How Postman Passport keeps API secrets inside your network
Blog post from Postman
Postman Passport is an Enterprise feature with an Advanced Security Administration add-on designed to reduce API secret sprawl by replacing distributed API keys with cryptographically bound credential references. Consumers place these references in requests, while a secure access proxy inside the organization’s network authenticates the caller, verifies authorization scope, retrieves the real secret from an existing secret store, injects it into the outbound request, and prevents the consumer from ever viewing the resolved credential. The system relies on certificates rooted in the organization’s certificate authority, keeps secrets out of the Postman cloud and audit logs, and supports access revocation without rotating keys or locating copies on users’ machines. Access is administered through namespaces, where Team Admins configure proxies and assign Managers to approve workspace and API-access requests for Members. Passport integrates with secret stores such as HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, and 1Password, while using the Postman CLI on the consumer side, and is positioned as particularly useful for regulated environments, offboarding users, and controlling credentials used by both people and AI agents.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.