Paperclip’s Postman MCP connector gives your AI agents tools to read collections and manage API workspaces. Each tool can be Allowed, Ask first or Off.
Agents reach workspaces, collections and environments accessible to the account or key. Paperclip has no workspace picker.
What agents can do with Postman
- Find workspaces and inspect a collection
getWorkspaces·getCollection - Read a collection before creating one
getCollection·createCollection - Inspect environments in a workspace
getWorkspaces·getEnvironment
How to connect Postman
- In Paperclip, open Connectors and select Postman.
- On the Access step, choose the identity and which agents may use the connection.
- Choose the region and capability group first. On US endpoints, complete browser sign-in; on EU endpoints, paste your Postman API key.
Postman tools for agents213
Read 104
getAllComponentsLists the components in the team's component library.
Full description
Lists the components in the team's component library. Use this to discover component IDs before reading or editing a component. Narrow the results with \`type\`, \`status\`, and \`hasVersions\`, and request extra fields with \`include\` (\`hasVersions\`, \`latestVersion\`, \`latestVersion.content\`) or \`expand\` (\`latestVersion\`). Do not use this tool to read a component's draft content; use getComponentDraft instead. Requires a Postman Enterprise plan.
getAllSpecsGets all API specifications in a workspace.
getAllWorkspaceRolesLists the workspace role types available to the team, which depend on the team's plan.
Full description
Lists the workspace role types available to the team, which depend on the team's plan. Call this before updateWorkspaceRoles to learn which roles you are allowed to assign. This returns the catalogue of possible roles, not anyone's actual assignments — use getWorkspaceRoles for those.
getAnalyticsDataGets analytics data based on the specified resource, metrics, and given filters for team, internal, and public workspaces, as well as Partner Workspaces.
Full description
Gets analytics data based on the specified resource, metrics, and given filters for team, internal, and public workspaces, as well as Partner Workspaces. **Note:** This endpoint only accepts the following resource:metric query parameter combinations: - \`user\` — \`workspace_active_users\`, \`active_users\` - \`workspace\` — \`elements_in_workspace\`, \`active_workspaces\`, \`api_calls\`, \`active_collections\`, \`response_status\`, \`pending_invites\`, \`needs_attention\`, \`success_rate\`, \`user_requests\`, \`collection_error_aggregate\` - \`team\` — \`user_api_journey\`, \`workspace_distribution\`, \`internal_workspace_distribution\`, \`license_consumption\`, \`members\`, \`last_autoflex_cycle\`, \`partner_engagement_funnel\` \`members_overtime\` , \`member_invites\`, \`invites_sent\` , \`invites_accepted\` - \`ai\` — \`top_agent_models_by_usage\`, \`activity_distribution\`, \`peak_activity\`, \`usage_leaderboard\`, \`credit_usage_by_model\`, \`messages_sent\`, \`credit_usage\`, \`agent_mode_sessions\`, \`new_vs_returning_users\`, \`agent_mode_users\` - \`api_development\` — \`active_workspaces\`, \`entity_activity\`, \`top_entities\` - \`api_testing\` — \`runs\`, \`functional_test_runs\`, \`performance_test_runs\` - \`api_production\` — \`monitor_runs\`, \`flow_executions\` - \`api_distribution\` — \`active_workspaces\`, \`pvt_network\`, \`partner\`, \`public\` - \`api_management\` — \`workspace_activity\` The \`view\` query parameter only accepts the following values when called with the following resource:metric pairs: \`detailed\` or \`summary\` — \`user:active_users\`, \`workspace:active_workspaces\`, \`workspace:pending_invites\`, \`workspace:needs_attention\`, \`workspace:success_rate\`, \`team:partner_engagement_funnel\`, \`api_distribution:pvt_network\`, \`api_distribution:partner\`, \`api_distribution:public\` - \`detailed\`, \`summary\`, or \`trends\` — \`api_development:entity_activity\`, \`api_testing:functional_test_runs\` , \`api_testing:performance_test_runs\`, \`api_production:monitor_runs\`, \`api_production:flow_executions\` - \`summary\` or \`trend\` — \`api_development:active_workspaces\`, \`api_testing:runs\`, \`api_distribution:active_workspaces\`, \`api_management:workspace_activity\` - \`summary\` only — \`workspace:elements_in_workspace\`, \`workspace:workspace_active_users\`, \`workspace:api_calls\`, \`workspace:response_status\`, \`team:user_api_journey\`, \`team:workspace_distribution\`, \`team:internal_workspace_distribution\`, \`team:license_consumption\` - \`detailed\` only — \`workspace:active_collections\`, \`workspace:user_requests\`, \`api_development:top_entities\`, \`api_management:popular_workspaces\` , \`team:invites_sent\` , \`team:invites_accepted\` - \`trend\` only — \`team:members_overtime\`, \`team:member_invites\`
getAnalyticsMetadataReturns a catalog of analytics resources and their corresponding metrics for use with the GET /analytics endpoint.
Full description
Returns a catalog of analytics resources and their corresponding metrics for use with the GET /analytics endpoint. These metrics provide insights on API usage, success, workspace, and team trends in Postman.
getApiCatalogDiscoveryServiceGets one discovered service in detail, including its endpoint list and its OpenAPI definition as a base64-encoded string — decode that value before reading it.
Full description
Gets one discovered service in detail, including its endpoint list and its OpenAPI definition as a base64-encoded string — decode that value before reading it. Use getApiCatalogDiscoveryServices first to find the service ID. Do not use this tool for a catalogued service's health, traffic, or ownership data; use getApiCatalogService instead. Requires a Postman Enterprise plan.
Show all 104 Read tools
Read tools 7–56
getApiCatalogDiscoveryServicesLists services that Postman has detected but that are not necessarily in the API Catalog yet.
Full description
Lists services that Postman has detected but that are not necessarily in the API Catalog yet. Use this to find candidates to onboard, or to check whether a service has already been integrated. Filter with \`discoverySource\` (\`api_gateway_app\`, \`insights_project\`, \`infra_watcher\`, \`public_api\`), \`status\` (\`discovered\`, \`integrated\`, \`archived\`), and \`search\` on the name; page with \`limit\` (max 100) and \`cursor\`. Do not use this tool for services already in the catalog — those have analytics and governance data and are read with getApiCatalogServices. Requires a Postman Enterprise plan.
getApiCatalogServiceGets one catalogued service's health, traffic, compliance, ownership, and dependencies in a given system environment.
Full description
Gets one catalogued service's health, traffic, compliance, ownership, and dependencies in a given system environment. Both the service ID and the required \`systemEnvironmentId\` are needed; get them from getApiCatalogServices and getApiCatalogSystemEnvironments. The same service reports different data per environment, so the environment is part of the question, not an optional filter. Do not use this tool for per-endpoint metrics; use getApiCatalogServiceEndpoints instead. Requires a Postman Enterprise plan.
getApiCatalogServiceCiRunsLists CI collection runs for a service, with summary statistics, pipeline details, and Git metadata.
Full description
Lists CI collection runs for a service, with summary statistics, pipeline details, and Git metadata. Use this to tie test results back to a branch, workflow, or commit author. \`systemEnvironmentId\` is required. Filter with \`collectionId\`, \`environmentId\`, \`status\`, \`branch\`, \`workflowName\`, \`actor\`, \`repoName\`, and \`repoOwner\`; order with \`sort\` in \`field:direction\` form over \`timestamp\` or \`duration\`. Do not use this tool for scheduled monitor runs; use getApiCatalogServiceMonitorRuns instead. Requires a Postman Enterprise plan.
getApiCatalogServiceEndpointsLists the endpoints Postman has observed for a service, with per-endpoint traffic and performance metrics.
Full description
Lists the endpoints Postman has observed for a service, with per-endpoint traffic and performance metrics. Use this to find a service's slowest or most error-prone endpoints. \`systemEnvironmentId\` is required. Filter with \`httpMethods\`, \`hosts\`, \`responseCodes\`, and \`search\` on the path; order with \`sort\` in \`field:direction\` form over \`count\`, \`endpoint\`, \`p95LatencyMs\`, or \`errorRate\`. These are observed endpoints, not a specification — do not use this tool to read a service's OpenAPI definition. Requires a Postman Enterprise plan.
getApiCatalogServiceMonitorRunsLists scheduled monitor runs for a service, with summary statistics per run.
Full description
Lists scheduled monitor runs for a service, with summary statistics per run. Use this to check whether a service's monitors are passing and when they last ran. \`systemEnvironmentId\` is required. Filter with \`collectionId\`, \`environmentId\`, and \`status\`; order with \`sort\` in \`field:direction\` form over \`timestamp\`, \`duration\`, or \`failedAssertions\`. Do not use this tool for CI-triggered runs; those are separate and read with getApiCatalogServiceCiRuns. Requires a Postman Enterprise plan.
getApiCatalogServiceSpecificationLintsLists specification lint runs for a service, with per-severity issue counts.
Full description
Lists specification lint runs for a service, with per-severity issue counts. Use this to see whether a service's specifications pass governance rules and which severities are failing. Unlike the other service reads, this one takes no \`systemEnvironmentId\`; scope it with \`specId\` instead. \`severity\` is a threshold — higher severities are always included. Order with \`sort\` in \`field:direction\` form over \`timestamp\` or \`errorCount\`. Do not use this tool to lint a specification on demand; it only reports runs that have already happened. Requires a Postman Enterprise plan.
getApiCatalogServicesLists the services catalogued in one system environment, with their analytics, compliance, and governance metadata.
Full description
Lists the services catalogued in one system environment, with their analytics, compliance, and governance metadata. \`systemEnvironmentId\` is required — call getApiCatalogSystemEnvironments first to get one, and repeat this call per environment when you need a cross-environment view. Narrow with \`name\`, \`tags\`, and \`governanceGroupId\`; page with \`limit\` (max 100) and \`cursor\`. Do not use this tool to find services that are not catalogued yet; use getApiCatalogDiscoveryServices instead. Requires a Postman Enterprise plan.
getApiCatalogSystemEnvironmentGets one system environment by ID.
Full description
Gets one system environment by ID. Use getApiCatalogSystemEnvironments when you need to discover the ID. Do not use this tool to list the services in that environment; use getApiCatalogServices with this environment's ID instead. Requires a Postman Enterprise plan.
getApiCatalogSystemEnvironmentAssociationsLists the workspace environments attached to a system environment.
Full description
Lists the workspace environments attached to a system environment. Use this to see which Postman environments feed a deployment stage before adding or removing any. Narrow to one workspace with \`workspaceId\`; page with \`limit\` (max 100) and \`cursor\`. Requires a Postman Enterprise plan.
getApiCatalogSystemEnvironmentsLists the team's system environments — the deployment stages (for example staging, production) that every service-scoped API Catalog read is keyed by.
