What it does
This n8n workflow shows how to protect a webhook with an API key. The incoming request must send the key in the x-api-key header, and a separate workflow checks it against a list of registered keys. A valid key gets a 200 response with the user ID, and anything else gets a 401.
Use cases
- 01Guard a public webhook with per-user keys
- 02Return 401 to requests without a valid key
- 03Separate the public endpoint from the key store
Connects
HTTP Request