n8n MCP: Using n8n as an MCP Server and Client
n8n speaks MCP in both directions. As a server, it lets Claude, Cursor or Codex find, run and even build your workflows; as a client, its nodes call any MCP server. Which of the four routes to use, how to add n8n to Claude, and what each one exposes.
7 min read
n8n works with MCP both ways. As a server, n8n’s built-in instance-level MCP access gives an AI client such as Claude, Cursor or Codex one connection to your instance, where it can search workflows, run the ones you enable and, from n8n 2.13.0, build and edit workflows; an MCP Server Trigger node turns a single workflow into a purpose-built server instead. As a client, the MCP Client node calls one tool on any MCP server as a fixed workflow step, and the MCP Client Tool node hands a server’s tools to an AI Agent node. Pick by who is in charge: the AI client driving n8n, or n8n driving the MCP server.
The agent side, meaning the AI Agent node, human approval on tools and a worked triage workflow, is covered in n8n AI agents with MCP. This piece is the map of all four routes and the setup for each.
The four routes at a glance
- Instance-level MCP access (n8n as server). One URL for the whole instance, ending in
/mcp-server/http, with OAuth or an API key. The client sees the workflows you enable, and can build new ones. - MCP Server Trigger node (n8n as server). One workflow becomes one server, exposing only the tool nodes attached to it, with its own URL and bearer or header authentication.
- MCP Client node (n8n as client). A normal workflow step that calls one tool you choose on an outside MCP server, with arguments you set.
- MCP Client Tool node (n8n as client). A sub-node of the AI Agent that lets the model choose among a server’s tools, all or a selected few.
Add n8n MCP to Claude and other clients
This is the instance-level route, and n8n’s guide to its MCP server (opens in a new tab) is the reference. Three steps on the n8n side:
- An instance owner or admin opens Settings, Instance-level MCP, and selects Enable MCP access. On n8n Cloud and self-hosted alike; on self-hosted,
N8N_DISABLED_MODULES=mcpremoves the feature entirely. - Enable each workflow a client may use: from the Workflows exposed page, the workflow’s own settings (Available in MCP), or its card in the workflows list. Only published workflows with a webhook, form, schedule or chat trigger qualify. Give each a description, because that is what the client reads when it chooses.
- Open Connect a client, choose OAuth (recommended) or API key, and copy the Server URL. The Connect a client dialog with per-client steps arrived in n8n 2.33.0; older versions show a simpler page.
Then on the client side. The Server URL is not your editor’s address, so copy it from that dialog rather than the browser’s address bar.
claude mcp add --transport http n8n https://<your-n8n-domain>/mcp-server/http # then run /mcp in Claude Code, select n8n, and approve access in n8n
- Claude Desktop and claude.ai: Settings, Connectors, Add custom connector, paste the Server URL, then approve access when n8n asks.
- Codex CLI, Gemini CLI, Cursor, VS Code and Windsurf: n8n’s client connection examples (opens in a new tab) give the exact command or config file for each.
- With an API key instead: n8n generates a personal access token tied to your account and shows it once. Clients that sign in with OAuth appear under Connected clients with the permissions you granted, and can be revoked there one by one; API-key clients do not appear in that list, so rotating the token is how you cut them off.
What the client can do once connected
n8n’s MCP server tools reference (opens in a new tab) lists the tools. They fall into groups:
- Find and inspect:
search_workflowssees previews of every workflow you can view, even ones not enabled for MCP;get_workflow_detailsreturns an enabled workflow with credential references stripped. - Run:
execute_workflowruns the published version by default (production), or the current draft withmanual;test_workflowruns it with pinned data;get_workflow_executionandsearch_workflow_executionsread the results. - Build and change:
search_nodes,validate_workflow,create_workflow_from_code,update_workflow,publish_workflowandarchive_workflow, plus tools for data tables and, where the instance has them, agents, which n8n marks as a preview feature.
