MCP for AI Agents: How to Use MCP Servers in n8n and Dify
・ Employee Store Operations

Summary
MCP is a shared standard for connecting AI applications to external tools and data. n8n and Dify can both use MCP servers and publish your own workflows or apps as MCP servers. This article explains how it works, how to use it, and what to watch for on security.
We checked this article against the official MCP, n8n, and Dify documentation on October 2, 2026. The MCP specification is updated with each version. Before you configure anything, check the latest information in the sources at the end.
When you connect an MCP server to an AI agent, the agent can use external tools and data according to a shared standard. In n8n you can bring MCP server tools into the AI Agent node, and in Dify into agents and workflows.
What MCP Is: A Shared Standard for Connecting AI to External Tools
MCP (Model Context Protocol) is an open-source standard for connecting AI applications to external systems. The official site describes it as something like USB-C for AI applications. Just as USB-C standardized how devices connect, MCP standardizes how AI connects to external systems.
With MCP, AI applications such as Claude and ChatGPT can connect to data such as files and databases, tools such as search engines, and prompts for set procedures.
What a server provides
- Tools: functions the AI calls to take actions, such as file operations, API calls, and database searches
- Resources: data that gives the AI context, such as file contents and database records
- Prompts: templates that structure interactions with a language model
A client first gets a list of what the server offers, for example with tools/list. It then runs tools with tools/call. The list is not fixed and can change on the server side.
MCP Servers and MCP Clients
MCP has three roles.
- MCP host: an AI application such as Claude Desktop or Claude Code. It manages one or more MCP clients
- MCP client: a component that maintains the connection to an MCP server and passes context received from the server to the host
- MCP server: a program that provides context to clients
The host creates one MCP client for each MCP server it connects to. Connecting to two servers means two clients.
- 1MCP hostAI application
- 2MCP client1 per server
- 3MCP serverProvides tools, resources, prompts
- 4External systemDatabases and APIs
Local and remote
There are two transport methods. stdio is a method where processes on the same machine communicate over standard input and output. It is used for local MCP servers and usually serves one client. Streamable HTTP communicates over HTTP. It is used for remote MCP servers and serves many clients.
Streamable HTTP supports authentication with bearer tokens, API keys, and custom headers. MCP recommends obtaining tokens with OAuth. Both use JSON-RPC 2.0 as the message format.
Using MCP in n8n: Both Client and Server
n8n has features for using MCP servers (as a client) and for acting as an MCP server. On the pricing page, even the Starter plan includes AI agents, MCP, and AI nodes.
| Feature | Role | When to use |
|---|---|---|
| MCP Client Tool node | Client | Give the AI Agent node tools from an external MCP server |
| MCP Client node | Client | Use tools from an external MCP server as regular workflow steps |
| MCP server list (registry) | Client | Select from the node panel, sign in, and connect to an agent |
| MCP Server Trigger node | Server | Expose one workflow's tools to external MCP clients |
| Instance-level MCP | Server | Search, run, and edit n8n workflows from Claude Desktop and others |
Giving an agent external tools
The MCP Client Tool node is a component you connect to the AI Agent node. You set the external MCP server's URL and authentication method. Authentication options are bearer, header, multiple headers, and OAuth2. In Tools to Include, you choose all tools, only selected tools, or all except selected tools.
The official n8n docs also explain when to use built-in nodes versus MCP servers. Built-in nodes let you fix one operation and its parameters, so you get fine control. With MCP servers, the agent decides which allowed tool to call and with what arguments. You get more flexibility but less control. We explain how to build agents in building AI agents with n8n.
Making n8n an MCP server
The MCP Server Trigger node provides a URL that MCP clients call. Only tool nodes can connect to this node. To expose your own workflow, connect it with the Custom n8n Workflow Tool node. It supports SSE and Streamable HTTP, but not stdio.
- There are two URLs: test and production. The production URL becomes active when you publish the workflow
- Authentication options are none, bearer, or header
- The path defaults to a random string so it does not collide with other nodes
Enable instance-level MCP under Instance-level MCP in Settings. This requires owner or admin permissions. Not every workflow is exposed; you enable each workflow individually. However, every connected client can see all enabled workflows. You cannot show different workflows to different clients.
Using MCP in Dify
Dify can also import tools from MCP servers and publish your own apps as MCP servers.
Importing tools from an MCP server
Add an MCP server under Tools in Integrations. Enter the server URL, a name, and a unique server identifier, and Dify connects, authorizes if needed, and imports the tools. You can call imported tools from tool nodes in Workflow and Chatflow, from Agent nodes, and from Agent apps.
