[GH-ISSUE #5430] [bug]: Secrets in environments are visible and editable for whole team - self hosted #2088

Closed
opened 2026-03-16 23:07:48 +03:00 by kerem · 2 comments
Owner

Originally created by @SpectoIT on GitHub (Oct 2, 2025).
Original GitHub issue: https://github.com/hoppscotch/hoppscotch/issues/5430

Originally assigned to: @nivedin on GitHub.

Is there an existing issue for this?

  • I have searched existing issues and this bug hasn't been reported yet

Platform

Web App

Browser

Chrome

Operating System

macOS

Bug Description

We are self hosting Hoppscotch and:

  1. Created a workspace
  2. Shared access to some teammates
  3. Added three envs (Dev/Staging/Prod)
  4. Added variables in envs, like BASE_URL
  5. Added secrets in envs for ourselves, like USERNAME or PASSWORD
Image

We expected that secrets would be visible only to the user who set them, but any teammate can edit them or see them.

The documentation states:
Image

Is there a setting that has to be changed, or another workflow that we should use? We need to share some variables that are available to everyone, but each person will have their own login and other variables that should not be visible or overridden by others.

Deployment Type

Self-hosted (on-prem deployment)

Version

2025.9.1

Originally created by @SpectoIT on GitHub (Oct 2, 2025). Original GitHub issue: https://github.com/hoppscotch/hoppscotch/issues/5430 Originally assigned to: @nivedin on GitHub. ### Is there an existing issue for this? - [x] I have searched existing issues and this bug hasn't been reported yet ### Platform Web App ### Browser Chrome ### Operating System macOS ### Bug Description We are self hosting Hoppscotch and: 1. Created a workspace 2. Shared access to some teammates 3. Added three envs (Dev/Staging/Prod) 4. Added variables in envs, like BASE_URL 5. Added secrets in envs for ourselves, like USERNAME or PASSWORD <img width="1530" height="642" alt="Image" src="https://github.com/user-attachments/assets/bab500bb-002b-414a-8720-fd0818a24189" /> We expected that secrets would be visible **only to the user who set them**, but **any teammate** can edit them or see them. The [documentation](https://docs.hoppscotch.io/documentation/features/environments#types-of-variables-in-an-environment) states: <img width="1548" height="464" alt="Image" src="https://github.com/user-attachments/assets/facb35e1-1501-4e7d-9452-142b6adf6120" /> Is there a setting that has to be changed, or another workflow that we should use? We need to share some variables that are available to everyone, but each person will have their own login and other variables that should not be visible or overridden by others. ### Deployment Type Self-hosted (on-prem deployment) ### Version 2025.9.1
kerem 2026-03-16 23:07:48 +03:00
  • closed this issue
  • added the
    bug
    label
Author
Owner

@liyasthomas commented on GitHub (Oct 3, 2025):

This behavior is not expected. We are investigating this and will inform you as soon as we have a resolution.

<!-- gh-comment-id:3364335668 --> @liyasthomas commented on GitHub (Oct 3, 2025): This behavior is not expected. We are investigating this and will inform you as soon as we have a resolution.
Author
Owner

@jamesgeorge007 commented on GitHub (Oct 8, 2025):

Closing this issue since it is now addressed in the latest release. Please let us know if you have any questions.

<!-- gh-comment-id:3381069296 --> @jamesgeorge007 commented on GitHub (Oct 8, 2025): Closing this issue since it is now addressed in the latest release. Please let us know if you have any questions.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/hoppscotch#2088
No description provided.