N8n user management: member sensitive credential data is visible to the owner

Hi there! When a member creates it own credentials, its content is visible for the owner.
But in the User management manual it’s said: " See all credentials (but not the sensitive information)"

I thought that credentials data is in fact the sensitive data. Can a member somhow hide it from the owner? So that the latter would see only “there’s a credential with such a name”.

Hey @artildo,

That is a good spot, Let me check with the rest of the team.

1 Like

Hey @artildo,

I have had a chat with the rest of the team and it looks like the Owner is meant to have the ability to see the credentials for other user accounts I guess to help solve problems if any pop up. It looks like this different when credential sharing is enabled that then hides the details unless the user allows the owner to have access to them.

Hi @Jon, thank you for pointing that out

So one usecase is when the owner is supposed to have access to his users’ creds.
But can I disable it? So that this data would become invisible to the owner.
Mabe some settings in the yml file?

Hey @artildo,

When credential sharing is not enabled it looks like it will work how it currently does and there is no way at the moment to change this we will need to pop open a feature request to have an option added.

@Jon,

So if I got you correctly, right now there is no way to hide members cred, but it can be enabled in future?

Hey @artildo,

That is my understanding, So right now you can’t hide them but when credential sharing is released and enabled that will then hide the credentials from the owner unless shared with them.

2 Likes

Hi! I was looking about this topic. Is possible nowadays hide the members credentials to the owner?
Thanks in advance

Hey @rubenalonsoes,

Welcome to the community :tada:

Good question, I think the values are hidden but as the owner is typically the server admin they will have access to everything from the cli anyway.

1 Like

Yes, but as owner I could create a workflow using that credential?

Technically… yes you could but not by selecting it from the UI in the node. We recommend using the owner account as more of a super admin account and lock it away so that no one uses it.

Ok, thanks Jon!

1 Like

Thanks for fixing. Now the creds are hidden to the owner.