Skip to main content

n8n MCP Server Trigger: Expose Any Workflow as an AI Tool

Set up the n8n MCP Server Trigger step by step: the MCP URL, authentication, tool descriptions and schemas AI clients call correctly, and a booking example.

Founder of IImagined.ai

Published
Oct 11, 2026
Reading time
12 min read
Quick answer

The n8n MCP Server Trigger turns a workflow into an MCP server: attach tool nodes, publish, and any MCP client that connects to its URL can list and call them. The setup takes minutes. Whether an AI client calls the right tool with the right arguments depends on the name, description and input schema you give each tool, so this guide covers those in detail, with an import-ready calendar booking server, the two MCP URLs, authentication and the fixes for common failures.

The n8n MCP Server Trigger turns a workflow into an MCP server: you attach tool nodes to it, publish, and any MCP client that connects to its URL can list those tools and call them. Adding the node takes five minutes. What decides whether an AI client calls the right tool with the right arguments is the name, description and input schema you give each tool, which is where this guide spends most of its time.

Checked October 2026 against n8n's docs for the MCP Server Trigger, the Call n8n Workflow Tool and $fromAI(), the node source in n8n 2.42.6 (the stable release on 9 October 2026), the Claude Code MCP docs, Anthropic's guide to defining tools and the MCP specification's tools page. The workflow JSON was checked against the node source and not executed, so test it on the test URL first.

This tutorial is part of our n8n hub. If MCP itself is new, read our plain-language MCP guide first; it explains servers, clients and tools.

n8n MCP server: the trigger node or the instance-level server?

n8n has two things called an MCP server, and they do different jobs. This page is about the first.

Two ways n8n acts as an MCP server
MCP Server Trigger node
  • A node inside one workflow
  • Exposes only the tool nodes you attach to it
  • Its own URL under /mcp/ and its own authentication
  • You write every tool name and description
  • For giving other AI apps a small, hand-built tool set
Instance-level MCP server
  • One connection for the whole n8n instance
  • Exposes workflows you mark as available, plus workflow-building tools
  • A URL that ends in /mcp-server/http, with OAuth scopes per client
  • n8n defines the tools
  • For building and running workflows from a coding agent

The instance-level server has its own walkthrough in connecting n8n to Claude Code via MCP. Use the trigger node when you want a client to have three or four specific abilities and nothing else.

How the MCP Server Trigger works

It is a trigger with no regular output. The docs put it this way: the node "only connects to and executes tool nodes". A client talks to it in four moves, and your design work decides the third.

One tool call, from client to calendar
  1. 01
    The client connects

    It opens the MCP URL over streamable HTTP or SSE and receives the server instructions.

  2. 02
    It lists the tools

    n8n returns each tool's name, description and input schema.

  3. 03
    The model picks one

    It reads those three things, nothing else, and fills in the arguments.

  4. 04
    n8n runs the tool node

    The arguments land in the node through $fromAI(), next to the values you fixed.

  5. 05
    The result goes back

    The node's output returns to the client as the tool result.

Prerequisites

Pre-flight checklist
  • An n8n instance on a recent 2.x release that an MCP client can reach over HTTPS
  • A Google Calendar OAuth2 credential in n8n, and the ID of a calendar used only for bookings
  • A long random token for the Bearer Auth credential
  • An MCP client that speaks streamable HTTP or SSE, such as Claude Code
  • Behind nginx or another proxy: buffering switched off for the /mcp/ path
  • Ten minutes to write the tool descriptions before you connect anything

Set up the n8n MCP Server Trigger: the steps

From empty canvas to a working MCP tool
  1. 1
    Add the trigger

    New workflow, add MCP Server Trigger. Expected result: the panel shows an MCP URL with Test URL and Production URL.

  2. 2
    Set Path and Authentication

    Path: booking. Authentication: Bearer Auth, with a new credential holding your token. Expected result: the Production URL ends in /mcp/booking.

  3. 3
    Write the Instructions

    Rules that span tools, such as: always check availability before creating a booking.

  4. 4
    Attach the tools

    Select the Tools connector and add two Google Calendar Tool nodes: one Availability, one Create event. Expected result: both hang under the trigger.

  5. 5
    Name and describe each tool

    Rename the nodes check_availability and create_booking. Set Tool Description to Set Manually and write when to call each one.

  6. 6
    Open the inputs to the model

    Use $fromAI() only for values the model must supply: start, end, title, attendee email. Fix the calendar yourself.

