Security

How Getman stores secrets, what it sends over the network, how scripts and responses are isolated, and the known defaults.

Getman is local-first. It has no account, no cloud service and no telemetry. Nothing leaves your machine except the requests you send. This page describes how the app protects secrets and what it does with the data it handles. It is not an independent audit.

Secrets

Where a secret can appear How it is protected
Secret variables, at global, project, collection or environment level The value is encrypted with AES-256-GCM in the local database. Each write uses a new random nonce. The JSON documents carry an empty value.
The encryption key A 256-bit key is stored in the operating system keychain (macOS Keychain or Windows Credential Manager), under the service name dev.getman.app. If no keychain is available, the key is kept in a master.key file in the app data folder, with owner-only permissions. The status bar then shows Key file instead of Keychain.
Tokens from OAuth 2.0 or a token flow Saved as secret environment variables, so they are encrypted in the same way.
History Request snapshots, URLs, headers and error text are redacted before they are stored. Secret values, Authorization and cookie headers, API-key headers, and token, key, secret, password and signature parameters are removed.
Exports: workspace backups, Postman files, the Git sync folder Secret values and literal auth secrets are blank. Exports are marked as redacted.
Script logs and test errors Redacted with the same list before they are shown or stored.
Repository importer .env files are read for their key names only. Values never reach the analyzer.

Projects are isolated from each other. Variables, secrets, cookies and history are loaded per project. Switching projects cannot reuse another project’s credentials.

Command line and agents

The installed command-line tool and the MCP server read the keychain key only after you allow it in Project settings → Command line & agents. That permission is stored in the keychain itself, so another program cannot turn it on silently. While it is off, the CLI exits with code 5. In workspace mode, secrets come from GETMAN_VAR_<KEY> environment variables and are never read from the sync folder.

Network

  • TLS certificate verification is on by default. You can turn it off for one request in the request’s Settings tab. The app shows a warning. There is no global switch. A custom CA certificate for the project is the safer choice.
  • Redirects are followed one at a time. When a redirect goes to another origin (a different scheme, host or port), the Authorization, Proxy-Authorization and Cookie headers are dropped, and so are headers that carry API keys, tokens, secrets or signatures. Request bodies for 307 and 308 redirects are not sent to the new origin.
  • Cookies are stored per project in the local database.
  • WebSocket connections refuse verifyTls: false for wss:// addresses.
  • Production safety: mutating requests (anything except GET, HEAD and OPTIONS) to environments in the project’s confirm list need an explicit confirmation, both in the editor and in the runner. The default list is production.

Scripts

Pre-request and post-response scripts run in QuickJS, compiled to WebAssembly. A script has a 32 MB memory limit and a 5 second time limit. It has no access to the file system, the network, timers or the page. It sees only the current project’s variables and the current request and response. Unsupported APIs, such as gm.sendRequest, throw an error.

Rendering responses

Response bodies from servers are untrusted. HTML previews use a sandboxed iframe with no scripts, no same-origin access and no navigation. JSON, XML and text render as plain text in the editor. Images render from a data URL.

Desktop surface

The desktop app grants its window only the core, dialog, clipboard, opener and window-state permissions, plus one internal command. Files are read only at paths you choose in a dialog. The repository importer scans with read-only access, skips node_modules, .git and build folders, and limits file size and type.

Known defaults

  • The Tauri content security policy is not yet set. It uses the scaffold default, which is null.
  • The app loads no remote code. Scripts, fonts and WebAssembly are bundled, and response HTML runs only in the script-free sandbox. A stricter policy is recommended, but it has not been verified in the packaged app.
  • Code signing is not configured yet. macOS builds are not signed, so the first launch needs Open from the context menu.