-domain>/mcp-server/httpAdd any API keys or environment variables the server's README lists.
About n8n MCP
The n8n MCP server is the MCP server built into n8n itself, which n8n's docs call instance-level MCP access. It is a remote MCP server that your own n8n instance serves, so Claude, ChatGPT, Cursor, VS Code and other MCP clients can search, run, build and edit your workflows. n8n says it is included on all n8n plans, including the free self-hosted Community Edition. It is not read-only.
Several different things get called "n8n MCP". This page covers the built-in server and shows how the MCP Server Trigger node, the MCP Client nodes and the community n8n-mcp npm package differ from it.
Quick facts (as of October 8, 2026)
| n8n MCP server (instance-level MCP) | |
|---|---|
| Maker | n8n. Built into the product and maintained by n8n, with no third-party service to run alongside your instance |
| Type | Remote MCP server served by your own n8n instance, on n8n Cloud or self-hosted. There is no separate package to install |
| Server URL | Ends in /mcp-server/http, for example https://<your-n8n-domain>/mcp-server/http. Copy it from Settings > Instance-level MCP > Connect a client |
| Authentication | OAuth (n8n's recommended method), or an API key: a personal access token sent in an Authorization: Bearer header |
| Who turns it on | An instance owner or admin, under Settings > Instance-level MCP > Enable MCP access |
| Access model | Read and write. A client can preview every workflow you can view, but can only read in full, run or change the workflows you have enabled for MCP |
| Tools | 53 tools in seven groups on n8n's tools reference (our count): workflow management, executions, credentials, instance context, workflow builder, agents and data tables |
| Workflow building | Creating and editing workflows from an MCP client is available from n8n 2.13.0 |
| Clients named in n8n's docs | Claude Desktop, Claude.ai, Claude Code, ChatGPT, Codex, Gemini CLI, Cursor, VS Code, Windsurf, Lovable, Mistral Vibe and Google ADK agents |
| Price | No separate MCP charge is listed. n8n's MCP page says it is included on all n8n plans |
| Docs | Connect to n8n MCP server |
Which "n8n MCP" do you mean?
n8n works with MCP in both directions, and a community project uses almost the same name. These are the pieces:
| Name | Made by | What it does |
|---|---|---|
| Instance-level MCP server (this page) | n8n | One connection per n8n instance with centralized authentication. External AI clients search, run, build and edit the workflows you choose to enable |
| MCP Server Trigger node | n8n | A node inside a single workflow. It exposes a URL and only the tool nodes attached to it, so one workflow acts as its own small MCP server. It supports SSE and streamable HTTP, and does not support stdio |
| MCP Client Tool node and MCP Client node | n8n | The opposite direction. The MCP Client Tool node lets an n8n AI agent call tools on an external MCP server. The MCP Client node uses those tools as regular workflow steps |
| MCP servers registry | n8n | A registry in n8n's node panel of external MCP servers you can connect to an AI agent |
| n8n docs MCP servers | n8n | Two servers that search n8n's documentation and knowledge base: a GitBook docs server at https://docs.n8n.io/~gitbook/mcp and a Kapa.ai server at https://n8n.mcp.kapa.ai |
n8n-mcp npm package | Community (Romuald Czlonkowski), MIT license | A separate project. Its README describes a server that gives AI assistants access to n8n node documentation, properties and operations, with extra workflow management tools if you supply an n8n API URL and key |
About npx n8n-mcp: that command runs the community package, not n8n's built-in server. The npm registry lists version 2.92.1 as the latest, published October 6, 2026, under the MIT license, requiring Node.js 20 or newer. Its README also describes a hosted option with a free tier of 100 tool calls per day. It is not maintained by n8n, and this page does not cover it in depth.
What the built-in server can do
n8n's tools reference groups the tools like this:
| Group | Tools | Examples |
|---|---|---|
| Workflow management | 13 | search_workflows, get_workflow_details, execute_workflow, test_workflow, publish_workflow, unpublish_workflow, version history and version diff |
| Execution management | 2 | get_workflow_execution, search_workflow_executions |
| Credential management | 1 | list_credentials, which n8n says never returns credential secret data |
| Instance context | 4 | get_instance_context, get_instance_activity, get_node_usage. A feature flag controls this group |
| Workflow builder | 11 | search_nodes, get_node_types, validate_workflow, create_workflow_from_code, update_workflow, archive_workflow, restore_workflow_version |
| Agent management | 15 | Create, change, validate, call, publish and delete n8n agents. Available from n8n 2.34.0; agents are in Preview |
| Data tables | 7 | Search, create and rename tables; add, rename and delete columns; add rows |
A few details from the reference are worth knowing before you connect anything:
- Building uses code, not JSON.
create_workflow_from_codetakes TypeScript or JavaScript written with the n8n Workflow SDK, and the code must be validated first withvalidate_workflow. n8n's announcement says this is deliberate: the model has to produce something that compiles before anything reaches your instance. - Running is asynchronous.
execute_workflowstarts the run and returns an execution ID straight away. The client checks the result withget_workflow_execution. - Supported triggers. Production mode supports workflows with Webhook, Chat Trigger, Form Trigger and Schedule Trigger nodes. Manual mode also supports Manual Trigger nodes. Multi-step forms and human-in-the-loop steps are not supported.