Full description
Lists the team's system environments — the deployment stages (for example staging, production) that every service-scoped API Catalog read is keyed by. Call this first whenever you need a \`systemEnvironmentId\` for getApiCatalogServices, getApiCatalogService, getApiCatalogServiceEndpoints, getApiCatalogServiceMonitorRuns, or getApiCatalogServiceCiRuns. Pass \`isProduction=true\` to return only production environments; page with \`limit\` (max 100) and \`cursor\`. These are not Postman environments holding variables — do not confuse them with getEnvironments. Requires a Postman Enterprise plan.
getApiDiscoveryInstructionsReturns instructions (markdown) for finding APIs in Postman — searching the public network, browsing private/internal/team collections, filtering by ownership and visibility, and comparing candidate
Full description
Returns instructions (markdown) for finding APIs in Postman — searching the public network, browsing private/internal/team collections, filtering by ownership and visibility, and comparing candidate APIs. Includes the rules for presenting results with Postman links and the patterns for evaluating tradeoffs between APIs. Call this when the user wants to find, search for, or compare APIs (e.g., "find me an email API", "search for the Payvance API", "compare Payvance and Cashloom"). Prerequisite: call getPostmanContextOverview first if you have not already loaded the Postman Context overview in this session.
getAsyncSpecTaskStatusGets the status of an asynchronous API specification creation task.
getAuditLogEventActionsLists every audit log event action Postman can record.
Full description
Lists every audit log event action Postman can record. This is the vocabulary the \`action\` filter on getAuditLogs expects, so call it first when you need to narrow an audit query to one kind of event. This returns the set of possible actions, not any events that happened. Requires a Postman Enterprise plan.
getAuditLogsGets the team's audit events — who did what and when across the Postman team.
Full description
Gets the team's audit events — who did what and when across the Postman team. Use this to answer questions about account changes, membership changes, and administrative activity. Narrow with \`userId\`, \`action\`, and a \`since\`/\`until\` window in \`YYYY-MM-DD\` format; page with \`limit\` and \`cursor\`, and order with \`orderBy\` (\`asc\` or \`desc\`). Get valid \`action\` values from getAuditLogEventActions rather than guessing them — an invalid action silently returns nothing useful. Prefer \`orderBy\` over the deprecated \`order_by\` parameter. Requires a Postman Enterprise plan.
getAuthenticatedUserGets information about the authenticated user.
Full description
Gets information about the authenticated user. - This endpoint provides “current user” context (\`user.id\`, \`username\`, \`teamId\`, roles). - When a user asks for “my …” (e.g., “my workspaces, my information, etc.”), call this first to resolve the user ID.
getCodeGenerationInstructionsReturns the full workflow instructions for discovering APIs, exploring collections, and generating client code from Postman.
Full description
Returns the full workflow instructions for discovering APIs, exploring collections, and generating client code from Postman. Includes step-by-step guidance, tool usage patterns, and code generation rules. MANDATORY: You MUST call this tool when the user says to "use postman", or when the user wants to do something that requires locating a specific API for the purpose of answering questions, planning a build, and in most cases proceeding to generate code that calls the API. ALWAYS call getCodeGenerationInstructions BEFORE calling other tools in this workflow. This tool returns comprehensive step-by-step instructions on how to search for APIs, gather API-specific context from other tools, and then generate client code based on the context retrieved.
getCollectionGet information about a collection.
Full description
Get information about a collection. By default this tool returns the lightweight collection map (metadata + recursive itemRefs). Use the model parameter to opt in to Postman's full API responses: - model=minimal — root-level folder/request IDs only - model=full — full Postman collection payload.
getCollectionCommentsGets all comments left by users in a collection.
getCollectionContextReturns a markdown-formatted summary of a collection, including its metadata, authentication, variables, and a tree of folders and requests.
Full description
Returns a markdown-formatted summary of a collection, including its metadata, authentication, variables, and a tree of folders and requests. Use this to understand the structure and contents of a collection.
getCollectionFolderGets information about a folder in a collection.
getCollectionForksGets a collection's forked collections.
Full description
Gets a collection's forked collections. The response returns data for each fork, such as the fork's ID, the user who forked it, and the fork's creation date.
getCollectionPullRequestsLists the pull requests opened against a collection.
Full description
Lists the pull requests opened against a collection. Returns each pull request's ID, title, status, and the source and destination collection details. Use this to discover open pull requests on a collection before reviewing or merging one.
getCollectionRequestGets information about a request in a collection.
getCollectionResponseGets information about a response in a collection.
getCollectionTagsGets all the tags associated with a collection.
getCollectionUpdatesTasksGets the status of an asynchronous collection update task.
getCollectionsThe workspace ID query is required for this endpoint.
Full description
The workspace ID query is required for this endpoint. If not provided, the LLM should ask the user to provide it.
getCollectionsForkedByUserGets a list of all the authenticated user's forked collections.
getComponentGets a single component's metadata by ID.
Full description
Gets a single component's metadata by ID. Use \`include\` (\`hasVersions\`, \`latestVersion\`, \`latestVersion.content\`) or \`expand\` (\`latestVersion\`) when you also need the most recently published version. Use getAllComponents first when you need to discover a component ID. Do not use this tool to read unpublished edits; use getComponentDraft instead. Requires a Postman Enterprise plan.
getComponentDraftGets a component's working draft — its latest unpublished content and format.
Full description
Gets a component's working draft — its latest unpublished content and format. The draft is where edits live before they are published, so it may differ from the most recently published version. Use this to read pending changes before publishing. Do not use this tool to read published content; use getComponentVersion instead. Requires a Postman Enterprise plan.
getComponentVersionGets a single published version of a component by version ID.
Full description
Gets a single published version of a component by version ID. Pass \`include=content\` to return the published content itself. Use getComponentVersions first when you need to discover a version ID. Do not use this tool to read the working draft; use getComponentDraft instead. Requires a Postman Enterprise plan.
getComponentVersionsLists a component's published versions.
Full description
Lists a component's published versions. Use this to discover version IDs and labels, or to check whether pending draft edits have been published yet. Pass \`include=content\` when you also need each version's content. Do not use this tool to read unpublished edits; use getComponentDraft instead. Requires a Postman Enterprise plan.
getContextGraphAskGets a submitted Context Graph ask's status and, once it finishes, its result.
Full description
Gets a submitted Context Graph ask's status and, once it finishes, its result. Call this after submitContextGraphAsk with the \`askId\` it returned, and poll while \`status\` is \`pending\` or \`running\` — leave a few seconds between polls rather than calling in a tight loop. \`result\` is only present once \`status\` is \`completed\`; a \`failed\` ask carries a short \`error\` instead. When reporting a completed ask, treat \`result.answer\` as the prose summary and \`result.structured\`, \`result.citations\`, and \`result.provenance\` as the graph data it rests on — cite that evidence rather than presenting the answer on its own, and say so when \`result.provenance.truncated\` is \`true\`, since the ask hit its deadline and the answer is partial.
getDetectedSecretsLocationsLists where one detected secret appears — the workspaces and resources holding it.
Full description
Lists where one detected secret appears — the workspaces and resources holding it. Use this after detectedSecretsQueries to turn a secret ID into the concrete places a person has to go and fix. Requires a \`workspaceId\`, and can be narrowed further with \`resourceType\` and a \`since\`/\`until\` window. Do not use this tool to search for secrets across the team; use detectedSecretsQueries instead. Requires a Postman Enterprise plan.
getDuplicateCollectionTaskStatusGets the status of a collection duplication task.
getEnabledToolsIMPORTANT: Run this tool first when a requested tool is unavailable.
Full description
IMPORTANT: Run this tool first when a requested tool is unavailable. Returns information about which tools are enabled in the full and minimal tool sets, helping you identify available alternatives.
getEnvironmentGets information about an environment.
getEnvironmentContextReturns a markdown-formatted summary of an environment, including its name and enabled variables with their keys, values, and types.
getEnvironmentsGets information about all of your environments.
Full description
Gets information about all of your [environments](https://learning.postman.com/docs/sending-requests/managing-environments/).
getFolderCommentsGets all comments left by users in a folder.
getFolderContextReturns a markdown-formatted summary of a folder within a collection, including its metadata, description, and authentication settings.
getGeneratedCollectionSpecsGets the API specification generated for the given collection.
getGroupGets one Postman user group by ID.
Full description
Gets one Postman user group by ID. Use this when you already hold a group ID — from a collection or workspace role assignment — and need that group's details; use getGroups when you need to list or search. This is a Postman user group, not a SCIM group and not a team.
getGroupsLists the team's Postman user groups — named sets of team members used to grant access collectively.
Full description
Lists the team's Postman user groups — named sets of team members used to grant access collectively. Use this to resolve the group IDs that appear in collection and workspace role responses, or to get a \`groupId\` for the filter on getTeamUsers. These are Postman user groups, not SCIM groups and not teams. Use getTeamUsers for individual members.
getInstalledApiMaintenanceInstructionsReturns instructions (markdown) for maintaining the API requests already installed in the user's project — listing installed requests, checking installed requests against their Postman sources for
Full description
Returns instructions (markdown) for maintaining the API requests already installed in the user's project — listing installed requests, checking installed requests against their Postman sources for upstream changes, finding unused requests, and safely removing installed requests. Installed requests are identifiable by a "Generated by Postman Code" comment in the file header. Call this when the user wants to manage existing integrations (e.g., "what requests do we have installed?", "are my API integrations up to date?", "find unused Postman requests", "remove the Payvance requests"). Prerequisite: call getPostmanContextOverview first if you have not already loaded the Postman Context overview in this session.
getMockGets information about a mock server.
Full description
Gets information about a mock server. - Resource: Mock server entity. Response includes the associated \`collection\` UID and \`mockUrl\`. - Use the \`collection\` UID to navigate back to the source collection.
getMockServerResponseGets the full details of a specific server response, including its \body\, \headers\, and \language\.
Full description
Gets the full details of a specific server response, including its \`body\`, \`headers\`, and \`language\`. - Use \`getMockServerResponses\` first to list available server response IDs. - To check which response is active, call \`getMock\` and read \`config.serverResponseId\`.
getMockServerResponsesGets all server responses configured for a mock server.
Full description
Gets all server responses configured for a mock server. - Server responses simulate 5xx server-level failures (e.g. 500, 503) independently of any specific route or example. - This endpoint returns summary metadata only (id, name, statusCode, timestamps). To get the full body and headers of a specific response, call \`getMockServerResponse\` with the response's \`id\`. - To see which server response is currently active, call \`getMock\` and check \`config.serverResponseId\`.
getMocksGets all active mock servers.
Full description
Gets all active mock servers. By default, returns only mock servers you created across all workspaces. - Always pass either the \`workspace\` or \`teamId\` query to scope results. Prefer \`workspace\` when known. - If you need team-scoped results, set \`teamId\` from the current user: call GET \`/me\` and use \`me.teamId\`. - If both \`teamId\` and \`workspace\` are passed, only \`workspace\` is used.
getMonitorGets information about a monitor.
Read tools 57–104
getMonitorRunResultsGets results for a monitor run, including trimmed execution logs (beforeItem and assertion events only) and result counts.
Full description
Gets results for a monitor run, including trimmed execution logs (beforeItem and assertion events only) and result counts. Use this to inspect per-request assertions and failure details for a specific run. This is Step 3 of the monitor-run workflow: listMonitorExecutions → listRunsForExecution → getMonitorRunResults. The runId must come from listRunsForExecution — do NOT use an executionId here, it will return 404.
getMonitorsGets all monitors.
getPackageGets an active package's metadata and current index script content by package ID.
