Lesson 6 / 25
HTTP Request and Credentials
Call any REST API with the HTTP Request node and store secrets as credentials.
The universal node
When no ready-made node exists, HTTP Request can call any API: choose the method, URL, query parameters, headers and body. Put API keys in n8n Credentials (Header Auth, Bearer Token, OAuth2 and so on) rather than typing them into node fields, so they are stored encrypted and are not visible in exported workflows.
The request as curl
This is what an HTTP Request node with Bearer auth sends. In n8n you fill the same parts in the node form, and the token comes from the credential.
curl -X POST https://api.example.com/v1/tickets \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"title":"Login fails","priority":"high"}'Never hard-code keys
Keys typed into a node can leak through exported JSON, screenshots or shared workflows. Always use credentials, and rotate any key that was ever pasted into a workflow field.
Quick check: Where should an API key live in n8n?
- In a node field in plain text
- In the workflow name
- In a Slack message
- In n8n Credentials
Answer
In n8n Credentials — Credentials are stored encrypted and kept out of exported workflow JSON.