- Test runs use pinned data.
test_workflow(from n8n 2.15.0) feeds simulated data to trigger nodes, nodes with credentials and HTTP Request nodes. The MCP timeout is five minutes by default and can be raised to 60 minutes. - Credentials stay masked. Workflow details keep only the
idandnameof each credential reference.
Setup
1. Enable MCP access. In n8n, go to Settings > Instance-level MCP and select Enable MCP access. This needs instance owner or admin permissions. On self-hosted instances from n8n 2.20.0 you can manage it with environment variables instead: N8N_MCP_MANAGED_BY_ENV=true and N8N_MCP_ACCESS_ENABLED=true. Setting N8N_DISABLED_MODULES=mcp removes the feature entirely.
2. Expose the workflows you want. Enabling the server does not expose everything. You enable each workflow individually: toggle Available in MCP in the workflow's settings, use the Workflows enabled page (called Workflows exposed before n8n 2.42.0), or switch a whole project or folder on (from n8n 2.24.0). The docs say most MCP tools work on unpublished workflows; the exception is execute_workflow, whose default production mode runs the published version.
3. Connect a client. From n8n 2.33.0, the Connect a client dialog shows setup steps per client and offers two tabs: OAuth (recommended) and API key. The first time you open the API key tab, n8n generates a personal access token tied to your user account. Copy it then, because n8n only shows a redacted value afterward.
4. Use the command or config for your client. These come from n8n's client examples page. Replace <your-n8n-domain> with your own domain; on n8n Cloud it looks like your-instance.app.n8n.cloud.
Claude Code, with OAuth:
claude mcp add --transport http n8n https://<your-n8n-domain>/mcp-server/http
Then run /mcp in Claude Code and select n8n to finish the OAuth authorization.
Claude Desktop: go to Settings > Connectors, choose Add custom connector, and paste the Server URL. n8n warns that this is not the address of your n8n editor, so do not paste the URL from your browser's address bar.
Cursor, in ~/.cursor/mcp.json:
{
"mcpServers": {
"n8n": {
"type": "streamable-http",
"url": "https://<your-n8n-domain>/mcp-server/http"
}
}
}
Other clients on the examples page:
- VS Code: a
serversentry with"type": "http"and the same URL in.vscode/mcp.json, or one-click setup from the Connect a client dialog. - Codex:
codex mcp add n8n --url "https://<your-n8n-domain>/mcp-server/http", thencodex mcp login n8n. - Gemini CLI:
gemini mcp add --transport http n8n https://<your-n8n-domain>/mcp-server/http, then/mcpto authorize. - Windsurf: a
serverUrlentry in~/.codeium/windsurf/mcp_config.json.
If your instance runs on plain HTTP, such as a local install at http://localhost:5678, use http:// in the URL. Copying the full Server URL from n8n gives you the right prefix either way.
5. Optional: add n8n Skills. n8n publishes a set of skills for coding agents in its n8n-io/skills repository. The docs describe 13 capability skills covering topics such as expressions, error handling, credentials and data tables, written as plain Markdown.
If the connection fails
n8n's troubleshooting list includes these checks:
- If you use a cloud-based MCP client, your n8n instance has to be publicly accessible.
- If you see "You do not have sufficient permissions to authorize this request", MCP access is not turned on for the instance.
- If n8n sits behind a reverse proxy, load balancer or web application firewall, allow the
MCP-Protocol-Version,Mcp-MethodandMcp-Nameheaders.
Limitations and things to watch
- It can change and run real workflows. The server includes tools to create, update, publish, unpublish and archive workflows, start executions, and change data tables.
delete_data_table_columnpermanently removes a column and its data. - Permissions are set when a client connects. n8n says each connected client only has the permissions you granted it at connection time, for example reading workflows without being able to create or run them. Grant the minimum.
- Workflow access is not scoped per client. Every client you connect can see all the workflows you have enabled for MCP. You cannot limit specific workflows to specific clients.
- Search reaches further than the enabled list.
search_workflowsreturns previews of every workflow the current user can view, even ones not enabled for MCP. It does not return full workflow data. - New workflows are exposed automatically. A workflow created through
create_workflow_from_codehas itsavailableInMCPflag set to true. - OAuth callback URLs are open by default. n8n allows any callback URL unless an owner or admin switches to Only trusted URLs, and its docs call the default less secure.
- API key clients are harder to audit. They do not appear in the Connected clients list. Generating a new token revokes the old one.
