n8n-io/n8n · error · NodeOperationError

Can't use a placeholder for the domain when using…

Error message

Can't use a placeholder for the domain when using authentication

What it means

The HTTP Request tool is configured with authentication, but the URL's domain is defined through a placeholder. Credentials cannot be attached to a request whose host is only known at tool-call time, so the node refuses this combination up front.

Solutions

  1. Hardcode the domain in the URL so the credential can apply
  2. Or drop authentication for this tool
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/@n8n/nodes-langchain/nodes/tools/ToolHttpRequest/ToolHttpRequest.node.ts:300 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of n8n-io/n8n@5ac6606e81 (2026-08-12). Data as JSON: /api/errors/0c6e794aac353e4f. Report an issue: GitHub.

Appendix: source

Thrown at packages/@n8n/nodes-langchain/nodes/tools/ToolHttpRequest/ToolHttpRequest.node.ts:300

			headers: {
				// FIXME: This is a workaround to prevent the node from sending a default User-Agent (`n8n`) when the header is not set.
				//  Needs to be replaced with a proper fix after NODE-1777 is resolved
				'User-Agent': undefined,
			},
			body: {},
			// We will need a full response object later to extract the headers and check the response's content type.
			returnFullResponse: true,
		};

		const authentication = this.getNodeParameter('authentication', itemIndex, 'none') as
			| 'predefinedCredentialType'
			| 'genericCredentialType'
			| 'none';

		if (authentication !== 'none') {
			const domain = new URL(requestOptions.url).hostname;
			if (domain.includes('{') && domain.includes('}')) {
				throw new NodeOperationError(
					this.getNode(),
					"Can't use a placeholder for the domain when using authentication",
					{
						itemIndex,
						description:
							'This is for security reasons, to prevent the model accidentally sending your credentials to an unauthorized domain',
					},
				);
			}
		}

		const httpRequest = await configureHttpRequestFunction(this, authentication, itemIndex);
		const optimizeResponse = configureResponseOptimizer(this, itemIndex);

		const rawRequestOptions: { [key: string]: string } = {
			qs: '',
			headers: '',
			body: '',

View on GitHub (pinned to 5ac6606e81)