CIRCL Hash Lookup API Microservice Compute Protocol Server for AI Agents - n8n Workflow

Use this comprehensive n8n workflow to set up an MCP server for the CIRCL Hash Lookup API, empowering your AI agents with 11 file hash verification tools. Get started with n8n templates today.

Workflow Preview

Ready to automate?

Download this n8n workflow template and start using it instantly.

Who is this best for?


  • AI/ML Engineers: Those developing AI agents or large language models (LLMs) requiring external, real-time security data lookups.

  • Security Researchers & Analysts: Professionals needing to automate threat intelligence checks using cryptographic hashes.

  • n8n Automation Specialists: Users seeking advanced examples of building AI tools using the n8n MCP functionality.

  • DevOps Teams: Groups looking to integrate file hash verification into automated deployment or monitoring pipelines using a powerful n8n node.

Overview

Integrating specialized APIs, especially those used for security and threat intelligence like the hashlookup CIRCL API, can be challenging for AI agents. This n8n workflow solves this by creating a dedicated Microservice Compute Protocol (MCP) server. This server transforms the standard REST API into a set of structured tools that AI agents can utilize instantly. By leveraging the power of n8n, developers gain access to 11 distinct operations—from bulk searches for MD5 and SHA1 hashes to fetching database information and managing search sessions.

This setup provides a critical bridge: the AI agent communicates intent, and the n8n node layer handles the precise, parameter-driven HTTP requests, ensuring secure and accurate data retrieval. This particular n8n workflow is a robust example of how to operationalize external services for autonomous AI operations.

How it Works

This automation functions entirely as an AI tool server, initiated by the custom n8n trigger for MCP. The process follows these steps:


  1. AI Request: An AI agent, configured with the MCP URL, identifies the need to perform a hash lookup (e.g., looking up an SHA1 hash).

  2. MCP Trigger Activation: The request hits the hashlookup CIRCL MCP Server n8n trigger, which receives the agent’s call and requested tool/operation.

  3. Tool Selection: The n8n workflow routes the request to the corresponding HTTP Request Tool n8n node (e.g., 'Lookup SHA1 Hash').

  4. Parameter Extraction: Each HTTP request n8n node utilizes the $fromAI() expression (e.g., {{ $fromAI('sha1', 'Sha1', 'string') }}). This mechanism securely extracts necessary arguments (like the hash value) from the AI agent's prompt or request body.

  5. API Execution: The n8n node executes the external request against the https://hashlookup.circl.lu API.

  6. Response Handling: The API response is captured by the n8n workflow and automatically returned via the MCP n8n trigger back to the originating AI agent, maintaining the original API structure for the agent to process.

Installation Guide

To deploy this comprehensive n8n workflow template, follow these steps:


  1. Import the n8n Workflow: Copy the provided JSON data and import it directly into your self-hosted or cloud n8n instance using the 'New' -> 'Import from JSON' option.

  2. Authentication: No external credentials or API keys are required for the CIRCL Hash Lookup API itself, simplifying deployment.

  3. Activate the n8n Workflow: Ensure the workflow is set to 'Active'. This starts the MCP server listening for incoming AI requests.

  4. Retrieve MCP URL: Click on the hashlookup CIRCL MCP Server n8n trigger node and copy the generated Webhook URL (the MCP endpoint).

  5. Configure AI Agent: Paste this URL into your AI agent's configuration, designating it as an available tool server. The agent can now use the 11 exposed operations provided by this n8n template.

Node Details

This n8n workflow is built around one primary n8n trigger and eleven specialized HTTP Request tool nodes, enabling seamless integration with AI agents.

hashlookup CIRCL MCP Server (MCP Trigger):
Function: Serves as the primary entry point for AI agent communications, listening on the path /hashlookup-circl-mcp.
Key Configuration: This special n8n trigger handles the handshake and routing logic necessary for the Microservice Compute Protocol.

Bulk Search MD5 Hashes (HTTP Request Tool n8n node):
Function: Performs bulk submission of MD5 hashes to the CIRCL API via a POST request.
Key Configuration: Configured to accept a JSON array of hashes.

Lookup MD5 Hash (HTTP Request Tool n8n node):
Function: Looks up a single MD5 hash.
Key Configuration: Uses the expression =https://hashlookup.circl.lu/lookup/md5/{{ $fromAI('md5', 'Md5', 'string') }}, illustrating how parameters are dynamically injected from the AI agent's request into the n8n node's URL.

List SHA1 Children (HTTP Request Tool n8n node):
Function: Retrieves children related to a specific SHA1 hash, supporting pagination.
Key Configuration: Requires dynamic path parameters for sha1, count, and cursor, all pulled directly using $fromAI() expressions, demonstrating complex parameter handling within the n8n workflow.

Get Database Info (HTTP Request Tool n8n node):
Function: Retrieves general information about the current state of the hashlookup database.
* Key Configuration: Simple GET request to the /info endpoint, requiring no AI-supplied parameters. This n8n node provides essential metadata for the agent.

Related n8n Workflows

Free

Nodes: 3 Nodes
Updated: December 26 2025
View all
Created by

A hacker by nature, programmer by trade ⚒️ I'm looking to collaborate on things that save human labor 📫 How to reach me Github👇 -> Discord

Featured*