Skip to main content

Connect n8n to Claude Code via MCP: Build and Run Workflows From Prompts

Connect n8n to Claude Code with the built-in MCP server: one command, OAuth scopes, then build, test and run a workflow from a prompt, with guardrails.

Founder of IImagined.ai

Published
Oct 11, 2026
Reading time
11 min read
Quick answer

To use n8n MCP in Claude Code, enable Instance-level MCP in n8n, run one claude mcp add command with your Server URL, and approve the connection from /mcp. Claude Code can then search, build, validate, test, run and publish workflows from a prompt. Connect with OAuth rather than the API key, because OAuth lets you grant read-only or custom scopes, and expose only the workflows you want an agent to touch.

To use n8n MCP in Claude Code, turn on Instance-level MCP in your n8n settings, run claude mcp add --transport http n8n https://<your-n8n-domain>/mcp-server/http, then approve the connection from /mcp inside Claude Code. After that, Claude Code can search your workflows, write new ones as code, validate, test, run and publish them, within the scopes you grant and the workflows you expose.

Checked October 2026 against n8n's docs on connecting to the n8n MCP server, its client examples and tools reference, the Claude Code docs on MCP and permissions, and the source of n8n 2.42.6. n8n ships MCP changes in most releases, so feature versions are noted where they matter.

This guide belongs to our n8n hub. It goes end to end: connect, build a workflow from a prompt, test it, run it, and put limits around the whole thing. The limits get the most space here, because an agent with write access to your automations deserves more thought than a one-line install.

Which "n8n MCP" is this?

The one built into n8n. Three different things answer to the name, and tutorials mix them up:

NameWhat it isUse it whenStatus
Instance-level MCP serverBuilt into n8n, one URL per instance ending in /mcp-server/httpClaude Code should search, build, test and run workflows across your instanceThis guide
MCP Server Trigger nodeA node inside one workflow that exposes the tools you connect to itYou want to hand other AI apps a small, hand-built tool setPublished by n8n
n8n-mcp by czlonkowskiA community project on GitHub, separate from n8nYou have a reason to prefer it over the built-in serverThird party, MIT licence

The rest of this page uses the first one. If MCP itself is new to you, our plain-language MCP guide covers hosts, clients and servers first.

From prompt to published workflow
  1. 01
    You describe the workflow

    Plain language in Claude Code: trigger, steps, where the result goes.

  2. 02
    Claude Code reads the rules

    It pulls n8n's Workflow SDK reference and looks up the node types it needs.

  3. 03
    It writes and validates code

    validate_workflow parses the code and returns errors and warnings.

  4. 04
    n8n saves a draft

    create_workflow_from_code stores it and returns a link to open it.

  5. 05
    Test, then run

    A pinned-data test first, a real execution second.

  6. 06
    A human publishes

    Open the draft, read it, publish it.

What you need before you start

Pre-flight for n8n MCP in Claude Code
  • An n8n instance on a recent 2.x release: building and editing workflows over MCP needs 2.13.0 or later
  • Version 2.33.0 or later if you want the Connect a client dialog shown in this guide
  • An instance owner or admin to switch MCP access on
  • Claude Code installed and signed in on the machine you work from
  • A network path from that machine to n8n: a local http://localhost:5678 install works
  • A project or folder in n8n set aside for agent-built drafts
  • Test credentials in that project, not production ones

If Claude Code is not installed yet, start with our install walkthrough. For a local n8n to practise on, the Docker Compose setup guide sets one up on your own machine.

How to use n8n MCP in Claude Code: the setup

Connect Claude Code to n8n
  1. 1
    Enable MCP access

    In n8n: Settings, Instance-level MCP, Enable MCP access. Expected result: the page shows Connection details, Access and Connected clients.

  2. 2
    Copy the Server URL

    Select Connect, pick Claude Code under Your client, and copy the Server URL. Expected result: a URL ending in /mcp-server/http.

  3. 3
    Add the server

    Run the claude mcp add command below in a terminal. Expected result: Claude Code prints an Added line.

