Lesson 6 / 25

HTTP Request and Credentials

Call any REST API with the HTTP Request node and store secrets as credentials.

The universal node

When no ready-made node exists, HTTP Request can call any API: choose the method, URL, query parameters, headers and body. Put API keys in n8n Credentials (Header Auth, Bearer Token, OAuth2 and so on) rather than typing them into node fields, so they are stored encrypted and are not visible in exported workflows.

The request as curl

This is what an HTTP Request node with Bearer auth sends. In n8n you fill the same parts in the node form, and the token comes from the credential.

curl -X POST https://api.example.com/v1/tickets \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"title":"Login fails","priority":"high"}'

Never hard-code keys

Keys typed into a node can leak through exported JSON, screenshots or shared workflows. Always use credentials, and rotate any key that was ever pasted into a workflow field.

Quick check: Where should an API key live in n8n?

  • In a node field in plain text
  • In the workflow name
  • In a Slack message
  • In n8n Credentials
Answer

In n8n Credentials — Credentials are stored encrypted and kept out of exported workflow JSON.