/ SONDA · BUILD

A variable can be asked, routed, or never kept at all.

Environments that build on each other, project variables, globals, and four flags that change what a variable is: Secret, Ask, Route and Ephemeral. The id of the person a request is about is asked for at the send; the token another request has to fetch first is routed; the thing that must never be written is not.

SECRET · ASK · ROUTE · EPHEMERAL "BASED ON" CHAINS MY VALUES

Where a value comes from

1A value a script set for this send.
2The data-file row of the runner's iteration.
3The active environment, through its "Based on" chain — the environment's own rows win over its base's.
4The project's variables.
5Globals.
+{{$guid}}, {{$timestamp}}, {{$isoTimestamp}}, {{$randomInt}} anywhere. Typing {{ opens autocomplete with the values. An unresolved name is flagged under the URL.
/ THE FOUR FLAGS

How a variable is filled is a block of its own in the table.

A row of a project's variables says not only what it is worth but how it comes to be worth it.

Secret

Masked, and kept out of the project

Shown as dots, left out of the project's folder on disk and out of exports. In a shared environment a secret row's name goes to the team store; its value stays on the computer that typed it.

Ask

No value kept. A form at the send

The person is asked when a request or a flow that reads it runs — as text, a number, yes or no, or a select with its choices. Every send, or once per session. At every request that uses it, at the requests you pick, or at those and at any other while it has no answer.

Route

A request that fills it, run first

The row names the request that produces the value — the one that gets the token. When the variable is empty, that request runs first and its script sets it. Nobody has to remember the order.

Ephemeral

Never written anywhere

Filled for the session only. Cleared at start and at a change of environment. What a script sets holds for the session the same way — listed under the table with Keep and Drop.

/ ENVIRONMENTS

Shared with the team. Yours on top.

An environment is born Local only or Shared. A shared one travels with the project; what you type over it does not.

Based on

Staging based on Base, Base based on Defaults: the chain is walked and the nearest row wins. Copy an environment to another workspace and the chain is folded in.

My values

Your own overrides of a shared environment's rows. They win on send and never leave this computer. A secret row's value is always one of these.

External secrets

A value can be secret://vault/path#field: fetched at send from Vault, AWS, Azure, Google, 1Password, Doppler or Infisical, cached in memory, never written. Or secret://sonda/name from the team's own vault.

Secrets
/ THE WORKSPACE

What is written, where, and under what.

Several accounts per computer, several workspaces per account. A workspace is a folder of files, every one of them sealed.

Sealed

A startup password seals every file — the workspace, its history, cookies, unsaved tab changes, the mail server — with Argon2id and AES-256-GCM. Setting, changing or removing it reseals everything or nothing, through a journal that finishes or undoes itself at the next start.

Nothing is written until Save

Every item is edited on its tab's copy; a dot marks the change. Unsaved changes survive a restart, sealed like the rest. In a team project, Save writes this computer alone; Save & Publish sends it.

History and Trash

300 sends per workspace, each the request as it went out, variables already filled: open it again or save it as a request. Deleted things wait 30 days in the Trash. The last known answer of every request is kept and shown when a send fails.

Incognito

Per request: no history, no cookie jar, the answer not kept.

Git-ready

A project can be kept as a folder: one YAML file per item, secrets apart in their own file. The Git pane drives your own git — init, commit, diff, log, branches, fetch, pull, push, clone — with tokens handed over for one command and never written to .git/config.

Backups

One file with the workspace, cookies, history, unsaved changes and the mail server; plain, or sealed with a passphrase. Offered before a workspace is deleted. Replace everything, or add.

/ LOCKFLARE SONDA

Ask, Route and Ephemeral, in the free edition.

Workspace and scripting, listed →