  7. 7
    Test on the test URL

    Select Listen for Test Event, connect a client to the Test URL and ask for a booking. Expected result: the call shows in the editor.

  8. 8
    Publish and switch URLs

    Publish the workflow and give your client the Production URL. Expected result: runs appear in the Executions tab.

Here is the finished workflow. Copy it, paste it onto a blank canvas, select your Google Calendar and Bearer Auth credentials, and replace the calendar ID in both tool nodes.

{
  "name": "Booking MCP server",
  "nodes": [
    {
      "parameters": {
        "authentication": "bearerAuth",
        "path": "booking",
        "instructions": "Tools for booking a 30 minute call. Always call check_availability for a time range before create_booking. Send times as ISO 8601 with a UTC offset. Never create an event the person has not confirmed."
      },
      "id": "e5c0a6d3-0001-4a4f-9c5e-000000000001",
      "name": "Booking MCP server",
      "type": "@n8n/n8n-nodes-langchain.mcpTrigger",
      "typeVersion": 2,
      "position": [
        0,
        0
      ],
      "webhookId": "e5c0a6d3-0004-4a4f-9c5e-000000000004"
    },
    {
      "parameters": {
        "descriptionType": "manual",
        "toolDescription": "Check whether a time range is free on the booking calendar. Use it before create_booking and whenever someone asks if a time is open. Pass start and end as ISO 8601 with a UTC offset, for example 2026-10-14T15:00:00+02:00, and keep the range to the length of one call. Returns available: true when nothing is booked in that range. It does not suggest other times.",
        "resource": "calendar",
        "operation": "availability",
        "calendar": {
          "__rl": true,
          "mode": "id",
          "value": "REPLACE_WITH_CALENDAR_ID@group.calendar.google.com"
        },
        "timeMin": "={{ $fromAI('start', 'Start of the range to check, ISO 8601 with UTC offset, for example 2026-10-14T15:00:00+02:00', 'string') }}",
        "timeMax": "={{ $fromAI('end', 'End of the range to check, ISO 8601 with UTC offset', 'string') }}",
        "options": {}
      },
      "id": "e5c0a6d3-0002-4a4f-9c5e-000000000002",
      "name": "check_availability",
      "type": "n8n-nodes-base.googleCalendarTool",
      "typeVersion": 1.3,
      "position": [
        -120,
        220
      ]
    },
    {
      "parameters": {
        "descriptionType": "manual",
        "toolDescription": "Create a calendar event for a confirmed call and invite the attendee. Only use it after check_availability returned available: true for the same start and end, and after the person has confirmed the time. Pass start and end as ISO 8601 with a UTC offset. It cannot move or cancel an existing event.",
        "resource": "event",
        "operation": "create",
        "calendar": {
          "__rl": true,
          "mode": "id",
          "value": "REPLACE_WITH_CALENDAR_ID@group.calendar.google.com"
        },
        "start": "={{ $fromAI('start', 'Start of the call, ISO 8601 with UTC offset, for example 2026-10-14T15:00:00+02:00', 'string') }}",
        "end": "={{ $fromAI('end', 'End of the call, ISO 8601 with UTC offset', 'string') }}",
        "additionalFields": {
          "summary": "={{ $fromAI('title', 'Short event title, for example Intro call with Dana Lee', 'string') }}",
          "attendees": [
            "={{ $fromAI('attendee_email', 'Email address of the person booking the call', 'string') }}"
          ],
          "sendUpdates": "all"
        }
      },
      "id": "e5c0a6d3-0003-4a4f-9c5e-000000000003",
      "name": "create_booking",
      "type": "n8n-nodes-base.googleCalendarTool",
      "typeVersion": 1.3,
      "position": [
        120,
        220
      ]
    }
  ],
  "connections": {
    "check_availability": {
      "ai_tool": [
        [
          {
            "node": "Booking MCP server",
            "type": "ai_tool",
            "index": 0
          }
        ]
      ]
    },
    "create_booking": {
      "ai_tool": [
        [
          {
            "node": "Booking MCP server",
            "type": "ai_tool",
            "index": 0
          }
        ]
      ]
    }
  },
  "settings": {
    "executionOrder": "v1"
  }
}

The calendar is fixed in both nodes, so no client can read or write any other calendar. sendUpdates is set to all, which the node describes as notifications sent to all guests.

n8n MCP URL: test, production and what the path means

The node shows both URLs at the top of its panel. They differ by one path segment and by when they listen.

