n8n-nodes-session-token-auth
v0.3.0
Published
n8n credential type (plus a small helper node) for APIs that log in with username/password, get back a session token, and send that token in a header on every subsequent request.
Maintainers
Readme
n8n-nodes-session-token-auth
An n8n credential type (plus a small helper node) for APIs shaped like this:
POSTa login path with a username and password- The response contains a session token (e.g.
{ "sessionId": "..." }) - Every subsequent request must send that token in a header — either
HTTP Basic (
Authorization: Basic base64(username:token)) or a raw custom header (e.g.X-Session-Id: <token>)
n8n's built-in credential store has no way to express this out of the box:
credential values are static, entered once in the UI, while a session token is
only known after a login call made at runtime. This credential type uses n8n's
preAuthentication hook to do that login once per credential entry (n8n stores
the token and re-runs the login after a 401), then injects the token into
every request that uses the credential.
What you get
- Credential type "Session Token Auth API" — use it on the HTTP Request node (Authentication → Predefined Credential Type) or on any node that accepts a predefined credential.
- "Session Token Auth" HTTP Request preset in the node palette — an HTTP Request node pre-wired to this credential.
- "Session Token" node with one operation, Get Session Token — performs the login and returns the token and the exact header the credential sends, for cases where you need the raw token (Code nodes, tools, nodes that only take a header value). The login runs on every execution of this node; only the credential itself caches the token.
Credential fields
| Field | Purpose |
|---|---|
| Base URL | Must be https://. Login Path is appended to it. |
| Login Path | Path that performs the login, e.g. login or auth/session. |
| Login HTTP Method | POST or GET. GET always sends credentials as query params. |
| Login Body Type | For POST only: JSON, Form-Urlencoded, or None (HTTP Basic Auth on the login request itself). |
| Username / Password | Your login credentials. |
| Username Field / Password Field | Key names used in the login request body. |
| Extra Login Fields (JSON) | Optional fixed fields the login endpoint requires besides username/password, e.g. { "LanguageId": "CZ", "DbProfile": "erp", "UseWindowsAuthentication": false }. Merged into the login body (POST) or query (GET), where Username/Password overwrite same-named keys. With Body Type None they form the JSON body on their own (credentials go via HTTP Basic) and keys named like the Username/Password fields are dropped. |
| Token Field | Dot-path to the token in the login response, e.g. sessionId. |
| Username Field (in Login Response) | Optional — if the server echoes back a canonical username to use afterwards. |
| Header Format | Basic (base64 of username:token) or Raw Token. |
| Header Name | Header sent on every request, e.g. Authorization or X-Session-Id. |
| Test Path | Optional authenticated GET endpoint used by the credential's Test button (e.g. api/me). The test always logs in first; without a Test Path it falls back to a GET on the Login Path, which many APIs reject even though the login succeeded. |
Session Token node output
{
"sessionToken": "…",
"username": "…",
"header": { "name": "Authorization", "value": "Basic …" }
}With Continue on Fail enabled, a failed item keeps the same shape with null
values plus an error message.
Security note. This output is a live credential. n8n stores node output in the execution history in plain text, so anyone who can view the workflow's executions can read the token. Prefer the credential directly on an HTTP Request node; if you must use this node, consider turning off Save successful executions in the workflow settings.
Install
From the n8n UI (self-hosted, Community Nodes enabled): Settings → Community
nodes → Install and enter n8n-nodes-session-token-auth.
Or manually, in n8n's user folder:
mkdir -p ~/.n8n/nodes && cd ~/.n8n/nodes && npm install n8n-nodes-session-token-authand restart n8n.
0.1.0 is not usable — it contained only the credential type, which n8n's UI installer rejects ("does not contain any nodes"), and its login hook was never invoked because the credential did not declare the expirable
sessionTokenproperty n8n requires. Use 0.2.1 or later.
Troubleshooting
"Class could not be found. Please check if the class is named correctly."
on install (0.2.0): your instance has a stale copy of n8n-workflow hoisted
into ~/.n8n/nodes/node_modules/ (left behind by community packages
installed on older n8n versions). Node resolves that copy before n8n's own,
and if it predates n8n 1.85 it lacks NodeConnectionTypes, so the node class
throws while loading. Fixed in 0.2.1, which no longer depends on that export.
You can check with ls ~/.n8n/nodes/node_modules/n8n-workflow inside your
n8n container; removing the stale copy is optional.
Build from source
npm install --ignore-scripts
npm run buildLicense
MIT — see LICENSE.
