A variable can be asked, routed, or never kept at all.
Environments that build on each other, project variables, globals, and four flags that change what a variable is: Secret, Ask, Route and Ephemeral. The id of the person a request is about is asked for at the send; the token another request has to fetch first is routed; the thing that must never be written is not.
Where a value comes from
How a variable is filled is a block of its own in the table.
A row of a project's variables says not only what it is worth but how it comes to be worth it.
Masked, and kept out of the project
Shown as dots, left out of the project's folder on disk and out of exports. In a shared environment a secret row's name goes to the team store; its value stays on the computer that typed it.
No value kept. A form at the send
The person is asked when a request or a flow that reads it runs — as text, a number, yes or no, or a select with its choices. Every send, or once per session. At every request that uses it, at the requests you pick, or at those and at any other while it has no answer.
A request that fills it, run first
The row names the request that produces the value — the one that gets the token. When the variable is empty, that request runs first and its script sets it. Nobody has to remember the order.
Never written anywhere
Filled for the session only. Cleared at start and at a change of environment. What a script sets holds for the session the same way — listed under the table with Keep and Drop.
Shared with the team. Yours on top.
An environment is born Local only or Shared. A shared one travels with the project; what you type over it does not.
Based on
Staging based on Base, Base based on Defaults: the chain is walked and the nearest row wins. Copy an environment to another workspace and the chain is folded in.
My values
Your own overrides of a shared environment's rows. They win on send and never leave this computer. A secret row's value is always one of these.
External secrets
A value can be secret://vault/path#field: fetched at send from Vault, AWS, Azure, Google, 1Password, Doppler or Infisical, cached in memory, never written. Or secret://sonda/name from the team's own vault.
What is written, where, and under what.
Several accounts per computer, several workspaces per account. A workspace is a folder of files, every one of them sealed.
Sealed
A startup password seals every file — the workspace, its history, cookies, unsaved tab changes, the mail server — with Argon2id and AES-256-GCM. Setting, changing or removing it reseals everything or nothing, through a journal that finishes or undoes itself at the next start.
Nothing is written until Save
Every item is edited on its tab's copy; a dot marks the change. Unsaved changes survive a restart, sealed like the rest. In a team project, Save writes this computer alone; Save & Publish sends it.
History and Trash
300 sends per workspace, each the request as it went out, variables already filled: open it again or save it as a request. Deleted things wait 30 days in the Trash. The last known answer of every request is kept and shown when a send fails.
Incognito
Per request: no history, no cookie jar, the answer not kept.
Git-ready
A project can be kept as a folder: one YAML file per item, secrets apart in their own file. The Git pane drives your own git — init, commit, diff, log, branches, fetch, pull, push, clone — with tokens handed over for one command and never written to .git/config.
Backups
One file with the workspace, cookies, history, unsaved changes and the mail server; plain, or sealed with a passphrase. Offered before a workspace is deleted. Replace everything, or add.