↶ rewindOpen Rewind →
REWIND / FREE EARLY ACCESS

A way back from an automation change.

Keep the changes from a workflow together, review a complete recovery plan, and let your workers restore supported records with version checks.

Start with one supported record.

Rewind supports opted-in Supabase rows and HTTP APIs with strong ETags and atomic conditional writes. Use n8n or a custom recovery worker. The worker and provider credentials stay in infrastructure you control.

It cannot reverse every n8n node, a sent email, a payment, an arbitrary deletion, or a change made before its snapshots were recorded. Nested values, array edits and creating or removing fields are outside the current adapters.

A later edit blocks recovery. An unknown outcome requires investigation and is never retried automatically. “Worker reported restored” is a report from your worker; verify the result in the connected service.

Recover a complete workflow run.

Group completed actions across named service connections, then close the complete history once the original workflow has stopped. Review all affected records and irreversible actions, then approve recovery once. Workers restore supported steps in reverse order.

A conflict or unknown outcome stops the remaining steps. Some records may already have been restored; recovery is not an atomic transaction across services. Repeated edits to the same record need a continuous captured version chain. Runs support up to 100 sequential actions and do not infer parallel dependencies.

Workflow run setup guide ↓

Your first workflow, end to end.

  1. Start with disposable data. Open Rewind and explore the sample workspace, then sign in to save real workflow history.
  2. Connect. Choose Supabase or HTTP, prepare the templates, and create separate recording and recovery keys. Attach the keys in n8n's credential store.
  3. Record one successful change. Capture before and after values plus the provider's resulting version. Keep the same idempotency key if recording delivery needs a retry.
  4. Review an undo. Open Workflow history, inspect the snapshots and approve. This queues a job for your worker.
  5. Verify the result. Publish the configured worker workflow, inspect its execution, and independently read the connected record. Test a later edit too: it should be protected.

Rewind hosting does not host n8n. You need your own running n8n instance or worker and a supported provider. Their costs and availability are separate.

Connect the tool you use.

Connect includes n8n templates and a JavaScript/TypeScript recorder with a durable local outbox and agent receipt adapter. Zapier actions are available as a developer package for private installation. Make custom-app sources are a preview; their hosted runtime has not been verified. These packages are not published marketplace listings.

Recording requires actual before and after snapshots and supported provider versions. A recovery worker is still required. Your automation platform, provider and local execution history have separate costs, access controls and retention.

Free, with a finite allowance.

Hosted early access has no subscription or card requirement. Each account allows 1,000 recorded operations and 10 active API keys; the service currently shares a 5,000-operation allowance. These are history limits, not monthly resets. The local edition allows 10,000 operations per account.

Recording stops at capacity and existing history remains exportable. A rejected recording does not undo an automation's original change. Provider quotas, downtime and free-project inactivity can interrupt availability. Each account can own five client workspaces with up to ten people in each. Their history allowance and key limit are shared across the owner’s workspaces. Billing and automatic retention controls are not available.

Recover together, with separate client histories.

The hosted app supports client workspaces, owner/operator/viewer roles, and optional second-person approval. Owners invite a verified GitHub email using a private, one-use link; Rewind does not send invitations by email. Members can see each other’s names and workspace recovery activity. Viewers can read and export history.

When a second approval is required, another owner or operator must review the same plan before any jobs are queued. Requests expire after 24 hours. Settings and membership changes cancel pending requests; already approved jobs keep their authorization. Owners manage this policy. These team controls are available in the hosted edition.

DATA HANDLING / UPDATED 2 OCTOBER 2026

Know what you send.

Hosted Rewind uses GitHub sign-in for your account name and email, without requesting repository access. It stores your sample workspace, workflow-supplied titles and resource identifiers, before/after values, recorded versions, recovery events and reports, key metadata and usage timestamps, and feedback messages with operator replies, client membership and invitation metadata, and approval requests and decisions.

Send only the fields needed for recovery. Do not put passwords, access tokens, payment details or unnecessary personal data in snapshots or feedback. Rewind does not automatically fetch the rest of a provider record.

Where data goes

The hosted app is served through Cloudflare. Supabase handles authentication and stores account data in the dedicated Rewind database in the United States. GitHub handles the identity login. These providers process requests needed to run the service. Fonts are loaded from Google Fonts, which receives the font request. Rewind adds no advertising or analytics trackers.

The local edition stores account data in the SQLite database on the computer running it. Guest sample data and your theme choice stay in your browser. Provider credentials belong in your n8n credential store or worker environment, not in Rewind reports or workflow exports.

Access and storage

Each client workspace has its own history and keys. Only its owner and invited members can access it. Removing or demoting an operator revokes the keys they issued in that workspace. Recording keys can submit changes; worker keys can claim approved recovery jobs and report results. They cannot approve undo. Key secrets are shown once, stored as hashes and expire after 90 days. You can revoke them in Connect.

Hosted sign-in uses secure, HttpOnly cookies. Rewind operators with server administration access can access stored account data for operating the service and investigating reports. Workflow snapshots are not encrypted end to end.

Export and deletion

Account → Download account data exports your profile, sample workspace, all owned workspaces’ workflow runs, recorded operations and events, approval and membership metadata, key metadata, and feedback with replies. Credentials and lease secrets are excluded. The export contains the data you sent and should be kept private. It is not an importable database backup.

Account deletion removes your identity, feedback and all workspaces you own, including their members, keys and history. History in workspaces owned by someone else stays with that owner; your membership and keys you issued there are removed. It does not undo or delete records in connected services. Stop workers and recording workflows, inspect unresolved outcomes, and export what you need first. A running recovery lease blocks deletion until its result arrives or the lease expires.

Application history has no automatic expiry and is kept until account deletion. Infrastructure logs have separate retention. Manual encrypted database backups are stored in a private GitHub repository. The latest verified snapshot is kept until replaced or explicitly removed, so it may contain data deleted from the live service. Deletions must be reconciled before a restored database is reopened. Automated production backups and automatic backup expiry are not currently enabled. Copies you downloaded or retained in n8n and other services are outside account deletion.

Feedback & help.

Sign in, open Account, and use Feedback & help. Reports are private to your account and the operator of this Rewind instance. Replies appear there; they are not emailed. Early access has no guaranteed response time.

Describe the steps, expected result and what happened. The form attaches no workflow data automatically. For recovery issues, the operation's Copy diagnostics button excludes snapshots, resource IDs and credentials. Review anything you share, and never paste API keys or customer data.

If sign-in is unavailable, retry later and check GitHub, Supabase and Cloudflare status. The in-app feedback channel requires a working account session. For an unknown recovery outcome, stop automatic recovery and investigate the original worker execution and provider history before taking another action.

Open your workspace →