# Flows-cred.json decrypt/encrypt dependency

**URL:** <https://discourse.nodered.org/t/flows-cred-json-decrypt-encrypt-dependency/78456>\
**Category:** General\
**Created:** [16 May 2023 09:12 UTC](https://discourse.nodered.org/t/flows-cred-json-decrypt-encrypt-dependency/78456 "2023-05-16T09:12:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lizzardguki](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lizzardguki/32/103637_2.png) [@lizzardguki](https://discourse.nodered.org/u/lizzardguki)\
**Post date:** [16 May 2023 09:12 UTC](https://discourse.nodered.org/t/flows-cred-json-decrypt-encrypt-dependency/78456/1 "2023-05-16T09:12:04Z")

</div>

I am creating a script that a user would provide a configuration file, that haves a list of:  
-dependencies

- settings ( for updating settings.js)  
-flows  
-subflows  
-configurations (for nodes)  
-nodes

What i want to do also is for a user to be able to provide different credentials for different nodes (that are saved in flow\_cred.json file). So that the program can encrypt the plaintext credentials to the cred file.

Tried looking what dependency node-red uses for this from GitHub repository, but without luck!

---

<div class="post-metadata">

**Author:** ![Shan](https://avatars.discourse-cdn.com/v4/letter/s/7ab992/32.png) [@Shan](https://discourse.nodered.org/u/Shan)\
**Post date:** [16 May 2023 09:44 UTC](https://discourse.nodered.org/t/flows-cred-json-decrypt-encrypt-dependency/78456/2 "2023-05-16T09:44:54Z")

</div>

> [@What encryption method is used to encrypt Flow Credentials in order to trigger flows via HTTP API?](https://discourse.nodered.org/t/what-encryption-method-is-used-to-encrypt-flow-credentials-in-order-to-trigger-flows-via-http-api/73579/3):
>
> bcrypt is a password-hashing algorthm, not an encryption scheme. If we used bcrypt for the credentials, we'd never be able to decrypt them. The code Node-RED uses to encrypt/decrypt credentials is here:

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [16 May 2023 13:20 UTC](https://discourse.nodered.org/t/flows-cred-json-decrypt-encrypt-dependency/78456/3 "2023-05-16T13:20:41Z")

</div>

The encrypt/decrypt functions are here: [node-red/credentials.js at 67dd7e30faf1a6fca07f5b745de75f4ad3036ce4 · node-red/node-red · GitHub](https://github.com/node-red/node-red/blob/67dd7e30faf1a6fca07f5b745de75f4ad3036ce4/packages/node_modules/%40node-red/runtime/lib/nodes/credentials.js#L34-L46)

We don't expose these in any api, but you can just copy/paste them into your own code.

```auto
const crypto = require('crypto')
// To encrypt
const originalKey = 'secret'
const credentials = { "a": "myPassword" }
const hashedKey = crypto.createHash('sha256').update(originalKey).digest();
const encryptedKeys = encryptCredentials(hashedKey, credentials)

```

---

<div class="post-metadata">

**Author:** ![Shan](https://avatars.discourse-cdn.com/v4/letter/s/7ab992/32.png) [@Shan](https://discourse.nodered.org/u/Shan)\
**Post date:** [16 May 2023 15:51 UTC](https://discourse.nodered.org/t/flows-cred-json-decrypt-encrypt-dependency/78456/4 "2023-05-16T15:51:24Z")

</div>

Hi Nick I am trying to reverse engineer this logic in python. Would there be a way where I can somehow test the decryption logic of a resultant `flows_cred.json` file i.e. create `flows_cred.json` file, mount it into a directory (via docker volumes) and see the logs of nodered whether the decryption of the file was successful or not?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [15 July 2023 15:51 UTC](https://discourse.nodered.org/t/flows-cred-json-decrypt-encrypt-dependency/78456/5 "2023-07-15T15:51:39Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
