# What encryption method is used to encrypt Flow Credentials in order to trigger flows via HTTP API?

**URL:** <https://discourse.nodered.org/t/what-encryption-method-is-used-to-encrypt-flow-credentials-in-order-to-trigger-flows-via-http-api/73579>\
**Category:** General\
**Created:** [12 January 2023 07:59 UTC](https://discourse.nodered.org/t/what-encryption-method-is-used-to-encrypt-flow-credentials-in-order-to-trigger-flows-via-http-api/73579 "2023-01-12T07:59:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shan](https://avatars.discourse-cdn.com/v4/letter/s/7ab992/32.png) [@Shan](https://discourse.nodered.org/u/Shan)\
**Post date:** [12 January 2023 07:59 UTC](https://discourse.nodered.org/t/what-encryption-method-is-used-to-encrypt-flow-credentials-in-order-to-trigger-flows-via-http-api/73579/1 "2023-01-12T07:59:19Z")

</div>

Based on the documentation for [POST /flows : Node-RED](https://nodered.org/docs/api/admin/methods/post/flows/) it mentions the usage of encrypted password within the flow JSON request body. What is the encryption mechanism that is actually used? It doesn't look like `bcrypt`.

Any idea which mechanism is it?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [12 January 2023 15:05 UTC](https://discourse.nodered.org/t/what-encryption-method-is-used-to-encrypt-flow-credentials-in-order-to-trigger-flows-via-http-api/73579/2 "2023-01-12T15:05:49Z")

</div>

While I don't know for certain, I would imagine it uses the same process as for the passwords: [Securing Node-RED : Node-RED (nodered.org)](https://nodered.org/docs/user-guide/runtime/securing-node-red)

Which is indeed bcrypt. However, it does use a salt. From settings.js:

```auto
    /** By default, credentials are encrypted in storage using a generated key. To
     * specify your own secret, set the following property.
     * If you want to disable encryption of credentials, set this property to false.
     * Note: once you set this property, do not change it - doing so will prevent
     * node-red from being able to decrypt your existing credentials and they will be
     * lost.
     */
    credentialSecret: 'xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx',

```

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [12 January 2023 15:28 UTC](https://discourse.nodered.org/t/what-encryption-method-is-used-to-encrypt-flow-credentials-in-order-to-trigger-flows-via-http-api/73579/3 "2023-01-12T15:28:27Z")

</div>

bcrypt is a password-hashing algorthm, not an encryption scheme. If we used bcrypt for the credentials, we'd never be able to decrypt them.

The code Node-RED uses to encrypt/decrypt credentials is here:

> <https://github.com/node-red/node-red/blob/master/packages/node_modules/%40node-red/runtime/lib/nodes/credentials.js#L34-L46>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [26 January 2023 15:29 UTC](https://discourse.nodered.org/t/what-encryption-method-is-used-to-encrypt-flow-credentials-in-order-to-trigger-flows-via-http-api/73579/4 "2023-01-26T15:29:00Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
