Updated: 28 September 2026 · Applies to: n8n 2.40 (self-hosted)

n8n encrypts every saved credential (passwords, API keys, OAuth tokens) with an encryption key before it writes it to the database. On the first start n8n creates a random key and saves it in the file config in its data folder (~/.n8n; in Docker /home/node/.n8n). If you lose that key, all saved credentials become unreadable, even if you have a full copy of the database.

Why you should set the key yourself

  • You know it and can store it safely, instead of it being hidden inside a volume.
  • Restoring on a new server works: n8n can decrypt the restored credentials only with the same key.
  • In queue mode every worker must use the same key.

Set your own key on a new n8n

  1. Generate a long random key on the server:
    openssl rand -hex 32
  2. Add it to your .env file:
    N8N_ENCRYPTION_KEY=PASTE-THE-KEY-HERE
  3. Pass it to n8n in the environment: section of compose.yaml:
    - N8N_ENCRYPTION_KEY=${N8N_ENCRYPTION_KEY}
  4. Start n8n: sudo docker compose up -d
  5. Store the key in a password manager and in your backup (How to back up and restore n8n (workflows, credentials and encryption key)?).

n8n uses your key when the settings file does not contain one yet, that is, on the first start. This is why How to install n8n with Docker Compose and HTTPS on an Ubuntu VPS? sets it before the first launch.

Find the key of an existing n8n

If n8n was started without N8N_ENCRYPTION_KEY, the generated key is in the config file inside the data volume:

cd ~/n8n-compose
sudo docker compose exec n8n cat /home/node/.n8n/config

Save the value of encryptionKey. If you want to define it explicitly in your settings, set N8N_ENCRYPTION_KEY to exactly this value. Keep this file and its value private.

Do not change the key of a running n8n

Setting a different key on an instance that already has credentials makes them unreadable. If you must replace the key, n8n provides a documented procedure for rotating encryption keys; make a full backup first and follow n8n's guide.

Symptoms of a wrong or missing key

Frequently asked questions

Is the key the same as my n8n password?
No. It is a separate secret for the credentials, and it never changes when you change a password.

Can I export credentials without the key?
n8n's CLI can export credentials in plain text with the --decrypted option. That file contains all your secrets, so store it very carefully and delete it after use.

Official documentation: n8n documentation: Set a custom encryption key.

Need a server for n8n, or a hand with the setup?

Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.

Was this answer helpful? 0 Users Found This Useful (0 Votes)