June 2022 Summaries
17 posts from Postman
Filter
Month:
Year:
Post Summaries
Back to Blog
Nnamdi Iregbulem, a partner at Lightspeed Venture Partners, offers insights into the evolving landscape of APIs, emphasizing the growing importance of real-time, streaming, and event-driven APIs in the business and technical domains. In a discussion on Postman’s Breaking Changes podcast, Nnamdi elucidates how these APIs are crucial for handling the vast amounts of data enterprises generate, which are pivotal for training future business intelligence through machine learning. The conversation explores the impact of this data landscape on operations and the increasing significance of DevOps, GitOps, DataOps, MLOps, and ModelOps in enterprise functionalities. Nnamdi highlights the continued relevance of synchronous APIs but underscores the exponential growth in the need for multi-protocol API gateways driven by our expanding data needs. His perspective aligns with Postman's investment in the open-source AsyncAPI specification, suggesting a future where APIs are central to the infrastructure supporting the development of machine learning models and enterprise operations.
Jun 30, 2022
539 words in the original blog post.
Postman has achieved the top rankings for both Best API Management Tool and Best API Design Tool in G2's 2022 Summer Reports, a recognition attributed to its vast community of 20 million developers. This accolade underscores Postman's commitment to revolutionizing API management by offering a unified platform for creating and utilizing APIs in an API-first environment. Postman Co-founder and CEO Abhinav Asthana highlights the evolution of API management from merely connecting applications to serving as the core components of modern software. The rise of an API-first approach, where applications are developed as interconnected services via APIs, is gaining traction, as evidenced by Postman's 2021 State of the API Report. Users can share their feedback through G2's review page and participate in the ongoing 2022 State of the API Survey until July 8, 2022.
Jun 28, 2022
221 words in the original blog post.
This blog post explores the security features available in Postman to help teams of any size protect their data and workflows. It emphasizes the importance of understanding and responsibly using variables, particularly the distinction between "initial value" and "current value," to avoid unintentional data sharing. The post introduces the concept of "secret" variables to mask sensitive information during collaborations or live demos and highlights the built-in token scanner alerts that notify users of potential security breaches. For larger organizations, it offers guidance on managing public elements, such as workspaces and collections, and the importance of role management to control access and visibility. It also discusses strategies for monitoring and reacting to security threats, including the use of audit logs and security reports, and stresses the importance of automating governance through measures like API key expiry and enterprise application management. The post concludes by recommending best practices and a security checklist to ensure effective implementation of these features.
Jun 27, 2022
2,081 words in the original blog post.
Postman faced challenges scaling its activity feed system, initially powered by a monolithic sync service that became a bottleneck as user numbers and workspace activities surged. To overcome these issues, Postman developed "Chronicle," a new feed system built with the flexibility to accommodate various entities, archive data efficiently, and support future growth. Chronicle leverages technologies like DocumentDB for its primary data source, Amazon SQS for managing data throughput, and AWS Lambda for data archiving. By decoupling from the legacy system, Postman significantly reduced database latency and increased system scalability. The team continues to explore improvements such as making feeds more actionable and customizing activity order based on user behavior.
Jun 25, 2022
1,239 words in the original blog post.
In an API-first world, enterprises are structured as a network of API artifacts that define microservices and infrastructure, enabling automation, testing, governance, and observability across operations. These artifacts serve as machine-readable contracts for internal, external, and third-party APIs, creating a detailed map that aids in decision-making and investment prioritization. Postman Collections have become essential, representing modular, executable API calls that enhance discoverability and quality assurance. They provide flexible integration units that support the automation of workflows and the expansion of API platforms, promoting industrial-grade interoperability and reliable operations. Automation can validate and govern API quality, ensuring compliance with documentation and testing standards. Observability is achieved through continuous monitoring of API interactions, using collections to extend visibility within existing application performance management (APM) infrastructures. This comprehensive approach to API management enhances collaboration, operational efficiency, and the potential to develop new services.
Jun 24, 2022
811 words in the original blog post.
In a recent episode of the Breaking Changes podcast, host Kin Lane interviewed Deepa Goyal, PayPal's Group Product Manager, to explore the intricacies of API product management. Deepa, who transitioned from Twilio to PayPal, offers an insightful perspective on treating APIs as products, emphasizing the need for standardization and a shared vocabulary to assess API maturity. Throughout the discussion, she highlighted the challenges of monetizing APIs and setting appropriate pricing while stressing the importance of moving beyond traditional metrics like "time to first API call" to "time to first API transaction," which measures the time taken for a developer to make a business-impacting API call. The conversation underscored the critical role of API product managers in bridging the gap between business needs and technological capabilities, thereby driving digital transformation within enterprises. The episode is available on multiple platforms, including Spotify, Apple Podcast, Google Podcast, Amazon Music, and YouTube.
