Before exposing a self-hosted n8n instance, configure HTTPS, restrict access to the editor and API, protect credentials and sensitive files, limit workflow capabilities to what trusted users need, and run n8n’s security audit. The right settings depend on your installed version, hosting setup, workflows, and who can create or edit them.
1. Put HTTPS in front of n8n
Use HTTPS for connections to the editor and API. n8n recommends putting a reverse proxy, such as Traefik, or a network load balancer in front of the instance to handle TLS and certificate renewal. This keeps certificate management at the network edge, but you must configure that proxy or load balancer correctly.
You can instead configure TLS certificates directly in n8n. The N8N_SSL_CERT and N8N_SSL_KEY settings point to the certificate and private-key files. With this approach, you are responsible for renewing and replacing the certificates.
| Approach | Where TLS is configured | Certificate renewal |
|---|---|---|
| Reverse proxy or load balancer | At the proxy or load balancer in front of n8n | Handled as part of that front-end setup |
| Direct TLS | In n8n, using N8N_SSL_CERT and N8N_SSL_KEY |
You must maintain renewal and update the files |
A secure-cookie setting does not create HTTPS. Configure TLS itself, then review the secure-cookie setting for your deployment and installed version.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
2. Restrict access to the editor and API
Keep the editor behind authentication and limit it to the people who need to manage workflows. Do not leave the public REST API available if your deployment does not need it; n8n documents disabling the public API as a security measure. Check that any integrations that rely on the API will still work before changing its availability.
Do not confuse the editor and management API with production webhooks. A workflow may need a webhook that anyone can call, but that should be an intentional endpoint, not an accidental way into the editor or API. Review each webhook’s purpose, authentication, and input handling. In particular, investigate any unprotected-webhook findings from the security audit.
3. Choose an account and login policy
For installations with multiple users, consider SSO and two-factor authentication (2FA), and give users only the access they need. n8n’s documented instance-wide 2FA policy applies to email-and-password logins; it does not apply to SAML or OIDC SSO logins. Availability of security-policy features depends on the n8n plan, so confirm that your plan supports a feature before looking for its setting.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
| Login option | What to account for |
|---|---|
| Email and password | Instance-wide 2FA enforcement is documented for this login method; plan availability can vary. |
| SAML or OIDC SSO | Instance-wide 2FA enforcement in n8n does not cover these sign-ins. Review authentication requirements with your identity provider. |
4. Protect the encryption key and n8n’s files
Protect the key n8n uses to encrypt credentials, along with the storage that contains n8n’s data. Limit access to both, keep sensitive configuration out of places where workflow authors can retrieve it, and include them in your backup and recovery planning. n8n identifies encryption-key rotation as a security topic; plan any rotation carefully so existing credentials remain usable.
Recommended Free Tools
Review these environment-variable controls against the needs of your workflows and the defaults for your installed n8n version:
N8N_BLOCK_ENV_ACCESS_IN_NODEcontrols access to environment variables from nodes.N8N_BLOCK_FILE_ACCESS_TO_N8N_FILESblocks node access to files in the.n8ndirectory.N8N_ENFORCE_SETTINGS_FILE_PERMISSIONSenforces restrictive permissions for the settings file.N8N_RESTRICT_FILE_ACCESS_TOlimits file access to selected paths.
These controls can affect legitimate workflows. Decide which file and environment-variable access is genuinely required, then set restrictions accordingly rather than changing every variable without checking its effect. Self-hosters are responsible for securing data at rest on their own infrastructure.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
5. Limit what workflows are allowed to do
A person who can create or edit workflows may be able to use the capabilities available to those workflows. Treat node restrictions as a trust-boundary decision: the appropriate set depends on who can edit workflows and what those workflows must accomplish.
Review community nodes
Assess community nodes before installing them, and keep only those your workflows need. Their presence expands the code and functionality running in your instance, so do not treat installation as a routine substitute for reviewing a workflow’s requirements.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Restrict code and powerful nodes where they are not needed
Review external-module access for the Code node, especially if workflow authors are not fully trusted. Exclude capabilities workflows do not require; n8n specifically gives Execute Command and SSH as examples of nodes to consider restricting. These restrictions may break workflows that depend on those features, so check actual workflow requirements before applying them.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
6. Run the security audit and work through its findings
Run the built-in audit before launch, after meaningful configuration changes or updates, and periodically thereafter. You can run it with the CLI command n8n audit, make an authenticated API request, or use the n8n node. For API use, follow the audit documentation for the endpoint and request format supported by your installed version.
The audit reports findings in five practical areas:
- Credentials: credential use that merits review.
- Database: risky database expressions.
- File system: file-system nodes that can expose or alter files.
- Nodes: risky built-in, community, or custom nodes.
- Instance configuration: issues such as unprotected webhooks, missing security settings, and an outdated instance.
Use the report to identify specific changes, then rerun the audit to check the result. Treat a clean report as a useful check, not a substitute for deciding who should have access or whether a workflow’s endpoints and capabilities are appropriate.
7. Decide whether execution-data redaction is needed
Execution data can contain sensitive information handled by workflows. Review n8n’s execution-data redaction controls if that information should not remain visible in execution records. n8n documents production-execution redaction as the recommended scope when enforcing its policy, and also describes a stricter scope covering both manual and production executions. Instance-wide enforcement has separate plan and version requirements; confirm support for your deployment rather than assuming the control is available.
8. Use a final pre-launch checklist
- HTTPS is configured, and certificate renewal has a clear owner.
- Only intended users can reach the editor; the public API is disabled if it is not needed.
- Public webhooks are intentional and have suitable authentication and input handling.
- Credential-encryption material, settings, and n8n storage are access-controlled.
- Environment and file-access restrictions match actual workflow needs.
- Community nodes, Code node module access, and powerful nodes are limited to the required set.
- Login controls and any execution-data redaction policy are supported by your plan and version.
- The security audit has been run and its findings reviewed.
Settings, defaults, and plan availability can change. Verify the relevant n8n documentation for the version you have installed, and validate changes against your own workflows before making the instance reachable from the internet.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