Full description
Gets an active package's metadata and current index script content by package ID. Use getPackages first when you need to discover a package ID. Do not use this tool to list packages or discover package IDs; use getPackages instead.
getPackagesLists active packages available to the authenticated user.
Full description
Lists active packages available to the authenticated user. Returns package metadata but does not include index script content. Use getPackage with a returned package ID when you also need the current script. Use the response cursor to fetch the next page when more packages are available. Do not use this tool to retrieve a package's script content; use getPackage instead.
getPostmanContextOverviewReturns the Postman Context overview (markdown).
Full description
Returns the Postman Context overview (markdown). Explains the core concepts (workspaces, collections, requests, installed code) and the end-to-end workflow for finding APIs, generating client code, and maintaining installed requests over time. Call this FIRST — and only — when the user wants to explore APIs in Postman's network, answer questions about how an API works, plan an integration, or generate client code grounded in real Postman API definitions, AND you have not already loaded the overview in this session. Do NOT call this for routine Postman operations like listing or editing workspaces, collections, environments, mocks, monitors, or specs — go straight to the relevant resource tool. After reading the overview, route to the appropriate topic-specific instructions tool: getApiDiscoveryInstructions (find/search/compare APIs), getCodeGenerationInstructions (generate client code from a request), or getInstalledApiMaintenanceInstructions (list, update, or remove installed requests).
getPullRequestGets a single pull request by its ID, including source and destination details, reviewers, and the current merge/review status.
Full description
Gets a single pull request by its ID, including source and destination details, reviewers, and the current merge/review status. Use this to inspect a specific pull request returned by getCollectionPullRequests.
getRequestCodeContextReturns comprehensive markdown-formatted context for generating code from a request.
Full description
Returns comprehensive markdown-formatted context for generating code from a request. Includes the full request definition (method, URL, headers, query params, body, auth), all response examples with full details, and merged collection and environment variables with source tags.
getRequestCommentsGets all comments left by users in a request.
getRequestContextReturns a markdown-formatted summary of a request within a collection, including its method, URL, headers, query parameters, path variables, body, authentication, and response example references.
getResponseCommentsGets all comments left by users in a response.
getResponseContextReturns a markdown-formatted summary of a saved response example within a collection request, including its status code, headers, body, and the original request details.
getSdkGets one SDK, including the \buildStatus\ of its generation job.
Full description
Gets one SDK, including the \`buildStatus\` of its generation job. This is the tool to poll after createSdk: \`succeeded\` means the archive is ready for getSdkDownloadUrl, and a failure status is reported here rather than by the original call. Requires a Postman Team or Enterprise plan.
getSdkDownloadUrlGets a short-lived signed URL for a generated SDK's zip archive.
Full description
Gets a short-lived signed URL for a generated SDK's zip archive. The response carries a URL, not the archive — the API deliberately does not stream file contents — and the URL expires within a few minutes, so fetch it at the moment you intend to download and do not store or pass it around. Only works once the SDK's \`buildStatus\` is \`succeeded\`; check with getSdk first, since asking too early returns 409. Requires a Postman Team or Enterprise plan.
getSdkGitConnectionGets one SDK Git connection, including which SDK was last delivered to its target branch and the most recent SDK-update pull request.
Full description
Gets one SDK Git connection, including which SDK was last delivered to its target branch and the most recent SDK-update pull request. Use this to check whether a connection is healthy and current. Requires a Postman Team or Enterprise plan.
getSdkGitConnectionPullRequestsLists the SDK-update pull requests opened through one Git connection.
Full description
Lists the SDK-update pull requests opened through one Git connection. Use this to report on what has been delivered to a repository and what is still waiting to be merged. The record survives disconnection, so a disconnected connection still returns its history. These are pull requests in the connected Git repository, not Postman collection pull requests — use getCollectionPullRequests for those. Requires a Postman Team or Enterprise plan.
getSdkGitConnectionsLists the Git repository connections in a workspace.
Full description
Lists the Git repository connections in a workspace. Each connection ties one collection or specification, in one SDK language, to one target repository, so a source with several languages has several connections. \`workspaceId\` is required. Filter with \`sourceId\`, \`language\`, \`status\`, and \`repositoryUrl\`. Requires a Postman Team or Enterprise plan.
getSdksLists the SDKs the caller can see in a workspace, with each one's build status.
Full description
Lists the SDKs the caller can see in a workspace, with each one's build status. \`workspaceId\` is required. Filter with \`buildStatus\`, \`language\`, and \`sourceId\`, or pass \`sdkIds\` (up to 100, comma-separated) to check several known SDKs at once — note that \`sdkIds\` overrides every other filter. Page with \`limit\` and \`cursor\`. Use \`sdkIds\` here rather than calling getSdk in a loop when you are polling more than one generation job. Requires a Postman Team or Enterprise plan.
getSecretTypesLists the kinds of secret the Secret Scanner recognises, with the type IDs used to filter detectedSecretsQueries.
Full description
Lists the kinds of secret the Secret Scanner recognises, with the type IDs used to filter detectedSecretsQueries. Call this first when you need to search for one specific kind of credential, since the \`secretTypes\` filter takes these IDs and not names. This returns the scanner's vocabulary, not any detected secrets. Requires a Postman Enterprise plan.
getSourceCollectionStatusChecks whether there is a change between the forked collection and its parent (source) collection.
Full description
Checks whether there is a change between the forked collection and its parent (source) collection. If the value of the \`isSourceAhead\` property is \`true\` in the response, then there is a difference between the forked collection and its source collection. **Note:** This endpoint may take a few minutes to return an updated \`isSourceAhead\` status.
getSpecGets information about an API specification.
getSpecCollectionsGets all of an API specification's generated collections.
getSpecDefinitionGets the complete contents of an OpenAPI or AsyncAPI specification's definition.
getSpecFileGets the contents of an API specification's file.
getSpecFilesGets all the files in an API specification.
getStatusOfAnAsyncApiTaskGets the status of an asynchronous task.
getTaggedEntitiesRequires an Enterprise plan.
Full description
**Requires an Enterprise plan.** Tagging is only available on Postman Enterprise plans. This tool returns a 404 error on Free, Basic, and Professional accounts. Gets Postman elements (entities) by a given tag. Tags enable you to organize and search workspaces, APIs, and collections that contain shared tags.
getTeamGets one Postman team by ID.
Full description
Gets one Postman team by ID. Pass \`include=members\` to list everyone with access — managers, members, guests, and groups representing other teams — or \`include=userRoles\` for the team's role assignments. Use getTeams when you need to discover the ID. Member entries carry IDs rather than names; resolve them with getTeamUsers and getGroups.
getTeamAccessRequestsLists a team's pending access requests — people asking to join, to be promoted, or to add members.
Full description
Lists a team's pending access requests — people asking to join, to be promoted, or to add members. Use this to report on what is waiting for a decision, and to get the request IDs that approveDenyAccessRequest needs. Reading requests is safe; acting on them is not. Do not chain straight into approveDenyAccessRequest without an explicit decision from an operator.
getTeamSettingsGets a team's settings.
Full description
Gets a team's settings. Use this to report on a team's current configuration, and to read the existing values before changing any of them with updateTeamSettings.
getTeamUserGets one member of the Postman team by user ID.
Full description
Gets one member of the Postman team by user ID. Use this when you already hold a user ID — from an audit log entry or a role assignment — and need that single person's details; use getTeamUsers when you need to search or list. This returns another person on the team. To find out who the current API key belongs to, use getAuthenticatedUser instead.
getTeamUsersLists the members of the authenticated user's Postman team.
Full description
Lists the members of the authenticated user's Postman team. Use this to resolve the numeric user IDs that appear in audit logs, collection roles, and workspace roles into names an operator can act on. Narrow to one user group with the \`groupId\` query parameter, using an ID from getGroups. This returns other people on the team. To find out who the current API key belongs to, use getAuthenticatedUser instead.
getTeamsLists the Postman teams in the organization.
Full description
Lists the Postman teams in the organization. Use this to discover team IDs before reading a team's settings, members, or access requests. Page with \`limit\` and \`cursor\`, and pass \`teamSettings\` or \`userRoles\` to include those in the response. This lists teams in the organization, not the members of a team — use getTeamUsers for people and getGroups for user groups.
getWorkspaceGets information about a workspace.
Full description
Gets information about a workspace. **Note:** This endpoint's response contains the \`visibility\` field. [Visibility](https://learning.postman.com/docs/collaborating-in-postman/using-workspaces/managing-workspaces/#changing-workspace-visibility) determines who can access the workspace: - \`personal\` — Only you can access the workspace. - \`team\` — All team members can access the workspace. - \`private\` — Only invited team members can access the workspace ([**Team** and **Enterprise** plans only](https://www.postman.com/pricing)). - \`public\` — Everyone can access the workspace. - \`partner\` — Only invited team members and [partners](https://learning.postman.com/docs/collaborating-in-postman/using-workspaces/partner-workspaces/) can access the workspace ([**Team** and **Enterprise** plans only](https://www.postman.com/pricing)).
getWorkspaceActivityFeedGets a workspace's activity feed — who added or removed collections, environments, and other elements, and who joined or left.
Full description
Gets a workspace's activity feed — who added or removed collections, environments, and other elements, and who joined or left. Use this to explain how a workspace reached its current state, or to build a changelog. Narrow with \`userId\` and \`elementType\`, and page with \`limit\` and \`cursor\`. This is workspace-level history. For a single collection's change history use the collection's own tools, and for team-wide administrative events use getAuditLogs.
getWorkspaceContextReturns a markdown-formatted summary of a single workspace, including its collections and environments.
Full description
Returns a markdown-formatted summary of a single workspace, including its collections and environments. Use this to understand what resources are available in a workspace before exploring specific collections or environments.
getWorkspaceEnvironmentsContextReturns a markdown-formatted summary of all environments in a workspace, including their variables.
Full description
Returns a markdown-formatted summary of all environments in a workspace, including their variables. Use this to understand the environment configuration available in a workspace.
getWorkspaceGlobalVariablesGets a workspace's global variables.
Full description
Gets a workspace's global [variables](https://learning.postman.com/docs/sending-requests/variables/#variable-scopes). Global variables enable you to access data between collections, requests, scripts, and environments and are available throughout a workspace.
getWorkspaceRolesGets who has access to a workspace and at what level, covering users, user groups, and partners.
Full description
Gets who has access to a workspace and at what level, covering users, user groups, and partners. Use this to audit access, and to read the current state before changing it. Pass \`include=scim\` to get SCIM IDs alongside Postman IDs. Partner roles do not support SCIM IDs. Resolve the IDs in the response with getTeamUsers and getGroups. For a single collection's access list use getCollectionRoles instead.
getWorkspaceTagsGets all the tags associated with a workspace.
getWorkspaceUpdatesLists a workspace's updates — the announcement posts that keep workspace watchers informed about new features, bug fixes, breaking changes, and other news.
Full description
Lists a workspace's updates — the announcement posts that keep workspace watchers informed about new features, bug fixes, breaking changes, and other news. Filter by \`category\` and page with \`cursor\`. These are authored announcements, not a record of what changed in the workspace. For that use getWorkspaceActivityFeed, and for the workspace's own settings use getWorkspace.
getWorkspacesGets all workspaces you have access to.
