# API KEY security for users exporting flows

**URL:** <https://discourse.nodered.org/t/api-key-security-for-users-exporting-flows/77671>\
**Category:** Developing Nodes\
**Tags:** security\
**Created:** [17 April 2023 18:20 UTC](https://discourse.nodered.org/t/api-key-security-for-users-exporting-flows/77671 "2023-04-17T18:20:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![HaroldPetersInskipp](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/haroldpetersinskipp/32/42319_2.png) [@HaroldPetersInskipp](https://discourse.nodered.org/u/HaroldPetersInskipp)\
**Post date:** [17 April 2023 18:20 UTC](https://discourse.nodered.org/t/api-key-security-for-users-exporting-flows/77671/1 "2023-04-17T18:20:36Z")

</div>

Recently I've seen a post where a user exposed their API KEY when exporting a flow using one of my nodes. What changes can I make to a node to prevent users from accidentally sharing their API KEY when they export a flow that contains that node?

---

<div class="post-metadata">

**Author:** ![kevinGodell](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kevingodell/32/27040_2.png) [@kevinGodell](https://discourse.nodered.org/u/kevinGodell)\
**Post date:** [17 April 2023 18:54 UTC](https://discourse.nodered.org/t/api-key-security-for-users-exporting-flows/77671/2 "2023-04-17T18:54:27Z")

</div>

You can use the credentials feature. It causes the setting to be saved in the credentials file instead of the flows file.

---

<div class="post-metadata">

**Author:** ![HaroldPetersInskipp](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/haroldpetersinskipp/32/42319_2.png) [@HaroldPetersInskipp](https://discourse.nodered.org/u/HaroldPetersInskipp)\
**Post date:** [17 April 2023 19:02 UTC](https://discourse.nodered.org/t/api-key-security-for-users-exporting-flows/77671/3 "2023-04-17T19:02:17Z")

</div>

Thank you, I thought I glanced over it awhile back somewhere but now I've found the [documentation](https://nodered.org/docs/creating-nodes/credentials) for it.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [17 April 2023 19:02 UTC](https://discourse.nodered.org/t/api-key-security-for-users-exporting-flows/77671/4 "2023-04-17T19:02:54Z")

</div>

Are you developing a node?

(please move this thread to #developing-nodes if yes)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [1 May 2023 19:03 UTC](https://discourse.nodered.org/t/api-key-security-for-users-exporting-flows/77671/5 "2023-05-01T19:03:06Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
