drzamarian/n8n-mcp-community

šŸ¢ Workplace & Productivity🟢 Verified Active
0 Views
0 Installs

šŸ“‡ šŸ  - Security-focused MCP server for self-hosted n8n Community Edition: 44 bounded tools for workflows, executions, credentials, tags, and diagnostics, read-only by default, with no external AI calls.

Quick Install

One-Click IDE Configuration
claude_desktop_config.json
{
  "mcpServers": {
    "drzamarian-n8n-mcp-community": {
      "command": "npx",
      "args": [
        "-y",
        "drzamarian-n8n-mcp-community"
      ]
    }
  }
}
Or

Using an AI coding agent (Claude Code, Cursor, etc.)? Copy a ready-made prompt that tells it to fetch the setup instructions and install this server for you.

Documentation Overview

n8n MCP Community

A security-focused Model Context Protocol server for self-hosted n8n Community Edition.

Connect an MCP client to a bounded 44-tool n8n Community Edition management surface: create, edit, activate, and delete workflows, update individual nodes surgically, and manage executions, credentials, tags, users, diagnostics, and instance metadata — 44 carefully bounded tools in total. Safety here is progressive, not restrictive: the server defaults to read-only, write unlocks authoring, and unsafe unlocks every tool with an exact per-call confirmation phrase for each destructive operation. It starts offline, uses the supported n8n Public API, and never sends workflow data to an external AI provider.

Release evidence: install only a version that appears consistently on npm, the latest GitHub release, and the MCP Registry entry io.github.drzamarian/n8n-mcp-community. A version in the source tree remains a candidate until those external readbacks agree. See Installation.

Read the synthetic terminal demo transcript. It shows the exact-version startup, 44-tool inventory, and local Introspect diagnostics using only synthetic identifiers and documented output shapes.

Animated synthetic terminal demonstration showing the exact-version startup, MCP inventory, and local Introspect result

Why this project

  • Community Edition first. The release surface is designed for self-hosted n8n Community Edition, without presenting paid-only capabilities as available.
  • 44 useful tools, one explicit contract. Every tool has bounded inputs, documented side effects, MCP safety annotations, and contract tests.
  • Safe by default. Read-only mode is the default. Writes and destructive or externally contacting operations require progressively stronger gates.
  • Deterministic Introspect. n8n_introspect runs a local 23-rule engine; it does not execute workflows, call an agent, or contact an external model.
  • Surgical node updates. n8n_update_node changes one validated node path while preserving the rest of the workflow and disclosing the Public API's non-atomic limitation.
  • Truthful discovery. n8n_list_node_types reports only types observed in accessible workflows. It does not claim to be a complete installed catalog.
  • Data minimization. Credential values, raw execution values, pin data, and static workflow data are not returned by the generic public tools.

Current verification

The current source candidate has been verified with:

  • exactly 44 tools, 5 resources, and 4 prompts over real stdio;
  • 291 passing tests and the complete verification gate on Node.js 22.23.1 and 24.18.0;
  • zero findings from Gitleaks, Semgrep, Trivy, and both project-root production/full npm audit runs; all three source scanners are reproduced in CI, with immutable scanner/action identities;
  • a separate no-override consumer install that resolves the reviewed @hono/node-server@1.19.15 backport, accepts only an exact GHSA-frvp-7c67-39w9 advisory or a fully clean advisory readback while registry metadata converges, and proves the stdio runtime and exact 44/5/4 inventory;
  • a reproducible dependency-license gate covering 224 installed package paths;
  • bounded same-origin HTTP contracts and zero-request policy-denial tests;
  • all 44 compiled tool lifecycles on disposable n8n Community 2.30.5 and 2.30.7 instances with egress isolation, revoked keys, cleanup, and zero residue; and
  • a reviewed offline npm-tarball installation under the project's committed dependency policy, plus a byte-reproducible unsigned MCPB with the same compiled runtime and complete production dependency notices.

Publication proceeds only through the reviewed release procedure: the repository-pinned MCPB signing identity, a human artifact-baseline receipt, tag-scoped protected-environment approval, and an externally signed MCPB handoff verified byte for byte against the reviewed unsigned candidate.

Quick start

Requirements: Node.js 22 or 24, npm, a self-hosted n8n Community Edition instance, and an n8n Public API key with only the permissions you need.

First identify a version whose npm provenance and GitHub release assets you have verified, then replace <VERIFIED_VERSION> below. Keep the pin exact:

{
  "mcpServers": {
    "n8n-community": {
      "command": "npx",
      "args": ["--yes", "n8n-mcp-community@<VERIFIED_VERSION>"],
      "env": {
        "N8N_API_URL": "https://n8n.example.com",
        "N8N_API_KEY": "replace-with-a-dedicated-api-key",
        "N8N_MCP_MODE": "read-only"
      }
    }
  }
}

read-only is the recommended starting point, not a capability ceiling: the same 44-tool surface includes full workflow authoring. Set N8N_MCP_MODE=write to create and edit workflows, nodes, credentials, and tags, or N8N_MCP_MODE=unsafe to enable every tool — activation, deletion, retries, and the other destructive operations, each still guarded by an exact per-call confirmation phrase. See Safety modes.

