Environment variables and secrets
Last updated: 18 September 2026
What it does
StreamView injects environment into a pane when that pane starts. You do not restart StreamView. Secrets live in named packs you attach to a stream — not in a repo .env, and not on every pane by default.
Where environment variables can live
A StreamView pane can get its environment from four places:
| Place | What is there |
|---|---|
Windows User environment (registry HKCU\Environment) |
Variables set with setx / [Environment]::SetEnvironmentVariable(..., 'User'). Every new process sees them. StreamView re-reads User env each time a pane starts, so you don't restart the app. |
| Settings → Environment (packs) | Named dotenv files, encrypted at %LOCALAPPDATA%\StreamView\env-packs\{name}.env. A stream attaches a pack; other panes do not get it. |
| A stream's Extra variables box | One-off overlays on top of the pack (AWS_PROFILE=dev). Encrypted with the template. |
Repo .env files |
Not read by StreamView. A project's .env (say, a Docker Compose file) belongs to whatever tool loads it. |
Where to put a variable
| Put it here | When | Who sees it |
|---|---|---|
| A named pack, attached to the stream | Shared by a few panes (an agent and a shell on the same project) but not the rest | Those streams, on next start. Encrypted on this machine. |
| The stream's Extra variables box | One key that only this pane needs | That stream only. |
| Windows User environment | Every new process on this PC, including PowerShell outside StreamView | Registry, not encrypted. |
| Neither | The program reads a file or prompt instead | — |
Example: an agent pane that needs an API endpoint and token.
- Settings → Environment → New pack
my-api(or Import from User environment if the variables are already set there). - Save the lines below.
- Edit the stream → Environment pack =
my-api. - Restart that pane — not StreamView.
API_BASE_URL=http://localhost:8080
API_TOKEN=<your token>
What "encrypted" actually means
StreamView uses Windows DPAPI bound to your Windows login (CurrentUser). The JSON stores a blob starting svdpapi:v1:, not the token.
It does protect against:
- Someone opening
custom-profiles.json(including the OneDrive copy) - Config export files and backups of the data directory
- Another Windows user on the same PC
It does not protect against:
- Software running as you on this unlocked PC — StreamView decrypts the blob whenever the pane starts, and the child process then has the plaintext in its environment. Malware with your token could do the same.
- Another machine. Ciphertext copied via OneDrive or a config bundle cannot be decrypted there. Re-enter the values on that PC, or keep machine-wide defaults in User env.
- Echoing the variable inside the pane, or a tool that logs its environment
That is the same trust model as Windows User environment (also readable by anything running as you), with a smaller blast radius: only this stream gets the values, and the file on disk is not plaintext.
User environment is not more encrypted. It is only less likely to land in a synced JSON file.
Why not a .env in the repo?
A project file such as my-project/.env is the usual dotenv convention. StreamView does not write one, and should not:
- Anything that reads the file (Grok, docker, dotenv, a
type .env) needs plaintext on disk. Encryption and "the tool loads.env" cannot both be true. - That file sits in the working tree. It gets committed, synced, and opened by an agent that can already read the folder. Many agent configs (an MCP server block, for example) expand
${VAR}from process environment, not from a dotenv file — so a repo.envoften isn't what the tool reads anyway. - A temporary plaintext
.envthat StreamView writes on start and deletes on stop still races a crash, still lands in the folder an agent can list, and still isn't needed if we inject the variables ourselves.
Settings → Environment
Packs, not a global dump. Open Settings → Environment, create or select a pack, edit KEY=VALUE lines, Save. Attach the pack on the stream. You do not restart StreamView.
Grok (or any agent) writes the same dotenv format to a file named after the pack:
%LOCALAPPDATA%\StreamView\env-incoming\my-api.env
StreamView merges it on the next pane start, or when you open Settings → Environment, then deletes it. Isolated screenshot instances use %STREAMVIEW_HOME%\local\env-incoming\.
Inherited environment
Every pane start re-reads Machine and User environment from Windows, then the attached pack, then the stream's extras. StreamView is long-lived, so a User var you set after it launched used to stay invisible until you restarted the whole app. Restarting the pane is enough.
On a name clash: extras win over the pack, the pack wins over User env.
Config export and other PCs
Settings → Data export includes the encrypted blob. Import on this PC restores it. Import on another PC keeps the blob but cannot read it — the editor shows a warning, and saving without typing new values leaves the blob untouched.
Related
Still stuck? In the app, use Help → Contact support, or open a ticket here.