Atlas / MCP servers / delano / Postman

PostmanSAFE

mcp/delano/postman

An MCP server that provides access to Postman.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
109 55r · 40w · 14d
Transport
stdio
License
MIT
Stars
159
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/postman-api-server) Version: v0.2.0

An MCP server that provides access to the Postman API. Functionality is based on the official OpenAPI specification. For more information, see the Postman API documentation.

This project is part of the Model Context Protocol (MCP) initiative from Anthropic. For more information, visit the MCP GitHub repository and the announcement on the Anthropic blog.

Skip ahead to install instructions

[!WARNING] This project is currently under active development. Please use with caution and expect breaking changes.
[!NOTE] AI Generated Code. I used Cline v2.2.2 with Claude 3.5 Sonnet (2024-10-22). See docs/README.md for prompts and details about how this code was generated.
  • Overview
  • Features
  • Collections
  • Environments
  • APIs
  • Authentication \& Authorization
  • Additional Features
  • Installation
  • Prerequisites
  • Steps
  • Usage
  • Setting up API Keys
  • Using Claude Desktop
  • Using Cline
  • Using Zed
  • Documentation
  • [Project Overv
Read from source at commit 2fe80e634e96OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add postman-api-server --env POSTMAN_API_KEY=${POSTMAN_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "postman-api-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "POSTMAN_API_KEY": "${POSTMAN_API_KEY}"
      }
    }
  }
}
03

Exposed tools (109)

