n8n Manager MCP Server
Part of the ellmos-ai family and open-bricks umbrella.
[!NOTE] For AI Assistants & LLMs: An
llms.txtindex file is available in the root directory for fast context ingestion, tool catalog references, and directory listings.
MCP (Model Context Protocol) server for managing n8n workflows via AI assistants like Claude, Cursor, and Windsurf.
System Architecture
graph TD
A["AI Client (Claude / Cursor / Windsurf)"] -->|MCP Stdio Protocol| B["n8n Manager MCP Server"]
subgraph "n8n Manager MCP Server"
B --> C["Tool Router (19 Tools)"]
C --> D["Safety Layer (Read-Only / Backups / Audit)"]
C --> E["Multi-Server Manager"]
end
E -->|REST API (API Key / Basic Auth)| F["n8n Instance 1 (Local)"]
E -->|REST API (API Key / Basic Auth)| G["n8n Instance 2 (Cloud / Remote)"]
D --> H[("Local Store (~/.n8n-manager-mcp/)")]
Directory Status
- npm package: published as
n8n-manager-mcp - Glama listing: public directory page for the ellmos-ai repo
- Enterprise DNA directory: additional public directory entry for
ellmos-ai/n8n-manager-mcp - PulseMCP listing: indexed as
ellmos-ai-n8n-manager - MCP namespace status: this repo contains
server.jsonandmcpNamemetadata forio.github.ellmos-ai/n8n-manager-mcp; some ecosystem directories still expose the legacyio.github.lukisch/n8n-manager-mcpname until their indexes refresh. - Search context: best matched by
n8n MCP server,n8n workflow management MCP,AI assistant n8n workflows, andellmos-ai n8n-manager-mcp.
Features
- 19 Tools for complete n8n workflow management
- List, create, update, delete, and activate/deactivate workflows
- Safety controls: read-only mode, backup-before-delete/update, local restore, and audit log
- Multi-server support (connect to multiple n8n instances)
- Export/Import workflows between servers
- View execution history and status
- Built-in node catalog with descriptions
- Zero dependencies on Python -- connects directly to n8n REST API
Installation
Claude Desktop
Add to claude_desktop_config.json:
{
"mcpServers": {
"n8n-manager": {
"command": "npx",
"args": ["-y", "n8n-manager-mcp"]
}
}
}
Claude Code
claude mcp add --scope user n8n-manager npx -y n8n-manager-mcp
Manual
npm install -g n8n-manager-mcp
Quick Start
After installation, use these commands in your AI assistant:
-
Add your n8n server:
"Add my n8n server at http://localhost:5678 with API key abc123"
-
List workflows:
"Show me all workflows on my n8n server"
-
Create a workflow:
"Create an n8n workflow that triggers on a webhook, fetches data from an API, and sends a Slack message"
-
Check executions:
"Show me the last 10 workflow executions"
Available Tools
| Tool | Description |
|---|---|
n8n_list_workflows |
List all workflows on a server |
n8n_get_workflow |
Get workflow details (nodes, connections) |
n8n_create_workflow |
Create a new workflow from nodes + connections |
n8n_update_workflow |
Update an existing workflow |
n8n_delete_workflow |
Delete a workflow |
n8n_activate_workflow |
Activate or deactivate a workflow |
n8n_list_executions |
List recent executions with status |
n8n_export_workflow |
Export workflow as importable JSON |
n8n_import_workflow |
Import workflow JSON onto a server |
n8n_safety_status |
Show local safety settings, backup directory, and audit log path |
n8n_set_safety_mode |
Toggle read-only mode, backup-before-mutation, and audit logging |
n8n_list_backups |
List local workflow backups created before mutations |
n8n_restore_workflow |
Restore a workflow from a local backup |
n8n_add_server |
Add/update n8n server connection |
n8n_list_servers |
List configured servers |
n8n_ping_server |
Test server connection |
n8n_remove_server |
Remove a server |
n8n_describe_nodes |
Browse available n8n node types |
n8n_manager_history |
Read version history, recorded decisions, and sync history from an optional n8n-workflow-manager (opt-in, read-only) |
Optional: n8n-workflow-manager seam
n8n itself keeps no record of why a workflow changed. The sibling project
n8n-workflow-manager does: it
stores versions, a mandatory decision per mutation, and a sync history in a local
database. n8n_manager_history makes that record readable from this MCP server.
