Back to Directory/Automation & Workflow

n8n Manager MCP

MCP server for n8n workflow management -- view, create, sync and manage workflows via AI.

Automation & WorkflowTypeScriptv0.1.13
n8n Manager MCP Server Banner

n8n Manager MCP Server

🇩🇪 Deutsche Version

Part of the ellmos-ai family and the open-bricks umbrella.

npm Tests MCP Tools Node.js Safety Security Third-Party Attribution: NOTICE Verified Last-Checked License: MIT LLM Ready Ecosystem: ellmos--ai Umbrella: open--bricks

[!NOTE] For AI Assistants & LLMs: An llms.txt index file is available in the root directory for fast context ingestion, tool catalog references, and directory listings.

MCP (Model Context Protocol) server for managing n8n workflows via AI assistants like Claude, Cursor, and Windsurf.

Quick Navigation

NrSectionHighlights
01📐 System Architecture & Topology (#system-architecture)Local stdio transport, multi-server routing, and safety middleware
02📊 Dual Mermaid Diagrams (#dual-mermaid-diagrams)Component Architecture flowchart TD & Safe Mutation Lifecycle sequence diagram
03🌐 Directory Status & Registries (#directory-status)Official listings on npm, Glama, PulseMCP, and Enterprise DNA
04🎯 Target Personas & Discoverability (#target-personas--discoverability)Persona mapping [PERSONA-01] to [PERSONA-04] and High-Intent SEO queries
05⚖️ Comparative Matrix & Alternatives (#comparative-matrix--alternatives)10-dimension evaluation vs raw REST API, shell CLI, browser UI, and cloud SaaS
06🛡️ Core Capabilities & Safety Invariants (#core-capabilities--safety-invariants)10 formal invariants (INV-LOCAL-01 to INV-SLA-10), read-only gates, audit logs
07✨ Key Features (#features)Direct REST integration, multi-server routing, backup snapshots, node catalog
08⚙️ Client Installation (#installation)One-command setup for Claude Code, Claude Desktop, Cursor, and Windsurf
09🚀 Quick Start (#quick-start)Step-by-step workflow creation, execution inspection, and server switching
10🛠️ Available Tools (19 Tools) (#available-tools)Complete MCP tool reference across CRUD, executions, backups, and nodes
11🔗 Optional: n8n-workflow-manager Seam (#optional-n8n-workflow-manager-seam)Decision tracking and change history integration with paired manager service
12🔒 Configuration & Safety Defaults (#configuration)Environment variables, local backup root, and strict monotonic constraints
13🧪 Development & Testing (#development)Multi-OS Vitest test suite, smoke runner, and offline node catalog tests
14🧱 ellmos-ai Ecosystem (#ellmos-ai-ecosystem)Sibling MCP servers, BACH agent OS, and open-bricks desktop software suites
15📜 Third-Party Licenses & Transparency (#third-party-licenses--transparency)100% permissive open-source dependencies (MIT, BSD, Apache-2.0)
16📈 Marketing & Personas Log (#marketing--personas-log)Comprehensive positioning log, keyword matrix, and 3-phase roadmap
17📝 Changelog (#changelog)Complete release notes, security hardenings, and discoverability history
18⚖️ Liability / Haftung (#haftung--liability)Statutory open-source donation notice under §§ 516 ff. BGB, MIT disclaimer, 48h SLA

System Architecture

The n8n Manager MCP Server operates as a local-first, stdio-connected bridge between AI development environments (Claude Code, Claude Desktop, Cursor, Windsurf) and local or remote n8n instances.

  • Process Model: Runs purely in user space (RunAsInvoker) as a dedicated Node.js child process communicating via standard input/output (stdio) using JSON-RPC 2.0.
  • Fail-Closed Safety Middleware: Every mutation tool call passes through an immutable safety gate before contacting n8n APIs or touching the filesystem.
  • Multi-Instance Router: Seamlessly targets independent n8n instances (development, staging, production) with isolated API credentials and atomic configuration persistence.
  • Offline Node Catalog: Provides instantaneous node schema introspection (n8n_describe_nodes) without incurring API latency or network calls.