URLShapeListensUse it for
Production URLhttps://<your-n8n>/mcp/<path>After you publish the workflowReal clients
Test URLhttps://<your-n8n>/mcp-test/<path>While you select Listen for Test Event or Execute workflowWatching calls arrive in the editor
Node version 1 workflowshttps://<your-n8n>/mcp/<path>/sseOlder workflows that still use the first version of the nodeSSE clients only

The mcp and mcp-test segments are n8n's defaults (N8N_ENDPOINT_MCP and N8N_ENDPOINT_MCP_TEST in the config source). Pick a path that is hard to guess if you run without authentication, though a path is not a secret: it ends up in client configs and logs.

Expose an n8n workflow as an MCP tool the model calls correctly

A model never sees your workflow. It sees a name, a description and a schema, and chooses from those. Anthropic's tool documentation is blunt about the priority: "Provide extremely detailed descriptions. This is by far the most important factor in tool performance." It asks for what the tool does, when it should and should not be used, what each parameter means and any caveats, in at least three or four sentences. In n8n, each of those pieces comes from a specific setting:

What the client seesWhere n8n takes it fromWhat to do
Tool nameThe tool node's name on the canvas. Anything other than letters, numbers, underscores and hyphens becomes an underscore, and the name is cut at 64 charactersRename the node to a verb and an object: check_availability
DescriptionThe Tool Description setting. Set Automatically builds it from the operation; Set Manually uses your textAlways Set Manually. Say when to call it and when not to
Input schemaEvery $fromAI(key, description, type) in the node's parameters becomes one input propertyOne call per value the model must supply, with a format and an example in the description
Fixed valuesAny parameter without $fromAI() is yours and never shown to the clientFix the calendar, the account and anything else the model should not choose
Server instructionsThe Instructions field on the trigger, sent to clients when they connectRules that span tools, such as the order to call them in
The same tool, described two ways
Left on automatic
  • Name: Google_Calendar1
  • Description: Create an event in Google Calendar
  • Parameter: Start, with no format given
  • The model also chooses the calendar
  • Nothing says a check must come first
Written for a model
  • Name: create_booking
  • Description: what it does, when to call it, when not to, what it cannot do
  • Parameter: start, ISO 8601 with UTC offset, with an example
  • The calendar is fixed in the node
  • Instructions: always call check_availability first

Two smaller rules. Keep the tool list short: n8n's own docs note that a built-in tool gives "tighter control" because you fix the operation and pin parameters, and every extra tool is one more thing to choose wrongly. And return little: a tool that answers available: true is easier for a model to act on than one that returns a raw API response.

When one node is not enough: Call n8n Workflow Tool

To expose a whole workflow as one tool, attach a Call n8n Workflow Tool node instead of an app tool. Three settings matter:

  1. The sub-workflow's inputs. Start it with the When Executed by Another Workflow trigger and set Input data mode to Define using fields below. Those fields become the tool's inputs.
  2. Description. The same rules as above. This text is the only thing a client knows about the workflow.
  3. Workflow Inputs. For each field, either fix a value or let the model supply it with $fromAI().

The sub-workflow has to be published. If it is not, the docs say the call fails with Workflow is not active and cannot be executed, returned as the tool result, which is easy to miss inside a longer answer. A good use: one book_call tool whose sub-workflow checks availability, creates the event and sends a confirmation, so the model makes one decision and not three.

Connect a client

Claude Code connects to the production URL directly. The header flag carries the token from your Bearer Auth credential:

claude mcp add --transport http booking https://n8n.example.com/mcp/booking \
  --header "Authorization: Bearer <your-token>"

Run /mcp inside Claude Code to confirm the server is connected and lists two tools. For Claude Desktop, the n8n docs use the mcp-remote gateway in the app's config file, with the same URL and header. Other servers worth running next to it are in our list of the best MCP servers for coding.

Authentication: who can call your tools

Whoever can connect can run your tools with the credentials saved in n8n. The node offers four settings in 2.42.6; the docs list the first three.

AuthenticationWhat the client sendsUse it when
NoneNothingA local instance that only you can reach
Bearer AuthAuthorization: Bearer <token>The default choice: one token per client set
Header AuthA header name and value you chooseClients or gateways that already send a custom header
n8n User Auth (OAuth2)The user signs in to n8n and gives consentTeam instances on node version 2 or later, where each caller should be a known n8n user

Authentication decides who gets in, not what they can do. That part is the tool design: a tool that can only create an event on one calendar cannot be talked into deleting anything. The MCP specification adds that a human should be able to deny tool calls, so prefer clients that ask before running a write tool.

