n8n

n8n

Included as an automation runtime whose instance-level MCP lets authorized users discover, build, test, publish, execute, and inspect workflows and manage data-table structures, while individual workflows can expose narrower tool servers through the MCP Server Trigger node.

Automation, data & MCP bridgesSystem of orchestrationAgent-accessible SaaS
An illustration of access surfaces surrounding a governed system.
System roleSystem of orchestration
Access maturityAgent-accessible SaaS
MCP supportOfficial MCP server
Reference updatedNot stated by publisher
BYO-UI reviewedJul 22, 2026

Concrete capability record

Data, retrieval, actions, identity, and operating limits

A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.

01 · Records and state owned

Workflows and published versions, executions and test pin data, projects, folders and tags, credential metadata, node types and SDK references, and data tables, columns, and rows.

02 · Data you can retrieve

Search workflow previews across workflows the user can access; inspect details for MCP-enabled workflows; search projects, folders, tags, executions, and data tables; list credential metadata; and retrieve workflow-building references and validation results.

03 · Actions and write paths

Execute and test workflows; prepare test pin data; publish or unpublish; create workflows from code, update or archive them; and create, rename, or alter data tables and add rows. The catalog includes permanent data-table column deletion.

04 · Authentication and permissions

The instance-level endpoint supports OAuth 2.0, recommended by n8n, or a personal MCP access token tied to the user. Owners or admins enable MCP at the instance level; effective workflow visibility and actions remain user-scoped and include permission scopes in search results.

05 · Monitoring, approval, and recovery

An owner or admin enables instance MCP, then workflows are exposed individually or by project or folder. Connected OAuth clients can be revoked and personal tokens rotated, which revokes the previous token. Self-hosted operators can remove the module entirely with `N8N_DISABLED_MODULES=mcp`.

06 · Limits and caveats

All MCP clients connected by the same user see the same MCP-enabled workflows; workflows cannot be allowlisted per client. `search_workflows` can preview all workflows the user can access even when not marked Available in MCP. Building and table tools are version-gated, multi-step forms and human-in-the-loop workflow execution are unsupported, and data-table column deletion cannot be undone.

First-party MCP tool catalog

30 named MCP tools · Instance-level MCP server

The complete 30-tool list in n8n's instance-level MCP reference. It covers workflow discovery and execution, execution records, credential metadata, workflow building and validation, and data tables; it is separate from individual MCP Server Trigger nodes. Reviewed Jul 10, 2026. Cloud and self-hosted instances support OAuth or access-token authentication after an owner or administrator enables MCP. Visibility follows the user, but enabled workflows cannot be scoped differently per connected MCP client. Several tools require recent n8n versions. Separately, n8n's public directory displayed 1,938 integration entries on 2026-07-10; that dynamic total mixes regular, trigger, core, partner-built, and other node types and should not be read as 1,938 connectors maintained or individually verified by n8n.

First-party exact listComplete list on cited pagen8n instance-level MCP server
30 shown
Workflow discovery and operation10
search_workflowsreadget_workflow_detailsreadexecute_workflowconsequential writetest_workflowconsequential writeprepare_test_pin_datareadpublish_workflowconsequential writeunpublish_workflowconsequential writesearch_projectsreadsearch_foldersreadlist_tagsread
Executions and credential metadata3
get_executionreadsearch_executionsreadlist_credentialsread
Workflow building and validation10
get_sdk_referencereadsearch_nodesreadget_node_typesreadget_workflow_best_practicesreadexplore_node_resourcesreadvalidate_workflowreadvalidate_node_configreadcreate_workflow_from_codedraftupdate_workflowwritearchive_workflowwrite
Data tables7
search_data_tablesreadcreate_data_tablewriteadd_data_table_columnwriterename_data_table_columnwritedelete_data_table_columnconsequential writerename_data_tablewriteadd_data_table_rowswrite

Agent access

MCP support

Official MCP serverInstance-level n8n MCP server plus separate workflow-scoped MCP Server Trigger endpointsCurrent instance-level service; workflow-building tools require n8n v2.13 or later and individual tools have later version gates

Support: Official MCP server

Read scope: Search user-visible workflow previews and supporting project, folder, tag, execution, credential, node, and data-table metadata; retrieve full workflow details only where the current user has access and MCP exposure permits it.

Write scope: 13 of 30 reviewed named tools have a write, draft, or mixed action label, including execute_workflow, test_workflow, publish_workflow, unpublish_workflow, create_workflow_from_code, and others. Read each catalog boundary before enabling them.

Authentication: OAuth 2.0 authorization at the instance endpoint is recommended; a bearer-style personal MCP access token tied to the n8n user is also supported and can be rotated.

Approval boundary: Require confirmation before publishing or unpublishing a workflow, running a production workflow with external effects, editing or archiving a definition, or changing data-table structure. Treat `delete_data_table_column` as destructive because n8n states that it permanently removes the column and its data.

Protocol does not erase product boundaries.

Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.

Editorial assessment

Access-maturity dimensions

A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.

Data access4
Action access4
Event access4
Identity2
Governance3
Agent access4
UI extensibility3
Portability4
Observability4
Documentation5

Proposed customer-shaped experiences

What customers could create on top.

The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that n8n ships them.

Single-platform patterns

  • Custom agent and Marcom operations workbench
  • Marcom control plane
  • Data-quality exception console
  • Approved capability registry
Use in the brief builder →

Multi-platform compositions

  • n8n + systems of record: marcom control plane
  • n8n + systems of engagement + interface host or builder: cross-system decision workspace
Explore composition recipes →

Evidence and dates

First-party references, with publisher and review dates separated

“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.

7 recorded sources
MCPRepresentative source
https://docs.n8n.io/connect/connect-to-n8n-mcp-server ↗

Official n8n docs confirm native server, tool reference, trigger node and client node; distinguish tenant server from public docs MCP.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 12, 2026

Targeted first-party MCP/agent-role review; broader API inventory retained

APISource inventory
https://docs.n8n.io/api/ ↗

First-party API reference or API overview recorded for this platform.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Developer docsSource inventory
https://docs.n8n.io/ ↗

First-party developer documentation or platform overview.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

HomepageSource inventory
https://n8n.io/ ↗

First-party product homepage used to confirm product identity and current positioning.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Webhooks / extensionsSource inventory
https://docs.n8n.io/integrations/ ↗

First-party webhook, event, SDK, embedded-app, or extension documentation.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Integration directoryTargeted review
Best app and software integrations ↗

Named catalog evidence used on this profile.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Targeted first-party catalog review

Verified fact

Tied to cited first-party evidence reviewed for this profile.

Source inventory

Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.

Editorial assessment

System role, maturity interpretation, and architectural boundary.

Proposed design

Interface patterns and compositions—not vendor product claims.