Manage publicly exposed Postman API keys
Blog post from Postman
Postman has introduced new features to enhance the management and security of API keys, particularly addressing the risks associated with exposed keys in public domains like GitHub, GitLab, and Postman's public workspaces. These enhancements allow Super Admin and Admin users to monitor and control publicly exposed API keys through the Manage Postman Keys page, offering details such as the key's name, location, detection date, last usage, and the team member responsible for its creation. Admins can manually or automatically revoke exposed keys, with notifications sent to the key owner via email, and all revoked actions are logged on the Audit Logs page. The auto-revoke feature is accessible to users with Enterprise plans, encouraging those not on such plans to upgrade for improved security. Additional resources for managing API keys and organizational security are available in the Postman Learning Center and Trust Center.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.