File Hash Verification MCP Server for AI Agents via CIRCL API

MCP server exposing 11 CIRCL hashlookup API operations for AI agents to perform MD5/SHA1/SHA256 hash lookups, bulk searches, parents/children queries, and database info retrieval.

n8n
File Hash Verification MCP Server for AI Agents via CIRCL API

This n8n workflow transforms the CIRCL hashlookup API into a fully functional MCP (Model Context Protocol) server, enabling AI agents to easily query file hashes for threat intelligence. It supports 11 endpoints including bulk MD5/SHA1 searches, individual lookups for MD5/SHA1/SHA256, parents/children relations for SHA1, and database info. The MCP trigger acts as the entry point, with HTTP request nodes handling API calls to https://hashlookup.circl.lu, and AI expressions like $fromAI() auto-populating parameters for seamless integration.

Key benefits include rapid deployment of a security-focused server without custom coding, direct AI agent compatibility via webhook URL, and native response formatting. It saves hours of development time for security teams integrating threat intel into AI workflows, reducing manual hash checks and enabling automated malware analysis.

Ideal use cases: AI-powered security scanning in DevOps pipelines, file upload verification in web apps, incident response automation for SOC teams, and research tools for cybersecurity analysts. Setup is straightforward: import, add CIRCL credentials, activate, and connect your AI agents to the webhook for instant access to CIRCL's vast hash database.

$22.99
Last updated October 3, 2026
30-day money-back guarantee
Instant download
Lifetime updates included

New buyers can create an account from the cart to unlock a controlled $10 first-purchase credit on eligible orders of $25+.

Secure checkout powered by Stripe

Support

How to import this workflow into n8n

  1. 1Purchase or download the workflow to get the n8n workflow JSON file.
  2. 2In your n8n instance, open Workflows and choose "Import from File" (or paste the JSON with Ctrl+V on the canvas).
  3. 3Open each node marked with a credential warning and connect your own accounts and API keys.
  4. 4Run the workflow once manually to verify the data flow, then toggle it to Active.

Related Other workflows

More from Matt Buds

Need this deployed? We'll set it up for you.

Our automation experts deploy this workflow in your stack, connect your accounts, and verify it works — or build a custom solution from scratch.