Secure Postman access for AI agents

Manage Postman workspaces, collections, environments, specs, mocks, and monitors, and search Postman's Learning Center, via Postman's official MCP server.

Postman is where API design, testing, and documentation live for most engineering orgs, which means an agent with Postman access can read collections and specs to answer questions, but can just as easily publish a mock server, delete a workspace, or rewrite a monitor nobody asked it to touch. Adding Postman here puts every tool call through your policies and onto the audit log, so agents can explore your API surface without quietly reshaping it.

Server URL: https://mcp.postman.com/mcp

Credential modes

Postman supports per-org dynamic registration only, so there is no app to create on Postman's side and no client ID or secret to enter. See Credential modes for how it compares with Use SecureAuth's app and Bring your own app.

Before you begin

  • A Postman account that can reach the workspaces and collections your agents need.
  • Administrator access to your Agent Authority workspace, to add the resource.

Setup

  1. In the Agent Authority console, go to Tools & Services and click Add Resource.
  2. Select Postman from the catalog.
  3. On Choose how to install Postman, click Per-org dynamic registration. Selecting it adds the resource right away with its tools pre-configured.

Dynamic client registration

When you add the resource, the gateway registers its own OAuth client with Postman, the credential that lets it sign users in. Postman's own team, workspace, and role-based permissions still apply, so an agent can only reach what the person who signed in could already reach.

Verify the connection

The gateway syncs the Postman tools automatically. To check the connection end to end, ask your agent to run a request:

Get my Postman user

If your Postman user details come back, the connection is working.

How users connect

Access is per user. Each additional user connects their own Postman account the first time their agent calls a Postman tool: the gateway returns a sign-in link, the user authorizes once, and the tools work from then on. Go to Connections to manage linked accounts.

Available tools

Postman exposes 124 tools. They are grouped below; the resource's Overview tab shows the authoritative per-tool list under Available Tools once installed.

