Sealed before it leaves your device
Secrets are encrypted end-to-end: your browser seals a value before it travels, and the server only ever stores ciphertext it cannot read.
N4N VAULT · GATE 25
n4n Vault keeps your team’s shared passwords, API keys and credentials sealed end-to-end — access granted per team, every reveal written to an audit trail. The keys to everything else, finally out of chat threads and spreadsheets.
SEALED SPECIMEN · GATE 25
Paste a credential and it is encrypted on your device before it travels — the server never holds anything it can read. Getting the value back takes a grant, and taking it leaves a mark.
engineering / production
4 secrets · 2 teams granted
illustrative collection · names and values are sample data
CAPABILITIES · GATE 25
A password manager stops at the login screen. Vault is built for a team’s whole credential surface — the database strings, deploy keys and processor keys the rest of the fleet runs on.
Secrets are encrypted end-to-end: your browser seals a value before it travels, and the server only ever stores ciphertext it cannot read.
Passwords, API keys, SSH keys, database strings and one-time codes each get structured fields — no more credentials pasted into a doc titled "misc".
Access follows collections: engineering sees deploy keys, finance sees processor keys. Nobody DMs a password again.
Every reveal writes who, when, from where and a purpose note to an append-only audit trail you can filter by secret or by person.
Time-box a grant for a contractor or an incident. When the clock runs out, the access revokes itself — no calendar reminder required.
Every secret carries its age. Set a rotation window, get flagged when one goes stale, and keep the full history of who rotated what, when.
ROUTE MAP · CONNECTIONS
Vault holds the keys the fleet runs on — People decides who gets them, Flow and Web use them without ever seeing them.
n4n People
gate 21 · scheduled
n4n Vault
gate 25 · this page
n4n Flow
gate 24 · scheduled
n4n Web
gate 28 · scheduled
PEOPLE → VAULT
Grants follow team membership in People — offboard someone and every collection they could open is closed the same minute.
VAULT → FLOW
Flow steps fetch credentials from Vault at run time, so a secret never lives inside an automation definition.
VAULT → WEB
Sites in Web reference integration keys by name — rotate the key in Vault and every site picks it up without a redeploy.
A DAY AT GATE 25
local time · illustrative
Not yet — n4n Vault is scheduled on the fleet board. Email support@n4n.io and we will tell you the moment it boards. The fleet’s first departure, n4n AI, is live today at n4n.ai.
A secret is encrypted on your device before it is stored, and decrypted on the device of someone with a grant when it is revealed. The server holds ciphertext it cannot decrypt — an operator with database access sees dots, not passwords.
Only people with a grant on its collection. Grants are made per team, so access follows the org chart rather than a chat thread — and every reveal is recorded with who, when, from where and why.
Offboarding in People revokes their grants the same minute. Vault then flags every secret they could reveal for rotation, so working down the list is a checklist, not an archaeology project.
GATE 25 · SCHEDULED
n4n Vault is scheduled on the fleet board — same login, same balance as every other app. Leave an address and we will tell you the moment it boards.