Troubleshooting

What you seeCauseFix
The client connects, then hangs or drops behind nginxThe proxy buffers the streamIn the location block for /mcp/: proxy_buffering off, gzip off, chunked_transfer_encoding off and an empty Connection header
Works on the test URL, fails in productionThe workflow is not published, or the client still points at /mcp-test/Publish, then give the client the Production URL
401 or 403 on connectThe token or header does not match the credentialSend Authorization: Bearer followed by the exact token stored in n8n
claude.ai asks you to sign in to n8n although Authentication is NoneDocumented behaviour: claude.ai assumes n8n user authentication on your domainUse another client for unauthenticated tests, or set up authentication
The tool result says "Workflow is not active and cannot be executed"A Call n8n Workflow Tool points at a sub-workflow that is not publishedPublish the sub-workflow
Connections break at random in queue modeSeveral webhook replicas share MCP trafficRoute all /mcp requests to one dedicated webhook replica
The model sends dates the tool rejectsThe parameter description gives no formatPut the format and one example in the $fromAI() description

In queue mode there are two more limits worth knowing: a queued tool call gets 120 seconds by default in 2.42.6, and a tool result larger than the webhook relay limit comes back as a tool error. Our n8n queue mode guide covers both settings.

Tool design is a skill that outlasts any one platform. Our AI SaaS Builder program has no n8n lessons, but it spends two modules on MCP in code: building your first MCP server, MCP use cases for a SaaS and building MCP into your own product.

n8n MCP Server Trigger: FAQ

What is the n8n MCP Server Trigger?

It is a trigger node that makes a workflow act as a Model Context Protocol server. Instead of passing data to the next node, it only connects to tool nodes. An MCP client that connects to the trigger's URL can list those tools and call them, and n8n runs the matching tool node. It supports SSE and streamable HTTP connections, not stdio. Checked October 2026 against the n8n docs.

What is the n8n MCP URL for the MCP Server Trigger?

The node shows two MCP URLs at the top of its panel. The production URL is your n8n address followed by /mcp/ and the Path you set, for example https://n8n.example.com/mcp/booking, and it works once the workflow is published. The test URL uses /mcp-test/ and only listens while you are testing in the editor. Workflows built with node version 1 add /sse to the path.

How do I expose an n8n workflow as an MCP tool?

Add an MCP Server Trigger, then attach a Call n8n Workflow Tool node to its Tools connector and select the workflow. Give the tool a description that says when to call it, and define the inputs with $fromAI() or the sub-workflow's input fields. Publish both workflows. For a single action, such as creating a calendar event, attach that app's tool node directly instead.

Does the n8n MCP Server Trigger support streamable HTTP?

Yes. The n8n docs say the node supports both Server-Sent Events and streamable HTTP, and does not support stdio. Clients that only speak stdio, such as older desktop app setups, need a small gateway like mcp-remote in front, which is what the n8n docs show for Claude Desktop. Claude Code connects directly with claude mcp add --transport http.

How do I secure an n8n MCP Server Trigger?

Set the node's Authentication to Bearer Auth or Header Auth and store a long random token in the credential, then send it from the client as a header. Without it, anyone who learns the URL can call your tools with the credentials saved in n8n. Keep write tools narrow, fix every parameter the model does not need to choose, and use a hard-to-guess path.

Why does my AI client call the wrong n8n tool?

Almost always because of the description. With Tool Description left on Set Automatically, n8n generates a line such as "Create an event in Google Calendar", which says nothing about when to use the tool or what its inputs mean. Switch to Set Manually, state when to call it and when not to, give each $fromAI() parameter a format and an example, and make tool names distinct.

Does the MCP Server Trigger work in n8n queue mode?

Yes, with one condition. The n8n docs say it works as expected with a single webhook replica. If you run several webhook replicas, route all /mcp requests to one dedicated replica, or SSE and streamable HTTP connections break. In queue mode the tool runs on a worker, and in n8n 2.42.6 a queued tool call is given 120 seconds by default.

All Access · all four programs · $99/mo

Your workflow is now a tool an AI can call. Next, build the server yourself.

AI SaaS Builder, included in All Access, goes from using MCP to writing it: building your first MCP server, MCP in your own product, Claude API tool use, Supabase, deployment and Stripe billing. It has no n8n lessons. All Access adds the other three programs, live coaching and the private community.

Start All Access — $99/mo →30-day money-back guarantee
Free

Show us your tool descriptions

Post your MCP tool names and descriptions in the free Discord and see how other builders word theirs before you let a client loose on them.