Home / Companies / Postman / Blog / Post Details
Content Deep Dive

Enterprises: Stop Handing Out API Keys! (How Postman Ended Credential Sprawl with Passport)

Blog post from Postman

Post Details
Company
Date Published
Author
Sam Chehab
Word Count
1,137
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

Postman describes developing Passport to address credential sprawl and overly broad API permissions as it expanded its use of AI agents and agentic workflows. Rather than distributing raw API keys, the approach uses a secure access proxy to provide verified human or agent identities with revocable, endpoint-specific access, reducing the risk that credentials spread across devices, tools, logs, and environments. The company began with an inventory process using endpoint scans to identify where secrets were concentrated, then observed human API traffic to infer appropriate policies while defining least-privilege rules for agents from their intended code and tool usage. Passport supports enforcement through its interface or integrations with IT service-management workflows and logs requests with identity, status, and telemetry data for auditing, alerting, compliance reporting, and ongoing policy refinement. Postman presents the system as a shift from detecting exposed credentials after the fact toward preventing their distribution while limiting each user or agent to only the API services and endpoints needed for its task.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 10 No monthly metrics for this publish month.
OpenTelemetry 1 No monthly metrics for this publish month.
Real-time 1 No monthly metrics for this publish month.
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.