n8n MCP Server

Built-in MCP server for n8n: search, execute, create, and edit workflows directly from any MCP-capable AI client.

Description

The n8n MCP Server is a built-in component of n8n — it is not a separate package but ships directly with n8n v1.x. It exposes a Streamable HTTP endpoint at /mcp-server/http and allows MCP-capable AI clients to access your n8n instance, search workflows, execute them, create new ones, and edit existing ones. The direct product link points to the official n8n documentation at docs.n8n.io; the repository n8n-io/n8n is the monorepo for the entire n8n project — the GitHub stars counted there (as of September 2026) refer to the project as a whole, not to the MCP server feature alone.

What is the n8n MCP Server

The n8n MCP Server is an instance-level MCP connection: a single connection covers the entire n8n instance. According to the provider, once enabled, MCP clients can search workflows, interact with and execute workflows marked as available for MCP, create new workflows and data tables, and edit existing workflows (editing available from n8n 2.13.0). This sets it apart from the MCP Server Trigger node, which operates within a single workflow and exposes fine-grained, workflow-specific tools. The built-in MCP Server targets scenarios where an AI agent needs to orchestrate multiple workflows across an instance or automatically build new automations. n8n hosts it on its own cloud platform (n8n Cloud) while also supporting self-hosted deployments on your own infrastructure — hence deployment_type = both.

Prerequisites

Using the n8n MCP Server requires: an n8n instance (n8n Cloud or self-hosted) running at minimum version 2.33.0 for the full feature set (per-client setup steps and allowed callback URLs), plus instance owner or admin permissions to enable it. Supported MCP clients include Claude Desktop, Claude Code, Cursor, Codex, and Lovable. On self-hosted instances, the MCP feature can be completely disabled using the environment variable N8N_DISABLED_MODULES=mcp. Older versions show a simplified setup screen without per-client steps. The free community edition of n8n includes the MCP server; n8n Cloud makes the feature available on all plans, though the scope may depend on the selected plan.

Features: Workflows, Agents, Data Tables

According to the provider, the n8n MCP Server exposes several groups of tools. Workflow execution tools allow starting workflows; execute_workflow defaults to production mode and runs the published version, with an optional manual mode to run the current unpublished version. Workflow editing tools (from n8n 2.13.0) allow creating and modifying workflows directly from the AI client. search_workflows can search all workflows the current user has access to but returns only previews, not full workflow data. Additionally, agents and data tables (when the agents feature is active on the instance) can be enabled for MCP clients. All MCP-capable clients connected to the same instance see the same enabled workflows — there is no per-client filtering; on the user level, standard user-scoped access control still applies.

Setup

To enable the MCP server, an instance owner or admin navigates to Settings > Instance-level MCP and selects Enable MCP access. The page then shows three sections: Connection details with MCP status and a Connect button, Access (showing how many workflows and optionally agents are exposed), and Connected clients. For client authentication, OAuth (recommended) and API key are available. The Connect a client dialog guides through client-specific steps for CLI clients (Claude Code, Codex, Gemini CLI), web clients (Claude.ai, ChatGPT), and IDE clients (Cursor, VS Code, Windsurf). For Claude Code via the command line, the install command looks like: claude mcp add --transport http n8n <your-instance-mcp-server-url>. After completing the OAuth sign-in, the connection is active. Individual workflows must then be manually enabled for MCP access.

Security and Data Access

According to the provider, MCP access applies equally to all connected clients — there is no way to restrict specific workflows to specific clients. Users can only see workflows they have permission to access. For self-hosted instances, n8n recommends using Allowed Callback URLs (available from 2.33.0) to restrict OAuth redirects to approved domains. Because the MCP server includes write tools for workflow creation and editing, only trusted clients should be connected. According to the provider, no workflow data is sent to third-party AI providers; the connected AI client controls what is forwarded to its model provider. Prompt injection through workflow names or descriptions controlled by an attacker is a theoretical risk and should be factored into access decisions.

FAQ

Is the n8n MCP Server free? The n8n source code (including the MCP server) is available under the Sustainable Use License on GitHub. n8n Cloud offers paid plans; the community edition can be self-hosted free of charge. Current pricing and plan details are published at n8n.io/pricing.

Can I control all workflows from the AI client? No. Workflows must be individually enabled for MCP access. search_workflows returns previews of all accessible workflows, but execute_workflow runs only published versions (or the current version in manual mode). Workflows that are not enabled for MCP cannot be executed through the MCP server.

What do the GitHub stars represent? The star count in this entry refers to the monorepo n8n-io/n8n, which contains the entire n8n project (core, UI, packages, nodes). The MCP server is an integrated component and does not have its own repository. The monorepo's popularity reflects the overall project, not the MCP feature alone.

Requirements

n8n instance (Cloud or self-hosted) from v2.33.0, instance owner or admin permissions, and an MCP-capable AI client (Claude Desktop, Cursor, Codex, etc.).

Installation instructions

Navigate to Settings > Instance-level MCP and enable access. Then use "Connect a client" to authenticate the desired MCP client (OAuth recommended). Afterwards, enable individual workflows for MCP access.

claude mcp add --transport http n8n <your-n8n-mcp-server-url>

Authentication

OAuth 2.0 (recommended) or API key. OAuth redirects through the n8n login; for self-hosted instances, configure allowed callback URLs.

Required access permissions

Permissions follow the authenticated n8n user. All connected MCP clients see the same enabled workflows; per-client restriction is not supported.

Transmitted or stored data

n8n processes tool calls and returns results. Workflow data is not sent directly to AI model providers; the client controls that.

Security risks

Write tools (workflow creation, editing) allow broad actions; connect only trusted clients. Prompt injection via workflow names is a theoretical risk.

License and costs

License
Sustainable Use License
Cost
free

Community edition is free (self-hosted). n8n Cloud offers paid plans; current pricing at n8n.io/pricing.

Alternatives

Not recorded yet.

At a glance

Provider
n8n
Status
Official server
Deployment
Local and remote
Current version
Not recorded yet.
GitHub stars
206,144
Last reviewed
08.09.2026

Repository and documentation

Categories

Supported clients