# Feature Request: Please add credential input to Inject and Change Node

**URL:** <https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645>\
**Category:** Feature Requests\
**Created:** [25 February 2025 16:46 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645 "2025-02-25T16:46:38Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![HarryPottar](https://avatars.discourse-cdn.com/v4/letter/h/bb73d2/32.png) [@HarryPottar](https://discourse.nodered.org/u/HarryPottar)\
**Post date:** [25 February 2025 16:46 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645/1 "2025-02-25T16:46:38Z")

</div>

Hello,

I communicate with multiple instances of the same API.

I have common flows; the only difference is the host and the credentials.

I use a change node to set the message values passed into the connector.  
However, I have the credentials in plain text; it would be great to have a credential input in the change node and the inject node.

TIA  
Harry

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [25 February 2025 17:06 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645/2 "2025-02-25T17:06:15Z")

</div>

Hi @HarryPottar

I've raised [FR: Add credential type to Change/Inject nodes · Issue #5063 · node-red/node-red · GitHub](https://github.com/node-red/node-red/issues/5063) to track this request.

One workaround available today would be set env vars on the Flow properties (which can be set as credentials) and then reference it in the Inject/Change nodes as `env` property. That may be a good enough solution to not warrant adding anything new to the nodes - but we'll see.

Nick

---

<div class="post-metadata">

**Author:** ![HarryPottar](https://avatars.discourse-cdn.com/v4/letter/h/bb73d2/32.png) [@HarryPottar](https://discourse.nodered.org/u/HarryPottar)\
**Post date:** [25 February 2025 19:29 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645/3 "2025-02-25T19:29:25Z")

</div>

Thanks Nick,

I know how to system level, and sub flow environment vars, how do you set env var for a flow(tab).

Thanks  
Harry

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [25 February 2025 19:31 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645/4 "2025-02-25T19:31:25Z")

</div>

Open the tab properties and there is an env vars sub-tab. Was introduced ~v3

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [25 February 2025 21:04 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645/5 "2025-02-25T21:04:01Z")

</div>

Groups also have that capability.

---

<div class="post-metadata">

**Author:** ![RvG](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rvg/32/96613_2.png) [@RvG](https://discourse.nodered.org/u/RvG)\
**Post date:** [26 February 2025 09:12 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645/6 "2025-02-26T09:12:28Z")

</div>

I'm using a third party node 'credentials' to safely store secrets in a flow.

---

<div class="post-metadata">

**Author:** ![ThingsTinkerer](https://avatars.discourse-cdn.com/v4/letter/t/91b2a8/32.png) [@ThingsTinkerer](https://discourse.nodered.org/u/ThingsTinkerer)\
**Post date:** [10 March 2025 12:41 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645/7 "2025-03-10T12:41:08Z")

</div>

I use .env file for all my secrets (independent of node red). My secrets are scattered all over, for example in urls or other fields which isn't covered by node red. I think the whole idea of having a built-in password vault is doomed to be incomplete because secrets can be used in so many places that will be infeasible to cover systematically.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [10 March 2025 13:23 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645/8 "2025-03-10T13:23:59Z")

</div>

Just remember that environment variables are NOT a security feature 🙂

They are fine as long as nothing has access to the OS - if it does, then the content of the variables can always be accessed I believe. (Hint - Node-RED has access to the OS!).

---

<div class="post-metadata">

**Author:** ![ThingsTinkerer](https://avatars.discourse-cdn.com/v4/letter/t/91b2a8/32.png) [@ThingsTinkerer](https://discourse.nodered.org/u/ThingsTinkerer)\
**Post date:** [11 March 2025 18:26 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645/9 "2025-03-11T18:26:04Z")

</div>

Yeah the secrets are used by node red, so necessarily it has access to them. What it does is remove all secrets from source code, so source control or copy-pasting won't compromise anything. That's more than the built-in encryption in node red does anyway.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [12 March 2025 14:34 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645/10 "2025-03-12T14:34:32Z")

</div>

> [@ThingsTinkerer](#):
>
> Yeah the secrets are used by node red

Sorry, for clarity, the point I was making is that the OS holds the environment variables in memory so any app that has access to OS features can read or even change the content of those variables.

In NR's case, if, for example, you had a cloud service password in an env, any application on the server could get hold of it. That includes but isn't limited to NR. But in NR's case, anyone with access to the Editor can display all env variables if they want to. So environment variables can only ever be considered a CONVENIENCE and NOT a _security feature_. Too many people forget this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [10 June 2025 14:34 UTC](https://discourse.nodered.org/t/feature-request-please-add-credential-input-to-inject-and-change-node/95645/11 "2025-06-10T14:34:43Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