Jun 23, 2022
602 words in the original blog post.
Postman is committed to democratizing APIs and enabling users to build and utilize APIs through its platform, celebrating a milestone of over 20 million users. To get started with Postman, users must create an account and can then choose to use the platform via a browser or desktop application. Postman allows users to send requests to APIs without needing to write code, and it supports various protocols such as HTTP, WebSockets, GraphQL, and gRPC. Users can add tests to ensure APIs function correctly by using JavaScript snippets or custom scripts. Postman Collections help organize requests and examples, which can be executed using the Collection Runner. Postman Flows, a low-code workflow builder in open beta, enables users to connect APIs and create workflows without complex coding. The platform emphasizes collaboration, allowing users to share their work and collaborate with others by publishing to the API network or inviting team members to work together in real-time.
Jun 22, 2022
804 words in the original blog post.
Aditya Kajla, co-founder and CEO at Warrant, explores the significance and implementation of role-based access control (RBAC) in SaaS and B2B applications, emphasizing its role in managing permissions and enhancing security. RBAC assigns roles to users based on their organizational functions, with each role carrying a set of permissions that determine what users can access and perform within an application. This access control mechanism is crucial for preventing security vulnerabilities and is ranked as a top web application security risk by OWASP. The article outlines a practical example of implementing RBAC using Warrant, a service designed to simplify the management of authorization models, and highlights the potential need for more detailed, fine-grained access control in certain applications. This more sophisticated control could involve specific permissions for individual users on particular objects, which is increasingly relevant with the rise of collaborative features and regulatory compliance requirements.
Jun 21, 2022
1,371 words in the original blog post.
API management is undergoing significant evolution as APIs transition from being mere connective elements to foundational components of modern software, prompting an API-first approach across industries. This transition is marked by varying interpretations of "API-first" among companies, with some focusing on public APIs and others on specification files. Furthermore, organizations are navigating challenges such as business alignment, maintaining centralized documentation, and addressing the API-design skills gap. The rise of multi-cloud and hybrid architectures is pushing companies to use APIs for infrastructure abstraction, while APIs are increasingly treated as products requiring continuous improvement and dedicated teams. The landscape is also characterized by a surge in API gateways, service meshes, and emerging protocols like gRPC and GraphQL, alongside a growing emphasis on API security and developer experience. As companies adopt API-first models, new organizational roles are emerging, including roles dedicated to API platforms and developer experience, reflecting the critical importance of APIs to business success.
Jun 16, 2022
1,782 words in the original blog post.
Çetin Kaan Taşkıngenç, a Postman Student Leader since 2021, shares his experiences and contributions to the student community, emphasizing the importance of networking and skill development through such communities. A third-year BASc student in Management Information Systems at Yaşar University, Çetin has been actively involved in creating content and hosting events to promote API literacy. His notable project includes developing an open-source Discord bot, "Postman Student Helper," which effectively combats phishing attacks by employing a distance detection system to identify suspicious links. His efforts in student communities have improved his public speaking skills and provided meaningful networking opportunities. Çetin encourages aspiring leaders to familiarize themselves with APIs, backend development, and content creation, emphasizing the value of collaboration and event hosting to gain critical soft skills.
Jun 14, 2022
1,155 words in the original blog post.
In a recent episode of Postman's Breaking Changes podcast, Aleksei Akimov, former head of API at Adyen, shared insights into Adyen's transition to an API-first company within the competitive payment API industry. Aleksei detailed how his journey from tech writer to API leader at Adyen helped shape the company's API-first approach, integrating design-first and code-first strategies and emphasizing the importance of a shared understanding of the API lifecycle. He highlighted the critical role of open-source tools and standards in building Adyen's API-first platform, which aids in navigating diverse regulatory landscapes and enhances business success. Aleksei's experiences underscore the significance of API awareness for business effectiveness, stressing that understanding payment APIs like those from Adyen, Stripe, and PayPal can offer greater control over business finances and facilitate global operations in the digital age. The episode provides valuable insights into why APIs are crucial in today's business environment and can be accessed on various podcast platforms and YouTube.
Jun 10, 2022
640 words in the original blog post.
Over the past year, Postman has significantly expanded its support for WebSockets, transforming from a basic debugging tool into a key component of collaborative API development. Initially launched as a simple client to connect and communicate with WebSocket APIs, Postman has since integrated support for the popular Socket.IO library, witnessing extensive adoption with over 120,000 users and 7 million connections. Postman offers a range of resources, including guides, videos, and public collections, to help users understand and utilize WebSockets seamlessly within their workflows, akin to HTTP workflows. The platform supports storing WebSocket requests in collections, fostering better organization and documentation, which enhances team collaboration and productivity. Postman continues to innovate by exploring WebSocket API testing capabilities and integrating schemas like AsyncAPI and OpenAPI for improved documentation and testing, ensuring the platform remains a vital tool for API developers.
