Structure, govern, and collaborate at scale with Postman Organizations

Postman recently rolled out Organizations, a new set of features designed to allow Enterprise plan customers to set up multiple Teams under…

Wiz Zero Critical Club!

Postman has joined Wiz’s Zero Critical Club, “a prestigious group of Wiz customers who have achieved the extraordinary feat of having zero…

Root Cause Analysis: Shai-Hulud 2.0

Postman Security knows that trust begins with transparency. So we are following up (as promised!) on the Shai Halud attack we first…

Smart API Security: The Power of LLMs and Postman MCP

APIs are the nervous system of modern software. They power apps, SaaS platforms, fintech products, and even your coffee machine. Yet, APIs…

Shai-Hulud 2.0 npm supply-chain attack

Update: our RCA has been posted here.  Postman has discovered unusual activity in our NPM org relating to the ongoing “Shai-Hulud 2.0…

Postman Security: Playing Chess, Because Every Move Matters

In today’s rapidly evolving API landscape, security isn’t a box to check; it’s a dynamic, evolving strategy. At Postman, we’re not just…

Product Security Scorecards: Coupling Security Issues with Preventative Controls to Drive Security Maturity

Postman’s commitment to Product Security begins with our approach to Application Security. Every engineering team in Postman has an assigned Security Engineer…

Scaling with Confidence: Postman’s Journey to Infrastructure as Code with Kubernetes and ArgoCD

At Postman, we serve millions of developers building, testing, and documenting APIs. As our platform scaled, so did the complexity of managing…

Postman (Free) is secure by design

Update: Postman plans are changing in early 2026. For the latest information, visit our pricing page. As Postman’s Head of Security, I…

Postman Security Update: Fixing a URL Exposure Risk in ‘Related Requests’

At Postman, security is a continuous, proactive process. As we recently wrote about, we build, test, and strengthen our platform daily to…