Quick overview
This workflow accepts a POST request, detects potential PII via an external HTTP API, anonymizes high-risk fields, forwards the anonymized payload to a downstream endpoint, and returns the cleaned data with an audit summary.
How it works
- Receives business data in a POST request via an n8n webhook.
- Validates the request, generates a request ID, and extracts likely PII candidate fields (including one-level nested fields).
- Waits briefly, then calls an external PII detection HTTP endpoint with the extracted candidates.
- Interprets the detection response (and falls back to regex heuristics) to assign a PII type and risk score per field.
- Waits briefly, then anonymizes fields above the risk threshold by hashing, masking, or redacting values based on type.
- Waits briefly, then posts the anonymized payload and change count to a downstream HTTP endpoint for logging or further processing.
- Builds an audit record and returns a JSON response to the webhook caller with the anonymized data, audit summary, and an HTTP status indicating success or detection failure.
Setup
- Configure the webhook path (default:
/pii-anonymize) and copy the production webhook URL into the system that will send the incoming requests.
- Replace the placeholder detection and downstream URLs (currently
https://httpbin.org/post) with your real PII detection API and audit/logging endpoint.
- If your detection or downstream endpoints require authentication, add the required headers (for example, an API key or bearer token) to the two HTTP Request steps.
- Update the anonymization settings in the code (especially
hashSalt, piiCandidates, and redactWith) to match your data model and security requirements.