Closing the API Security Gap: Postman and Wiz, Better Together
What do you get when you combine Postman’s API platform with Wiz’s cloud security intelligence? A single, unified view of every API your team owns, and the risk that comes with it. Wiz’s runtime security is now embedded directly in the Postman API Catalog, so your team can see, understand, and fix API risk before it becomes a breach.
The gap no one is talking about
Security teams have made real progress in understanding what’s running in production. Tools like Wiz give CISOs and security engineers a powerful lens into deployed services, surfacing runtime risk, misconfigurations, and exposure across cloud environments.
But there’s a blind spot most organizations haven’t fully addressed: the APIs that haven’t shipped yet. APIs that are actively being designed, built, and reviewed, but haven’t reached production, carry real risk. Today, they’re largely invisible to security tooling.
That’s the gap we’re closing together with Wiz.
How the current workflow breaks down
In the existing model, a security engineer using Wiz has to manually pull risk signals from the dashboard, translate those findings, and then track down the right developer to fix the issue, often across tools and teams. Context gets lost in Slack threads and email handoffs. Fixes happen slowly, if at all.
The problem isn’t visibility. It’s where that visibility lives. When security signals exist outside the developer’s workspace, the workflow breaks down at the handoff.
The Postman API Catalog has always given teams a comprehensive view of their known APIs. Wiz has always excelled at highlighting risk in what’s deployed. But until now, neither tool could see the other’s picture completely.
Before: Pull risk from Wiz, find the engineer, fix in real time.
After: Risk surfaces in Postman, inside the API Catalog, in context.
Integrating Wiz into Postman’s API Catalog
One of the key value drivers for Postman customers has always been our commitment to API security, and the Wiz CISO dashboard has always been a core component of that. This new integration takes that a step further by embedding the Wiz dashboard right into the Postman platform through the Postman API Catalog. It’s exactly what it sounds like: Wiz’s security intelligence, embedded natively inside the Postman platform.
By embedding the Wiz CLI and dashboard directly into Postman, teams get a unified scorecard with operational health and a complete inventory of every known service, all in one view.
This matters because it fulfills the first mandate of any security program. If you have services, you need visibility into them before you can create and enforce policy. That visibility now lives in the tool your developers already use every day.
Think of it as the intersection of Postman’s API governance and Wiz’s cloud security intelligence: every known service, its operational health, and its security posture, in a single, actionable view.
Three capabilities that change the workflow
- See what Wiz can’t see alone. APIs on the left side of the lifecycle, undeployed and in development, are invisible to runtime scanners. The API Catalog surfaces them and now flags risk before they ship.
- Full-spectrum coverage. Deployed APIs get Wiz’s runtime risk analysis. Undeployed APIs get policy and design-time checks. Current risk and future risk, in one place.
- Embedded, not bolted on. The dashboard lives inside Postman, not as a separate tab to remember, but as part of the API Catalog workflow your team already uses.

Shift left on security, for real
“Shift left” has become a cliche. The principle still holds: catching a security problem at design time is orders of magnitude cheaper than fixing it in production. The Wiz API Catalog dashboard makes that possible in a way that wasn’t feasible before.
When a developer opens an API in Postman, they’ll see a scorecard alongside everything else, not because they went looking for it, but because the signal came to them. That’s the model that actually changes behavior.
“The new dashboard shows risks based on APIs that aren’t deployed yet, before they become a problem. That’s how we move from reactive to preventive.”
Get started today
The Wiz API Catalog dashboard is available now for customers on Postman’s Enterprise plan. To turn on the integration, go to your API Catalog settings or reach out to your Postman account team.
We’re just getting started. Expect deeper workflows, expanded coverage, and more customer stories in the weeks ahead. In the meantime, we’d love to hear how your team is using it.
Resources
- Postman API Catalog
- Wiz Runtime Sensor
- Postman API Governance
- Postman Security Overview
- Wiz Platform

What do you think about this topic? Tell us in a comment below.