Dual Mermaid Diagrams

Component Architecture

flowchart TD
    Client["AI Client (Claude Code / Desktop / Cursor / Windsurf)"] -->|"MCP Stdio Protocol (JSON-RPC 2.0)"| Router["Tool Router (19 Tools)"]
    subgraph MCPServer["n8n Manager MCP Server (Local Stdio Process)"]
        Router --> Safety["Safety Layer (Read-Only Gate & Traversal Guard)"]
        Safety --> Backup["Pre-Mutation Snapshot Engine"]
        Safety --> MultiServer["Multi-Server Manager"]
        Safety --> Catalog["Offline Node Catalog (n8n_describe_nodes)"]
        Backup --> Audit["Append-Only Audit Logger"]
    end
    MultiServer -->|"REST API (API Key / Auth Header)"| LocalInst["Local n8n Instance (127.0.0.1:5678)"]
    MultiServer -->|"REST API (HTTPS / Token)"| CloudInst["Remote / Cloud n8n Instance"]
    Backup --> BackupFS[("Backups (~/.n8n-manager-mcp/backups/)")]
    Audit --> AuditFS[("Audit Log (~/.n8n-manager-mcp/audit.log)")]

Safe Workflow Mutation Lifecycle

sequenceDiagram
    autonumber
    actor AI as AI Assistant (Claude / Cursor)
    participant MCP as n8n-manager-mcp Router
    participant Safety as Safety & Read-Only Gate
    participant Snapshot as Backup Engine
    participant Store as Local Storage (~/.n8n-manager-mcp)
    participant N8N as n8n REST API Instance
    participant Audit as Forensic Audit Logger

    AI->>MCP: Call Mutation Tool (n8n_update_workflow / n8n_delete_workflow)
    MCP->>Safety: Check N8N_MANAGER_READ_ONLY
    alt Read-Only Active (INV-READ-02)
        Safety-->>AI: Blocked: Read-only mode active (Fail-Closed)
        Safety->>Audit: Record blocked mutation attempt
    else Mutation Permitted
        Safety->>Snapshot: Trigger Pre-Mutation Snapshot (INV-BACK-03)
        Snapshot->>N8N: GET /workflows/{id} (Fetch current state)
        N8N-->>Snapshot: Current Workflow JSON
        Snapshot->>Store: Save timestamped backup (~/backups/{server}/{id}-{timestamp}.json)
        Snapshot-->>Safety: Backup verified & path resolved
        Safety->>N8N: Execute Mutation (PUT / DELETE / PATCH)
        N8N-->>Safety: Mutation Response (200 OK / Updated ID)
        Safety->>Audit: Append structured forensic receipt (INV-AUDIT-04)
        Safety-->>AI: Success response with backup path & rollback receipt
    end

Directory Status

  • npm package: published as n8n-manager-mcp
  • Glama listing: public directory page for the ellmos-ai repo
  • Enterprise DNA directory: additional public directory entry for ellmos-ai/n8n-manager-mcp
  • PulseMCP listing: indexed as ellmos-ai-n8n-manager
  • MCP namespace status: this repo contains server.json and mcpName metadata for io.github.ellmos-ai/n8n-manager-mcp; some ecosystem directories still expose the legacy io.github.lukisch/n8n-manager-mcp name until their indexes refresh.
  • Search context: best matched by n8n MCP server, n8n workflow management MCP, AI assistant n8n workflows, and ellmos-ai n8n-manager-mcp.

Target Personas & Discoverability

PersonaCore NeedsPain Points SolvedTarget Discovery Terms
[PERSONA-01] Autonomous AI Agents & SwarmsNon-destructive workflow manipulation, pre-mutation snapshots, deterministic receiptsLLM hallucination breaking active production workflows; inability to inspect node connections offlinen8n mcp server, ai agent n8n workflow management, claude code n8n automation
[PERSONA-02] DevOps & Multi-Environment EngineersSafe multi-server routing, export/import synchronization across stagesManual JSON export friction; staging-to-production drift; unversioned workflow copiesn8n multi-server mcp, sync n8n workflows staging prod, n8n workflow export import mcp
[PERSONA-03] SecOps, Compliance & Risk TeamsMonotonic read-only locks, local audit trail, zero external data leakageUnregulated agent mutations; unvetted API calls; loss of forensic mutation historysafe n8n mcp server, read-only n8n automation, audit log n8n ai integration
[PERSONA-04] Ecosystem Builders & Tool IntegratorsStandardized MCP schemas, validated manifests, reliable TypeScript SDK seamSchema mismatch across MCP directories; missing regression and contract test suitesmodelcontextprotocol n8n, glama n8n-manager-mcp, smithery n8n workflow

