{"product_id":"n8n-api-gateway-stripe-rbac-redis-rate-limiting","title":"n8n API Gateway: Stripe RBAC + Redis Rate Limiting","description":"\u003ch3\u003eSecure your n8n webhooks with a Stripe-backed API Gateway (RBAC + Redis rate limiting)\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow turns a single n8n webhook into an API Gateway: it authenticates requests using \u003cstrong\u003eStripe customer metadata\u003c\/strong\u003e, authorizes them with \u003cstrong\u003erole-based access control (RBAC)\u003c\/strong\u003e, and enforces \u003cstrong\u003eper-role rate limits\u003c\/strong\u003e via \u003cstrong\u003eRedis\u003c\/strong\u003e—before forwarding allowed requests to your internal n8n webhook endpoints.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eReceives a POST request\u003c\/strong\u003e on the gateway webhook including an API key, target route, method, and payload.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eAuthenticates against Stripe\u003c\/strong\u003e by searching for a Stripe customer whose \u003ccode\u003emetadata.apiKey\u003c\/code\u003e matches the provided API key, then reads the requester role from \u003ccode\u003emetadata.role\u003c\/code\u003e (e.g., \u003cstrong\u003eadmin\u003c\/strong\u003e, \u003cstrong\u003euser\u003c\/strong\u003e, \u003cstrong\u003ereadonly\u003c\/strong\u003e).\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRejects unauthorized requests\u003c\/strong\u003e with a \u003ccode\u003e401\u003c\/code\u003e JSON response when no matching Stripe customer is found.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eAuthorizes routes via RBAC\u003c\/strong\u003e using a configured route-to-roles permission map; disallowed access returns \u003ccode\u003e403\u003c\/code\u003e with a JSON response.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eEnforces per-role rate limits\u003c\/strong\u003e by incrementing a counter in Redis for the current time window and comparing it to the configured limit.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eThrottles over-limit requests\u003c\/strong\u003e with \u003ccode\u003e429\u003c\/code\u003e JSON plus a \u003ccode\u003eRetry-After\u003c\/code\u003e header, or forwards allowed requests to the mapped internal n8n webhook URL.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eResponds transparently\u003c\/strong\u003e by returning the internal workflow response and including \u003ccode\u003eX-RateLimit-Limit\u003c\/code\u003e and \u003ccode\u003eX-RateLimit-Remaining\u003c\/code\u003e headers.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eSaaS operators exposing controlled API access to n8n workflows with Stripe customer ownership.\u003c\/li\u003e\n  \u003cli\u003eTeams that need strict RBAC for different route permissions (admin vs user vs readonly).\u003c\/li\u003e\n  \u003cli\u003eProtecting expensive automations with Redis-backed rate limits per API key and role.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eIntegrations:\u003c\/strong\u003e Stripe (search customers), Redis (rate-limit counters)\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003en8n nodes used:\u003c\/strong\u003e \u003cem\u003ewebhook\u003c\/em\u003e, \u003cem\u003eif\u003c\/em\u003e, \u003cem\u003eset\u003c\/em\u003e, \u003cem\u003ecode\u003c\/em\u003e, \u003cem\u003eredis\u003c\/em\u003e\n\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eOperational setup:\u003c\/strong\u003e add Stripe credentials with customer search permissions; ensure each customer has \u003ccode\u003emetadata.apiKey\u003c\/code\u003e and \u003ccode\u003emetadata.role\u003c\/code\u003e; provide Redis connectivity; update gateway configuration to match your API routes.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":46047288361139,"sku":"N8N-19668","price":52.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/C-f38PIfhEcOTZUB0Idhp_HY6u7yp5.png?v=1789636011","url":"https:\/\/buyflowscripts.com\/products\/n8n-api-gateway-stripe-rbac-redis-rate-limiting","provider":"N8N Commerce","version":"1.0","type":"link"}