One server, many apps: Composio and n8n-mcp
Composio and n8n-mcp put many business apps behind one MCP connection in two different ways. Composio Connect is a hosted server with managed OAuth through which Claude Code, Codex and Cursor call tools in GitHub, Linear, Slack and other apps. n8n-mcp does not call those apps: it teaches the agent n8n so the agent builds, validates and deploys n8n workflows that do.
This page is for developers who want their agent to act in the team’s SaaS tools, and for tech leads who approve what those connections may do. You need the agent to read a GitHub issue, open a Linear ticket and post to Slack. That is three vendor servers, three OAuth setups and three sets of tool schemas in every session. Then someone asks for a nightly job that does the same thing without the agent, and the agent writes n8n JSON with a node parameter that n8n dropped a year ago.
What you’ll walk away with from integration hubs
Section titled “What you’ll walk away with from integration hubs”- A decision table for when one hub beats a set of vendor servers, scored on auth, audit, permission granularity and context cost
- Composio set up the way its vendor recommends for Claude Code and Codex (CLI plugin), and as a plain MCP server, with permission rules that make every write action ask first
- n8n-mcp in documentation-only mode, then against a development n8n instance with destructive tools removed
- Copy-paste prompts that build an n8n workflow from a sentence, validate it, and push it to a development instance inactive
- The measured context cost of each option, and the traps in each vendor’s install path
Composio and n8n-mcp solve different problems
Section titled “Composio and n8n-mcp solve different problems”The two tools share a category name and nothing else. Pick by the question you are answering.
| Composio Connect (Composio, official) | n8n-mcp (community, GitHub user czlonkowski) | |
|---|---|---|
| Question it answers | “Let my agent act in the SaaS tools we already use” | “Let my agent build n8n workflows that act in those tools, and run without the agent” |
| What the agent calls | Seven meta-tools that search Composio’s catalog, connect accounts and execute app tools | Tools that search n8n nodes and templates, read node schemas, validate workflow JSON, and (with an API key) manage workflows on your n8n instance |
| Where it runs | Remote Streamable HTTP at https://connect.composio.dev/mcp, or the composio CLI driven by a plugin | Local stdio via npm n8n-mcp; also Docker, or a hosted service |
| Auth | OAuth to Composio, then one OAuth grant per app, held by Composio | None for documentation tools; N8N_API_URL and N8N_API_KEY for instance tools |
| Write control | Client-side permission rules; per-app scopes chosen when you connect | DISABLED_TOOLS and DISABLED_TOOL_OPERATIONS on the server, plus the rights of the n8n API key |
| Popularity (2026-09-26) | ComposioHQ/composio ★30.3k (the SDK monorepo, not a count of Connect users); plugin repos ★9 and ★6 | czlonkowski/n8n-mcp ★23.0k; companion czlonkowski/n8n-skills ★6.3k |
Star counts were read from GitHub on 2026-09-26 for this site’s MCP research dossier. Stars measure attention on a repository, not use of a server. Composio describes its catalog as “1000+ apps”; that is the vendor’s own figure and was not independently counted. n8n-mcp’s README counts “2,864 workflow automation nodes (836 core + 2,028 community)” and “2,352 workflow templates”, also vendor figures.
Composio is listed in the Official MCP Registry as io.github.ComposioHQ/composio 1.0.5. n8n-mcp is not listed under its author’s namespace (checked 2026-09-26), and the several unrelated */n8n* entries there are not this server.
When does one hub beat five vendor servers?
Section titled “When does one hub beat five vendor servers?”A hub trades several direct relationships for one intermediary. That is a good trade for some teams and a bad one for others, and the deciding factors are not the ones on the vendor’s landing page. Score your case on these five rows before you install anything.
| Factor | A hub such as Composio wins when… | Vendor servers win when… |
|---|---|---|
| Auth | You would otherwise run three or more OAuth setups, and some apps have no official MCP server at all | Every app you need has an official remote server with OAuth (GitHub, Linear, Atlassian, Sentry, Notion) |
| Who holds the grants | Your security team accepts one third party holding OAuth grants to every connected app | Grants must stay between your identity provider and each vendor, with no intermediary |
| Audit | You want one place to list and revoke every connection | You need each vendor’s own audit log to show the agent’s actions under your user |
| Permission granularity | Read versus write per action does not matter much, or you use the CLI route where each command is visible (see below) | You need to allow reads and block writes per tool at the client, because a hub’s MCP route funnels every app through one execute tool |
| Context cost | You need many apps: a meta-tool hub keeps the schema cost flat as you add apps | You need two or three apps: their tool schemas cost less than the hub’s machinery |
n8n-mcp sits outside this table, because it does not replace any vendor server. It wins when the job should become an n8n workflow: something that runs on a schedule or on a webhook, without an agent and without a model bill, and that the operations team can see and edit in n8n.
