Appearance
Secret variables
Mark a variable as Secret for API keys, tokens and passwords. Collapy stores the value encrypted, never shows it again in the editor, and keeps it out of execution history. You use a secret in requests the same way as any other variable: {{apiToken}}.
Make a variable secret
- Open the environment. See Environments.
- In the Variables table, click the lock icon in the Secret column. Its tooltip changes from Public variable to Secret variable.
- Type the value. It's masked as you type.
- Click Save or press
Ctrl+S(macOS:Cmd+S).
After you save, the Value field is empty and shows the hint Value stored securely. Nobody can read the value back in the app, including you.
Secret values have a maximum length.
Change or remove a secret
- Change the value. Type a new value into the empty field and save. The new value replaces the stored one.
- Keep the value. Leave the field empty. Saving without typing anything keeps the stored value.
- Make it a normal variable again. Click the lock icon to turn Secret off. The stored value is deleted when you save, so type the value again as a normal value.
- Delete it. Remove the row and save.
- Set it from a request. In REQUEST VARIABLES, type a new value for the secret and choose Update shared value. The value is saved to secure storage, the same as saving it in the environment. See Variables.
Deleting an environment deletes its secrets too.
How secrets are used when you send
Web app
Your browser sends the request with the {{placeholder}} still in it. Collapy fills in the secret value on its servers just before the request goes out, so the value isn't loaded into the request editor or into the request your browser builds.
Desktop app (coming soon)
The desktop app fetches secret values when you click Send and fills them in on your computer. The values aren't kept in the editor.
Secrets follow the same rules as other variables: they must exist in the active environment, and they resolve once. Unlike other variables, a per-request override in REQUEST VARIABLES isn't used when you send. See Variables.
Where secrets stay hidden
| Place | What you see |
|---|---|
| Environment editor | An empty field with Value stored securely |
| REQUEST VARIABLES, including All variables | Dots, also while you type a new value |
Hold-to-preview (eye button or Ctrl+E) | Dots |
| Execution history (web app) | The {{placeholder}}, not the value |
| Execution history (desktop app, coming soon) | *** in place of the value |
| Duplicated environment | An empty field with Value stored securely. The value is copied to the duplicate in secure storage. |
Responses aren't masked
If the API echoes a secret back in its response, for example in a token exchange, the response body shows the value. If you copy text from the response and it contains a secret from the active environment, Collapy warns you with Copied — value contains a secret. The text is still copied. The check only covers secret values at least 12 characters long.
Who can use a secret
A secret has the same access as its environment:
- In a shared environment, every workspace member can use the secret in requests, but nobody can read it in the app.
- In a private environment, only you and the workspace's admins and owners have access.
FAQ
I forgot a secret's value. Can I see it?
No. Collapy never shows a stored secret. Type a new value and save.
Do secrets in Postman imports stay secret?
Yes. Postman variables of type secret are marked Secret in the environment the import creates, and their values are stored securely like any other secret. You don't need to enter them again. See Import a Postman collection.
Are secrets copied when I duplicate an environment?
Yes. The copy gets the same secret values, stored securely, and keeps the original's Private setting. See Environments.
