n8n

Authorization failed - please check your credentials

What this means

The app your workflow talks to rejected the login n8n sent. The key or account is missing, typed wrong, expired, or not allowed to do this.

Why you're seeing this

  • The key is sent in the wrong format (or not sent at all)

    Common

    The service expects the key in a specific shape — for example a word like "Bearer", "Token" or "Key" in front of it, under a specific header name. If the prefix is missing, the header name is wrong, or the HTTP Request node's authentication is left on None, the service sees no valid login. This was the most frequently solved cause in the forum threads read (fal.ai, Baserow, ManyChat and a generic API key case).

  • The token expired or was revoked

    Common

    Workflows that ran fine start failing later. Forum examples: WhatsApp temporary access tokens from Meta's API setup page expire after hours, Google connections stopped working until reconnected, and QuickBooks and ClickUp users reported connections dropping after a run. Several of these threads had no confirmed fix, so the pattern is well reported but the cure varies by service.

  • The login works, but that account isn't allowed to do this action

    Sometimes

    The service knows who you are but the user or app behind the credential lacks permission for this operation. Two WordPress threads showed this: the service said the user was not allowed to create posts.

  • The key came from the wrong place

    Sometimes

    Some services have more than one kind of key. Confirmed forum cases: a Gemini key made in Vertex AI Studio instead of Google AI Studio, and a WhatsApp token generated on the API setup page instead of a system user's token.

  • A needed credential field is left empty

    Rare

    Some nodes need an extra field that isn't obvious. In one solved thread, the HubSpot Trigger failed with this error until the Developer API Key field was filled in, even though the account showed as connected.

  • The service blocks n8n's location or network

    Rare

    The key is correct, but the service rejects where the request comes from. Forum cases: an Infobip IP allowlist rejecting n8n Cloud, and a Notion account restricted until the n8n server was moved to a different country.

  • A temporary glitch or an n8n bug

    Rare

    Occasionally the same credentials work on a retry (a Baserow thread suspected rate limiting on Baserow's side), or an n8n release had a bug (an Asana OAuth problem fixed in n8n 0.163.1).

How to fix it

  1. 1

    Open the failed node and read the extra detail shown under the error. It is the service's own reason — for example "Authentication credentials were not provided", "Session has expired" or "not allowed to create posts" — and tells you which of the causes above you have.

  2. 2

    If you use the HTTP Request node, check that Authentication is not set to None. Choose Generic Credential Type, then Header Auth or Bearer Auth (or Query Auth if the service wants the key in the web address), and create a credential there.

  3. 3

    Check the service's API documentation for the exact header name and value format, and copy it exactly — including any word in front of the key such as "Bearer ", "Token " or "Key ", and leaving it out if the docs say to send only the raw key.

  4. 4

    Open the credential in n8n, delete the key, and paste it again with no spaces before or after. Then log in to the service and confirm the key is still active; if in doubt, create a new key and use that.

  5. 5

    Make sure the key is the right kind, from the place the service's docs point to (for example Google AI Studio for a Gemini API key, or a system user's token for WhatsApp Cloud API rather than the temporary token on the setup page).

  6. 6

    If it worked before and suddenly stopped, reconnect the credential (sign in again for OAuth connections). If the service offers a long-lived or non-expiring token, switch to it so this doesn't keep happening.

  7. 7

    If the detail says you aren't allowed to do the action, give the account or app behind the credential the missing permission inside the service itself (for example a WordPress user role that can create posts).

  8. 8

    Still failing with a key you know is right? Fill in every field of the credential (some trigger nodes need an extra key), check whether the service restricts access by IP address or country, and update n8n in case it's a fixed bug. To see exactly what n8n sends, point a test HTTP Request at a request-inspector site such as webhook.site and look at the header it receives.

Why this happens (the technical detail)

This message comes from the remote service, not from n8n itself. When a node's request comes back with HTTP status 401 ("unauthorized"), n8n replaces the raw error with this standard message; the service's own explanation appears in the error details. A 401 means the service didn't accept the login that came with the request — it was missing, malformed, expired or rejected. It is different from a 403 ("Forbidden - perhaps check your credentials?"), though in practice services use the two codes loosely, so a 401 can also mean "we know who you are, but you can't do this." A green "connection tested" result on the credential does not guarantee the node will work: forum threads show the test passing while the real request still fails.

Related errors

Sources

Last verified 2026-09-18.