N8nSAFE
MCP server implementation for n8n workflow automation
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP server that provides access to n8n workflows, executions, credentials, and more through the Model Context Protocol. This allows Large Language Models (LLMs) to interact with n8n instances in a secure and standardized way.
Installation
Get your n8n API Key
- Log into your n8n instance
- Click your user icon in the bottom left
- Go to Settings
- Select API
- Click "Create API Key"
- Copy your API key (you won't be able to see it again)
Install the MCP Server
Option 1: Install from npm (Recommended)
npm install -g @illuminaresolutions/n8n-mcp-server
Option 2: Install from Source
- Clone the repository:
git clone https://github.com/illuminaresolutions/n8n-mcp-server.git cd n8n-mcp-server
- Install dependencies and build:
npm install npm run build
- Start the server in the background:
nohup npm start > n8n-mcp.log 2>&1 &
To stop the server:
pkill -f "node build/index.js"
Note: When installing from npm, the server will be available as n8n-mcp-server in your PATH.
Configuration
Claude Desktop
- Open your Claude Desktop configuration:
~/Library/Application Support/Claude/claude_desktop_config.json
- Add the n8n configuration:
{
"mcpServers": {
"n8n": {
"command": "n8n-mcp-server",
"env": {
"N8N_HOST": "https://your-n8n-instance.com",
"N8N_API_KEY": "your-api-key-here"
}
}
}
}Cline (VS Code)
- Install the server (follow Installation steps above)
- Open VS Code
- Open the Cline extension from the left sidebar
- Click the 'MCP Servers' icon at the top of the pane
- Scroll to bottom and click 'Configure MCP Servers'
- Add to the opened settings file:
{
"mcpServers": {
"n8n": {
"command": "n8n-mcp-server",
"env": {
b323dda9ab3dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add n8n-mcp-server -- npx -y @illuminaresolutions/[email protected]
{
"mcpServers": {
"n8n-mcp-server": {
"command": "npx",
"args": [
"-y",
"@illuminaresolutions/[email protected]"
]
}
}
}Exposed tools (33)
14 read · 12 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
activate-workflow | write | Activate a workflow by ID. This will enable the workflow to run. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
create-credential | write | Create a credential that can be used by nodes of the specified type. The credential type name can be found in the n8n UI when creating credentials (e.g., |
create-project | write | Create a new project in n8n. NOTE: Requires n8n Enterprise license with project management features enabled. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
create-tag | write | Create a new tag in your instance. |
create-users | write | Create one or more users in your instance. |
create-variable | write | Create a new variable in n8n. NOTE: Requires n8n Enterprise license with variable management features enabled. Variables can be used across workflows to store and share data. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
create-workflow | write | Create a new workflow in n8n. Use to set up a new workflow with optional nodes and connections. IMPORTANT: 1) Arguments must be provided as compact, single-line JSON without whitespace or newlines. 2) Must provide full workflow structure including nodes and connections arrays, even if empty. The |
deactivate-workflow | write | Deactivate a workflow by ID. This will prevent the workflow from running. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
delete-credential | destructive | Delete a credential by ID. You must be the owner of the credentials. |
delete-execution | destructive | Delete a specific execution by ID. |
delete-project | destructive | Delete a project by ID. NOTE: Requires n8n Enterprise license with project management features enabled. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
delete-tag | destructive | Delete a tag by ID. |
delete-user | destructive | Delete a user from your instance. |
delete-variable | destructive | Delete a variable by ID. NOTE: Requires n8n Enterprise license with variable management features enabled. Use after list-variables to get the ID of the variable to delete. This action cannot be undone. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
delete-workflow | destructive | Delete a workflow by ID. This action cannot be undone. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
generate-audit | read | Generate a security audit for your n8n instance. |
get-credential-schema | read | Show credential data schema for a specific credential type. The credential type name can be found in the n8n UI when creating credentials (e.g., |
get-execution | read | Retrieve a specific execution by ID. |
get-tag | read | Retrieve a specific tag by ID. |
get-user | read | Get user by ID or email address. |
get-workflow | read | Retrieve a workflow by ID. Use after list-workflows to get detailed information about a specific workflow. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
get-workflow-tags | read | Get tags associated with a workflow. |
init-n8n | read | Initialize connection to n8n instance. Use this tool whenever an n8n URL and API key are shared to establish the connection. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
list-executions | read | Retrieve all executions from your instance with optional filtering. |
list-projects | read | List all projects from n8n. NOTE: Requires n8n Enterprise license with project management features enabled. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
list-tags | read | Retrieve all tags from your instance. |
list-users | read | Retrieve all users from your instance. Only available for the instance owner. |
list-variables | read | List all variables from n8n. NOTE: Requires n8n Enterprise license with variable management features enabled. Use after init-n8n to see available variables. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
list-workflows | read | List all workflows from n8n. Use after init-n8n to see available workflows. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines. |
update-project | write | Update a project |
update-tag | write | Update a tag |
update-workflow | write | Update an existing workflow in n8n. Use after get-workflow to modify a workflow |
update-workflow-tags | write | Update tags associated with a workflow. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
delete-credential, delete-execution, delete-project, delete-tag, delete-user, delete-variable, delete-workflow
@modelcontextprotocol/sdk, zod, node-fetch, @types/node, typescript
load_dotenv() # load environment variables from .env
An MCP server that provides access to n8n workflows, executions, credentials, and more through the Model Context Protocol. This allows Large Language Models (LLMs) to interact with n8n instances in a
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
b323dda9ab3dfull audit observations/trust-audit/mcp-server/illuminaresolutions__n8n.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b323dda9ab3d | SAFE | B | 89 | first audit |
Questions
What is the N8n MCP server?
MCP server implementation for n8n workflow automation
What tools does N8n expose?
33 in total: 14 read-only, 12 that write, and 7 that can delete or overwrite (delete-credential, delete-execution, delete-project, delete-tag, delete-user). Every one is listed on this page with its risk.
Is N8n safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does N8n need?
No credential environment variables were found in its source, so it appears to need none.
How does N8n run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @illuminaresolutions/n8n-mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (b323dda9ab3d), read on 2026-10-07. The repository is watched and re-audited when it changes.