Atlas / MCP servers / salehkhatri / Postman

PostmanSAFE

mcp/salehkhatri/postman-2

A Model Context Protocol (MCP) server that provides seamless integration with the Postman API. This package enables AI assistants and applications to interact with Postman workspaces, collections, requests, environments, and folders programmatically.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
19 6r · 9w · 4d
Transport
stdio
License
MIT
Stars
31
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides seamless integration with the Postman API. This package enables AI assistants and applications to interact with Postman workspaces, collections, requests, environments, and folders programmatically.

[](https://www.npmjs.com/package/postman-mcp) [](https://opensource.org/licenses/MIT)

🚀 Features

📁 Workspace Management

  • List all workspaces
  • Get detailed workspace information
  • Create new workspaces (personal/team)
  • Update workspace metadata

📚 Collection Management

  • List collections within workspaces
  • Get collection details with full structure
  • Create new collections
  • Update collection metadata and variables
  • Delete collections

🔧 Request Management

  • Add new HTTP requests to collections
  • Update existing requests (method, URL, headers, body)
  • Move requests between folders
  • Delete requests
  • Support for all HTTP methods (GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS)

🌍 Environment Management

  • List environments in workspaces
  • Get environment details and variables
  • Create new environments with variables
  • Update environment variables
  • Delete environments
  • Support for secret, default, and custom variable types

📂 Folder Organization

  • Create nested folder structures
  • Organize requests within folders
  • Support for hierarchical folder paths

⚙️ Setup

1. Get Your Postman API Key

  1. Go to Postman Account Settings
  2. Click "Generate API Key"
  3. Give it a name and copy the generated key

2. MCP Configuration

For Claude Desktop

Add to your Claude Desktop configuration file (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):

{
"mcpServers": {
"postman": {
"command": "npx",
"args": ["postman-mcp"],
"env": {
"POSTM
Read from source at commit 509733ecaa76OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add postman-mcp --env POSTMAN_API_KEY=${POSTMAN_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "postman-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "POSTMAN_API_KEY": "${POSTMAN_API_KEY}"
      }
    }
  }
}
03

Exposed tools (19)

6 read · 9 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_requestwriteAdd a new request to a collection
create_collectionwriteCreate a new collection
create_environmentwriteCreate a new environment
create_folderwriteCreate a new folder in a collection
create_workspacewriteCreate a new workspace
delete_collectiondestructiveDelete a Postman collection
delete_environmentdestructiveDelete an existing environment
delete_folderdestructiveDelete a folder from a collection
delete_requestdestructiveDelete a request from a collection
get_collectionreadGet detailed information about a specific collection
get_environmentreadGet detailed information about a specific environment
get_workspacereadGet detailed information about a specific workspace
list_collectionsreadList all collections in a workspace
list_environmentsreadList all environments
list_workspacesreadList all workspaces
update_collectionwriteUpdate collection metadata (name, description, variables)
update_environmentwriteUpdate an existing environment
update_requestwriteUpdate an existing request in a collection
update_workspacewriteUpdate an existing workspace
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_collection, delete_environment, delete_folder, delete_request
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, dotenv, zod, zod-to-json-schema, @types/node, tsx, typescript
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 509733ecaa76full audit observations/trust-audit/mcp-server/salehkhatri__postman-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08509733ecaa76SAFEB89first audit
06

Questions

What is the Postman MCP server?

A Model Context Protocol (MCP) server that provides seamless integration with the Postman API. This package enables AI assistants and applications to interact with Postman workspaces, collections, requests, environments, and folders programmatically.

What tools does Postman expose?

19 in total: 6 read-only, 9 that write, and 4 that can delete or overwrite (delete_collection, delete_environment, delete_folder, delete_request). Every one is listed on this page with its risk.

Is Postman safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Postman need?

It reads POSTMAN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Postman run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as postman-mcp at 1.0.3.

How current is this page?

The grade is for one exact copy of the source (509733ecaa76), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement