Skip to content

Environments and secrets

An environment is one place your application runs (UAT, Staging, Production smoke) together with the values and credentials a test needs there. Tests never contain addresses or passwords. They refer to the environment’s, so one test runs anywhere.

Environments

You need the Manage environments and secrets permission (Test Manager and Admin) to change environments. Everyone in the project can see environment names, variable names and which secrets exist, but never secret values.

  1. Environments → New environment and enter a name.

  2. Fill in:

    Field Notes
    Name e.g. Maximo UAT
    Application Optional: the application this environment hosts
    Variables (JSON) Any values tests need, as a JSON object. baseUrl is the conventional address.
    {
    "baseUrl": "https://uat.example.com/maximo",
    "apiUrl": "https://uat.example.com/api",
    "site": "BEDFORD"
    }

    Steps use them as {{baseUrl}}, {{apiUrl}}, {{site}}.

  3. Save environment.

Under Add a secret, type a NAME (e.g. APP_PASSWORD) and its value, then Add secret. The value is stored on the server and never shown again. The list only says it is set. × removes a secret.

Use it in a step as {{secret.APP_PASSWORD}}. On a Type step, also tick sensitive.

A configured environment

  • A secret is resolved only inside the runner, at the moment a step uses it.
  • Before use, its value is registered with a redaction filter. Every log line, step detail, error message and variable shown in a report is scrubbed of it, and appears as •••• or ***REDACTED***.
  • Recording never stores a secret’s value. If you type a value that matches a secret, the step records {{secret.NAME}}.
  • Custom code sees only the secrets the step explicitly declares.
  • The AI step writer receives secret names, never values.

Secrets lists every secret name used in the project, across all environments.

Secrets inventory

Column Meaning
Reference {{secret.NAME}}
Defined in Environments that have a value for it. × removes it from one.
Used by Tests that reference it
Status OK, Missing (a test uses it but no environment defines it, so the run will fail), or Unused (defined but no test uses it)

+ Add secret sets a secret in a chosen environment from here.

Check this page after importing tests or before a release. A Missing secret is a failure waiting to happen.

  • Editor: the selector above the steps. It starts on the first environment in the list, so check it before running.
  • Recorder and Pick: the dialog’s Environment field.
  • API: environmentId in POST /api/runs.
  • CLI: --env file.json with variables and secrets. See CLI.
  • Keep variable names identical across environments (baseUrl, apiUrl), so a test runs unchanged against any of them.
  • Use separate, low-privilege test accounts per environment. Never real people’s credentials.
  • Name environments after where they point (Maximo UAT), not who uses them.