Atlas / MCP servers / illuminaresolutions / N8n

N8nSAFE

mcp/illuminaresolutions/n8n

MCP server implementation for n8n workflow automation

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
33 14r · 12w · 7d
Transport
stdio
License
MIT
Stars
119
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP server that provides access to n8n workflows, executions, credentials, and more through the Model Context Protocol. This allows Large Language Models (LLMs) to interact with n8n instances in a secure and standardized way.

Installation

Get your n8n API Key

  1. Log into your n8n instance
  2. Click your user icon in the bottom left
  3. Go to Settings
  4. Select API
  5. Click "Create API Key"
  6. Copy your API key (you won't be able to see it again)

Install the MCP Server

Option 1: Install from npm (Recommended)

npm install -g @illuminaresolutions/n8n-mcp-server

Option 2: Install from Source

  1. Clone the repository:
git clone https://github.com/illuminaresolutions/n8n-mcp-server.git
cd n8n-mcp-server
  1. Install dependencies and build:
npm install
npm run build
  1. Start the server in the background:
nohup npm start > n8n-mcp.log 2>&1 &

To stop the server:

pkill -f "node build/index.js"

Note: When installing from npm, the server will be available as n8n-mcp-server in your PATH.

Configuration

Claude Desktop

  1. Open your Claude Desktop configuration:
~/Library/Application Support/Claude/claude_desktop_config.json
  1. Add the n8n configuration:
{
"mcpServers": {
"n8n": {
"command": "n8n-mcp-server",
"env": {
"N8N_HOST": "https://your-n8n-instance.com",
"N8N_API_KEY": "your-api-key-here"
}
}
}
}

Cline (VS Code)

  1. Install the server (follow Installation steps above)
  2. Open VS Code
  3. Open the Cline extension from the left sidebar
  4. Click the 'MCP Servers' icon at the top of the pane
  5. Scroll to bottom and click 'Configure MCP Servers'
  6. Add to the opened settings file:
{
"mcpServers": {
"n8n": {
"command": "n8n-mcp-server",
"env": {
Read from source at commit b323dda9ab3dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add n8n-mcp-server -- npx -y @illuminaresolutions/[email protected]
claude-desktop
{
  "mcpServers": {
    "n8n-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@illuminaresolutions/[email protected]"
      ]
    }
  }
}
03

Exposed tools (33)

14 read · 12 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
activate-workflowwriteActivate a workflow by ID. This will enable the workflow to run. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
create-credentialwriteCreate a credential that can be used by nodes of the specified type. The credential type name can be found in the n8n UI when creating credentials (e.g.,
create-projectwriteCreate a new project in n8n. NOTE: Requires n8n Enterprise license with project management features enabled. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
create-tagwriteCreate a new tag in your instance.
create-userswriteCreate one or more users in your instance.
create-variablewriteCreate a new variable in n8n. NOTE: Requires n8n Enterprise license with variable management features enabled. Variables can be used across workflows to store and share data. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
create-workflowwriteCreate a new workflow in n8n. Use to set up a new workflow with optional nodes and connections. IMPORTANT: 1) Arguments must be provided as compact, single-line JSON without whitespace or newlines. 2) Must provide full workflow structure including nodes and connections arrays, even if empty. The
deactivate-workflowwriteDeactivate a workflow by ID. This will prevent the workflow from running. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
delete-credentialdestructiveDelete a credential by ID. You must be the owner of the credentials.
delete-executiondestructiveDelete a specific execution by ID.
delete-projectdestructiveDelete a project by ID. NOTE: Requires n8n Enterprise license with project management features enabled. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
delete-tagdestructiveDelete a tag by ID.
delete-userdestructiveDelete a user from your instance.
delete-variabledestructiveDelete a variable by ID. NOTE: Requires n8n Enterprise license with variable management features enabled. Use after list-variables to get the ID of the variable to delete. This action cannot be undone. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
delete-workflowdestructiveDelete a workflow by ID. This action cannot be undone. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
generate-auditreadGenerate a security audit for your n8n instance.
get-credential-schemareadShow credential data schema for a specific credential type. The credential type name can be found in the n8n UI when creating credentials (e.g.,
get-executionreadRetrieve a specific execution by ID.
get-tagreadRetrieve a specific tag by ID.
get-userreadGet user by ID or email address.
get-workflowreadRetrieve a workflow by ID. Use after list-workflows to get detailed information about a specific workflow. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
get-workflow-tagsreadGet tags associated with a workflow.
init-n8nreadInitialize connection to n8n instance. Use this tool whenever an n8n URL and API key are shared to establish the connection. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
list-executionsreadRetrieve all executions from your instance with optional filtering.
list-projectsreadList all projects from n8n. NOTE: Requires n8n Enterprise license with project management features enabled. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
list-tagsreadRetrieve all tags from your instance.
list-usersreadRetrieve all users from your instance. Only available for the instance owner.
list-variablesreadList all variables from n8n. NOTE: Requires n8n Enterprise license with variable management features enabled. Use after init-n8n to see available variables. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
list-workflowsreadList all workflows from n8n. Use after init-n8n to see available workflows. IMPORTANT: Arguments must be provided as compact, single-line JSON without whitespace or newlines.
update-projectwriteUpdate a project
update-tagwriteUpdate a tag
update-workflowwriteUpdate an existing workflow in n8n. Use after get-workflow to modify a workflow
update-workflow-tagswriteUpdate tags associated with a workflow.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete-credential, delete-execution, delete-project, delete-tag, delete-user, delete-variable, delete-workflow
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, node-fetch, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
LLM_GUIDE.md:3297
load_dotenv()  # load environment variables from .env
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:3
An MCP server that provides access to n8n workflows, executions, credentials, and more through the Model Context Protocol. This allows Large Language Models (LLMs) to interact with n8n instances in a
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
LLM_GUIDE.md:3881
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b323dda9ab3dfull audit observations/trust-audit/mcp-server/illuminaresolutions__n8n.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b323dda9ab3dSAFEB89first audit
06

Questions

What is the N8n MCP server?

MCP server implementation for n8n workflow automation

What tools does N8n expose?

33 in total: 14 read-only, 12 that write, and 7 that can delete or overwrite (delete-credential, delete-execution, delete-project, delete-tag, delete-user). Every one is listed on this page with its risk.

Is N8n safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does N8n need?

No credential environment variables were found in its source, so it appears to need none.

How does N8n run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @illuminaresolutions/n8n-mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (b323dda9ab3d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement