Two workflows
Ask:
Ask the wiki: a message arrives, an AI Agent node with the MCP Client Tool searches and reads Folio, and replies with the answer and a link. Event to row: a release or an alert arrives, and a workflow adds a row to the Incident log table.
The reply carries a link to the page. The table shows the new row at once, and Git history shows the write with the token owner's name.
Connect
What you need
- n8n 1.104 or newer. Streamable HTTP in the MCP nodes arrived in 1.104 and is the default from 1.114.
- A Folio token. For a workflow that only answers questions, use read. For one that writes, create the token under a separate Folio user with the editor role in one space.
- n8n must be able to reach Folio. n8n Cloud reaches only a public address. A self-hosted n8n can reach Folio on the same network.
Steps
Step 1: In n8n create a credential of type Bearer Auth. Paste the Folio token. A Header Auth credential with the name Authorization and the value Bearer folio_pat_... works too.
Step 2: For an AI agent: add the MCP Client Tool node to the Tool input of an AI Agent node. Set the endpoint to your Folio address, the server transport to HTTP Streamable and authentication to Bearer, with your credential.
Endpointhttps://your-folio.example.com/mcpStep 3: Under Tools to Include choose Selected and pick only what the agent needs: search_pages and read_page for answers, plus folio_table_insert if it should log a row. With All, the agent sees every tool, including the ones that write.
Step 4: For a plain workflow step, use the MCP Client node instead. It lists the server's tools and runs the one you pick. A scheduled digest, for example, calls folio_table_query and sends the rows to Slack or email.
Step 5: To start from a ready-made workflow, import github-issue-to-table-row.json or weekly-summary-page.json from the Folio repository (workflow menu, Import from file). Then pick your Bearer credential in the Folio nodes and set your Folio address.
Step 6: Before an agent writes to a table, make it call folio_table_schema. Column ids and the options of select and status columns are not guessable from names.
Try it against the demo
The demo does not issue personal tokens, so n8n cannot connect to it. Run your own Folio, which takes a few minutes with Docker, or try the demo from Claude or ChatGPT.
What the agent can do
Folio exposes 23 tools over MCP. Full reference.
| Reading (11) | What it does |
|---|---|
list_spaces | Spaces you can see, with your role in each |
list_tree | The page tree of a space |
search_pages | Full-text search across the pages you can open |
read_page | A page as Markdown, with its metadata |
resolve_folio_url | A Folio link to the page it points at |
get_backlinks | Pages that link to a page |
page_history | The Git commits that touched a page |
page_at_sha | A page as it was at a given commit |
folio_table_list | Data tables in a space |
folio_table_schema | A table's real columns, types and options |
folio_table_query | Table rows with filter, sort and search |
search | The same search under the name ChatGPT deep research looks for |
fetch | A page by the id that search returned, as Markdown |
| Writing (10) | What it does |
|---|---|
create_page | A new document with text, or a table with columns |
update_page | Replace the text of a page; merges with live editing |
create_board | A whiteboard from a short description of boxes and arrows |
update_board | Replace a whiteboard's scene |
board_ops | Align, distribute, move or auto-layout board elements |
folio_table_create | A table with an explicit schema |
folio_table_add_column | A new column |
folio_table_insert | New rows |
folio_table_update | Cells, by row id or by filter |
folio_table_delete | Rows, by id |
- Reading needs the read scope. Writing needs write. With read only, every tool that changes something refuses to run.
- All 23 tools carry read-only or destructive annotations, so a client can ask before it writes.
- An agent cannot manage access rights, invite people, or rename and delete spaces. Those actions exist only in the browser.
- A write reaches the page file at once. The Git commit follows after about 90 seconds of quiet, so page history can lag behind an edit.
- The direction is n8n to Folio. Folio has no webhooks or outgoing events yet, so an edit in Folio cannot start a workflow. To react to changes, poll on a schedule: query a table or search pages.
Security
- A personal access token carries the rights of the person who created it, narrowed by its scope. Give an agent its own Folio user with the editor role in the spaces it needs, and create the token there. Do not hand an agent an administrator's token.
- Use a read token when the agent only answers questions.
- The token is shown once. Keep it in an environment variable or the client's secret store, not in a file that goes to Git. Delete it under API tokens when you stop using it.
- Administrative routes are cookie-only: no token reaches them with any scope.
- Page content is data, not instructions. Folio's tool descriptions say so, but the real protection is rights. An agent that also has a shell and write access can be misled by a page someone else wrote, so give it the narrowest token that does the job.
Limits and honest notes
- Field labels can differ slightly between n8n versions.
- Folio has no webhooks or outgoing events.