The seam is opt-in and read-only:
- Without
N8N_MCP_MANAGER_URL, nothing changes — every tool talks to n8n directly, as before. - With it set (for example
http://127.0.0.1:8100),n8n_manager_historyreads from the running manager. Omitworkflow_idto list the manager's workflows, pass it for full history. - IDs are manager IDs, not n8n instance IDs. The manager stores that mapping but exposes no route to resolve it, so this server does not guess a translation.
- If the manager is configured but unreachable, the tool fails with an explicit message instead of quietly answering from the n8n instance — that store has no decision history, so a substituted answer would be a different answer.
n8n_safety_statusreports the measured state of the seam (configured, reachable, manager version), not just the environment variable.
Setup: pip install n8n-workflow-manager, then n8n-manager serve (binds 127.0.0.1:8100).
The manager API is unauthenticated and loopback-only by design; a non-loopback URL is
flagged in n8n_safety_status.
Numeric guardrails are part of the MCP schemas: workflow, execution, and
backup list limits are finite positive integers from 1 to 1000 (the existing
defaults remain 100, 20, and 20), and workflow connection from_output/
to_input indices are finite non-negative integers from 0 to 1000. Invalid
values are rejected before any n8n API, filesystem, or workflow-array access.
Configuration
Server connections and safety settings are stored in ~/.n8n-manager-mcp/servers.json.
Safety defaults:
backup_before_mutations: truesaves workflow JSON before update, delete, activate/deactivate, and overwrite-restore operations.audit_log: trueappends mutation outcomes to~/.n8n-manager-mcp/audit.log.read_only: falsecan be enabled withn8n_set_safety_modeorN8N_MANAGER_READ_ONLY=1. The environment flag is an enforcement ceiling: while it is enabled, persisted settings andn8n_set_safety_modecannot turn read-only mode off.- Backups are stored under
~/.n8n-manager-mcp/backups/and can be listed/restored with the backup tools. Server/workflow names are reduced to safe single path segments; reserved names, separators, traversal, and symlink/reparse escapes cannot leave that root, and listing exposes only regular.jsonbackups. n8n_add_servervalidates server connection input before saving: URLs must behttporhttpsbase URLs without embedded credentials, query strings, or fragments, and API keys must not contain whitespace.n8n_add_serverdefault semantics are explicit: the first server becomes default; an update withoutis_defaultpreserves the existing flag;truepromotes the server;falseintentionally removes its flag, after which default lookup falls back to the first configured server.
Development
npm install
npm run build # One-time build
npm run dev # Watch mode
npm start # Start server
npm test # Run test suite (vitest)
npm run smoke # Start the built MCP server and verify tool discovery
Testing
The test suite covers URL building, server input validation, server management, safety settings, backup path handling, workflow JSON construction, export/import validation, i18n language packs, repository hygiene, and error handling. The manager seam is tested against a local stub HTTP server, including its refusal to fall back to a direct n8n query.
npm test # Run all tests
npx vitest run # Same as above
npx vitest --watch # Watch mode
npm run smoke # Manual stdio MCP smoke test (requires npm run build first)
The current verification record covers Windows locally and Ubuntu Linux in GitHub Actions; GitHub Actions runs build, test, and npm package checks on Node.js 20, 22, and 24. The commit-specific local record is kept in CHANGELOG.md. The smoke runner starts dist/index.js through the MCP SDK client, verifies all 19 tool registrations, and calls the safe n8n_describe_nodes catalog tool without requiring n8n credentials.
