# Moving node-RED - Failed to decrypt credentials

**URL:** <https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830>\
**Category:** General\
**Created:** [12 November 2019 10:22 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830 "2019-11-12T10:22:16Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [12 November 2019 10:22 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/1 "2019-11-12T10:22:16Z")

</div>

Currently running node-RED on a local Raspberry Pi, and in the process of moving all flows etc to a Oracle VM.  
In the Pi, I've been using 'Projects', but in the VM I will not be using 'Projects'.  
So, I've created an archive comprising of the following files from the Pi;

```auto
flows_raspberrypi_cred.json (from projects/master_flow/)
flows_raspberrypi.json (from projects/master_flow/)
package.json (from projects/master_flow/)
.sessions.json (from .node-red/)
settings.js (from .node-red/)
.config.json (from .node-red/)
lib (from .node-red/)

```

as per the [the cookbook](https://github.com/node-red/cookbook.nodered.org/wiki/How-to-backup-flows-and-related-configuration).

Tonight I'm intending to restore these in the VM, in the `.node-red/` folder.  
I am already using a `credentialSecret` hash in my Pi's settings file, so I've added the same hash to the VM's setting file.

Does all this look correct? also, do I need to rename most of the files from for example 'flows\_ **raspberrypi**.json' to 'flows\_ **digitalnut**.json' (change the machine name)

---

<div class="post-metadata">

**Author:** ![zenofmud](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/zenofmud/32/316_2.png) [@zenofmud](https://discourse.nodered.org/u/zenofmud)\
**Post date:** [12 November 2019 10:48 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/2 "2019-11-12T10:48:44Z")

</div>

> [@Paul-Reed](#):
>
> do I need to rename most of the files from for example 'flows\_ **raspberrypi**.json' to 'flows\_ **digitalnut**.json' (change the machine name)

Like all answers 'it depends'. You can start NR using `node-red yourflowname` so you could use `node-red flows_raspberrypi.json`. You could also hard code the flow file in settings.js. If you want it to connect to it automatically, then use the `flows_<hostname>.json` format.

---

<div class="post-metadata">

**Author:** ![kuema](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kuema/32/6542_2.png) [@kuema](https://discourse.nodered.org/u/kuema)\
**Post date:** [12 November 2019 10:50 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/3 "2019-11-12T10:50:41Z")

</div>

That is the first thing I change in my settings.js

I always use `flowFile: 'flows.json'` because the default format with hostname is really annoying.

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [12 November 2019 13:40 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/4 "2019-11-12T13:40:59Z")

</div>

So I guess I'm going to have to add;  
`flowFile: 'flows_raspberrypi.json'`  
to my VM's node-RED settings...

---

<div class="post-metadata">

**Author:** ![kuema](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kuema/32/6542_2.png) [@kuema](https://discourse.nodered.org/u/kuema)\
**Post date:** [12 November 2019 14:08 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/5 "2019-11-12T14:08:06Z")

</div>

Or just use `flows.json` for your workspaces and rename the file. 😀

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [12 November 2019 14:14 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/6 "2019-11-12T14:14:05Z")

</div>

> [@kuema](#):
>
> and rename the file

So if I rename the flows file to `flows.json`, the cred file would also need changing to `flows_cred.json`?

---

<div class="post-metadata">

**Author:** ![kuema](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kuema/32/6542_2.png) [@kuema](https://discourse.nodered.org/u/kuema)\
**Post date:** [12 November 2019 14:18 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/7 "2019-11-12T14:18:59Z")

</div>

> [@Paul-Reed](#):
>
> the cred file would also need changing to `flows_cred.json` ?

Exactly. 🙂

I use the `flows.json` as name for all of my instances. This way I can move them around easily, and your workspace always looks consistent.

