PostmanSAFE
An MCP server that provides access to Postman.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/postman-api-server) Version: v0.2.0
An MCP server that provides access to the Postman API. Functionality is based on the official OpenAPI specification. For more information, see the Postman API documentation.
This project is part of the Model Context Protocol (MCP) initiative from Anthropic. For more information, visit the MCP GitHub repository and the announcement on the Anthropic blog.
Skip ahead to install instructions
[!WARNING] This project is currently under active development. Please use with caution and expect breaking changes.
[!NOTE] AI Generated Code. I used Cline v2.2.2 with Claude 3.5 Sonnet (2024-10-22). See docs/README.md for prompts and details about how this code was generated.
- Overview
- Features
- Collections
- Environments
- APIs
- Authentication \& Authorization
- Additional Features
- Installation
- Prerequisites
- Steps
- Usage
- Setting up API Keys
- Using Claude Desktop
- Using Cline
- Using Zed
- Documentation
- [Project Overv
2fe80e634e96OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add postman-api-server --env POSTMAN_API_KEY=${POSTMAN_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"postman-api-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"POSTMAN_API_KEY": "${POSTMAN_API_KEY}"
}
}
}
}Exposed tools (109)
55 read · 40 write · 14 destructive. Blast radius: 14 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Webhooks | read | List of configured webhooks |
add_api_collection | write | Add a collection to an API |
add_pan_element | write | Add element or folder to Private API Network |
analyze_collection | read | Analyze a Postman collection for potential improvements and best practices |
api_id | read | ID of the API to document |
collection_id | read | ID of the collection to analyze |
coverage_level | read | Desired test coverage level (basic/comprehensive) |
create_api | write | Create a new API |
create_api_comment | write | Create a new comment on an API (max 10,000 characters) |
create_api_schema | write | Create a schema for an API |
create_api_version | write | Create a new version of an API |
create_collection | write | Create a new collection in a workspace. Supports Postman Collection v2.1.0 format. |
create_collection_folder | write | Create a new folder in a collection |
create_collection_request | write | Create a new request in a collection |
create_collection_response | write | Create a new response in a collection |
create_environment | write | Create a new environment in a workspace. Creates in |
create_mock | write | Create a new mock server. Creates in Personal workspace if workspace not specified. |
create_monitor | write | Create a new monitor. Cannot create monitors for collections added to an API definition. |
create_server_response | write | Create a server response. Only one server response can be active at a time. |
create_update_schema_file | write | Create or update a schema file |
create_webhook | write | Creates webhook that triggers collection with custom payload |
delete_api | destructive | Delete an API |
delete_api_comment | destructive | Delete an API comment |
delete_api_version | destructive | Delete an API version |
delete_collection | destructive | Delete a collection |
delete_collection_access_key | destructive | Delete a collection access key |
delete_collection_folder | destructive | Delete a folder from a collection |
delete_collection_request | destructive | Delete a request from a collection |
delete_collection_response | destructive | Delete a response from a collection |
delete_environment | destructive | Delete an environment |
delete_mock | destructive | Delete a mock server |
delete_monitor | destructive | Delete a monitor |
delete_schema_file | destructive | Delete a schema file |
delete_server_response | destructive | Delete a server response |
document_api | read | Generate documentation for an API based on its collection and schema |
environment_id | read | ID of the environment to review |
fork_collection | read | Fork a collection to a workspace |
fork_environment | write | Create a fork of an environment in a workspace |
format | read | Documentation format (markdown/html) |
get_accounts | read | Gets Postman billing account details for the given team |
get_api | read | Get details of a specific API |
get_api_collection | read | Get a specific collection from an API |
get_api_comments | read | Get comments for an API |
get_api_schema | read | Get a specific schema from an API |
get_api_schema_files | read | Get files in an API schema |
get_api_tags | read | Get tags for an API |
get_api_version | read | Get a specific version of an API |
get_api_versions | read | Get all versions of an API |
get_authenticated_user | read | Get authenticated user information |
get_collection | read | Get details of a specific collection |
get_collection_folder | read | Get details of a specific folder in a collection |
get_collection_forks | read | Get a list of collection forks |
get_collection_request | read | Get details of a specific request in a collection |
get_collection_response | read | Get details of a specific response in a collection |
get_collection_roles | read | Get roles for a collection |
get_environment | read | Get details of a specific environment |
get_environment_forks | read | Get a list of environment forks |
get_mock | read | Get details of a specific mock server |
get_mock_call_logs | read | Get mock call logs. Maximum 6.5MB or 100 call logs per API call. Retention period based on Postman plan. |
get_monitor | read | Get details of a specific monitor |
