Server profile · Evaluated September 2026

n8n-MCP

A community MCP server for giving AI agents deep n8n node knowledge plus tools to inspect, build, validate, modify, execute and administer n8n workflows. Its strongest advantage is workflow-specific intelligence and precise incremental editing; its tradeoffs are broad permissions, high context usage, telemetry and a serious recent security history.

Automation stdio + HTTP MIT Write capable
Publisher
Romuald Czlonkowski
Community project
Tool surface
23–28
Deployment-dependent
Transport
stdio + HTTP
Local or remote
Management auth
n8n API key
API URL + key
Context impact
High
Score 55 / 100
Write capability
Yes
Broad management surface

Start with Decision, Score, Official vs Community, Access, Safety, Token Cost and Fit. Use Setup for implementation details and the lower sections for technical evidence.

Should you use n8n-MCP?

Best for

Serious n8n builders who repeatedly create, debug and modify workflows through Claude Code, Cursor, Codex or similar agentic clients.

Think twice when

You are a casual n8n user, work with highly sensitive production instances, or can meet your needs with n8n's first-party MCP without running another privileged component.

Main advantage

Deep n8n-specific node knowledge, validation and precise diff-based workflow editing that reduce schema guessing during agentic workflow construction.

Main tradeoff

Large permissions, large context, enabled-by-default telemetry and a substantial 2026 security history make production configuration important.

MCPVerdict view

n8n-MCP is valuable when its node intelligence, validation and incremental editing materially improve repeated workflow development. It is not the default choice merely because someone wants MCP access to n8n.

Why n8n-MCP scores 72/100

The 72/100 score is weighted around the job that matters most: letting an AI agent construct and modify working n8n automation without creating unacceptable operational risk.

Feature breadth therefore does not automatically improve the verdict. Workflow correctness, credential containment, safe failure reporting, context efficiency and security boundaries matter more than the number of exposed tools.

Universal parameterScoreFinding
Effectiveness82Extensive workflow construction, validation, debugging and management capability.
Reliability68Active project, but recent validator, execution and authentication bugs reduce confidence.
Safety57Strong hardening controls exist, but broad write authority and recent CVEs matter.
Efficiency63Partial updates are efficient; node and workflow context can become large.
Compatibility73Broad client support, but current-spec conformance is not proven.
Maintainability91Rapid releases and active development.
Setup friction72Easy for documentation use; API and remote production deployments require more care.

n8n-specific parameters

ParameterScoreWhy it matters
Workflow correctness75Strong schemas and validation, but generated workflows can still require repair.
Incremental editing88Targeted workflow diffs are one of the project's strongest differentiators.
Validation fidelity66False positives and validator failures reduce trust in automated repair loops.
Credential/write containment68Good controls exist, but safe deployments require deliberate restriction.
Context efficiency55Large schemas and tool results can consume substantial model context.
Schema freshness88Frequent updates help keep node definitions aligned with current n8n releases.
Safe failure reporting62Historical false-success and misleading health signals matter in agentic workflows.
Official-MCP differentiation73The community server remains deeper in several areas, but n8n's native MCP is now a strong alternative.
Why confidence is Moderate

The documentary evidence is strong, but there is no controlled live A/B benchmark showing how often a modern agent produces a working workflow on the first attempt with community n8n-MCP versus n8n's official MCP.

What is n8n-MCP?

n8n-MCP is a community Model Context Protocol server that gives AI clients structured knowledge about n8n nodes and, when n8n API credentials are configured, direct tools for creating, inspecting, validating, editing, executing and administering n8n workflows.

The server has two operating layers. The first is a local knowledge layer for node search, node definitions, validation and template discovery. The second is a management layer that uses N8N_API_URL and N8N_API_KEY to act on a real n8n instance.

Those two layers have different risk profiles. Documentation-only use does not need n8n credentials. Management use can affect live workflows, executions, credentials and data.

Community n8n-MCP vs n8n's official MCP

The community czlonkowski/n8n-mcp project is not the same product as n8n's official instance-level MCP server. Both connect AI clients with n8n, but they expose different capability surfaces and trust boundaries.

The community project's remaining differentiation is deeper node intelligence, dedicated validation, template discovery, resource resolution and precise incremental workflow editing. The official MCP reduces the need to run another privileged third-party component when those deeper capabilities are unnecessary.

AttributeCommunity n8n-MCPOfficial n8n MCP
PublisherRomuald Czlonkowskin8n
Primary roleDeep n8n knowledge + workflow managementFirst-party instance-level MCP access
Node-schema knowledgeExtensive local databaseNative n8n capability surface
Dedicated node validationYesDifferent native workflow path
Template searchYesNot the core differentiator
Create/edit workflowsYesYes
Partial diff editingMajor featureDifferent implementation
Extra third-party componentYesNo
Community telemetryEnabled by default unless disabledNot the same telemetry system
The comparison is now fundamental

The question is no longer “MCP or no MCP.” It is whether the community server's deeper workflow intelligence justifies another privileged component beside n8n.

n8n MCP server vs n8n MCP client

The phrase n8n MCP can describe two opposite connection directions. The community n8n-mcp package is an MCP server. n8n itself can also act as an MCP client through dedicated client nodes.

n8n as server

AI client → n8n

Claude Code, Cursor, Codex or another MCP client invokes tools exposed by n8n-MCP or n8n's official MCP server.

n8n as client

n8n → external MCP

An n8n workflow connects outward to tools exposed by another MCP server using n8n's MCP client functionality.

n8n also provides an MCP Server Trigger for exposing a workflow-defined tool surface. That is related to, but distinct from, the community n8n-MCP server and the official instance-level MCP server.

What can n8n-MCP do?

n8n-MCP combines n8n knowledge tools with a large management surface. It can research nodes, inspect schemas, find templates, validate configurations, create workflows, edit workflows, execute tests, inspect failures, manage versions, administer credentials and data tables, and audit an n8n instance.

Capability groupWhat it enables
Node discoverySearch n8n core and community nodes.
Node inspectionRetrieve properties, versions, documentation and examples.
Node validationCheck required fields and complete configuration.
Workflow validationValidate connections, expressions and workflow structure.
Template discoverySearch and retrieve reusable workflow templates.
Workflow creationCreate workflows through n8n management access.
Workflow editingReplace complete workflows or apply targeted diffs.
Workflow executionTrigger workflows and inspect execution results.
Workflow versionsInspect, compare, roll back or remove stored versions.
CredentialsList, inspect, create, update and delete credentials where allowed.
Data tablesRead and modify tables, rows and columns.
Security / auditRun workflow and instance-oriented checks.
Incremental editing is a real differentiator

The project's partial-workflow update path sends targeted changes instead of repeatedly replacing full workflow JSON. Publisher documentation reports 80–90% token reduction for incremental edits compared with full replacement; treat that percentage as publisher-measured rather than independently benchmarked.

n8n-MCP tool inventory

The tool count is not completely fixed across documentation and deployment modes. The evaluated README documented 7 core knowledge tools plus 16 n8n management tools, while newer HTTP deployment documentation described configurations exposing up to 28 total tools.

The safest client-facing wording is therefore 23 documented in the evaluated main README; up to 28 in newer configured deployments.

Core knowledge toolPurpose
search_nodesFind relevant n8n nodes.
get_nodeRetrieve node schema and documentation.
validate_nodeValidate node configuration.
validate_workflowValidate workflow structure and configuration.
search_templatesFind reusable n8n templates.
get_templateRetrieve a selected template.
Additional knowledge utilityThe current documented surface has grown over time.
Do not treat the tool count as a permanent constant

n8n-MCP has expanded quickly. Tool availability and count should be checked against the installed release and deployment mode.

How does n8n-MCP work?

n8n-MCP sits between an AI client and n8n. The server supplies local node knowledge, exposes MCP tools to the AI client, and uses configured n8n credentials when a tool must inspect or change a real instance.

AI clientClaude / Cursor / Codex
MCP sessionstdio or HTTP
n8n-MCPknowledge + tools
n8n APIcredential boundary
n8n instanceworkflows / data

Documentation-only operation can stay on the local knowledge path. Management operations contact the configured n8n instance using N8N_API_URL and N8N_API_KEY. HTTP deployments add a separate MCP authentication token.

What access does n8n-MCP get?

n8n-MCP receives the effective permissions of the credentials configured for its n8n connection. A broadly privileged API key can allow an AI agent to create, replace, partially edit, delete, execute and repair workflows while also exposing management operations for executions, credentials, tables and versions.

That creates a large blast radius when the server is attached to production credentials.

Potential write surfaceOperational effect
Create workflowsAdd new automation logic.
Replace workflowsOverwrite complete workflow state.
Partial workflow editsApply targeted changes to live workflows.
Delete workflowsPermanently remove automation.
Execute workflowsTrigger live downstream effects.
Manage versionsRoll back or delete stored versions.
Manage credentialsCreate, update or delete integration credentials.
Modify Data TablesChange n8n-managed structured data.

How to reduce the blast radius

  • use a dedicated n8n API key;
  • disable tools that are not required;
  • disable specific destructive operations;
  • remove credential-management tools unless explicitly needed;
  • prefer read-only or limited-write deployments for production;
  • test destructive operations only against disposable data.

Is n8n-MCP safe?

n8n-MCP has useful hardening controls, but MCPVerdict assigns Scan Grade C because the server legitimately handles credentials and can perform high-impact writes. Production safety depends on current versions, constrained credentials, disabled destructive tools, protected HTTP transport and deliberate telemetry settings.

The project publishes a security policy and hardening guidance. That is a positive signal. It does not erase the importance of its recent security history.

Recent security history matters

Reviewed 2026 issues included a critical cross-tenant workflow-version backup flaw, high-severity credential-isolation and SSRF defects, HTTP information-disclosure problems, sensitive logging issues and a telemetry-sanitization vulnerability. Known issues were patched, so historical severity should not be misrepresented as proof that the evaluated latest release remained vulnerable.

The correct interpretation is:

Historically serious security record ≠ current release proven vulnerable.

It does mean update discipline and permission containment are part of the product's operating model.

What telemetry does n8n-MCP collect?

Anonymous telemetry is enabled by default unless explicitly disabled. The project's privacy documentation says sanitized data is used for feature usage analysis, error analysis, product improvement, development prioritization and workflow-generation ML training, with telemetry stored through Supabase.

Disable it with:

N8N_MCP_TELEMETRY_DISABLED=true

A reviewed May 2026 security advisory found that earlier versions could retain fragments from URL-shaped workflow values before telemetry transmission. That issue was patched in version 2.51.3.

MCPVerdict recommendation

For sensitive production workflows, disable telemetry unless participation is deliberate. The setting is easy to change, and workflow data can contain operational identifiers that deserve a conservative default.

MCP 2026-07-28 compatibility

Current 2026-07-28 MCP conformance is not proven. The evaluated repository used @modelcontextprotocol/sdk 1.28.0, while later development showed ongoing stateless-transport and conformance work.

An August 2026 issue still reported a protocol requirement violation even against an older specification target. MCPVerdict therefore classifies the status as Unknown / Transitional rather than Adopted.

How much context does n8n-MCP use?

n8n-MCP can consume substantial model context because there are two different costs: the initial tool-schema surface and the data returned during workflow construction.

1. Tool-schema cost

For a broadly enabled deployment exposing roughly 23–28 tools, the evaluation estimates approximately 8,000–15,000 input tokens of schema overhead. This is an estimate, not a universal measured count.

2. Tool-result cost

Results from node retrieval, templates, complete workflows, executions and validators can add thousands to tens of thousands of tokens during a serious workflow build.

3. Partial updates help

The project's diff-based editing avoids repeatedly sending complete workflow JSON. Publisher documentation claims 80–90% token reduction for incremental edits versus full workflow replacement.

Why context efficiency scores 55

The server is efficient when applying small edits, but a repeated build/debug session can still become context-heavy because the model frequently needs node definitions, validation responses, workflow state and execution output.

What does a realistic n8n-MCP run cost?

The MCP package itself is free. Real cost comes from model usage, n8n hosting or plan costs, server infrastructure, workflow executions and the APIs called by those workflows.

A realistic evaluation budget for a moderately complex workflow is approximately 60K input + 20K output tokens. That is an evaluation estimate, not a measured universal session size.

ModelPricing usedApprox. 60K input + 20K output
Claude Opus 5
Anthropic
$5/M input · $25/M output$0.80
Claude Sonnet 5
Anthropic
$2/M input · $10/M output$0.32
GPT-5.6 Sol
OpenAI
$4/M input · $20/M output$0.64
Gemini 2.5 Pro
Google
$1.25/M input · $10/M output$0.275
Local / open modelAPI $0Compute only

Those figures describe model inference, not the price of installing n8n-MCP. Subscription products may express practical cost through plan quotas rather than a direct charge per MCP call.

Hidden costs

  • n8n Cloud plan or self-hosted infrastructure;
  • Docker/Node hosting for persistent remote MCP deployment;
  • third-party APIs called by workflows;
  • security hardening and maintenance;
  • context consumed during long workflow-debugging sessions;
  • human review when validators or writes behave unexpectedly.

How to install and connect n8n-MCP

n8n-MCP can run locally through npm or as a persistent remote server through Docker/HTTP. Documentation-only operation needs no n8n credentials. Workflow management requires the n8n instance URL and API key.

