74
/ 100
25 days ago
glama

n8n MCP Server

Enables AI assistants to search, validate, and manage n8n workflows, providing structured access to over 1,800 node documentations and templates.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 12 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 7 credentials: AUTH_TOKEN, MCP_AUTH_TOKEN, N8N_API_KEY, N8N_MCP_LLM_API_KEY, OPENAI_API_KEY, SUPABASE_ANON_KEY, SUPABASE_SERVICE_ROLE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies12 high12 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highform-data@4.0.5GHSA-hmw2-7cc7-3qxx

form-data: CRLF injection in form-data via unescaped multipart field names and filenames

highaxios@1.14.0GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.14.0GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

highaxios@1.14.0GHSA-6chq-wfr3-2hj9

Axios: Header Injection via Prototype Pollution

highaxios@1.14.0GHSA-777c-7fjr-54vf

Allocation of Resources Without Limits or Throttling in Axios

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAUTH_RATE_LIMIT_MAX
configAUTH_RATE_LIMIT_WINDOW
🔐 secretAUTH_TOKEN🔐 Autenticación por token — protegido con
configAUTH_TOKEN_FILE
configAWS_EXECUTION_ENV
configAZURE_FUNCTIONS_ENVIRONMENT
configBASE_URLURL pública del servidor No
configCORS_ORIGIN
configDISABLED_TOOLS
configDISABLE_CONSOLE_OUTPUT
configDISABLE_TELEMETRY
configENABLE_MULTI_TENANTActivar modo multi-tenant false
configFLY_APP_NAME
configGITHUB_ACTIONS
configGITHUB_REF
configGITHUB_REPOSITORY
configGITHUB_RUN_ID
configGITHUB_RUN_NUMBER
configGITHUB_SHA
configGIT_COMMIT
configGOOGLE_CLOUD_PROJECT
configHEROKU_APP_NAME
configHOSTHost de escucha 0.0.0.0
configIS_CONTAINER
configIS_DOCKER
configKUBERNETES_SERVICE_HOST
configLOG_LEVELNivel de logging info
🔐 secretMCP_AUTH_TOKEN
configMCP_MODEModo del servidor (stdio o http) http
configMCP_PORT
configMCP_URL
configMULTI_TENANT_ALLOW_CONCURRENT_SESSIONS
configMULTI_TENANT_SESSION_STRATEGYEstrategia de sesiones (instance / shared) instance
🔐 secretN8N_API_KEYAPI Key de n8n Sí
configN8N_API_URLURL de la instancia n8n (sin /api/v1) Sí
configN8N_CUSTOM_PATH
configN8N_MCP_CONFIG_VOLUME
🔐 secretN8N_MCP_LLM_API_KEY
configN8N_MCP_LLM_BASE_URL
configN8N_MCP_LLM_MODEL
configN8N_MCP_LLM_TIMEOUT
configN8N_MCP_MAX_SESSIONS
configN8N_MCP_TELEMETRY_DISABLEDDesactivar telemetría true
configN8N_MCP_USER_ID
configN8N_MODE
configN8N_MODULES_PATH
configN8N_SKILLS_SOURCE
🔐 secretOPENAI_API_KEY
configPORTPuerto HTTP 3001
configPUBLIC_URL
configRENDER
configSESSION_TIMEOUT_MINUTES
configSKIP_WORKFLOW_VALIDATION
configSQLJS_SAVE_INTERVAL_MS
🔐 secretSUPABASE_ANON_KEY
🔐 secretSUPABASE_SERVICE_ROLE_KEY
configSUPABASE_URL
configTELEMETRY_DISABLED
configTRUST_PROXYConfiar en proxy inverso (0 o 1) 0
configUSE_FIXED_HTTP
configWORKFLOW_VERSION_RETENTION_DAYS
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/luislopezsanchez-n8n-mcp-server-1joqn5)](https://m8ven.ai/mcp/luislopezsanchez-n8n-mcp-server-1joqn5)
commit: 0f0d998ed3e914f6f750a89be5c1d0e9a3c00f40
code hash: 4c36c4ab5a7f302e85222df017b2112bea2decbab6679bda84cd1b0ec13a094d
verified: 6/27/2026, 8:55:55 AM
view raw JSON →