To use n8n MCP in Claude Code, enable Instance-level MCP in n8n, run one claude mcp add command with your Server URL, and approve the connection from /mcp. Claude Code can then search, build, validate, test, run and publish workflows from a prompt. Connect with OAuth rather than the API key, because OAuth lets you grant read-only or custom scopes, and expose only the workflows you want an agent to touch.
To use n8n MCP in Claude Code, turn on Instance-level MCP in your n8n settings, run claude mcp add --transport http n8n https://<your-n8n-domain>/mcp-server/http, then approve the connection from /mcp inside Claude Code. After that, Claude Code can search your workflows, write new ones as code, validate, test, run and publish them, within the scopes you grant and the workflows you expose.
Checked October 2026 against n8n's docs on connecting to the n8n MCP server, its client examples and tools reference, the Claude Code docs on MCP and permissions, and the source of n8n 2.42.6. n8n ships MCP changes in most releases, so feature versions are noted where they matter.
This guide belongs to our n8n hub. It goes end to end: connect, build a workflow from a prompt, test it, run it, and put limits around the whole thing. The limits get the most space here, because an agent with write access to your automations deserves more thought than a one-line install.
Which "n8n MCP" is this?
The one built into n8n. Three different things answer to the name, and tutorials mix them up:
| Name | What it is | Use it when | Status |
|---|---|---|---|
| Instance-level MCP server | Built into n8n, one URL per instance ending in /mcp-server/http | Claude Code should search, build, test and run workflows across your instance | This guide |
| MCP Server Trigger node | A node inside one workflow that exposes the tools you connect to it | You want to hand other AI apps a small, hand-built tool set | Published by n8n |
| n8n-mcp by czlonkowski | A community project on GitHub, separate from n8n | You have a reason to prefer it over the built-in server | Third party, MIT licence |
The rest of this page uses the first one. If MCP itself is new to you, our plain-language MCP guide covers hosts, clients and servers first.
- 01You describe the workflow
Plain language in Claude Code: trigger, steps, where the result goes.
- 02Claude Code reads the rules
It pulls n8n's Workflow SDK reference and looks up the node types it needs.
- 03It writes and validates code
validate_workflow parses the code and returns errors and warnings.
- 04n8n saves a draft
create_workflow_from_code stores it and returns a link to open it.
- 05Test, then run
A pinned-data test first, a real execution second.
- 06A human publishes
Open the draft, read it, publish it.
What you need before you start
- An n8n instance on a recent 2.x release: building and editing workflows over MCP needs 2.13.0 or later
- Version 2.33.0 or later if you want the Connect a client dialog shown in this guide
- An instance owner or admin to switch MCP access on
- Claude Code installed and signed in on the machine you work from
- A network path from that machine to n8n: a local http://localhost:5678 install works
- A project or folder in n8n set aside for agent-built drafts
- Test credentials in that project, not production ones
If Claude Code is not installed yet, start with our install walkthrough. For a local n8n to practise on, the Docker Compose setup guide sets one up on your own machine.
How to use n8n MCP in Claude Code: the setup
- 1Enable MCP access
In n8n: Settings, Instance-level MCP, Enable MCP access. Expected result: the page shows Connection details, Access and Connected clients.
- 2Copy the Server URL
Select Connect, pick Claude Code under Your client, and copy the Server URL. Expected result: a URL ending in /mcp-server/http.
- 3Add the server
Run the claude mcp add command below in a terminal. Expected result: Claude Code prints an Added line.
- 4Authenticate
Start claude, run /mcp and select n8n. Expected result: your browser opens n8n's approval screen.
- 5Choose the scopes
Pick Read only for a first session, or Custom to tick exactly what this client may do. Expected result: a success page, then a redirect back.
- 6Confirm the connection
Run claude mcp list. Expected result: n8n is listed as Connected.
- 7Expose a workflow
In a workflow's Settings, turn on Available in MCP. Expected result: Claude Code can read its details instead of only a preview.
The command, from n8n's client examples:
claude mcp add --transport http n8n https://<your-n8n-domain>/mcp-server/httpBy default Claude Code stores the server for the current project only. Add --scope user to have it in every project, or --scope project to write a .mcp.json file your team can share. The same entry as JSON:
{
"mcpServers": {
"n8n": {
"type": "http",
"url": "https://<your-n8n-domain>/mcp-server/http"
}
}
}OAuth or the API key?
Use OAuth. n8n recommends it, and it is the only route that lets you limit what Claude Code can do. The API key tab hands out a personal access token tied to your user, and n8n's source is explicit that such a token "grants access to all tools" (mcp-scopes.ts).
