How production workflows in n8n, Make, and AI Agents protect sensitive credentials from leaks, logging dumps, and downtime.
Hardcoding a password or API key directly inside an n8n node or Make webhook is like gluing your house key to the front door. Anyone who exports the workflow JSON or views execution history sees it in plaintext.
When replacing an old key, don't just delete it. Services support two active keys simultaneously: generate Key B, update your workflow credentials, verify production runs successfully, and only then revoke Key A.
When building AI agent workflows, never hand the LLM your master database admin key. Issue dedicated, scoped sub-keys that can only perform the exact action needed (e.g. read-only, or 10 requests/min rate limit).
EXECUTIONS_DATA_PRUNE=true) to ensure customer payloads and Authorization headers don't sit in local SQLite/Postgres databases forever.
X-Webhook-Token) or HMAC signature validation before processing the payload.