Creating a Secure Webhook - Must Have
## How it works This workflow demonstrates a fundamental pattern for securing a webhook by requiring an API key. It acts as a gatekeeper, checking for a valid key in the request header before allowing the request to proceed. 1. **Incoming Request:** The `Secured Webhook` node receives an incoming `POST` request. It expects an API key to be sent in the `x-api-key` header. 2. **API Key Verification:** The `Check API Key` node takes the key from the incoming request's header. It then makes an internal HTTP request to a second webhook (`Get API Key`) which acts as a mock database. This second webhook retrieves a list of registered API keys (from the `Registered API Keys` node) and filters it to find a match for the key that was provided. 3. **Conditional Response:** If a match is found, the `API Key Identified` node routes the execution to the success path, returning a `200 OK` response with the identified user's ID. If no match is found, it routes to the unauthorized path, returning a `401 Unauthorized` error. This pattern separates the public-facing endpoint from the data source, which is a good security practice. ## Set up steps **Setup time: ~2 minutes** This workflow is designed to be a self-contained example. 1. **Set up Credentials:** This workflow uses Header Auth for its internal communication. Go to **Credentials** and create a new **Header Auth** credential. You can use any name and value (e.g., Name: `X-N8N-Auth`, Value: `my-secret-password`). Select this credential in all four webhook/HTTP Request nodes. 2. **Add Your API Keys:** Open the **`Registered API Keys`** node. This is your mock database. Edit the array to include the `user_id` and `api_key` pairs you want to authorize. 3. **Activate the workflow.** 4. **Test it:** Use the **`Test Secure Webhook`** node to send a request. Try it with a valid key from your list to see the success response. Change the `x-api-key` header to an invalid key to see the `401 Unauthorized` error. **For Production:** Replace the mock database part of this workflow (the `Get API Key` webhook and `Registered API Keys` node) with a real database node like Supabase, Postgres, or Baserow to look up keys.
How it works
This workflow demonstrates a fundamental pattern for securing a webhook by requiring an API key. It acts as a gatekeeper, checking for a valid key in the request header before allowing the request to proceed.
- Incoming Request: The
Secured Webhooknode receives an incomingPOSTrequest. It expects an API key to be sent in thex-api-keyheader. - API Key Verification: The
Check API Keynode takes the key from the incoming request's header. It then makes an internal HTTP request to a second webhook (Get API Key) which acts as a mock database. This second webhook retrieves a list of registered API keys (from theRegistered API Keysnode) and filters it to find a match for the key that was provided. - Conditional Response: If a match is found, the
API Key Identifiednode routes the execution to the success path, returning a200 OKresponse with the identified user's ID. If no match is found, it routes to the unauthorized path, returning a401 Unauthorizederror.
This pattern separates the public-facing endpoint from the data source, which is a good security practice.
Set up steps
Setup time: ~2 minutes
This workflow is designed to be a self-contained example.
- Set up Credentials: This workflow uses Header Auth for its internal communication. Go to Credentials and create a new Header Auth credential. You can use any name and value (e.g., Name:
X-N8N-Auth, Value:my-secret-password). Select this credential in all four webhook/HTTP Request nodes. - Add Your API Keys: Open the
Registered API Keysnode. This is your mock database. Edit the array to include theuser_idandapi_keypairs you want to authorize. - Activate the workflow.
- Test it: Use the
Test Secure Webhooknode to send a request. Try it with a valid key from your list to see the success response. Change thex-api-keyheader to an invalid key to see the401 Unauthorizederror.
For Production: Replace the mock database part of this workflow (the Get API Key webhook and Registered API Keys node) with a real database node like Supabase, Postgres, or Baserow to look up keys.
New buyers can create an account from the cart to unlock a controlled $10 first-purchase credit on eligible orders of $25+.
Related bundle
n8n Starter Kit
8 hand-picked workflows for $39.00.
That is $4.88 each, vs $9.99 for this one alone.
View bundleSecure checkout powered by Stripe
Support
How to import this workflow into n8n
- 1Purchase or download the workflow to get the n8n workflow JSON file.
- 2In your n8n instance, open Workflows and choose "Import from File" (or paste the JSON with Ctrl+V on the canvas).
- 3Open each node marked with a credential warning and connect your own accounts and API keys.
- 4Run the workflow once manually to verify the data flow, then toggle it to Active.
Related Development & IT workflows
- Create daily historical AI videos with Gemini, fal.ai, Telegram and YouTube$14.99
- Advanced multi-agent AI personal assistant with 250+ task capabilities (WhatsApp + GPT)$2.99
- Send Organized Security CVE Digests from NVD with AI-Polished Summaries to Gmail$4.99
- Learn n8n basics in 3 easy steps ✨$14.99
- Automated multi-platform sales agent with RAG, CRM & payment processing$2.99
- Version Control n8n Workflows in GitLab with Custom and Organization$14.99
More from Lucas Peyrin
Need this deployed? We'll set it up for you.
Our automation experts deploy this workflow in your stack, connect your accounts, and verify it works — or build a custom solution from scratch.