Full description
Gets all workspaces you have access to. - For “my …” requests, first call GET \`/me\` and pass \`createdBy={me.user.id}\`. - This endpoint's response contains the visibility field. Visibility determines who can access the workspace: - \`personal\` — Only you can access the workspace. - \`team\` — All team members can access the workspace. - \`private\` — Only invited team members can access the workspace (Professional and Enterprise). - \`public\` — Everyone can access the workspace. - \`partner\` — Invited team members and partners (Professional and Enterprise). - For tools that require the workspace ID, and no workspace ID is provided, ask the user to provide the workspace ID. If the user does not provide the workspace ID, call this first with the createdBy parameter to use the first workspace. - Results are paginated. Use the \`cursor\` parameter to retrieve additional pages. - Examples: - “List my workspaces” → GET \`/me\`, then GET \`/workspaces?createdBy={me.user.id}&limit=100\` - “List my personal workspaces” → GET \`/me\`, then GET \`/workspaces?type=personal&createdBy={me.user.id}&limit=100\` - “List all public workspaces” → GET \`/workspaces?type=public&limit=100\`
getWorkspacesContextReturns a markdown-formatted summary of all workspaces accessible to the user.
Full description
Returns a markdown-formatted summary of all workspaces accessible to the user. Use this to discover available workspaces and their collections before diving into specific resources. Supports pagination and filtering by name.
listMonitorExecutionsLists executions for a monitor.
Full description
Lists executions for a monitor. Cursor-based pagination, 25 results per page. Returns execution metadata including state, trigger, results summary, and timestamps. This is Step 1 of the monitor-run workflow: listMonitorExecutions → listRunsForExecution → getMonitorRunResults. Each execution has an `id` (executionId). To get run results, you must first pass this executionId to listRunsForExecution to obtain run IDs — do NOT use executionId as a runId.
listPrivateNetworkAddRequestsGets all requests to add workspaces to your team's Private API Network.
Full description
Gets all requests to add workspaces to your team's Private API Network. WARNING: This tool is for Private API Network management, not for general workspace operations. For workspace management use: getWorkspaces, getWorkspace, createWorkspace, updateWorkspace, deleteWorkspace.
listPrivateNetworkWorkspacesGets information about workspaces added to your team's Private API Network.
Full description
Gets information about workspaces added to your team's Private API Network. WARNING: This tool is for Private API Network management, not for general workspace operations. For workspace management use: getWorkspaces, getWorkspace, createWorkspace, updateWorkspace, deleteWorkspace.
listRunsForExecutionLists runs for a monitor execution.
Full description
Lists runs for a monitor execution. Each execution may produce multiple runs across regions. Returns run metadata including region, state, result counts, and timestamps. Not paginated. This is Step 2 of the monitor-run workflow: listMonitorExecutions → listRunsForExecution → getMonitorRunResults. Pass the executionId from listMonitorExecutions. Returns run objects whose `id` is the runId needed by getMonitorRunResults.
searchLearningCenterSearch the official Postman documentation and learning resources at https://learning.postman.com.
Full description
Search the official Postman documentation and learning resources at https://learning.postman.com. Use this tool when you need authoritative, up-to-date guidance on how to use Postman features — for example creating mock servers, writing tests, using environments, configuring monitors, or any "how do I…" question about the Postman product. Returns relevant documentation passages with their source URLs. Do not use this tool to search a user's own Postman resources (collections, workspaces, specs) — use `searchPostmanElements` for that.
searchPostmanElementsSearch for Postman entities (requests, collections, workspaces, specs, flows, environments, mocks, and documents).
Full description
Search for Postman entities (requests, collections, workspaces, specs, flows, environments, mocks, and documents). **Ownership:** - `organization` — Search within all resources owned by your organization (default). - `external` — Search within the public Postman network (third-party and community APIs). - `all` — Search across all scopes. **When to use each ownership value and filters:** | Goal | Recommended approach | |------|----------------------| | Find an internal API (e.g. "our notification service") | `ownership: organization` | | Find a trusted API published to the Private Network | `ownership: organization` + `privateNetwork: true` filter | | Find an internal API in all resources of organization and are visible to the organization only | `ownership: organization` + `visibility: internal` filter | | Find an API by your organization that is made publicly visible | `ownership: organization` + `visibility: public` filter | | Find a third party publicly visible API (e.g. "Stripe API", "Twilio API") | `ownership: external` + `visibility: public` filter | | User says "our APIs", "internal", "team" | `ownership: organization` | | Search across all scopes | `ownership: all` | **Element Types:** - `requests`: Search for individual API requests. - `collections`: Search for API collections. - `workspaces`: Search for Postman workspaces. - `specs`: Search for API specifications. - `flows`: Search for Postman Flows. - `environments`: Search for Postman Environments. - `mocks`: Search for Postman Mock Servers. - `documents`: Search for Postman workspace documents. **Filters:** Use the `filters` parameter to narrow results. The top-level key must be `$and` with an array of condition objects. Each condition object must contain exactly one field key. Supported filter fields: | Field | Operators | Notes | |-------|-----------|-------| | `workspaceId` | `$eq`, `$ne`, `$in`, `$nin` | All element types. `$in`/`$nin` accept arrays. | | `collectionId` | `$eq`, `$ne`, `$in`, `$nin` | Requests and collections only. | | `visibility` | `$eq`, `$ne` | Values: `public`, `partner`, `internal`. All element types. | | `privateNetwork` | `$eq`, `$ne` | Boolean. All element types. | | `publisherIsVerified` | `$eq`, `$ne` | Boolean. All element types. | | `method` | `$eq`, `$ne`, `$in`, `$nin` | HTTP methods (GET, POST, etc.). Requests only. | | `tags` | `$eq`, `$ne`, `$in`, `$nin` | Workspaces and collections only. | | `requestId` | `$eq`, `$ne`, `$in`, `$nin` | Requests only. | | `specificationId` | `$eq`, `$ne`, `$in`, `$nin` | Specs only. | | `flowId` | `$eq`, `$ne`, `$in`, `$nin` | Flows only. | | `documentId` | `$eq`, `$ne`, `$in`, `$nin` | Documents only. | | `createdBy` | `$eq`, `$ne`, `$in`, `$nin` | All element types. | | `organizationId` | `$eq`, `$ne`, `$in`, `$nin` | All element types. | | `teamId` | `$eq`, `$ne`, `$in`, `$nin` | All element types. | | `isGitConnected` | `$eq`, `$ne` | Boolean. Workspaces, collections, requests, specs, flows, environments, mocks, documents. | | `type` | `$eq`, `$ne`, `$in`, `$nin` | Requests only. | **Filter examples:** - Private API Network only: `{"$and":[{"privateNetwork":{"$eq":true}}]}` - Single workspace: `{"$and":[{"workspaceId":{"$eq":"ws-abc123"}}]}` - Multiple workspaces: `{"$and":[{"workspaceId":{"$in":["ws-1","ws-2"]}}]}` - Public visibility: `{"$and":[{"visibility":{"$eq":"public"}}]}` - GET requests only: `{"$and":[{"method":{"$eq":"GET"}}]}` - Combine conditions: `{"$and":[{"visibility":{"$eq":"public"}},{"workspaceId":{"$eq":"ws-abc123"}}]}` - Environments in a workspace: `{"$and":[{"workspaceId":{"$eq":"ws-abc123"}}]}`
Write 109
addApiCatalogSystemEnvironmentAssociationsAttaches workspace environments to a system environment.
Full description
Attaches workspace environments to a system environment. Send 1 to 25 \`workspaceEnvironmentIds\` per call, each an environment UID (\`userId\`-\`environmentId\`). \`allowPartial=false\` rejects the whole call if any single association is ineligible, while \`allowPartial=true\` adds the eligible ones and skips the rest — prefer \`false\` unless you intend to accept a partial result, and read the response to see which were skipped. Do not use this tool to create the environments themselves; use createEnvironment first. Requires a Postman Enterprise plan.
addWorkspaceToPrivateNetworkPublishes a workspace to your team's Private API Network.
Full description
Publishes a workspace to your team's Private API Network. WARNING: This tool is for Private API Network management, not for general workspace operations. For workspace management use: getWorkspaces, getWorkspace, createWorkspace, updateWorkspace, deleteWorkspace.
approveDenyAccessRequestApproves or denies a pending team access request.
Full description
Approves or denies a pending team access request. Get the request ID from getTeamAccessRequests. Approving grants someone access to the team and its contents, and that is an authorization decision, not a piece of bookkeeping. Only call this when an operator has explicitly told you which request to approve or deny — never to clear a backlog of pending requests, and never by inferring intent from the request itself.
createAccessRequestCreates an access request against a team — to join it, to raise a user's role, to add members, or to request team role access to another team.
Full description
Creates an access request against a team — to join it, to raise a user's role, to add members, or to request team role access to another team. This asks for a privilege change on someone's behalf, and if team discovery is enabled the request is approved automatically, which means it can grant access with no human in the loop. Only call it on an explicit request from the person the access is for.
createApiCatalogSystemEnvironmentCreates a system environment for the team.
Full description
Creates a system environment for the team. \`name\` and \`color\` (a six-digit hex code such as \`#00FF00\`) are both required, and the name must be unique within the team — a duplicate returns 409. Optionally set \`label\` (lowercase alphanumerics, hyphens, and underscores only), \`description\`, and \`isProduction\`. Do not use this tool to create a Postman environment with variables; use createEnvironment instead. Requires a Postman Enterprise plan.
createCollectionCreates a collection using the Postman Collection v2.1.0 schema format.
Full description
Creates a collection using the [Postman Collection v2.1.0 schema format](https://schema.postman.com/collection/json/v2.1.0/draft-07/docs/index.html). **Note:** If you do not include the \`workspace\` query parameter, the system creates the collection in the oldest personal Internal workspace you own.
Show all 109 Write tools
Write tools 7–56
createCollectionCommentCreates a comment on a collection.
Full description
Creates a comment on a collection. To create a reply on an existing comment, include the \`threadId\` property in the request body. **Note:** This endpoint accepts a max of 10,000 characters.
createCollectionFolderCreates a folder in a collection.
Full description
Creates a folder in a collection. For a complete list of properties, refer to the **Folder** entry in the [Postman Collection Format documentation](https://schema.postman.com/collection/json/v2.1.0/draft-07/docs/index.html). You can use this endpoint to to import requests and responses into a newly-created folder. To do this, include the \`requests\` field and the list of request objects in the request body. For more information, see the provided example. **Note:** It is recommended that you pass the \`name\` property in the request body. If you do not, the system uses a null value. As a result, this creates a folder with a blank name.
createCollectionForkCreates a fork from an existing collection into a workspace.
Full description
Creates a [fork](https://learning.postman.com/docs/collaborating-in-postman/version-control/#creating-a-fork) from an existing collection into a workspace.
createCollectionPullRequestCreates a pull request to merge changes from a forked collection into its parent (destination) collection.
Full description
Creates a pull request to merge changes from a forked collection into its parent (destination) collection. Provide the title, description, source and destination collection IDs, and reviewer IDs. Use this after forking a collection (createCollectionFork) to propose the fork's changes for review rather than hard-merging them directly.
createCollectionRequestCreates a request in a collection.
