Secrets and private data
Token-shaped strings, sensitive fields, emails, IP addresses, credential references, pinned data, and exposed webhook identifiers.
FLOXOLAB / FREE N8N WORKFLOW CHECKER
Turn an n8n export into a focused review. Find risky settings, inspect affected nodes, and take a concrete action list back to your workflow.
Your JSON stays here.
Your workflow never runs.
01 / Input
Use one workflow export, not a full instance backup. The file is read locally and checked as soon as you choose it.
Drop your workflow JSON here
The browser reads and checks the file locally. Its contents never need to leave this page.
No workflow upload, execution or browser storage. Choose a new export to recheck after you make changes in n8n.
The pasted JSON has changed. Check it again to generate a current report.
Use the JSON export of a single workflow. Read n8n's export instructions ↗
Examples are synthetic. A quiet report is not proof that a workflow will work.
02 / Review → Fix → Recheck
The checker inspects exported settings and connections. It does not contact your n8n instance or any service in the workflow.
No check has run yet. Try an example to explore the report.
Reviewing structure, failure paths, side effects, privacy signals, and AI guardrails.
02 / YOUR WORKFLOW REVIEW
Static findings · not runtime testing
The score summarizes rule penalties. Reviewing an item does not change it; fixing your workflow and rechecking can.
A baseline stays in this tab only. Load your revised export to compare. Clear the workflow to discard it.
Mark findings reviewed after considering them. This is a checklist, not a confirmation that they are fixed.
For review, not a repaired workflow. Credentials, URLs, identifiers and node labels are removed or replaced. Other sensitive text may remain: inspect the copy before sharing it. Reconfigure it before any import or execution.
What the checker looks for
The checks flag patterns worth reviewing in exported node settings and connections. The checker shows evidence without echoing detected secrets into the report.
Token-shaped strings, sensitive fields, emails, IP addresses, credential references, pinned data, and exposed webhook identifiers.
Missing authentication, test URLs, delegated responses without a response node, and signature checks that deserve manual verification.
Missing error workflows, HTTP calls without bounded retries, hidden errors, missing execution timeouts, and risky loops.
Writes, sends, and creates with no visible idempotency or deduplication signal before an irreversible side effect.
Free-form AI output without schema validation and model-driven actions without a clearly named human approval step.
Broken connections, duplicate names, unreachable nodes, standalone scratch nodes, cycles, and workflows that are difficult to own.
Privacy boundary
The downloadable copy replaces common sensitive fields and identifiers. It helps prepare an export for review; it cannot guarantee that all confidential information is gone.
The sanitized copy replaces node names with neutral labels and preserves the connection structure so another person can still understand the graph. Review it manually before sharing.
Hands-on workflow review
Need a person to turn the findings into a fix plan?
I will review one exported n8n workflow, interpret the static findings, and return a prioritized plan from $75. Workflow execution, security certification, and implementation are separate scopes.
Partner disclosure. The n8n Cloud link below is a partner link. I may earn a commission if you sign up, at no extra cost to you.
n8n partner link
Want managed n8n without maintaining a server?
Affiliate disclosure: I may earn a commission if you sign up through this link, at no extra cost to you.