The n8n MCP Server Trigger turns a workflow into an MCP server: attach tool nodes, publish, and any MCP client that connects to its URL can list and call them. The setup takes minutes. Whether an AI client calls the right tool with the right arguments depends on the name, description and input schema you give each tool, so this guide covers those in detail, with an import-ready calendar booking server, the two MCP URLs, authentication and the fixes for common failures.
The n8n MCP Server Trigger turns a workflow into an MCP server: you attach tool nodes to it, publish, and any MCP client that connects to its URL can list those tools and call them. Adding the node takes five minutes. What decides whether an AI client calls the right tool with the right arguments is the name, description and input schema you give each tool, which is where this guide spends most of its time.
Checked October 2026 against n8n's docs for the MCP Server Trigger, the Call n8n Workflow Tool and $fromAI(), the node source in n8n 2.42.6 (the stable release on 9 October 2026), the Claude Code MCP docs, Anthropic's guide to defining tools and the MCP specification's tools page. The workflow JSON was checked against the node source and not executed, so test it on the test URL first.
This tutorial is part of our n8n hub. If MCP itself is new, read our plain-language MCP guide first; it explains servers, clients and tools.
n8n MCP server: the trigger node or the instance-level server?
n8n has two things called an MCP server, and they do different jobs. This page is about the first.
- A node inside one workflow
- Exposes only the tool nodes you attach to it
- Its own URL under /mcp/ and its own authentication
- You write every tool name and description
- For giving other AI apps a small, hand-built tool set
- One connection for the whole n8n instance
- Exposes workflows you mark as available, plus workflow-building tools
- A URL that ends in /mcp-server/http, with OAuth scopes per client
- n8n defines the tools
- For building and running workflows from a coding agent
The instance-level server has its own walkthrough in connecting n8n to Claude Code via MCP. Use the trigger node when you want a client to have three or four specific abilities and nothing else.
How the MCP Server Trigger works
It is a trigger with no regular output. The docs put it this way: the node "only connects to and executes tool nodes". A client talks to it in four moves, and your design work decides the third.
- 01The client connects
It opens the MCP URL over streamable HTTP or SSE and receives the server instructions.
- 02It lists the tools
n8n returns each tool's name, description and input schema.
- 03The model picks one
It reads those three things, nothing else, and fills in the arguments.
- 04n8n runs the tool node
The arguments land in the node through $fromAI(), next to the values you fixed.
- 05The result goes back
The node's output returns to the client as the tool result.
Prerequisites
- An n8n instance on a recent 2.x release that an MCP client can reach over HTTPS
- A Google Calendar OAuth2 credential in n8n, and the ID of a calendar used only for bookings
- A long random token for the Bearer Auth credential
- An MCP client that speaks streamable HTTP or SSE, such as Claude Code
- Behind nginx or another proxy: buffering switched off for the /mcp/ path
- Ten minutes to write the tool descriptions before you connect anything
Set up the n8n MCP Server Trigger: the steps
- 1Add the trigger
New workflow, add MCP Server Trigger. Expected result: the panel shows an MCP URL with Test URL and Production URL.
- 2Set Path and Authentication
Path: booking. Authentication: Bearer Auth, with a new credential holding your token. Expected result: the Production URL ends in /mcp/booking.
- 3Write the Instructions
Rules that span tools, such as: always check availability before creating a booking.
- 4Attach the tools
Select the Tools connector and add two Google Calendar Tool nodes: one Availability, one Create event. Expected result: both hang under the trigger.
- 5Name and describe each tool
Rename the nodes check_availability and create_booking. Set Tool Description to Set Manually and write when to call each one.
- 6Open the inputs to the model
Use $fromAI() only for values the model must supply: start, end, title, attendee email. Fix the calendar yourself.
- 7Test on the test URL
Select Listen for Test Event, connect a client to the Test URL and ask for a booking. Expected result: the call shows in the editor.
- 8Publish and switch URLs
Publish the workflow and give your client the Production URL. Expected result: runs appear in the Executions tab.
Here is the finished workflow. Copy it, paste it onto a blank canvas, select your Google Calendar and Bearer Auth credentials, and replace the calendar ID in both tool nodes.
