Which activity should be used to securely pass a sensitive password to an API as part of a login request without exposing it in the logs?
Trap 1: String variable
Using a standard String variable for passwords causes the value to be stored in plain text. This is a major security risk, as the password can be easily read in the logs, memory, or debugging watch windows. It fails to meet the minimum security standards required for handling authentication credentials in enterprise automation.
Trap 2: GenericValue variable
GenericValue is an untyped, flexible data container that does not provide any security features. It stores data as plain text strings, making it just as insecure as a standard String variable. It is not intended for managing sensitive data and should never be used for password handling in any automation project.
Trap 3: Array of Strings
An Array of Strings is a collection structure for holding multiple text values. It provides no encryption or security for the data stored within it. Like standard strings, the contents of the array are visible in memory and logs, making it entirely inappropriate for storing and passing sensitive passwords to an API.
- A
String variable
Why it fails: Using a standard String variable for passwords causes the value to be stored in plain text. This is a major security risk, as the password can be easily read in the logs, memory, or debugging watch windows. It fails to meet the minimum security standards required for handling authentication credentials in enterprise automation.
- B
SecureString variable
SecureString variables are purpose-built to store sensitive information in an encrypted memory format. They are supported in the HTTP Request activity, ensuring that the password remains protected from logging, inspection, or unauthorized access during the execution of the workflow. This is the correct, secure method for passing authentication secrets to APIs.
- C
GenericValue variable
Why it fails: GenericValue is an untyped, flexible data container that does not provide any security features. It stores data as plain text strings, making it just as insecure as a standard String variable. It is not intended for managing sensitive data and should never be used for password handling in any automation project.
- D
Array of Strings
Why it fails: An Array of Strings is a collection structure for holding multiple text values. It provides no encryption or security for the data stored within it. Like standard strings, the contents of the array are visible in memory and logs, making it entirely inappropriate for storing and passing sensitive passwords to an API.