Skip to content

Variables

Organization Variables hold values Escape injects into scans across the organization: base URLs, seeded credentials, tokens. You create them once, then reference them in profile configuration as {{KEY}}. Secrets stay write-only in the UI. An External variable stores a pointer to a secret in Azure Key Vault. Scans do not resolve that pointer yet.

Creating, editing, or deleting variables, and linking vaults, requires Manage Vault Variables or Admin through a global role binding.

Variables list with a secret and a plain text value Organization Variables, with New Variable, a secret row, and a plain text row.

The line under the search box says key vault references are read on a schedule. Scans do not do that. External variables stay unresolved. See How Values Are Applied During a Scan.

Variable Types

Type What you store In the UI
Plain text A readable value Shown in the list and when you open the row
Secret A value Escape must not show again Write-only after save; the list shows ****
External A reference to a secret in Azure Key Vault Source column shows the linked vault name

New Variable sidepanel with Secret selected New Variable with Secret selected. Reference the key as {{MY_SUPER_SECRET}}.

Create a Variable

  1. Open Organization, then Variables.
  2. Click New Variable.
  3. Set a Key. Scans reference it as {{KEY}}. The key must be SCREAMING_SNAKE_CASE, start with a letter, stay within 128 characters, and be unique in the organization. Spaces inside the braces are fine: {{ API_BASE_URL }} resolves the same key as {{API_BASE_URL}}.
  4. Pick a type, then set the value:
    • Plain text or Secret: enter the value Escape should inject.
    • External: pick the Azure Key Vault integration, the vault, and the secret name. If the vault is not linked yet, use Vault not listed? Link a new one.
  5. Click Create Variable.

Connect Azure Key Vault

External variables need an Azure Key Vault integration. Open Integrations, create an Azure Key Vault integration, and provide:

Field Value
Tenant ID Directory (tenant) ID of your Entra ID tenant
Client ID Application (client) ID of the registered app
Client Secret Secret value created for the app

Give the service principal:

  • Reader on the subscriptions that hold the vaults Escape should list
  • Key Vault Secrets User on each vault Escape should read

When no key vault integration exists yet, the External type in New Variable points you to Integrations to connect one.

Use a Variable in a Profile

For plain-text and secret variables, you can write {{KEY}} instead of a literal anywhere a string value appears in scan configuration (authentication credentials, headers, URLs, and similar fields). Escape replaces the reference with the variable's value when the scan starts.

On an authentication user, put the variable in the credential fields. Username below is {{USERNAME}} and Password is {{PASSWORD}}.

Authentication user with variable references in username and password A profile user with {{USERNAME}} and {{PASSWORD}}.

JSON object keys are not templated. Only string values are.

If the name does not match a variable in the organization, Escape leaves the {{NAME}} text as written.

How Values Are Applied During a Scan

Escape reads referenced plain-text and secret variables once when the scan or validation starts, then reuses that snapshot for the whole run. A re-login later in the scan still uses the values from the start. Secrets must stay valid for the full scan duration.

External variables are not resolved for scans. A {{KEY}} that points at an external variable is left as written.

Redaction

In customer-facing scan outputs, Escape replaces occurrences of secret values with [REDACTED: KEY] when the value is at least 8 characters long. Plain text values aren't redacted. Values shorter than 8 characters are left as is, so short placeholders don't wipe common words from logs.

Avoid secrets whose clear text also appears in normal application data. A secret set to password, for example, would redact every password string in the output.