Related
- n8n-workflow-manager — the state & history layer for humans (Web UI + REST API, Python): per-workflow change history and decision log, visual graph viewer, multi-server sync. Designed as a pair with this MCP server — the MCP is the AI action layer (create/update/delete/activate), the manager is where you review, document, and roll back. Memory & context (roadmap): an MCP server alone can't guarantee an agent checks prior context before a destructive change — that enforcement belongs in the manager (client-agnostic), with conversational context optionally from a pull-based history index like ctx (Apache-2.0). Planned: a shared history/decision store + a check-history-before-mutating guard.
- n8n -- The workflow automation platform
License
MIT
ellmos-ai Ecosystem
This MCP server is part of the ellmos-ai ecosystem — AI infrastructure, MCP servers, and intelligent tools.
MCP Server Family
| Server | Tools | Focus | npm |
|---|---|---|---|
| FileCommander | 46 | Filesystem, process management, interactive sessions, cloud-lock-safe operations | ellmos-filecommander-mcp |
| CodeCommander | 22 | Code analysis, JSON repair, imports, diffs, regex | ellmos-codecommander-mcp |
| Clatcher | 12 | File repair, format conversion, batch operations | ellmos-clatcher-mcp |
| n8n Manager | 19 | n8n workflow management via AI assistants | n8n-manager-mcp |
| ControlCenter | 20 | MCP stack discovery, profile management, control plane | ellmos-controlcenter-mcp |
| Homebase | 45 | Local-first LLM memory, knowledge, state, routing, swarm orchestration | ellmos-homebase-mcp (alpha) |
| ServerCommander | 8 | Server operations: health checks, log analysis, deploy dry-runs, mail diagnostics | ellmos-servercommander-mcp (alpha) |
| Blender Use | 3 | Headless Blender asset QA and FBX reimport verification | ellmos-blender-use-mcp (alpha) |
| Open Compute | 10 | Model-agnostic computer use: capture, safety-gated actions, Windows UIA | open-compute-mcp (alpha) |
AI Infrastructure
| Project | Description |
|---|---|
| BACH | Local-first text-based OS for LLM agents — 113+ handlers, 550+ tools, SQLite memory |
| open-compute | Model-agnostic computer-use core powering Open Compute MCP |
| clutch | Provider-neutral LLM orchestration with auto-routing and budget tracking |
| rinnsal | Lightweight agent memory, connectors, and automation infrastructure |
| ellmos-stack | Self-hosted AI research stack (Ollama + n8n + Rinnsal + KnowledgeDigest) |
| MarbleRun | Autonomous agent chain framework for Claude Code |
| gardener | Minimalist database-driven LLM OS prototype (4 functions, 1 table) |
| ellmos-tests | Testing framework for LLM operating systems (7 dimensions) |
Desktop Software & Sibling Tools
Our partner organization open-bricks and sister suites bundle AI-native desktop applications and developer utilities:
- ProFiler (file-bricks) — Advanced file and asset management workbench
- DokuZen (doc-bricks) — Markdown and document workspace
- safe-start-for-codex (dev-bricks) — Fast and reliable agent bootstrap
- automation-master (dev-bricks) — Central multi-host automation orchestrator
- DevCenter (dev-bricks) — Unified dashboard for local developer ecosystems
- CodeBox (dev-bricks) — Sandboxed tool execution environment
Haftung / Liability
Dieses Projekt ist eine unentgeltliche Open-Source-Schenkung im Sinne der §§ 516 ff. BGB. Die Haftung des Urhebers ist gemäß § 521 BGB auf Vorsatz und grobe Fahrlässigkeit beschränkt. Ergänzend gilt der Haftungsausschluss der MIT-Lizenz.
Nutzung auf eigenes Risiko. Keine Wartungszusage, keine Verfügbarkeitsgarantie, keine Gewähr für Fehlerfreiheit oder Eignung für einen bestimmten Zweck.
This project is an unpaid open-source donation under the MIT License. Liability is limited to intent and gross negligence (§ 521 German Civil Code). Use at your own risk. No warranty, no maintenance guarantee, no fitness-for-purpose assumed.
No comments yet
Be the first to share your take.