API Client Variables: Scopes, Precedence, and Secrets Explained
Hardcoding a URL, a token, or an ID directly into a request works until you
need to run that same request against a second environment, a second
account, or a teammate’s machine. Variables solve this: write
{{base_url}} once, and let it resolve to something different depending
on where and how the request runs.
The {{variable}} Syntax
Most API clients, HTTP Titan included, use double curly braces:
{{base_url}}/users/{{user_id}}. If you ever need a literal {{ in a
request body that isn’t meant to be interpolated, escaping it
(\{{not_a_variable}}) keeps it as plain text instead of triggering a
lookup.
Scopes
Variables typically live at more than one level, from broadest to narrowest:
- Collection variables — shared across every request in a collection, good for values that rarely change (a base URL, a fixed account ID).
- Environment variables — swapped as a set when you switch environments (local / staging / production), so the same collection points somewhere different without editing a single request.
- Local variables — set at runtime, typically from a pre-request script, and scoped to that one request execution.
Precedence
When the same variable name exists at more than one scope, the narrower scope wins: local overrides environment, environment overrides collection. This lets a script temporarily override a value (say, a freshly-fetched token) for one request without touching the environment variable everyone else’s requests still rely on.
Secrets
Not every variable should be visible in plain text — an API key or a password shouldn’t render openly on screen or end up readable in a shared export. A secret variable stores the same way but displays masked in the UI and gets redacted from anywhere it might otherwise be logged, while still resolving correctly when the request actually sends.
Testing Variables in HTTP Titan
HTTP Titan supports all three scopes described above — collection,
environment, and local (from pre-request scripts) — with {{name}}
interpolation and the same local-over-environment-over-collection
precedence. Environment variables can be marked secret, masking the value
in the UI while still resolving it correctly at send time — useful for the
bearer tokens, API keys, and OAuth credentials a
request’s auth usually depends on.