Appearance
Execution history
Each time you send a request, Collapy records an execution: what was sent, what came back and who sent it. Executions are stored in the cloud and shared with the workspace, so a teammate can open the exact response you saw. Credentials are kept out of the stored copy.
What's recorded
An execution is created when you click Send, and updated when the response arrives. It contains:
- The request as sent — method, final URL, headers, query parameters, body, and the auth type and values after inheritance and variable fill-in. Credentials are replaced, see below.
- The response — status code and text, headers, body and size.
- Timing — total duration and the phases shown on the Profile tab.
- Who and when — the member who sent it and the time.
- The error, if no response arrived.
A request that's blocked before sending — for example because of missing variables — isn't recorded. Sends refused by the per-minute limit or the monthly cap are still recorded, as Failed executions.
Credentials and secrets
Collapy changes the stored copy of the request, not the request that's sent. What goes to the API is exactly what you built.
| Value | Stored as |
|---|---|
| Bearer Token token, Basic Auth password, API Key value | <redacted>, shown on the Req Auth tab. The basic-auth username and the API key's name are kept. |
Values of credential headers you add yourself: Authorization, Proxy-Authorization, Cookie, X-API-Key, Api-Key, ApiKey, X-Auth-Token, X-Access-Token, X-CSRF-Token, X-XSRF-Token | <redacted>, shown on the Req Headers tab. Header names match in any letter case. |
A value that's only a {{variable}} placeholder, such as {{apiToken}} or Bearer {{apiToken}} | Kept as written. |
| Secret variable values anywhere in the request | Never stored. You see the {{name}} placeholder, or *** where the value was filled in. |
Some values aren't redacted:
- Credentials typed into the URL, query params or body. Only secret variable values are masked there. Put credentials in secret variables and write
{{name}}in the URL, params or body instead. - Responses are stored as received. If an API echoes a credential back in its response, that response is stored as it is.
Executions recorded before Collapy started redacting credentials were cleaned up the same way.
Headers, bodies, query parameters, auth values and responses are encrypted at rest. The URL isn't.
Who can see executions
Everyone in the workspace can see the executions of shared requests, including the request, the response and who sent it.
Executions of a Private request are private too. Only you and the workspace's Admins and Owners can see them. Executions recorded before this rule was introduced were updated to follow it.
The EXECUTIONS panel
The EXECUTIONS panel lists the most recent executions across the whole workspace, newest first. New executions appear live as you and your teammates send requests.
When the panel is docked at the bottom, it shows a table:
| Column | Shows |
|---|---|
| Method | The HTTP method. |
| Title | The request's name. |
| Status | The status code, or ERR if no response arrived. |
| Time | How long the request took. |
| Size | The response size. |
| Called by | The member who sent it. |
| When | How long ago it was sent. |
In a side panel, the same information is shown as a compact list.
The panel header has two buttons:
- Showing all / Showing mine only — switches between everyone's executions and only yours.
- Refresh — reloads the list.
Click an execution to open its request in a tab and load that execution's response into the RESPONSE panel.
A single request's executions
You can see the recent executions of one request in two places:
- The Executions tab of the request. Each row shows the status code (or
ERR), the duration and how long ago it ran. Before the first send it shows No executions yet. - The call history sidebar in the RESPONSE panel. Click Show call history in the panel header to open an EXECUTIONS column next to the response. The execution you're looking at is highlighted. Click Refresh to reload it, or Hide call history to close it.
Click any execution to load its response, headers, request details, timing and info into the RESPONSE panel. Both lists show the 25 most recent executions of the request that you can see.
How long executions are kept
Each organization keeps a rolling number of executions, up to your plan's limit. See Plans and limits for the numbers.
The limit counts executions from all workspaces in the organization. About every 30 minutes, Collapy removes the oldest executions above the limit. Reaching the limit never stops you from sending requests — older history simply makes room for new.
This is separate from the monthly cloud execution quota, which limits how many requests the web app can send each month. See Usage and quotas and Plans and limits.
FAQ
Can I delete an execution?
No. Old executions are removed automatically when your organization passes its plan's limit.
Are executions of a private request private too?
Yes. They're visible to you and to the workspace's Admins and Owners, like the request itself. See Who can see executions.
Why does my token show as <redacted>?
Collapy doesn't store typed credentials in execution history. The request was sent with the real token. Only the stored copy shows <redacted>. See Credentials and secrets.
