Secrets
Keep passwords and tokens out of your tests: encrypted on your PC, per environment.
A secret is a password, token or API key that a test needs but should never be written into it. Secrets are stored encrypted on your PC, separately for each environment (dev, staging, prod…), and tests refer to them by name: {{secret:password}}.
Add a secret
- Open Project settings (gear next to the environment selector) → Secrets.
- Choose the environment.
- Enter a name (e.g.
password) and the value. It is saved immediately.
Saved secrets are listed by name, with the value shown as ••••••. A value can’t be read back, only replaced (Replace) or deleted. Add the same name in each environment, with that environment’s value.
Use it in a step
On a step card, click { } → Secrets (env) and pick the name, or write {{secret:name}}. At run time the test uses the value of the active environment: switch the environment and the same test logs in with that server’s password. If the secret is missing in the active environment, the card warns you and the test stops with a clear message (Secret “password” is not set for this environment…).
Recorded passwords: Save as secret
When you record typing into a password field, the card shows Password saved in clear text in the test with a Save as secret button. One click stores the password as a secret of the active environment and replaces the value with {{secret:password}}. Until you convert it, the password is masked (••••••) in the card, notifications, Manual Steps and Gherkin, but is still in plain text in the code.
How secrets are protected
- Encrypted with Windows data protection and stored in the app’s data, outside your project folders: never written into test files, exports or anything you commit.
- Masked as
••••••in the Runner output, in error messages and in step screenshots. - Renaming an environment keeps its secrets; deleting the project deletes them.
Secrets in an exported project
Exported projects contain no secret values. Their README.md lists the environment variables to set where the tests run — one per secret, named QA_SECRET_ plus the name in capitals.
Something unclear or missing? Write to info@actify-studio.com.