---

<div class="post-metadata">

**Author:** ![zenofmud](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/zenofmud/32/316_2.png) [@zenofmud](https://discourse.nodered.org/u/zenofmud)\
**Post date:** [12 November 2019 14:24 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/8 "2019-11-12T14:24:19Z")

</div>

If you want to just use `flows.json` you still have to uncomment the line in settings.js to tell it to only use that as the name

> ```
> // The file containing the flows. If not set, it defaults to flows_<hostname>.json
> //flowFile: 'flows.json',
> 
> ```

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [12 November 2019 19:43 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/9 "2019-11-12T19:43:10Z")

</div>

Well I did exactly what was discussed above, and upon starting node-RED I got;

```auto
12 Nov 19:37:24 - [info] Server now running at https://127.0.0.1:1880/
12 Nov 19:37:24 - [warn] Error loading credentials: SyntaxError: Unexpected token in JSON at position 0
12 Nov 19:37:24 - [warn] Error loading flows: Error: Failed to decrypt credentials
12 Nov 19:37:24 - [info] Starting flows
12 Nov 19:37:24 - [info] Started flows

```

....and this message;

![creds](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/2X/2/2efd99b54961c8d848151eb039990e7726ffa4a2.jpeg)

Any ideas why this has happened, and how it can be recovered please?

---

<div class="post-metadata">

**Author:** ![kuema](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kuema/32/6542_2.png) [@kuema](https://discourse.nodered.org/u/kuema)\
**Post date:** [13 November 2019 05:42 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/10 "2019-11-13T05:42:40Z")

</div>

Things I would look for:

Check for syntax errors in the `settings.js`.

In your settings.js, is the value of `credentialSecret` the same as on the other machine?  
If it was not set, then Node-RED will use a random one and print a big fat warning on start-up. I don't know where this random key is stored.  
If you changed it, then just use that value. I read that you used Projects, so this key is likely in the project's subdir in the `settings.json`.

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [13 November 2019 09:40 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/11 "2019-11-13T09:40:04Z")

</div>

> [@kuema](#):
>
> Check for syntax errors in the `settings.js`

No errors, in fact this morning I re-copied settings.js from my original working local Pi, and have used that settings file in the VM instance (just amended https entry).  
I get the same error.

> [@kuema](#):
>
> In your settings.js, is the value of `credentialSecret` the same as on the other machine?

As above - using a copy of the same settings file.

> [@kuema](#):
>
> I read that you used Projects, so this key is likely in the project's subdir in the `settings.json`

Yes, that's the one I'm using.

> [@Paul-Reed](#):
>
> flows\_raspberrypi\_cred.json (from projects/master\_flow/)

---

<div class="post-metadata">

**Author:** ![kuema](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kuema/32/6542_2.png) [@kuema](https://discourse.nodered.org/u/kuema)\
**Post date:** [13 November 2019 09:57 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/12 "2019-11-13T09:57:19Z")

</div>

When "Projects" is turned off, all settings are in the `settings.js` (not `.json`).

I have never used the Projects feature, but I think the `credentialSecret` key is in your `projects/master_flow/settings.json` on the old machine.  
You need to add that key to the `settings.js` on your new machine.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [13 November 2019 09:58 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/13 "2019-11-13T09:58:30Z")

</div>

You might be quicker just to let it reset the credentials and re-enter them in each config node.

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [13 November 2019 10:06 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/14 "2019-11-13T10:06:51Z")

</div>

> [@kuema](#):
>
> are in the `settings.js` (not `.json` ).

Yes, indeed (typo)

> [@kuema](#):
>
> but I think the `credentialSecret` key is in your `projects/master_flow/settings.json` on the old machine.

Nope, there is no settings there. The only settings (and which is also shown in the NR log) is in `.node-red/settings.js`

> [@Colin](#):
>
> You might be quicker just to let it reset the credentials and re-enter them in each config node

There are about 4 years worth of credentials which will be a pain to recover and re-enter.

Also, from a trust perspective, users need to have confidence that node-RED backups can be safely restored, otherwise what's the value in creating backups.  
This example shows otherwise...

