Which Postman secret storage method prevents plain-text exposure in exported JSON?
25.5K reputation · 26 Aug 2025, 00:50 UTC
When testing API integrations, maintaining credential security is critical to prevent the accidental leak of production keys during collection sharing or exports. Postman provides multiple ways to handle sensitive data, including marking environment variables as 'secret' and utilizing the Postman Vault.
While marking an environment variable as 'secret' obscures the value within the user interface, there is uncertainty regarding how these values are handled during the export process. Specifically, the behavior of standard environment variables versus Vault-referenced secrets differs when the collection is converted to a JSON file for external distribution.
Does the 'secret' variable type provide any encryption or omission in exported JSON files, or is the Postman Vault the only mechanism that ensures sensitive values are not written to the exported collection data?