Skip to main content
Create your own
Lesson illustration

API Authentication Methods

Hello! Welcome back to our course on mastering n8n.

In the last lesson, you learned how to use the powerful HTTP Request node to make custom API calls. We successfully retrieved and created data using a public API, but we deliberately set aside the crucial topic of authentication. Today, we fill that gap.

This lesson is all about securely connecting to APIs. As a developer, you know that hard-coding API keys, tokens, or other secrets directly into your code (or in this case, your workflow) is a major security risk. This lesson will teach you how to authenticate with APIs using API keys, Bearer tokens, and OAuth2, leveraging n8n's robust and secure credential management system. This is the professional way to handle API integrations.

1. The n8n Credential Store: Your Digital Vault

Before diving into specific methods, it's essential to understand n8n's philosophy on credentials. n8n treats credentials as a separate, reusable, and secure entity, much like you would use environment variables or a dedicated secrets manager (like HashiCorp Vault or AWS Secrets Manager) to keep sensitive data out of your application's source code.

How to Connect Any API with n8n (Step-by-Step Guide)

This brief article from Techvoot highlights the core building blocks of n8n and emphasizes the importance of separating credentials from your workflow logic for security and portability.

Read sections '1. Understand the n8n Building Blocks' and '13. Security & Governance'. Pay close attention to the principle of never hard-coding secrets and storing them only in Credentials.

When you configure authentication in an HTTP Request node, you have two primary choices:

  • Predefined Credential Type: A simplified, guided setup for services that have a dedicated n8n integration node (e.g., Google, HubSpot, Airtable). n8n has already figured out the authentication details for you.
  • Generic Credential Type: A flexible, manual setup for any other API. This gives you direct control over the authentication mechanism.

We will explore both in this lesson.

2. Method 1: API Keys (via Header or Query Auth)

An API key is the simplest form of authentication. It's a unique string that you send with your request to identify your application. API documentation will specify how to send it, but it's usually in one of two ways:

  • As a request header: e.g., X-Api-Key: YOUR_SECRET_KEY
  • As a query parameter: e.g., https://api.example.com/data?api_key=YOUR_SECRET_KEY

In n8n, you handle these using the Header Auth and Query Auth generic credential types, respectively.

Complete n8n Authentication Mastery in 14 Minutes | All Auth Methods | Complete Guide

The video 'Complete n8n Authentication Mastery' by FuturMinds provides a concise overview of the different generic authentication types. This segment covers how to handle keys sent in headers or query parameters.

Watch from 03:37 to 04:53 to understand Bearer and Header Auth, and from 06:03 to 07:20 for Query Auth. Note how Header Auth allows you to specify a custom header name, while Query Auth lets you define the name of the URL parameter.

In the previous lesson's video, "n8n HTTP Request Node & Tool", you saw a practical example of setting up a generic credential for Appify using Query Auth (timestamp 42:46 - 44:33). The API required the token in the URL (?token=...), making Query Auth the correct choice.

3. Method 2: Bearer Tokens

Bearer Token authentication is a specific standard for sending tokens. It's extremely common in modern REST APIs. The token is sent in the Authorization header, prefixed with the word "Bearer" and a space.

Format: Authorization: Bearer <your_token>

The term "bearer" implies that whoever possesses (or "bears") the token is authorized to access the resources.

Bearer Token Authentication Flow
This diagram shows the typical Bearer Token flow. The client first requests an access token from an authorization server. It then uses that token in the `Authorization` header to make a successful request to the API (the resource server).

n8n has a dedicated Bearer Auth generic credential type that simplifies this. You only need to provide the token, and n8n handles formatting the header correctly.

Real-World Example: Airtable Personal Access Tokens

Let's look at a practical, developer-focused example. Airtable recently deprecated its old API keys in favor of "Personal Access Tokens." These new tokens are functionally Bearer tokens. The video we used in the last lesson contains an excellent walkthrough of this exact scenario.

n8n HTTP Request Node & Tool (Connect to APIs)

This segment from 'n8n HTTP Request Node & Tool' demonstrates authenticating with Airtable. It's a perfect real-world example of reading documentation, dealing with deprecated keys, and setting up a Bearer token-style credential.

Watch from 45:38 to 49:51. Notice how the documentation leads to using a 'Personal Access Token', which is a form of Bearer token. Also, pay attention to the concept of 'scopes', which define the permissions your token has (e.g., read, write, delete). This is a critical security feature.

