← StreamView

Environment variables and secrets

Last updated: 18 September 2026

What it does

StreamView injects environment into a pane when that pane starts. You do not restart StreamView. Secrets live in named packs you attach to a stream — not in a repo .env, and not on every pane by default.

Where environment variables can live

A StreamView pane can get its environment from four places:

Place What is there
Windows User environment (registry HKCU\Environment) Variables set with setx / [Environment]::SetEnvironmentVariable(..., 'User'). Every new process sees them. StreamView re-reads User env each time a pane starts, so you don't restart the app.
Settings → Environment (packs) Named dotenv files, encrypted at %LOCALAPPDATA%\StreamView\env-packs\{name}.env. A stream attaches a pack; other panes do not get it.
A stream's Extra variables box One-off overlays on top of the pack (AWS_PROFILE=dev). Encrypted with the template.
Repo .env files Not read by StreamView. A project's .env (say, a Docker Compose file) belongs to whatever tool loads it.

Where to put a variable

Put it here When Who sees it
A named pack, attached to the stream Shared by a few panes (an agent and a shell on the same project) but not the rest Those streams, on next start. Encrypted on this machine.
The stream's Extra variables box One key that only this pane needs That stream only.
Windows User environment Every new process on this PC, including PowerShell outside StreamView Registry, not encrypted.
Neither The program reads a file or prompt instead —

Example: an agent pane that needs an API endpoint and token.

  1. Settings → Environment → New pack my-api (or Import from User environment if the variables are already set there).
  2. Save the lines below.
  3. Edit the stream → Environment pack = my-api.
  4. Restart that pane — not StreamView.
API_BASE_URL=http://localhost:8080
API_TOKEN=<your token>

What "encrypted" actually means

StreamView uses Windows DPAPI bound to your Windows login (CurrentUser). The JSON stores a blob starting svdpapi:v1:, not the token.

It does protect against:

  • Someone opening custom-profiles.json (including the OneDrive copy)
  • Config export files and backups of the data directory
  • Another Windows user on the same PC

It does not protect against:

  • Software running as you on this unlocked PC — StreamView decrypts the blob whenever the pane starts, and the child process then has the plaintext in its environment. Malware with your token could do the same.
  • Another machine. Ciphertext copied via OneDrive or a config bundle cannot be decrypted there. Re-enter the values on that PC, or keep machine-wide defaults in User env.
  • Echoing the variable inside the pane, or a tool that logs its environment

That is the same trust model as Windows User environment (also readable by anything running as you), with a smaller blast radius: only this stream gets the values, and the file on disk is not plaintext.

User environment is not more encrypted. It is only less likely to land in a synced JSON file.

Why not a .env in the repo?

A project file such as my-project/.env is the usual dotenv convention. StreamView does not write one, and should not:

  • Anything that reads the file (Grok, docker, dotenv, a type .env) needs plaintext on disk. Encryption and "the tool loads .env" cannot both be true.
  • That file sits in the working tree. It gets committed, synced, and opened by an agent that can already read the folder. Many agent configs (an MCP server block, for example) expand ${VAR} from process environment, not from a dotenv file — so a repo .env often isn't what the tool reads anyway.
  • A temporary plaintext .env that StreamView writes on start and deletes on stop still races a crash, still lands in the folder an agent can list, and still isn't needed if we inject the variables ourselves.

Settings → Environment

Packs, not a global dump. Open Settings → Environment, create or select a pack, edit KEY=VALUE lines, Save. Attach the pack on the stream. You do not restart StreamView.

Grok (or any agent) writes the same dotenv format to a file named after the pack:

%LOCALAPPDATA%\StreamView\env-incoming\my-api.env

StreamView merges it on the next pane start, or when you open Settings → Environment, then deletes it. Isolated screenshot instances use %STREAMVIEW_HOME%\local\env-incoming\.

Inherited environment

Every pane start re-reads Machine and User environment from Windows, then the attached pack, then the stream's extras. StreamView is long-lived, so a User var you set after it launched used to stay invisible until you restarted the whole app. Restarting the pane is enough.

On a name clash: extras win over the pack, the pack wins over User env.

Config export and other PCs

Settings → Data export includes the encrypted blob. Import on this PC restores it. Import on another PC keeps the blob but cannot read it — the editor shows a warning, and saving without typing new values leaves the blob untouched.

Still stuck? In the app, use Help → Contact support, or open a ticket here.

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.