# Secret Management

**URL:** <https://discourse.nodered.org/t/secret-management/3237>\
**Category:** General\
**Created:** [18 September 2018 11:46 UTC](https://discourse.nodered.org/t/secret-management/3237 "2018-09-18T11:46:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![johntdyer](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/johntdyer/32/2638_2.png) [@johntdyer](https://discourse.nodered.org/u/johntdyer)\
**Post date:** [18 September 2018 11:46 UTC](https://discourse.nodered.org/t/secret-management/3237/1 "2018-09-18T11:46:21Z")

</div>

Is there a way to move secrets out of my settings.js file and into another file which I can add to .gitignore ? I am looking for something similar to secrets.yaml on hass.

-John

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [18 September 2018 23:15 UTC](https://discourse.nodered.org/t/secret-management/3237/2 "2018-09-18T23:15:45Z")

</div>

> [@johntdyer](#):
>
> Is there a way to move secrets out of my settings.js file and into another file

Yes, absolutely. Since Node-RED uses Node.js, we can use the standard module form for including other files. You need a separate `.js` file that does an `export` of one or more variables/objects and then you use `require` in your settings.js.

---

<div class="post-metadata">

**Author:** ![janvda](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/janvda/32/234_2.png) [@janvda](https://discourse.nodered.org/u/janvda)\
**Post date:** [19 September 2018 07:02 UTC](https://discourse.nodered.org/t/secret-management/3237/3 "2018-09-19T07:02:17Z")

</div>

You can use [node-red-contrib-credentials](https://flows.nodered.org/node/node-red-contrib-credentials).  
In this node you can configure a set of credentials which will not be stored in the flows.json file but in the flows\_cred.json.

The extra nice thing is that this works perfectly together with the node-RED project feature as it will store those credentials in the encrypted \_cred.json on github. So the credentials are also backed up without being readable by the world.
