Strings and Interpolation

Text and templates

Single- and double-quoted strings are plain text. Use backticks and ${expression} to insert values. Backtick templates can span multiple lines.

name = "api"
path = '/health'
endpoint = `https://${name}.example.test${path}`
message = `Checking ${endpoint}`
print(message)

Plain strings support escapes such as \n, \t, and \\. Writing ${name} inside ordinary quotes does not interpolate it.

Raw strings and bytes

path = r"C:\Users\tester"
payload = b"\x41\x42"
magic = h"deadbeef"
  • r"text" keeps backslashes as written, useful for paths and regular expressions.
  • b"text" produces bytes and supports escapes.
  • h"deadbeef" produces bytes from hexadecimal pairs.

Commands and secrets

Prefer a module’s named parameters over building command strings. For shell, write the command as a literal or backtick template, not a prebuilt string variable. Avoid raw(...) with untrusted data: it bypasses command-value quoting.

Treat credentials and strings derived from them as sensitive. Display masking is not a reason to print secrets or send them to an untrusted endpoint. See Inputs and credentials.

Improve team velocity with
better security and privacy.