Restart the MCP client and confirm exactly 44 tools, 5 resources, and 4 prompts. Compatible desktop clients can instead install the signed MCPB from the latest verified release; verify its checksum against the release SHA256SUMS first.

Quick start from source

Requirements: Node.js 22 or 24, npm, and a Git checkout of this repository.

npm ci
npm run verify:contributor

Configure your MCP client to run the compiled stdio entry point:

{
  "mcpServers": {
    "n8n-community": {
      "command": "node",
      "args": ["/absolute/path/to/n8n-mcp-community/dist/index.js"],
      "env": {
        "N8N_API_URL": "https://n8n.example.com",
        "N8N_API_KEY": "replace-with-your-api-key",
        "N8N_MCP_MODE": "read-only"
      }
    }
  }
}

Restart the MCP client and list tools. The server can initialize and expose its inventory without n8n credentials; connected tools validate the URL and API key only when called.

Verified releases provide both a signed MCPB for compatible clients and exact-version npx configuration for portability. @latest, global installs, and curl | shell are not reproducible defaults. See Installation for the release policy and client-specific guidance.

Safety modes

ModeWhat it allowsRequired configuration
Read-onlyRead-only tools onlyDefault, or N8N_MCP_MODE=read-only
WriteRead-only and mutation tools without the unsafe confirmation gateN8N_MCP_MODE=write
UnsafeAll toolsN8N_MCP_MODE=unsafe plus the exact per-call confirmation

Unsafe mode is necessary but not sufficient. Every unsafe call also requires a confirmation such as DELETE wf_123, STOP exec_123, or TEST cred_123. The n8n API key remains the final upstream permission boundary.

Plain HTTP is accepted automatically only for loopback URLs. A non-loopback HTTP instance additionally requires N8N_ALLOW_INSECURE_HTTP=1, which accepts the risk of exposing the API key and data in transit.

Tool catalog

Every entry links to its complete input, output, endpoint, compatibility, failure, and security reference.

Workflows

ToolModePurpose
n8n_workflows_listRead-onlyList accessible workflows with bounded filters and pagination.
n8n_workflows_getRead-onlyRead one workflow while withholding pin and static data values.
n8n_workflows_createWriteCreate a validated workflow through the Public API.
n8n_workflows_updateWriteGuard and update selected fields while preserving omitted fields.
n8n_update_nodeWriteChange one validated node property with non-atomic concurrency guards.
n8n_workflows_deleteUnsafePermanently delete one workflow after exact confirmation.
n8n_workflows_activateUnsafeActivate one workflow after exact confirmation.
n8n_workflows_deactivateUnsafeDeactivate one workflow after exact confirmation.
n8n_workflows_get_versionRead-onlyRetrieve one retained historical workflow version.
n8n_workflows_get_tagsRead-onlyList tags assigned to a workflow.
n8n_workflows_update_tagsWriteReplace a workflow's complete tag assignment.
n8n_workflows_archiveUnsafeArchive one workflow after exact confirmation.
n8n_workflows_unarchiveUnsafeRestore one archived workflow after exact confirmation.
n8n_workflows_diffRead-onlyCompare nodes and connections without returning raw values.

Executions

ToolModePurpose
n8n_executions_listRead-onlyList execution metadata with value-free data-presence summaries.
n8n_executions_getRead-onlyRead one execution's metadata without returning workflow payloads.
n8n_executions_deleteUnsafePermanently delete a saved execution.
n8n_executions_retryUnsafeRetry an eligible saved execution.
n8n_executions_stopUnsafeStop one running execution and bind identity from validated input.

Credentials

ToolModePurpose
n8n_credentials_createWriteCreate a credential without returning its values.
n8n_credentials_deleteUnsafePermanently delete one credential.
n8n_credentials_schemaRead-onlyRead the public schema for a credential type.
n8n_credentials_listRead-onlyList credential metadata verified on n8n 2.30.5 and 2.30.7.
n8n_credentials_getRead-onlyRead one credential's public metadata.
n8n_credentials_updateWriteUpdate credential metadata or values without echoing secrets.
n8n_credentials_testUnsafeTest a stored credential, potentially contacting its external service.
n8n_credentials_usageRead-onlyFind exact credential-ID references in one bounded workflow page.

Tags

ToolModePurpose
n8n_tags_listRead-onlyList workflow tags.
n8n_tags_getRead-onlyRead one tag.
n8n_tags_createWriteCreate a tag with the live 1–24 character bound.
n8n_tags_updateWriteRename a tag with the live 1–24 character bound.
n8n_tags_deleteUnsafePermanently delete one tag.

Users

ToolModePurpose
n8n_users_listRead-onlyList users visible to the API key.
n8n_users_getRead-onlyRead one user by stable ID or exact email.
n8n_users_createUnsafeInvite a member or admin after exact email confirmation.
n8n_users_deleteUnsafeDelete one API-eligible user without unsupported transfer claims.

Diagnostics and instance metadata

ToolModePurpose
n8n_healthRead-onlyPerform a bounded same-origin health check.
n8n_insights_summaryRead-onlyRead the official insights summary with optional date filters.
n8n_audit_generateUnsafeGenerate n8n's instance security audit after exact confirmation.
n8n_search_workflowsRead-onlySearch one workflow page locally by name, node type, or tag.
n8n_get_node_docsRead-onlyRead one of four immutable offline core-node references.
n8n_list_node_typesRead-onlyInventory node types observed in bounded accessible workflow pages.
n8n_introspectRead-onlyRun deterministic local workflow and execution diagnostics.
n8n_community_packages_listRead-onlyList installed community-package metadata without mutation paths.

Resources and prompts

The server also exposes five static resources:

  • n8n://usage-guide
  • n8n://node-docs/webhook
  • n8n://node-docs/code
  • n8n://node-docs/http-request
  • n8n://node-docs/if

Four prompts guide safe workflow creation, debugging, optimization, and credential management: create-workflow, debug-workflow, optimize-workflow, and manage-credentials.

Security model in one minute

  • The server uses local stdio; it does not expose an inbound HTTP listener.
  • Connected requests are same-origin and limited to the configured n8n host.
  • Redirects are rejected; request and response bodies are bounded to 2 MiB.
  • Generic output is validated, sanitized, bounded to 256 KiB, and wrapped as { "data": ..., "redacted": boolean, "untrusted": true }.
  • Raw credential values and generic execution payload values are never returned.
  • n8n_introspect uses fixed local rules and has no external-model code path.
  • Security controls reduce risk; they do not make untrusted n8n content safe to execute or authorize broader API-key permissions.

Read the complete security model and use SECURITY.md to report a vulnerability privately.

Documentation

Development

npm ci
npm run verify:contributor
npm run sbom > sbom.cdx.json

npm run verify:contributor runs the complete keyless contributor gate, including formatting, dependency licenses/notices, strict TypeScript, all tests, the compiled runtime, and documentation inventory parity. See CONTRIBUTING.md before opening a change.

Scope and non-affiliation

This project is not affiliated with, endorsed by, or sponsored by n8n GmbH. ā€œn8nā€ is used only to identify compatibility with the n8n product and Public API. The project does not redistribute the n8n-nodes-base catalog and does not use browser cookies, interactive session routes, or runtime package downloads to construct one.

The v0.1.2 candidate surface intentionally excludes arbitrary workflow execution, credential/workflow transfer, folders, data tables, beta evaluation endpoints, and execution annotations. See the roadmap for the annotation proposal retained outside the release target.

License and maintainer

The project is released under the MIT License. Third-party dependencies retain their own licenses.

Created and maintained by Dr. Walter Zamarian Jr..

Related MCP Servers

6figr-com/jobgpt-mcp-server

šŸ“‡ ā˜ļø šŸ  šŸŽ 🪟 🐧 - MCP server for JobGPT — search jobs, auto-apply, generate tailored resumes, track applications, and find recruiters from any MCP client. 34 tools for job search, applications, resumes, and outreach.

šŸ¢ Workplace & Productivity0 views
Agentled/mcp-server

šŸ“‡ ā˜ļø - AI-native workflow orchestration with long-term memory, 100+ integrations, and unified credits. 32 MCP tools for building and running intelligent business workflows — lead enrichment, content publishing, company research, media production, and more. Knowledge Graph that learns across executions.

šŸ¢ Workplace & Productivity0 views
alex13slem/openproject-codex-plugin

šŸ“‡ ā˜ļø šŸ  šŸŽ 🪟 🐧 - Write-capable MCP server for OpenProject API v3 with Community Edition support. Search, create, update, assign, prioritize, and comment on work packages. Published as io.github.alex13slem/openproject in the official MCP Registry and installable with npx -y openproject-codex-plugin.

šŸ¢ Workplace & Productivity0 views
ap311036/ews-meeting-mcp

šŸ šŸ  šŸŽ 🪟 🐧 - Safely schedule Outlook meetings on on-prem Exchange EWS. Resolves attendees, discovers rooms, suggests slots, and requires preview-confirmed create/update/cancel writes with local credential handling and audit-friendly lifecycle records.

šŸ¢ Workplace & Productivity0 views

Engagement

Views
0
Installs
0
Upvotes
0

Views and upvotes are unique per visitor network (hashed IP). Installs count copy actions.

Status

Health: Active

Recent health check succeeded.

Last checked: 7/28/2026, 11:30:25 PM

Unclaimed listing (imported or pending owner verification). Claim it →
ā˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to get the verified badge and attach your website.

Claim this listing

Promote this listing

Optional paid placement. Free listings stay free forever.

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.