AI Automation with n8n, Make and Zapiern8n in depth · Lesson 4 of 17

n8n AI: the AI Agent node, LangChain nodes and MCP

Article · 18 min · 8 min lecture

Video lecture

n8n AI: the AI Agent node, LangChain nodes and MCP

13 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 13

n8n AI

  • Chains, extractors, classifiers
  • AI Agent with tools
  • MCP client and server
  • Configure for reliability

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

n8n's AI building blocks

n8n's AI features are built on LangChain concepts and appear as root nodes with attached sub-nodes:

Root nodeWhat it does
AI AgentAn LLM that can call tools in a loop to reach a goal (tools-agent pattern)
Basic LLM ChainSingle prompt in, text out; optional output parser
Information ExtractorExtract structured fields from text into a schema
Text ClassifierRoute items into categories you define
Sentiment AnalysisClassify sentiment
Summarization ChainSummarize long documents
Question and Answer ChainAnswer from a retriever (RAG)
GuardrailsCheck text for issues such as PII, jailbreak attempts or topical violations before or after LLM steps (check current options)
Sub-node typeExamples
Chat modelOpenAI, Anthropic, Google Gemini, Mistral, Azure OpenAI, AWS Bedrock, Ollama (local), OpenRouter, DeepSeek, Groq and others
MemorySimple (window buffer), Postgres, Redis, MongoDB chat memory
ToolsCall n8n Workflow, HTTP Request tool, Code tool, MCP Client Tool, Think tool, vector store tool, and app-specific tool versions of many nodes
Output parserStructured output parser (JSON schema), auto-fixing parser
RetrievalVector stores (Postgres PGVector, Supabase, Pinecone, Qdrant and others), embeddings, text splitters, document loaders

The provider list grows constantly; check the node library.

When to use an agent vs a chain

  • Use a chain or extractor when the steps are known: classify this email, extract these fields, summarize this call. Cheaper, faster, more predictable.
  • Use an agent when the model must choose among tools dynamically: "Answer the customer's question using our order lookup, FAQ search or escalation tool as needed."
  • Many robust workflows use deterministic nodes for the flow and small AI steps inside it. Agents are powerful but harder to test.

Configuring an AI Agent well

  1. System message: role, goal, rules, when to use each tool, output format, what never to do.
  2. Tools with precise names and descriptions: the description is how the model decides; include parameter meanings.
  3. Max iterations: cap the tool loop to prevent runaway costs.
  4. Memory: only where multi-turn context is needed (chat); key it by session or user ID.
  5. Structured output: attach a structured output parser when downstream nodes need fields.
  6. Human review for risky tools: n8n supports human-in-the-loop approvals for tool calls and "send and wait for response" approvals in messaging and email nodes (see Module 6).
  7. Model choice: a smaller, faster model for routine steps; stronger reasoning models only where needed. Some workflows route between models with a model selector.

MCP in n8n

  • MCP Client Tool (sub-node): lets your AI Agent call tools exposed by external MCP servers (for example a CRM or documentation server).
  • MCP Server Trigger: exposes n8n workflows as tools to external MCP clients (for example a desktop AI assistant or another agent platform). That means your carefully built, tested workflows ("create_quote", "lookup_order") become callable tools for AI assistants, with n8n handling credentials and logic.

Secure MCP endpoints with authentication, expose only the tools needed, and log calls.

Worked example: an inbound email triage agent for a UK e-commerce brand

Trigger: new email in the support inbox. Flow:

  1. Guardrails node checks for PII patterns to redact before sending text to the LLM (card numbers, for example).
  2. Text Classifier: order_status, return_request, product_question, complaint, spam.
  3. For order_status and product_question, an AI Agent with tools: lookup_order (sub-workflow calling Shopify), search_faq (vector store tool over help articles), and a Think tool. System message requires citing order data and never promising refunds.
  4. The agent drafts a reply; a structured output parser returns {reply, confidence, needs_human}.
  5. If needs_human or confidence is low, or category is complaint: create a helpdesk ticket for a human with the draft attached. Otherwise send via Gmail after a send-and-wait approval in Slack for the first two weeks, then auto-send for low-risk categories.

Hands-on: structured extraction with the Information Extractor

Attribute schema for lead emails:

{
  "type": "object",
  "properties": {
    "company": {"type": "string"},
    "service_interest": {"type": "string", "enum": ["seo", "paid_social", "web_design", "content", "other"]},
    "budget_mentioned": {"type": "boolean"},
    "budget_amount": {"type": ["number", "null"]},
    "currency": {"type": ["string", "null"], "description": "ISO code such as PKR, AED, SAR, GBP, USD"},
    "urgency": {"type": "string", "enum": ["low", "medium", "high"]},
    "language": {"type": "string", "enum": ["en", "ur", "ar", "mixed"]}
  },
  "required": ["service_interest", "budget_mentioned", "urgency", "language"]
}

Steps: Gmail Trigger -> Information Extractor (chat model sub-node: a fast, low-cost model; schema above) -> IF service_interest is not other -> CRM upsert with extracted fields -> Slack notification. Test with 20 real (anonymized) emails, including Urdu and Arabic ones, and measure field accuracy before trusting it.

Pitfalls

  • Using an agent where a classifier would do.
  • Vague tool descriptions ("does stuff with orders").
  • No iteration cap or cost monitoring on agents.
  • Sending raw personal data to external models without need or agreement.

Key takeaways

  • n8n AI uses root nodes (AI Agent, LLM Chain, Information Extractor, Text Classifier, Guardrails) with sub-nodes for models, memory, tools, parsers and vector stores.
  • Prefer chains/extractors/classifiers for known steps; use agents when tool choice must be dynamic.
  • Configure agents with clear system messages, precise tool descriptions, iteration caps, structured output and human approval for risky tools.
  • MCP Client Tool lets agents call external MCP servers; MCP Server Trigger exposes n8n workflows as tools, which must be secured.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. You need to extract company, budget and urgency from every lead email. Which n8n node fits best?
  2. What does the MCP Server Trigger do?
  3. An agent occasionally loops through tools many times, running up costs. What setting helps most directly?

Put it into practice

Build the lead-email extractor (Gmail -> Information Extractor -> IF -> CRM -> Slack). Run it on 20 anonymized emails including Urdu and Arabic ones and record per-field accuracy.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.