Appearance
Authentication
The Auth tab tells Collapy how to authenticate a request. You can set auth on each request, or set it once on a collection or the workspace and let requests inherit it.
Auth types
| Type | Fields | What Collapy sends |
|---|---|---|
| Inherit Auth from Parent | — | Whatever the parent collection or workspace uses. See Inheritance. |
| No Auth | — | Nothing. The tab shows No authentication will be used. |
| Basic Auth | Username, Password | Header Authorization: Basic <base64 of username:password> |
| Bearer Token | Token | Header Authorization: Bearer <token> |
| API Key | Key, Value, Add to (Header or Query Param) | A header named after Key with Value as its value — see the warning below. |
The Password field is hidden as you type.
API Key with Query Param
Collapy currently sends the API key as a header even when Add to is set to Query Param. If your API expects the key in the query string, add it as a row on the Params tab instead, for example api_key = {{apiKey}}, and set the request's auth to No Auth.
OAuth 2.0 isn't supported. When you import a Postman collection or an OpenAPI spec that uses OAuth 2.0, Collapy shows the warning OAuth2 auth is not supported and was skipped and the request is imported without that auth.
Set auth on a request
- Open the request and select the Auth tab.
- Choose a type from the drop-down.
- Fill in the fields.
- Save the request (
Ctrl+S, orCmd+Son macOS).
Auth set on the Auth tab replaces a header with the same name on the Headers tab. For example, a Bearer Token overrides an Authorization header you typed yourself.
Use variables and secrets
Every auth field accepts {{variables}}. Type {{ to get suggestions from the active environment. For example:
- Token:
{{accessToken}} - Username:
{{apiUser}}, Password:{{apiPassword}}
Store tokens and passwords as secret variables. Secret values are filled in only when the request is sent and are never stored in plain text in your execution history. See Secret variables.
Tokens, passwords and API key values you type straight into these fields aren't stored in execution history either. The execution's Req Auth tab shows them as <redacted>. See Execution history.
Inheritance
New requests start with Inherit Auth from Parent, so you can manage auth in one place. When you send a request, Collapy looks for the first level that doesn't inherit:
- The request. If it has its own auth type (including No Auth), that's used.
- Its collection. If the request is in a collection and that collection has an auth type, that's used.
- Parent collections, one level up at a time, for nested collections.
- The workspace. The workspace is the top of the chain and always has a concrete auth type.
If every level inherits, the request is sent without auth.
New collections don't inherit
A new collection starts with No Auth, which stops the chain. If you want requests in a collection to use the workspace's auth, open the collection, set its Auth tab to Inherit Auth from Parent, and save.
Requests at the root of the workspace (not in any collection) go straight from the request to the workspace.
Example
| Level | Auth setting |
|---|---|
| Workspace | Bearer Token {{accessToken}} |
| Collection Billing | Inherit Auth from Parent |
| Collection Billing → Admin | API Key X-Admin-Key = {{adminKey}} |
| Request List invoices in Billing | Inherit Auth from Parent → sends the workspace's Bearer token |
| Request Delete customer in Admin | Inherit Auth from Parent → sends the X-Admin-Key header |
Set auth on a collection
- Open the collection from the Explorer.
- Select the collection's Auth tab.
- Choose Inherit Auth from Parent to pass auth down from the parent collection or workspace, or choose a concrete type and fill it in.
- Save the collection.
See Collections and the Explorer.
Set auth on the workspace
Workspace settings currently live in the app under Account.
- Go to Account → Workspaces and select the workspace.
- Open the Auth tab.
- Choose No Auth, Basic Auth, Bearer Token or API Key and fill it in. Inherit Auth from Parent isn't offered, because nothing sits above the workspace.
- Save.
Changing workspace settings needs the right workspace role. See Workspaces.
Check what was sent
After you send a request, the Req Auth tab in the RESPONSE panel shows the auth type that was actually used after inheritance, and its values. See Send a request and read the response.
FAQ
Why is my request sent without auth even though the workspace has a token?
The request is probably in a collection set to No Auth — new collections start that way. Set the collection's auth to Inherit Auth from Parent.
Can a request opt out of inherited auth?
Yes. Set the request's auth to No Auth. It then sends no auth, whatever its collection or workspace uses.
