Postman for AI agents

Postman is an API platform for building, testing, and documenting APIs with collaboration features for teams. Developers use it to design, test, and monitor APIs throughout their lifecycle. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Developer toolsAPI keyMCP + RESTpostman.com
AUDIT LOG · POSTMANPOLICY: acme-support
09:41:07 · claude · u_8f2read
postman.get_an_api
Get API Information✓ allowed · 212ms
09:41:08 · claude · u_8f2read
postman.get_a_spec
Get API Specification✓ allowed · 164ms
09:41:09 · claude · u_8f2write
postman.create_an_api
Create an API✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
postman.delete_an_api
Delete an API✕ blocked · policy: deny
EVERY POSTMAN CALL, ON THE RECORD
01 · USE CASES

What agents do in Postman.

01

Create a request in a collection

Add a new API request to a collection so it can be tested and shared with the team.

02

Check a monitor's run history read-only

Look up a monitor's recent runs to confirm an API is passing its scheduled checks.

03

Delete a collection with approval

Remove an unused collection only after the team confirms it is no longer needed.

02 · ACTIONS

135 Postman actions, graded by risk.

Every Postman action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

60

Look things up. Allowed by default.

  • postman.get_an_api
    Get API Information
  • postman.get_a_spec
    Get API Specification
  • postman.get_accounts
    Get Billing Account Details
  • postman.get_a_folder
    Get Folder Information
  • postman.get_all_apis
    Get All APIs
  • postman.get_a_schema
    Get API Schema
  • postman.get_all_specs
    Get All API Specifications
  • postman.get_a_monitor
    Get Monitor Information
  • postman.get_a_request
    Get Request Information
  • postman.get_all_groups
    Get All Groups
  • postman.get_a_response
    Get Response Information
  • postman.get_a_spec_file
    Get Spec File Contents
  • postman.get_a_team_user
    Get Team User
  • postman.get_a_workspace
    Get Workspace Details
  • postman.get_all_monitors
    Get All Monitors
  • postman.get_all_versions
    Get All API Versions
+ 44 MORE

write

57

Create and change things. Allow, or ask the user first.

  • postman.create_an_api
    Create an API
  • postman.create_a_spec
    Create a Spec
  • postman.update_an_api
    Update an API
  • postman.create_a_fork2
    Create Environment Fork
  • postman.create_a_folder
    Create a Folder
  • postman.create_a_schema
    Create API Schema
  • postman.update_a_folder
    Update a Folder
  • postman.create_a_monitor
    Create a Monitor
  • postman.create_a_request
    Create Request in Collection
  • postman.create_a_webhook
    Create a Webhook
  • postman.create_relations
    Create API Version Relations
  • postman.update_a_monitor
    Update a Monitor
  • postman.update_a_request
    Update Request in Collection
  • postman.create_a_response
    Create a Response
  • postman.update_a_response
    Update a Response
  • postman.create_a_spec_file
    Create Spec File
+ 41 MORE

destructive

18

Delete, cancel or archive. Ask first, or deny outright.

  • postman.delete_an_api
    Delete an API
  • postman.delete_a_spec
    Delete a Spec
  • postman.delete_monitor
    Delete Monitor
  • postman.delete_a_folder
    Delete a Folder
  • postman.delete_a_response
    Delete a Response
  • postman.delete_a_spec_file
    Delete Spec File
  • postman.delete_a_workspace
    Delete a Workspace
  • postman.delete_a_collection
    Delete a Collection
  • postman.delete_a_schema_file
    Delete a Schema File
  • postman.delete_an_environment
    Delete an environment
  • postman.delete_an_apis_comment
    Delete an API's Comment
  • postman.delete_a_folders_comment
    Delete a Folder's Comment
  • postman.delete_a_server_response
    Delete Mock Server Response
  • postman.delete_a_requests_comment
    Delete a Request's Comment
  • postman.delete_a_responses_comment
    Delete a Response's Comment
  • postman.delete_a_collections_comment
    Delete a collection's comment
+ 2 MORE
03 · HOW IT WORKS

Postman in three steps.

  1. 01Your users connect PostmanThey add their Postman api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create an API” can wait for the user, and “delete an API” can be denied outright.
  3. 03Any agent can actYour agent calls Postman through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('postman', {
  read: 'allow',
  write: 'ask',        // create_an_api
  destructive: 'deny',  // delete_an_api
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Postman connects.

Users add their Postman api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Postman connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Postman from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Postman and Arc0, answered.

Q01

Can I use Postman with Claude, ChatGPT or Cursor?

Yes. Connect Postman to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Postman actions you allow.

Q02

How do users connect Postman?

Users add their Postman api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Postman actions can my agent take?

135 in total: 60 read, 57 write and 18 destructive, such as “create an API”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Postman?

Yes. Actions like “delete an API” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Postman too?

Yes. The same Postman connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Postman into your agent.

Your users connect Postman once, under your brand. Your agent gets 135 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan