n8n Workflow Export and Import: Handling Credentials at Delivery
・ Employee Store Operations

Summary
You can export an n8n workflow as a JSON file and import it into another n8n instance. However, the exported JSON may still contain credential names and similar details. This article explains the export and import steps and what to check before handing a workflow to someone else.
When you hand over an n8n workflow you built, you start by exporting it. The recipient then imports that file to use it. The steps are short, but if you handle credentials incorrectly, you can end up sharing information you should not.
The steps in this article were checked against the official n8n documentation on October 2, 2026. Screens and commands may change. Before using them, check the latest content through the sources at the end.
Workflows can be exported as JSON
According to the official n8n documentation, n8n stores workflows in JSON format. You can export a workflow as a JSON file and import a JSON file into n8n.
There are several ways to export and import.
- From the editor: download as a file, or import from a file or URL
- Copy and paste: select nodes, copy them, and paste them into another editor
- Command line: bundle into a package with the n8n CLI, or export with the server CLI
- n8n API: work with JSON through the workflow endpoints
If you only need to hand over one workflow, exporting from the editor is enough. To move several workflows or folders at once, use the command line.
Export steps
Export from the editor
- Open the workflow you want to export
- Open the three-dot menu at the top right of the screen
- Select “Download”. The workflow is saved to your computer as a JSON file
To hand over only some nodes, select them, copy with Ctrl + c (cmd + c on Mac), and paste into the recipient's editor with Ctrl + v (cmd + v on Mac).
Export from the command line
If you run n8n on your own server, you can export with the server CLI. For example, n8n export:workflow --id=<ID> --output=file.json exports the specified workflow to a single file. Adding --published exports the published version instead of the draft being edited. Passing a version ID to --version exports a specific past version. At delivery, export the version you tested with the client, so that what you deliver matches what was tested.
n8n recommends the n8n CLI for migrating between instances. The n8n CLI bundles workflows and the folders and references they need into a package in the .n8np format. The documentation says packages are in Preview and may change.
Import steps
- In the target n8n, open a new workflow
- Open the three-dot menu at the top right of the screen
- Choose the JSON file with “Import from File”. For JSON at a URL, choose “Import from URL”
- Set up credentials again in each node of the imported workflow
- Run it with test data and check the results before publishing
Import from URL is useful for importing workflow JSON hosted on GitHub or similar sites. When you try a public workflow, check its contents after importing and before setting up credentials.
Import from the command line
On your own server, you can import with n8n import:workflow --input=file.json. If you pass --separate and a folder to --input, all JSON files in the folder are imported together. By default, all imported workflows are deactivated.
The official documentation warns that exported files also include workflow and credential IDs. If the target already has a workflow or credential with the same ID, it is overwritten. To avoid this, remove or change the IDs before importing. If the client will import into their n8n, note this in the instructions.
Setup after importing
An n8n JSON import is done once you choose the file. The real work is setting up credentials afterward. When importing a package, n8n matches credentials against those in the target. If none is found, by default it creates an empty credential. Workflows that use empty credentials are not published, so fill them in before publishing.
How credentials are handled
The official documentation explains that exported workflow JSON files include credential names and IDs. IDs are not sensitive, but names can be, depending on how you name them. HTTP Request nodes imported from cURL may also contain authentication headers. The documentation asks you to remove or redact these before sharing.
What the JSON contains
- Nodes and their settings
- Credential names and IDs
- Auth headers in nodes imported from cURL
What to do before handing over
- Check credential names for company or personal names
- Remove headers from HTTP Request nodes
- Let the buyer set up API keys themselves
Credentials themselves are exported with a separate command (n8n export:credentials). Adding --decrypted exports them in plain text, and the official documentation warns that all sensitive information is then visible in the file. You do not need to export and hand over your own credentials when delivering a workflow. n8n CLI packages also do not include credential data.
Credentials also have a setting that limits which domains HTTP Request nodes can send to. When the buyer sets them up, explaining in the instructions how to limit them to the domains of the services in use prevents the credentials from being used for other destinations.
Sharing within the same n8n
You can also share within the same n8n instead of handing over a file. Workflow sharing is available on all n8n Cloud plans, and on Business and Enterprise for self-hosted n8n. Editors it is shared with can use all credentials that the workflow uses. If you are invited into the client's n8n, for example, check this point before sharing.
Instructions to include with the deliverable
If you hand over only the JSON file, the recipient will not know how to run it. Include instructions that cover the following.
- The workflow's purpose and the flow from input to output
- The type of n8n used to build it (cloud or self-hosted) and its version
- The types of credentials needed and how to issue each
- Nodes to reconfigure and the fields to change (destination addresses, sheet names and so on)
- If it starts with a Webhook, how to replace the URL
- If it uses an error workflow for alerts, how to set it up
- Test data for checking it works, and the expected results
Also write the name of the delivered workflow and the export date in the instructions. When you later deliver a fixed version, the client can tell which version they are using.
Writing instructions overlaps with writing a listing page description. See also How to write an AI agent description. The terms for delivering n8n workflows for a fee are covered in n8n commercial use, and connecting to other services in n8n integrations.
Deliver through the Employee Store delivery box
When an AI listed on Employee Store is hired, the seller is notified. The seller delivers the JSON file and instructions through the delivery box for that transaction. Delivery is due within 3 business days in principle, and the buyer is refunded if it is late.
- 1Export the JSON
- 2Check credential names and headers
- 3Add instructions
- 4Deliver via the delivery boxIn principle within 3 business days
- 5Buyer imports and sets up
- 6Receipt confirmed
The buyer checks the deliverable in the transaction room and confirms receipt. If anything about setup is unclear, the parties can exchange messages in the transaction room. Do not send API keys or passwords by message. Instead, guide the buyer through issuing and setting them up themselves. For the full flow, see How to use Employee Store.
FAQ
- If I move an n8n workflow to another n8n, do the credentials move with it?
- Workflow JSON includes credential names and IDs, but you need to set up credentials again in the target. n8n CLI packages also do not include credential data, and an empty credential is created if none is found.
- Can I publish exported JSON as is?
- Before publishing, check credential names and the headers in HTTP Request nodes. The official n8n documentation asks you to remove or redact these before sharing.
- Can I import a workflow built on n8n Cloud into a self-hosted n8n?
- You import a JSON file exported from the editor using “Import from File” in the other n8n. Check that the nodes you use also exist in the target, then set up credentials and test after importing.


