Secure Postman access for AI agents
Manage Postman workspaces, collections, environments, specs, mocks, and monitors, and search Postman's Learning Center, via Postman's official MCP server.
Postman is where API design, testing, and documentation live for most engineering orgs, which means an agent with Postman access can read collections and specs to answer questions, but can just as easily publish a mock server, delete a workspace, or rewrite a monitor nobody asked it to touch. Adding Postman here puts every tool call through your policies and onto the audit log, so agents can explore your API surface without quietly reshaping it.
Server URL: https://mcp.postman.com/mcp
Credential modes
Postman supports per-org dynamic registration only, so there is no app to create on Postman's side and no client ID or secret to enter. See Credential modes for how it compares with Use SecureAuth's app and Bring your own app.
Before you begin
- A Postman account that can reach the workspaces and collections your agents need.
- Administrator access to your Agent Authority workspace, to add the resource.
Setup
- In the Agent Authority console, go to Tools & Services and click Add Resource.
- Select Postman from the catalog.
- On Choose how to install Postman, click Per-org dynamic registration. Selecting it adds the resource right away with its tools pre-configured.
Dynamic client registration
When you add the resource, the gateway registers its own OAuth client with Postman, the credential that lets it sign users in. Postman's own team, workspace, and role-based permissions still apply, so an agent can only reach what the person who signed in could already reach.
Verify the connection
The gateway syncs the Postman tools automatically. To check the connection end to end, ask your agent to run a request:
Get my Postman userIf your Postman user details come back, the connection is working.
How users connect
Access is per user. Each additional user connects their own Postman account the first time their agent calls a Postman tool: the gateway returns a sign-in link, the user authorizes once, and the tools work from then on. Go to Connections to manage linked accounts.
Available tools
Postman exposes 124 tools. They are grouped below; the resource's Overview tab shows the authoritative per-tool list under Available Tools once installed.
| Tool | Tags | Description |
|---|---|---|
getAuthenticatedUser | read-only | Get information about the authenticated user |
getEnabledTools | read-only | List the tools enabled for this connection: run this first if a tool seems missing |
createWorkspace | write | Create a new workspace |
getWorkspace | read-only | Get information about a workspace |
getWorkspaces | read-only | Get all workspaces you have access to |
updateWorkspace | write | Update a workspace's property, such as its name or visibility |
deleteWorkspace | destructive | Delete an existing workspace |
getWorkspaceGlobalVariables | read-only | Get a workspace's global variables |
updateWorkspaceGlobalVariables | destructive | Replace a workspace's global variables |
getWorkspaceTags | read-only | Get all the tags associated with a workspace |
updateWorkspaceTags | destructive | Update a workspace's associated tags |
addWorkspaceToPrivateNetwork | write | Publish a workspace to your team's Private API Network |
removeWorkspaceFromPrivateNetwork | write | Remove a workspace from your team's Private API Network |
listPrivateNetworkWorkspaces / listPrivateNetworkAddRequests | read-only | List workspaces on the Private API Network, or pending add requests |
respondPrivateNetworkAddRequest | write | Approve or reject a request to add a workspace to the Private API Network |
createCollection | write | Create a collection in the Postman Collection v2.1.0 format |
getCollection | read-only | Get information about a collection |
getCollections | read-only | Get all collections in a workspace |
putCollection | destructive | Replace the contents of a collection |
patchCollection | write | Update specific collection information, such as its name, events, or its variables |
deleteCollection | destructive | Delete a collection |
duplicateCollection | write | Create a duplicate of the given collection in another workspace |
getDuplicateCollectionTaskStatus / getCollectionUpdatesTasks | read-only | Check the status of an async collection duplication or update task |
generateCollection / generateSpecFromCollection | write | Generate a collection from a spec, or a spec from a collection |
getCollectionTags | read-only | Get all the tags associated with a collection |
updateCollectionTags | destructive | Update a collection's associated tags |
createCollectionFork | write | Create a fork from an existing collection into a workspace |
getCollectionForks | read-only | Get a collection's forked collections |
getCollectionsForkedByUser | read-only | Get a list of all the authenticated user's forked collections |
mergeCollectionFork | destructive | Merge a forked collection into its parent (deprecated) |
pullCollectionChanges | destructive | Pull the changes from a parent (source) collection into the forked collection |
getSourceCollectionStatus | read-only | Check whether a fork differs from its parent collection |
createCollectionFolder | write | Create a folder in a collection |
getCollectionFolder | read-only | Get information about a folder in a collection |
updateCollectionFolder | write | Update a folder in a collection |
deleteCollectionFolder | destructive | Delete a folder in a collection |
transferCollectionFolders | write | Copy or move folders into a collection or folder |
createCollectionRequest | write | Create a request in a collection |
getCollectionRequest | read-only | Get information about a request in a collection |
updateCollectionRequest | write | Update a request in a collection |
deleteCollectionRequest | destructive | Delete a request in a collection |
transferCollectionRequests | write | Copy or move requests into a collection or folder |
createCollectionResponse | write | Create a request response in a collection |
getCollectionResponse | read-only | Get information about a response in a collection |
updateCollectionResponse | write | Update a response in a collection |
deleteCollectionResponse | destructive | Delete a response in a collection |
transferCollectionResponses | write | Copy or move responses into a request |
createCollectionComment | write | Create a comment on a collection |
getCollectionComments | read-only | Get all comments left by users in a collection |
updateCollectionComment | write | Update a comment on a collection |
deleteCollectionComment | destructive | Delete a comment from a collection |
updateApiCollectionComment | write | Update a comment on an API's collection |
deleteApiCollectionComment | destructive | Delete a comment from an API's collection |
createFolderComment | write | Create a comment on a folder |
getFolderComments | read-only | Get all comments left by users in a folder |
updateFolderComment | write | Update a comment on a folder |
deleteFolderComment | destructive | Delete a comment from a folder |
createRequestComment | write | Create a comment on a request |
getRequestComments | read-only | Get all comments left by users in a request |
updateRequestComment | write | Update a comment on a request |
deleteRequestComment | destructive | Delete a comment from a request |
createResponseComment | write | Create a comment on a response |
getResponseComments | read-only | Get all comments left by users in a response |
updateResponseComment | write | Update a comment on a response |
deleteResponseComment | destructive | Delete a comment from a response |
resolveCommentThread | write | Resolve a comment and any associated replies |
getTaggedEntities | read-only | Get workspaces, APIs, and collections by tag (Enterprise plan) |
createEnvironment | write | Create an environment |
getEnvironment | read-only | Get information about an environment |
getEnvironments | read-only | Get all of your environments |
putEnvironment | destructive | Replace all the contents of an environment with the given information |
patchEnvironment | write | Update specific environment properties, such as its name and variables |
deleteEnvironment | destructive | Delete an environment |
createMock | write | Create a mock server in a collection |
getMock | read-only | Get information about a mock server |
getMocks | read-only | Get all active mock servers |
updateMock | write | Update a mock server |
deleteMock | destructive | Delete a mock server |
publishMock | write, external | Publish a mock server |
unpublishMock | write | Unpublish a mock server |
createMockServerResponse | write | Create a server response on a mock server |
getMockServerResponse | read-only | Get the full details of a mock server response |
getMockServerResponses | read-only | Get all server responses configured for a mock server |
updateMockServerResponse | write | Update a mock server response's name, status code, body, headers, or language |
deleteMockServerResponse | destructive | Delete a server response from a mock server |
createMonitor | write | Create a monitor |
getMonitor | read-only | Get information about a monitor |
getMonitors | read-only | Get all monitors |
updateMonitor | write | Update a monitor's configurations |
deleteMonitor | destructive | Delete a monitor |
runMonitor | write | Run a monitor and return its run results |
getMonitorRunResults | read-only | Get results for a monitor run, with trimmed execution logs |
listMonitorExecutions / listRunsForExecution | read-only | List a monitor's executions, or the runs within one |
createSpec | write | Create an API specification in Spec Hub |
getSpec | read-only | Get information about an API specification |
getAllSpecs | read-only | Get all API specifications in a workspace |
deleteSpec | destructive | Delete an API specification |
getSpecDefinition / getSpecCollections | read-only | Get a spec's full definition, or the collections generated from it |
createSpecFile | write | Create a file for an OpenAPI or a protobuf 2 or 3 specification |
getSpecFile | read-only | Get the contents of an API specification's file |
getSpecFiles | read-only | Get all the files in an API specification |
updateSpecFile | write | Update a file for an OpenAPI or protobuf 2 or 3 specification |
deleteSpecFile | destructive | Delete a file in an API specification |
updateSpecProperties | write | Update a spec's properties, such as its name |
syncSpecWithCollection | destructive | Sync an API specification linked to a collection |
syncCollectionWithSpec | destructive | Sync a collection generated from an API specification |
getGeneratedCollectionSpecs | read-only | Get the API specification generated for the given collection |
getAsyncSpecTaskStatus / getStatusOfAnAsyncApiTask | read-only | Check the status of an async spec-creation or other API task |
publishDocumentation | write, external | Publish a collection's documentation |
unpublishDocumentation | write | Unpublish a collection's documentation |
getAnalyticsData / getAnalyticsMetadata | read-only | Get analytics data for a resource, or the metric catalog for the analytics API |
searchPostmanElements | read-only | Search across requests, collections, workspaces, specs, flows, and mocks |
searchLearningCenter | read-only | Search Postman's official documentation and learning resources |
getPostmanContextOverview / getApiDiscoveryInstructions / getCodeGenerationInstructions / getInstalledApiMaintenanceInstructions | read-only | Context and workflow guidance for discovering, generating from, and maintaining APIs in Postman |
A handful of these are worth a second look before you allow them broadly: respondPrivateNetworkAddRequest controls what joins your org's shared API network, publishMock/publishDocumentation make things externally visible, and the delete* family (collections, workspaces, mocks, monitors, specs, folders, requests, responses) is permanent: Postman has no recycle bin for most of these.
Required scopes
The gateway does not request a fixed scope list for Postman. It registers the client without naming any scopes and records the ones Postman returns.
Policy examples
Read-only Postman for everyone
One deny rule blocks every mutating tool while leaving reads on the default path:
- In Agent Actions, click Add Rule and name it "Postman: no writes."
- Set the effect pill to Deny and the MCP scope pill to Postman.
- Add these tool patterns:
create*,update*,delete*,put*,patch*,duplicate*,generate*,publish*,unpublish*,merge*,transfer*,resolve*,respond*,add*,remove*,run*,sync*,pull*. - Set the status to Active and click Create.
That prefix list covers every writer in the tool set above; everything left over (the get*, list*, and search tools) keeps working.
Scope one agent to collection and spec browsing only
An allow rule on its own restricts nothing, because every org is seeded with an Allow all rule that anything unmatched falls through to. To confine an agent, pair the allow with a deny beneath it:
- Create the deny rule first: effect Deny, MCP scope Postman, Agent scope your browsing agent, tool pattern
*. - Then create the allow rule: effect Allow, MCP scope Postman, the same Agent scope, tool patterns
getCollection,getCollections,getCollectionFolder,getCollectionRequest,getCollectionResponse,getSpec,getAllSpecs,getSpecDefinition,searchPostmanElements,searchLearningCenter.
Order matters, and so does the sequence you create them in: new rules insert at the top of the list, so building the deny first leaves the allow above it. That is the order you need. Evaluation is first-match-wins, so the agent's browsing calls hit the allow, every other Postman call hits the deny, and neither ever reaches Allow all.
Scoping both rules to one agent keeps the blast radius small. A deny with no Agent scope would cut off every agent and user in the org.
Block destructive tools
One deny rule blocks every tool tagged destructive, regardless of its name:
- In Agent Actions, click Add Rule and name it "Postman: no destructive tools."
- Set the effect pill to Deny and the MCP scope pill to Postman.
- Open the Tools pill and pick the built-in tag
destructive. - Set the status to Active and click Create.
Next steps
- Create a policy – the full rule editor walkthrough.
- Policies – how first-match-wins ordering and the default Allow all rule interact.
- Block an agent from deleting GitHub branches – the same deny-first shape on another resource.
Notion
Search, read, and edit pages, databases, comments, and meeting notes via Notion's official MCP server.
Ramp
Manage corporate cards, transactions, reimbursements, bills, purchase orders, funds, vendors, treasury accounts, and travel bookings, plus run spend analytics, using Ramp's official MCP server.