n8n is a workflow automation tool. You connect apps, databases and APIs on a visual canvas, and n8n runs the workflow when something happens: a form is submitted, an invoice is paid, a row is added to a sheet, or a clock reaches 8:00 on Monday.
You can use n8n as a hosted service, or run it on a server of your own. This post covers why a business might choose to self-host, what you need to run it properly, and the security basics that keep it from becoming a liability.
Why run n8n on your own server
Your data stays on a server you control
Automations touch sensitive data by design: customer records, orders, invoices, support tickets. When n8n runs on your own server, that data passes through a machine you control, in a location you chose, and the credentials for every connected app are stored there too.
Predictable costs as you grow
Self-hosted, your main cost is the server. A workflow that runs every five minutes costs the same as one that runs once a day, as long as the server has the resources for it. That makes it easier to automate small, frequent jobs you would otherwise not bother with.
Freedom to extend it
On your own server you can install community nodes, reach internal systems that are not on the public internet, and run workflows next to the databases and apps they talk to.
Check the license for your use
The self-hosted community edition of n8n is published under n8n’s Sustainable Use License, which covers running it for your own business’s internal automations. If you plan to offer n8n to your customers as a service, read the license terms first.
What you need to run it properly
Getting n8n to start is quick. Running it as something your business depends on takes a few more pieces.
A server
A small Linux VPS is enough to start. n8n usually runs in Docker, which makes updates and moves simple. Plan for more memory if your workflows handle large files or process thousands of items at a time.
A domain or subdomain
Give n8n its own address, such as n8n.yourbusiness.com. Create an A record for that subdomain pointing at your server’s IP address. A stable address matters because webhook URLs, the links other apps call to start your workflows, are built from it. Tell n8n its public address with the WEBHOOK_URL environment variable, along with N8N_HOST and N8N_PROTOCOL=https.
SSL
n8n listens on port 5678 by default, over plain HTTP. Do not expose that port to the internet. Put a reverse proxy such as Nginx, Caddy or Traefik in front of it, serve the site on port 443 with a free Let’s Encrypt certificate, and forward traffic to n8n on the server itself. Make sure the proxy passes WebSocket connections, because the n8n editor uses them.
A real database
Out of the box n8n stores everything in SQLite. That is fine for trying it out. For business use, n8n also supports PostgreSQL, which handles many workflows running at once better and is easier to back up while it runs.
Backups, including the encryption key
n8n encrypts the credentials you save (API keys, passwords, tokens) with an encryption key. If you lose that key, a restored database is useless: every credential has to be entered again by hand.
- Set
N8N_ENCRYPTION_KEYyourself and store a copy somewhere safe, away from the server. - Back up the database every day, and keep copies off the server.
- Back up the n8n data folder, which holds settings and any files your workflows write.
- Export important workflows to JSON now and then, or keep them in Git.
- Test a restore on a spare server before you need it.
SMTP for sending mail
Most business automations send email: order confirmations, alerts, weekly reports, “a new lead just arrived” messages. n8n needs an SMTP account for two separate jobs.
- n8n’s own mail. Invitations and password resets for your team. Set
N8N_EMAIL_MODE=smtpand fill inN8N_SMTP_HOST,N8N_SMTP_PORT,N8N_SMTP_USER,N8N_SMTP_PASSandN8N_SMTP_SENDER. - Your workflows’ mail. The Send Email node uses an SMTP credential you create inside n8n.
Use a real mailbox on your own domain, so mail arrives from an address your customers recognize and passes SPF, DKIM and DMARC. Connect on port 587 with STARTTLS, or port 465 with SSL. Our guide lists the SMTP, IMAP and POP3 details for CloudWish mailboxes.
Keep volumes in mind. A CloudWish mailbox can send up to 300 messages an hour, which suits alerts, confirmations and internal reports. Business email is not the place for newsletters or cold outreach from a workflow; those belong on a dedicated email marketing platform.
Security basics
An n8n server holds the keys to every app it connects to. Treat it like one.
Lock down the server
- Allow only ports 22, 80 and 443 through the firewall. Keep 5678 closed to the outside.
- Sign in over SSH with keys, not passwords, and disable root password login.
- Turn on automatic security updates for the operating system.
Lock down n8n
- Create the owner account as soon as n8n starts. Until you do, anyone who reaches the address can claim it.
- Ask every user to turn on two-factor authentication.
- Invite colleagues as members, not owners, unless they need full control.
- Keep n8n updated. Read the release notes before major version jumps, and back up first.
Protect your webhooks
A webhook URL is a door into your workflows. Add authentication on the Webhook node (a header token or basic auth), check incoming data before acting on it, and never let a public webhook trigger something expensive or destructive without a check.
Limit what credentials can do
Give each connected app the narrowest access that works: a read-only database user for reporting workflows, an API key scoped to one project, a separate mailbox for automated mail. If a credential leaks, the damage stays small.
Keep execution data under control
n8n saves data from each workflow run, and that can include customer details. Turn on pruning with EXECUTIONS_DATA_PRUNE=true and set EXECUTIONS_DATA_MAX_AGE to how many hours you need to keep it. This also stops the database growing without limit.
A quick checklist
| Item | Done when |
|---|---|
| Subdomain | n8n.yourbusiness.com points at the server |
| SSL | The editor loads over https with a valid certificate |
| Webhook URL | Webhook nodes show your https address, not localhost |
| Database | PostgreSQL, backed up daily off the server |
| Encryption key | Set by you and stored safely |
| SMTP | A test email arrives from your own domain |
| Access | Owner account created, 2FA on, port 5678 closed |
| Pruning | Old execution data is deleted on a schedule |
Or let us set it up for you
VPS with one-click apps from CloudWish is in early access, and n8n is one of the first apps ready at launch. We create the server, install n8n, point your subdomain at it and switch on SSL and daily backups. Your workflows send mail from your CloudWish business mailbox, and you keep full root access to change anything you like.