October 2026 Summaries
7 posts from Postman
Filter
Month:
Year:
Post Summaries
Back to Blog
No summary generated yet.
Oct 09, 2026
1,965 words in the original blog post.
No summary generated yet.
Oct 08, 2026
2,150 words in the original blog post.
Astropods, part of Postman’s AI stack, is presented as an agent operating system for building, deploying, governing, and monitoring production AI agents through a unified lifecycle. Developers define agents in an astropods.yml specification, create and run projects locally using the ast CLI and Docker, optionally use managed models through the AI Gateway, and can leverage coding assistants such as Claude Code to build or migrate applications. Agents are packaged as versioned blueprints after specification validation, then deployed through a web interface or CLI, with documentation in AGENT.md serving as the user-facing Agent Card. Astropods also supports Slack deployment through an adapter requiring a configured Slack app, tokens, scopes, and access policies. After deployment, teams can use traces to inspect interactions and tool calls, evaluations to identify issues such as unnecessary calls or data exposure, and monitoring to assess usage, costs, latency, network activity, and adoption. The guide emphasizes production readiness through validated specifications, secure credential handling, accurate integration documentation, tested workflows, appropriate access controls, and healthy operational metrics.
Oct 07, 2026
995 words in the original blog post.
Postman describes developing Passport to address credential sprawl and overly broad API permissions as it expanded its use of AI agents and agentic workflows. Rather than distributing raw API keys, the approach uses a secure access proxy to provide verified human or agent identities with revocable, endpoint-specific access, reducing the risk that credentials spread across devices, tools, logs, and environments. The company began with an inventory process using endpoint scans to identify where secrets were concentrated, then observed human API traffic to infer appropriate policies while defining least-privilege rules for agents from their intended code and tool usage. Passport supports enforcement through its interface or integrations with IT service-management workflows and logs requests with identity, status, and telemetry data for auditing, alerting, compliance reporting, and ongoing policy refinement. Postman presents the system as a shift from detecting exposed credentials after the fact toward preventing their distribution while limiting each user or agent to only the API services and endpoints needed for its task.
Oct 06, 2026
1,137 words in the original blog post.
Postman has introduced site-wide licensing and Private Cloud deployments to give large organizations greater flexibility in purchasing, data control, and platform operation, while planning an air-gapped client for early 2027 for teams working entirely within disconnected networks. Site-wide licensing combines a platform fee for all users and agents with consumption-based pricing for products used, while Private Cloud provides a managed, single-tenant deployment intended for regulated enterprises requiring stronger control over data storage and handling. The company also highlights recent product releases, including Git-native Workspaces, Agent Mode, API Catalog, Context Graph, Performance Testing, AI Engineer, and an AI-oriented technology stack. Addressing API security risks created by distributed keys, scripts, SDKs, and autonomous agents, Postman promotes Passport, which keeps API keys in customer-managed secret stores and routes access through a proxy in the customer’s VPC so keys and requests remain within the organization’s network.
Oct 05, 2026
560 words in the original blog post.
Postman deployed its Passport access-management system to secure production API access for developers building and maintaining its agentOS fleet, which grew from 32 to 70 agents across go-to-market, product, and engineering functions. A security audit had identified 278 API keys spread across developer devices, CI configurations, and deployment manifests, including over-scoped vendor credentials and shared keys that complicated attribution and rotation. Passport replaces local secrets in environment files with references that are resolved at request time through a managed laptop daemon and corporate-network proxy, while real credentials remain in vaults. Security created a catalog limiting 42 SaaS and internal systems to 104 approved endpoints, enabling resource-level permissions, time-limited developer access, per-call attribution to developers, agents, and runs, and centralized revocation. The five-day rollout replaced existing environment credentials and rotated old keys, reportedly reducing production credentials on developer machines to zero while shortening new-system onboarding from 15 to three days and enabling new developers to contribute within two hours.
Oct 05, 2026
832 words in the original blog post.
Postman API Catalog is an Enterprise feature designed to provide a continuously updated, centralized view of an organization’s APIs and services, combining ownership information, specifications, test results, CI/CD status, and production performance data. It discovers APIs automatically by scanning connected repositories and can incorporate live Kubernetes endpoints, reducing reliance on manual service inventories. Teams can map APIs to separate staging, production, or other environments, allowing them to compare branch-level test and specification compliance with live metrics such as p95 latency, error rates, uptime, and request volume. Its Service Health Scorecard consolidates these signals and supports thresholds that classify services by health status, while Agent Mode enables natural-language queries to identify failures and potentially diagnose or implement fixes through Git integrations. By bringing governance, development, and operational data together, the Catalog aims to help platform teams accelerate reviews, incident response, ownership discovery, and service-level discussions.
Oct 01, 2026
1,127 words in the original blog post.