High-Intent Search Queries

  • n8n mcp server claude code
  • ai assistant n8n workflow management
  • local-first n8n mcp stdio
  • safe n8n automated workflow mutation
  • n8n multi-server workflow sync mcp
  • n8n describe nodes offline catalog
  • zero-egress n8n agent automation
  • modelcontextprotocol n8n typescript

Comparative Matrix & Alternatives

Dimensionn8n-manager-mcpDirect n8n REST APIStandard Agent ShellManual n8n Web UIGeneric Cloud SaaS
Primary InterfaceNative MCP Stdio (JSON-RPC)Raw HTTP REST (Curl/Axios)Ad-hoc CLI / Bash ScriptsInteractive Web CanvasProprietary Web Portal
Safety GuardrailsMonotonic Read-Only Gate (N8N_MANAGER_READ_ONLY=1)None (Unchecked API execution)Shell exit code heuristicsHuman confirmation modalsRemote vendor RBAC
Mutation BackupsAutomated Pre-Mutation JSON Snapshots (INV-BACK-03)None (Overwrites live instance)None (Script dependent)None (Live canvas modifications)Vendor-dependent snapshots
Rollback Facility1-Click n8n_restore_workflow from Local DiskManual JSON reconstruction via POSTManual script rollback logicManual node rebuilding on canvasVendor rollback UI (Paywalled)
Forensic Audit LogAppend-Only Structured audit.log (INV-AUDIT-04)Generic webserver access logsEphemeral terminal stdoutCanvas execution logs onlyCloud vendor log retention
Node IntrospectionBuilt-in Offline Catalog (n8n_describe_nodes)Manual online documentationGuesswork & parameter trialsVisual palette browsingOnline API documentation
Multi-Server IsolationIsolated Stored Profiles (servers.json)Manual token switching in scriptsShell history token exposureMulti-tab credential clutterCloud workspace switching
Privacy & Zero-Egress100% Local Stdio Transport, Zero TelemetryDirect HTTP client trafficLocal shell executionBrowser telemetry & analyticsRemote third-party hosting
Workflow MigrationBuilt-in n8n_export_workflow & n8n_import_workflowCustom Python/Curl ETL scriptsComplex bash/jq pipelinesDownload / Upload JSON dialogCloud enterprise paywall
License & Audited Security100% Permissive MIT (Audited, 48h Security SLA)Fair-Code (n8n source available)Mixed / Ad-hoc licensesCommercial / Fair-CodeClosed Proprietary SaaS

Core Capabilities & Safety Invariants

Invariant IDCapability / InvariantTechnical GuaranteeUser Benefit
INV-LOCAL-01100% Local-First & Zero-EgressMCP Stdio transport; binds only to 127.0.0.1 by default; no external telemetryComplete privacy; no workflow logic or credentials ever leave your host
INV-READ-02Monotonic Read-Only EnforcementN8N_MANAGER_READ_ONLY=1 establishes a process-level ceiling immune to tool overrideProvable air-gapping against accidental workflow deletions or alterations
INV-BACK-03Automated Pre-Mutation BackupsFull workflow JSON snapshots stored under ~/.n8n-manager-mcp/backups/ before mutate/deleteInstant 1-click rollback via n8n_restore_workflow upon unwanted modifications
INV-AUDIT-04Local Audit TrailAppend-only structured JSON log in ~/.n8n-manager-mcp/audit.logComplete forensic visibility over all agent actions and execution outcomes
INV-SRV-05Multi-Server & Isolated CredentialsEncrypted/isolated server configs in servers.json; API key whitespace validationSeamless cross-instance workflow migration between staging and production
INV-TRAV-06Strict Input & Path Traversal GuardBounded numeric limits (1..1000), connection indices (0..1000), path escape rejectionImmune to directory traversal, prototype pollution, and malformed payload crashes
INV-PRIV-07Non-Elevation & User-Space SecurityOperates strictly as unprivileged user processZero root/administrator privilege requirements for local or CI execution
INV-SEAM-08Opt-In Decision History SeamClean adapter to n8n-workflow-manager via N8N_MCP_MANAGER_URL; explicit fail-fastBridges human decision logs and versioning without corrupting standard MCP mode
INV-NODE-09Built-in Node Catalog & IntrospectionComprehensive offline catalog for triggers, actions, logic, transform, and AI nodesLLMs formulate valid node connections without trial-and-error network calls
INV-SLA-10Multi-Node CI & 48h Security SLAAutomated GitHub Actions CI across Node.js 20, 22 with Concurrency cancellation; 48h response / 5d triage SLAGuaranteed cross-platform stability, verified security responsiveness, and regression-free distribution

