Home / Companies / Postman / Blog / Post Details
Content Deep Dive

Manage publicly exposed Postman API keys

Blog post from Postman

Post Details
Company
Date Published
Author
Suhas Gaikwad
Word Count
314
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

Postman has introduced new features to enhance the management and security of API keys, particularly addressing the risks associated with exposed keys in public domains like GitHub, GitLab, and Postman's public workspaces. These enhancements allow Super Admin and Admin users to monitor and control publicly exposed API keys through the Manage Postman Keys page, offering details such as the key's name, location, detection date, last usage, and the team member responsible for its creation. Admins can manually or automatically revoke exposed keys, with notifications sent to the key owner via email, and all revoked actions are logged on the Audit Logs page. The auto-revoke feature is accessible to users with Enterprise plans, encouraging those not on such plans to upgrade for improved security. Additional resources for managing API keys and organizational security are available in the Postman Learning Center and Trust Center.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.