Developers
API tokens
An API token authenticates the REST API and the MCP server. It acts as you, inside one workspace. Treat it like a password.
Format
A token is fb_ followed by 32 alphanumeric characters — 35 in total. Send it as a bearer token:
Authorization: Bearer fb_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxThe same header works for the API and the MCP server. Only a SHA-256 hash is stored, so a lost token cannot be recovered — create a new one.
Limits
10 tokens per person per workspace. Access tokens issued when you connect an OAuth app (
fbo_…) sit on the same page but do not count.Expires 30 days after creation. There is no extend button — create a new token and delete the old one.
One workspace. A token is bound to the workspace it was created in. A call that names another workspace, or a form in one, fails with
FORBIDDEN, even when you are a member of both.No scopes. A token does everything you can do in that workspace. There is no read-only token.
Every plan has API access
Creating and using tokens is not gated by plan. Individual calls still are — scheduling request reminders needs Pro or Business, for
example, and answers with UPGRADE_REQUIRED otherwise.
Create a token
- 1
Open OAuth and API Keys
In the sidebar, under your workspace. Tokens live in the API Keys card.
- 2
Click Create token
Name it in the Create API token dialog — "CI/CD Pipeline", "n8n production".
- 3
Copy it now
The API token created dialog shows the value once. Copy & Close, and the value is gone for good.
- 4
Store it in your secrets manager
Never commit it, and never ship it to a browser.
The list then shows the name, the first 11 characters, when it was created, and when it expires. An expired token is marked Expired and stops authenticating.
Rotate a token
- 1
Create the replacement
Give it a name that says which generation it is, like "n8n production v2".
- 2
Roll it out
Update every consumer. Both tokens work while you switch.
- 3
Delete the old one
Use the trash icon on its row and confirm in Delete API token?.
Revoke a token
Deleting a token removes it permanently and it stops working on the next call — there is no grace period, and anything still using it
starts getting 401 UNAUTHORIZED. You can also rename a token with the pencil icon (up to 64 characters); renaming does not
change its value.
Only you see your own tokens — workspace admins cannot list or delete them. Leaving the workspace, or being removed from it, deletes them for you.
A token is full access
Anyone holding it can act as you inside that workspace. If one leaks, delete it first and investigate second.
OAuth instead
A third-party app connecting on behalf of a user should use the OAuth flow instead of asking for a token. It gets an fbo_…
access token, valid one hour and refreshable for 30 days, bound to the one workspace the user picked at consent. The user sees and
disconnects those apps in Connected apps on the same page. See MCP server.