Features

  • 19 Tools for complete n8n workflow management
  • List, create, update, delete, and activate/deactivate workflows
  • Safety controls: read-only mode, backup-before-delete/update, local restore, and audit log
  • Multi-server support (connect to multiple n8n instances)
  • Export/Import workflows between servers
  • View execution history and status
  • Built-in node catalog with descriptions
  • Zero dependencies on Python -- connects directly to n8n REST API

Installation

Claude Desktop

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "n8n-manager": {
      "command": "npx",
      "args": ["-y", "n8n-manager-mcp"]
    }
  }
}

Claude Code

claude mcp add --scope user n8n-manager npx -y n8n-manager-mcp

Manual

npm install -g n8n-manager-mcp

Quick Start

After installation, use these commands in your AI assistant:

  1. Add your n8n server:

    "Add my n8n server at http://localhost:5678 with API key abc123"

  2. List workflows:

    "Show me all workflows on my n8n server"

  3. Create a workflow:

    "Create an n8n workflow that triggers on a webhook, fetches data from an API, and sends a Slack message"

  4. Check executions:

    "Show me the last 10 workflow executions"


Available Tools

ToolDescription
n8n_list_workflowsList all workflows on a server
n8n_get_workflowGet workflow details (nodes, connections)
n8n_create_workflowCreate a new workflow from nodes + connections
n8n_update_workflowUpdate an existing workflow
n8n_delete_workflowDelete a workflow
n8n_activate_workflowActivate or deactivate a workflow
n8n_list_executionsList recent executions with status
n8n_export_workflowExport workflow as importable JSON
n8n_import_workflowImport workflow JSON onto a server
n8n_safety_statusShow local safety settings, backup directory, and audit log path
n8n_set_safety_modeToggle read-only mode, backup-before-mutation, and audit logging
n8n_list_backupsList local workflow backups created before mutations
n8n_restore_workflowRestore a workflow from a local backup
n8n_add_serverAdd/update n8n server connection
n8n_list_serversList configured servers
n8n_ping_serverTest server connection
n8n_remove_serverRemove a server
n8n_describe_nodesBrowse available n8n node types
n8n_manager_historyRead version history, recorded decisions, and sync history from an optional n8n-workflow-manager (opt-in, read-only)

Optional: n8n-workflow-manager seam

n8n itself keeps no record of why a workflow changed. The sibling project n8n-workflow-manager does: it stores versions, a mandatory decision per mutation, and a sync history in a local database. n8n_manager_history makes that record readable from this MCP server.

The seam is opt-in and read-only:

  • Without N8N_MCP_MANAGER_URL, nothing changes — every tool talks to n8n directly, as before.
  • With it set (for example http://127.0.0.1:8100), n8n_manager_history reads from the running manager. Omit workflow_id to list the manager's workflows, pass it for full history.
  • IDs are manager IDs, not n8n instance IDs. The manager stores that mapping but exposes no route to resolve it, so this server does not guess a translation.
  • If the manager is configured but unreachable, the tool fails with an explicit message instead of quietly answering from the n8n instance — that store has no decision history, so a substituted answer would be a different answer.
  • n8n_safety_status reports the measured state of the seam (configured, reachable, manager version), not just the environment variable.

Setup: pip install n8n-workflow-manager, then n8n-manager serve (binds 127.0.0.1:8100). The manager API is unauthenticated and loopback-only by design; a non-loopback URL is flagged in n8n_safety_status.

Numeric guardrails are part of the MCP schemas: workflow, execution, and backup list limits are finite positive integers from 1 to 1000 (the existing defaults remain 100, 20, and 20), and workflow connection from_output/ to_input indices are finite non-negative integers from 0 to 1000. Invalid values are rejected before any n8n API, filesystem, or workflow-array access.


Configuration

Server connections and safety settings are stored in ~/.n8n-manager-mcp/servers.json.

