Postman
Full API lifecycle in Claude Code — sync collections, run tests, create mocks, and audit API security.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for Postman, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
Full API lifecycle management for Claude Code powered by the Postman MCP Server. Sync collections, generate client code, discover APIs, run tests, create mocks, publish docs, and audit security. Surface: bundled Postman MCP server exposing collection, test, mock, and security-audit tools.
Key features and capabilities
- Postman MCP server integration
- Collection sync and client-code generation
- Automated API test runs and mocks
- API security auditing
Use cases
- Drive Postman collections and tests from the agent
- Audit an API's security posture during development