n8n-MCP
A community MCP server for giving AI agents deep n8n node knowledge plus tools to inspect, build, validate, modify, execute and administer n8n workflows. Its strongest advantage is workflow-specific intelligence and precise incremental editing; its tradeoffs are broad permissions, high context usage, telemetry and a serious recent security history.
Start with Decision, Score, Official vs Community, Access, Safety, Token Cost and Fit. Use Setup for implementation details and the lower sections for technical evidence.
Should you use n8n-MCP?
Serious n8n builders who repeatedly create, debug and modify workflows through Claude Code, Cursor, Codex or similar agentic clients.
You are a casual n8n user, work with highly sensitive production instances, or can meet your needs with n8n's first-party MCP without running another privileged component.
Deep n8n-specific node knowledge, validation and precise diff-based workflow editing that reduce schema guessing during agentic workflow construction.
Large permissions, large context, enabled-by-default telemetry and a substantial 2026 security history make production configuration important.
n8n-MCP is valuable when its node intelligence, validation and incremental editing materially improve repeated workflow development. It is not the default choice merely because someone wants MCP access to n8n.
Why n8n-MCP scores 72/100
The 72/100 score is weighted around the job that matters most: letting an AI agent construct and modify working n8n automation without creating unacceptable operational risk.
Feature breadth therefore does not automatically improve the verdict. Workflow correctness, credential containment, safe failure reporting, context efficiency and security boundaries matter more than the number of exposed tools.
| Universal parameter | Score | Finding |
|---|---|---|
| Effectiveness | 82 | Extensive workflow construction, validation, debugging and management capability. |
| Reliability | 68 | Active project, but recent validator, execution and authentication bugs reduce confidence. |
| Safety | 57 | Strong hardening controls exist, but broad write authority and recent CVEs matter. |
| Efficiency | 63 | Partial updates are efficient; node and workflow context can become large. |
| Compatibility | 73 | Broad client support, but current-spec conformance is not proven. |
| Maintainability | 91 | Rapid releases and active development. |
| Setup friction | 72 | Easy for documentation use; API and remote production deployments require more care. |
n8n-specific parameters
| Parameter | Score | Why it matters |
|---|---|---|
| Workflow correctness | 75 | Strong schemas and validation, but generated workflows can still require repair. |
| Incremental editing | 88 | Targeted workflow diffs are one of the project's strongest differentiators. |
| Validation fidelity | 66 | False positives and validator failures reduce trust in automated repair loops. |
| Credential/write containment | 68 | Good controls exist, but safe deployments require deliberate restriction. |
| Context efficiency | 55 | Large schemas and tool results can consume substantial model context. |
| Schema freshness | 88 | Frequent updates help keep node definitions aligned with current n8n releases. |
| Safe failure reporting | 62 | Historical false-success and misleading health signals matter in agentic workflows. |
| Official-MCP differentiation | 73 | The community server remains deeper in several areas, but n8n's native MCP is now a strong alternative. |
The documentary evidence is strong, but there is no controlled live A/B benchmark showing how often a modern agent produces a working workflow on the first attempt with community n8n-MCP versus n8n's official MCP.
What is n8n-MCP?
n8n-MCP is a community Model Context Protocol server that gives AI clients structured knowledge about n8n nodes and, when n8n API credentials are configured, direct tools for creating, inspecting, validating, editing, executing and administering n8n workflows.
The server has two operating layers. The first is a local knowledge layer for node search, node definitions, validation and template discovery. The second is a management layer that uses N8N_API_URL and N8N_API_KEY to act on a real n8n instance.
Those two layers have different risk profiles. Documentation-only use does not need n8n credentials. Management use can affect live workflows, executions, credentials and data.
Community n8n-MCP vs n8n's official MCP
The community czlonkowski/n8n-mcp project is not the same product as n8n's official instance-level MCP server. Both connect AI clients with n8n, but they expose different capability surfaces and trust boundaries.
The community project's remaining differentiation is deeper node intelligence, dedicated validation, template discovery, resource resolution and precise incremental workflow editing. The official MCP reduces the need to run another privileged third-party component when those deeper capabilities are unnecessary.
| Attribute | Community n8n-MCP | Official n8n MCP |
|---|---|---|
| Publisher | Romuald Czlonkowski | n8n |
| Primary role | Deep n8n knowledge + workflow management | First-party instance-level MCP access |
| Node-schema knowledge | Extensive local database | Native n8n capability surface |
| Dedicated node validation | Yes | Different native workflow path |
| Template search | Yes | Not the core differentiator |
| Create/edit workflows | Yes | Yes |
| Partial diff editing | Major feature | Different implementation |
| Extra third-party component | Yes | No |
| Community telemetry | Enabled by default unless disabled | Not the same telemetry system |
The question is no longer “MCP or no MCP.” It is whether the community server's deeper workflow intelligence justifies another privileged component beside n8n.
n8n MCP server vs n8n MCP client
The phrase n8n MCP can describe two opposite connection directions. The community n8n-mcp package is an MCP server. n8n itself can also act as an MCP client through dedicated client nodes.
AI client → n8n
Claude Code, Cursor, Codex or another MCP client invokes tools exposed by n8n-MCP or n8n's official MCP server.
n8n → external MCP
An n8n workflow connects outward to tools exposed by another MCP server using n8n's MCP client functionality.
n8n also provides an MCP Server Trigger for exposing a workflow-defined tool surface. That is related to, but distinct from, the community n8n-MCP server and the official instance-level MCP server.
What can n8n-MCP do?
n8n-MCP combines n8n knowledge tools with a large management surface. It can research nodes, inspect schemas, find templates, validate configurations, create workflows, edit workflows, execute tests, inspect failures, manage versions, administer credentials and data tables, and audit an n8n instance.
| Capability group | What it enables |
|---|---|
| Node discovery | Search n8n core and community nodes. |
| Node inspection | Retrieve properties, versions, documentation and examples. |
| Node validation | Check required fields and complete configuration. |
| Workflow validation | Validate connections, expressions and workflow structure. |
| Template discovery | Search and retrieve reusable workflow templates. |
| Workflow creation | Create workflows through n8n management access. |
| Workflow editing | Replace complete workflows or apply targeted diffs. |
| Workflow execution | Trigger workflows and inspect execution results. |
| Workflow versions | Inspect, compare, roll back or remove stored versions. |
| Credentials | List, inspect, create, update and delete credentials where allowed. |
| Data tables | Read and modify tables, rows and columns. |
| Security / audit | Run workflow and instance-oriented checks. |
The project's partial-workflow update path sends targeted changes instead of repeatedly replacing full workflow JSON. Publisher documentation reports 80–90% token reduction for incremental edits compared with full replacement; treat that percentage as publisher-measured rather than independently benchmarked.
n8n-MCP tool inventory
The tool count is not completely fixed across documentation and deployment modes. The evaluated README documented 7 core knowledge tools plus 16 n8n management tools, while newer HTTP deployment documentation described configurations exposing up to 28 total tools.
The safest client-facing wording is therefore 23 documented in the evaluated main README; up to 28 in newer configured deployments.
| Core knowledge tool | Purpose |
|---|---|
search_nodes | Find relevant n8n nodes. |
get_node | Retrieve node schema and documentation. |
validate_node | Validate node configuration. |
validate_workflow | Validate workflow structure and configuration. |
search_templates | Find reusable n8n templates. |
get_template | Retrieve a selected template. |
| Additional knowledge utility | The current documented surface has grown over time. |
n8n-MCP has expanded quickly. Tool availability and count should be checked against the installed release and deployment mode.
How does n8n-MCP work?
n8n-MCP sits between an AI client and n8n. The server supplies local node knowledge, exposes MCP tools to the AI client, and uses configured n8n credentials when a tool must inspect or change a real instance.
Documentation-only operation can stay on the local knowledge path. Management operations contact the configured n8n instance using N8N_API_URL and N8N_API_KEY. HTTP deployments add a separate MCP authentication token.
What access does n8n-MCP get?
n8n-MCP receives the effective permissions of the credentials configured for its n8n connection. A broadly privileged API key can allow an AI agent to create, replace, partially edit, delete, execute and repair workflows while also exposing management operations for executions, credentials, tables and versions.
That creates a large blast radius when the server is attached to production credentials.
| Potential write surface | Operational effect |
|---|---|
| Create workflows | Add new automation logic. |
| Replace workflows | Overwrite complete workflow state. |
| Partial workflow edits | Apply targeted changes to live workflows. |
| Delete workflows | Permanently remove automation. |
| Execute workflows | Trigger live downstream effects. |
| Manage versions | Roll back or delete stored versions. |
| Manage credentials | Create, update or delete integration credentials. |
| Modify Data Tables | Change n8n-managed structured data. |
How to reduce the blast radius
- use a dedicated n8n API key;
- disable tools that are not required;
- disable specific destructive operations;
- remove credential-management tools unless explicitly needed;
- prefer read-only or limited-write deployments for production;
- test destructive operations only against disposable data.
