Variables¶
Organization Variables hold values Escape injects into scans across the organization: base URLs, seeded credentials, tokens. You create them once, then reference them in profile configuration as {{KEY}}. Secrets stay write-only in the UI. An External variable stores a pointer to a secret in Azure Key Vault. Scans do not resolve that pointer yet.
Creating, editing, or deleting variables, and linking vaults, requires Manage Vault Variables or Admin through a global role binding.
Organization Variables, with New Variable, a secret row, and a plain text row.
The line under the search box says key vault references are read on a schedule. Scans do not do that. External variables stay unresolved. See How Values Are Applied During a Scan.
Variable Types¶
| Type | What you store | In the UI |
|---|---|---|
| Plain text | A readable value | Shown in the list and when you open the row |
| Secret | A value Escape must not show again | Write-only after save; the list shows **** |
| External | A reference to a secret in Azure Key Vault | Source column shows the linked vault name |
New Variable with Secret selected. Reference the key as {{MY_SUPER_SECRET}}.
Create a Variable¶
- Open Organization, then Variables.
- Click New Variable.
- Set a Key. Scans reference it as
{{KEY}}. The key must beSCREAMING_SNAKE_CASE, start with a letter, stay within 128 characters, and be unique in the organization. Spaces inside the braces are fine:{{ API_BASE_URL }}resolves the same key as{{API_BASE_URL}}. - Pick a type, then set the value:
- Plain text or Secret: enter the value Escape should inject.
- External: pick the Azure Key Vault integration, the vault, and the secret name. If the vault is not linked yet, use Vault not listed? Link a new one.
- Click Create Variable.
Connect Azure Key Vault¶
External variables need an Azure Key Vault integration. Open Integrations, create an Azure Key Vault integration, and provide:
| Field | Value |
|---|---|
| Tenant ID | Directory (tenant) ID of your Entra ID tenant |
| Client ID | Application (client) ID of the registered app |
| Client Secret | Secret value created for the app |
Give the service principal:
- Reader on the subscriptions that hold the vaults Escape should list
- Key Vault Secrets User on each vault Escape should read
When no key vault integration exists yet, the External type in New Variable points you to Integrations to connect one.
Use a Variable in a Profile¶
For plain-text and secret variables, you can write {{KEY}} instead of a literal anywhere a string value appears in scan configuration (authentication credentials, headers, URLs, and similar fields). Escape replaces the reference with the variable's value when the scan starts.
On an authentication user, put the variable in the credential fields. Username below is {{USERNAME}} and Password is {{PASSWORD}}.
A profile user with {{USERNAME}} and {{PASSWORD}}.
JSON object keys are not templated. Only string values are.
If the name does not match a variable in the organization, Escape leaves the {{NAME}} text as written.
How Values Are Applied During a Scan¶
Escape reads referenced plain-text and secret variables once when the scan or validation starts, then reuses that snapshot for the whole run. A re-login later in the scan still uses the values from the start. Secrets must stay valid for the full scan duration.
External variables are not resolved for scans. A {{KEY}} that points at an external variable is left as written.
Redaction¶
In customer-facing scan outputs, Escape replaces occurrences of secret values with [REDACTED: KEY] when the value is at least 8 characters long. Plain text values aren't redacted. Values shorter than 8 characters are left as is, so short placeholders don't wipe common words from logs.
Avoid secrets whose clear text also appears in normal application data. A secret set to password, for example, would redact every password string in the output.
Related¶
- Authentication: where credentials often use
{{KEY}} - Manage Vault Variables: permission required to manage variables and link vaults
- Audit Logs: vault links, variable changes, and variable use by workflows