This example shows that while the UI might say "API Key" or "Personal Access Token," if the documentation tells you to put it in an Authorization: Bearer ... header, you're dealing with a Bearer Token.

Test your understanding!

The API documentation for a service gives you the following cURL command example:

curl -X GET 'https://api.anyservice.com/v1/items' \
-H 'accept: application/json' \
-H 'x-api-token: sk_123abc456def'

Which Generic Credential Type should you use in n8n, and what would you enter for its Name and Value fields?

Show answer

You should use Header Auth.

  • Name: x-api-token
  • Value: sk_123abc456def

Bearer Auth would be incorrect because the header name is not Authorization, and the value is not prefixed with Bearer.

4. Method 3: OAuth2

OAuth2 is not just an authentication method; it's a protocol for delegated authorization. It allows a user to grant a third-party application (like your n8n workflow) limited access to their data on another service (like Google Calendar or Slack) without sharing their password.

The process is more complex and involves several steps, including a user-interactive consent screen.

The Main Actors in OAuth2:

  • Resource Owner: The user who owns the data.
  • Client: Your n8n application that wants to access the data.
  • Authorization Server: The service that prompts the user for consent and issues access tokens (e.g., accounts.google.com).
  • Resource Server: The API that stores the user's data (e.g., gmail.googleapis.com).

Setting up OAuth2 in n8n involves a one-time configuration where you exchange information between the service provider and your n8n credential settings.

Complete n8n Authentication Mastery in 14 Minutes | All Auth Methods | Complete Guide

The 'Complete n8n Authentication Mastery' video provides one of the clearest step-by-step explanations of the entire OAuth2 flow available. It walks through both the theory and a practical setup with Google.

Watch this detailed segment from 07:08 to 12:58. Focus on understanding the multi-step process: (1) Registering your 'app' in the Google Cloud Console to get a Client ID and Secret. (2) Providing n8n's 'Redirect URL' to Google. (3) Filling out the OAuth2 credential fields in n8n (Auth URL, Token URL, Scopes). (4) The final 'Connect my account' step that initiates the user consent flow.

While OAuth2 is the most complex to set up initially, n8n handles the most difficult part for you: token refreshing. Access tokens are typically short-lived. Once configured, n8n will automatically use the refresh token to get a new access token in the background, ensuring your workflows continue to run without interruption.

5. Predefined vs. Generic: A Final Look

Now that you understand the underlying mechanisms, the benefit of Predefined Credentials becomes clear. When you use a predefined credential for "Google Sheets," for example, n8n presents you with a simple "Connect my account" button. Behind the scenes, it's performing the entire OAuth2 dance you just learned about.

This is why the recommended practice is:

  1. Always check for a Predefined Credential Type first.
  2. If one doesn't exist, use the appropriate Generic Credential Type based on the API's documentation.

The FuturMinds video provides a great summary of this decision-making process.

Complete n8n Authentication Mastery in 14 Minutes | All Auth Methods | Complete Guide

This final clip from 'Complete n8n Authentication Mastery' summarizes the selection criteria, helping you decide which authentication method to choose in different scenarios.

Watch the conclusion from 12:47 to 14:01. It provides a clear hierarchy of which authentication methods to prefer.

Conclusion

You have now added the most critical component for building professional-grade API integrations to your n8n skillset: secure authentication. You've moved beyond public APIs and are now equipped to connect to virtually any service on the web.

Key Takeaways:

  • Never hard-code secrets: Always use the n8n credential store to keep your workflows secure and portable.
  • Read the documentation: The API provider's documentation is the ultimate source of truth for which authentication method to use.
  • You learned to configure the three most common authentication patterns:
    • API Keys using Header Auth or Query Auth.
    • Bearer Tokens using the dedicated Bearer Auth type.
    • OAuth2 for delegated user permissions, handling the multi-step setup process.
  • Prefer Predefined Credentials for simplicity when available, but master Generic Credentials for universal connectivity.

In this lesson, you successfully authenticated and received data. In our next lesson, "Extract and map data from JSON API responses using expressions," we will focus on what to do with that data. You'll learn how to navigate the JSON output from your API calls and use n8n's powerful expression editor to pick out, transform, and use the exact pieces of information you need.

Can't find a good explanation? Sign up and we'll make it for you

Sign up