ToolTagsDescription
getAuthenticatedUserread-onlyGet information about the authenticated user
getEnabledToolsread-onlyList the tools enabled for this connection: run this first if a tool seems missing
createWorkspacewriteCreate a new workspace
getWorkspaceread-onlyGet information about a workspace
getWorkspacesread-onlyGet all workspaces you have access to
updateWorkspacewriteUpdate a workspace's property, such as its name or visibility
deleteWorkspacedestructiveDelete an existing workspace
getWorkspaceGlobalVariablesread-onlyGet a workspace's global variables
updateWorkspaceGlobalVariablesdestructiveReplace a workspace's global variables
getWorkspaceTagsread-onlyGet all the tags associated with a workspace
updateWorkspaceTagsdestructiveUpdate a workspace's associated tags
addWorkspaceToPrivateNetworkwritePublish a workspace to your team's Private API Network
removeWorkspaceFromPrivateNetworkwriteRemove a workspace from your team's Private API Network
listPrivateNetworkWorkspaces / listPrivateNetworkAddRequestsread-onlyList workspaces on the Private API Network, or pending add requests
respondPrivateNetworkAddRequestwriteApprove or reject a request to add a workspace to the Private API Network
createCollectionwriteCreate a collection in the Postman Collection v2.1.0 format
getCollectionread-onlyGet information about a collection
getCollectionsread-onlyGet all collections in a workspace
putCollectiondestructiveReplace the contents of a collection
patchCollectionwriteUpdate specific collection information, such as its name, events, or its variables
deleteCollectiondestructiveDelete a collection
duplicateCollectionwriteCreate a duplicate of the given collection in another workspace
getDuplicateCollectionTaskStatus / getCollectionUpdatesTasksread-onlyCheck the status of an async collection duplication or update task
generateCollection / generateSpecFromCollectionwriteGenerate a collection from a spec, or a spec from a collection
getCollectionTagsread-onlyGet all the tags associated with a collection
updateCollectionTagsdestructiveUpdate a collection's associated tags
createCollectionForkwriteCreate a fork from an existing collection into a workspace
getCollectionForksread-onlyGet a collection's forked collections
getCollectionsForkedByUserread-onlyGet a list of all the authenticated user's forked collections
mergeCollectionForkdestructiveMerge a forked collection into its parent (deprecated)
pullCollectionChangesdestructivePull the changes from a parent (source) collection into the forked collection
getSourceCollectionStatusread-onlyCheck whether a fork differs from its parent collection
createCollectionFolderwriteCreate a folder in a collection
getCollectionFolderread-onlyGet information about a folder in a collection
updateCollectionFolderwriteUpdate a folder in a collection
deleteCollectionFolderdestructiveDelete a folder in a collection
transferCollectionFolderswriteCopy or move folders into a collection or folder
createCollectionRequestwriteCreate a request in a collection
getCollectionRequestread-onlyGet information about a request in a collection
updateCollectionRequestwriteUpdate a request in a collection
deleteCollectionRequestdestructiveDelete a request in a collection
transferCollectionRequestswriteCopy or move requests into a collection or folder
createCollectionResponsewriteCreate a request response in a collection
getCollectionResponseread-onlyGet information about a response in a collection
updateCollectionResponsewriteUpdate a response in a collection
deleteCollectionResponsedestructiveDelete a response in a collection
transferCollectionResponseswriteCopy or move responses into a request
createCollectionCommentwriteCreate a comment on a collection
getCollectionCommentsread-onlyGet all comments left by users in a collection
updateCollectionCommentwriteUpdate a comment on a collection
deleteCollectionCommentdestructiveDelete a comment from a collection
updateApiCollectionCommentwriteUpdate a comment on an API's collection
deleteApiCollectionCommentdestructiveDelete a comment from an API's collection
createFolderCommentwriteCreate a comment on a folder
getFolderCommentsread-onlyGet all comments left by users in a folder
updateFolderCommentwriteUpdate a comment on a folder
deleteFolderCommentdestructiveDelete a comment from a folder
createRequestCommentwriteCreate a comment on a request
getRequestCommentsread-onlyGet all comments left by users in a request
updateRequestCommentwriteUpdate a comment on a request
deleteRequestCommentdestructiveDelete a comment from a request
createResponseCommentwriteCreate a comment on a response
getResponseCommentsread-onlyGet all comments left by users in a response
updateResponseCommentwriteUpdate a comment on a response
deleteResponseCommentdestructiveDelete a comment from a response
resolveCommentThreadwriteResolve a comment and any associated replies
getTaggedEntitiesread-onlyGet workspaces, APIs, and collections by tag (Enterprise plan)
createEnvironmentwriteCreate an environment
getEnvironmentread-onlyGet information about an environment
getEnvironmentsread-onlyGet all of your environments
putEnvironmentdestructiveReplace all the contents of an environment with the given information
patchEnvironmentwriteUpdate specific environment properties, such as its name and variables
deleteEnvironmentdestructiveDelete an environment
createMockwriteCreate a mock server in a collection
getMockread-onlyGet information about a mock server
getMocksread-onlyGet all active mock servers
updateMockwriteUpdate a mock server
deleteMockdestructiveDelete a mock server
publishMockwrite, externalPublish a mock server
unpublishMockwriteUnpublish a mock server
createMockServerResponsewriteCreate a server response on a mock server
getMockServerResponseread-onlyGet the full details of a mock server response
getMockServerResponsesread-onlyGet all server responses configured for a mock server
updateMockServerResponsewriteUpdate a mock server response's name, status code, body, headers, or language
deleteMockServerResponsedestructiveDelete a server response from a mock server
createMonitorwriteCreate a monitor
getMonitorread-onlyGet information about a monitor
getMonitorsread-onlyGet all monitors
updateMonitorwriteUpdate a monitor's configurations
deleteMonitordestructiveDelete a monitor
runMonitorwriteRun a monitor and return its run results
getMonitorRunResultsread-onlyGet results for a monitor run, with trimmed execution logs
listMonitorExecutions / listRunsForExecutionread-onlyList a monitor's executions, or the runs within one
createSpecwriteCreate an API specification in Spec Hub
getSpecread-onlyGet information about an API specification
getAllSpecsread-onlyGet all API specifications in a workspace
deleteSpecdestructiveDelete an API specification
getSpecDefinition / getSpecCollectionsread-onlyGet a spec's full definition, or the collections generated from it
createSpecFilewriteCreate a file for an OpenAPI or a protobuf 2 or 3 specification
getSpecFileread-onlyGet the contents of an API specification's file
getSpecFilesread-onlyGet all the files in an API specification
updateSpecFilewriteUpdate a file for an OpenAPI or protobuf 2 or 3 specification
deleteSpecFiledestructiveDelete a file in an API specification
updateSpecPropertieswriteUpdate a spec's properties, such as its name
syncSpecWithCollectiondestructiveSync an API specification linked to a collection
syncCollectionWithSpecdestructiveSync a collection generated from an API specification
getGeneratedCollectionSpecsread-onlyGet the API specification generated for the given collection
getAsyncSpecTaskStatus / getStatusOfAnAsyncApiTaskread-onlyCheck the status of an async spec-creation or other API task
publishDocumentationwrite, externalPublish a collection's documentation
unpublishDocumentationwriteUnpublish a collection's documentation
getAnalyticsData / getAnalyticsMetadataread-onlyGet analytics data for a resource, or the metric catalog for the analytics API
searchPostmanElementsread-onlySearch across requests, collections, workspaces, specs, flows, and mocks
searchLearningCenterread-onlySearch Postman's official documentation and learning resources
getPostmanContextOverview / getApiDiscoveryInstructions / getCodeGenerationInstructions / getInstalledApiMaintenanceInstructionsread-onlyContext and workflow guidance for discovering, generating from, and maintaining APIs in Postman

