Authentication
Create, protect and revoke account API keys.
Bearer authentication
Authorization: Bearer YOUR_API_KEYCreate a new key in Settings → API keys. API launch keys use cryptographic randomness, are stored as a digest and are shown only once. List pages cannot recover the original key.
Replace legacy keys
Keys issued before the API launch return 403 api_key_upgrade_required. Create a replacement, update your server, and revoke the old key. Each account allows 10 active keys and creation of 10/hour, 20/day.
Server-side use
Requests carrying an Origin header are rejected. Never place keys in query strings, prompts, frontend code, mobile binaries, logs, repositories or exported workflows. Keep keys in a server secret manager or n8n Credential.
Revocation and task ownership
Revoke exposed keys immediately. Retrying and polling require the original API key. A different key, even under the same account, cannot query that generation through the API. Key revocation does not cancel an already submitted task.