{
"name": "Booking MCP server",
"nodes": [
{
"parameters": {
"authentication": "bearerAuth",
"path": "booking",
"instructions": "Tools for booking a 30 minute call. Always call check_availability for a time range before create_booking. Send times as ISO 8601 with a UTC offset. Never create an event the person has not confirmed."
},
"id": "e5c0a6d3-0001-4a4f-9c5e-000000000001",
"name": "Booking MCP server",
"type": "@n8n/n8n-nodes-langchain.mcpTrigger",
"typeVersion": 2,
"position": [
0,
0
],
"webhookId": "e5c0a6d3-0004-4a4f-9c5e-000000000004"
},
{
"parameters": {
"descriptionType": "manual",
"toolDescription": "Check whether a time range is free on the booking calendar. Use it before create_booking and whenever someone asks if a time is open. Pass start and end as ISO 8601 with a UTC offset, for example 2026-10-14T15:00:00+02:00, and keep the range to the length of one call. Returns available: true when nothing is booked in that range. It does not suggest other times.",
"resource": "calendar",
"operation": "availability",
"calendar": {
"__rl": true,
"mode": "id",
"value": "REPLACE_WITH_CALENDAR_ID@group.calendar.google.com"
},
"timeMin": "={{ $fromAI('start', 'Start of the range to check, ISO 8601 with UTC offset, for example 2026-10-14T15:00:00+02:00', 'string') }}",
"timeMax": "={{ $fromAI('end', 'End of the range to check, ISO 8601 with UTC offset', 'string') }}",
"options": {}
},
"id": "e5c0a6d3-0002-4a4f-9c5e-000000000002",
"name": "check_availability",
"type": "n8n-nodes-base.googleCalendarTool",
"typeVersion": 1.3,
"position": [
-120,
220
]
},
{
"parameters": {
"descriptionType": "manual",
"toolDescription": "Create a calendar event for a confirmed call and invite the attendee. Only use it after check_availability returned available: true for the same start and end, and after the person has confirmed the time. Pass start and end as ISO 8601 with a UTC offset. It cannot move or cancel an existing event.",
"resource": "event",
"operation": "create",
"calendar": {
"__rl": true,
"mode": "id",
"value": "REPLACE_WITH_CALENDAR_ID@group.calendar.google.com"
},
"start": "={{ $fromAI('start', 'Start of the call, ISO 8601 with UTC offset, for example 2026-10-14T15:00:00+02:00', 'string') }}",
"end": "={{ $fromAI('end', 'End of the call, ISO 8601 with UTC offset', 'string') }}",
"additionalFields": {
"summary": "={{ $fromAI('title', 'Short event title, for example Intro call with Dana Lee', 'string') }}",
"attendees": [
"={{ $fromAI('attendee_email', 'Email address of the person booking the call', 'string') }}"
],
"sendUpdates": "all"
}
},
"id": "e5c0a6d3-0003-4a4f-9c5e-000000000003",
"name": "create_booking",
"type": "n8n-nodes-base.googleCalendarTool",
"typeVersion": 1.3,
"position": [
120,
220
]
}
],
"connections": {
"check_availability": {
"ai_tool": [
[
{
"node": "Booking MCP server",
"type": "ai_tool",
"index": 0
}
]
]
},
"create_booking": {
"ai_tool": [
[
{
"node": "Booking MCP server",
"type": "ai_tool",
"index": 0
}
]
]
}
},
"settings": {
"executionOrder": "v1"
}
}The calendar is fixed in both nodes, so no client can read or write any other calendar. sendUpdates is set to all, which the node describes as notifications sent to all guests.
n8n MCP URL: test, production and what the path means
The node shows both URLs at the top of its panel. They differ by one path segment and by when they listen.
| URL | Shape | Listens | Use it for |
|---|---|---|---|
| Production URL | https://<your-n8n>/mcp/<path> | After you publish the workflow | Real clients |
| Test URL | https://<your-n8n>/mcp-test/<path> | While you select Listen for Test Event or Execute workflow | Watching calls arrive in the editor |
| Node version 1 workflows | https://<your-n8n>/mcp/<path>/sse | Older workflows that still use the first version of the node | SSE clients only |
The mcp and mcp-test segments are n8n's defaults (N8N_ENDPOINT_MCP and N8N_ENDPOINT_MCP_TEST in the config source). Pick a path that is hard to guess if you run without authentication, though a path is not a secret: it ends up in client configs and logs.