  4. 4
    Authenticate

    Start claude, run /mcp and select n8n. Expected result: your browser opens n8n's approval screen.

  5. 5
    Choose the scopes

    Pick Read only for a first session, or Custom to tick exactly what this client may do. Expected result: a success page, then a redirect back.

  6. 6
    Confirm the connection

    Run claude mcp list. Expected result: n8n is listed as Connected.

  7. 7
    Expose a workflow

    In a workflow's Settings, turn on Available in MCP. Expected result: Claude Code can read its details instead of only a preview.

The command, from n8n's client examples:

claude mcp add --transport http n8n https://<your-n8n-domain>/mcp-server/http

By default Claude Code stores the server for the current project only. Add --scope user to have it in every project, or --scope project to write a .mcp.json file your team can share. The same entry as JSON:

{
  "mcpServers": {
    "n8n": {
      "type": "http",
      "url": "https://<your-n8n-domain>/mcp-server/http"
    }
  }
}

OAuth or the API key?

Use OAuth. n8n recommends it, and it is the only route that lets you limit what Claude Code can do. The API key tab hands out a personal access token tied to your user, and n8n's source is explicit that such a token "grants access to all tools" (mcp-scopes.ts).

Two ways to authenticate
API key
  • One token per user, used by every client you paste it into
  • No scopes: every tool is available
  • Sits in plain text in a config file or shell history
  • Not listed under Connected clients
  • Stopped by generating a new token, which cuts off every client using it
OAuth (recommended)
  • One grant per client, approved in the browser
  • All, Read only or Custom scopes
  • Claude Code stores and refreshes the token for you
  • Listed under Connected clients with its permissions
  • Revoked per client, effective at once

Source: n8n docs and n8n 2.42.6 source, checked October 2026

Claude Code n8n workflow: build, test and run one from a prompt

Once connected, you work in sentences. Start with something small and say where it should stop:

Use the n8n MCP server. In my personal project, build a workflow named
"Lead intake": a Webhook trigger that receives { email, message },
an If node that drops empty messages, and a Slack node that posts the
message to #leads. Validate it, create it, then test it with pinned data.
Do not run it for real and do not publish it.

What happens next is a fixed sequence of tool calls. Knowing it lets you spot when the agent cuts a corner:

StageTools Claude Code callsWhat to check
Learn the rulesget_workflow_sdk_reference, search_nodes, get_node_typesThe docs say the SDK reference should be called first; if Claude Code skips it, tell it to start there
Check the codevalidate_workflowMust run before a create or update; warnings can appear even when the code is valid
Save the draftcreate_workflow_from_codeLands in your personal project unless you name one; credentials are auto-assigned, except on HTTP Request nodes
Dry runtest_workflowTriggers, credentialed nodes and HTTP Request nodes use pinned data; it waits for the result, five minutes by default
Real runexecute_workflow, then get_workflow_executionReturns an execution ID at once; manual mode runs the draft, production mode runs the published version
Go livepublish_workflowTurns the draft into the active version; keep this step for a human at first

Four behaviours from the tools reference matter in practice:

  • A workflow built over MCP is exposed over MCP. create_workflow_from_code sets the Available in MCP flag on what it creates, so every connected client can reach it from then on.
  • A test is not a sandbox. test_workflow pins triggers, nodes with credentials and HTTP Request nodes. Other nodes run for real, including credential-free ones that execute commands or write files.
  • Manual mode uses real credentials. execute_workflow in manual mode runs the current draft against live services. If the Slack node is real, the message is sent.
  • Runs are asynchronous. execute_workflow returns an execution ID immediately. Claude Code has to call get_workflow_execution to see whether the run passed.

Editing follows the same pattern. update_workflow applies a batch of targeted changes and saves nothing if one fails. It can also set workflow settings, including the error workflow, so "add error handling to this workflow" is a fair request. Read our Error Trigger guide first, because the handler has to exist and be published before the link does anything.