55 read · 40 write · 14 destructive. Blast radius: 14 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
WebhooksreadList of configured webhooks
add_api_collectionwriteAdd a collection to an API
add_pan_elementwriteAdd element or folder to Private API Network
analyze_collectionreadAnalyze a Postman collection for potential improvements and best practices
api_idreadID of the API to document
collection_idreadID of the collection to analyze
coverage_levelreadDesired test coverage level (basic/comprehensive)
create_apiwriteCreate a new API
create_api_commentwriteCreate a new comment on an API (max 10,000 characters)
create_api_schemawriteCreate a schema for an API
create_api_versionwriteCreate a new version of an API
create_collectionwriteCreate a new collection in a workspace. Supports Postman Collection v2.1.0 format.
create_collection_folderwriteCreate a new folder in a collection
create_collection_requestwriteCreate a new request in a collection
create_collection_responsewriteCreate a new response in a collection
create_environmentwriteCreate a new environment in a workspace. Creates in
create_mockwriteCreate a new mock server. Creates in Personal workspace if workspace not specified.
create_monitorwriteCreate a new monitor. Cannot create monitors for collections added to an API definition.
create_server_responsewriteCreate a server response. Only one server response can be active at a time.
create_update_schema_filewriteCreate or update a schema file
create_webhookwriteCreates webhook that triggers collection with custom payload
delete_apidestructiveDelete an API
delete_api_commentdestructiveDelete an API comment
delete_api_versiondestructiveDelete an API version
delete_collectiondestructiveDelete a collection
delete_collection_access_keydestructiveDelete a collection access key
delete_collection_folderdestructiveDelete a folder from a collection
delete_collection_requestdestructiveDelete a request from a collection
delete_collection_responsedestructiveDelete a response from a collection
delete_environmentdestructiveDelete an environment
delete_mockdestructiveDelete a mock server
delete_monitordestructiveDelete a monitor
delete_schema_filedestructiveDelete a schema file
delete_server_responsedestructiveDelete a server response
document_apireadGenerate documentation for an API based on its collection and schema
environment_idreadID of the environment to review
fork_collectionreadFork a collection to a workspace
fork_environmentwriteCreate a fork of an environment in a workspace
formatreadDocumentation format (markdown/html)
get_accountsreadGets Postman billing account details for the given team
get_apireadGet details of a specific API
get_api_collectionreadGet a specific collection from an API
get_api_commentsreadGet comments for an API
get_api_schemareadGet a specific schema from an API
get_api_schema_filesreadGet files in an API schema
get_api_tagsreadGet tags for an API
get_api_versionreadGet a specific version of an API
get_api_versionsreadGet all versions of an API
get_authenticated_userreadGet authenticated user information
get_collectionreadGet details of a specific collection
get_collection_folderreadGet details of a specific folder in a collection
get_collection_forksreadGet a list of collection forks
get_collection_requestreadGet details of a specific request in a collection
get_collection_responsereadGet details of a specific response in a collection
get_collection_rolesreadGet roles for a collection
get_environmentreadGet details of a specific environment
get_environment_forksreadGet a list of environment forks
get_mockreadGet details of a specific mock server
get_mock_call_logsreadGet mock call logs. Maximum 6.5MB or 100 call logs per API call. Retention period based on Postman plan.
get_monitorreadGet details of a specific monitor
get_schema_file_contentsreadGet contents of a schema file
get_server_responsereadGet a specific server response
get_tagged_elementsreadGet elements by tag
get_task_statusreadGet status of an asynchronous task
get_user_inforeadGet information about the authenticated user
get_workspacereadGet details of a specific workspace
get_workspace_rolesreadGet roles for a specific workspace
get_workspace_tagsreadGet workspace tags
list_account_invoicesreadGets all invoices for a Postman billing account filtered by status
list_apisreadList all APIs in a workspace
list_collection_access_keysreadList collection access keys with optional filtering by collection ID
list_collectionsreadShow all collections across workspaces
list_environmentsreadShow all environments and their variables
list_mocksreadShow all mock servers and their configurations
list_monitorsreadShow all active monitors and their status
list_pan_elementsreadGet all elements and folders in Private API Network
list_server_responsesreadGet all server responses for a mock
list_workspace_rolesreadGet all available workspace roles based on team\
list_workspacesreadShow all available workspaces and their details
merge_collection_forkwriteMerge a forked collection back into its parent
merge_environment_forkwriteMerge a forked environment back into its parent
patch_collectionwritePartially update a collection. Only updates provided fields.
publish_mockwritePublish mock server (sets Access Control to public)
pull_collection_changesreadPull changes from parent collection into forked collection
pull_environmentreadPull changes from parent environment into forked environment
remove_pan_elementdestructiveRemove element or folder from Private API Network
resolve_comment_threadreadResolves a comment and any associated replies
review_environmentreadReview environment variables for security and completeness
run_monitorwriteRun a monitor. For async=true, response won\
suggest_testsreadSuggest test cases for API endpoints in a collection
sync_collection_with_schemawriteSync a collection with its schema
transfer_collection_itemswriteTransfer items between collections
unpublish_mockreadUnpublish mock server (sets Access Control to private)
update_apiwriteUpdate an existing API
update_api_commentwriteUpdate an existing API comment (max 10,000 characters)
update_api_tagswriteUpdate tags for an API
update_api_versionwriteUpdate an API version
update_collectionwriteUpdate an existing collection. Full collection replacement with maximum size of 20 MB.
update_collection_folderwriteUpdate a folder in a collection. Acts like PATCH, only updates provided values.
update_collection_requestwriteUpdate a request in a collection. Cannot change request folder.
update_collection_responsewriteUpdate a response in a collection. Acts like PATCH, only updates provided values.
update_collection_roleswriteUpdate collection roles (requires EDITOR role)
update_environmentwriteUpdate an existing environment. Only include variables that need to be modified.
update_mockwriteUpdate an existing mock server
update_monitorwriteUpdate an existing monitor
update_pan_elementwriteUpdate element or folder in Private API Network
update_server_responsewriteUpdate a server response
update_workspace_roleswriteUpdate workspace roles for users and groups (limited to 50 operations per call)
update_workspace_tagswriteUpdate workspace tags
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_api, delete_api_comment, delete_api_version, delete_collection, delete_collection_access_key, delete_collection_folder, delete_collection_request, delete_collection_response, delete_environment
Why it matters. 14 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/api/additional-features/definitions.ts:1
import { ToolDefinition } from '../../../types/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/api/additional-features/index.ts:7
} from '../../../types/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/api/apis/definitions.ts:1
import { ApiCollectionOperationType, ApiSchemaType } from '../../../types/apis.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/api/apis/definitions.ts:2
import { ToolDefinition } from '../../../types/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/api/apis/index.ts:7
} from '../../../types/index.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@types/axios, axios, zod, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/api/summaries/README.md:403
Workthrough the markdown summary document, operating one endpoint at a time, updating its documentation based on the contents of the definition file. Each POST/PUT/etc request endpoint in the pathsonl
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/api/references/README.md:44
- Full access to platform features (workspaces, environments, monitors etc)
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:73
- **API Key Authentication**: Secure access using API keys.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 2fe80e634e96full audit observations/trust-audit/mcp-server/delano__postman.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-072fe80e634e96SAFEB89first audit
06

Questions

What is the Postman MCP server?

An MCP server that provides access to Postman.

What tools does Postman expose?

109 in total: 55 read-only, 40 that write, and 14 that can delete or overwrite (delete_api, delete_api_comment, delete_api_version, delete_collection, delete_collection_access_key). Every one is listed on this page with its risk.

Is Postman safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 14 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Postman need?

It reads POSTMAN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Postman run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as postman-api-server at 0.2.0.

How current is this page?

The grade is for one exact copy of the source (2fe80e634e96), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement