# n8n authentication

Nodurile platformein8nautentifică cu un token de acces OAuth 2.0 creat în interfața de utilizare a platformei și stocat într-o credențialăn8n.

Fiecare cerere de platformăAPIinclude:

```http
Authorization: Bearer <oauth-token>
```

Accesul eficient este intersecția dintre domeniile OAuth ale tokenului și permisiunile actuale ale platformei utilizatorului subiacent.

:::precauție Oricine obține tokenul poate folosi accesul acordat până când expiră sau este revocat. Păstrați-l în stocul de acreditărin8n– nu în câmpurile de flux de lucru, expresii, date de execuție, jurnalele sau configurația exportată :::

## Alegeți platforma de implementare

Serverul și tokenul OAuth trebuie să aparțină aceleiași implementări ale platformei:

  

```text
https://us.probo.com
```

  
  

```text
https://eu.probo.com
```

  
  

```text
https://<your-host>
```

  

Enter the origin only. Do not append `/api`, a GraphQL path, or a trailing
route. The node selects the API path for each operation.

## Create an OAuth token

1. Sign in to the the platform deployment that contains the data.
2. Open your account menu and select **OAuth tokens**.
3. Select **Create token**.
4. Enter a purpose-specific name such as `n8n production – compliance sync`.
5. Choose an expiration and only the scopes required by the workflow.
6. Create and copy the token. the platform displays its value only once.

Creați un token separat pentru fiecare mediun8nToken-urile separate oferă domenii independente, expirare, istoric de audit și limite de revocare.

:::Notă Token-urile create manual în UI sunt token-uri de acces standalone. Acestea nu includ un token de reîmprospătare. Alegeți o expirare care se potrivește cu politica dvs. de rotație și înlocuiți tokenul înainte de expirarea acestuia. :::

## Select scopes

Resource scopes use two forms:

- `v1:<resource>:read` permits read operations for that resource family.
- `v1:<resource>` permits both read and write operations for that family.

For example:

| Workflow capability                 | Scope examples                                            |
| ----------------------------------- | --------------------------------------------------------- |
| Credential test and organizations   | `v1:iam:read` for reads or `v1:iam` for writes            |
| Read or change risks                | `v1:risk:read` or `v1:risk`                               |
| Read or change third parties        | `v1:third-party:read` or `v1:third-party`                 |
| Read or change documents            | `v1:document:read` or `v1:document`                       |
| Read or change tasks                | `v1:task:read` or `v1:task`                               |
| Activate and manage the platform Trigger   | `v1:webhook`                                              |

Other families include `asset`, `audit`, `control`, `privacy`, `access-review`,
`itam`, and `compliance-page`. The scope list shown when creating the token is
authoritative for that deployment.

Testul de acreditaren8nsolicită identitatea autentificată, deci include
`v1:iam:read` or `v1:iam` even when the workflow primarily uses another
resource family. A write scope includes that family's read operations; you do
not need to select both forms.

## Configure the n8n credential

1. **Open a the platform node**

   Adăugați ** platforma** sau ** platforma Trigger** la un flux de lucru.

2. **Create a the platform credential**

   Open **Credential** and select **Create New Credential**. Use a name that
   identifies the deployment and environment, such as `Probo EU – production`.

3. **Setarea serverului și a tokenului OAuth**

   | Field            | Value                                                                                               |
   | ---------------- | --------------------------------------------------------------------------------------------------- |
   | **the platform Server** | `https://us.probo.com`, `https://eu.probo.com`, or the origin of your self-hosted deployment        |
   | **OAuth Token**  | Scoped OAuth token created on that deployment                                                       |

4. **Test the credential**

   Select **Test**. n8n sends a `viewer { id }` query to:

   ```text
   /api/console/v1/graphql
   ```

   Un test de succes dovedește căn8npoate ajunge la implementare și că tokenul include un domeniu de aplicare IAM acceptat de interogarea de identitate.

5. ** Salvați și testați o operațiune de citire**

   Salvați acreditările, apoi rulați **Organizație → Obțineți multe** sau o altă operațiune numai pentru citire înainte de a testa scrierea sau activarea unui declanșator.