- A test run is not a full dry run. In
test_workflow, nodes such as Set, If and Code still execute normally, and so do credential-free nodes like Execute Command and file read or write nodes. - Agent tools have real side effects. n8n warns that
call_agentruns an agent's real tools with real credentials. Agents are in Preview. - Features depend on your n8n version. Examples: workflow building needs 2.13.0, the Connect a client dialog 2.33.0, agent tools 2.34.0, and choosing a trigger by name in
execute_workflow2.36.0. - n8n's own caveats. Its April 29, 2026 announcement says complex workflows often need a second or third pass and heavy branching often needs manual cleanup. The author also notes that edits made in the n8n editor mid-session were overwritten after forgetting to tell the client to check for them.
Pros and cons
Pros
- First-party and built in. There is no extra service to install or keep running.
- OAuth with permissions granted per client and access you can revoke per client, plus an API key option for clients that need it.
- A client cannot read a workflow in full, run it or change it until you enable MCP for the instance and then for that workflow.
- Included on all n8n plans, according to n8n, including the free Community Edition.
Cons
- It has write tools, so a mistaken or manipulated agent can change workflows you enabled.
- You cannot give different clients different sets of workflows.
- Many features are tied to specific recent n8n versions, and agent support is in Preview.
- It covers n8n only. The tools reference lists tools for workflows, executions, credentials, agents and data tables, not ready-made actions for other apps.
Who it is for
A good fit if:
- You already run n8n and want an assistant or coding agent to build, debug and run workflows on it. n8n's docs suggest coding agents such as Claude Code over chat clients for building, because they specialize in generating and validating TypeScript code.
- You want an assistant to trigger automations you have already built, with you deciding which workflows it can reach.
Not the right tool if:
- You only want to expose two or three hand-picked tools. The MCP Server Trigger node does that inside one workflow.
- You do not use n8n and want ready-made app actions without building workflows. Compare the Zapier MCP server or Composio MCP.
- You want to control a smart home rather than business workflows. See how to connect Home Assistant to Claude.
n8n and MCP are different things
Some people search for n8n versus MCP, but the two are not alternatives. n8n is a workflow automation tool. MCP is an open standard for connecting AI applications to external systems, with servers that expose tools and clients that call them. n8n simply speaks MCP on both sides: as a server through instance-level MCP and the MCP Server Trigger node, and as a client through the MCP Client nodes. If the protocol itself is new to you, start with what an MCP server is.
Pricing
n8n does not list a separate price for the MCP server. n8n's MCP page says it is included on all n8n plans, and its announcement says it is built into every edition: Cloud, Enterprise and the free self-hosted Community Edition. So the cost is whatever you pay for n8n.
- Self-hosted Community Edition: free, per n8n's docs (as of October 2026).
- n8n Cloud: paid plans, with a free trial. n8n's docs name the Cloud plans as Starter, Pro and Enterprise. This page does not quote plan prices: n8n's pricing page showed euro amounts when we loaded it, and we could not confirm US dollar prices. Check n8n's pricing page for current figures.
n8n prices plans by monthly workflow executions, and one execution is a single run of an entire workflow.
What we could not verify
- Whether workflow building is still a public preview. n8n's April 29, 2026 announcement called it a Public Preview. The docs page we read today does not label it either way.
- n8n Cloud prices in US dollars. The pricing page displayed euro prices with annual billing when we loaded it, so this page does not quote plan prices.
- Whether runs started through MCP count toward your plan's workflow executions. The pricing page and MCP docs do not address this directly.
- Setup for clients n8n does not document, such as Antigravity. The examples page does not include it.
- How the server behaves in practice. We read the documentation and did not connect a client to an n8n instance.
How this page was put together
We read the pages listed under Sources on October 5, 2026, and rechecked them on October 8, 2026: n8n's documentation, MCP product page, pricing page and April 2026 announcement, plus the npm registry entry and README for the community n8n-mcp package. Nothing here comes from running the server. An earlier version of this listing showed npx n8n-mcp as the install command; that is the community package, so we corrected it. n8n changes this feature often, so check the docs before relying on a detail.
Sources
- n8n docs: Connect to n8n MCP server
- n8n docs: MCP client connection examples
- n8n docs: MCP server tools reference
- n8n docs: Use n8n MCP server
- n8n docs: MCP Server Trigger node
- n8n docs: MCP Client Tool node
- n8n docs: MCP Client node
- n8n docs: MCP servers registry
- n8n docs: Connect to the n8n docs MCP server
- n8n docs: Manage settings using environment variables
- n8n docs: Choose how to use n8n
- n8n docs: home page
- n8n: MCP server product page
- n8n: Plans and pricing
- n8n blog: Build and Update Workflows with n8n's MCP Server (April 29, 2026)
- npm registry: n8n-mcp (community package)
- n8n-mcp README as published to npm, version 2.92.1
Pricing
Freemium: from Free on the self-hosted Community Edition; n8n Cloud plans are paid (no separate MCP charge listed by n8n, as of October 2026)
Our Take on n8n MCP
The right choice if you already run n8n and want Claude, ChatGPT or a coding agent to build, debug and run workflows on it: it is first-party, built in and, according to n8n, included on all n8n plans. Treat it as a write-capable connection. Enable only the workflows you need, grant each client the minimum permissions, and prefer OAuth. If you only need to expose a few specific tools, use the MCP Server Trigger node instead.