---

<div class="post-metadata">

**Author:** ![zenofmud](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/zenofmud/32/316_2.png) [@zenofmud](https://discourse.nodered.org/u/zenofmud)\
**Post date:** [13 November 2019 10:30 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/15 "2019-11-13T10:30:25Z")

</div>

I just tried to move a flow and the credentials from a Pi to my Mac and I hit the same issue:

```auto
13 Nov 05:23:41 - [warn] Error loading credentials: SyntaxError: Unexpected token � in JSON at position 0
13 Nov 05:23:41 - [warn] Error loading flows: Error: Failed to decrypt credentials

```

in this case the original flow was NOT in a project. I then realized I had not moved the `.config.json`. Once I did, it worked fine.

So I would recheck the original `.config.json` against the one in the oracle VM to make suer they are the same

---

<div class="post-metadata">

**Author:** ![kuema](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kuema/32/6542_2.png) [@kuema](https://discourse.nodered.org/u/kuema)\
**Post date:** [13 November 2019 10:33 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/16 "2019-11-13T10:33:26Z")

</div>

Maybe the auto-generated `credentialSecret` is stored in there. That would explain it.

---

<div class="post-metadata">

**Author:** ![kuema](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kuema/32/6542_2.png) [@kuema](https://discourse.nodered.org/u/kuema)\
**Post date:** [13 November 2019 10:45 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/17 "2019-11-13T10:45:38Z")

</div>

I just checked... it is indeed in the `.config.json` as key `_credentialSecret`

So once you set `credentialSecret` in your `settings.js` with your own secret, it will be removed from there at the next launch and the existing credentials will be re-encrypted with your own key.

For reference, these are the files I commit to source control. Everything to run the instance is in there. I just need to run `npm install` after checkout. So backups of your workspace are not really an issue if you follow that setup.

```auto
.
├── .gitignore
├── flows_cred.json
├── flows.json
├── package.json
├── package-lock.json
└── settings.js

```

NOTE:  
These settings are important for this:

```auto
flowFile: 'flows.json',
flowFilePretty: true,
credentialSecret: "your key here...",

```

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [13 November 2019 10:49 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/18 "2019-11-13T10:49:49Z")

</div>

> [@zenofmud](#):
>
> in this case the original flow was NOT in a project. I then realized I had not moved the `.config.json` . Once I did, it worked fine.

Thanks for testing Paul.  
I think that the issue maybe in the last few lines of the `.config.json` file;

```auto
"projects": {
  "projects": {
   "Master_flow": {
    "credentialSecret": "mysecret"
   },
   "Store": {
    "credentialSecret": "mysecret"
   }
  },
  "activeProject": "Master_flow"
 }
}

```

Where it's still referring to 'projects' & `"activeProject": "Master_flow"`  
What are the last entries in your `.config.json` file Paul?

---

<div class="post-metadata">

**Author:** ![kuema](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kuema/32/6542_2.png) [@kuema](https://discourse.nodered.org/u/kuema)\
**Post date:** [13 November 2019 10:53 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/19 "2019-11-13T10:53:44Z")

</div>

You can try to use the `credentialSecret` from the `"Master_flow"` section. That is the actual secret that was used to encrypt the credentials.

Just set it as `credentialSecret` in the `settings.js` on the new machine.

And, on the new machine, look out for the `_credentialSecret` in `.config.json`. I _think_ it should be removed beforehand (or delete the `.config.json`, it will be regenerated)

---

<div class="post-metadata">

**Author:** ![kuema](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kuema/32/6542_2.png) [@kuema](https://discourse.nodered.org/u/kuema)\
**Post date:** [13 November 2019 11:00 UTC](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830/20 "2019-11-13T11:00:55Z")

</div>

I think by now it would be best to start the migration again with a fresh Node-RED workspace on the target machine. I have some steps in mind that you could follow. I can write them down, if you want.

[Next page](https://discourse.nodered.org/t/moving-node-red-failed-to-decrypt-credentials/17830.md?page=2)