Full description
Creates a request in a collection. For a complete list of properties, refer to the **Request** entry in the [Postman Collection Format documentation](https://schema.postman.com/collection/json/v2.1.0/draft-07/docs/index.html). **Note:** It is recommended that you pass the \`name\` property in the request body. If you do not, the system uses a null value. As a result, this creates a request with a blank name.
createCollectionResponseCreates a request response in a collection.
Full description
Creates a request response in a collection. For a complete list of request body properties, refer to the **Response** entry in the [Postman Collection Format documentation](https://schema.postman.com/collection/json/v2.1.0/draft-07/docs/index.html). **Note:** It is recommended that you pass the \`name\` property in the request body. If you do not, the system uses a null value. As a result, this creates a response with a blank name.
createComponentCreates a component in the team's component library and seeds its first draft with the content you provide.
Full description
Creates a component in the team's component library and seeds its first draft with the content you provide. Use this when a team wants a reusable schema, parameter, response, or security scheme that specifications can reference instead of redefining. The component starts active and unpublished: the content lands in its draft only. Call createComponentVersion afterwards to publish it and make it referenceable. Do not use this tool to edit an existing component's content; use updateComponentDraft instead. Requires a Postman Enterprise plan.
createComponentVersionPublishes the component's current draft as a new immutable version under the \label\ you supply, making it referenceable by the team's specifications.
Full description
Publishes the component's current draft as a new immutable version under the \`label\` you supply, making it referenceable by the team's specifications. Labels must be unique per component. Publishing cannot be undone and the resulting version cannot be edited — publish another version to supersede it. Archived components cannot be published; restore them with updateComponent first. Do not use this tool to save work in progress; use updateComponentDraft instead. Requires a Postman Enterprise plan.
createEnvironmentCreates an environment.
Full description
Creates an environment. **Note:** - The request body size cannot exceed the maximum allowed size of 30MB. - If you receive an HTTP \`411 Length Required\` error response, manually pass the \`Content-Length\` header and its value in the request header. - If you do not include the \`workspace\` query parameter, the system creates the environment in the oldest personal Internal workspace you own. - Only [shared variable](https://learning.postman.com/docs/use/send-requests/variables/variables/#share-variable-values) values can be modified through the Postman API. A shared variable is an environment variable with its value synced and stored in the Postman cloud, and can be accessed by your teammates in the environment's workspace.
createFolderCommentCreates a comment on a folder.
Full description
Creates a comment on a folder. To create a reply on an existing comment, include the \`threadId\` property in the request body. **Note:** This endpoint accepts a max of 10,000 characters.
createMockCreates a mock server in a collection.
Full description
Creates a mock server in a collection. - Pass the collection UID (ownerId-collectionId), not the bare collection ID. - If you only have a \`collectionId\`, resolve the UID first: 1) Prefer GET \`/collections/{collectionId}\` and read \`uid\`, or 2) Construct \`{ownerId}-{collectionId}\` using ownerId from GET \`/me\`: - For team-owned collections: \`ownerId = me.teamId\` - For personal collections: \`ownerId = me.user.id\` - Use the \`workspace\` query to place the mock in a specific workspace. Prefer explicit workspace scoping.
createMockServerResponseCreates a server response on a mock server.
Full description
Creates a server response on a mock server. Server responses simulate 5xx server-level failures (e.g. 500, 503) that are agnostic to any specific route — when active, every request to the mock returns this response. - \`statusCode\` must be a 5xx value (500–599). - \`body\` is a raw string — pass the response body exactly as the mock should return it (e.g. a JSON string like \`"{\"message\":\"error\"}"\` or plain text). - \`language\` controls syntax highlighting in the Postman UI (\`json\`, \`xml\`, \`html\`, \`javascript\`, \`text\`). It does not affect the actual response Content-Type — set that via \`headers\` instead. - \`headers\` is an array of \`{key, value}\` pairs for response headers (e.g. \`[{"key": "Content-Type", "value": "application/json"}]\`). - You can create multiple server responses per mock, but only one can be active at a time. Creating a response does NOT automatically activate it — call \`updateMock\` with \`config.serverResponseId\` set to the new response's \`id\` to activate it.
createMonitorCreates a monitor.
Full description
Creates a monitor. **Note:** - You cannot create monitors for collections added to an API definition. - If you do not pass the \`workspace\` query parameter, the system creates the monitor in the oldest personal Internal workspace you own.
createPackageCreates a Postman Package Library package and its initial index script.
Full description
Creates a Postman Package Library package and its initial index script. Use this when you want to add reusable JavaScript functions, tests, or utilities for a team to import into Postman scripts. A workspace ID is required to identify the workspace where the package is created. Do not use this tool to modify an existing package; use updatePackage instead.
createRequestCommentThe request ID must contain the team ID as a prefix, in \teamId-requestId\ format.
Full description
The request ID must contain the team ID as a prefix, in \`teamId-requestId\` format. For example, if you're creating a comment on collection ID \`24585957-[example ID]\` (note on the prefix), and the collection request's ID is \`[example ID]\`, then the \`{requestId}\` must be \`24585957-[example ID]\`.
createResponseCommentCreates a comment on a response.
Full description
Creates a comment on a response. To create a reply on an existing comment, include the \`threadId\` property in the request body. **Note:** This endpoint accepts a max of 10,000 characters.
createSdkStarts an SDK generation job for one language from a collection or a specification.
Full description
Starts an SDK generation job for one language from a collection or a specification. Returns 202 with a job record — the SDK does not exist yet. Poll getSdk and wait for \`buildStatus\` to reach \`succeeded\` before trying to download it. The request body depends on the \`language\` you pick, so send only the properties that language accepts. One call generates one language; call it once per language rather than expecting a bundle. Requires a Postman Team or Enterprise plan.
createSdkGitConnectionConnects a collection or specification to a Git repository for one SDK language, so generated SDK updates can be delivered there as pull requests.
Full description
Connects a collection or specification to a Git repository for one SDK language, so generated SDK updates can be delivered there as pull requests. The connection starts \`active\`. Each source and language pair supports exactly one connection — creating a second returns 409, and the way to change an existing one is updateSdkGitConnection, not a repeat call here. \`autoUpdatePullRequestsEnabled\` is Enterprise-only and is forced to false on Team plans. Requires a Postman Team or Enterprise plan.
createSpecCreates an API specification in Postman's Spec Hub.
Full description
Creates an API specification in Postman's [Spec Hub](https://learning.postman.com/docs/design-apis/specifications/overview/). Specifications can be single or multi-file. **Note:** - Postman supports OpenAPI (2.0, 3.0, and 3.1), AsyncAPI (2.0 and 3.0), protobuf (2 and 3), GraphQL, and Smithy specifications. - If the file path contains a \`/\` (forward slash) character, then a folder is created. For example, if the path is the \`components/schemas.json\` value, then a \`components\` folder is created with the \`schemas.json\` file inside. - Multi-file specifications can only have one root file. - Files cannot exceed a maximum of 12 MB in size.
createSpecFileCreates a file for an OpenAPI or a protobuf 2 or 3 specification.
Full description
Creates a file for an OpenAPI or a protobuf 2 or 3 specification. **Note:** - If the file path contains a \`/\` (forward slash) character, then a folder is created. For example, if the path is the \`components/schemas.json\` value, then a \`components\` folder is created with the \`schemas.json\` file inside. - Creating a spec file assigns it the \`DEFAULT\` file type. - Multi-file specifications can only have one root file. - Files cannot exceed a maximum of 10 MB in size.
createTeamCreates a new Postman team in the organization.
Full description
Creates a new Postman team in the organization. \`name\` accepts only alphanumeric characters and spaces. This creates a billable organizational unit and is not something to do speculatively — only call it on an explicit, specific instruction to create a team, never to satisfy a vaguer request such as organizing or setting up a workspace. Use createWorkspace for that instead.
createWorkspaceCreates a new workspace.
Full description
Creates a new [workspace](https://learning.postman.com/docs/collaborating-in-postman/using-workspaces/creating-workspaces/). **Note:** - This endpoint returns a 403 \`Forbidden\` response if the user does not have permission to create workspaces. [Admins and Super Admins](https://learning.postman.com/docs/collaborating-in-postman/roles-and-permissions/#team-roles) can configure workspace permissions to restrict users and/or user groups from creating workspaces or require approvals for the creation of team workspaces. - Private and [Partner Workspaces](https://learning.postman.com/docs/collaborating-in-postman/using-workspaces/partner-workspaces/) are available on Postman [**Team** and **Enterprise** plans](https://www.postman.com/pricing). - There are rate limits when publishing public workspaces. - Public team workspace names must be unique. - The \`teamId\` property must be passed in the request body if [Postman Organizations](https://learning.postman.com/docs/administration/onboarding-checklist) is enabled.
createWorkspaceUpdatePublishes an update in a workspace, notifying everyone watching it.
Full description
Publishes an update in a workspace, notifying everyone watching it. Use this to announce a breaking change, a release, or a deprecation to the workspace's consumers. This notifies real people, so only post when explicitly asked to announce something, and post the message you were given rather than a summary you composed. It does not change the workspace itself — use updateWorkspace for settings.
deleteApiCollectionCommentDeletes a comment from an API's collection.
Full description
Deletes a comment from an API's collection. On success, this returns an HTTP \`204 No Content\` response. **Note:** Deleting the first comment of a thread deletes all the comments in the thread.
deleteCollectionDeletes a collection.
deleteCollectionCommentDeletes a comment from a collection.
Full description
Deletes a comment from a collection. On success, this returns an HTTP \`204 No Content\` response. **Note:** Deleting the first comment of a thread deletes all the comments in the thread.
deleteCollectionFolderDeletes a folder in a collection.
deleteCollectionRequestDeletes a request in a collection.
deleteCollectionResponseDeletes a response in a collection.
deleteEnvironmentDeletes an environment.
deleteFolderCommentDeletes a comment from a folder.
Full description
Deletes a comment from a folder. On success, this returns an HTTP \`204 No Content\` response. **Note:** Deleting the first comment of a thread deletes all the comments in the thread.
deleteMockDeletes a mock server.
Full description
Deletes a mock server. - Resource: Mock server entity. This is destructive. - Ensure you are targeting the correct mock ID.
deleteMockServerResponseDeletes a server response from a mock server.
Full description
Deletes a server response from a mock server. - If this server response is currently active (\`config.serverResponseId\` on the mock), deleting it will not automatically deactivate it. Call \`updateMock\` with \`config.serverResponseId: null\` first to deactivate. - This action is destructive and cannot be undone.
deleteMonitorDeletes a monitor.
deletePackageDeletes a package and its associated index script content.
Full description
Deletes a package and its associated index script content. This operation returns no content and also succeeds when the package no longer exists. Do not use this tool to clear or replace script content while retaining the package; use updatePackage instead.
deleteRequestCommentDeletes a comment from a request.
Full description
Deletes a comment from a request. On success, this returns an HTTP \`204 No Content\` response. **Note:** Deleting the first comment of a thread deletes all the comments in the thread.
deleteResponseCommentDeletes a comment from a response.