Local stdio

npx n8n-mcp

Global npm install

npm install -g n8n-mcp

Enable n8n management

N8N_API_URL=https://your-n8n-instance.com
N8N_API_KEY=your-n8n-api-key

HTTP server URL

A local HTTP deployment commonly exposes:

http://localhost:3000/mcp

A remote deployment exposes the same /mcp path under its configured host and should be protected with HTTPS and MCP authentication.

Verify before granting broad write access

  1. Connect with documentation-only or restricted tools first.
  2. Confirm node search and validation work.
  3. Attach a disposable n8n instance.
  4. Create and validate one simple workflow.
  5. Test a targeted partial update.
  6. Only then consider production credentials or broader management tools.

Can n8n-MCP be self-hosted?

Yes. n8n-MCP supports local npm execution, Docker and persistent HTTP deployment. Self-hosting gives the operator control over transport, authentication and network placement, but it does not remove the credential and permission risks of management access.

A public HTTP deployment adds its own operational requirements: HTTPS, proxy configuration, secret storage, rate limiting, network policy and careful client authentication.

For sensitive use, a local stdio deployment against a disposable or tightly permissioned n8n instance is the simplest place to start.

Which AI clients work with n8n-MCP?

n8n-MCP is designed for MCP-compatible clients using stdio or HTTP. The evaluated profile includes Claude Desktop, Claude Code, Cursor, Windsurf, Codex and similar agentic clients.

ClientTypical useConnection
Claude DesktopLocal MCP-assisted n8n workstdio / configured MCP
Claude CodeAgentic workflow building and editingstdio or remote MCP
CursorCoding-agent workflow constructionMCP configuration
CodexAgentic workflow construction and iterationMCP configuration
WindsurfDevelopment-environment MCP workflowMCP configuration
Other compatible clientsDepends on transport and tool supportstdio or HTTP

Client support and model support are separate. The MCP client manages the connection; the language model handles reasoning and tool selection.

n8n-MCP vs the n8n API

The n8n API exposes programmatic n8n operations; n8n-MCP packages those operations for AI agents and adds node knowledge, schema retrieval, validation, templates and workflow-editing semantics.

Attributen8n-MCPn8n API
Primary consumerAI agent / MCP clientApplication / developer
Interaction modelDiscoverable toolsHTTP API calls
Node knowledgeBuilt into the serverDeveloper must supply needed domain knowledge
ValidationDedicated agent-facing toolsApplication must implement validation logic
TemplatesSearch/retrieval toolsNot an agent-native abstraction
Workflow mutationModel chooses toolsApplication calls endpoints directly
ControlHigher agent autonomyMore deterministic application logic

Use the API when deterministic application logic is more important than agent autonomy. Use n8n-MCP when the AI agent itself must discover nodes, construct workflows and iteratively repair them.

If you are deciding between agent-selected tools and deterministic integrations, read our MCP versus API comparison.

Where n8n-MCP is strongest — and where it falls short

Strongest use cases

High-value fit

  • Repeated AI-assisted n8n workflow construction.
  • Incrementally modifying existing workflows.
  • Debugging and validating workflow configuration.
  • Searching detailed n8n node documentation.
  • Managing live n8n resources with carefully constrained permissions.
  • Agentic clients that benefit from targeted diff editing.
Main limitations

Where value drops

  • Casual or occasional n8n questions.
  • Highly sensitive production instances with broad credentials.
  • Teams unwilling to restrict destructive tools.
  • Sessions where context/token efficiency is critical.
  • Environments requiring verified current-spec conformance.
  • Cases where n8n's official MCP already covers the needed workflow.

The cheapest sensible test

Run n8n-MCP locally through stdio, disable telemetry, use a disposable n8n instance and expose only the workflow read/create/update tools needed for the evaluation.

Run the same five workflows against community n8n-MCP and n8n's official MCP. Measure:

  • first-attempt workflow correctness;
  • number of repair turns;
  • total input/output tokens;
  • node and schema lookups required;
  • quality of validation errors;
  • precision of partial edits;
  • permissions required to finish the task.

The result tells you much more than simply asking whether n8n-MCP “works.”

n8n-MCP technical details

Show the full technical profile
AttributeEvaluated value
Canonical repositoryhttps://github.com/czlonkowski/n8n-mcp
PublisherRomuald Czlonkowski
TypeCommunity n8n-specific MCP server
Evaluated version2.87.0
Evaluation dateSeptember 2026
LicenseMIT
Transportstdio + HTTP
n8n management authenticationN8N_API_URL + N8N_API_KEY
HTTP authenticationMCP auth token
Docker deploymentSupported
TelemetryEnabled by default; can be disabled
Known hardcoded secretsNone found in evaluation
Documented core tools7
Documented management tools16 in evaluated README; newer configured deployments up to 28 total
Native write capabilityYes
Scan gradeC
Overall score72/100
ConfidenceModerate
MCP 2026-07-28Unknown / transitional

Recent n8n-MCP evidence

The evaluated evidence corpus includes recent user comparisons, reproducible GitHub issues, reviewed security advisories and current maintenance activity.

Evidence confidence: Strong. Overall verdict confidence: Moderate because no controlled live A/B benchmark was run.

Show the evidence findings
  1. Mar 2026: user report found successful workflow building but very high context consumption and parameter/expression mistakes on complex builds.
  2. Mar 2026: comparison estimated the official MCP path at roughly 31K tokens across 11 calls and found community n8n-MCP significantly heavier.
  3. May 2026: official-vs-community comparison found community n8n-MCP useful for iteration while the official MCP had a cleaner/lighter initial build path.
  4. Apr 2026: sensitive request metadata could be logged for unauthorized HTTP MCP calls; patched in 2.47.11.
  5. Apr–May 2026: multiple SSRF vulnerabilities affected HTTP/API paths and were patched.
  6. May 2026: telemetry sanitizer could transmit fragments of URL-shaped workflow values; patched in 2.51.3.
  7. May 2026: multi-tenant request handling could fall back to process-level n8n credentials.
  8. Jun 2026: cross-tenant workflow backup exposure received a Critical advisory.
  9. May 2026: API authentication behind Kubernetes ingress could fail while health checks still reported connected.
  10. Jun 2026: multi-instance credential creation could target the wrong instance.
  11. Jul 2026: telemetry processing could make mutation calls hang in stdio mode until telemetry was disabled; issue later fixed.
  12. Aug 2026: conformance testing still found an MCP protocol requirement violation.
  13. Aug 2026: workflow validation could intermittently terminate connections.
  14. Sep 2026: recent reports included validator false positives and execution-error misreporting.
  15. Sep 2026: project remained exceptionally active, with frequent releases and more than 100 commits in the preceding 90 days.

Frequently asked questions

Can n8n serve as an MCP server?

Yes. n8n now has its own official instance-level MCP server, while the community n8n-mcp project is a separate MCP server that adds deeper node knowledge, validation and workflow-management tooling.

What is n8n-MCP?

n8n-MCP is a community MCP server that gives AI clients structured n8n node knowledge and, when configured with n8n credentials, tools for creating, validating, editing, executing and administering workflows.

Is n8n-MCP the same as n8n's official MCP?

No. The community project is maintained independently. n8n's official MCP is first-party and reduces the need for a separate privileged component when its native capabilities are sufficient.

Is n8n-MCP an MCP client?

No. The czlonkowski/n8n-mcp package is an MCP server. n8n itself has separate MCP client functionality for calling external MCP servers.

Does n8n-MCP work with Claude?

Yes. The evaluated profile supports Claude Desktop and Claude Code, together with other MCP-compatible clients such as Cursor, Windsurf and Codex.

Can Cursor use n8n-MCP?

Yes. Cursor can connect through its MCP configuration and use n8n-MCP as a workflow-building and debugging tool server.

Can Codex use n8n-MCP?

Yes, provided the Codex environment has MCP support and the n8n-MCP server is configured with the required transport and credentials.

Can n8n-MCP be self-hosted?

Yes. It can run locally through npm or in Docker/HTTP mode. Self-hosting changes network control, not the underlying credential and write risks.

What is the n8n-MCP server URL?

A local HTTP deployment commonly exposes http://localhost:3000/mcp. Remote deployments use the same /mcp path under the configured host.

Is n8n-MCP free?

The MCP package is MIT-licensed and free to install. Real cost comes from model usage, n8n hosting or plan costs, server infrastructure, workflow executions and third-party APIs.

What is MCP vs the n8n API?

The API is a conventional programmatic interface. n8n-MCP gives AI agents discoverable tools plus node knowledge, validation and workflow-specific abstractions on top of n8n access.

Does n8n-MCP collect telemetry?

Yes. Anonymous telemetry is enabled by default unless disabled with N8N_MCP_TELEMETRY_DISABLED=true.

Evaluating this for a team?

Check the choice against your workflow, clients, permissions, deployment, and alternatives.

Team evaluation
Cookie policy · Disclaimer