
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@postman/postman-plugin
Advanced tools
Installs the Postman plugin into every supported coding agent on this machine.
Powering API engineering for agents
The Postman plugin brings filesystem-first API development and organization-wide API context to coding agents. It enables agents to design, mock, test, document, monitor, and ship APIs directly from Claude Code, Cursor, and Codex. Every operation produces inspectable files or CLI commands that fit naturally into Git and CI, while the Postman Context Graph helps agents understand dependencies, ownership, runtime behavior, and the likely impact of a change.
Install Postman in every compatible coding agent detected on your machine:
npx @postman/postman-plugin
One command configures Claude Code, Codex, Cursor, Kimi Code and OpenCode.
Run it again to update, status to see what's installed, and remove to
uninstall; --agent <id> limits any of them to one agent.
You can also use the following commands to install individually:
View Postman on Claude Plugins
claude plugin install postman@postman
View Postman on the Cursor Marketplace
/add-plugin postman
View Postman on ChatGPT Plugins
codex plugin add postman@postman
All postman resources have a filesystem representation, so your agent can work with the API ecosystem through the interface it understands best: files. API specifications, collections, environments, examples, mocks, documentation, and Flows can live beside the application code.
The git-native v3 collection schema makes this
especially agent-friendly. A collection is a directory tree under
postman/collections/, where every request, folder definition, and saved
example is its own YAML file. Environments use the same file-first model under
postman/environments/. HTTP, GraphQL, gRPC, WebSocket, Socket.IO, MQTT, MCP,
and LLM requests all have defined schemas the agent can follow.
That means the agent can:
A repository can show what an endpoint calls, but rarely who calls it, whether those consumers are active in production, where they are deployed, or which team owns them. The Context Graph fills that gap with a private, authenticated, organization-wide map of your API ecosystem.
It reconciles signals from the systems where API knowledge already lives:
The api-discovery skill lets the agent start with the
thing you plan to change and ask one natural-language question:
postman context-graph ask "What could break if we change the billing API?" --wait
The graph discovers the surrounding scope—including repositories that are not checked out locally—before the agent starts editing code. It refreshes nightly as services, deployments, ownership, and runtime relationships change.
In Postman's controlled benchmark across 468 repositories, starting with this map used up to 74% fewer tokens, 52% fewer tool calls, and 72% lower cost. Accuracy also improved in 18 of 21 scored prompt-model pairs. Most graph queries completed in roughly 20–40 seconds. Read the methodology and results in Introducing the Context Graph API: One Map of Your API Ecosystem.
The api-mocking skill creates a working mock from an
OpenAPI specification or collection and stores the implementation beside the
API code. The agent can run it locally, add success and failure scenarios, and
test consumers without waiting for the real service to be ready or available.
The mock stays local until you choose to push and deploy it. When teammates or external systems need access, the same mock can become a durable hosted URL without rebuilding it in another tool.
Some Postman CLI commands report usage analytics by default. Where supported,
you can disable reporting for an individual command with
--no-report-events. postman application test uses
--report-events=false instead.
What is sent by default:
| Command | Data sent |
|---|---|
postman collection run | Run analytics and run history |
postman application test | Run results and analytics |
postman spec lint | Lint analytics, including violation counts and pass/fail |
postman workspace push | Push analytics |
postman runner start | Runner analytics |
postman flows run | Flow-run analytics |
postman request | Request analytics |
Important limits:
postman collection run --no-report-events disables analytics but does not
disable run-history uploads.postman init makes richer reporting opt-in with --report-events; it does
not accept --report-events=false.collection run, spec lint, workspace push, init, the
mock commands, and performance run in the US region; other regions,
including the EU, do not emit them.Apache-2.0 — see LICENSE.
FAQs
Installs the Postman plugin into every supported coding agent on this machine.
We found that @postman/postman-plugin demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.