## În cazul în care credențialul este utilizat

Toate nodurile platformei pot reutiliza credențialul:

| Node or operation             | Request made with the OAuth token                                                             |
| ----------------------------- | --------------------------------------------------------------------------------------------- |
| Dedicated the platform actions       | Console GraphQL API at `/api/console/v1/graphql`                                               |
| Execute → Console API         | Custom operation at `/api/console/v1/graphql`                                                  |
| Execute → Connect API         | Custom operation at `/api/connect/v1/graphql`                                                  |
| the platform Trigger activation      | Creates, checks, and deletes a webhook subscription through the Console GraphQL API            |
| the platform Trigger event delivery  | Does not send the OAuth token; the platform signs the delivery with the subscription's signing secret |

Actualizarea sau revocarea tokenului OAuth nu invalidează o semnătură webhook deja livrată.

## Authorization model

Testarea acreditărilor nu dovedește că fiecare operațiune a fluxului de lucru este autorizată.

Accesul efectiv este intersecţia dintre:

1. Domeniul de aplicare al resurselor acordat tokenului OAuth.2. apartenența curentă a utilizatorului tokenului în organizația țintă.3. permisiunea utilizatorului pentru citirea, crearea, actualizarea, publicarea, arhivarea, ștergerea sau operațiunea specializată solicitată.

For example, a token can pass the credential test but fail **Risk → Create**
when it has only `v1:risk:read`, or when its user cannot create risks in the
selected organization. the platform Trigger requires both the `v1:webhook` scope and
the user's permission to create and delete webhook subscriptions.

To reduce access:

- Grant only the resource scopes needed by the workflow.
- Prefer `:read` scopes when the workflow does not write.
- Use a the platform user with only the memberships and permissions required by the
  automation.
- Separate workflows with materially different privilege levels into
  different n8n credentials and, where appropriate, different the platform identities.
- Revoke tokens before removing or deactivating the user that created them.

Modificările de permisiune și de membru se aplică solicitărilor ulterioareAPI; tokenul nu păstrează accesul pe care utilizatorul nu îl mai are.

## Expiration, rotation, and revocation

Tokenurile OAuth create de UI au o expirare explicită și niciun token de reîmprospătare.n8nnu le poate extinde sau reîmprospăta.

Rotate without interrupting scheduled workflows:

1. Creați un token de înlocuire OAuth pe aceeași implementare cu domeniile necesare. 2. înlocuiți tokenul în credențialuln8nexistent. 3. testați credențialul și efectuați o operațiune de citire reprezentativă. 4. testați o scriere autorizată într-un mediu sigur atunci când fluxul de lucru scrie date. 5. confirmați că fluxurile de lucru activ pot verifica în continuare abonamentele lor. 6. revocați vechiul token sub **OAuth tokens**.

Revocați un token imediat când este expus, fluxul său de lucru este retras sau utilizatorul său nu ar trebui să mai fie reprezentat de automatizare. Revocarea nu este o pauză: solicitările care utilizează acel token opresc autentificarea și nu poate fi restaurată.

## Self-hosted connectivity

Pentru o implementare auto-gazdă a platformei, utilizați originea accesibilă din fiecare procesn8ncare execută un nod al platformei, de exemplu
`https://probo.internal.example.com`. The n8n main process and workers must:

- Resolve the hostname.
- Reach the server through applicable network and firewall rules.
- Trust the server's TLS certificate chain.
- Preserve the `Authorization` header through any reverse proxy.

The credential test targets:

```text
https://probo.internal.example.com/api/console/v1/graphql
```

platforma Trigger necesită conectivitate bidirecțională.n8ntrebuie să ajungă la platformă pentru a gestiona abonamentul, în timp ce platforma trebuie să ajungă la URL-ul webhook de producție aln8nprin HTTPS pentru a livra evenimente.

## Diagnose authentication failures

| Symptom                                      | Likely cause                                                                                                               |
| -------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| Credential test cannot connect               | Invalid server origin, DNS failure, untrusted TLS certificate, proxy, or firewall                                          |
| Credential test reports authentication error | Malformed, expired, revoked, or wrong-deployment token                                                                     |
| Credential test reports insufficient scope   | Token is missing `v1:iam:read` or `v1:iam`                                                                                 |
| Test passes but an operation is forbidden    | Missing resource scope, organization membership, or user permission                                                        |
| Resource is not found                        | Wrong resource ID, wrong organization, or a resource hidden by the authorization boundary                                  |
| Execute works for Console but not Connect    | The operation is absent from that API or the token does not authorize it                                                    |
| Trigger activation fails                     | Missing `v1:webhook`, missing user permission, incorrect organization ID, or invalid n8n production webhook configuration   |

Modificarea formatării purtătorului nu corectează un eșec de autorizare după ce testul de acreditare a reușit. Verificați implementarea selectată, expirarea tokenului, domeniile acordate, organizația și permisiunile curente ale utilizatorului.