Environment
Named {{var}} sets, generated values, sealed secrets, and inheritance — point the same attacks at staging or prod by switching one dropdown.
An environment is a named set of variables that expand as {{variable_name}}
wherever Hugin builds a request (Community). Switch the active environment from the
header; its enabled variables (and any inherited from a parent environment) are
available everywhere.

What you can store and do
Each variable has a key, a value, a description, and a secret flag (secret values render masked and are scrubbed to empty on export). Beyond static values:
- Extraction rules — pull a value out of a response with a regex and auto-populate a variable.
- Pre-request hooks — run a small request that extracts a variable before your sends (for a fresh token), with host/port/TLS overrides.
- Inheritance — chain environments via a parent so shared variables live in one place.
Generated values: UUID, timestamp, hash, encode
Hugin ships built-in generators that start with $. Write one where a request or
payload is built and Hugin substitutes a computed value — no Decoder round-trip, no
hand-precomputing.
| Generator | Produces |
|---|---|
{{$uuid}} | A random UUID v4 |
{{$timestamp}} / {{$isoDate}} | Current UTC time, ISO 8601 (2026-06-17T14:30:00Z) |
{{$unixtime}} | Current Unix time in seconds |
{{$date}} | Current UTC date (2026-06-17) |
{{$randomInt}} | A random integer, 0–999999 |
{{$randomHex:N}} | N random hex characters (max 128) |
{{$randomString:N}} | N random lowercase-alphanumeric characters (max 128) |
{{$base64:value}} | Base64 of value |
{{$urlEncode:value}} | URL-encoded value |
{{$md5:value}} | MD5 of value, hex |
{{$sha256:value}} | SHA-256 of value, hex |
Names are case-insensitive. Only the first colon splits the name from its argument,
so {{$base64:user:pass}} encodes the whole user:pass. A name Hugin doesn't
recognize, or a parameterized generator with no argument, is left untouched. A
stored variable with the same name wins over the generator.
These resolve when Hugin builds the request — in Intruder requests and payloads,
and in pre-request hook requests. A pre-request hook recomputes its generators
each time it fires, so a hook that sends {{$timestamp}} or {{$uuid}} carries a
fresh value on every fire. The plain {{var}} variables and fallbacks below expand
everywhere in the list at the end of this page.
In an Intruder request or a pre-request hook, that means:
Authorization: Basic {{$base64:user:pass}}— base64 a credential inline.X-Signature: {{$sha256:...}}— drop a hash where the target expects one.{{$urlEncode:...}}— URL-encode a payload value without precomputing it.
Defaults, prefixes, and nested variables
- Defaults —
{{NAME|fallback}}resolves to the literalfallbackwhenNAMEisn't set, so a request still fires before you've filled the variable in:Authorization: Bearer {{TOKEN|anonymous}}. - Burp-compatible prefixes —
{{env:NAME}}and{{vars.NAME}}resolve to the same variable as the bare{{NAME}}. Paste a Burp request or Match & Replace rule that uses the explicit prefix and it still resolves against the active environment. - Nesting — a variable's value can reference another. Set
HOSTtoapi.{{TENANT}}.exampleandTENANTtoacme, and{{HOST}}resolves toapi.acme.example. Hugin re-resolves a few levels deep; a circular reference stops safely instead of hanging. - An unknown
{{...}}with no fallback is left in place verbatim, so a server-side template or a typo stays visible rather than vanishing.
Keep secrets out of the file
Flag a variable secret and its value renders masked (********) everywhere — the
variable list, exports, and logs. Toggle the eye to read or edit it in place.
Secret values never sit in the environments file as plaintext — on save Hugin seals them in your OS keyring (or an encrypted file when no keyring is available). The saved file keeps only an empty placeholder; the real value loads back on the next start.
Export scrubs every secret value to an empty string — the keys, descriptions, and secret flags travel, but the values do not. After importing an environment, re-type each secret.
Move environments in and out
- Import — paste a JSON environment back into the view to restore it. Driving
Hugin from an AI agent over MCP, the import action also reads
.envfiles, Postman environment exports, and Insomnia environment exports. - Secret auto-detection — on import, keys whose names contain
token,key,password,secret,bearer, orauthare flagged secret automatically. - Export — copy the whole environment as JSON (secrets scrubbed) to share, back up, or move to another machine.
- Duplicate — copy an environment, including its variables, extraction rules, hooks, and parent link, to branch a profile (prod → prod-as-lowpriv) without retyping everything.
Compare two environments for drift
Compare the selected environment against another to see which variable names each one
holds and which they share. This catches parity drift before it bites: if prod
defines ADMIN_TOKEN and staging doesn't, a set of Repeater tabs or a campaign you
switch from staging to prod won't quietly fire with a missing variable.
How variables stack up
- Inheritance — give an environment a parent and it inherits the parent's variables; the child's own keys override the parent's. Chains run up to 8 levels deep — for example Defaults → Tenant → Region → Persona — and a disabled variable drops out of the merge.
- Setting a parent — the Environment view preserves an inheritance link once it exists, but it doesn't show a parent picker. Set or change a parent by driving Hugin from an AI agent over MCP.
- Per-tab override — in Repeater, a single tab can override a variable just for
itself. Point one tab at a different
{{BASE_URL}}or persona without touching the active environment for every other tab. - Runtime overrides — a value a pre-request hook extracts during the session, a fresh CSRF token or an OAuth bearer, rides on top of the active environment and survives switching environments, so flipping from staging to prod mid-session doesn't wipe a live token. Drop them deliberately with the Clear runtime overrides toolbar action.
Precedence at send time, highest wins:
- a literal value typed directly in the request
- a value the tab extracted from an earlier response
- a per-tab override
- the active environment — its own variables first, then each parent up the chain
Where {{var}} works
The variables expand in Repeater, Intruder, bambda scripts, workflows, and campaigns, and feed the Scanner, Crawler, Sequencer, Comparer, Discover, and FFuzzer.
Keep a {{base_url}} and a {{token}} per target and you can point the same
Repeater tabs and campaigns at staging or prod by switching the active environment.