Learn

Secrets from the environment

Don’t paste tokens into the suite. Write ${TOKEN} and pass the value when you run. AUTH: bearer ${TOKEN} is just an Authorization header.

Where ${TOKEN} comes from

Anything in ${NAME} is filled in at run time — your environment, a .env next to the suite, or -D NAME=value on the command line. Missing means the test fails with Undefined variable ${NAME}.

The playground always has a TOKEN. The CLI doesn’t, which is why this fails until you pass one.

CLI

Same mock as POST. In the repo: examples/users/auth.sapi.

SUITE: Users
URL: http://127.0.0.1:8765
HEADER Content-Type: application/json

TEST: Create User
  POST: /users
  AUTH: bearer ${TOKEN}
  BODY: {"name": "Jane", "email": "jane@example.com"}
  EXPECT: status == 201
snapapi mock mock.json --port 8765
snapapi auth.sapi

No token → a failed test, not a parse error:

  Create User
    Undefined variable ${TOKEN}. Set it in the environment or pass --env
  FAIL  0ms

  0 passed  1 failed  0ms

Then pass it. This mock ignores the header — you’re only checking that ${TOKEN} fills in:

snapapi auth.sapi -D TOKEN=secret
  Create User
    POST /users                       201  3ms
  PASS  4ms

  1 passed  0 failed  4ms

Or put TOKEN=secret in a .env next to the suite (don’t commit real secrets). SnapAPI picks that up on its own. --env path if you want a specific file. Cloned the repo? Copy examples/users/.env.example to examples/users/.env.

The local mock accepts any Authorization header. Against a real API a bad token is usually 401, not Undefined variable.