Two limits to plan around. Every connected client sees every workflow you enabled; you cannot give Claude one set and ChatGPT another, though each person still sees only workflows they have access to. And a client that can build and publish workflows can change what runs in production, so start it on a test instance or a copy, and keep an eye on the workflow’s version history.
The MCP Server Trigger: one workflow, one server
Use the trigger when you want a small, purpose-built server rather than access to the instance. Its node page (opens in a new tab) sets out the behavior: the node exposes a URL, clients list and call the tool nodes attached to it, and a Custom n8n Workflow Tool attached to it turns a whole workflow into one tool. It supports SSE and Streamable HTTP, not stdio. There are separate test and production URLs, and the production one is registered when you publish.
Clients that speak only stdio, such as Claude Desktop with a local config entry, need a bridge. n8n’s own pages disagree on which: the trigger page shows npx mcp-remote with the URL and an Authorization: Bearer header, while the instance-level examples use npx supergateway --streamableHttp. Both are third-party bridges that relay stdio to HTTP; use one, and prefer a client’s built-in remote connector where it has one. The operational details of the trigger (queue mode with several webhook replicas, proxy buffering behind nginx) are in n8n AI agents with MCP.
Can n8n connect to an MCP server?
Yes, with either client node. Both support bearer, generic header, multiple headers and OAuth2 authentication, or none.
- The MCP Client node is for a fixed step. You give it the transport and the endpoint URL (n8n’s own example is Notion’s hosted server), pick one tool from the list it fetches, and set the arguments by hand or as JSON. No model is involved, so the step does the same thing every run.
- The MCP Client Tool node is for an agent. It plugs into the AI Agent node, and Tools to Include (All, Selected or All Except) decides which of the server’s tools the model can see. Servers already in n8n’s MCP registry connect from the node panel without a credential.
One inconsistency in n8n’s documentation: the MCP Client Tool page still calls its URL field “SSE Endpoint,” while the newer MCP Client node page has a Server Transport choice. If the Client Tool will not connect to a Streamable HTTP server, check the transport setting in your n8n version before blaming the server.
The best n8n MCP server for building workflows
Searches for the best n8n MCP server usually mean “which server helps an AI build n8n workflows?” There are three candidates, and they do different jobs:
- n8n’s own instance-level server, above. It works on your real instance, can validate, create and publish workflows, and pairs with n8n Skills, a set of guidance files n8n publishes for coding agents. n8n suggests coding agents such as Claude Code over chat clients for building.
- n8n’s documentation servers. The n8n docs MCP server page (opens in a new tab) lists two: a GitBook server at
https://docs.n8n.io/~gitbook/mcpthat answers from the docs alone, and a Kapa.ai server that also draws on the forum and blog and asks you to sign in. Both are Streamable HTTP only. They answer questions; they cannot touch your instance. - The community
n8n-mcpproject. An independent open-source server that gives assistants detailed knowledge of n8n’s nodes and templates and, with an n8n API key, can manage workflows. It is not made by n8n; its own README warns never to let AI edit production workflows directly. Read its access requirements before you give it a key.
n8n and a task board
The two directions combine well with a board. fenbs is a task board that is itself an MCP server at https://fenbs.ai/api/mcp. From n8n, an MCP Client node can call fenbs_create_item as a fixed step, say to file a bug when a monitored job fails, with a key such as the job’s run id so a retry never files the same bug twice. A workflow cannot complete a browser sign-in, so it uses a token issued under Settings with a name, only the scopes it needs, and an optional expiry; revoking it there stops the workflow without touching anyone else. The other way round, the assistant you point at n8n can record what it built or changed as a task, with the plan and how it was tested, and History shows each change under its name.
Related
The agent side of n8n: n8n AI agents with MCP. No-code routes to MCP: using MCP without writing code and Zapier MCP. Tokens and scopes for automations: assistant tokens and scopes. Connecting fenbs: the MCP docs.