Self-hosting n8n for business automations: what you need and how to secure it

in Blog

n8n is a workflow automation tool. You connect apps, databases and APIs on a visual canvas, and n8n runs the workflow when something happens: a form is submitted, an invoice is paid, a row is added to a sheet, or a clock reaches 8:00 on Monday.

You can use n8n as a hosted service, or run it on a server of your own. This post covers why a business might choose to self-host, what you need to run it properly, and the security basics that keep it from becoming a liability.

Why run n8n on your own server

Your data stays on a server you control

Automations touch sensitive data by design: customer records, orders, invoices, support tickets. When n8n runs on your own server, that data passes through a machine you control, in a location you chose, and the credentials for every connected app are stored there too.

Predictable costs as you grow

Self-hosted, your main cost is the server. A workflow that runs every five minutes costs the same as one that runs once a day, as long as the server has the resources for it. That makes it easier to automate small, frequent jobs you would otherwise not bother with.

Freedom to extend it

On your own server you can install community nodes, reach internal systems that are not on the public internet, and run workflows next to the databases and apps they talk to.

Check the license for your use

The self-hosted community edition of n8n is published under n8n’s Sustainable Use License, which covers running it for your own business’s internal automations. If you plan to offer n8n to your customers as a service, read the license terms first.

What you need to run it properly

Getting n8n to start is quick. Running it as something your business depends on takes a few more pieces.

A server

A small Linux VPS is enough to start. n8n usually runs in Docker, which makes updates and moves simple. Plan for more memory if your workflows handle large files or process thousands of items at a time.

A domain or subdomain

Give n8n its own address, such as n8n.yourbusiness.com. Create an A record for that subdomain pointing at your server’s IP address. A stable address matters because webhook URLs, the links other apps call to start your workflows, are built from it. Tell n8n its public address with the WEBHOOK_URL environment variable, along with N8N_HOST and N8N_PROTOCOL=https.

SSL

n8n listens on port 5678 by default, over plain HTTP. Do not expose that port to the internet. Put a reverse proxy such as Nginx, Caddy or Traefik in front of it, serve the site on port 443 with a free Let’s Encrypt certificate, and forward traffic to n8n on the server itself. Make sure the proxy passes WebSocket connections, because the n8n editor uses them.

A real database

Out of the box n8n stores everything in SQLite. That is fine for trying it out. For business use, n8n also supports PostgreSQL, which handles many workflows running at once better and is easier to back up while it runs.

Backups, including the encryption key

n8n encrypts the credentials you save (API keys, passwords, tokens) with an encryption key. If you lose that key, a restored database is useless: every credential has to be entered again by hand.

  • Set N8N_ENCRYPTION_KEY yourself and store a copy somewhere safe, away from the server.
  • Back up the database every day, and keep copies off the server.
  • Back up the n8n data folder, which holds settings and any files your workflows write.
  • Export important workflows to JSON now and then, or keep them in Git.
  • Test a restore on a spare server before you need it.

SMTP for sending mail

Most business automations send email: order confirmations, alerts, weekly reports, “a new lead just arrived” messages. n8n needs an SMTP account for two separate jobs.

  1. n8n’s own mail. Invitations and password resets for your team. Set N8N_EMAIL_MODE=smtp and fill in N8N_SMTP_HOST, N8N_SMTP_PORT, N8N_SMTP_USER, N8N_SMTP_PASS and N8N_SMTP_SENDER.
  2. Your workflows’ mail. The Send Email node uses an SMTP credential you create inside n8n.

Use a real mailbox on your own domain, so mail arrives from an address your customers recognize and passes SPF, DKIM and DMARC. Connect on port 587 with STARTTLS, or port 465 with SSL. Our guide lists the SMTP, IMAP and POP3 details for CloudWish mailboxes.

Keep volumes in mind. A CloudWish mailbox can send up to 300 messages an hour, which suits alerts, confirmations and internal reports. Business email is not the place for newsletters or cold outreach from a workflow; those belong on a dedicated email marketing platform.

Security basics

An n8n server holds the keys to every app it connects to. Treat it like one.

Lock down the server

  • Allow only ports 22, 80 and 443 through the firewall. Keep 5678 closed to the outside.
  • Sign in over SSH with keys, not passwords, and disable root password login.
  • Turn on automatic security updates for the operating system.

Lock down n8n

  • Create the owner account as soon as n8n starts. Until you do, anyone who reaches the address can claim it.
  • Ask every user to turn on two-factor authentication.
  • Invite colleagues as members, not owners, unless they need full control.
  • Keep n8n updated. Read the release notes before major version jumps, and back up first.

Protect your webhooks

A webhook URL is a door into your workflows. Add authentication on the Webhook node (a header token or basic auth), check incoming data before acting on it, and never let a public webhook trigger something expensive or destructive without a check.

Limit what credentials can do

Give each connected app the narrowest access that works: a read-only database user for reporting workflows, an API key scoped to one project, a separate mailbox for automated mail. If a credential leaks, the damage stays small.

Keep execution data under control

n8n saves data from each workflow run, and that can include customer details. Turn on pruning with EXECUTIONS_DATA_PRUNE=true and set EXECUTIONS_DATA_MAX_AGE to how many hours you need to keep it. This also stops the database growing without limit.

A quick checklist

Item Done when
Subdomain n8n.yourbusiness.com points at the server
SSL The editor loads over https with a valid certificate
Webhook URL Webhook nodes show your https address, not localhost
Database PostgreSQL, backed up daily off the server
Encryption key Set by you and stored safely
SMTP A test email arrives from your own domain
Access Owner account created, 2FA on, port 5678 closed
Pruning Old execution data is deleted on a schedule

Or let us set it up for you

VPS with one-click apps from CloudWish is in early access, and n8n is one of the first apps ready at launch. We create the server, install n8n, point your subdomain at it and switch on SSL and daily backups. Your workflows send mail from your CloudWish business mailbox, and you keep full root access to change anything you like.

See n8n on CloudWish and join early access

Start with email. Add the rest when you need it.