A handful of these are worth a second look before you allow them broadly: respondPrivateNetworkAddRequest controls what joins your org's shared API network, publishMock/publishDocumentation make things externally visible, and the delete* family (collections, workspaces, mocks, monitors, specs, folders, requests, responses) is permanent: Postman has no recycle bin for most of these.

Required scopes

The gateway does not request a fixed scope list for Postman. It registers the client without naming any scopes and records the ones Postman returns.

Policy examples

Read-only Postman for everyone

One deny rule blocks every mutating tool while leaving reads on the default path:

  1. In Agent Actions, click Add Rule and name it "Postman: no writes."
  2. Set the effect pill to Deny and the MCP scope pill to Postman.
  3. Add these tool patterns: create*, update*, delete*, put*, patch*, duplicate*, generate*, publish*, unpublish*, merge*, transfer*, resolve*, respond*, add*, remove*, run*, sync*, pull*.
  4. Set the status to Active and click Create.

That prefix list covers every writer in the tool set above; everything left over (the get*, list*, and search tools) keeps working.

Scope one agent to collection and spec browsing only

An allow rule on its own restricts nothing, because every org is seeded with an Allow all rule that anything unmatched falls through to. To confine an agent, pair the allow with a deny beneath it:

  1. Create the deny rule first: effect Deny, MCP scope Postman, Agent scope your browsing agent, tool pattern *.
  2. Then create the allow rule: effect Allow, MCP scope Postman, the same Agent scope, tool patterns getCollection, getCollections, getCollectionFolder, getCollectionRequest, getCollectionResponse, getSpec, getAllSpecs, getSpecDefinition, searchPostmanElements, searchLearningCenter.

Order matters, and so does the sequence you create them in: new rules insert at the top of the list, so building the deny first leaves the allow above it. That is the order you need. Evaluation is first-match-wins, so the agent's browsing calls hit the allow, every other Postman call hits the deny, and neither ever reaches Allow all.

Scoping both rules to one agent keeps the blast radius small. A deny with no Agent scope would cut off every agent and user in the org.

Block destructive tools

One deny rule blocks every tool tagged destructive, regardless of its name:

  1. In Agent Actions, click Add Rule and name it "Postman: no destructive tools."
  2. Set the effect pill to Deny and the MCP scope pill to Postman.
  3. Open the Tools pill and pick the built-in tag destructive.
  4. Set the status to Active and click Create.

Next steps

On this page