# Feature Request : Secured Template/Function node

**URL:** <https://discourse.nodered.org/t/feature-request-secured-template-function-node/88634>\
**Category:** Feature Requests\
**Tags:** function-node\
**Created:** [12 June 2024 08:13 UTC](https://discourse.nodered.org/t/feature-request-secured-template-function-node/88634 "2024-06-12T08:13:26Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [12 June 2024 09:20 UTC](https://discourse.nodered.org/t/feature-request-secured-template-function-node/88634/2 "2024-06-12T09:20:38Z")

</div>

If you want a way to safely store credentials that the Function node can use, then you can add them as environment variables at the Group/Subflow/Flow/Global level (depending on how widely accessible you need them to be). The env vars can be stored as credentials (so they won't get exposed in the editor) and the Function node can use `env.get('MY_TOKEN')` to retrieve the value.

It wouldn't be practical to have a 'secure' function node in the way you describe as credential values _never_ get returned to the editor - so you wouldn't be able to edit the content the next time you reloaded the editor.

---

_[View the full topic](https://discourse.nodered.org/t/feature-request-secured-template-function-node/88634)._
