{"record":{"id":"788b6c32bb1e5aa5","repo":"n8n-io/n8n","slug":"set-credential-field","errorCode":"SET_CREDENTIAL_FIELD","errorMessage":"${nodeRef} has a field named \"${assignment.name}\" which appears to be storing credentials. Use n8n's credential system instead.","messagePattern":"(.+?) has a field named \"(.+?)\" which appears to be storing credentials\\. Use n8n's credential system instead\\.","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/@n8n/workflow-sdk/src/workflow-builder/plugins/validators/set-node-validator.ts","lineNumber":185,"sourceCode":"\t\t\t\t\t});\n\t\t\t\t}\n\t\t\t}\n\n\t\t\tif (assignment.value === undefined) {\n\t\t\t\tissues.push({\n\t\t\t\t\tcode: 'SET_INVALID_ASSIGNMENT',\n\t\t\t\t\tmessage: `${nodeRef} assignment at index ${index} is missing the \"value\" field.`,\n\t\t\t\t\tseverity: 'error',\n\t\t\t\t\tviolationLevel: 'major',\n\t\t\t\t\tnodeName: displayName,\n\t\t\t\t\tparameterPath: `${parameterPath}.value`,\n\t\t\t\t\toriginalName: origForWarning,\n\t\t\t\t});\n\t\t\t}\n\n\t\t\tif (isNonEmptyString(assignment.name) && isCredentialFieldName(assignment.name)) {\n\t\t\t\tissues.push({\n\t\t\t\t\tcode: 'SET_CREDENTIAL_FIELD',\n\t\t\t\t\tmessage: `${nodeRef} has a field named \"${assignment.name}\" which appears to be storing credentials. Use n8n's credential system instead.`,\n\t\t\t\t\tseverity: 'warning',\n\t\t\t\t\tnodeName: displayName,\n\t\t\t\t\toriginalName: origForWarning,\n\t\t\t\t});\n\t\t\t}\n\t\t}\n\n\t\treturn issues;\n\t},\n};\n","sourceCodeStart":167,"sourceCodeEnd":197,"githubUrl":"https://github.com/n8n-io/n8n/blob/5ac6606e81f67bb9534255570cd4e86fd8101eee/packages/@n8n/workflow-sdk/src/workflow-builder/plugins/validators/set-node-validator.ts#L167-L197","documentation":"Fires in validateNode when a manual-mode Set assignment has a name that isCredentialFieldName flags as a credential-like field (e.g. names resembling password, apiKey, token). Storing secrets as Set node field values puts them in plaintext in the workflow JSON and execution data; the validator rejects this pattern. The offending input is the assignment.name string; this is a lint-style guard, not a runtime throw.","triggerScenarios":"Thrown at packages/@n8n/workflow-sdk/src/workflow-builder/plugins/validators/set-node-validator.ts:185 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Remove the credential-valued assignment and attach an n8n credential to the node that needs the secret instead","If the field is legitimate (not a secret), rename it so it no longer matches credential-style names","Pass the secret via an expression referencing a credential-backed node's output rather than a literal value"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"5ac6606e81f67bb9534255570cd4e86fd8101eee","analyzedAt":"2026-08-12T05:26:35.080Z","contentChangedAt":"2026-08-12T05:26:35.080Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}