
An n8n holds the keys to everything it automates: e-mail, sheets, shop, WhatsApp. Whoever gets into it reaches all of that. Securing n8n comes down to three fronts: who gets into the editor, how the credentials are stored and who may call the webhooks. On top of that, the VPS itself, which is yours.
1. Who gets into the editor
|
|
|
|
2. Credentials
| Rule | Why |
| Keep everything in n8n credentials, never typed into a node | Credentials are encrypted with the encryption key; text typed into a node is in plain view of whoever opens the workflow. |
Keep N8N_ENCRYPTION_KEY off the server |
It is the key to everything. See backing up n8n. |
| Give each credential the fewest powers | A read-only key deletes nothing if someone steals it. See API tokens: automating without handing over your password. |
| One credential per purpose | If one is stolen, revoke it without breaking the rest. |
| Spending limits on AI keys | See getting an API key for an AI model, and keeping it safe. |
3. Exposed webhooks
A production webhook is an address open to the internet. Whoever knows it can call it. So:
|
|
|
|
|
| Executions keep the data that passed through, names, e-mails and messages included. Clear out old executions and do not keep those of sensitive workflows longer than you need to. |
| The VPS counts too. System updates, firewall, SSH key access: see keeping your VPS secure: the six that matter. And n8n itself must be updated: updating n8n safely. |
|
Think someone got into your VPS? Open a ticket with what you saw. Open a support ticket |
|
SEE ALSO Keeping your VPS or dedicated server secure: the six that matter n8n webhooks: test URL and production URL |
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from 5.940,00 Kz/mo (3-year plan, with coupon) See plans |
- 0 Users Found This Useful











