nodevstack

How to back up a self-hosted n8n

Self-hosting n8n is cheap and powerful — right up until a server dies and your workflows and credentials go with it. Backups are the boring step that makes self-hosting safe. Here's exactly what to back up, the one piece almost everyone forgets, and copy-paste commands to automate it.

New to self-hosting n8n? Start with self-hosting n8n on Contabo, then come back here.

What actually needs backing up

  1. 1. The database. Your workflows, credentials and execution history live here — PostgreSQL if you set it up properly, or a SQLite file (database.sqlite in the data folder) on a default install.
  2. 2. The encryption key. n8n encrypts every stored credential with a key kept in ~/.n8n/config (or set via N8N_ENCRYPTION_KEY). This is the piece people forget — see the warning below.
  3. 3. The data folder. /home/node/.n8n holds the config, the key and (on SQLite) the database — backing up the whole volume covers a lot in one move.

The mistake that ruins restores

If you back up the database but not the encryption key, your restored n8n will load every workflow — and every credential will fail to decrypt. Fix it once: pin the key as an environment variable so it's known and identical across every instance.

# In your docker-compose environment — pin the key so backups
# and restores always use the same one.
- N8N_ENCRYPTION_KEY=a-long-random-string-you-keep-safe

Method 1 — a daily Postgres dump (recommended)

If you run n8n with PostgreSQL (the production choice), a nightly pg_dump is the core of your backup. This script keeps 14 days and deletes older ones:

#!/bin/bash
# /opt/n8n/backup.sh — daily Postgres dump, keep 14 days
set -e
DIR=/opt/n8n/backups
mkdir -p "$DIR"
STAMP=$(date +%F)
docker compose -f /opt/n8n/docker-compose.yml exec -T db \
  pg_dump -U n8n n8n | gzip > "$DIR/n8n-$STAMP.sql.gz"
find "$DIR" -name 'n8n-*.sql.gz' -mtime +14 -delete

Make it executable and schedule it with cron:

# crontab -e  → run every day at 03:30
30 3 * * * /opt/n8n/backup.sh >> /var/log/n8n-backup.log 2>&1

Method 2 — portable JSON export (belt and braces)

n8n's CLI can export every workflow (and your credentials, kept encrypted) to JSON. It's human-readable, easy to version in git, and portable between instances — a great extra alongside the database dump, not a replacement for it:

# Portable JSON export of every workflow (and credentials, kept encrypted)
docker compose exec n8n n8n export:workflow --all --output=/home/node/.n8n/backup-workflows.json
docker compose exec n8n n8n export:credentials --all --output=/home/node/.n8n/backup-credentials.json

Leave credentials encrypted (the default). There's a --decrypted flag that dumps them in plain text — don't use it for backups, it's a secrets leak waiting to happen.

Get a copy off the server

A backup that lives only on the box it's protecting isn't a backup. Push the nightly dumps somewhere else — object storage (S3-compatible), another server via rsync, or your VPS provider's snapshots. If you host on Contabo, its snapshots and auto-backup add-on give you a whole-disk restore point in a couple of clicks, which pairs well with the file-level dumps above. Aim for 3-2-1: three copies, two kinds of media, one off-site.

Restoring

Stand up a fresh n8n with the same N8N_ENCRYPTION_KEY, then load the dump into its database:

# Restore a Postgres dump into a fresh n8n (same N8N_ENCRYPTION_KEY!)
gunzip -c n8n-2026-08-24.sql.gz | \
  docker compose exec -T db psql -U n8n -d n8n

Then the golden rule: test the restore before you need it. A backup you've never restored is a guess. Spin up a throwaway instance once, restore into it, and confirm a credential actually connects.

Frequently asked

What do I actually need to back up in n8n?

Three things: the database (your workflows, credentials and execution history — Postgres or the SQLite file), the encryption key that n8n uses to encrypt stored credentials, and ideally the whole n8n data folder. The encryption key is the one people forget — without it, a restored database still can't decrypt your saved credentials.

Why do my credentials break after restoring a backup?

Because the encryption key didn't come with them. n8n encrypts every stored credential with a key kept in ~/.n8n/config (or set via N8N_ENCRYPTION_KEY). Restore the database onto an n8n instance with a different key and the credentials are unreadable. Pin N8N_ENCRYPTION_KEY to a known value in your environment so every backup and restore uses the same key.

Can I just back up the workflows as JSON?

You can, and it's a great portable extra — n8n's CLI exports every workflow to JSON. But JSON export alone doesn't capture execution history and, unless you export credentials separately (kept encrypted), it isn't a full restore. Use it alongside a database dump, not instead of one.

How often should I back up?

Daily is a sensible default for a personal or small-team instance, kept for 7–14 days, with at least one copy off the server (object storage, another machine, or a provider snapshot). Follow 3-2-1: three copies, two media, one off-site.

Related

Prefer managed? Try n8n Cloud →Get a Contabo VPS →

Some links here are affiliate links — we earn a commission on n8n and Contabo, at no extra cost to you. See our Affiliate Disclosure.