| Account |
Not needed for anything. |
Needed for collections and environments. Signed out, you get a lightweight client that can send requests but can't save to collections or use
environments. Source
|
| Where your work lives |
A file in your app data folder, or plain YAML files in a project folder in your repo. Nothing leaves your computer unless you share it. |
Postman's cloud: "a cloud-based product that syncs your work when you're signed in"
(source). Since March 2026, Native Git can also
keep collections as files in your repo (source).
|
| Secrets |
In your OS keychain, never in the workspace file, exports or AI prompts. |
Local Vault on one machine, or a Shared Vault in Postman's cloud on paid plans.
Source
|
| Protocols |
REST, GraphQL, gRPC, server-sent events, MCP. |
REST, GraphQL, gRPC, server-sent events, MCP, WebSocket, Socket.IO, MQTT. |
| gRPC protos |
Synced from your git repo in the background (Buf workspaces too), FieldMask picker, warnings when the server sends fields your protos don't define. |
Server reflection, or .proto files you import. Source
|
| Chaining requests |
Flows: each step can use earlier responses, with checks, repeats and inputs. A notebook, or a canvas you drag values across. |
Scripts, and Postman Flows, a visual drag-and-drop canvas. |
| Scripting |
Script steps in flows, in Python, JavaScript, Ruby, Bash or any command. No scripts on single requests. |
Pre-request and post-response JavaScript. |
| CI runs, monitors, mocks, docs |
CI runs with the ofcors command. Monitors, mocks and docs: not yet. |
Yes: Postman CLI and Newman, monitors, mock servers, published docs. |
| Expired tokens |
Any login request can feed a token variable; it's refreshed when it expires and retried once on a 401. |
Token handling through auth helpers and scripts. |
| The app |
Native: a Rust core in a Tauri shell. |
Electron. Source |