N4N VAULT · GATE 25

Every secret sealed, every reveal logged.

n4n Vault keeps your team’s shared passwords, API keys and credentials sealed end-to-end — access granted per team, every reveal written to an audit trail. The keys to everything else, finally out of chat threads and spreadsheets.

Scheduledoperations · gate 25 · end-to-end encrypted

SEALED SPECIMEN · GATE 25

Watch a collection seal itself

Paste a credential and it is encrypted on your device before it travels — the server never holds anything it can read. Getting the value back takes a grant, and taking it leaves a mark.

sealencrypted client-side, stored as ciphertext
grantaccess per team, revoked the minute someone leaves
revealevery look at a value writes an audit entry
n4n vault · engineering / production

engineering / production

4 secrets · 2 teams granted

sealed
prod-postgres•••••••••••••••••••••••••••engineeringrotated 12d ago
stripe-live••••••••••••••••••••••••financerotated 4d ago
deploy-ssh••••••••••••••••••••••••cirotated 30d ago
smtp-relay••••••••••••••••••••••••••engineeringrotated 61d ago
14:32 · m.ito revealed stripe-live · purpose: refund scriptlogged

illustrative collection · names and values are sample data

CAPABILITIES · GATE 25

Built for the keys to everything else

A password manager stops at the login screen. Vault is built for a team’s whole credential surface — the database strings, deploy keys and processor keys the rest of the fleet runs on.

Sealed before it leaves your device

Secrets are encrypted end-to-end: your browser seals a value before it travels, and the server only ever stores ciphertext it cannot read.

A shape for every secret

Passwords, API keys, SSH keys, database strings and one-time codes each get structured fields — no more credentials pasted into a doc titled "misc".

Grants by team, not by thread

Access follows collections: engineering sees deploy keys, finance sees processor keys. Nobody DMs a password again.

Reveals that leave a trace

Every reveal writes who, when, from where and a purpose note to an append-only audit trail you can filter by secret or by person.

Access with an expiry

Time-box a grant for a contractor or an incident. When the clock runs out, the access revokes itself — no calendar reminder required.

Rotation you can prove

Every secret carries its age. Set a rotation window, get flagged when one goes stale, and keep the full history of who rotated what, when.

ROUTE MAP · CONNECTIONS

The vault the rest of the fleet trusts

Vault holds the keys the fleet runs on — People decides who gets them, Flow and Web use them without ever seeing them.

PEOPLE → VAULT

Grants follow team membership in People — offboard someone and every collection they could open is closed the same minute.

VAULT → FLOW

Flow steps fetch credentials from Vault at run time, so a secret never lives inside an automation definition.

VAULT → WEB

Sites in Web reference integration keys by name — rotate the key in Vault and every site picks it up without a redeploy.

A DAY AT GATE 25

A quiet day in the vault

local time · illustrative

08:57nightly sweep flags 2 secrets past their rotation window→ rotation queue
09:14a.reyes joined engineering · 12 grants appliedvia People
11:02stripe-live rotated by k.osei6 flows picked up the new key
17:30contractor grant expired · access revokedautomatic · logged

FAQ · GATE 25

Before you board

Anything else, ask a person:support@n4n.io

Is n4n Vault available today?

Not yet — n4n Vault is scheduled on the fleet board. Email support@n4n.io and we will tell you the moment it boards. The fleet’s first departure, n4n AI, is live today at n4n.ai.

What does end-to-end encrypted mean here?

A secret is encrypted on your device before it is stored, and decrypted on the device of someone with a grant when it is revealed. The server holds ciphertext it cannot decrypt — an operator with database access sees dots, not passwords.

Who can see a secret?

Only people with a grant on its collection. Grants are made per team, so access follows the org chart rather than a chat thread — and every reveal is recorded with who, when, from where and why.

What happens when someone leaves the team?

Offboarding in People revokes their grants the same minute. Vault then flags every secret they could reveal for rotation, so working down the list is a checklist, not an archaeology project.

GATE 25 · SCHEDULED

Give the keys a gate of their own

n4n Vault is scheduled on the fleet board — same login, same balance as every other app. Leave an address and we will tell you the moment it boards.