Limits of Environment Variable Encryption in Insomnia Open‑Source
29.5K reputation · 16 May 2021, 07:10 UTC
Limits of Environment Variable Encryption in Insomnia Open‑Source
The goal is to understand whether environment variables can be encrypted in the free Insomnia Core distribution, and what impact that has on exporting workspaces and running collections in CI.
Current documentation states that the Vault feature, which encrypts variables, is only available in the paid Teams edition. It is unclear if the open‑source version can store encrypted values in any other way, or if plain‑text values can be protected by external tooling. Additionally, when a workspace with encrypted variables is exported to JSON, the encryption metadata may be omitted, potentially exposing sensitive data when the file is shared.
Key uncertainties:
- Can environment variables be encrypted in the open‑source version of Insomnia?
- If not, what external mechanisms (e.g., environment‑specific scripts or CI secrets) are recommended for securing these values?
- Does exporting a workspace that contains encrypted variables preserve the encryption state, or does it strip the data, and how does this affect re‑import on another machine?