Robust JWT Authentication System using Data Tables and Crypto Nodes - n8n Workflow

Implement a full-featured, secure JWT authentication system (Registration, Login, Refresh, Verification) using n8n Data Tables and Crypto nodes. A powerful n8n workflow for developers.

Workflow Preview

Ready to automate?

Download this n8n workflow template and start using it instantly.

Who is this best for?


  • Backend developers needing a stateless, self-hosted authentication solution.

  • Organizations building secure microservices and APIs within n8n.

  • Users looking for advanced examples of cryptography and flow control within an n8n workflow.

Overview

This comprehensive n8n workflow template provides a production-ready, highly secure JWT (JSON Web Token) authentication system. It covers the full lifecycle: user registration, secure login using password salting and SHA-512 hashing, the issuance of short-lived access tokens and long-lived refresh tokens, and robust token verification and refresh mechanisms. By leveraging n8n's Crypto and Data Table features, this n8n template ensures sensitive data like passwords are never stored in plain text and refresh tokens can be easily revoked, essential for any modern application security model. This highly structured n8n workflow demonstrates complex logic and secure practices.

How it Works

This powerful n8n workflow operates across four distinct flows, all initiated by separate webhook n8n triggers:


  1. Registration: The n8n trigger receives user details. It first validates the uniqueness of the email and username using n8n Data Tables. A unique salt is generated, combined with the password, and hashed using SHA-512. The resulting 'salt:hash' is stored securely in the users Data Table.

  2. Login: The n8n trigger accepts credentials. It retrieves the stored salt and hash for the user. The input password is then hashed with the retrieved salt. The Verify Password n8n node compares the two hashes. If they match, the workflow generates and signs a short-lived Access Token (15 minutes) and a long-lived Refresh Token (7 days) using HMAC-SHA256. The Refresh Token is hashed and stored in the dedicated refreshtokens Data Table before the two tokens are returned.

  3. Token Verification: An external application sends the Access Token to the verification n8n trigger. The n8n workflow parses the JWT, checks its expiration, and uses the defined secret key to re-sign the token header and payload. The Compare Signatures Code n8n node ensures the provided signature matches the expected signature, guaranteeing the token's authenticity and integrity.

  4. Token Refresh: If the Access Token expires, the client sends the Refresh Token. This refresh n8n trigger verifies the Refresh Token's signature and expiration, then uses a hash of the token to perform a fast database lookup against the refreshtokens Data Table. If the session is active, the n8n node creates and signs a brand new Access Token, extending the user's active session without requiring re-login.

Installation Guide

To deploy this secure n8n workflow template, follow these steps:


  1. Import: Copy the provided JSON data and import it into your n8n instance.

  2. Data Table Setup: You must manually create two n8n Data Tables:

users: Columns required are email (string), username (string), and passwordhash (string).
refresh
tokens: Columns required are tokenhash (string), userid (number), and expiresat (dateTime).

  1. Set Secrets: Locate the SET ACCESS AND REFRESH SECRET n8n node (and its duplicates in the Verify and Refresh flows: SET ACCESS AND REFRESH SECRET1 and SET ACCESS AND REFRESH SECRET2). Input long, complex, and distinct strings for ACCESSSECRET and REFRESH_SECRET. Crucially, these secrets must match across all three Set nodes (or ideally, use n8n Variables for global consistency).

  2. Activate Webhooks: Save and activate the n8n workflow to make the /register-user, /login, /verify-token, and /refresh webhook n8n triggers live.

Node Details

Webhook (Registration, Login, Verify, Refresh): Acts as the n8n trigger for the entire system, exposing API endpoints for client applications.
Data Table (Get User, Create User, Upsert/Update Token): Used for persistent storage of user data, performing uniqueness checks (registration), and managing the state and revocation of Refresh Tokens.
Crypto (Generate Salt, Hash Password, Sign Token): The core security component. Used for generating a unique salt, securely hashing passwords using SHA-512, and creating the digital signature for JWTs using HMAC-SHA256.
Code (Extract Salt & Hash, Verify Password, Parse JWT, Create JWT Payload): Custom JavaScript n8n nodes handle complex string manipulation, password hash comparison, JWT decoding, expiration checks, and base64URL encoding/decoding necessary to construct the final JWT strings. This is where token logic resides in the n8n workflow.


  • If/Respond To Webhook: Manages the flow and returns appropriate HTTP status codes (200, 400, 401, 403) based on logic validation (e.g., if password fails verification, if token is expired, or if registration fails uniqueness check).

Related n8n Workflows

Free

Nodes: 10 Nodes
Updated: December 26 2025
View all
Created by
Luka Zivkovic
Luka Zivkovic

Featured*