Connect Composio the way the vendor recommends
Section titled “Connect Composio the way the vendor recommends”Composio’s own Connect page says: “If you use Codex or Claude Code and did not explicitly choose MCP, install the native Composio agent plugin instead.” The plugin does not register an MCP server. It installs guidance and hooks that teach the agent to run the composio CLI: composio search finds a tool, composio link connects an account, and composio execute runs a tool.
# Terminal: install the CLI (vendor script), sign in, configure Claude Codecurl -fsSL https://composio.dev/install | shcomposio logincomposio setup --target claude # --target auto configures Claude Code and CodexOr install the plugin yourself, in the Claude Code prompt:
/plugin marketplace add ComposioHQ/composio-plugin-cc/plugin install composio@composiocurl -fsSL https://composio.dev/install | shcomposio logincomposio setup --target codex# or install the plugin with Codex directly (vendor lines)codex plugin marketplace add https://github.com/ComposioHQ/composio-plugin-openai.git --jsoncodex plugin add composio@composio --jsonComposio points Cursor users to its plugin in the Cursor Marketplace (Install Composio Plugin for Cursor, then authorize in the browser). If you prefer plain MCP, the entry is the same URL as for the other clients:
{ "mcpServers": { "composio": { "url": "https://connect.composio.dev/mcp" } } }This JSON is derived from the registry URL and was not tested in Cursor.
Add --yes to composio setup when a script or an agent runs it, because setup otherwise asks before it changes local files.
Why the CLI route is easier to govern
Section titled “Why the CLI route is easier to govern”With the plugin, every Composio action is a shell command the agent must run, so your normal command permissions apply per verb. Allow the discovery commands and make every execution and new connection ask first:
{ "permissions": { "allow": ["Bash(composio search:*)", "Bash(composio whoami)"], "ask": ["Bash(composio execute:*)", "Bash(composio link:*)"]} }Codex reads prefix_rule() calls from .rules files in ~/.codex/rules/ (or .codex/rules/ in a trusted project). Restart Codex after you add one:
prefix_rule( pattern = ["composio", ["execute", "link"]], decision = "prompt", justification = "Composio calls act on real accounts; review the arguments",)Check the rule before you rely on it. codex execpolicy check --rules ~/.codex/rules/composio.rules composio execute GITHUB_CREATE_ISSUE returned "decision":"prompt" in codex-cli 0.157.1, and composio search matched no rule.
You then approve each composio execute GITHUB_… or SLACK_… call with its arguments in view. For how each agent decides what asks, see permissions and sandboxing.
Use Composio as a plain MCP server
Section titled “Use Composio as a plain MCP server”Choose MCP when a client has no plugin route, or when you want the same entry in every client:
# Terminal, repo root. Then run /mcp in Claude Code and complete the OAuth loginclaude mcp add --transport http -s project composio https://connect.composio.dev/mcpcodex mcp add composio --url https://connect.composio.dev/mcpcodex mcp login composioUse the .cursor/mcp.json entry from the tab above, then authorize Composio when Cursor opens the login page.
Over MCP the agent sees seven meta-tools: COMPOSIO_SEARCH_TOOLS, COMPOSIO_GET_TOOL_SCHEMAS, COMPOSIO_MULTI_EXECUTE_TOOL (Composio says “up to 50 per call”), COMPOSIO_MANAGE_CONNECTIONS, COMPOSIO_WAIT_FOR_CONNECTIONS, COMPOSIO_REMOTE_WORKBENCH (Python in a remote sandbox) and COMPOSIO_REMOTE_BASH_TOOL. Every app action, read or write, goes through COMPOSIO_MULTI_EXECUTE_TOOL, so a client rule cannot allow “read Gmail” and block “send Gmail”. Put the execute tool behind a prompt instead:
{ "permissions": { "allow": ["mcp__composio__COMPOSIO_SEARCH_TOOLS", "mcp__composio__COMPOSIO_GET_TOOL_SCHEMAS"], "ask": ["mcp__composio__COMPOSIO_MULTI_EXECUTE_TOOL", "mcp__composio__COMPOSIO_MANAGE_CONNECTIONS"], "deny": ["mcp__composio__COMPOSIO_REMOTE_WORKBENCH", "mcp__composio__COMPOSIO_REMOTE_BASH_TOOL"]} }# ~/.codex/config.toml — expose only the tools you allow[mcp_servers.composio]url = "https://connect.composio.dev/mcp"enabled_tools = ["COMPOSIO_SEARCH_TOOLS", "COMPOSIO_GET_TOOL_SCHEMAS", "COMPOSIO_MULTI_EXECUTE_TOOL", "COMPOSIO_MANAGE_CONNECTIONS", "COMPOSIO_WAIT_FOR_CONNECTIONS"]Use a run mode that asks before MCP tool calls while the Composio server is enabled (see Cursor’s run-mode settings), and approve each COMPOSIO_MULTI_EXECUTE_TOOL call in the chat with its arguments in view. Cursor’s per-tool controls could not be checked from the writing environment, so confirm in your version’s MCP settings whether you can switch off the two remote sandbox tools.
Denying the two remote sandbox tools keeps bulk processing of app data on your machine, where your own tools can see it. Allow them only if you have decided that Composio’s sandbox may process that data.
Try Composio on a real triage task
Section titled “Try Composio on a real triage task”What you should see: on first use, one connection link per app (GitHub, Linear, Slack) that you open and approve in the browser. On the plugin route the agent then runs composio search for each task and composio execute with a tool slug, and each execute asks for approval under the rules above. On the MCP route you see COMPOSIO_SEARCH_TOOLS, COMPOSIO_MANAGE_CONNECTIONS and then COMPOSIO_MULTI_EXECUTE_TOOL calls. The result is a list of Linear keys and one Slack message whose links you can click to check.
Build and validate an n8n workflow from a prompt
Section titled “Build and validate an n8n workflow from a prompt”This is the framework-level loop n8n-mcp is for: plan the automation in a sentence, let the agent build it against n8n’s real node schemas, validate it statically, test it on a development instance, and ship it through review. The agent never touches the production instance.
-
Install n8n-mcp in documentation-only mode. Without n8n credentials the server starts as
n8n-documentation-mcpwith seven tools:tools_documentation,search_nodes,get_node,validate_node,get_template,search_templatesandvalidate_workflow. It can design and validate, and it cannot change anything anywhere.Terminal window # Terminal, repo root. Pin the version; opt out of the server's default-on telemetryclaude mcp add -s project n8n-mcp -e MCP_MODE=stdio -e LOG_LEVEL=error \-e DISABLE_CONSOLE_OUTPUT=true -e N8N_MCP_TELEMETRY_DISABLED=true \-- npx -y n8n-mcp@2.89.0Terminal window codex mcp add n8n-mcp --env MCP_MODE=stdio --env LOG_LEVEL=error \--env DISABLE_CONSOLE_OUTPUT=true --env N8N_MCP_TELEMETRY_DISABLED=true \-- npx -y n8n-mcp@2.89.0.cursor/mcp.json { "mcpServers": { "n8n-mcp": {"command": "npx","args": ["-y", "n8n-mcp@2.89.0"],"env": { "MCP_MODE": "stdio", "LOG_LEVEL": "error","DISABLE_CONSOLE_OUTPUT": "true", "N8N_MCP_TELEMETRY_DISABLED": "true" } } } }MCP_MODE=stdiomatters: without it the server’s log lines can corrupt the stdio stream. n8n-mcp enables anonymous telemetry on first run unlessN8N_MCP_TELEMETRY_DISABLEDistrue(checked in the 2.89.0 package source). -
Ask for the workflow and a validation pass. Name the trigger, the steps and the target, and require validation before the agent shows you anything.
What you should see: calls to
search_templates,search_nodes,get_nodeforn8n-nodes-base.githubTrigger,n8n-nodes-base.codeandn8n-nodes-base.slack, then one or morevalidate_workflowcalls. The validator returnsvalid, asummarywitherrorCountandwarningCount, and per-node messages. In the test run for this page, a hand-broken workflow came back with"valid": falseand errors such asConnection to non-existent node: "Post to Slak"andExpression error: text: Unmatched expression brackets {{ }}. Expect the agent to loop untilvalidistrue. -
Connect a development n8n instance, with the delete, overwrite and rollback tools removed. Setting
N8N_API_URLandN8N_API_KEYraised the tool count from 7 to 28 in the test, includingn8n_delete_workflowandn8n_manage_credentials. Remove what the loop does not need. The profile below also turns off evaluation runs (n8n_evaluations:run,cancel) andn8n_workflow_versions:expose, but still allows folder create, rename and move, and test executions (step 4 runs one). n8n-mcp 2.89.0 marks those remaining operations destructive too, so disable them as well if your loop does not need them. The server appliesDISABLED_TOOLSandDISABLED_TOOL_OPERATIONSitself, so the limit holds in every client.Terminal window # Single quotes keep ${…} in .mcp.json; Claude Code expands them at launch from your shellclaude mcp add -s project n8n-dev -e MCP_MODE=stdio -e LOG_LEVEL=error \-e DISABLE_CONSOLE_OUTPUT=true -e N8N_MCP_TELEMETRY_DISABLED=true \-e 'N8N_API_URL=${N8N_DEV_URL}' -e 'N8N_API_KEY=${N8N_DEV_API_KEY}' \-e 'DISABLED_TOOLS=n8n_delete_workflow,n8n_update_full_workflow,n8n_deploy_template,n8n_manage_credentials,n8n_manage_datatable,n8n_manage_agents' \-e 'DISABLED_TOOL_OPERATIONS=n8n_executions:delete;n8n_workflow_versions:delete,rollback,prune,expose;n8n_manage_folders:delete;n8n_evaluations:run,cancel' \-- npx -y n8n-mcp@2.89.0# ~/.codex/config.toml — the key and URL are forwarded from your shell, not written here[mcp_servers.n8n-dev]command = "npx"args = ["-y", "n8n-mcp@2.89.0"]env_vars = ["N8N_API_URL", "N8N_API_KEY"][mcp_servers.n8n-dev.env]MCP_MODE = "stdio"LOG_LEVEL = "error"DISABLE_CONSOLE_OUTPUT = "true"N8N_MCP_TELEMETRY_DISABLED = "true"DISABLED_TOOLS = "n8n_delete_workflow,n8n_update_full_workflow,n8n_deploy_template,n8n_manage_credentials,n8n_manage_datatable,n8n_manage_agents"DISABLED_TOOL_OPERATIONS = "n8n_executions:delete;n8n_workflow_versions:delete,rollback,prune,expose;n8n_manage_folders:delete;n8n_evaluations:run,cancel"Export
N8N_API_URLandN8N_API_KEYfor the development instance before you start Codex.Put this entry in the user-level
~/.cursor/mcp.json, not the repository’s.cursor/mcp.json, because it holds a key: the samecommandandargsas step 1, and anenvblock with the four variables from step 1,N8N_API_URL,N8N_API_KEY,DISABLED_TOOLSandDISABLED_TOOL_OPERATIONSwith the values from the Claude Code tab.With that profile the test server exposed 22 tools. Create the n8n API key in the development instance only, under Settings → API.
-
Create the workflow inactive and test it on the development instance.
n8n_create_workflowcreates workflows inactive. You attach the credentials in the n8n editor, publish a test release in a sandbox repository, and ask the agent to read the run withn8n_executions. -
Ship it through review. Open a pull request with the JSON file and the execution evidence. A person imports the reviewed JSON into production n8n and activates it there.
Add the n8n skills for how workflows are written
Section titled “Add the n8n skills for how workflows are written”The server tells the agent what n8n’s nodes are. The companion czlonkowski/n8n-skills plugin tells it how to use them well: expression syntax, validation, error handling, Code nodes, sub-workflows and AI agents.
# Claude Code prompt/plugin marketplace add czlonkowski/n8n-skills/plugin install n8n-mcp-skills@n8n-mcp-skillsMeasured with claude plugin details (plugin 1.35.0, 2026-09-26): 15 skills, three hooks (SessionStart, PreToolUse, PostToolUse), no MCP server, and ~3,963 tokens always-on in every session. Each skill costs 4k to 12k tokens when it fires. Install it in the repository where you build workflows, not globally. The repository also contains an mcp.json that points at the hosted https://api.n8n-mcp.com/mcp; the plugin install did not register it, so you still add the server yourself.