Full description
Deletes a comment from a response. On success, this returns an HTTP \`204 No Content\` response. **Note:** Deleting the first comment of a thread deletes all the comments in the thread.
deleteSdkDeletes an SDK record and the stored archive behind it.
Full description
Deletes an SDK record and the stored archive behind it. Returns 204 with no body on success. Anyone still holding a download URL loses access to the artifact. This cannot cancel a generation job that is still running — a job in progress has to finish first. Only call this on an explicit instruction naming the SDK. Requires a Postman Team or Enterprise plan.
deleteSpecDeletes an API specification.
Full description
Deletes an API specification. On success, this returns an HTTP \`204 No Content\` response.
deleteSpecFileDeletes a file in an API specification.
Full description
Deletes a file in an API specification. On success, this returns an HTTP \`204 No Content\` response.
deleteWorkspaceDeletes an existing workspace.
deleteWorkspaceUpdateDeletes a workspace update.
Full description
Deletes a workspace update. This removes an announcement watchers may already have seen and cannot be undone. Prefer patchWorkspaceUpdate to correct a mistake — deleting leaves consumers with no record of a change they were told about. Only delete on an explicit instruction.
detectedSecretsQueriesSearches the secrets Postman's Secret Scanner has detected across the team.
Full description
Searches the secrets Postman's Secret Scanner has detected across the team. Despite being a POST this only reads — the body carries the query, and an empty body returns everything. Filter with \`secretTypes\` (IDs from getSecretTypes), \`statuses\` (\`ACTIVE\`, \`FALSE_POSITIVE\`, \`REVOKED\`, \`ACCEPTED_RISK\`), \`resolved\`, \`workspaceVisibilities\`, and either \`workspaceIds\` or \`resources\` — those last two are mutually exclusive, and sending both fails. Page with \`limit\` and \`cursor\`, and pass \`include=meta.total\` when you need the total count. Secret values come back obfuscated and hashed, never in full. Use getDetectedSecretsLocations to find where a specific secret appears. Requires a Postman Enterprise plan.
duplicateCollectionCreates a duplicate of the given collection in another workspace.
Full description
Creates a duplicate of the given collection in another workspace. Use the GET \`/collection-duplicate-tasks/{taskId}\` endpoint to get the duplication task's current status.
generateCollectionCreates a collection from the given API specification.
Full description
Creates a collection from the given API specification. The specification must already exist or be created before it can be used to generate a collection. The response contains a polling link to the task status.
generateSpecFromCollectionGenerates an OpenAPI 2.0, 3.0, or 3.1 specification for the given collection.
Full description
Generates an OpenAPI 2.0, 3.0, or 3.1 specification for the given collection. The response contains a polling link to the task status.
getWorkspaceUpdateGets one workspace update by ID.
Full description
Gets one workspace update by ID. Use getWorkspaceUpdates to discover the ID. This is an announcement post, not the workspace's settings — use getWorkspace for those.
managePartnerWorkspaceInvitesManages Partner Workspace access: invites partners by email address, removes them from one workspace, or removes them from the partnership and every workspace in it.
Full description
Manages Partner Workspace access: invites partners by email address, removes them from one workspace, or removes them from the partnership and every workspace in it. Existing partners are added directly; new email addresses are sent an invitation. Two of these three actions are broad and irreversible in effect — removing someone from a partnership revokes their access to every shared workspace at once, not just the one you were looking at. Confirm the scope before calling, and only act on an explicit instruction naming the addresses and the action. Inviting sends real email to external people, so never invite speculatively or to an address you inferred. Requires a Team or Enterprise plan, and the Partner Manager, Workspace Editor, or Admin role depending on the action.
manageTeamMemberRolesAdds or removes roles in bulk for users, groups, teams, and organizations within a team.
Full description
Adds or removes roles in bulk for users, groups, teams, and organizations within a team. Removing a role from a group or a team strips that role's permissions from every member of it at once, so the blast radius is much larger than the size of the request body. This changes who can do what. Only call it on an explicit instruction naming the entities and roles involved, and read the current state with getTeam (\`include=userRoles\`) first so you can describe what will change.
mergeCollectionForkThis endpoint is deprecated.
Full description
**This endpoint is deprecated.** Merges a forked collection back into its parent collection. You must have the [Editor role](https://learning.postman.com/docs/collaborating-in-postman/roles-and-permissions/#collection-roles) for the collection to merge a fork.
Write tools 57–106
patchCollectionUpdates specific collection information, such as its name, events, or its variables.
Full description
Updates specific collection information, such as its name, events, or its variables. For more information, see the [Postman Collection Format documentation](https://schema.postman.com/collection/json/v2.1.0/draft-07/docs/index.html). **Important usage notes:** - **Sequential calls only.** Do NOT call \`patchCollection\` in parallel with other \`patchCollection\` calls for the same collection — concurrent PATCH requests conflict with each other and cause cancellation errors. Always wait for one call to complete before making another. - **Partial updates.** Only include the fields you want to change. Omit all other fields entirely; unspecified fields are left unchanged. - **Variables (\`collection.variable\`).** Send \`key\` and \`value\` for each variable, and use \`disabled\` to turn one off. An \`enabled\` field is accepted but silently ignored, so \`disabled\` is the only one that takes effect. - **Secret variables.** You can't set secret variables through this endpoint. Manage cloud- or vault-backed secrets through environments instead. - **Events (\`collection.events\`).** Each event's \`script.id\` is required and must be supplied by you — generate a UUID string for it. Omitting it fails with \`Parameters required: ('id') for key: 'collection.events.script'\`. The event itself is identified by its \`script.id\`.
patchEnvironmentUpdates specific environment properties, such as its name and variables.
Full description
Updates specific environment properties, such as its name and variables. **Note:** - You can only perform one type of operation at a time. For example, you cannot perform an \`add\` and \`replace\` operation in the same call. - The request body size cannot exceed the maximum allowed size of 30MB. - If you receive an HTTP \`411 Length Required\` error response, manually pass the \`Content-Length\` header and its value in the request header. - To add a description to an existing variable, use the \`add\` operation. - Only [shared variable](https://learning.postman.com/docs/use/send-requests/variables/variables/#share-variable-values) values can be modified through the Postman API. A shared variable is an environment variable with its value synced and stored in the Postman cloud, and can be accessed by your teammates in the environment's workspace.
patchWorkspaceUpdateEdits a published workspace update.
Full description
Edits a published workspace update. Requires the \`application/merge-patch+json\` Content-Type header, and only the fields you send are changed. Watchers may have already read the original, so correct an update rather than rewriting its meaning, and post a new one with createWorkspaceUpdate when the news itself has changed.
postApiCatalogDiscoveryServicesRegisters services with the API Catalog as discovered services, for sources Postman cannot detect on its own.
Full description
Registers services with the API Catalog as discovered services, for sources Postman cannot detect on its own. Accepts up to 20 services per call; each needs at least a \`name\`. Supply \`apiDefinition\` to attach an OpenAPI definition, or \`endpoints\` to list endpoints directly — if you send both, \`endpoints\` is ignored. Without \`providerServiceId\` the system derives one from \`{name}:{version}\`, so pass it explicitly when you need a stable identifier across calls. Do not use this tool to create a Postman API specification or collection; it only adds catalog discovery records. Requires a Postman Enterprise plan.
publishDocumentationPublishes a collection's documentation.
Full description
Publishes a collection's documentation. This makes it publicly available to anyone with the link to the documentation. **Note:** - Your [Postman plan](https://www.postman.com/pricing/) impacts your use of these endpoints: - For **Free** and **Solo** users, you must have permissions to edit the collection. - If [API Governance and Security](https://learning.postman.com/docs/api-governance/configurable-rules/configurable-rules-overview/) is enabled for your [**Enterprise**](https://www.postman.com/pricing/) team, only users with the [Community Manager role](https://learning.postman.com/docs/collaborating-in-postman/roles-and-permissions/#team-roles) can publish documentation. - Publishing is only supported for collections with HTTP requests. - You cannot publish a collection added to an API.
publishMockPublishes a mock server.
Full description
Publishes a mock server. Publishing a mock server sets its **Access Control** configuration setting to public.
pullCollectionChangesPulls the changes from a parent (source) collection into the forked collection.
Full description
Pulls the changes from a parent (source) collection into the forked collection. In the endpoint's response: - The \`destinationId\` is the ID of the forked collection. - The \`sourceId\` is the ID of the source collection.
putCollectionReplaces the contents of a collection using the Postman Collection v2.1.0 schema format.
Full description
Replaces the contents of a collection using the [Postman Collection v2.1.0 schema format](https://schema.postman.com/collection/json/v2.1.0/draft-07/docs/index.html). Include the collection's ID values in the request body. If you do not, the endpoint removes the existing items and creates new items. - To perform an update asynchronously, use the \`Prefer\` header with the \`respond-async\` value. When performing an async update, this endpoint returns a HTTP \`202 Accepted\` response. - For a complete list of properties and information, see the [Postman Collection Format documentation](https://schema.postman.com/collection/json/v2.1.0/draft-07/docs/index.html). - For protocol profile behavior, refer to Postman's [Protocol Profile Behavior documentation](https://github.com/postmanlabs/postman-runtime/blob/develop/docs/protocol-profile-behavior.md). **Note:** - The maximum collection size this endpoint accepts cannot exceed 100 MB. - Use the GET \`/collection-updates-tasks/{taskId}\` endpoint to get the collection's update status when performing an asynchronous update. - If you don't include the collection items' ID values from the request body, the endpoint **removes** the existing items and recreates the items with new ID values. - To copy another collection's contents to the given collection, remove all ID values before you pass it in this endpoint. If you do not, this endpoint returns an error. These values include the \`id\`, \`uid\`, and \`postman_id\` values.
putEnvironmentReplaces all the contents of an environment with the given information.
Full description
Replaces all the contents of an environment with the given information. **Note:** - The request body size cannot exceed the maximum allowed size of 30MB. - If you receive an HTTP \`411 Length Required\` error response, manually pass the \`Content-Length\` header and its value in the request header. - Only [shared variable](https://learning.postman.com/docs/use/send-requests/variables/variables/#share-variable-values) values can be modified through the Postman API. A shared variable is an environment variable with its value synced and stored in the Postman cloud, and can be accessed by your teammates in the environment's workspace.
removeApiCatalogSystemEnvironmentAssociationsDetaches workspace environments from a system environment.
Full description
Detaches workspace environments from a system environment. Send 1 to 25 \`workspaceEnvironmentIds\` per call, each an environment UID (\`userId\`-\`environmentId\`). This only removes the association — the underlying Postman environments are left intact. Do not use this tool to delete an environment; use deleteEnvironment instead. Requires a Postman Enterprise plan.
removeTeamMembersRemoves users, groups, or organizations from a Postman team.
Full description
Removes users, groups, or organizations from a Postman team. Returns 204 with no body on success. This is destructive and not self-reversing: removed members lose access to the team's collections, environments, and workspaces, and restoring them means re-inviting them and rebuilding their roles. Only call it on an explicit instruction naming exactly who to remove. Never call it to tidy up inactive members, to act on a list you assembled yourself, or as a step in some larger cleanup.
removeWorkspaceFromPrivateNetworkRemoves a workspace from your team's Private API Network.
