Skip to content

One server, many apps: Composio and n8n-mcp

Composio and n8n-mcp put many business apps behind one MCP connection in two different ways. Composio Connect is a hosted server with managed OAuth through which Claude Code, Codex and Cursor call tools in GitHub, Linear, Slack and other apps. n8n-mcp does not call those apps: it teaches the agent n8n so the agent builds, validates and deploys n8n workflows that do.

This page is for developers who want their agent to act in the team’s SaaS tools, and for tech leads who approve what those connections may do. You need the agent to read a GitHub issue, open a Linear ticket and post to Slack. That is three vendor servers, three OAuth setups and three sets of tool schemas in every session. Then someone asks for a nightly job that does the same thing without the agent, and the agent writes n8n JSON with a node parameter that n8n dropped a year ago.

What you’ll walk away with from integration hubs

Section titled “What you’ll walk away with from integration hubs”
  • A decision table for when one hub beats a set of vendor servers, scored on auth, audit, permission granularity and context cost
  • Composio set up the way its vendor recommends for Claude Code and Codex (CLI plugin), and as a plain MCP server, with permission rules that make every write action ask first
  • n8n-mcp in documentation-only mode, then against a development n8n instance with destructive tools removed
  • Copy-paste prompts that build an n8n workflow from a sentence, validate it, and push it to a development instance inactive
  • The measured context cost of each option, and the traps in each vendor’s install path

Composio and n8n-mcp solve different problems

Section titled “Composio and n8n-mcp solve different problems”

The two tools share a category name and nothing else. Pick by the question you are answering.

Composio Connect (Composio, official)n8n-mcp (community, GitHub user czlonkowski)
Question it answers“Let my agent act in the SaaS tools we already use”“Let my agent build n8n workflows that act in those tools, and run without the agent”
What the agent callsSeven meta-tools that search Composio’s catalog, connect accounts and execute app toolsTools that search n8n nodes and templates, read node schemas, validate workflow JSON, and (with an API key) manage workflows on your n8n instance
Where it runsRemote Streamable HTTP at https://connect.composio.dev/mcp, or the composio CLI driven by a pluginLocal stdio via npm n8n-mcp; also Docker, or a hosted service
AuthOAuth to Composio, then one OAuth grant per app, held by ComposioNone for documentation tools; N8N_API_URL and N8N_API_KEY for instance tools
Write controlClient-side permission rules; per-app scopes chosen when you connectDISABLED_TOOLS and DISABLED_TOOL_OPERATIONS on the server, plus the rights of the n8n API key
Popularity (2026-09-26)ComposioHQ/composio ★30.3k (the SDK monorepo, not a count of Connect users); plugin repos ★9 and ★6czlonkowski/n8n-mcp ★23.0k; companion czlonkowski/n8n-skills ★6.3k

Star counts were read from GitHub on 2026-09-26 for this site’s MCP research dossier. Stars measure attention on a repository, not use of a server. Composio describes its catalog as “1000+ apps”; that is the vendor’s own figure and was not independently counted. n8n-mcp’s README counts “2,864 workflow automation nodes (836 core + 2,028 community)” and “2,352 workflow templates”, also vendor figures.

Composio is listed in the Official MCP Registry as io.github.ComposioHQ/composio 1.0.5. n8n-mcp is not listed under its author’s namespace (checked 2026-09-26), and the several unrelated */n8n* entries there are not this server.

When does one hub beat five vendor servers?

Section titled “When does one hub beat five vendor servers?”

A hub trades several direct relationships for one intermediary. That is a good trade for some teams and a bad one for others, and the deciding factors are not the ones on the vendor’s landing page. Score your case on these five rows before you install anything.

FactorA hub such as Composio wins when…Vendor servers win when…
AuthYou would otherwise run three or more OAuth setups, and some apps have no official MCP server at allEvery app you need has an official remote server with OAuth (GitHub, Linear, Atlassian, Sentry, Notion)
Who holds the grantsYour security team accepts one third party holding OAuth grants to every connected appGrants must stay between your identity provider and each vendor, with no intermediary
AuditYou want one place to list and revoke every connectionYou need each vendor’s own audit log to show the agent’s actions under your user
Permission granularityRead versus write per action does not matter much, or you use the CLI route where each command is visible (see below)You need to allow reads and block writes per tool at the client, because a hub’s MCP route funnels every app through one execute tool
Context costYou need many apps: a meta-tool hub keeps the schema cost flat as you add appsYou need two or three apps: their tool schemas cost less than the hub’s machinery

n8n-mcp sits outside this table, because it does not replace any vendor server. It wins when the job should become an n8n workflow: something that runs on a schedule or on a webhook, without an agent and without a model bill, and that the operations team can see and edit in n8n.

Connect Composio the way the vendor recommends

Section titled “Connect Composio the way the vendor recommends”

Composio’s own Connect page says: “If you use Codex or Claude Code and did not explicitly choose MCP, install the native Composio agent plugin instead.” The plugin does not register an MCP server. It installs guidance and hooks that teach the agent to run the composio CLI: composio search finds a tool, composio link connects an account, and composio execute runs a tool.

Terminal window
# Terminal: install the CLI (vendor script), sign in, configure Claude Code
curl -fsSL https://composio.dev/install | sh
composio login
composio setup --target claude # --target auto configures Claude Code and Codex

Or install the plugin yourself, in the Claude Code prompt:

/plugin marketplace add ComposioHQ/composio-plugin-cc
/plugin install composio@composio

Add --yes to composio setup when a script or an agent runs it, because setup otherwise asks before it changes local files.

With the plugin, every Composio action is a shell command the agent must run, so your normal command permissions apply per verb. Allow the discovery commands and make every execution and new connection ask first:

.claude/settings.json
{ "permissions": {
"allow": ["Bash(composio search:*)", "Bash(composio whoami)"],
"ask": ["Bash(composio execute:*)", "Bash(composio link:*)"]
} }

You then approve each composio execute GITHUB_… or SLACK_… call with its arguments in view. For how each agent decides what asks, see permissions and sandboxing.

Choose MCP when a client has no plugin route, or when you want the same entry in every client:

Terminal window
# Terminal, repo root. Then run /mcp in Claude Code and complete the OAuth login
claude mcp add --transport http -s project composio https://connect.composio.dev/mcp

Over MCP the agent sees seven meta-tools: COMPOSIO_SEARCH_TOOLS, COMPOSIO_GET_TOOL_SCHEMAS, COMPOSIO_MULTI_EXECUTE_TOOL (Composio says “up to 50 per call”), COMPOSIO_MANAGE_CONNECTIONS, COMPOSIO_WAIT_FOR_CONNECTIONS, COMPOSIO_REMOTE_WORKBENCH (Python in a remote sandbox) and COMPOSIO_REMOTE_BASH_TOOL. Every app action, read or write, goes through COMPOSIO_MULTI_EXECUTE_TOOL, so a client rule cannot allow “read Gmail” and block “send Gmail”. Put the execute tool behind a prompt instead:

.claude/settings.json
{ "permissions": {
"allow": ["mcp__composio__COMPOSIO_SEARCH_TOOLS", "mcp__composio__COMPOSIO_GET_TOOL_SCHEMAS"],
"ask": ["mcp__composio__COMPOSIO_MULTI_EXECUTE_TOOL", "mcp__composio__COMPOSIO_MANAGE_CONNECTIONS"],
"deny": ["mcp__composio__COMPOSIO_REMOTE_WORKBENCH", "mcp__composio__COMPOSIO_REMOTE_BASH_TOOL"]
} }

Denying the two remote sandbox tools keeps bulk processing of app data on your machine, where your own tools can see it. Allow them only if you have decided that Composio’s sandbox may process that data.

What you should see: on first use, one connection link per app (GitHub, Linear, Slack) that you open and approve in the browser. On the plugin route the agent then runs composio search for each task and composio execute with a tool slug, and each execute asks for approval under the rules above. On the MCP route you see COMPOSIO_SEARCH_TOOLS, COMPOSIO_MANAGE_CONNECTIONS and then COMPOSIO_MULTI_EXECUTE_TOOL calls. The result is a list of Linear keys and one Slack message whose links you can click to check.

Build and validate an n8n workflow from a prompt

Section titled “Build and validate an n8n workflow from a prompt”

This is the framework-level loop n8n-mcp is for: plan the automation in a sentence, let the agent build it against n8n’s real node schemas, validate it statically, test it on a development instance, and ship it through review. The agent never touches the production instance.

