Home / Companies / Postman / Blog / Post Details
Content Deep Dive

How Postman Passport keeps API secrets inside your network

Blog post from Postman

Post Details
Company
Date Published
Author
Talia Kohan
Word Count
1,537
Company Posts That Month
17
Language
English
Hacker News Points
-
Post removed?
No
Summary

Postman Passport is an Enterprise feature with an Advanced Security Administration add-on designed to reduce API secret sprawl by replacing distributed API keys with cryptographically bound credential references. Consumers place these references in requests, while a secure access proxy inside the organization’s network authenticates the caller, verifies authorization scope, retrieves the real secret from an existing secret store, injects it into the outbound request, and prevents the consumer from ever viewing the resolved credential. The system relies on certificates rooted in the organization’s certificate authority, keeps secrets out of the Postman cloud and audit logs, and supports access revocation without rotating keys or locating copies on users’ machines. Access is administered through namespaces, where Team Admins configure proxies and assign Managers to approve workspace and API-access requests for Members. Passport integrates with secret stores such as HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, and 1Password, while using the Postman CLI on the consumer side, and is positioned as particularly useful for regulated environments, offboarding users, and controlling credentials used by both people and AI agents.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.