Full description
Removes a workspace from your team's Private API Network. This does not delete the workspace itself — it only removes it from the Private API Network folder. WARNING: This tool is for Private API Network management, not for general workspace operations. For workspace management use: getWorkspaces, getWorkspace, createWorkspace, updateWorkspace, deleteWorkspace.
resolveCommentThreadResolves a comment and any associated replies.
Full description
Resolves a comment and any associated replies. On success, this returns an HTTP \`204 No Content\` response. Comment thread IDs return in the GET \`/comments\` response for [collections](https://www.postman.com/postman/workspace/postman-public-workspace/request/12959542-[example ID]) and [collection items](https://www.postman.com/postman/workspace/postman-public-workspace/folder/12959542-[example ID]).
respondPrivateNetworkAddRequestResponds to a user's request to add a workspace to your team's Private API Network.
Full description
Responds to a user's request to add a workspace to your team's Private API Network. Only managers can approve or deny a request. Once approved, the workspace will appear in the team's Private API Network. WARNING: This tool is for Private API Network management, not for general workspace operations. For workspace management use: getWorkspaces, getWorkspace, createWorkspace, updateWorkspace, deleteWorkspace.
reviewPullRequestReviews a pull request by performing an action on it.
Full description
Reviews a pull request by performing an action on it. The required \`action\` field determines the outcome: - \`approve\` — approve the pull request for merge. - \`merge\` — merge the pull request into its destination (parent) collection. - \`decline\` — decline the pull request; optionally include a \`comment\` explaining why. - \`unapprove\` — revoke a previous \`approve\` (does not decline the pull request). Use this tool to formally approve, merge, decline, or unapprove a pull request.
runCollectionRuns a Postman collection by ID with detailed test results and execution statistics.
Full description
Runs a Postman collection by ID with detailed test results and execution statistics. Supports optional environment for variable substitution. Note: Advanced parameters like custom delays and other runtime options are not yet available.
runMonitorRuns a monitor and returns its run results.
Full description
Runs a monitor and returns its run results. **Note:** - If you pass the \`async=true\` query parameter, the response does not return the \`stats\`, \`executions\`, and \`failures\` responses. To get this information for an asynchronous run, call the GET \`/monitors/{id}\` endpoint. - If the call exceeds 300 seconds, the endpoint returns an HTTP \`202 Accepted\` response. Use the GET \`/monitors/{id}\` endpoint to check the run's status in the response's \`lastRun\` property. To avoid this, it is recommended that you include the \`async=true\` query parameter when using this endpoint.
submitContextGraphAskAsks a natural-language question about the team's software estate — which APIs and services exist, what they expose, and how they depend on each other — and gets an answer grounded in the team's
Full description
Asks a natural-language question about the team's software estate — which APIs and services exist, what they expose, and how they depend on each other — and gets an answer grounded in the team's Context Graph. Use this for questions about the estate as a whole that no single collection or workspace can answer. This is asynchronous and does not return the answer: it returns an \`askId\` with status \`pending\`. Poll getContextGraphAsk with that ID until \`status\` is \`completed\` or \`failed\`, and only report an answer once it is \`completed\`. Set \`includeAnswer=false\` when you want just the graph data and intend to phrase the answer yourself, and lower \`maxSteps\` (1-15, default 10) to cap how much work the ask does. Do not use this tool to search Postman elements by name; use searchPostmanElements instead. Each ask counts against the team's quota, so ask one well-formed question rather than retrying variations of the same one. Requires Context Graph to be enabled for the team.
syncCollectionWithSpecSyncs a collection generated from an API specification.
Full description
Syncs a collection generated from an API specification. This is an asynchronous endpoint that returns an HTTP \`202 Accepted\` response. **Note:** - This endpoint only supports the OpenAPI 2.0, 3.0, and 3.1 specification types. - You can only sync collections generated from the given spec ID.
syncSpecWithCollectionSyncs an API specification linked to a collection.
Full description
Syncs an API specification linked to a collection. This is an asynchronous endpoint that returns an HTTP \`202 Accepted\` response. **Note:** - This endpoint only supports the OpenAPI 2.0, 3.0, and 3.1 specification types. - You can only sync collections generated from the given specification ID.
transferCollectionFoldersCopies or moves folders into a collection or folder.
transferCollectionRequestsCopies or moves requests into a collection or folder.
transferCollectionResponsesCopies or moves responses into a request.
transferWorkspaceElementMoves or copies an element — a collection, environment, mock, monitor, or Flows module or action — from one workspace into another.
Full description
Moves or copies an element — a collection, environment, mock, monitor, or Flows module or action — from one workspace into another. Both workspaces' activity feeds record the change. Transferring changes who can see the element, since access follows the destination workspace. Team workspaces cannot transfer into personal workspaces. To duplicate a collection without moving it, use duplicateCollection instead.
transferWorkspaceToTeamMoves a workspace from one team to another, with \source\ as the current team and \destination\ as the new one.
Full description
Moves a workspace from one team to another, with \`source\` as the current team and \`destination\` as the new one. Only available on Enterprise plans with Postman Organizations enabled. This rewrites access as a side effect: anyone whose role exists in the source team but not the destination loses it on transfer, so people can silently lose access to the workspace's contents. Read getWorkspaceRoles first so you can say who is affected, and only call this on an explicit instruction naming both teams. To move a single collection or environment instead of the whole workspace, use transferWorkspaceElement.
unpublishDocumentationUnpublishes a collection's documentation.
Full description
Unpublishes a collection's documentation. On success, this returns an HTTP \`204 No Content\` response.
unpublishMockUnpublishes a mock server.
Full description
Unpublishes a mock server. Unpublishing a mock server sets its **Access Control** configuration setting to private.
updateApiCatalogSystemEnvironmentUpdates a system environment's \name\, \description\, \color\, or \isProduction\.
Full description
Updates a system environment's \`name\`, \`description\`, \`color\`, or \`isProduction\`. Send at least one field; omitted fields are left unchanged. A new name must stay unique within the team — a duplicate returns 409. Pass \`description\` as an empty string to clear it. \`label\` cannot be changed after creation. Do not use this tool to change which workspace environments are attached; use addApiCatalogSystemEnvironmentAssociations or removeApiCatalogSystemEnvironmentAssociations instead. Requires a Postman Enterprise plan.
updateApiCollectionCommentUpdates a comment on an API's collection.
Full description
Updates a comment on an API's collection. **Note:** This endpoint accepts a max of 10,000 characters.
updateCollectionCommentUpdates a comment on a collection.
Full description
Updates a comment on a collection. **Note:** This endpoint accepts a max of 10,000 characters.
updateCollectionFolderUpdates a folder in a collection.
Full description
Updates a folder in a collection. For a complete list of properties, refer to the **Folder** entry in the [Postman Collection Format documentation](https://schema.postman.com/collection/json/v2.1.0/draft-07/docs/index.html). **Note:** This endpoint acts like a PATCH method. It only updates the values that you pass in the request body (for example, the \`name\` property). The endpoint does not update the entire resource.
updateCollectionRequestUpdates a request in a collection.
Full description
Updates a request in a collection. For a complete list of properties, refer to the **Request** entry in the [Postman Collection Format documentation](https://schema.postman.com/collection/json/v2.1.0/draft-07/docs/index.html). **Note:** - You must pass a collection ID (\`[example ID]\`), not a collection(\`12345678-[example ID]\`), in this endpoint. - This endpoint does not support changing the folder of a request. - This endpoint acts like a PATCH method. It only updates the values that you pass in the request body.
updateCollectionResponseUpdates a response in a collection.
Full description
Updates a response in a collection. For a complete list of properties, see the [Postman Collection Format documentation](https://schema.postman.com/collection/json/v2.1.0/draft-07/docs/index.html). **Note:** - You must pass a collection ID (\`[example ID]\`), not a collection UID (\`12345678-[example ID]\`), in this endpoint. - This endpoint acts like a PATCH method. It only updates the values that you pass in the request body (for example, the \`name\` property). The endpoint does not update the entire resource.
updateCollectionTagsUpdates a collection's associated tags.
Full description
Updates a collection's associated tags. This endpoint replaces all existing tags with those you pass in the request body.
updateComponentRenames a component or changes its lifecycle status.
Full description
Renames a component or changes its lifecycle status. Send \`name\` to rename, or \`status\` to archive (\`archive\`, making the component read-only while keeping its published versions accessible) or restore it (\`active\`). Send only one of the two per call: name and status cannot change together. Archived components cannot be renamed, edited, or published until they are set back to \`active\`. Do not use this tool to change a component's content; use updateComponentDraft instead. Requires a Postman Enterprise plan.
updateComponentDraftUpdates a component's working draft content, format, or both.
Full description
Updates a component's working draft content, format, or both. Include at least one field; omitted fields remain unchanged. Edits are not visible to teammates referencing the component until you publish them with createComponentVersion. Archived components cannot be edited — restore them with updateComponent first. Do not use this tool to publish changes; use createComponentVersion instead. Requires a Postman Enterprise plan.
updateDetectedSecretResolutionsRecords how a detected secret was dealt with, in one workspace.
Full description
Records how a detected secret was dealt with, in one workspace. Requires \`workspaceId\` and a \`resolution\` of \`FALSE_POSITIVE\` (not really a secret), \`REVOKED\` (was real, key has been rotated), or \`ACCEPTED_RISK\` (real, exposure accepted). This only records a judgement — it does not revoke a credential, remove the secret from the collection, or make the exposure safe. Never mark something \`REVOKED\` unless the key has actually been rotated, and never mark it \`ACCEPTED_RISK\` on a person's behalf: both are decisions a human owner has to make. Requires a Postman Enterprise plan.
updateFolderCommentUpdates a comment on a folder.
Full description
Updates a comment on a folder. **Note:** This endpoint accepts a max of 10,000 characters.
updateMockUpdates a mock server.
Full description
Updates a mock server. - Resource: Mock server entity associated with a collection UID. - Use this to change name, environment, privacy, or default server response. - To activate a server response, set \`config.serverResponseId\` to the server response's \`id\`. Pass \`null\` to deactivate.
updateMockServerResponseUpdates a server response's name, statusCode, body, headers, or language.
Full description
Updates a server response's name, statusCode, body, headers, or language. - \`statusCode\` must remain a 5xx value (500–599). - \`body\` is the raw response body string. Pass the full desired body — this is a full replacement, not a partial update. - Updating a server response does not change which response is active. To activate it, call \`updateMock\` with \`config.serverResponseId\`.
updateMonitorUpdates a monitor's configurations.
Full description
Updates a monitor's [configurations](https://learning.postman.com/docs/monitoring-your-api/setting-up-monitor/#configure-a-monitor).
updatePackageUpdates an active package's description, index script content, or both.
Full description
Updates an active package's description, index script content, or both. Include at least one field and only the fields you want to change; omitted fields remain unchanged. Do not use this tool to create or delete a package.
updatePullRequestUpdates the editable metadata of an open pull request, such as its title, description, or reviewers.
