Backing up n8n: workflows, credentials and the encryption key

An n8n backup you can restore holds three things: the data (workflows, executions, credentials), the encryption key (N8N_ENCRYPTION_KEY) and the compose file with its variables. Miss one and the restore is incomplete. The key is the one most people forget: without it, restored credentials cannot be read.

What to keep, and where it is

What Where it is How to keep it
n8n data In the persistent volume of the compose file (the n8n data folder). Copy the folder with n8n stopped, or include the volume in a VPS backup.
Encryption key In the N8N_ENCRYPTION_KEY variable of the compose file (or in the n8n configuration, if you never set it). In a password manager, off the server.
Compose file and variables In the folder where you wrote it. Copy the whole folder.
Database, if you use PostgreSQL In the compose database service. A dump of the database: backing up with mysqldump and pg_dump.

If you never set the key, n8n made one and stored it in the data folder: in that case a copy of the folder already carries it, but copy it out anyway and start setting it in the compose file, as in installing n8n with Docker Compose.

A simple backup

1 Stop n8n for a moment with docker compose stop. While it is writing, a copy of the folder can come out half-done.
2 Copy the data folder and the compose folder into a compressed file with the date in its name.
3 Start it again with docker compose start.
4 Take the copy off the VPS. A backup stored on the machine that fails is not a backup. See backing up a VPS: snapshots or files.
5 Automate it with a cron job, as in automatic backups of your own application.

Besides copying the folder, n8n has command-line instructions to export workflows and credentials to files. They are useful for keeping workflows as readable files and for moving them between installations. Check the exact options with the command’s help in your version and in the official documentation. By default the exported credentials stay encrypted with the key.

Restoring, and proving it works

1 On a clean VPS (or a clean directory), put the compose file and the data folder back.
2 Make sure N8N_ENCRYPTION_KEY is the same, exactly.
3 Start with docker compose up -d and open n8n: the workflows should be there, and one credential should work in a test.
A backup you never restored is a hope, not a backup. Rehearse the restore before you need it, and repeat now and then. The method is in making and keeping your own backup, and testing that it works.
Take a backup before every n8n update. See updating n8n safely.

Need help with the VPS itself (snapshots, disk, access)? Open a ticket.

Open a support ticket

SEE ALSO

Updating n8n safely

Backing up a VPS: snapshots or files

Making and keeping your own backup, and testing that it works

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $6.60/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?