Safety defaults:

  • backup_before_mutations: true saves workflow JSON before update, delete, activate/deactivate, and overwrite-restore operations.
  • audit_log: true appends mutation outcomes to ~/.n8n-manager-mcp/audit.log.
  • read_only: false can be enabled with n8n_set_safety_mode or N8N_MANAGER_READ_ONLY=1. The environment flag is an enforcement ceiling: while it is enabled, persisted settings and n8n_set_safety_mode cannot turn read-only mode off.
  • Backups are stored under ~/.n8n-manager-mcp/backups/ and can be listed/restored with the backup tools. Server/workflow names are reduced to safe single path segments; reserved names, separators, traversal, and symlink/reparse escapes cannot leave that root, and listing exposes only regular .json backups.
  • n8n_add_server validates server connection input before saving: URLs must be http or https base URLs without embedded credentials, query strings, or fragments, and API keys must not contain whitespace.
  • n8n_add_server default semantics are explicit: the first server becomes default; an update without is_default preserves the existing flag; true promotes the server; false intentionally removes its flag, after which default lookup falls back to the first configured server.

Development

npm install
npm run build    # One-time build
npm run dev      # Watch mode
npm start        # Start server
npm test         # Run test suite (vitest)
npm run smoke    # Start the built MCP server and verify tool discovery

Testing

The test suite covers URL building, server input validation, server management, safety settings, backup path handling, workflow JSON construction, export/import validation, i18n language packs, repository hygiene, and error handling. The manager seam is tested against a local stub HTTP server, including its refusal to fall back to a direct n8n query.

npm test              # Run all tests
npx vitest run        # Same as above
npx vitest --watch    # Watch mode
npm run smoke         # Manual stdio MCP smoke test (requires npm run build first)

The current verification record covers Windows locally and Ubuntu Linux in GitHub Actions; GitHub Actions runs build, test, and npm package checks on Node.js 20, 22, and 24. The commit-specific local record is kept in CHANGELOG.md. The smoke runner starts dist/index.js through the MCP SDK client, verifies all 19 tool registrations, and calls the safe n8n_describe_nodes catalog tool without requiring n8n credentials.

Related

  • n8n-workflow-manager — the state & history layer for humans (Web UI + REST API, Python): per-workflow change history and decision log, visual graph viewer, multi-server sync. Designed as a pair with this MCP server — the MCP is the AI action layer (create/update/delete/activate), the manager is where you review, document, and roll back. Memory & context (roadmap): an MCP server alone can't guarantee an agent checks prior context before a destructive change — that enforcement belongs in the manager (client-agnostic), with conversational context optionally from a pull-based history index like ctx (Apache-2.0). Planned: a shared history/decision store + a check-history-before-mutating guard.
  • n8n -- The workflow automation platform

License

MIT


ellmos-ai Ecosystem

This MCP server is part of the ellmos-ai ecosystem — AI infrastructure, MCP servers, and intelligent tools.

MCP Server Family

ServerToolsFocusnpm
FileCommander46Filesystem, process management, interactive sessions, cloud-lock-safe operationsellmos-filecommander-mcp
CodeCommander22Code analysis, JSON repair, imports, diffs, regexellmos-codecommander-mcp
Clatcher12File repair, format conversion, batch operationsellmos-clatcher-mcp
n8n Manager19n8n workflow management via AI assistantsn8n-manager-mcp
ControlCenter20MCP stack discovery, profile management, control planeellmos-controlcenter-mcp
Homebase45Local-first LLM memory, knowledge, state, routing, swarm orchestrationellmos-homebase-mcp (alpha)
ServerCommander8Server operations: health checks, log analysis, deploy dry-runs, mail diagnosticsellmos-servercommander-mcp (alpha)
Blender Use3Headless Blender asset QA and FBX reimport verificationellmos-blender-use-mcp (alpha)
Open Compute10Model-agnostic computer use: capture, safety-gated actions, Windows UIAopen-compute-mcp (alpha)

AI Infrastructure

ProjectDescription
BACHLocal-first text-based OS for LLM agents — 113+ handlers, 550+ tools, SQLite memory
open-computeModel-agnostic computer-use core powering Open Compute MCP
clutchProvider-neutral LLM orchestration with auto-routing and budget tracking
rinnsalLightweight agent memory, connectors, and automation infrastructure
ellmos-stackSelf-hosted AI research stack (Ollama + n8n + Rinnsal + KnowledgeDigest)
MarbleRunAutonomous agent chain framework for Claude Code
gardenerMinimalist database-driven LLM OS prototype (4 functions, 1 table)
ellmos-testsTesting framework for LLM operating systems (7 dimensions)

Desktop Software & Sibling Tools

Our partner organization open-bricks and sister suites bundle AI-native desktop applications and developer utilities:

