n8n Workflows: a rewritten history, and dependency pins from 2023
GitHub describes it as all of the workflows of n8n i could find (also from the site itself). The repository metadata lists Python as its primary language. The metadata lists the MIT license. This article stays within the project description and details documented in the GitHub repository README.
At a glance
- What is it?
- This repository is a catalogue rather than a runtime: thousands of n8n workflow JSON files served by a FastAPI application over SQLite full-text search, with a Docker image, a compose file and a Kubernetes chart around it. Its single release is named for a history rewrite, and its dependencies are pinned with exact equality operators.
- Who is it for?
- Use this repository when you want a searchable library of n8n workflow JSON to import into an instance you already run, and when a static catalogue served over HTTP is an acceptable substitute for a real instance. Do not use it as a runtime, because nothing in the tree executes a workflow, and do not treat the security posture described in the README as continuous, because the dependencies are pinned to exact versions and the only release is a history rewrite from 2025-08-14.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 98 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The only release is a repository history rewrite
There is exactly one release in this repository, dated 2025-08-14, and it is not a code release. It is named dmca-compliance-2025-08-14 with the title Repository History Rewrite - DMCA Compliance. That single fact should shape how you clone it. Anything that depends on a specific historical commit, a tag, or a fork relationship formed before that date may not resolve after the rewrite, and blame on old lines will not point at the commits a contributor remembers. The last push to main was on 2026-06-24, so the tree is being touched, but the release history gives you one event to plan around rather than a version series. If you are forking this to keep your own catalogue, copy the JSON rather than depend on the commit graph.
Every dependency is pinned with an equality operator, from a 2023 vintage
requirements.txt uses exact pins throughout and carries a comment describing them as stable versions compatible with Python 3.9-3.12: fastapi==0.109.0, uvicorn[standard]==0.27.0, pydantic==2.5.3, PyJWT==2.8.0, passlib[bcrypt]==1.7.4, python-multipart==0.0.9, httpx==0.26.0, requests==2.31.0, psutil==5.9.8, email-validator==2.1.0 and gunicorn==21.2.0. The consequence is that no patch release arrives unless a human edits the file, so a fix for any of those libraries waits on a pull request rather than on your installer. The README states that a full security audit was completed and all CVEs resolved, and that is true of a snapshot; it is not a subscription. Note also the version spread around it: the prerequisite section says Python 3.9 or newer, the Dockerfile builds on python:3.11-slim-bookworm, and the pins were chosen for a range that ends at 3.12.
The compose file and the README name two different images
The documented Docker route runs the published image with port 8000 mapped to 8000, while docker-compose.yml defines a service called workflows-docs that builds from the local Dockerfile and tags the result workflows-doc:latest. Those are different artefacts with different names, and only the README form points at something on Docker Hub. The compose service is otherwise the more production-shaped of the two: it mounts a named volume at /app/database and another at /app/logs, sets ENVIRONMENT=production and LOG_LEVEL=info, restarts unless stopped, and attaches Traefik labels. So there are two deployment stories here, one for looking at the catalogue and one for running it behind a proxy, and they do not share an image reference. Anyone scripting a rollout has to pick one and be explicit about which.
The server is a search index over a folder of JSON, not an n8n instance
The architecture diagram is short: a user hits the web interface, which talks to a FastAPI server, which queries SQLite with FTS5, which reads a workflow database, alongside a branch serving static files and the workflow JSONs themselves. The HTTP surface is six read endpoints: the web interface at the root, /api/search, /api/stats, /api/workflow/{id}, /api/categories and /api/export. Search runs full text across names, descriptions and nodes, and the filters are category, complexity across low, medium and high, trigger type across webhook, schedule and manual, and service. The consequence is the important one: this is a catalogue. Nothing here executes a workflow, there is no scheduler and no credential store, and a file you download is a JSON document you import into an instance you run elsewhere. The two Python entry points, api_server.py and workflow_db.py, with run.py as the launcher, are all catalogue code.