Expose an n8n workflow as an MCP tool the model calls correctly
A model never sees your workflow. It sees a name, a description and a schema, and chooses from those. Anthropic's tool documentation is blunt about the priority: "Provide extremely detailed descriptions. This is by far the most important factor in tool performance." It asks for what the tool does, when it should and should not be used, what each parameter means and any caveats, in at least three or four sentences. In n8n, each of those pieces comes from a specific setting:
| What the client sees | Where n8n takes it from | What to do |
|---|---|---|
| Tool name | The tool node's name on the canvas. Anything other than letters, numbers, underscores and hyphens becomes an underscore, and the name is cut at 64 characters | Rename the node to a verb and an object: check_availability |
| Description | The Tool Description setting. Set Automatically builds it from the operation; Set Manually uses your text | Always Set Manually. Say when to call it and when not to |
| Input schema | Every $fromAI(key, description, type) in the node's parameters becomes one input property | One call per value the model must supply, with a format and an example in the description |
| Fixed values | Any parameter without $fromAI() is yours and never shown to the client | Fix the calendar, the account and anything else the model should not choose |
| Server instructions | The Instructions field on the trigger, sent to clients when they connect | Rules that span tools, such as the order to call them in |
- Name: Google_Calendar1
- Description: Create an event in Google Calendar
- Parameter: Start, with no format given
- The model also chooses the calendar
- Nothing says a check must come first
- Name: create_booking
- Description: what it does, when to call it, when not to, what it cannot do
- Parameter: start, ISO 8601 with UTC offset, with an example
- The calendar is fixed in the node
- Instructions: always call check_availability first
Two smaller rules. Keep the tool list short: n8n's own docs note that a built-in tool gives "tighter control" because you fix the operation and pin parameters, and every extra tool is one more thing to choose wrongly. And return little: a tool that answers available: true is easier for a model to act on than one that returns a raw API response.
When one node is not enough: Call n8n Workflow Tool
To expose a whole workflow as one tool, attach a Call n8n Workflow Tool node instead of an app tool. Three settings matter:
- The sub-workflow's inputs. Start it with the When Executed by Another Workflow trigger and set Input data mode to Define using fields below. Those fields become the tool's inputs.
- Description. The same rules as above. This text is the only thing a client knows about the workflow.
- Workflow Inputs. For each field, either fix a value or let the model supply it with
$fromAI().
The sub-workflow has to be published. If it is not, the docs say the call fails with Workflow is not active and cannot be executed, returned as the tool result, which is easy to miss inside a longer answer. A good use: one book_call tool whose sub-workflow checks availability, creates the event and sends a confirmation, so the model makes one decision and not three.
Connect a client
Claude Code connects to the production URL directly. The header flag carries the token from your Bearer Auth credential:
claude mcp add --transport http booking https://n8n.example.com/mcp/booking \
--header "Authorization: Bearer <your-token>"Run /mcp inside Claude Code to confirm the server is connected and lists two tools. For Claude Desktop, the n8n docs use the mcp-remote gateway in the app's config file, with the same URL and header. Other servers worth running next to it are in our list of the best MCP servers for coding.
Authentication: who can call your tools
Whoever can connect can run your tools with the credentials saved in n8n. The node offers four settings in 2.42.6; the docs list the first three.
| Authentication | What the client sends | Use it when |
|---|---|---|
| None | Nothing | A local instance that only you can reach |
| Bearer Auth | Authorization: Bearer <token> | The default choice: one token per client set |
| Header Auth | A header name and value you choose | Clients or gateways that already send a custom header |
| n8n User Auth (OAuth2) | The user signs in to n8n and gives consent | Team instances on node version 2 or later, where each caller should be a known n8n user |
Authentication decides who gets in, not what they can do. That part is the tool design: a tool that can only create an event on one calendar cannot be talked into deleting anything. The MCP specification adds that a human should be able to deny tool calls, so prefer clients that ask before running a write tool.