Is n8n-MCP safe?
n8n-MCP has useful hardening controls, but MCPVerdict assigns Scan Grade C because the server legitimately handles credentials and can perform high-impact writes. Production safety depends on current versions, constrained credentials, disabled destructive tools, protected HTTP transport and deliberate telemetry settings.
The project publishes a security policy and hardening guidance. That is a positive signal. It does not erase the importance of its recent security history.
Reviewed 2026 issues included a critical cross-tenant workflow-version backup flaw, high-severity credential-isolation and SSRF defects, HTTP information-disclosure problems, sensitive logging issues and a telemetry-sanitization vulnerability. Known issues were patched, so historical severity should not be misrepresented as proof that the evaluated latest release remained vulnerable.
The correct interpretation is:
Historically serious security record ≠ current release proven vulnerable.
It does mean update discipline and permission containment are part of the product's operating model.
What telemetry does n8n-MCP collect?
Anonymous telemetry is enabled by default unless explicitly disabled. The project's privacy documentation says sanitized data is used for feature usage analysis, error analysis, product improvement, development prioritization and workflow-generation ML training, with telemetry stored through Supabase.
Disable it with:
N8N_MCP_TELEMETRY_DISABLED=true
A reviewed May 2026 security advisory found that earlier versions could retain fragments from URL-shaped workflow values before telemetry transmission. That issue was patched in version 2.51.3.
For sensitive production workflows, disable telemetry unless participation is deliberate. The setting is easy to change, and workflow data can contain operational identifiers that deserve a conservative default.
MCP 2026-07-28 compatibility
Current 2026-07-28 MCP conformance is not proven. The evaluated repository used @modelcontextprotocol/sdk 1.28.0, while later development showed ongoing stateless-transport and conformance work.
An August 2026 issue still reported a protocol requirement violation even against an older specification target. MCPVerdict therefore classifies the status as Unknown / Transitional rather than Adopted.
How much context does n8n-MCP use?
n8n-MCP can consume substantial model context because there are two different costs: the initial tool-schema surface and the data returned during workflow construction.
1. Tool-schema cost
For a broadly enabled deployment exposing roughly 23–28 tools, the evaluation estimates approximately 8,000–15,000 input tokens of schema overhead. This is an estimate, not a universal measured count.
2. Tool-result cost
Results from node retrieval, templates, complete workflows, executions and validators can add thousands to tens of thousands of tokens during a serious workflow build.
3. Partial updates help
The project's diff-based editing avoids repeatedly sending complete workflow JSON. Publisher documentation claims 80–90% token reduction for incremental edits versus full workflow replacement.
The server is efficient when applying small edits, but a repeated build/debug session can still become context-heavy because the model frequently needs node definitions, validation responses, workflow state and execution output.
What does a realistic n8n-MCP run cost?
The MCP package itself is free. Real cost comes from model usage, n8n hosting or plan costs, server infrastructure, workflow executions and the APIs called by those workflows.
A realistic evaluation budget for a moderately complex workflow is approximately 60K input + 20K output tokens. That is an evaluation estimate, not a measured universal session size.
| Model | Pricing used | Approx. 60K input + 20K output |
|---|---|---|
| Claude Opus 5 Anthropic | $5/M input · $25/M output | $0.80 |
| Claude Sonnet 5 Anthropic | $2/M input · $10/M output | $0.32 |
| GPT-5.6 Sol OpenAI | $4/M input · $20/M output | $0.64 |
| Gemini 2.5 Pro | $1.25/M input · $10/M output | $0.275 |
| Local / open model | API $0 | Compute only |
Those figures describe model inference, not the price of installing n8n-MCP. Subscription products may express practical cost through plan quotas rather than a direct charge per MCP call.
Hidden costs
- n8n Cloud plan or self-hosted infrastructure;
- Docker/Node hosting for persistent remote MCP deployment;
- third-party APIs called by workflows;
- security hardening and maintenance;
- context consumed during long workflow-debugging sessions;
- human review when validators or writes behave unexpectedly.
How to install and connect n8n-MCP
n8n-MCP can run locally through npm or as a persistent remote server through Docker/HTTP. Documentation-only operation needs no n8n credentials. Workflow management requires the n8n instance URL and API key.
Local stdio
npx n8n-mcp
Global npm install
npm install -g n8n-mcp
Enable n8n management
N8N_API_URL=https://your-n8n-instance.com
N8N_API_KEY=your-n8n-api-key
HTTP server URL
A local HTTP deployment commonly exposes:
http://localhost:3000/mcp
A remote deployment exposes the same /mcp path under its configured host and should be protected with HTTPS and MCP authentication.
Verify before granting broad write access
- Connect with documentation-only or restricted tools first.
- Confirm node search and validation work.
- Attach a disposable n8n instance.
- Create and validate one simple workflow.
- Test a targeted partial update.
- Only then consider production credentials or broader management tools.
Can n8n-MCP be self-hosted?
Yes. n8n-MCP supports local npm execution, Docker and persistent HTTP deployment. Self-hosting gives the operator control over transport, authentication and network placement, but it does not remove the credential and permission risks of management access.
A public HTTP deployment adds its own operational requirements: HTTPS, proxy configuration, secret storage, rate limiting, network policy and careful client authentication.
For sensitive use, a local stdio deployment against a disposable or tightly permissioned n8n instance is the simplest place to start.
Which AI clients work with n8n-MCP?
n8n-MCP is designed for MCP-compatible clients using stdio or HTTP. The evaluated profile includes Claude Desktop, Claude Code, Cursor, Windsurf, Codex and similar agentic clients.
| Client | Typical use | Connection |
|---|---|---|
| Claude Desktop | Local MCP-assisted n8n work | stdio / configured MCP |
| Claude Code | Agentic workflow building and editing | stdio or remote MCP |
| Cursor | Coding-agent workflow construction | MCP configuration |
| Codex | Agentic workflow construction and iteration | MCP configuration |
| Windsurf | Development-environment MCP workflow | MCP configuration |
| Other compatible clients | Depends on transport and tool support | stdio or HTTP |
Client support and model support are separate. The MCP client manages the connection; the language model handles reasoning and tool selection.
n8n-MCP vs the n8n API
The n8n API exposes programmatic n8n operations; n8n-MCP packages those operations for AI agents and adds node knowledge, schema retrieval, validation, templates and workflow-editing semantics.
| Attribute | n8n-MCP | n8n API |
|---|---|---|
| Primary consumer | AI agent / MCP client | Application / developer |
| Interaction model | Discoverable tools | HTTP API calls |
| Node knowledge | Built into the server | Developer must supply needed domain knowledge |
| Validation | Dedicated agent-facing tools | Application must implement validation logic |
| Templates | Search/retrieval tools | Not an agent-native abstraction |
| Workflow mutation | Model chooses tools | Application calls endpoints directly |
| Control | Higher agent autonomy | More deterministic application logic |
Use the API when deterministic application logic is more important than agent autonomy. Use n8n-MCP when the AI agent itself must discover nodes, construct workflows and iteratively repair them.
If you are deciding between agent-selected tools and deterministic integrations, read our MCP versus API comparison.
Where n8n-MCP is strongest — and where it falls short
High-value fit
- Repeated AI-assisted n8n workflow construction.
- Incrementally modifying existing workflows.
- Debugging and validating workflow configuration.
- Searching detailed n8n node documentation.
- Managing live n8n resources with carefully constrained permissions.
- Agentic clients that benefit from targeted diff editing.
Where value drops
- Casual or occasional n8n questions.
- Highly sensitive production instances with broad credentials.
- Teams unwilling to restrict destructive tools.
- Sessions where context/token efficiency is critical.
- Environments requiring verified current-spec conformance.
- Cases where n8n's official MCP already covers the needed workflow.
The cheapest sensible test
Run n8n-MCP locally through stdio, disable telemetry, use a disposable n8n instance and expose only the workflow read/create/update tools needed for the evaluation.
Run the same five workflows against community n8n-MCP and n8n's official MCP. Measure:
- first-attempt workflow correctness;
- number of repair turns;
- total input/output tokens;
- node and schema lookups required;
- quality of validation errors;
- precision of partial edits;
- permissions required to finish the task.
The result tells you much more than simply asking whether n8n-MCP “works.”
n8n-MCP technical details
Show the full technical profile
| Attribute | Evaluated value |
|---|---|
| Canonical repository | https://github.com/czlonkowski/n8n-mcp |
| Publisher | Romuald Czlonkowski |
| Type | Community n8n-specific MCP server |
| Evaluated version | 2.87.0 |
| Evaluation date | September 2026 |
| License | MIT |
| Transport | stdio + HTTP |
| n8n management authentication | N8N_API_URL + N8N_API_KEY |
| HTTP authentication | MCP auth token |
| Docker deployment | Supported |
| Telemetry | Enabled by default; can be disabled |
| Known hardcoded secrets | None found in evaluation |
| Documented core tools | 7 |
| Documented management tools | 16 in evaluated README; newer configured deployments up to 28 total |
| Native write capability | Yes |
| Scan grade | C |
| Overall score | 72/100 |
| Confidence | Moderate |
| MCP 2026-07-28 | Unknown / transitional |
Recent n8n-MCP evidence
The evaluated evidence corpus includes recent user comparisons, reproducible GitHub issues, reviewed security advisories and current maintenance activity.
Evidence confidence: Strong. Overall verdict confidence: Moderate because no controlled live A/B benchmark was run.
Show the evidence findings
- Mar 2026: user report found successful workflow building but very high context consumption and parameter/expression mistakes on complex builds.
- Mar 2026: comparison estimated the official MCP path at roughly 31K tokens across 11 calls and found community n8n-MCP significantly heavier.
- May 2026: official-vs-community comparison found community n8n-MCP useful for iteration while the official MCP had a cleaner/lighter initial build path.
- Apr 2026: sensitive request metadata could be logged for unauthorized HTTP MCP calls; patched in 2.47.11.
- Apr–May 2026: multiple SSRF vulnerabilities affected HTTP/API paths and were patched.
- May 2026: telemetry sanitizer could transmit fragments of URL-shaped workflow values; patched in 2.51.3.
- May 2026: multi-tenant request handling could fall back to process-level n8n credentials.
- Jun 2026: cross-tenant workflow backup exposure received a Critical advisory.
- May 2026: API authentication behind Kubernetes ingress could fail while health checks still reported connected.
- Jun 2026: multi-instance credential creation could target the wrong instance.
- Jul 2026: telemetry processing could make mutation calls hang in stdio mode until telemetry was disabled; issue later fixed.
- Aug 2026: conformance testing still found an MCP protocol requirement violation.
- Aug 2026: workflow validation could intermittently terminate connections.
- Sep 2026: recent reports included validator false positives and execution-error misreporting.
- Sep 2026: project remained exceptionally active, with frequent releases and more than 100 commits in the preceding 90 days.
Frequently asked questions
Can n8n serve as an MCP server?
Yes. n8n now has its own official instance-level MCP server, while the community n8n-mcp project is a separate MCP server that adds deeper node knowledge, validation and workflow-management tooling.
What is n8n-MCP?
n8n-MCP is a community MCP server that gives AI clients structured n8n node knowledge and, when configured with n8n credentials, tools for creating, validating, editing, executing and administering workflows.
Is n8n-MCP the same as n8n's official MCP?
No. The community project is maintained independently. n8n's official MCP is first-party and reduces the need for a separate privileged component when its native capabilities are sufficient.
Is n8n-MCP an MCP client?
No. The czlonkowski/n8n-mcp package is an MCP server. n8n itself has separate MCP client functionality for calling external MCP servers.
Does n8n-MCP work with Claude?
Yes. The evaluated profile supports Claude Desktop and Claude Code, together with other MCP-compatible clients such as Cursor, Windsurf and Codex.
Can Cursor use n8n-MCP?
Yes. Cursor can connect through its MCP configuration and use n8n-MCP as a workflow-building and debugging tool server.
Can Codex use n8n-MCP?
Yes, provided the Codex environment has MCP support and the n8n-MCP server is configured with the required transport and credentials.
Can n8n-MCP be self-hosted?
Yes. It can run locally through npm or in Docker/HTTP mode. Self-hosting changes network control, not the underlying credential and write risks.
What is the n8n-MCP server URL?
A local HTTP deployment commonly exposes http://localhost:3000/mcp. Remote deployments use the same /mcp path under the configured host.
Is n8n-MCP free?
The MCP package is MIT-licensed and free to install. Real cost comes from model usage, n8n hosting or plan costs, server infrastructure, workflow executions and third-party APIs.
What is MCP vs the n8n API?
The API is a conventional programmatic interface. n8n-MCP gives AI agents discoverable tools plus node knowledge, validation and workflow-specific abstractions on top of n8n access.
Does n8n-MCP collect telemetry?
Yes. Anonymous telemetry is enabled by default unless disabled with N8N_MCP_TELEMETRY_DISABLED=true.