The production profile starts Traefik with an insecure dashboard
The optional reverse-proxy service in the compose file is under the production profile, so it does not start unless you ask for it. When it does, the command enables the dashboard with --api.dashboard=true and also sets --api.insecure=true, maps 8080 for that dashboard, and mounts the Docker socket read-only so it can read container labels. Provider discovery is narrowed with --providers.docker.exposedbydefault=false, which is the right instinct, but the dashboard itself is left unauthenticated. The certificate resolver is named myresolver and its ACME contact is [email protected], a placeholder address that has to be replaced before a certificate will ever issue. Volumes for Let's Encrypt are mounted from ./letsencrypt. Read those three settings as the deployment checklist rather than as a working configuration.
The example environment file ships placeholder secrets and a loopback host
.env.example is the closest thing to a configuration reference, and every value in it matters. Three are credentials: JWT_SECRET_KEY set to a placeholder that says to change it in production, ADMIN_PASSWORD likewise, and ADMIN_TOKEN described as the token for protected endpoints. The rest are behaviour. WORKFLOW_DB_PATH points at database/workflows.db, HOST is 127.0.0.1 and PORT is 8000, so the API binds loopback by default and is unreachable from another machine until you change it. ALLOWED_ORIGINS lists three origins including the project's own GitHub Pages site, which is a cross-origin allowance for the hosted catalogue rather than for your deployment. RATE_LIMIT_REQUESTS is 60 with RATE_LIMIT_WINDOW at 60. The container runs as uid 1001 with a group of the same gid, and a non-root user is one of the stated security features.
The counts are undated, and the news section predates the last commit
The README reports 4,343 production-ready workflows, 365 unique integrations, 29,445 total nodes, 15 organized categories and a 100 percent import success rate, plus performance claims of under 100 ms search response and under 50 MB memory. None of those numbers carries a date, and the section headed Latest Updates is dated November 2025 while the last push to main is 2026-06-24. That gap is worth taking seriously for a collection whose entire value is its size: a catalogue that stopped growing, or that was pruned, would present exactly the same figures. The repository structure is the ground truth, with the JSON files under workflows/ organised by category, so counting the directories tells you what is actually there. Treat the headline numbers as marketing copy and the tree as the inventory.
Editorial conclusion
Use this repository when you want a searchable library of n8n workflow JSON to import into an instance you already run, and when a static catalogue served over HTTP is an acceptable substitute for a real instance. Do not use it as a runtime, because nothing in the tree executes a workflow, and do not treat the security posture described in the README as continuous, because the dependencies are pinned to exact versions and the only release is a history rewrite from 2025-08-14. Verify four things before you deploy it. That your own history is safe, since the repository was rewritten and old commit references may not resolve. That .env is filled in, because the example file ships placeholder values for the JWT secret, the admin password and the admin token. That you have changed HOST from 127.0.0.1 if the API is meant to be reachable. And that you do not start the production compose profile unmodified, because its Traefik service enables an insecure dashboard and carries an example ACME email address.
Frequently asked questions
Is n8n workflows free?
The repository is MIT licensed and the workflow JSON files are free to use. What you pay for is the machine that runs the catalogue server, since the local route needs Python 3.9 or newer plus pip, and the Docker route needs a container runtime. The collection itself executes nothing, so running an actual n8n instance is a separate cost.
What is n8n workflows?
It is a collection of n8n workflow JSON files, described by its author as all the n8n workflows that could be found, plus a small FastAPI and SQLite FTS5 server that makes them searchable over HTTP. The README reports 4,343 workflows across 365 integrations in 15 categories, served from a folder of JSON rather than from a running n8n instance.
What are the best n8n workflows?
The collection answers that by category rather than by opinion: the search runs full text across workflow names, descriptions and nodes, and you can filter by category, by complexity, by trigger type and by service. The API exposes /api/search, /api/categories and /api/stats for the same purpose, and the hosted version at zie619.github.io/n8n-workflows does it in a browser.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/zie619-n8n-workflows)