Troubleshooting
| What you see | Cause | Fix |
|---|---|---|
| The client connects, then hangs or drops behind nginx | The proxy buffers the stream | In the location block for /mcp/: proxy_buffering off, gzip off, chunked_transfer_encoding off and an empty Connection header |
| Works on the test URL, fails in production | The workflow is not published, or the client still points at /mcp-test/ | Publish, then give the client the Production URL |
| 401 or 403 on connect | The token or header does not match the credential | Send Authorization: Bearer followed by the exact token stored in n8n |
| claude.ai asks you to sign in to n8n although Authentication is None | Documented behaviour: claude.ai assumes n8n user authentication on your domain | Use another client for unauthenticated tests, or set up authentication |
| The tool result says "Workflow is not active and cannot be executed" | A Call n8n Workflow Tool points at a sub-workflow that is not published | Publish the sub-workflow |
| Connections break at random in queue mode | Several webhook replicas share MCP traffic | Route all /mcp requests to one dedicated webhook replica |
| The model sends dates the tool rejects | The parameter description gives no format | Put the format and one example in the $fromAI() description |
In queue mode there are two more limits worth knowing: a queued tool call gets 120 seconds by default in 2.42.6, and a tool result larger than the webhook relay limit comes back as a tool error. Our n8n queue mode guide covers both settings.
Tool design is a skill that outlasts any one platform. Our AI SaaS Builder program has no n8n lessons, but it spends two modules on MCP in code: building your first MCP server, MCP use cases for a SaaS and building MCP into your own product.
n8n MCP Server Trigger: FAQ
What is the n8n MCP Server Trigger?
It is a trigger node that makes a workflow act as a Model Context Protocol server. Instead of passing data to the next node, it only connects to tool nodes. An MCP client that connects to the trigger's URL can list those tools and call them, and n8n runs the matching tool node. It supports SSE and streamable HTTP connections, not stdio. Checked October 2026 against the n8n docs.
What is the n8n MCP URL for the MCP Server Trigger?
The node shows two MCP URLs at the top of its panel. The production URL is your n8n address followed by /mcp/ and the Path you set, for example https://n8n.example.com/mcp/booking, and it works once the workflow is published. The test URL uses /mcp-test/ and only listens while you are testing in the editor. Workflows built with node version 1 add /sse to the path.
How do I expose an n8n workflow as an MCP tool?
Add an MCP Server Trigger, then attach a Call n8n Workflow Tool node to its Tools connector and select the workflow. Give the tool a description that says when to call it, and define the inputs with $fromAI() or the sub-workflow's input fields. Publish both workflows. For a single action, such as creating a calendar event, attach that app's tool node directly instead.
Does the n8n MCP Server Trigger support streamable HTTP?
Yes. The n8n docs say the node supports both Server-Sent Events and streamable HTTP, and does not support stdio. Clients that only speak stdio, such as older desktop app setups, need a small gateway like mcp-remote in front, which is what the n8n docs show for Claude Desktop. Claude Code connects directly with claude mcp add --transport http.
How do I secure an n8n MCP Server Trigger?
Set the node's Authentication to Bearer Auth or Header Auth and store a long random token in the credential, then send it from the client as a header. Without it, anyone who learns the URL can call your tools with the credentials saved in n8n. Keep write tools narrow, fix every parameter the model does not need to choose, and use a hard-to-guess path.
Why does my AI client call the wrong n8n tool?
Almost always because of the description. With Tool Description left on Set Automatically, n8n generates a line such as "Create an event in Google Calendar", which says nothing about when to use the tool or what its inputs mean. Switch to Set Manually, state when to call it and when not to, give each $fromAI() parameter a format and an example, and make tool names distinct.
Does the MCP Server Trigger work in n8n queue mode?
Yes, with one condition. The n8n docs say it works as expected with a single webhook replica. If you run several webhook replicas, route all /mcp requests to one dedicated replica, or SSE and streamable HTTP connections break. In queue mode the tool runs on a worker, and in n8n 2.42.6 a queued tool call is given 120 seconds by default.
Your workflow is now a tool an AI can call. Next, build the server yourself.
AI SaaS Builder, included in All Access, goes from using MCP to writing it: building your first MCP server, MCP in your own product, Claude API tool use, Supabase, deployment and Stripe billing. It has no n8n lessons. All Access adds the other three programs, live coaching and the private community.
Show us your tool descriptions
Post your MCP tool names and descriptions in the free Discord and see how other builders word theirs before you let a client loose on them.