We're on Product Hunt today! Leave a comment

n8n authenticator app

n8n two-factor authentication works with any authenticator app, including one in your browser — on n8n Cloud and self-hosted alike. Open Settings → Personal, select “Enable 2FA”, and scan the QR code from the screen with the Authenticator extension.

An n8n login opens every workflow on the instance and the credentials they run with — API keys, OAuth connections, database passwords for everything you have automated. Whoever signs in with your password can read them, change what the workflows do or point them somewhere else. With 2FA on, n8n also asks for the code from your authenticator, so a leaked password alone is not enough.

Turn on two-factor authentication in n8n

2FA is set up per n8n instance: if you use several — a Cloud workspace and your own server, say — turn it on in each. It applies to signing in with email and password; if you sign in through your company’s single sign-on (SAML or OIDC), the second step is up to that login instead. On a self-hosted instance, an admin can turn 2FA off for everyone with N8N_MFA_ENABLED=false, but n8n ignores that while any user has 2FA on.

  1. Sign in to your n8n instance — your n8n Cloud workspace or your self-hosted n8n — in Chrome on your computer.
  2. Go to “Settings” → “Personal”.
  3. Select “Enable 2FA”.
  4. When n8n shows a QR code, leave that window open and add it to the extension as described below — then enter the code from the extension in “Code from authenticator app” and select “Continue”.
n8n’s own instructions

Add n8n to Authenticator

  1. Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
  2. Leave the n8n page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
  3. The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
  4. Go back to n8n and type the current code into the confirmation field. If it is about to expire, wait for the next one.
  5. n8n confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.

No QR code, or it will not scan? Look for the option to enter a key manually on n8n’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.

Get 2FA Authenticator for Chrome — free

Save your n8n recovery codes

After you select “Continue”, n8n displays your recovery codes. Save them somewhere other than this computer — they are what gets you back into the account if you lose your authenticator. n8n’s docs do not say how many there are or how to see them again, so save the whole list the moment it appears.

The code is not accepted?

Most often the QR code changed: the website makes a new one each time its setup page is reloaded or opened again, so the account you added first no longer matches. Start the setup again, add the QR code that is on the screen now and type its code in straight away. Two entries for the same website? Use the newest. Other reasons: why codes are refused.

Typed the key in by hand? Paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.

Questions

Can I use n8n 2FA without a phone?
Yes. n8n’s docs mention an app on your phone, but all n8n checks is the code, and any standard authenticator produces it. The Authenticator extension reads the QR code straight off the n8n settings and generates the codes in Chrome.
Can an admin make 2FA mandatory in n8n?
Yes, on n8n Cloud Enterprise and on self-hosted Business and Enterprise plans: Settings → Security → “Enforce two-factor authentication”. Everyone who signs in with email and password must then set up 2FA before continuing — those who have not are prompted at their next sign-in. Users signing in through SAML or OIDC single sign-on are not affected.
What if I lose access to my authenticator?
Sign in with one of your recovery codes, then set 2FA up again. On a self-hosted instance, if the codes are gone too, an admin with access to the server can run n8n mfa:disable --email=you@example.com, with your email address, and you set 2FA up again at your next sign-in. On n8n Cloud there is no such command for you to run — contact n8n support.
Why does n8n say my code is wrong?
Usually the QR code changed: if the 2FA window was closed or opened again, n8n made a new one, and the account you added first no longer matches. Add the QR code that is on the screen now and type its code in straight away. If you have two entries for the same n8n instance, use the newest.

Your codes, one click from the login page

Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.

Get 2FA Authenticator for Chrome — free