Updated: 28 September 2026 · Applies to: n8n 2.40 (self-hosted)
n8n encrypts every saved credential (passwords, API keys, OAuth tokens) with an encryption key before it writes it to the database. On the first start n8n creates a random key and saves it in the file config in its data folder (~/.n8n; in Docker /home/node/.n8n). If you lose that key, all saved credentials become unreadable, even if you have a full copy of the database.
Why you should set the key yourself
- You know it and can store it safely, instead of it being hidden inside a volume.
- Restoring on a new server works: n8n can decrypt the restored credentials only with the same key.
- In queue mode every worker must use the same key.
Set your own key on a new n8n
- Generate a long random key on the server:
openssl rand -hex 32
- Add it to your
.envfile:N8N_ENCRYPTION_KEY=PASTE-THE-KEY-HERE
- Pass it to n8n in the
environment:section ofcompose.yaml:- N8N_ENCRYPTION_KEY=${N8N_ENCRYPTION_KEY} - Start n8n:
sudo docker compose up -d - Store the key in a password manager and in your backup (How to back up and restore n8n (workflows, credentials and encryption key)?).
n8n uses your key when the settings file does not contain one yet, that is, on the first start. This is why How to install n8n with Docker Compose and HTTPS on an Ubuntu VPS? sets it before the first launch.
Find the key of an existing n8n
If n8n was started without N8N_ENCRYPTION_KEY, the generated key is in the config file inside the data volume:
cd ~/n8n-compose sudo docker compose exec n8n cat /home/node/.n8n/config
Save the value of encryptionKey. If you want to define it explicitly in your settings, set N8N_ENCRYPTION_KEY to exactly this value. Keep this file and its value private.
Do not change the key of a running n8n
Setting a different key on an instance that already has credentials makes them unreadable. If you must replace the key, n8n provides a documented procedure for rotating encryption keys; make a full backup first and follow n8n's guide.
Symptoms of a wrong or missing key
- After a restore or a move, workflows appear but their credentials cannot be used or show decryption errors. Use the same
N8N_ENCRYPTION_KEYas the old server. - You restored the database but not the
.n8nfolder: the key file is missing. Restore it as described in How to back up and restore n8n (workflows, credentials and encryption key)?.
Frequently asked questions
Is the key the same as my n8n password?
No. It is a separate secret for the credentials, and it never changes when you change a password.
Can I export credentials without the key?
n8n's CLI can export credentials in plain text with the --decrypted option. That file contains all your secrets, so store it very carefully and delete it after use.
Official documentation: n8n documentation: Set a custom encryption key.
Need a server for n8n, or a hand with the setup?
- n8n VPS hosting: a VPS made for self-hosted n8n.
- n8n setup service: we install n8n on your own server with SSL, backups and security.
- n8n automation services: workflows, integrations and consulting.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