Guardrails: read-only mode, scopes and what Claude Code may touch

Limit the connection in four places, because each one covers a gap the others leave. n8n decides which workflows are reachable and which tools a client holds. Claude Code decides which of those tools run without asking you.

1. Expose workflows on purpose

A client cannot read, run or change a workflow until you mark it Available in MCP. Three caveats from the docs: search_workflows still returns previews of every workflow your user can view, exposure is not per client (every connected client sees the same set), and Auto-expose new workflows is off by default. Leave it off.

2. Grant scopes per client

On the approval screen, Read only lets a client view workflows and data without making changes. Custom lets you tick individual scopes. This is how the scopes map to tools in n8n 2.42.6:

ScopeLabel on the approval screenWhat it unlocks
workflow:readList workflowsSearch, details, version history, node search, SDK reference, validation
workflow:writeCreate and update workflowsCreate, update, archive, restore a version, publish and unpublish
workflow:executeRun workflowsexecute_workflow, test_workflow, prepare_workflow_pin_data
execution:readGet execution detailsRead one execution or search executions
credential:readList credentialsCredential names and types only; secret data is never returned
dataTable:read / writeList, create and update data tablesSearch tables; create tables, columns and rows
communityPackage:installInstall verified community nodesChanges what the instance can run, so it is a separate scope

Note where publishing sits: inside workflow:write. A client that can edit a workflow can also publish it, so n8n alone cannot give you "may draft, may not ship". That gap is what the next layer closes.

Pick scopes by where the agent works
Sandbox project
Read only in a sandbox: a safe first connection test.
Where agents should build: workflow:write and workflow:execute, with test credentials only.
Live workflows
Read only on live workflows: audits, documentation and debugging failed executions.
Write and run on live workflows: only with ask rules in Claude Code and a human publishing.
Read
Write and run

3. Add permission rules in Claude Code

Claude Code names MCP tools mcp__<server>__<tool> and accepts them in allow, ask and deny rules. Put this in .claude/settings.json in the project where you work on n8n:

{
  "permissions": {
    "allow": [
      "mcp__n8n__search_workflows",
      "mcp__n8n__get_workflow_details",
      "mcp__n8n__validate_workflow"
    ],
    "ask": [
      "mcp__n8n__update_workflow",
      "mcp__n8n__execute_workflow"
    ],
    "deny": [
      "mcp__n8n__publish_workflow",
      "mcp__n8n__unpublish_workflow",
      "mcp__n8n__archive_workflow"
    ]
  }
}

Deny rules win over everything else, so publishing stays a human job even in a session where you have approved other tools. The names assume you called the server n8n in claude mcp add; change the middle segment if you used another name.

4. Shrink the account behind the connection

MCP access is user-scoped: a client sees only what the connecting user can see. Connecting as the instance owner hands the agent the whole instance. Where your plan allows extra users and projects, connect as a member who can reach only the sandbox project. Owners and admins can also set Allowed callback URLs to Only trusted URLs, and revoke any client from Connected clients.

Should you add the official n8n Skills?

Yes, once the plain connection works. The MCP server gives Claude Code the tools, but not n8n's conventions for expressions, loops or error handling. The n8n Skills repository, built by the n8n team, adds 13 capability skills and hooks that load the right guidance before high-impact MCP calls. Inside a Claude Code session:

/plugin marketplace add n8n-io/skills
/plugin install n8n-skills@n8n-io
/reload-plugins

The installer asks for your instance URL (the base URL, without a path) and bundles its own MCP connection named n8n-mcp. If you already added a server called n8n, you now have two copies of every tool, and the README says to disable the duplicate from /mcp. Mind the names when you do: Claude Code calls a plugin's tools mcp__plugin_<plugin>_<server>__<tool>, so rules written for mcp__n8n__ do not cover the plugin's copy. Deny and ask rules accept wildcards, so mcp__*__publish_workflow blocks publishing through either one. For other servers worth pairing with it, see our list of the best MCP servers for coding.

Connecting tools is one module of a bigger skill set. Our AI SaaS Builder program spends two modules on Claude Code and MCP, including building your own MCP server and wiring MCP into a product you sell.

Troubleshooting the n8n MCP connection

Most failures are one of seven, and each has a specific message. Check /mcp in Claude Code first, then the n8n settings page.

What you seeCauseFix
"You do not have sufficient permissions to authorize this request"MCP access is off for the instanceAn owner or admin selects Enable MCP access, then you connect again
The server "has a url but no type"A JSON entry without a type is read as a local stdio serverAdd "type": "http" to the entry
claude mcp list shows "Needs authentication"The OAuth sign-in was never finished or the token was revokedRun /mcp and select n8n, or run claude mcp login n8n
Claude Code finds a workflow but cannot open or run itThe workflow is not marked Available in MCPTurn the toggle on in the workflow's Settings
execute_workflow returns a list of trigger namesThe workflow has several triggers, or its trigger needs inputAsk Claude Code to pass triggerNodeName and the inputs
Production run refusedProduction mode needs a published versionPublish the workflow, or run it in manual mode
Connection fails behind a proxy or firewallMCP request headers are being strippedAllow MCP-Protocol-Version, Mcp-Method and Mcp-Name

If Claude Code itself is the unfamiliar part, our Claude Code complete guide explains permission modes, settings files and the /mcp panel in more depth.

n8n MCP and Claude Code: FAQ

How do I connect n8n to Claude Code?

In n8n, open Settings, then Instance-level MCP, and select Enable MCP access. Copy the Server URL from Connect a client; it ends in /mcp-server/http. In a terminal run claude mcp add --transport http n8n followed by that URL. Then start Claude Code, run /mcp, select n8n and approve access in the browser. Checked October 2026 against the n8n and Claude Code docs.

Can Claude Code build n8n workflows?

Yes. From n8n 2.13.0 the instance-level MCP server includes workflow builder tools. Claude Code reads n8n's Workflow SDK reference, searches node types, writes the workflow as code, validates it and saves it with create_workflow_from_code. It can then test the workflow with pinned data, run it and publish it, if the scopes you granted allow those actions.

What is the n8n MCP server URL?

It is your n8n address followed by /mcp-server/http, for example https://your-instance.app.n8n.cloud/mcp-server/http on n8n Cloud. n8n shows the exact value under Settings, Instance-level MCP, Connect a client, Server URL. It is not the editor address in your browser bar. A local install uses http instead of https, such as http://localhost:5678/mcp-server/http.

Is there a read-only mode for the n8n MCP server?

Yes, when you connect with OAuth. The approval screen lets you choose All, Read only or Custom scopes for each client, and a read-only client can view workflows and data without making changes. A client that connects with the API key instead is not scoped: n8n's source treats that token as access to all tools. Checked October 2026 against n8n 2.42.6.

What is the difference between the n8n MCP server and the MCP Server Trigger node?

The instance-level MCP server is one connection for the whole n8n instance, with central authentication and a list of workflows you choose to expose. The MCP Server Trigger is a node inside a single workflow that exposes only the tools you wire into that workflow. Use the instance server to build and manage workflows, and the trigger node to publish a custom tool set to other AI apps.

Do I need a paid n8n plan to use MCP with Claude Code?

The n8n docs describe instance-level MCP for both Cloud and self-hosted instances, and the official n8n Skills repository lists the prerequisite as an n8n instance on any plan with the instance-level MCP server enabled, minimum version 2.2.0. An instance owner or admin has to turn it on. You also need Claude Code itself, which has its own plans.

All Access · all four programs · $99/mo

You can now build automations by describing them. Learn to build the product around them.

AI SaaS Builder, included in All Access, covers Claude Code and MCP in depth, then the rest of a shippable product: Supabase, Next.js, Claude API features and Stripe billing. All Access adds the other three programs, live coaching and the private community.

Start All Access — $99/mo →30-day money-back guarantee
Free · no signup

Compare setups in the free Discord

Share your MCP config, scopes and permission rules with other builders, and see what they let their agents do.