- One token per user, used by every client you paste it into
- No scopes: every tool is available
- Sits in plain text in a config file or shell history
- Not listed under Connected clients
- Stopped by generating a new token, which cuts off every client using it
- One grant per client, approved in the browser
- All, Read only or Custom scopes
- Claude Code stores and refreshes the token for you
- Listed under Connected clients with its permissions
- Revoked per client, effective at once
Source: n8n docs and n8n 2.42.6 source, checked October 2026
Claude Code n8n workflow: build, test and run one from a prompt
Once connected, you work in sentences. Start with something small and say where it should stop:
Use the n8n MCP server. In my personal project, build a workflow named
"Lead intake": a Webhook trigger that receives { email, message },
an If node that drops empty messages, and a Slack node that posts the
message to #leads. Validate it, create it, then test it with pinned data.
Do not run it for real and do not publish it.What happens next is a fixed sequence of tool calls. Knowing it lets you spot when the agent cuts a corner:
| Stage | Tools Claude Code calls | What to check |
|---|---|---|
| Learn the rules | get_workflow_sdk_reference, search_nodes, get_node_types | The docs say the SDK reference should be called first; if Claude Code skips it, tell it to start there |
| Check the code | validate_workflow | Must run before a create or update; warnings can appear even when the code is valid |
| Save the draft | create_workflow_from_code | Lands in your personal project unless you name one; credentials are auto-assigned, except on HTTP Request nodes |
| Dry run | test_workflow | Triggers, credentialed nodes and HTTP Request nodes use pinned data; it waits for the result, five minutes by default |
| Real run | execute_workflow, then get_workflow_execution | Returns an execution ID at once; manual mode runs the draft, production mode runs the published version |
| Go live | publish_workflow | Turns the draft into the active version; keep this step for a human at first |
Four behaviours from the tools reference matter in practice:
- A workflow built over MCP is exposed over MCP.
create_workflow_from_codesets the Available in MCP flag on what it creates, so every connected client can reach it from then on. - A test is not a sandbox.
test_workflowpins triggers, nodes with credentials and HTTP Request nodes. Other nodes run for real, including credential-free ones that execute commands or write files. - Manual mode uses real credentials.
execute_workflowin manual mode runs the current draft against live services. If the Slack node is real, the message is sent. - Runs are asynchronous.
execute_workflowreturns an execution ID immediately. Claude Code has to callget_workflow_executionto see whether the run passed.
Editing follows the same pattern. update_workflow applies a batch of targeted changes and saves nothing if one fails. It can also set workflow settings, including the error workflow, so "add error handling to this workflow" is a fair request. Read our Error Trigger guide first, because the handler has to exist and be published before the link does anything.
Guardrails: read-only mode, scopes and what Claude Code may touch
Limit the connection in four places, because each one covers a gap the others leave. n8n decides which workflows are reachable and which tools a client holds. Claude Code decides which of those tools run without asking you.
1. Expose workflows on purpose
A client cannot read, run or change a workflow until you mark it Available in MCP. Three caveats from the docs: search_workflows still returns previews of every workflow your user can view, exposure is not per client (every connected client sees the same set), and Auto-expose new workflows is off by default. Leave it off.
2. Grant scopes per client
On the approval screen, Read only lets a client view workflows and data without making changes. Custom lets you tick individual scopes. This is how the scopes map to tools in n8n 2.42.6:
| Scope | Label on the approval screen | What it unlocks |
|---|---|---|
| workflow:read | List workflows | Search, details, version history, node search, SDK reference, validation |
| workflow:write | Create and update workflows | Create, update, archive, restore a version, publish and unpublish |
| workflow:execute | Run workflows | execute_workflow, test_workflow, prepare_workflow_pin_data |
| execution:read | Get execution details | Read one execution or search executions |
| credential:read | List credentials | Credential names and types only; secret data is never returned |
| dataTable:read / write | List, create and update data tables | Search tables; create tables, columns and rows |
| communityPackage:install | Install verified community nodes | Changes what the instance can run, so it is a separate scope |
Note where publishing sits: inside workflow:write. A client that can edit a workflow can also publish it, so n8n alone cannot give you "may draft, may not ship". That gap is what the next layer closes.
3. Add permission rules in Claude Code
Claude Code names MCP tools mcp__<server>__<tool> and accepts them in allow, ask and deny rules. Put this in .claude/settings.json in the project where you work on n8n:
{
"permissions": {
"allow": [
"mcp__n8n__search_workflows",
"mcp__n8n__get_workflow_details",
"mcp__n8n__validate_workflow"
],
"ask": [
"mcp__n8n__update_workflow",
"mcp__n8n__execute_workflow"
],
"deny": [
"mcp__n8n__publish_workflow",
"mcp__n8n__unpublish_workflow",
"mcp__n8n__archive_workflow"
]
}
}Deny rules win over everything else, so publishing stays a human job even in a session where you have approved other tools. The names assume you called the server n8n in claude mcp add; change the middle segment if you used another name.
4. Shrink the account behind the connection
MCP access is user-scoped: a client sees only what the connecting user can see. Connecting as the instance owner hands the agent the whole instance. Where your plan allows extra users and projects, connect as a member who can reach only the sandbox project. Owners and admins can also set Allowed callback URLs to Only trusted URLs, and revoke any client from Connected clients.
Should you add the official n8n Skills?
Yes, once the plain connection works. The MCP server gives Claude Code the tools, but not n8n's conventions for expressions, loops or error handling. The n8n Skills repository, built by the n8n team, adds 13 capability skills and hooks that load the right guidance before high-impact MCP calls. Inside a Claude Code session:
/plugin marketplace add n8n-io/skills
/plugin install n8n-skills@n8n-io
/reload-pluginsThe installer asks for your instance URL (the base URL, without a path) and bundles its own MCP connection named n8n-mcp. If you already added a server called n8n, you now have two copies of every tool, and the README says to disable the duplicate from /mcp. Mind the names when you do: Claude Code calls a plugin's tools mcp__plugin_<plugin>_<server>__<tool>, so rules written for mcp__n8n__ do not cover the plugin's copy. Deny and ask rules accept wildcards, so mcp__*__publish_workflow blocks publishing through either one. For other servers worth pairing with it, see our list of the best MCP servers for coding.
Connecting tools is one module of a bigger skill set. Our AI SaaS Builder program spends two modules on Claude Code and MCP, including building your own MCP server and wiring MCP into a product you sell.
Troubleshooting the n8n MCP connection
Most failures are one of seven, and each has a specific message. Check /mcp in Claude Code first, then the n8n settings page.
| What you see | Cause | Fix |
|---|---|---|
| "You do not have sufficient permissions to authorize this request" | MCP access is off for the instance | An owner or admin selects Enable MCP access, then you connect again |
| The server "has a url but no type" | A JSON entry without a type is read as a local stdio server | Add "type": "http" to the entry |
| claude mcp list shows "Needs authentication" | The OAuth sign-in was never finished or the token was revoked | Run /mcp and select n8n, or run claude mcp login n8n |
| Claude Code finds a workflow but cannot open or run it | The workflow is not marked Available in MCP | Turn the toggle on in the workflow's Settings |
| execute_workflow returns a list of trigger names | The workflow has several triggers, or its trigger needs input | Ask Claude Code to pass triggerNodeName and the inputs |
| Production run refused | Production mode needs a published version | Publish the workflow, or run it in manual mode |
| Connection fails behind a proxy or firewall | MCP request headers are being stripped | Allow MCP-Protocol-Version, Mcp-Method and Mcp-Name |
If Claude Code itself is the unfamiliar part, our Claude Code complete guide explains permission modes, settings files and the /mcp panel in more depth.
n8n MCP and Claude Code: FAQ
How do I connect n8n to Claude Code?
In n8n, open Settings, then Instance-level MCP, and select Enable MCP access. Copy the Server URL from Connect a client; it ends in /mcp-server/http. In a terminal run claude mcp add --transport http n8n followed by that URL. Then start Claude Code, run /mcp, select n8n and approve access in the browser. Checked October 2026 against the n8n and Claude Code docs.
Can Claude Code build n8n workflows?
Yes. From n8n 2.13.0 the instance-level MCP server includes workflow builder tools. Claude Code reads n8n's Workflow SDK reference, searches node types, writes the workflow as code, validates it and saves it with create_workflow_from_code. It can then test the workflow with pinned data, run it and publish it, if the scopes you granted allow those actions.
What is the n8n MCP server URL?
It is your n8n address followed by /mcp-server/http, for example https://your-instance.app.n8n.cloud/mcp-server/http on n8n Cloud. n8n shows the exact value under Settings, Instance-level MCP, Connect a client, Server URL. It is not the editor address in your browser bar. A local install uses http instead of https, such as http://localhost:5678/mcp-server/http.
Is there a read-only mode for the n8n MCP server?
Yes, when you connect with OAuth. The approval screen lets you choose All, Read only or Custom scopes for each client, and a read-only client can view workflows and data without making changes. A client that connects with the API key instead is not scoped: n8n's source treats that token as access to all tools. Checked October 2026 against n8n 2.42.6.
What is the difference between the n8n MCP server and the MCP Server Trigger node?
The instance-level MCP server is one connection for the whole n8n instance, with central authentication and a list of workflows you choose to expose. The MCP Server Trigger is a node inside a single workflow that exposes only the tools you wire into that workflow. Use the instance server to build and manage workflows, and the trigger node to publish a custom tool set to other AI apps.
Do I need a paid n8n plan to use MCP with Claude Code?
The n8n docs describe instance-level MCP for both Cloud and self-hosted instances, and the official n8n Skills repository lists the prerequisite as an n8n instance on any plan with the instance-level MCP server enabled, minimum version 2.2.0. An instance owner or admin has to turn it on. You also need Claude Code itself, which has its own plans.
You can now build automations by describing them. Learn to build the product around them.
AI SaaS Builder, included in All Access, covers Claude Code and MCP in depth, then the rest of a shippable product: Supabase, Next.js, Claude API features and Stripe billing. All Access adds the other three programs, live coaching and the private community.
Compare setups in the free Discord
Share your MCP config, scopes and permission rules with other builders, and see what they let their agents do.