How much context does each option cost?
Section titled “How much context does each option cost?”| Install | What loads | Cost (2026-09-26) |
|---|---|---|
Composio plugin composio@composio 0.2.4 (Claude Code) | 1 skill, 2 hooks, no MCP server | ~54 tokens always-on (measured, claude plugin details), plus a SessionStart line of about 480 characters |
| Composio over MCP | 7 meta-tools | not measured (endpoint unreachable here); run /context before and after adding it |
| n8n-mcp, documentation only | 7 tools | about 11,800 characters of tool schemas (measured tools/list, compact JSON) |
| n8n-mcp with instance tools | 28 tools, or 22 with the profile in step 3 | about 49,900 characters with all 28, about 39,400 with the 22-tool profile (measured) |
n8n-mcp-skills plugin 1.35.0 | 15 skills, 3 hooks | ~3,963 tokens always-on (measured) |
Character counts are the size of the JSON the server returns; tokens are fewer. Claude Code and Codex both search MCP tools on demand, which defers most schema cost until a tool is needed, so measure your real cost with /context in your client. The pattern holds regardless: a meta-tool hub stays flat as you add apps, and n8n-mcp’s instance tools cost about four times its documentation tools. More techniques are in reducing MCP token cost.
How do you verify what the agent did through a hub?
Section titled “How do you verify what the agent did through a hub?”You check the artifacts and the connections, not the agent’s summary of them:
- Writes are approved one by one.
composio executeandCOMPOSIO_MULTI_EXECUTE_TOOLsit inask, so each write shows its tool slug and arguments before it runs. - Results are clickable. The triage prompt ends with Linear keys and GitHub URLs; a reviewer opens three at random and compares them with the source issues.
- Connections are reviewed on a schedule. Once a month, list the connected apps (over MCP,
COMPOSIO_MANAGE_CONNECTIONSlists them), compare the list with what the team approved, and revoke the rest in Composio’s dashboard. - Workflow JSON passes validation twice.
validate_workflowreturns"valid": truelocally, andn8n_validate_workflowpasses on the development instance. Keep the final output of both in the pull request. - A real execution proves behaviour. One test release in a sandbox repository produces one Slack message; the
n8n_executionsrecord for that run goes into the pull request. - The workflow is code. The JSON lives in the repository, the reviewer reads the diff of node parameters, and rollback is deactivating the workflow and importing the previous JSON.
- A person owns production. The agent’s key only reaches the development instance. Import and activation in production are done by the workflow owner.
What breaks with Composio and n8n-mcp?
Section titled “What breaks with Composio and n8n-mcp?”The agent says it has no Composio tools after composio setup. Setup changes local config, and the plugin loads at session start. Open a new session. If it still fails, run composio whoami; the plugin’s own session hook reports “Run composio login to connect” when the CLI is signed out.
The OAuth link expired. Composio’s Connect troubleshooting guide says OAuth links are short-lived. Ask the agent to retry the action; Composio generates a fresh link.
An app action fails with an auth error. The app connection is stale or was revoked. Ask the agent to inspect the connection, then disconnect and reconnect it when prompted.
Every Composio call is blocked, or none is. Over MCP one tool carries every app action, so the rule is all-or-nothing. Use ask on the execute tool, or move to the CLI route where rules can match per command.
n8n-mcp breaks the client with parse errors. MCP_MODE=stdio is missing, and log output is mixed into the protocol stream. Add it along with DISABLE_CONSOLE_OUTPUT=true.
The instance tools do not appear. N8N_API_URL or N8N_API_KEY never reached the process. In Claude Code check the env block with claude mcp get n8n-dev; in Codex check env_vars and that you exported both variables before starting.
The workflow validates and still fails at run time. validate_workflow checks structure, connections, expressions and node parameters. It cannot check that a credential exists, that the Slack channel is right, or what the GitHub payload looks like on a real release. That is what the test execution in step 4 is for.
The agent activated a workflow. n8n_update_partial_workflow includes an activateWorkflow operation. That is acceptable on a development instance and the reason the agent’s key must never reach production.
Text inside an email, issue or execution log steers the agent. Every app a hub reaches is a source of untrusted text, and a hub puts many of them in one session with write access. Keep writes on ask, and read MCP security before connecting mail or chat.
General connection problems are covered in MCP connection issues.