get_schema_file_contents | read | Get contents of a schema file |
get_server_response | read | Get a specific server response |
get_tagged_elements | read | Get elements by tag |
get_task_status | read | Get status of an asynchronous task |
get_user_info | read | Get information about the authenticated user |
get_workspace | read | Get details of a specific workspace |
get_workspace_roles | read | Get roles for a specific workspace |
get_workspace_tags | read | Get workspace tags |
list_account_invoices | read | Gets all invoices for a Postman billing account filtered by status |
list_apis | read | List all APIs in a workspace |
list_collection_access_keys | read | List collection access keys with optional filtering by collection ID |
list_collections | read | Show all collections across workspaces |
list_environments | read | Show all environments and their variables |
list_mocks | read | Show all mock servers and their configurations |
list_monitors | read | Show all active monitors and their status |
list_pan_elements | read | Get all elements and folders in Private API Network |
list_server_responses | read | Get all server responses for a mock |
list_workspace_roles | read | Get all available workspace roles based on team\ |
list_workspaces | read | Show all available workspaces and their details |
merge_collection_fork | write | Merge a forked collection back into its parent |
merge_environment_fork | write | Merge a forked environment back into its parent |
patch_collection | write | Partially update a collection. Only updates provided fields. |
publish_mock | write | Publish mock server (sets Access Control to public) |
pull_collection_changes | read | Pull changes from parent collection into forked collection |
pull_environment | read | Pull changes from parent environment into forked environment |
remove_pan_element | destructive | Remove element or folder from Private API Network |
resolve_comment_thread | read | Resolves a comment and any associated replies |
review_environment | read | Review environment variables for security and completeness |
run_monitor | write | Run a monitor. For async=true, response won\ |
suggest_tests | read | Suggest test cases for API endpoints in a collection |
sync_collection_with_schema | write | Sync a collection with its schema |
transfer_collection_items | write | Transfer items between collections |
unpublish_mock | read | Unpublish mock server (sets Access Control to private) |
update_api | write | Update an existing API |
update_api_comment | write | Update an existing API comment (max 10,000 characters) |
update_api_tags | write | Update tags for an API |
update_api_version | write | Update an API version |
update_collection | write | Update an existing collection. Full collection replacement with maximum size of 20 MB. |
update_collection_folder | write | Update a folder in a collection. Acts like PATCH, only updates provided values. |
update_collection_request | write | Update a request in a collection. Cannot change request folder. |
update_collection_response | write | Update a response in a collection. Acts like PATCH, only updates provided values. |
update_collection_roles | write | Update collection roles (requires EDITOR role) |
update_environment | write | Update an existing environment. Only include variables that need to be modified. |
update_mock | write | Update an existing mock server |
update_monitor | write | Update an existing monitor |
update_pan_element | write | Update element or folder in Private API Network |
update_server_response | write | Update a server response |
update_workspace_roles | write | Update workspace roles for users and groups (limited to 50 operations per call) |
update_workspace_tags | write | Update workspace tags |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
delete_api, delete_api_comment, delete_api_version, delete_collection, delete_collection_access_key, delete_collection_folder, delete_collection_request, delete_collection_response, delete_environment
import { ToolDefinition } from '../../../types/index.js';} from '../../../types/index.js';
import { ApiCollectionOperationType, ApiSchemaType } from '../../../types/apis.js';import { ToolDefinition } from '../../../types/index.js';} from '../../../types/index.js';
@types/axios, axios, zod, @types/node, typescript
Workthrough the markdown summary document, operating one endpoint at a time, updating its documentation based on the contents of the definition file. Each POST/PUT/etc request endpoint in the pathsonl
- Full access to platform features (workspaces, environments, monitors etc)
- **API Key Authentication**: Secure access using API keys.
Gates applied: no_behavioural_pass.
2fe80e634e96full audit observations/trust-audit/mcp-server/delano__postman.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 2fe80e634e96 | SAFE | B | 89 | first audit |
Questions
What is the Postman MCP server?
An MCP server that provides access to Postman.
What tools does Postman expose?
109 in total: 55 read-only, 40 that write, and 14 that can delete or overwrite (delete_api, delete_api_comment, delete_api_version, delete_collection, delete_collection_access_key). Every one is listed on this page with its risk.
Is Postman safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 14 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Postman need?
It reads POSTMAN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Postman run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as postman-api-server at 0.2.0.
How current is this page?
The grade is for one exact copy of the source (2fe80e634e96), read on 2026-10-07. The repository is watched and re-audited when it changes.