- Only MCP servers that communicate over HTTP are supported
- Authentication defaults to Dynamic Client Registration. For servers that do not support it, enter a Client ID and Client Secret
- For servers that authenticate with static tokens, you can add custom headers such as Authorization: Bearer
- Refreshing the tool list can remove or change tools you were using and break your apps
- Apps reference servers by identifier. If you change the identifier, that server's tools stop working
Publishing an app as an MCP server
Enable the feature on the MCP Server card in the app's Access Point tab. It is off by default. When enabled, a dedicated MCP server address is created for the app. Claude Desktop and Cursor can call the app at this address.
This URL contains credentials. The official docs ask you to treat it like an API key. If you suspect a leak, create a new URL with the regenerate button. The old URL stops working immediately. We explain how to build agents in Dify in building agents with Dify.
Security When Using MCP Servers
Connecting an MCP server lets an agent operate external systems. The OWASP Top 10 for LLM Applications (2025 edition) lists Excessive Agency as LLM06. It is caused by giving an agent more functionality, permissions, or autonomy than it needs.
- Keep callable tools to a minimum. In n8n you can narrow them with Tools to Include
- Keep each tool's functionality to a minimum. For summarizing email, allow reading only
- Keep permissions on external systems to a minimum. If reading is enough, connect with read-only permissions or scopes
- Have a person approve high-impact actions before they run
What to avoid
- Exposing tools you do not use
- Allowing writes or deletes when reading is enough
- Sending or deleting without confirmation
Countermeasures
- Limit to the tools you use
- Connect with read-only permissions
- Have a person approve high-impact actions
OWASP also lists prompt injection as LLM01. The LLM06 description includes an example where text in a malicious email causes an agent to forward information from the inbox to an outside party. Treat any text brought in from outside as if it may contain hidden instructions to the AI.
Local MCP servers also need care. The official MCP security guide explains that local MCP servers run on the user's machine and may have direct access to the system. Installing a server of unknown origin can lead to arbitrary command execution or data exfiltration. Check the commands that will run, and use only servers from trusted sources.
In n8n, the Slack node can serve as a step that asks a person for approval before the AI Agent calls a tool. We also explain how to think about permissions in AI agent security.
Publishing Your Own Tools via MCP
When you publish your own workflows or apps via MCP, MCP hosts such as Claude Desktop and Cursor can call them. In n8n, connect a Custom n8n Workflow Tool node to the MCP Server Trigger node. In Dify, enable the app's MCP Server card.
The official Dify docs list two points to watch when publishing.
- Descriptions: write tool and input descriptions with how the AI will read them in mind. Instead of just writing input data, be specific, such as JSON with the required fields
- Wait time: if the app takes time to process, the client feels that wait directly. Split heavy processing into smaller pieces
If you let others use an MCP server you published, set up authentication and decide in advance how to hand out and revoke URLs and tokens.
Employee Store is a marketplace where companies can adopt AI agents built by developers. You can list in any format, including n8n and Dify workflows and agents you developed in-house. There is no listing fee or upfront cost. The fee is 20% of the deal amount and applies only when a deal closes. For details, see the seller guide.
FAQ
- How is MCP different from an API?
- MCP is a shared standard for AI applications to connect to external systems. An MCP server returns a list of its tools, and the client reads the list before calling a tool. Some MCP servers call existing APIs inside their tools.
- When should I use n8n's MCP Server Trigger versus instance-level MCP?
- MCP Server Trigger sits inside one workflow and exposes only that workflow's tools. Instance-level MCP creates one connection for all of n8n so enabled workflows can be searched and run together.
- Can Dify connect to a stdio MCP server?
- According to the official Dify docs, it can connect only to MCP servers that communicate over HTTP. Servers that use stdio locally cannot be added as they are.
Sources
- Model Context Protocol: What is the Model Context Protocol (MCP)? (checked October 2, 2026)
- Model Context Protocol: Architecture overview
- Model Context Protocol: Security Best Practices
- n8n Docs: MCP Server Trigger
- n8n Docs: MCP Client Tool
- n8n Docs: MCP Client
- n8n Docs: MCP servers
- n8n Docs: Connect to n8n MCP server
- n8n Docs: Slack node
- n8n: Plans and Pricing
- Dify Docs
- Dify Docs: Dify Tools
- Dify Docs: MCP Server
- OWASP Gen AI Security Project: LLM Top 10 for 2025
- OWASP Gen AI Security Project: LLM06:2025 Excessive Agency
- Employee Store: Seller Guide (Japanese)


