Updated: 28 September 2026 · Applies to: n8n 2.40 (Docker Compose)
A complete n8n backup contains more than an export of your workflows. If you only save workflow files, you lose users, execution history and, above all, the key that decrypts your saved credentials. This guide shows what to save, how to export workflows and credentials, and how to restore.
What a complete backup contains
- The
.n8nfolder. Itsconfigfile contains the key that encrypts your credentials, and with the default SQLite database the database file lives here as well. In Docker it is the volumen8n_data, mounted at/home/node/.n8n. - Your PostgreSQL database, if you use one instead of SQLite (How to use PostgreSQL instead of SQLite with n8n?). Back it up with the database's own tools. You still need the
.n8nfolder: the credentials stored in the database can only be decrypted with the key from that folder. - Your deployment settings: the
compose.yamland.envfiles, includingN8N_ENCRYPTION_KEY.
Without the encryption key a restored database cannot be decrypted. Store the key in a password manager as well (How to set and back up the n8n encryption key (N8N_ENCRYPTION_KEY)?).
Option 1: back up the whole data volume (recommended)
With the default SQLite database, stop n8n while you copy the data, because a database file that is copied while n8n writes to it can be damaged.
- Stop n8n:
cd ~/n8n-compose sudo docker compose stop n8n
- Pack the volume into a dated archive. Docker Compose names the volume after the folder, so check the name first with
sudo docker volume ls(for examplen8n-compose_n8n_data):sudo docker run --rm -v n8n-compose_n8n_data:/data -v $(pwd):/backup alpine tar czf /backup/n8n-data-$(date +%Y%m%d).tar.gz -C /data .
- Pack your settings files too (they contain your encryption key, so keep the archive private), then start n8n again:
tar czf n8n-settings-$(date +%Y%m%d).tar.gz compose.yaml .env sudo docker compose start n8n
- Copy the archive and the settings files to another machine or storage. A backup that only lives on the same server does not protect you from losing that server.
Option 2: export workflows and credentials with n8n's CLI
This is convenient to move workflows to another n8n. Use a separate folder for each command, and a folder that is mounted from the host (for example ./local-files in the Compose file of How to install n8n with Docker Compose and HTTPS on an Ubuntu VPS?, seen inside n8n as /files), otherwise the files disappear with the container:
sudo docker compose exec n8n n8n export:workflow --backup --output=/files/backup/workflows/ sudo docker compose exec n8n n8n export:credentials --backup --output=/files/backup/credentials/
The --backup option writes each workflow and credential to its own readable JSON file. The exported credentials stay encrypted. The CLI export does not contain users and their roles, execution history, variables or instance settings including the encryption key; it is enough to move workflows, not to rebuild a whole instance.
Restore
Whole instance from a volume backup:
- Stop n8n:
sudo docker compose stop n8n - Restore the archive into the (empty) volume:
sudo docker run --rm -v n8n-compose_n8n_data:/data -v $(pwd):/backup alpine sh -c "rm -rf /data/* /data/.[!.]* ; tar xzf /backup/n8n-data-YYYYMMDD.tar.gz -C /data"
Use the correct date and volume name. This deletes the current contents of the volume first. - Restore your PostgreSQL database if you use one, put back
compose.yamland.env, then start:sudo docker compose up -d
Workflows and credentials from CLI files: finish the owner setup on the new n8n first, because the import needs an existing user. Then:
sudo docker compose exec n8n n8n import:workflow --separate --input=/files/backup/workflows/ sudo docker compose exec n8n n8n import:credentials --separate --input=/files/backup/credentials/
Imported workflows are switched off; publish them again in the editor. Credentials can only be read if the new n8n uses the same N8N_ENCRYPTION_KEY as the old one. Existing items with the same ID are overwritten.
Back up to GitHub automatically
Ucartz publishes a free template in the official n8n template library that saves your self-hosted workflows to a GitHub repository: Sync self-hosted workflow backups to GitHub. It is a good addition, but not a replacement for the volume backup above.
Frequently asked questions
How often should I back up?
Before every update and regularly, for example daily with a scheduled job on the server.
Where is my encryption key?
In the config file inside the .n8n folder, or in your N8N_ENCRYPTION_KEY setting if you set one.
Can Ucartz set up automatic backups?
Yes; our engineers can automate this for you (see below).
Official documentation: n8n documentation: Back up and restore.
Need a server for n8n, or a hand with the setup?
- n8n VPS hosting: a VPS made for self-hosted n8n.
- n8n setup service: we install n8n on your own server with SSL, backups and security.
- n8n automation services: workflows, integrations and consulting.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
