# Best Practice for storing settings and secrets

**URL:** <https://community.glideapps.com/t/best-practice-for-storing-settings-and-secrets/58490>\
**Category:** Ask for Help\
**Created:** [February 26, 2023, 1:55pm UTC](https://community.glideapps.com/t/best-practice-for-storing-settings-and-secrets/58490 "2023-02-26T13:55:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pigeonflight](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/pigeonflight/32/54611_2.png) [@pigeonflight](https://community.glideapps.com/u/pigeonflight)\
**Post date:** [February 26, 2023, 1:55pm UTC](https://community.glideapps.com/t/best-practice-for-storing-settings-and-secrets/58490/1 "2023-02-26T13:55:11Z")

</div>

Where is the best place to store app settings, things like colour options and api keys?  
I know I could place them in a table but I suspect that there may be a better way.

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [February 26, 2023, 2:32pm UTC](https://community.glideapps.com/t/best-practice-for-storing-settings-and-secrets/58490/2 "2023-02-26T14:32:09Z")

</div>

Unfortunately there isn’t.  
If you use API keys or other secrets anywhere in your App, then they are potentially exposed.

For these sorts of things, the current best practice would be to use them outside of Glide, and push the data they provide in via the Glide API.

For example, if you’re making an authenticated API call that returns some data, use an Integration tool such as Zapier or Make, or build your own custom code column and host it on GitHub\*.

For non-sensitive data that needs to be available globally, then storing it in the User Profiles table is a good choice. This is because the User Profile row can be accessed directly from anywhere in the App without the need to build relations and lookups, etc.

The issue of being able to securely handle things like API keys is something I’m hopeful that Glide may address later this year. They are certainly aware of this.

\*_actually, I’m not even sure if that would be a fully secure option. It could be that even with an externally hosted code column, the code is still downloaded and executed locally. This is something I’m not clear about._

---

<div class="post-metadata">

**Author:** ![Jeff\_Hager](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jeff_hager/32/43_2.png) [@Jeff\_Hager](https://community.glideapps.com/u/Jeff_Hager)\
**Post date:** [February 26, 2023, 3:07pm UTC](https://community.glideapps.com/t/best-practice-for-storing-settings-and-secrets/58490/3 "2023-02-26T15:07:06Z")

</div>

> [@Darren\_Murphy](#):
>
> It could be that even with an externally hosted code column, the code is still downloaded and executed locally

I think you are correct. GitHub isn’t processing code for all it’s users. It’s just storing the code and allowing you to import it into local projects where it’s ran locally.

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [February 26, 2023, 3:08pm UTC](https://community.glideapps.com/t/best-practice-for-storing-settings-and-secrets/58490/4 "2023-02-26T15:08:36Z")

</div>

Yes, I managed to confirm that with Mark. All code columns are executed locally. So that’s definitely not a strategy for securing secrets.

---

<div class="post-metadata">

**Author:** ![pigeonflight](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/pigeonflight/32/54611_2.png) [@pigeonflight](https://community.glideapps.com/u/pigeonflight)\
**Post date:** [February 26, 2023, 6:12pm UTC](https://community.glideapps.com/t/best-practice-for-storing-settings-and-secrets/58490/5 "2023-02-26T18:12:40Z")

</div>

Thanks for this Darren. This will affect how I design and implement apps with Glide.