RepositoryOrg / SuiteFocus & Functionality
ProFilerfile-bricksAdvanced file and asset management workbench with duplicate detection
ExplorerProfile-bricksTabbed, filterable file manager with smart batch processing
WinStorePackagerfile-bricksMSIX packaging and Windows Store release preparation
DokuZendoc-bricksOffline Markdown editor, live preview, and document structuring workbench
PDFtoPDFocrdoc-bricksOffline OCR pipeline converting scanned PDF documents to searchable PDFs
USR_PDFunlockdoc-bricksBirthday/date password recovery tool for protected PDF archives
UniversalInvoiceMaildoc-bricksAutomated invoice extraction and email processing
CleanMarkdowndoc-bricksLossless formatting and typography cleanup for technical markdown
safe-start-for-codexdev-bricksFast, reliable agent bootstrap and environment check runner
automation-masterdev-bricksCentral multi-host automation orchestrator and task monitor
DevCenterdev-bricksUnified developer workspace dashboard for local tool chains
CodeBoxdev-bricksSandboxed multi-language tool execution environment
githubbotdev-bricksAutomated multi-org repository maintenance and discoverability engine
swarm-aiellmos-aiDistributed multi-agent swarming framework with stigmergic coordination
ellmos-coreellmos-aiEnterprise AI agent backend, hybrid RAG, and multi-tenant security
open-bricksopen-bricksUmbrella portal and catalog across all local-first AI software products

Third-Party Licenses & Transparency

This project is licensed under the MIT License with attribution declared in NOTICE. To guarantee complete supply chain integrity and compliance in enterprise and autonomous agent environments, all dependencies are continuously audited:

DependencyTypeVersionLicenseVerification Status
@modelcontextprotocol/sdkRuntime (Direct)^1.29.0MITPermissive / Audited
zodRuntime (Direct)^3.23.8MITPermissive / Audited
update-notifierRuntime (Direct)^7.3.1BSD-2-ClausePermissive / Audited
typescriptDev / Compiler^5.3.3Apache-2.0Permissive / Audited
vitestDev / Test Runner^4.1.11MITPermissive / Audited
@types/nodeDev / Type Definitions^20.11.0MITPermissive / Audited
  • Zero Copyleft / AGPL: Contains no viral copyleft or unreviewed commercial dependencies.
  • Zero External Telemetry: Emits no network beacons, analytics payloads, or external phone-home pings.
  • Detailed Open-Source Inventory: Complete attribution notices, license texts, and transitive dependency analyses are available in THIRD_PARTY_LICENSES.md.

Marketing & Personas Log

For marketing positioning, target persona definitions, governance invariant mappings, and the 3-phase discoverability roadmap, see MARKETING-LOG.txt.


Changelog

See CHANGELOG.md for detailed version history, release notes, and past migration milestones.


Haftung / Liability

Statutory Notice & Liability Disclaimer (§ 521 BGB)

Dieses Projekt ist eine unentgeltliche Open-Source-Schenkung im Sinne der §§ 516 ff. BGB. Die Haftung des Urhebers ist gemäß § 521 BGB auf Vorsatz und grobe Fahrlässigkeit beschränkt. Ergänzend gilt der Haftungsausschluss der MIT-Lizenz.

Nutzung auf eigenes Risiko. Keine Wartungszusage, keine Verfügbarkeitsgarantie, keine Gewähr für Fehlerfreiheit oder Eignung für einen bestimmten Zweck.

This project is an unpaid open-source donation under the MIT License. Liability is limited to intent and gross negligence (§ 521 German Civil Code). Use at your own risk. No warranty, no maintenance guarantee, no fitness-for-purpose assumed.

Security Response SLA & Vulnerability Reporting

As codified in SECURITY.md, we maintain a strict binding security policy:

  • Initial Response SLA: Guaranteed within 48 hours (INV-SLA-10).
  • Triage Commitment: Vulnerability assessment completed within 5 business days.
  • Remediation SLA: Coordinated security patches delivered within 30 calendar days.
  • Direct Contact Endpoints:
    • security@open-bricks.org
    • security@ellmos.ai
    • lukas@open-bricks.org

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y n8n-manager-mcp

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-ellmos-ai-n8n-manager-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "n8n-manager-mcp"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

n8n-manager-mcpnpm

Compatible MCP Clients

n8n Manager MCP works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More