  1. Install n8n-mcp in documentation-only mode. Without n8n credentials the server starts as n8n-documentation-mcp with seven tools: tools_documentation, search_nodes, get_node, validate_node, get_template, search_templates and validate_workflow. It can design and validate, and it cannot change anything anywhere.

    Terminal window
    # Terminal, repo root. Pin the version; opt out of the server's default-on telemetry
    claude mcp add -s project n8n-mcp -e MCP_MODE=stdio -e LOG_LEVEL=error \
    -e DISABLE_CONSOLE_OUTPUT=true -e N8N_MCP_TELEMETRY_DISABLED=true \
    -- npx -y n8n-mcp@2.89.0

    MCP_MODE=stdio matters: without it the server’s log lines can corrupt the stdio stream. n8n-mcp enables anonymous telemetry on first run unless N8N_MCP_TELEMETRY_DISABLED is true (checked in the 2.89.0 package source).

  2. Ask for the workflow and a validation pass. Name the trigger, the steps and the target, and require validation before the agent shows you anything.

    What you should see: calls to search_templates, search_nodes, get_node for n8n-nodes-base.githubTrigger, n8n-nodes-base.code and n8n-nodes-base.slack, then one or more validate_workflow calls. The validator returns valid, a summary with errorCount and warningCount, and per-node messages. In the test run for this page, a hand-broken workflow came back with "valid": false and errors such as Connection to non-existent node: "Post to Slak" and Expression error: text: Unmatched expression brackets {{ }}. Expect the agent to loop until valid is true.

  3. Connect a development n8n instance, with the delete, overwrite and rollback tools removed. Setting N8N_API_URL and N8N_API_KEY raised the tool count from 7 to 28 in the test, including n8n_delete_workflow and n8n_manage_credentials. Remove what the loop does not need. The profile below also turns off evaluation runs (n8n_evaluations:run,cancel) and n8n_workflow_versions:expose, but still allows folder create, rename and move, and test executions (step 4 runs one). n8n-mcp 2.89.0 marks those remaining operations destructive too, so disable them as well if your loop does not need them. The server applies DISABLED_TOOLS and DISABLED_TOOL_OPERATIONS itself, so the limit holds in every client.

    Terminal window
    # Single quotes keep ${…} in .mcp.json; Claude Code expands them at launch from your shell
    claude mcp add -s project n8n-dev -e MCP_MODE=stdio -e LOG_LEVEL=error \
    -e DISABLE_CONSOLE_OUTPUT=true -e N8N_MCP_TELEMETRY_DISABLED=true \
    -e 'N8N_API_URL=${N8N_DEV_URL}' -e 'N8N_API_KEY=${N8N_DEV_API_KEY}' \
    -e 'DISABLED_TOOLS=n8n_delete_workflow,n8n_update_full_workflow,n8n_deploy_template,n8n_manage_credentials,n8n_manage_datatable,n8n_manage_agents' \
    -e 'DISABLED_TOOL_OPERATIONS=n8n_executions:delete;n8n_workflow_versions:delete,rollback,prune,expose;n8n_manage_folders:delete;n8n_evaluations:run,cancel' \
    -- npx -y n8n-mcp@2.89.0

    With that profile the test server exposed 22 tools. Create the n8n API key in the development instance only, under Settings → API.

  4. Create the workflow inactive and test it on the development instance.

    n8n_create_workflow creates workflows inactive. You attach the credentials in the n8n editor, publish a test release in a sandbox repository, and ask the agent to read the run with n8n_executions.

  5. Ship it through review. Open a pull request with the JSON file and the execution evidence. A person imports the reviewed JSON into production n8n and activates it there.

Add the n8n skills for how workflows are written

Section titled “Add the n8n skills for how workflows are written”

The server tells the agent what n8n’s nodes are. The companion czlonkowski/n8n-skills plugin tells it how to use them well: expression syntax, validation, error handling, Code nodes, sub-workflows and AI agents.

# Claude Code prompt
/plugin marketplace add czlonkowski/n8n-skills
/plugin install n8n-mcp-skills@n8n-mcp-skills

Measured with claude plugin details (plugin 1.35.0, 2026-09-26): 15 skills, three hooks (SessionStart, PreToolUse, PostToolUse), no MCP server, and ~3,963 tokens always-on in every session. Each skill costs 4k to 12k tokens when it fires. Install it in the repository where you build workflows, not globally. The repository also contains an mcp.json that points at the hosted https://api.n8n-mcp.com/mcp; the plugin install did not register it, so you still add the server yourself.

InstallWhat loadsCost (2026-09-26)
Composio plugin composio@composio 0.2.4 (Claude Code)1 skill, 2 hooks, no MCP server~54 tokens always-on (measured, claude plugin details), plus a SessionStart line of about 480 characters
Composio over MCP7 meta-toolsnot measured (endpoint unreachable here); run /context before and after adding it
n8n-mcp, documentation only7 toolsabout 11,800 characters of tool schemas (measured tools/list, compact JSON)
n8n-mcp with instance tools28 tools, or 22 with the profile in step 3about 49,900 characters with all 28, about 39,400 with the 22-tool profile (measured)
n8n-mcp-skills plugin 1.35.015 skills, 3 hooks~3,963 tokens always-on (measured)

Character counts are the size of the JSON the server returns; tokens are fewer. Claude Code and Codex both search MCP tools on demand, which defers most schema cost until a tool is needed, so measure your real cost with /context in your client. The pattern holds regardless: a meta-tool hub stays flat as you add apps, and n8n-mcp’s instance tools cost about four times its documentation tools. More techniques are in reducing MCP token cost.

How do you verify what the agent did through a hub?

Section titled “How do you verify what the agent did through a hub?”

You check the artifacts and the connections, not the agent’s summary of them:

  • Writes are approved one by one. composio execute and COMPOSIO_MULTI_EXECUTE_TOOL sit in ask, so each write shows its tool slug and arguments before it runs.
  • Results are clickable. The triage prompt ends with Linear keys and GitHub URLs; a reviewer opens three at random and compares them with the source issues.
  • Connections are reviewed on a schedule. Once a month, list the connected apps (over MCP, COMPOSIO_MANAGE_CONNECTIONS lists them), compare the list with what the team approved, and revoke the rest in Composio’s dashboard.
  • Workflow JSON passes validation twice. validate_workflow returns "valid": true locally, and n8n_validate_workflow passes on the development instance. Keep the final output of both in the pull request.
  • A real execution proves behaviour. One test release in a sandbox repository produces one Slack message; the n8n_executions record for that run goes into the pull request.
  • The workflow is code. The JSON lives in the repository, the reviewer reads the diff of node parameters, and rollback is deactivating the workflow and importing the previous JSON.
  • A person owns production. The agent’s key only reaches the development instance. Import and activation in production are done by the workflow owner.

The agent says it has no Composio tools after composio setup. Setup changes local config, and the plugin loads at session start. Open a new session. If it still fails, run composio whoami; the plugin’s own session hook reports “Run composio login to connect” when the CLI is signed out.

The OAuth link expired. Composio’s Connect troubleshooting guide says OAuth links are short-lived. Ask the agent to retry the action; Composio generates a fresh link.

An app action fails with an auth error. The app connection is stale or was revoked. Ask the agent to inspect the connection, then disconnect and reconnect it when prompted.

Every Composio call is blocked, or none is. Over MCP one tool carries every app action, so the rule is all-or-nothing. Use ask on the execute tool, or move to the CLI route where rules can match per command.

n8n-mcp breaks the client with parse errors. MCP_MODE=stdio is missing, and log output is mixed into the protocol stream. Add it along with DISABLE_CONSOLE_OUTPUT=true.

The instance tools do not appear. N8N_API_URL or N8N_API_KEY never reached the process. In Claude Code check the env block with claude mcp get n8n-dev; in Codex check env_vars and that you exported both variables before starting.

The workflow validates and still fails at run time. validate_workflow checks structure, connections, expressions and node parameters. It cannot check that a credential exists, that the Slack channel is right, or what the GitHub payload looks like on a real release. That is what the test execution in step 4 is for.

The agent activated a workflow. n8n_update_partial_workflow includes an activateWorkflow operation. That is acceptable on a development instance and the reason the agent’s key must never reach production.

Text inside an email, issue or execution log steers the agent. Every app a hub reaches is a source of untrusted text, and a hub puts many of them in one session with write access. Keep writes on ask, and read MCP security before connecting mail or chat.

General connection problems are covered in MCP connection issues.