# Is it a standard feature that when a flow is exported the credentials within them are not available in the exported JSON file?

**URL:** <https://discourse.nodered.org/t/is-it-a-standard-feature-that-when-a-flow-is-exported-the-credentials-within-them-are-not-available-in-the-exported-json-file/65322>\
**Category:** General\
**Created:** [19 July 2022 12:43 UTC](https://discourse.nodered.org/t/is-it-a-standard-feature-that-when-a-flow-is-exported-the-credentials-within-them-are-not-available-in-the-exported-json-file/65322 "2022-07-19T12:43:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shan](https://avatars.discourse-cdn.com/v4/letter/s/7ab992/32.png) [@Shan](https://discourse.nodered.org/u/Shan)\
**Post date:** [19 July 2022 12:43 UTC](https://discourse.nodered.org/t/is-it-a-standard-feature-that-when-a-flow-is-exported-the-credentials-within-them-are-not-available-in-the-exported-json-file/65322/1 "2022-07-19T12:43:04Z")

</div>

I have a subflow which encapsulates a MySQL node. I have added the credentials to them via subflow environment variables i.e., user enters them by clicking on the subflow node and this information is resolved using `$(<env_var_in_ui)`.

An interesting observation was the fact that upon exporting the flow, I observed that the necessary key `credentials` is not available.

I conducted a test for a simple flow with mysql (without subflows) and this also seems to be case there.

The only explanation I can come up with is maybe for security reasons where the plain-text password SHOULD NOT be made available.

Is this really the case?

## Env

Node-RED 2.2.2 using Docker

---

<div class="post-metadata">

**Author:** ![Shan](https://avatars.discourse-cdn.com/v4/letter/s/7ab992/32.png) [@Shan](https://discourse.nodered.org/u/Shan)\
**Post date:** [19 July 2022 13:40 UTC](https://discourse.nodered.org/t/is-it-a-standard-feature-that-when-a-flow-is-exported-the-credentials-within-them-are-not-available-in-the-exported-json-file/65322/2 "2022-07-19T13:40:37Z")

</div>

I think I have found the solution.

Node-RED will store the relevant credentials in the `flows_cred.json` and depending on the `credentialSecret` setting set in the `settings.js` the file will contain the ID and the password either in:

- `credentialSecret` -\> `true` encrypted manner
- `credentialSecret` -\> `false` in plain-text JSON

So maybe when exporting, the information is somehow packed into a respective ID.

> NOTE: assuming you have not changed the `flows_cred.json` file this information should be available when importing the exported flows.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [19 July 2022 13:48 UTC](https://discourse.nodered.org/t/is-it-a-standard-feature-that-when-a-flow-is-exported-the-credentials-within-them-are-not-available-in-the-exported-json-file/65322/3 "2022-07-19T13:48:36Z")

</div>

The editor doesn't have access to the credentials once they have been set. You cannot export them from the editor.

There have been various discussions about how best to allow the editor to export a flow that includes credentials - in a way that doesn't expose the credentials for anyone to access. There isn't a specific plan for it yet however.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [2 August 2022 13:49 UTC](https://discourse.nodered.org/t/is-it-a-standard-feature-that-when-a-flow-is-exported-the-credentials-within-them-are-not-available-in-the-exported-json-file/65322/4 "2022-08-02T13:49:08Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