Jun 09, 2022
758 words in the original blog post.
The blog post discusses the importance of securing Postman API Platform accounts and outlines best practices for managing access and user roles to prevent the leakage of sensitive information. It highlights the significance of assigning appropriate roles at the element, workspace, and team levels to ensure that users have suitable access, recommending a default Viewer role with Editors and Admins assigned as needed. The post also emphasizes the use of Postman’s version control workflows to maintain quality in shared collections and suggests implementing single sign-on (SSO) and SCIM for efficient user management. Additionally, it introduces Domain Capture as a feature to consolidate individual user accounts into a single, company-managed account to enhance collaboration and security. The post serves as Part 1 of a series aimed at guiding teams, regardless of size, in adopting robust security practices within the Postman platform.
Jun 08, 2022
1,676 words in the original blog post.
API platforms are designed to optimize success throughout the API lifecycle by incorporating strong feedback loops that address consumer and stakeholder needs, ensuring rapid, reliable, and well-communicated releases. These platforms enable high productivity and efficiency across microservices, APIs, and integrations within enterprises by allowing quick responses to incidents and consumer feedback, thus meeting customer needs more swiftly and with enhanced quality. Design-first practices and well-defined API lifecycles contribute to higher velocity by allowing teams to rapidly design, develop, test, and deliver new capabilities, fostering a reliable relationship between producers and consumers. Furthermore, API platforms support consistent forward progress through modular testing and CI/CD pipelines, minimizing failed deployments and avoiding rollbacks. They also facilitate quick recovery from incidents, maintaining consumer trust by efficiently responding to and resolving issues. By organizing and automating team productivity across business domains, API platforms ensure that essential integrations and workflows are ubiquitous and repeatable, enabling enterprises to advance without significant disruptions.
Jun 07, 2022
800 words in the original blog post.
Basketball and DevOps may seem worlds apart, but they share intriguing parallels in their ranking systems, as both the NBA playoffs and DevOps Research and Assessment (DORA) metrics use data-driven methods to evaluate performance. In the NBA, teams are ranked based on their regular-season win-loss records, determining their seeding in the playoffs, where top-ranked teams like the Miami Heat and Phoenix Suns may not always reach the finals. Similarly, DORA metrics assess DevOps teams' performance across aspects such as deployment frequency and change failure rate, categorizing them into Elite, High, Medium, or Low performance levels. Postman, a key tool in the DevOps lifecycle, aids teams in elevating their DORA scores by offering capabilities that enhance testing, debugging, and reliability, which is considered an emerging fifth metric by DORA Research Lead Dustin Smith. Both the NBA and DevOps systems provide structured ways to gauge success, highlighting the universal nature of performance assessment across different fields.
Jun 03, 2022
780 words in the original blog post.
Postman's universal search, introduced in 2020, aimed to facilitate the discovery of various entities like collections and workspaces within the Postman API Platform by implementing a federated search system across multiple Elasticsearch indices. The initial approach categorized results by entities, allowing users to filter search queries; however, a unified result list from a federated search was found to enhance user experience. To address the challenge of differing index-specific scores from Elasticsearch's BM25 algorithm, Postman implemented z-score normalization, allowing for comparable scores across indices. Further improvements included the development of query understanding to predict user intent and boost relevant results based on consumption data and a custom word corpus tailored to Postman’s technical jargon. Machine learning models, particularly SVM with TF-TDF vectorizer, were employed to enhance result relevance, resulting in a significant increase in search conversion rates from 30% to 42% post-implementation. Future enhancements are planned to incorporate semantic search, user-specific interactions, and real-time data replication to continue improving search functionality.
Jun 02, 2022
2,169 words in the original blog post.
Meta has expanded developer access to its WhatsApp Cloud API, previously available only to select partners, to reach smaller companies and broaden its market presence. As a major tech player owning platforms like WhatsApp, Messenger, and Instagram, Meta's decision reflects a broader trend among API providers to invest in cloud-based solutions. Cloud APIs, hosted on infrastructure managed by the provider, offer rapid implementation and scalability without the need for consumers to manage their own infrastructure, in contrast to on-premises APIs that require consumer-managed setups and are often used by industries with strict regulatory requirements. Despite the rise of cloud technologies, on-premises APIs remain vital for many enterprises, particularly those with compliance needs, as providers like Meta continue to support both solutions to meet diverse consumer demands.
Jun 01, 2022
472 words in the original blog post.