Full description
Updates the editable metadata of an open pull request, such as its title, description, or reviewers. Use reviewPullRequest (not this tool) to approve, decline, or merge a pull request.
updateRequestCommentUpdates a comment on a request.
Full description
Updates a comment on a request. **Note:** This endpoint accepts a max of 10,000 characters.
updateResponseCommentUpdates a comment on a response.
Full description
Updates a comment on a response. **Note:** This endpoint accepts a max of 10,000 characters.
updateSdkGitConnectionChanges an SDK Git connection's lifecycle status.
Full description
Changes an SDK Git connection's lifecycle status. Setting \`active\` connects or reconnects the repository and resumes auto-update pull requests; \`disconnected\` stops any further pull requests being opened while preserving the historical record, which stays queryable through getSdkGitConnectionPullRequests. The call is idempotent, so setting current values is a harmless no-op. The \`inaccessible\` status is set by Postman and cannot be assigned here — seeing it means the repository or its credentials need attention on the Git side. \`autoUpdatePullRequestsEnabled\` is Enterprise-only and is forced to false on Team plans. Requires a Postman Team or Enterprise plan.
updateSpecFileUpdates a file for an OpenAPI or protobuf 2 or 3 specification.
Full description
Updates a file for an OpenAPI or protobuf 2 or 3 specification. **Note:** - This endpoint does not accept an empty request body. You must pass one of the accepted values. - This endpoint does not accept multiple request body properties in a single call. For example, you cannot pass both the \`content\` and \`type\` property at the same time. - Multi-file specifications can only have one root file. - When updating a file type to \`ROOT\`, the previous root file is updated to the \`DEFAULT\` file type. - Files cannot exceed a maximum of 10 MB in size.
updateSpecPropertiesUpdates an API specification's properties, such as its name.
updateTeamSettingsUpdates a team's settings.
Full description
Updates a team's settings. This is a PUT and applies team-wide, affecting every member at once — read the current values with getTeamSettings first and send the full intended state, since a partial body can reset settings you did not mean to touch. Only call this on an explicit instruction naming the setting to change. Do not use it to infer configuration an operator did not ask for.
updateWorkspaceUpdates a workspace's property, such as its name or visibility.
Full description
Updates a workspace's property, such as its name or visibility. **Note:** - This endpoint does not support the following visibility changes: - \`private\` to \`public\`, \`public\` to \`private\`, and \`private\` to \`personal\` for **Free** and **Solo** [plans](https://www.postman.com/pricing/). - \`public\` to \`personal\` for team users only. - There are rate limits when publishing public workspaces. - Public team workspace names must be unique.
Write tools 107–109
updateWorkspaceGlobalVariablesUpdates and replaces a workspace's global variables.
Full description
Updates and replaces a workspace's global [variables](https://learning.postman.com/docs/sending-requests/variables/#variable-scopes). This endpoint replaces all existing global variables with the variables you pass in the request body.
updateWorkspaceRolesChanges who can access a workspace, for users, user groups, or partners.
Full description
Changes who can access a workspace, for users, user groups, or partners. Read the current state with getWorkspaceRoles first and get assignable role names from getAllWorkspaceRoles. Several constraints will reject an otherwise reasonable call: at most 50 operations per request, exactly one action per user, group, or partner in a body, and partner roles and user roles cannot be changed in the same call. Personal workspaces do not support role assignment, the external Guest role is not supported, and user groups require an Enterprise plan. Pass the \`identifierType=scim\` header to use SCIM IDs. This grants or removes access to everything in the workspace, so only call it on an explicit instruction naming the people and roles involved.
updateWorkspaceTagsUpdates a workspace's associated tags.
Full description
Updates a workspace's associated tags. This endpoint replaces all existing tags with those you pass in the request body.
Tool availability and permissions
This list describes the reviewed tools. Your selected method, provider access and action permissions determine what agents can use.
These lists use a conservative permission policy. Read requires a provider read-only hint or a reviewed Paperclip read rule. Evidence that an action changes data or submits information elsewhere puts it in Write. Write also includes actions we cannot verify as read-only. Read describes the reviewed evidence; it does not guarantee that an action has no side effects. A connected account can group actions differently.
Minimal, Code and Full have separate tool lists. Published source code does not establish the hosted version or what an account can access.
Tools for US · Browser sign-in — Minimal / EU · API key — Minimal
createCollection, createCollectionRequest, createCollectionResponse, createEnvironment, createMock, createSpec, createSpecFile, createWorkspace, duplicateCollection, generateCollection, generateSpecFromCollection, getAllSpecs, getAuthenticatedUser, getCollection, getCollections, getDuplicateCollectionTaskStatus, getEnabledTools, getEnvironment, getEnvironments, getGeneratedCollectionSpecs, getMock, getMocks, getSpec, getSpecCollections, getSpecDefinition, getSpecFile, getSpecFiles, getTaggedEntities, getWorkspace, getWorkspaces, publishMock, putCollection, putEnvironment, runCollection, searchPostmanElements, syncCollectionWithSpec, syncSpecWithCollection, updateCollectionRequest, updateMock, updateSpecFile, updateSpecProperties, updateWorkspace
Tools for US · Browser sign-in — Code / EU · API key — Code
getApiDiscoveryInstructions, getAuthenticatedUser, getCodeGenerationInstructions, getCollection, getCollectionContext, getCollectionFolder, getCollectionRequest, getCollectionResponse, getEnvironment, getEnvironmentContext, getEnvironments, getFolderContext, getInstalledApiMaintenanceInstructions, getPostmanContextOverview, getRequestCodeContext, getRequestContext, getResponseContext, getWorkspace, getWorkspaceContext, getWorkspaceEnvironmentsContext, getWorkspaces, getWorkspacesContext, searchPostmanElements
Tools for US · Browser sign-in — Full / EU · API key — Full
addApiCatalogSystemEnvironmentAssociations, addWorkspaceToPrivateNetwork, approveDenyAccessRequest, createAccessRequest, createApiCatalogSystemEnvironment, createCollection, createCollectionComment, createCollectionFolder, createCollectionFork, createCollectionPullRequest, createCollectionRequest, createCollectionResponse, createComponent, createComponentVersion, createEnvironment, createFolderComment, createMock, createMockServerResponse, createMonitor, createPackage, createRequestComment, createResponseComment, createSdk, createSdkGitConnection, createSpec, createSpecFile, createTeam, createWorkspace, createWorkspaceUpdate, deleteApiCollectionComment, deleteCollection, deleteCollectionComment, deleteCollectionFolder, deleteCollectionRequest, deleteCollectionResponse, deleteEnvironment, deleteFolderComment, deleteMock, deleteMockServerResponse, deleteMonitor, deletePackage, deleteRequestComment, deleteResponseComment, deleteSdk, deleteSpec, deleteSpecFile, deleteWorkspace, deleteWorkspaceUpdate, detectedSecretsQueries, duplicateCollection, generateCollection, generateSpecFromCollection, getAllComponents, getAllSpecs, getAllWorkspaceRoles, getAnalyticsData, getAnalyticsMetadata, getApiCatalogDiscoveryService, getApiCatalogDiscoveryServices, getApiCatalogService, getApiCatalogServiceCiRuns, getApiCatalogServiceEndpoints, getApiCatalogServiceMonitorRuns, getApiCatalogServiceSpecificationLints, getApiCatalogServices, getApiCatalogSystemEnvironment, getApiCatalogSystemEnvironmentAssociations, getApiCatalogSystemEnvironments, getApiDiscoveryInstructions, getAsyncSpecTaskStatus, getAuditLogEventActions, getAuditLogs, getAuthenticatedUser, getCodeGenerationInstructions, getCollection, getCollectionComments, getCollectionFolder, getCollectionForks, getCollectionPullRequests, getCollectionRequest, getCollectionResponse, getCollectionTags, getCollectionUpdatesTasks, getCollections, getCollectionsForkedByUser, getComponent, getComponentDraft, getComponentVersion, getComponentVersions, getContextGraphAsk, getDetectedSecretsLocations, getDuplicateCollectionTaskStatus, getEnabledTools, getEnvironment, getEnvironments, getFolderComments, getGeneratedCollectionSpecs, getGroup, getGroups, getInstalledApiMaintenanceInstructions, getMock, getMockServerResponse, getMockServerResponses, getMocks, getMonitor, getMonitorRunResults, getMonitors, getPackage, getPackages, getPostmanContextOverview, getPullRequest, getRequestComments, getResponseComments, getSdk, getSdkDownloadUrl, getSdkGitConnection, getSdkGitConnectionPullRequests, getSdkGitConnections, getSdks, getSecretTypes, getSourceCollectionStatus, getSpec, getSpecCollections, getSpecDefinition, getSpecFile, getSpecFiles, getStatusOfAnAsyncApiTask, getTaggedEntities, getTeam, getTeamAccessRequests, getTeamSettings, getTeamUser, getTeamUsers, getTeams, getWorkspace, getWorkspaceActivityFeed, getWorkspaceGlobalVariables, getWorkspaceRoles, getWorkspaceTags, getWorkspaceUpdate, getWorkspaceUpdates, getWorkspaces, listMonitorExecutions, listPrivateNetworkAddRequests, listPrivateNetworkWorkspaces, listRunsForExecution, managePartnerWorkspaceInvites, manageTeamMemberRoles, mergeCollectionFork, patchCollection, patchEnvironment, patchWorkspaceUpdate, postApiCatalogDiscoveryServices, publishDocumentation, publishMock, pullCollectionChanges, putCollection, putEnvironment, removeApiCatalogSystemEnvironmentAssociations, removeTeamMembers, removeWorkspaceFromPrivateNetwork, resolveCommentThread, respondPrivateNetworkAddRequest, reviewPullRequest, runCollection, runMonitor, searchLearningCenter, searchPostmanElements, submitContextGraphAsk, syncCollectionWithSpec, syncSpecWithCollection, transferCollectionFolders, transferCollectionRequests, transferCollectionResponses, transferWorkspaceElement, transferWorkspaceToTeam, unpublishDocumentation, unpublishMock, updateApiCatalogSystemEnvironment, updateApiCollectionComment, updateCollectionComment, updateCollectionFolder, updateCollectionRequest, updateCollectionResponse, updateCollectionTags, updateComponent, updateComponentDraft, updateDetectedSecretResolutions, updateFolderComment, updateMock, updateMockServerResponse, updateMonitor, updatePackage, updatePullRequest, updateRequestComment, updateResponseComment, updateSdkGitConnection, updateSpecFile, updateSpecProperties, updateTeamSettings, updateWorkspace, updateWorkspaceGlobalVariables, updateWorkspaceRoles, updateWorkspaceTags
Connection policies
Discovered actions follow the connection’s policies. Review their permissions and set actions to Ask first or Off as needed. Environment values can contain secrets. Running a collection issues its requests against the configured targets.
Postman connector FAQ
Can I require approval for actions?
Set an action to Ask first to require human approval of each call or Off to prevent calls. Allowed actions run without approval. Read and Write grouping is separate from these settings.
What can agents reach in Postman?
Agents reach workspaces, collections and environments accessible to the account or key. Paperclip has no workspace picker.
What do I need before connecting?
Use a Postman account or key for the correct region. Choose Minimal, Code or Full by the operations you need; group names do not establish read-only access.